Privacy Policy Contacts

Privacy Policy Contacts

This privacy policy aims to provide all the information regarding the processing of personal data carried out by Iumob S.r.l. when the user contacts Yooppe.com (as better specified below).


Please note that, for Users residing in the United States, the use of Yooppe’s Services is available exclusively through the App.

1. INTRODUCTION – WHO ARE WE?

Iumob S.r.l., with registered offices in Via Comelico, No. 3, 20135 Milano, Tax Code/VAT No. 07048770965, enrolled in the Company Register of Milan with the No. MI-1931950  (hereinafter the “Data Controller”), owner of the website www.yooppe.com (hereinafter the “Website”) and the application Yooppe (hereinafter the “App”), as the controller of personal data of the users who browse and are registered on the Website and the App (hereinafter the “Users”) provides the following privacy policy according to Article 13 of EU Regulation 2016/679 dated 27 April 2016 (hereinafter, “GDPR”) and for Users in the United Kingdom, pursuant to Article 13 of the UK General Data Protection Regulation (hereinafter “UK GDPR” and, together with the GDPR, the “Regulations”), and in accordance with the Data Protection Act 2018 (hereinafter, together with the Regulations, the “Applicable Law”) as well as any further provisions that apply if the User resides outside the European Union and the United Kingdom (hereinafter, the “Further Provisions”).


2. HOW TO CONTACT US?
The Data Controller takes the utmost account of its Users’ right to privacy and protection of personal data. For any information related to this privacy policy, Users may contact the Data Controller at any time, using the following methods.
  1. Directly online:
    1. By contacting customer service (hereinafter, "Customer Service") by clicking directly here;
  2. By Mail:
    1. Sending a registered letter with return receipt to the registered offices of the Data Controller (Via Comelico, 3, 20135 Milano);

For specific requests to be sent to the Data Protection Officer (DPO), if the User who uses the Website/App resides in an EU or non-EU country (with the exception of the United Kingdom), the User can contact the Controller's DPO, whose contact details are provided below: 
company Shibumi S.r.l. - e-mail: dpo@iumob.it.


If the User using the Website/App resides in the UK, for requests relating to the processing of personal data, the User may contact GDPRLocal Ltd., as the Controller's designated Representative in the United Kingdom, pursuant to Article 27 of the UK GDPR, whose contact details are provided below:

  1. Telephone number: + 441 772 217 800
  2. Address: GDPRLocal Ltd. 1st Floor Front Suite 27-29 North Street, Brighton, England BN1 1EB


3. WHAT DO WE DO? – PROCESSING PURPOSES
The User may contact the Data Controller through Customer Service, accessible by filling out the appropriate form in the “Contact” section, by browsing the Site or App, by e-mail to the address published on the Data Controller’s Website and App, or eventually by any other method indicated by the Data Controller.  In relation to these activities, the Data Controller collects personal data relating to the Users.

This Site/App and any services offered through the Site/App are reserved for individuals who are 18 years and over. Therefore, the Data Controller does not collect personal data relating to individuals under 18 years of age. Upon request of the Users, the Data Controller will promptly delete all personal data that has been involuntarily collected and related to subjects under the age of 18.

In particular, Users' personal data will be processed by the Controller in compliance with the Applicable Law and the Further Provisions for the following processing purposes:
  1. executing the User’s request: the personal data of the Users are collected and processed by the Data Controller with the only purpose to reply to their query, including that transmitted to Customer Service. The Data Controller will collect the following personal data in order to be able to reply to the User’s request: name, surname, email address, and any other information relating to the User possibly and voluntary given by the User to the Data Controller. No other processing will be carried out by the Data Controller in relation to the Users’ personal data. Without prejudice to what is stipulated elsewhere in this privacy policy, under no circumstances the Controller will make the personal data accessible to other Users and/or third parties; 
  2. accounting-administrative purposes, or in order to carry out organisational, administrative, financial and accounting activities, as internal organisational activities and activities aimed at fulfilling contractual and precontractual obligations;
  3. legal obligations, or in order to fulfil obligations provided by the law or the European laws or by the Further Provisions.
The provision of personal data for the processing purposes indicated above is optional but necessary, since failure to provide such data will make it impossible for the User to make a request to the Controller.

