⚗️ EVIDE GOVERNANCE LAB  |  Adaptive Evidentiary Governance Research  |  No legal or evidentiary value  |  EVIDE Canonical →
Privacy

Privacy Notice

EVIDE Governance Lab — lab.certifywebcontent.com
Information on personal data processing pursuant to EU Regulation 2016/679 (GDPR).

Version 1.2.3  ·  Effective 21 September 2026  ·  Language: English (governing version)
This is an informative notice, not a contract: it explains how personal data is processed and does not itself require your signature or acceptance. See the Terms of Use & Governance Lab Procedure (version 1.2.3) for the procedure that references this notice. Updates to this document do not alter agreements already executed (see Section 12).

1. Data Controller

Informatica in Azienda — Dott. Emanuel Celano
Via Vaccaro 5, 40132 Bologna, Italy — VAT IT02137271207
Email: info@certifywebcontent.com

2. Nature of the Processing Context

The EVIDE Governance Lab is an experimental research environment. Personal data processed through the Lab is used exclusively for governance architecture research purposes. Some processing activities may additionally fall within the research safeguards of GDPR Art. 89 — see Section 5, which explains what that does and does not mean, rather than treating it as a general basis for processing (see Section 4 for the actual legal bases).

3. Data Collected

CategoryDataPurpose
Registration data First name, last name, email address, WhatsApp number, professional domain, job role, motivation statement Identity verification, access management, research context qualification
Administrative communication WhatsApp number and messages exchanged through it Guiding the participant through the Governance Lab Procedure, receiving step confirmations and the signed Mutual NDA — see Section 6
Identity verification document Copy of a valid personal ID document — only when a participant signs the Mutual NDA by hand (not requested for a qualified or advanced electronic signature) Verifying the identity of a participant who signs the Mutual NDA by hand — see the detail below
Access credentials Lab Code (unique pseudonymous identifier), session data Authentication, quota management, API access control
Research activity data Intake session UUIDs, governance payload hashes, timestamps, API call logs, buffer event logs Research record, governance architecture validation, evidentiary lifecycle documentation
Technical data IP address, browser type, access timestamps Platform security, abuse prevention

Personal data is not used for commercial profiling or advertising and is processed only for the purposes described in this Notice, including registration, administration, security and research activities.

Identity verification document — detail. This document is requested only for the handwritten-signature path of the Mutual NDA (Terms of Use, Section 5, Option 2); it is not requested for a qualified or advanced electronic signature.
  • Purpose: solely to verify that the person signing the NDA by hand is who they claim to be.
  • Access: only the Lab administrator (Dott. Emanuel Celano) accesses this document. It is handled manually, outside the Lab's application database, and is not part of the intake pipeline or any other automated system.
  • Redaction: you may redact non-essential fields on the document (photograph, unrelated ID numbers) before sending it, as long as your name and signature remain legible and verifiable.
  • Retention: kept only as long as needed to verify the countersigned NDA, then deleted.
  • Erasure: you may request earlier deletion at any time — see Section 8 (Data Subject Rights); this document is not subject to the research-record retention described in Section 7.

4. Legal Basis

  • Art. 6(1)(b) GDPR — steps taken at the participant's request and, following approval, performance of the Lab access arrangement.
  • Art. 6(1)(f) GDPR — legitimate interest of the controller in platform security and abuse prevention.

GDPR Art. 89 is not, by itself, an independent legal basis for processing — it is a framework of additional safeguards and conditions that can apply to processing already grounded in Art. 6, where that processing is for research purposes. See Section 5.

5. Research Safeguards (Art. 89 GDPR)

Where specific processing within the Lab is for scientific/research purposes and is grounded in one of the legal bases in Section 4, GDPR Art. 89 may additionally apply appropriate safeguards to that processing. This is assessed per processing activity, not assumed across the board, and it does not by itself remove or limit any data subject right.

The one place this becomes concrete in this notice is the possible, case-by-case limitation on erasure/objection for certain research activity records described in Section 8 (Data Subject Rights) and Section 7 (Data Retention) — Art. 89 does not justify any other limitation beyond that.

6. WhatsApp as an Administrative Channel

The WhatsApp number collected at registration is used exclusively as the Lab's administrative communication channel: to verify the participant's contact, to guide the participant from one Governance Lab Procedure step to the next, to receive step confirmations, and to receive and return the Mutual NDA. It is not used for marketing.

WhatsApp is a service operated by Meta Platforms. Messages exchanged through it are subject to WhatsApp's own terms and privacy policy, independently of this Lab, and may be processed on infrastructure located outside Italy — see Section 10 (Data Transfers).

