← Documenti legali

Privacy Policy

CONSOO S.R.L.S. — hice

Edition: English master (international)

Last updated: 29 July 2026


1. Introduction and scope

1.1 This Privacy Policy (hereinafter the «Policy») is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (hereinafter the «GDPR») and to Legislative Decree 196/2003 as amended (hereinafter the «Privacy Code»).

1.2 This Policy describes how CONSOO S.R.L.S. (hereinafter «hice», the «Provider», «we») processes Personal Data in its capacity as Data Controller, in relation to:

  • the Users and Authorized Users who access the Service;
  • the Customers (companies and self-employed professionals) who subscribe to the Service, with reference to the data of the natural persons who serve as contact, administration and billing persons;
  • visitors to the website https://hice.ai and to the web application https://app.hice.ai;
  • prospective customers (leads) who contact us or request information.

1.3 What hice is. hice is a multi-tenant SaaS platform for Professional Services Automation (PSA) with an AI assistant, natively in Italian, aimed at IT consulting and services firms operating on a Time & Materials basis and at self-employed professionals. It is accessible via the web at the address app.hice.ai and through the mobile applications for iOS (App Store) and Android (Google Play).

1.4 Service offered only to professional parties (B2B). hice is offered exclusively to companies and to VAT-registered professionals acting in the exercise of their business; it is not aimed at consumers. The processing of Users' data — that is, of the natural persons (owners, employees, collaborators) who access the Service on the Customer's behalf — takes place in that professional context and within the contractual relationship between hice and the Customer.

1.5 Scope: only the data for which hice is Controller. This Policy concerns exclusively the processing in which hice acts as Controller. For Customer Data — that is, the data, including the personal data of third parties (candidates, employees, consultants, contacts, the content of synchronized email and calendar), that the Customer or the Users enter, upload or generate in the Service — hice acts as Data Processor on the Customer's behalf, the Customer being the Controller. The rules governing such processing are set out in the DPA (dpa-trattamento-dati.md). See §3.

1.6 Terms with an initial capital letter not defined in this Policy have the meaning given to them in the General Terms of Service (condizioni-generali-servizio.md).


2. Data Controller and contacts

2.1 The Data Controller is:

FieldValue
Company nameCONSOO S.R.L.S.
FormSimplified limited liability company
Registered officePiazzetta Umberto Giordano 2, 20122 Milan (MI), Italy
VAT / Tax codeIT13823860963
REAMI-2745733
Certified email (PEC)consoo@pec.it
Contact emailinfo@hice.ai
Privacy emailinfo@hice.ai
Web servicehttps://app.hice.ai
Websitehttps://hice.ai

2.2 Data Protection Officer (DPO). hice assessed the criteria under Article 37 GDPR and did not appoint a DPO, as the mandatory-appointment requirements are not met given the nature, scope and purposes of its processing activities. The point of contact for privacy matters is the address info@hice.ai.

2.3 How to contact us. For any request relating to the processing of Personal Data and to exercise the rights referred to in §11, you may write to info@hice.ai.


3. Privacy roles: Controller and Processor

3.1 hice operates with a dual role, which it is essential to distinguish.

3.2 hice is the Data Controller (Article 4(7) GDPR) — and this Policy governs this — for:

  • the User's registration and identity data (name, email, credentials);
  • the Customer's billing and payment data;
  • security logs, technical audits, product diagnostics and telemetry data;
  • support communications;
  • lead/marketing data collected on the website.

3.3 hice is the Data Processor (Article 28 GDPR), on behalf of the Customer acting as Controller, for all Customer Data uploaded or generated in the use of the Service, including the personal data of third parties (candidates, employees, consultants, contacts, the content of synchronized email and calendar). This processing is not the subject of this Policy: it is governed by the DPA (dpa-trattamento-dati.md), an integral part of the Terms.

3.4 The Customer is the Controller of its own Customer Data. The Customer warrants that it has a legal basis for uploading such data and for having hice process it (for example, the consents and notices provided to candidates and employees).

3.5 Practical consequence for the data subject. If you are an Authorized User who is an employee or collaborator of a Customer, or a candidate/contact whose data has been entered into the Service by a Customer, and you wish to exercise your rights over that data, you must turn first of all to your organization (the Customer as Controller). hice, as Processor, will provide that organization with the assistance set out in the DPA. For the data of which hice is Controller (for example, the data of your Account), you may instead contact us directly.


4. Categories of Personal Data processed

In its capacity as Controller, hice processes the following categories of data. We do not intentionally request or process special categories of personal data (Article 9 GDPR) for the purposes for which hice is Controller.

