Privacy
Privacy policy
Last updated: 30 September 2026
BizFi is the social Wi-Fi and digital menu service of Biztems SRL. This policy explains which personal data we process, why, on what legal basis, for how long, and what your rights are.
It covers visitors to this website, people who ask us for a demo, customer venues and the people who use the dashboard and, for our part, the guests who join the Wi-Fi of a venue that uses BizFi. This is a translation: if it differs from the Italian version, the Italian version prevails.
1. Who we are
The data controller is Biztems SRL:
- registered office: Via Sarajevo, 13 – 84014 Nocera Inferiore (SA), Italy;
- operational office: Via Giovanni Porzio, 4 – Isola A/2, Centro Direzionale – 80143 Naples (NA), Italy;
- VAT number IT04857960654;
- email info@biztems.it, phone +39 081 196 42 686.
We have appointed a Data Protection Officer (DPO), whom you can reach at privacy@biztems.it with any question about this policy and to exercise your rights.
2. Our role: controller or processor
In BizFi we have two different roles, depending on who you are.
- We are the controller of the data of visitors to this website, of people who ask us for a demo, and of customers and the people who use the BizFi dashboard (sections 3, 4 and 5).
- We are a processor (Art. 28 GDPR) of the data of guests who join a venue’s Wi-Fi through the BizFi portal or browse its digital menu. For these data the controller is the venue: the venue decides which data to collect and what they are for, and we process them only on its behalf and on its instructions (section 6).
If you are a guest, the privacy notice that applies to you is the venue’s, and it is the venue you can turn to for your rights. If you write to us, we forward your request to the venue and help it answer you.
3. Visitors to this website
Data: IP address, date and time of the request, the page requested and the referring page, browser and operating system type, and the outcome of the request. They are logged automatically by the systems of Netlify, the provider that hosts the website, for every page you visit.
Why: to run the website, keep it secure and detect abuse and faults. We do not use these data to identify or profile you.
Legal basis: our legitimate interest in offering a working, secure website (Art. 6(1)(f) GDPR).
How long: as long as needed for these purposes and in any case no longer than 12 months, unless they are needed to establish offences against the website.
Cookies: this website uses no cookies or other tracking tools, contains no analytics or advertising tools, and loads nothing from other websites (even the fonts are hosted by us). That is why we do not ask for your consent.
4. People who ask us for a demo
Data: what you enter in the form — name, venue name, email and, if you give them, phone, city, number of venues, whether you already use a UniFi network and your message — plus the language of the page you write from.
Why: to answer your request, arrange the demo and, if you ask, prepare an offer.
Legal basis: your request, that is, pre-contractual steps taken at your request (Art. 6(1)(b) GDPR). The required fields are the ones we need to answer you: without them, we can’t.
How long: 12 months from the last contact if no contract follows; if you become a customer, the periods in section 5 apply.
Who receives them: the request reaches us by email. The BizFi app, hosted by Netlify, forwards it through Amazon Simple Email Service to the Biztems inbox, where the people who handle it read it. We keep it nowhere else. We do not use these data to send you marketing.
5. Customers and dashboard users
This section concerns the venues that use BizFi and the people who sign in to the dashboard (app.bizfi.it): owners, invited team members and contract contacts.
Data:
- account data: name, email, role (admin or manager) and the venues you can access;
- your password, which we store only in a non-reversible encrypted form (a hash);
- technical data about sign-in sessions: IP address and browser type;
- for the contract contact, the data needed for the contract, invoicing and payments.
Why, and on what basis:
- to provide the service, manage accounts and give support: performance of the contract (Art. 6(1)(b) GDPR); for team members invited by a customer, our legitimate interest in providing the service the customer asked for (Art. 6(1)(f) GDPR);
- to protect accounts and the service from unauthorised access and abuse: legitimate interest (Art. 6(1)(f) GDPR);
- to meet tax and accounting obligations: legal obligation (Art. 6(1)(c) GDPR).
Service emails: the invitation to create your account and the link to reset your password come from no-reply@bizfi.it, sent through Amazon Simple Email Service. The link is valid for 24 hours.
Dashboard cookies: the dashboard uses only technical cookies, needed to keep you signed in and to remember the language you chose. They require no consent (Art. 122 of the Italian Privacy Code).
How long: account data for the duration of the relationship and until the account is closed; contract and invoicing data for the 10 years after the relationship ends, as the law requires (Art. 2220 of the Italian Civil Code).
6. Venue guests: the data we process on behalf of venues
When you join the Wi-Fi of a venue that uses BizFi, the portal you see is the venue’s: the controller of your data is the venue, and we process them on its behalf, as a processor. This is what happens to your data on our systems.
