Data Controller Identification
City Green Light S.p.A. is identified as the data controller with contact details provided.
🌐 citygreenlight.com
Lists data categories and retention periods, but lacks detail on security measures, data sharing, and sensitive data handling.
Cites GDPR, outlines user rights, and provides contact for requests, but lacks specifics on international transfers and data breach procedures.
Reserves right to modify policy unilaterally and requires user to cease use if they disagree, which is one-sided.
Uses tables for clarity but contains legal jargon and poor formatting, making it difficult to read.
The legal basis "Consenso dell'interessato" is used for all data processing purposes, including contacting the user via the website form and for analytics cookies. This is overly broad and likely non-compliant. Contacting a user who initiates contact is typically based on legitimate interest or contract performance, not consent. Using consent for strictly necessary functions can invalidate the consent mechanism.
The retention period for basic contact data (name, surname, email) collected via the website contact form is listed as 10 years. This period is excessively long and not proportionate for the stated purpose of "contacting the user." No justification is provided for this duration.
The policy lists Google Analytics cookies (_ga, _gat, _gid) with the purpose "Contattare l'utente" (Contact the user). This is factually incorrect. The purpose of analytics cookies is to analyze website usage, not to contact the user. The stated purpose does not match the actual function of the cookies.
For the CITYGREENAPP, the legal basis for processing registration data (including password) is listed as "Consenso dell'interessato" for the purpose of "Inoltro di segnalazioni e ricezione di notifiche di aggiornamento." Processing necessary for the performance of an app service contract is typically based on Article 6(1)(b) GDPR (contract), not consent. Using consent here is problematic.
The policy states that for the "MODULO ADESIONE COMUNITÀ ENERGETICA," the purpose includes "Inoltro di comunicazioni e informative su iniziative commerciali e di marketing" based on consent. Bundling consent for marketing with consent for the core service (energy community verification) is not allowed under GDPR. Consent must be separate and specific.
For the "PORTALE FORTHINK," the policy states data is kept "per l’intera durata del contratto e successivamente al massimo per 6 mesi." This is vague. It does not specify if the 6-month period starts after contract termination or after the last interaction, creating ambiguity.
The policy mentions that the company may access information from the energy distributor ("Distributore") using a delegation from the user for verification in the energy community module. The legal mechanism and safeguards for this third-party data access are not explained.
The document references "Reg. UE 2016/679" but uses the Italian phrase "Global Data Protection Regulation" which is an incorrect translation of "General Data Protection Regulation." This shows a lack of attention to detail.
The "Ultima modifica" date is 15.10.2020. This policy is likely outdated, as it has not been updated for over three years, during which time regulatory guidance and practices have evolved.
The policy states the user is responsible for third-party data shared and guarantees the right to communicate it, freeing the Data Controller from liability. While common, such clauses cannot absolve the controller of its due diligence obligations under GDPR to ensure lawful processing of all data it handles.
The contact email in the header is info@citygreenlight.com, while the privacy contact email in the body is privacy@citygreenlight.com. This inconsistency is minor but could cause confusion.
The document structure is highly fragmented with excessive and inconsistent HTML/formatting tags, making it difficult to read and potentially indicating a lack of professional presentation.
City Green Light S.p.A. is identified as the data controller with contact details provided.
Website collects contact data, cookies, and usage data. App collects registration and contact data.
Users have rights to access, rectify, delete, port data, object, and lodge complaints with authorities.
Collects detailed personal data including tax code, address, and ID copy for energy community verification.
Controller reserves right to modify policy; users must review changes or cease using services.
Install the free Termzy AI browser extension and get instant AI-powered analysis of any legal document you encounter online.
Add Termzy AI to the Browser - It's Free