4.1 User registration and identity data. First name, last name, email address, business role, organization (Tenant) of affiliation, language preferences and profile settings.

4.2 Credentials and authentication data. Password (stored in encrypted form by means of a hash function), session tokens and access identifiers. Upon your activation, any sign-in integrations.

4.3 Customer billing and payment data. Company name or first and last name, address, VAT number / tax code, SDI recipient code or PEC for electronic invoicing, subscription data, history of payments and invoices. The card or payment instrument data is processed directly by the payment processing service provider: hice does not store full card numbers.

4.4 Security logs, technical audits and diagnostics. IP address, device identifier and type, operating system, application logs, log of accesses and of events relevant to security (audit log), diagnostic and error data necessary for the operation and protection of the Service.

4.5 Product telemetry. Data on use of and interaction with the Service (usage events, features used, technical identifiers), processed in masked form where possible, in order to measure and improve the operation of the Service. Collection by means of cookies and similar technologies is governed by the Cookie Policy (see §8).

4.6 Support communications. The content of support requests, correspondence with our team, and the data necessary to handle and respond to them.

4.7 Lead and marketing data. Data that you provide to us spontaneously by contacting us or requesting information (name, email, company, message), as well as any data collected through contact forms on the website.

4.8 Push notifications (mobile app). If you enable them, a notification token associated with your device, used exclusively to send you alerts relating to the Service.

4.9 Mobile application permissions. The mobile app may request certain device permissions, all optional and activated only when you use the corresponding feature; you may revoke them at any time from the operating system settings:

  • Microphone and speech recognition: to dictate messages to the chat. The audio is used for transcription and is not retained as an audio file.
  • Camera and photos: to take or attach receipts, invoices and documents (e.g., capture and automatic reading of expense reports). We access only the images that you choose to attach.
  • Notifications: to alert you to deadlines, approvals, messages and Service events.
  • Secure storage: the access token is stored in encrypted form in the protected area of the device (Keychain / Keystore), so that you stay authenticated without re-entering your credentials at each launch.

Note: the images, receipts and documents that you upload into the Service normally constitute Customer Data (see §3 and the DPA).


5. Purposes of processing and legal bases

For each category of processing we indicate the purpose and the corresponding legal basis pursuant to Article 6 GDPR.

#PurposeCategories of dataLegal basis
5.1Creation and management of the Account and provision of the Service and its features to the Authorized UserRegistration and identity (4.1); credentials (4.2)Performance of the contract (Art. 6.1.b) — or pre-contractual measures. For a User who is an employee of the Customer: legitimate interest (Art. 6.1.f) of hice and of the Customer in delivering the Service within the contractual relationship with the Customer
5.2Management of the relationship with the Customer, billing and paymentsBilling and payment (4.3)Performance of the contract (Art. 6.1.b) for the relationship; legal obligation (Art. 6.1.c) for tax, accounting and electronic-invoicing obligations
5.3Security, prevention of abuse and fraud, continuity of the Service, diagnostics and resolution of malfunctionsLogs and audit (4.4); diagnosticsLegitimate interest (Art. 6.1.f) in ensuring the security, integrity and continuity of the Service and in preventing unlawful uses
5.4Improvement and analysis of the product (usage statistics, performance measurement)Product telemetry (4.5)Legitimate interest (Art. 6.1.f) in improving the Service; where collection takes place through non-necessary cookies/tools, consent (Art. 6.1.a) in accordance with the Cookie Policy (§8)
5.5Assistance and support to the User and the CustomerSupport communications (4.6)Performance of the contract (Art. 6.1.b); legitimate interest (Art. 6.1.f) in providing effective support
5.6Compliance with legal obligations (accounting, tax, retention, requests from authorities)All relevant categoriesLegal obligation (Art. 6.1.c)
5.7Sending service communications (technical and security notices, contractual or Policy changes)Registration and identity (4.1)Performance of the contract (Art. 6.1.b); legal obligation (Art. 6.1.c) where applicable
5.8Push notifications on the mobile deviceNotification token (4.8)Consent / explicit activation by the User (Art. 6.1.a); revocable from the operating system settings
5.9Optional features activated by the User (e.g., «BYO» email and calendar integrations)Data necessary for the activated featureConsent / explicit activation (Art. 6.1.a). Note: synchronized content normally constitutes Customer Data (see §3 and the DPA)
5.10Management of leads and direct marketing towards prospective customers who contact us; possible newsletterLead and marketing (4.7)Consent (Art. 6.1.a) for promotional communications; legitimate interest (Art. 6.1.f) for responding to a contact request and, within the limits of Article 130(4) of the Privacy Code, for communications about services similar to those purchased by existing customers (soft spam) with the possibility to object
5.11Establishment, exercise or defense of a legal claim in courtRelevant categoriesLegitimate interest (Art. 6.1.f)

5.12 Legitimate interest balancing. When we process data on the basis of legitimate interest, we have carried out a balancing assessment between that interest and the rights and freedoms of the data subjects. You may request further information on that assessment using the contacts referred to in §2 and you have the right to object to the processing (see §11).