7. Data Retention

  • Registration / account data (name, email, WhatsApp number): retained for the duration of active Lab access. Following termination of access, removal or anonymization is carried out manually by the Lab administrator; there is currently no automated process that performs this on a fixed schedule (see Section 9).
  • Identity verification document (handwritten NDA signature only): see the detail in Section 3 — kept only until the NDA is verified, then deleted, and erasable on request at any time.
  • Participant Materials and intake data exchanged as part of registration or an experiment: retention is governed by the applicable Experimental Scope, by the Mutual NDA where one has been executed, and by the legal basis engaged for that specific data — not by a single blanket rule. A deletion request concerning this data is evaluated case by case against those factors and against the research-integrity considerations in Section 8, rather than refused automatically.
  • Genuinely non-personal technical/integrity records (opaque session hashes, UUIDs, and timestamps that carry no personal content by themselves) may be retained separately as part of the Lab's forensic observation history, independently of what happens to any associated personal data.
  • Technical access data: application-level log files are automatically deleted after 30 days by a scheduled process. Other technical records stored in the database in connection with registration or API activity (such as IP addresses) are retained as part of the platform's operational records; they are not currently subject to an automated deletion schedule and are removed manually where applicable.

8. Data Subject Rights

As a data subject under GDPR, you have the following rights:

  • Right of access to your personal data (Art. 15)
  • Right to rectification of inaccurate data (Art. 16)
  • Right to erasure (Art. 17)
  • Right to restriction of processing (Art. 18)
  • Right to object to processing (Art. 21)
  • Right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, www.gpdp.it)

To exercise your rights, write to: info@certifywebcontent.com. Requests are reviewed and handled manually. We may ask you to verify your identity before acting on a request. You will receive a response within the timeframe required by applicable law. There is no general, automatic refusal of erasure requests: each request is evaluated on its own facts.

The one specific, narrower exception: the right to erasure and the right to object may, depending on the circumstances, be limited with respect to research activity records (intake sessions, buffer event logs, evidentiary hashes) where erasure would render the research dataset incomplete or compromise its forensic integrity. Any such limitation is considered case by case under GDPR Art. 17(3)(d) and Art. 89(2) (see Section 5); it is not applied as an automatic, blanket exception, it does not apply to the identity verification document described in Section 3, and it does not affect your other rights or your right to complain to the Garante.

9. Account Termination and Data

Account termination — whether requested by the researcher or decided unilaterally by the Lab administrator — results in the immediate deactivation of access credentials. Removal or anonymization of registration data (name, email, WhatsApp number) is then handled manually by the Lab administrator; there is no automated process that deletes this data on a fixed schedule after termination.

Participant Materials, intake data, and research activity records are handled as described in Section 7, consistently with whatever Experimental Scope or NDA governed them — account termination by itself does not trigger their automatic deletion, but it also does not by itself block a case-by-case erasure request under Section 8.

10. Data Transfers

Personal data is primarily stored and processed on servers located in Italy (Aruba S.p.A., Italian datacenter), and the Lab's own email is sent through the same Italian infrastructure.

Two categories of third-party service are integrated into the Lab and may involve data being processed outside Italy, independently of the Lab's own infrastructure:

  • Google reCAPTCHA and Google Fonts (Google LLC) — used on the registration form and for page typography. These may involve limited technical data, such as your IP address, being processed on Google's own infrastructure, under Google's own data protection terms.
  • WhatsApp (Meta Platforms) — used as the administrative channel described in Section 6. Messages you send through it are handled under WhatsApp's own terms and privacy policy, independently of the Lab.

Outside of these two integrations, and except where otherwise required by law, intake data, evidentiary profiles, and other research data are not transferred outside Italy in the ordinary operation of the Lab.

11. Cookies

The Lab itself sets only technically necessary cookies:

  • Session cookie (evidelab_session): manages authentication. Duration: session.
  • Language cookie (lang): stores selected language. Duration: 30 days.

No analytics, advertising, or tracking cookies are set by the Lab. The registration form embeds Google reCAPTCHA for spam prevention, which may set its own cookies under Google's own cookie policy; this is outside the Lab's control.

12. Changes to This Notice

This notice may be updated at any time. The current version, its version number, and its effective date are always available at this URL. A later version is not retroactively applied to a confirmation of this notice already given under an earlier version — see Section 12 of the Terms of Use for the corresponding non-retroactivity provision.

Data Controller: Informatica in Azienda — Dott. Emanuel Celano
Via Vaccaro 5, 40132 Bologna, Italia — P.IVA IT02137271207
Email: info@certifywebcontent.com
Supervisory Authority: Garante per la Protezione dei Dati Personali