Privacy Policy

City Green Light's Privacy Policy Analysed

🌐 citygreenlight.com

City Green Light is an Italian company that manages public lighting and smart city services, focusing on energy efficiency and sustainability.
AI-Powered Analysis
Last analyzed March 30, 2026 11:07
View Original Privacy Policy
63
Moderate Score

Overall Rating: 63/100

Based on analysis of data protection, legal compliance, transparency, and fairness

65

User Data Protection

Lists data categories and retention periods, but lacks detail on security measures, data sharing, and sensitive data handling.

70

Legal Compliance

Cites GDPR, outlines user rights, and provides contact for requests, but lacks specifics on international transfers and data breach procedures.

55

Balance & Fairness

Reserves right to modify policy unilaterally and requires user to cease use if they disagree, which is one-sided.

60

Transparency & Readability

Uses tables for clarity but contains legal jargon and poor formatting, making it difficult to read.

AI Summary

The legal basis "Consenso dell'interessato" is used for all data processing purposes, including contacting the user via the website form and for analytics cookies. This is overly broad and likely non-compliant. Contacting a user who initiates contact is typically based on legitimate interest or contract performance, not consent. Using consent for strictly necessary functions can invalidate the consent mechanism.

The retention period for basic contact data (name, surname, email) collected via the website contact form is listed as 10 years. This period is excessively long and not proportionate for the stated purpose of "contacting the user." No justification is provided for this duration.

The policy lists Google Analytics cookies (_ga, _gat, _gid) with the purpose "Contattare l'utente" (Contact the user). This is factually incorrect. The purpose of analytics cookies is to analyze website usage, not to contact the user. The stated purpose does not match the actual function of the cookies.

For the CITYGREENAPP, the legal basis for processing registration data (including password) is listed as "Consenso dell'interessato" for the purpose of "Inoltro di segnalazioni e ricezione di notifiche di aggiornamento." Processing necessary for the performance of an app service contract is typically based on Article 6(1)(b) GDPR (contract), not consent. Using consent here is problematic.

The policy states that for the "MODULO ADESIONE COMUNITÀ ENERGETICA," the purpose includes "Inoltro di comunicazioni e informative su iniziative commerciali e di marketing" based on consent. Bundling consent for marketing with consent for the core service (energy community verification) is not allowed under GDPR. Consent must be separate and specific.

For the "PORTALE FORTHINK," the policy states data is kept "per l’intera durata del contratto e successivamente al massimo per 6 mesi." This is vague. It does not specify if the 6-month period starts after contract termination or after the last interaction, creating ambiguity.

The policy mentions that the company may access information from the energy distributor ("Distributore") using a delegation from the user for verification in the energy community module. The legal mechanism and safeguards for this third-party data access are not explained.

The document references "Reg. UE 2016/679" but uses the Italian phrase "Global Data Protection Regulation" which is an incorrect translation of "General Data Protection Regulation." This shows a lack of attention to detail.

The "Ultima modifica" date is 15.10.2020. This policy is likely outdated, as it has not been updated for over three years, during which time regulatory guidance and practices have evolved.

The policy states the user is responsible for third-party data shared and guarantees the right to communicate it, freeing the Data Controller from liability. While common, such clauses cannot absolve the controller of its due diligence obligations under GDPR to ensure lawful processing of all data it handles.

The contact email in the header is info@citygreenlight.com, while the privacy contact email in the body is privacy@citygreenlight.com. This inconsistency is minor but could cause confusion.

The document structure is highly fragmented with excessive and inconsistent HTML/formatting tags, making it difficult to read and potentially indicating a lack of professional presentation.

📋 Key Clauses Analyzed

Data Controller Identification

City Green Light S.p.A. is identified as the data controller with contact details provided.

Types of Data Collected

Website collects contact data, cookies, and usage data. App collects registration and contact data.

Data Subject Rights

Users have rights to access, rectify, delete, port data, object, and lodge complaints with authorities.

Energy Community Module Data

Collects detailed personal data including tax code, address, and ID copy for energy community verification.

Policy Modification Rights

Controller reserves right to modify policy; users must review changes or cease using services.

❓ Questions About This Privacy Policy

✨ AI Enhanced Answers
Generating AI response
The summary indicates that using consent for all processing purposes, including contacting users who initiate contact and for strictly necessary functions, is overly broad and likely non-compliant. For example, contacting a user who initiates contact is typically based on legitimate interest or contract performance, not consent. Using consent for necessary functions can invalidate the consent mechanism.
Generating AI response
The summary states that the retention period of 10 years is excessively long and not proportionate for the stated purpose of 'contacting the user.' No justification is provided for this duration, which violates the principle of storage limitation under GDPR.
Generating AI response
The policy lists Google Analytics cookies (_ga, _gat, _gid) with the purpose 'Contattare l'utente' (Contact the user), which is factually incorrect. The actual purpose of analytics cookies is to analyze website usage, not to contact users. This mismatch between stated purpose and actual function is misleading.
For the CITYGREENAPP, the legal basis for processing registration data (including password) is listed as consent for the purpose of 'Inoltro di segnalazioni e ricezione di notifiche di aggiornamento.' However, processing necessary for the performance of an app service contract is typically based on Article 6(1)(b) GDPR (contract), not consent. Using consent here is problematic because it may not be freely given if required for the service.
The policy states that for the 'MODULO ADESIONE COMUNITÀ ENERGETICA,' the purpose includes 'Inoltro di comunicazioni e informative su iniziative commerciali e di marketing' based on consent. Bundling consent for marketing with consent for the core service (energy community verification) is not allowed under GDPR. Consent must be separate and specific for each purpose.

Never blindly click "agree" again

Install the free Termzy AI browser extension and get instant AI-powered analysis of any legal document you encounter online.

Add Termzy AI to the Browser - It's Free
🎉

Thank You for Using Termzy AI!

You're getting the full experience with complete policy analysis, all clauses unlocked, and unlimited FAQ access.