5.13 Provision of data. The provision of the data indicated as necessary for registration, for the performance of the contract and for legal obligations is mandatory: failure to provide it prevents the creation of the Account or the use of the Service. The provision of data for consent-based purposes is optional and refusal does not affect use of the Service (save for the optional features to which the consent relates).


6. AI Features

6.1 The Service includes AI Features (conversational chat assistant, candidate↔opportunity matching, CV parsing, OCR of receipts and invoices). When you interact with the chat, the text of your messages and the context necessary to respond are processed by artificial intelligence models hosted on the Service's infrastructure or at the processing service provider for the AI Features (see §9 and §10).

6.2 No training on Customer Data. hice does not use Customer Data to train foundation AI models. The data processed by the AI Features is used to generate the response and for the operation of the related features; it is not transferred to third parties for advertising purposes nor used to train third-party models.

6.3 Human oversight (HITL). Write actions suggested by the AI require human confirmation before being executed (human-in-the-loop).

6.4 Transparency and automated decisions. For the detailed description of the AI Features, of the models and providers used, of the limitations of the systems (possible errors and «hallucinations»), of the processing of data in recruiting and of the rules on automated decision-making, please refer to the AI and Algorithmic Transparency Notice (informativa-ai-trasparenza.md). See also §12.


7. Methods of processing

7.1 The data is processed using electronic and automated tools, and to a residual extent on paper, with logic related to the purposes referred to in §5 and with measures suitable to ensure its security and confidentiality.

7.2 The processing is carried out by authorized and instructed personnel of hice and by the providers (Processors and Sub-processors) indicated in §9, bound by confidentiality obligations and by contracts compliant with Article 28 GDPR.

7.3 The security measures adopted include: encryption of data in transit (TLS/HTTPS) and encryption at rest of sensitive data (PII via AES-256-GCM, encrypted OAuth integration tokens); strict isolation between organizations (multi-tenant architecture with Row Level Security); role-based access control according to the principle of least privilege; logging of security events (audit log); backups for continuity purposes. The detailed technical and organizational measures relating to Customer Data are described in the Annex to the DPA (dpa-trattamento-dati.md).


8. Cookies and similar technologies

8.1 The website and the web application use cookies and similar technologies. Technical/necessary cookies are used for the operation of the Service and of authentication; analytics/product cookies (attributable to the product analytics service provider in the category indicated in §9) are used, where consent is provided, to measure use of the Service.

8.2 Product analytics and session replay. The product analytics tool includes a session replay feature, which reconstructs the interaction with the interface for improvement, security and diagnostic purposes. The recording takes place with masking of all text and input fields and does not capture personal data (PII). The legal basis is your consent (Art. 6.1.a GDPR and ePrivacy rules): in the absence of consent, product analytics and session replay are disabled. The management and withdrawal of consent are described in the Cookie Policy (cookie-policy.md), to which reference is made.

8.3 The complete rules — categories, purposes, legal bases, durations, itemized list of tools and how to manage and withdraw consent — are set out in the Cookie Policy (cookie-policy.md), to which reference is made.


9. Recipients, Processors and Sub-processors

9.1 We do not sell your Personal Data. The data may be disclosed or made accessible to the following categories of recipients:

  • authorized personnel of hice (system administrators, support, administration);
  • providers acting as Data Processors (Article 28 GDPR), bound by contract and limited to the purposes indicated;
  • professionals and advisors (e.g., accountant, lawyers) and competent authorities, where required by law or necessary for the establishment, exercise or defense of a legal claim.

9.2 Categories of Sub-processors. hice relies on external providers acting as Sub-processors, described below by functional category (without indication of the individual providers or tools). The list of names is maintained for internal use and may be made available on request within applicable limits.