4.  LEGAL BASIS
Execution of the User’s request (as described in paragraph 3, letter a) above): the legal basis is Article 6, paragraph 1, letter b) of the Regulations, since the processing is necessary for the performance of a contract to which the User is party or in order to take steps at the request of the User prior to entering into a contract.

Accounting-administrative purposes (as described in paragraph 3, letter b) above): the legal basis is Article 6, paragraph 1, letter b) of the Regulations, since the processing is necessary for the performance of a contract to which the User is party or in order to take steps at the request of the User prior to entering into a contract.

Legal obligations (as described in paragraph 3, letter c) above): the legal basis is Article 6, paragraph 1, letter c) of the Regulations, since the processing is necessary for compliance with a legal obligation to which the controller is subject.

5. PROCESSING METHODS AND DATA RETENTION PERIOD
The Data Controller will process the personal data of Users using manual and IT tools, with logic strictly related to the purposes themselves and, in any case, in order to guarantee the security and confidentiality of the data.

The personal data of the Users will be retained for the time strictly necessary to carry out the main purposes explained in paragraph 3 above or, in any case, as necessary for the protection in civil law of the interests of both the Users and the Data Controller.

For any further information or clarification regarding data retention periods and the Data Retention Policy adopted by the Controller, User can contact customer service by clicking directly here.

6. TRANSMISSION AND DISSEMINATION OF DATA
The User’s personal data may be transferred outside the European Union and the UK and, in this case, the Data Controller will ensure that the transfer is carried out in accordance with the Applicable Law and, in particular, in accordance with Articles 45 (Transfer on the basis of an adequacy decision) and 46 (Transfer subject to appropriate safeguards) of the Regulations as well as the Further Provisions.

The employees and/or collaborators of the Data Controller who are in charge of carrying out Website/App maintenance may become aware of the personal data of the Users. These subjects, who have been instructed by the Data Controller accordingly to article 29 of the Regulations, will process the User's data exclusively for the purposes indicated in this policy and in compliance with the provisions of the Applicable Law as well as the Further Provisions.

The personal data of the Users may also be disclosed to third parties who may process personal data on behalf of the Data Controller as “Data Processors” pursuant to Article 28 of the Regulations, such as, for example, IT and logistic service providers functional to the operation of the Website/App, outsourcing or cloud computing service providers, professionals and consultants.

Users have the right to obtain a list of any data processors appointed by the Data Controller, making a request to the Data Controller in the manner indicated in paragraph 7 below.

7. RIGHTS OF THE DATA SUBJECTS
Users may exercise their rights granted by the Applicable Law by contacting the Data Controller as follows:
  1. Directly online:
    1. By contacting Customer Service by clicking directly here;
  2. By Mail:
    1. Sending a registered letter with return receipt to the registered offices of the Data Controller (Via Comelico, 3, 20135 Milano);

For specific requests to be sent to the Data Protection Officer (DPO), if the User who uses the Website/App resides in an EU or non-EU country (with the exception of the United Kingdom), the User can contact the Controller's DPO, whose contact details are provided below: the company Shibumi S.r.l. - e-mail: dpo@iumob.it.


If the User using the Website/App resides in the UK, for requests relating to the processing of personal data, the User may contact GDPRLocal Ltd., as the Controller's designated Representative of the Data Controller in the United Kingdom, pursuant to Article 27 of the UK GDPR, whose contact details are provided below:
  1. Telephone number: + 441 772 217 800
  2. Address: GDPRLocal Ltd. 1st Floor Front Suite 27-29 North Street, Brighton, England BN1 1EB
Pursuant to Applicable Law and/or the Further Provisions that apply to the specific case, the Data Controller informs that Users have the right to obtain indication (i) of the origin of personal data; (ii) the purposes and methods of the processing; (iii) the logic applied in the event of processing carried out with the aid of electronic instruments; (iv) of the identification details of the data controller and processors; (v) the subjects or categories of subjects to whom the personal data may be communicated or who may come to aware of them as processors or agents.

