Legal information
Privacy Policy
This notice explains in clear terms how personal data are handled when you visit yerocle.com, create an account or use the Yerocle project-management platform.
Last updated: 8 August 20261. Controller and scope
The data controller for the public website, account management, platform security and service administration is Unica Cooperativa Sociale, Via Cerrate Casale 38, 73100 Lecce (LE), Italy · VAT no. / P. IVA 04702960750 · Tax code / C.F. 93098480754. You can contact us at info@yerocle.com.
For project content entered by a customer organisation or a project partnership, that organisation may act as data controller and Unica Cooperativa Sociale may process data on its documented instructions. The individual Terms of Use do not replace an Article 28 agreement: where Unica processes personal data on behalf of an organisation acting as controller, the parties must separately define roles, instructions, security commitments and deletion or return of data as required by the GDPR.
2. Data we process
- Account and access data: full name, email address, password hash, language, activation status, role, partner membership and permissions.
- Project content: project, partner, work package, activity, deliverable, output, task, budget, expense, procedure, meeting, minutes, communication, publication and reporting data, including uploaded files.
- Support and communications: messages, requests, email delivery data and information you provide when asking for assistance.
- Integration data: configuration and credentials for services enabled by an authorised Master, such as email or Zoom; secrets are stored in encrypted form.
- Technical and security data: IP address, date and time, requested resource, browser/device information, authentication and error events, and information needed to prevent misuse.
Do not upload special-category data, criminal-offence data or other unnecessary personal information unless your organisation has verified a valid legal basis, access rules and appropriate safeguards.
3. Purposes and legal bases
We do not use consent as the legal basis for functions that are necessary to provide the account or the requested service. If a future optional activity requires consent, it will be requested separately and may be withdrawn at any time.
| Purpose | Legal basis |
|---|---|
| Create and administer accounts; provide platform features; manage access and projects. | Performance of a contract or pre-contractual steps requested by the user/organisation. |
| Operate authentication, backups, troubleshooting, security monitoring and abuse prevention. | Legitimate interests in providing a secure, reliable service; compliance with legal obligations where applicable. |
| Send service messages, account activation and password-recovery emails. | Performance of the service and legitimate interests in account security. These are not marketing emails. |
| Manage billing, contracts, compliance requests and disputes. | Performance of a contract, legal obligations and establishment, exercise or defence of legal claims. |
| Process customer project content on the customer’s instructions. | The legal basis is determined by the customer acting as controller; Yerocle acts as processor where applicable. |
4. Assisted features and human review
When an authorised user requests document analysis, imports, suggestions or report drafting, the relevant project content may be sent to the configured technology provider solely to generate the requested result. Users must review, correct and confirm proposals before relying on or saving them.
Yerocle does not make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals.
5. Authorised persons and service providers
Data are accessible only to authorised users according to project roles and permissions, authorised Unica personnel who need access for administration or support, and suppliers necessary to operate the service. Depending on the features enabled, these may include:
- Aruba, for domain, infrastructure, hosting and related cloud services;
- Resend and email infrastructure providers, for transactional email delivery;
- OpenAI, only when an authorised user invokes an assisted function that requires content processing;
- Zoom, Microsoft 365, Gmail or SMTP providers only when the relevant integration is explicitly configured for a project.
Providers act under their applicable contractual and data-protection terms. Data are not sold and are not disclosed for third-party advertising.
6. International transfers
Some suppliers may process data outside the European Economic Area. Where this occurs, transfers are based on an adequacy decision or appropriate safeguards under Chapter V of the GDPR, such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where necessary. Further details can be requested at info@yerocle.com.
7. Retention
- Account and project content are retained for the duration of the service or project and afterwards only for the time needed to complete deletion/return, meet legal obligations or protect legal rights.
- Password-recovery links expire after 30 minutes; authentication sessions last up to 8 hours.
- Contractual, invoicing and accounting records are retained for statutory periods, normally up to 10 years where applicable.
- Security logs and backups are retained for limited, proportionate operational periods and replaced according to the applicable rotation.
A customer’s retention instructions for project content may differ where required by grant, audit, public-procurement or other sector rules. Deletion requests remain subject to mandatory retention obligations.
8. Security
Yerocle applies technical and organisational measures proportionate to risk, including HTTPS encryption in transit, personal authentication, role-based access, password hashing, encrypted integration credentials, backups, logging and access minimisation. No system can eliminate every risk; users must protect their credentials, use authorised devices and report suspected incidents promptly.
9. Your rights
Where the GDPR applies, you may request access, rectification, erasure, restriction, portability, object to processing based on legitimate interests, and withdraw consent where consent is used. To exercise a right, email info@yerocle.com; we may need to verify your identity. If your request concerns project content controlled by your organisation, we may direct it to that controller.
You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali).
10. Changes to this notice
We may update this notice when the service, suppliers or applicable rules change. The current version and update date will always be published on this page; material changes will be communicated through an appropriate channel.