Functional categoryService providedCategories of data processedLocation
Cloud infrastructure, hosting, database, authentication, storageDelivery and storage of the ServiceAccount data, application data, files, logs, backupsEuropean Union / EEA
Payment processingManagement of subscriptions and paymentsPayment data, Customer billing dataEuropean Union / EEA, or with adequate safeguards
Sending of transactional emailInvitations, password resets, service notificationsRecipient's email and name, content of the transactional messageEuropean Union / EEA
Product analytics and diagnosticsImprovement, security and diagnosticsUsage events, technical identifiers, masked interaction dataEuropean Union / EEA
Push notifications (optional, opt-in)Notifications on the mobile appDevice token, notification metadataEuropean Union / EEA, or with adequate safeguards
Processing for the AI FeaturesInference of the artificial intelligence modelsPrompt text (may contain personal data: CV text, chat content)European Union / EEA, or with adequate safeguards
Email and calendar integrations chosen by the Customer («BYO»)Synchronization activated by the Customer with its own credentialsCalendar events, email metadataDetermined by the provider chosen by the Customer

9.3 Location and transfers. The cloud services and servers used to deliver the Service are located in the reference region of this edition (European Union / European Economic Area). Should a processing operation exceptionally require a transfer outside that region, it is carried out by adopting adequate safeguards in accordance with applicable law (for the EU edition: Chapter V of the GDPR — Standard Contractual Clauses or an adequacy decision). See §10.

9.4 «BYO» integrations (email/calendar). The email and calendar integrations are activated by the Customer with its own credentials at the provider it has chosen: the related processing takes place in the Customer's environment, for which the Customer is responsible as controller.

9.5 Local processing on the infrastructure. The OCR and document-compression tools are software components executed locally on the Service's infrastructure, without disclosure to external providers.

9.6 The list of Sub-processors that process Customer Data, as well as the arrangements for notifying changes and the Customer's right to object, are governed by the DPA (dpa-trattamento-dati.md).

9.7 Google Workspace data (Gmail and Google Calendar)

When a User connects a Google account, hice accesses only the data required for the requested features through the gmail.send and/or calendar.events.owned OAuth scopes:

  • for Gmail: the sender account identity and the recipients, subject, and content of new emails that the User chooses to send;
  • for Google Calendar: title, description, date and time, attendees, location, meeting links and event status.

This data is used only to let the User send new emails and view, create, update, or delete events. OAuth tokens are encrypted. HICE does not read or synchronize the Gmail mailbox, sent mail, drafts, labels, or trash. Calendar events are stored and synchronized within the Service. Outputs that the User chooses to generate through the AI chat may remain in chat history under the applicable retention periods.

Google data retention and deletion. HICE does not create a copy of the Gmail mailbox; disconnecting Google Mail deletes its OAuth tokens and stops new email delivery. Disconnecting Calendar immediately deletes the OAuth tokens and stops synchronization; previously imported events remain in the Service as an operational history until the User or Customer deletes them. When the Account or contract ends, remaining Google data in active systems is deleted or anonymized within 30 days, except where law, security or the establishment or defense of legal claims requires longer retention.

AI sharing. Only when the User intentionally invokes an AI feature on Mail or Calendar are the prompt and the minimum Google data necessary transmitted to a third-party LLM API provider, through a dedicated API environment, solely to generate the requested response. Google Workspace data is not sent to any other AI provider, sold, used for advertising or credit profiling, or used to train general-purpose models. HICE does not opt in to voluntary data sharing for model training. The selected provider may retain abuse-monitoring logs for up to 30 days under its business/API terms.

The use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.


10. Transfers of data to non-EEA countries

10.1 The cloud services and servers used to deliver the Service are located in the European Union / European Economic Area (EEA). The data resides in that region and, as a rule, is not transferred outside it.

10.2 Should a processing operation exceptionally require a transfer outside the EEA, it is carried out in compliance with Chapter V of the GDPR, on the basis of one or more of the following safeguards:

  • an adequacy decision of the European Commission, where applicable;
  • Standard Contractual Clauses (SCCs) adopted by the European Commission, supplemented by additional measures where necessary.

10.3 You may request information on the safeguards applied and, where provided, a copy of them, by writing to the contacts referred to in §2.


11. Retention periods

11.1 hice retains Personal Data for the time strictly necessary for the purposes for which it is collected and in compliance with legal obligations, according to the following criteria.