Furthermore, Users have the right to obtain:

a) access, updating, rectification, or, when interested, integration of data;

b) the cancellation, transformation into anonymous form or the restriction of data processed in breach of the law, including data that does not need to be stored in relation to the purposes for which the data was collected or subsequently processed;

c) certification to the effect that notification has been supplied of operations as per letters a) and b), as also regards their content, to those to whom the data was communicated or disseminated, except for the case where notification proves impossible or requires the use of means clearly disproportionate to the right being protected.

Moreover, the Users have: 

a) the right to revoke consent at any time, if the processing is based on their consent;

b) (where applicable) the right to data portability (the right to receive all personal data concerning them in a structured format, commonly used and readable by automatic device);

c) the right to oppose to:

i) in whole or part, for legitimate reasons, the processing of personal data relating to him/her for legitimate reasons even pertinent to the purpose of collection;

ii) in whole or part, the handling of personal data for the purpose of sending advertising or sales materials or for the carrying out of market research or for commercial communication purposes;

iii) if personal data is processed for direct marketing purposes, at any time, to the processing of data for this purpose, including profiling to the extent that it is related to such direct marketing.

Furthermore, if the User resides in a country outside the European Union, the User may be granted different and/or additional rights, based on the Further Provisions. For further information on the list of these rights and how to exercise them, the User may contact the Controller by following the methods indicated at the beginning of this paragraph.

If the User believes that the processing of personal data concerning the User violates the Regulations and/or the Further Provisions, the right to lodge a complaint with a Supervisory authority (in the Member State in which he/she usually resides, in the one in which he/she works or in the one in which the alleged violation has occurred). The Italian Supervisory Authority is the Data Protection Authority, with registered offices in Piazza Venezia No. 11, 00187 – Rome (http://www.garanteprivacy.it/). For the United Kingdom, the supervisory authority is the Information Commissioner's Office (ICO), located at Wycliffe House, Water Lane, SK9 5AF – Wilmslow (Cheshire) (https://ico.org.uk/).

For further information on the Supervisory Authority of the User’s state of residence and on the possibility of lodging a complaint with that Authority, the User may contact the Controller using the methods indicated at the beginning of this paragraph.



The Data Controller is not responsible for updating all links viewed in this Privacy Policy, therefore, whenever a link does not work and/or is not updated, the Users acknowledge and accept that they must always refer to the document and/or section of the websites referred to by this link.

Version updated on: July 07, 2026
Should the Controller make substantial changes to this policy, the Users will be promptly notified.


    • Related Articles

    • Colorado Safety Policy Information

      This section contains relevant information regarding the safety policies and reporting procedures adopted by Iumob S.r.l. (“Data Controller” or “Controller”), in accordance with the applicable law of the State of Colorado. Please also refer to the ...
    • Privacy Policy

      This privacy policy is intended to provide all the information on the processing of personal data carried out by Iumob S.r.l. when the User browses, registers, and uses the services offered on www.yooppe.com or on the Yooppe App. Please note that, ...
    • Addendum to the CCPA Privacy Policy

      For consumers in California This section, which relates to the State of California, supplements the Privacy Policy and applies exclusively to consumers residing in California, excluding the personnel of Iumob S.r.l. (“Data Controller” or ...
    • Privacy Policy for Users Residing in Other U.S. States

      This Privacy Policy supplements the general Privacy Policy and is provided by Iumob S.r.l. (“Data Controller” or “Controller”) and applies solely to Users residing in the states of Indiana, Maryland, Nebraska, New Jersey, Texas, Tennessee, Virginia, ...
    • Cookies Policy and other tracking tools

      Dear Visitor (hereinafter, "You" or the '"User"), This Internet website www.yooppe.com (hereinafter, the "Website") and the application Yooppe (hereinafter, the “App”) are owned by the company Iumob S.r.l., having its registered office in Via ...