CategoryRetention criterion
Account and identity data (4.1, 4.2)For the entire duration of the contractual relationship; after termination, deletion or anonymization within 30 days, save for defensive needs or legal obligations
Billing and payment data (4.3)10 years from registration, in compliance with civil-law and tax obligations (Article 2220 of the Italian Civil Code and tax legislation)
Security and audit logs (4.4)For the time necessary for security and diagnostic purposes, as a rule 12 months, save for further retention in the event of incidents or for the establishment/defense of a legal claim
Product telemetry (4.5)For the time necessary for the analysis and improvement of the Service, for a maximum of 12 months, in aggregated or pseudonymized form where possible
Support communications (4.6)For the time necessary to handle the request and for 24 months thereafter, for service-quality and legal-defense purposes
Lead and marketing data (4.7)Until consent is withdrawn or an objection is raised and in any case no later than 24 months from the last contact
Push notification token (4.8)As long as the feature remains active or until the app is uninstalled / the permission is revoked

11.2 Retention of candidate data (recruiting). The candidate data entered into the Service constitutes Customer Data (hice is Processor; see §3). The Service applies differentiated retention periods by country, running from the date the candidate is entered: 24 months for the EU/EEA, 12 months for the United Kingdom, 24 months as a prudential default for other countries. The definition of the purposes and of the time limits vis-à-vis candidates remains with the Customer as Controller; the rules are set out in the DPA (dpa-trattamento-dati.md) and in the Customer notice templates (modelli-informative-cliente.md).

11.3 Once the indicated periods have elapsed, the data is deleted or rendered anonymous, save for legal retention obligations or needs relating to the establishment, exercise or defense of a legal claim.


12. Automated decision-making and profiling

12.1 hice does not take decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect data subjects, for the processing of which hice is Controller.

12.2 The Service's AI Features — in particular candidate matching — constitute an aid to human decision-making and do not decide autonomously. When the Customer uses them as part of recruitment processes, it is the Customer (Controller and employer/decision-maker) that must ensure human oversight, inform the candidates and guarantee the rights to human intervention, to express their point of view and to contest the decision.

12.3 For the complete rules on algorithmic transparency, on Article 22 GDPR and on the obligations of Regulation (EU) 2024/1689 (EU AI Act), please refer to the AI and Algorithmic Transparency Notice (informativa-ai-trasparenza.md).


13. Data subject rights

13.1 In relation to the data of which hice is Controller, you have the right to exercise, within the limits and under the conditions set out in Articles 15–22 GDPR:

  • access to your data (Article 15);
  • rectification of inaccurate or incomplete data (Article 16);
  • erasure of data («right to be forgotten», Article 17);
  • restriction of processing (Article 18);
  • portability of the data that you have provided to us, in a structured, machine-readable format (Article 20);
  • objection to processing based on legitimate interest, on grounds relating to your particular situation, and at any time to processing for direct marketing purposes (Article 21);
  • withdrawal of consent at any time, for processing based on consent, without prejudice to the lawfulness of the processing carried out before the withdrawal (Article 7.3).

13.2 How to exercise your rights. You may exercise your rights by writing to info@hice.ai. We will respond without undue delay and in any case within one month, which may be extended by two months in cases of particular complexity (Article 12 GDPR). We may ask you for information necessary to verify your identity.

13.3 Complaint to the supervisory authority. You have the right to lodge a complaint with the competent supervisory authority. In Italy this is the Garante per la protezione dei dati personali (the Garante) (Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it), without prejudice to any other administrative or judicial remedy (Articles 77–79 GDPR).

13.4 Data processed by hice as Processor. If your data is processed by hice as Processor on behalf of a Customer acting as Controller (the Customer Data, §3), address your request first of all to your organization. hice will provide that organization with the assistance set out in the DPA in order to respond to your requests.


14. Minors

14.1 hice is a professional tool and is not intended for minors under 16 years of age. We do not knowingly collect Personal Data of minors for the processing of which we are Controller. Should we become aware of the inadvertent processing of a minor's data, we will delete it without undue delay.


15. Updates to this Policy

15.1 This Policy may be updated over time, for example due to changes in legislation, in providers or in the features of the Service. In the event of material changes we will give notice through the Service or by email. The date of the last update is indicated at the top of the document.

15.2 It is the responsibility of the data subject and of the Customer to review the version in force periodically.


16. References and related documents

  • DPA — Data Processing Agreement (dpa-trattamento-dati.md): for Customer Data, where hice is Processor.
  • AI and Algorithmic Transparency Notice (informativa-ai-trasparenza.md): for the AI Features and automated decisions.
  • Cookie Policy (cookie-policy.md): for cookies and similar technologies.
  • General Terms of Service (condizioni-generali-servizio.md): for the contractual relationship and the definitions.