Which data
- The form data: first name, last name, phone, email, date of birth and city. The venue decides which of these to ask for, and which to make required.
- Your consent choices: your acceptance of the Wi-Fi terms of use and of the venue’s privacy notice, and the optional consents to marketing and statistics, each with the date and the version of the text you saw.
- Device and connection data: your device’s MAC address, your IP address, the browser, operating system and device type, language, time zone and screen size, and the access point and Wi-Fi network you join.
- Connection history: the date and time of each connection, how long Wi-Fi was granted for, and the button you chose (for example the menu or one of the venue’s social pages).
What they are for
- Getting you online: the portal passes your device’s MAC address to the venue’s UniFi network system, which lets it online for the time the venue has chosen. We send the network system no name, phone number or email.
- Recognising you when you come back, to greet you by name and spare you the form.
- Showing you the venue’s digital menu, in your language.
- The venue’s marketing, only if you consent: BizFi sends you no marketing. The venue sees guests’ contacts and their consent choices in the dashboard, and can export them to use, with its own tools and under its own responsibility, those of guests who consented.
- Meta and Google tools, only if you consent and only if the venue has turned them on: with marketing consent the confirmation page can load the venue’s Meta Pixel; with statistics consent, the venue’s Google Analytics 4. Without consent nothing is loaded. Meta and Google receive these data under their own privacy policies.
Technical storage on your device
The portal keeps how far you have got, and what you have typed in, in your browser’s session storage, which is cleared when you close the window: that way a page that reloads doesn’t make you start again. The menu page may store its files in the browser cache to load faster.
How long
The venue chooses the period, between 30 days and 10 years (365 days unless it changes it). Every day we automatically delete connections older than that period and the data of guests who haven’t been back for as long. If you ask the venue to delete you, it does so from the dashboard: your data and your consents are deleted at once and the device is made anonymous, while the technical log of past connections, no longer linked to you, stays until the retention period runs out.
Your rights
Contact the venue, which is the controller. If you write to privacy@biztems.it, we forward your request to the venue and help it act on it.
7. Who processes data on our behalf
Besides authorised Biztems staff, data are processed by providers we have appointed as processors (or, for guest data, sub-processors), bound by contract to confidentiality and security:
| Provider | What it does | Where |
|---|---|---|
| Netlify, Inc. | Hosts this website and the BizFi app, which forwards demo form requests | App functions in Frankfurt (Germany); pages served from a worldwide server network; company based in the United States |
| Neon, Inc. | The app’s database | Frankfurt (Germany), on Amazon Web Services; company based in the United States |
| Amazon Web Services EMEA SARL | Storage of logos and menu images, sending of service emails and demo requests, the server that directs guests to the portal | Ireland |
When a venue connects its UniFi network through Ubiquiti’s cloud service, the device’s MAC address and the access duration pass through Ubiquiti Inc. (United States), the provider of the venue’s network system, to reach the venue’s network.
We disclose data to others only when the law requires it, for example to public authorities, or to advisers bound to confidentiality.
8. Transfers outside the European Union
The app’s data are stored in the European Union: the database in Frankfurt, files and emails in Ireland. Some providers, however, are based, or use group companies, outside the European Economic Area, mostly in the United States. In those cases data are transferred only with the safeguards the GDPR provides for (Art. 44 onwards):
- to US companies certified under the EU-US Data Privacy Framework, on the basis of the European Commission’s adequacy decision of 10 July 2023 (Implementing Decision (EU) 2023/1795), for as long as it remains in force;
- otherwise, and as an additional safeguard, on the basis of the standard contractual clauses approved by the European Commission (Implementing Decision (EU) 2021/914).
You can ask for a copy of these safeguards by writing to privacy@biztems.it.
9. How long we keep data
| Data | How long |
|---|---|
| Website browsing data | Up to 12 months |
| Demo requests | 12 months from the last contact, if no contract follows |
| Dashboard accounts | For the duration of the relationship, until the account is closed |
| Contract and invoicing data | The duration of the relationship and the 10 years after |
| Guest data (on behalf of venues) | The period the venue chooses, between 30 days and 10 years (365 days unless it changes it): each connection from its date, the guest’s data from their last visit. Deleted automatically every day |
When the period ends we delete the data or make them anonymous, unless they are needed to establish, exercise or defend legal claims.
10. Your rights
You have the right to ask us for access to your data, for their rectification or erasure, for restriction of processing and for the portability of the data you gave us (Arts. 15–20 GDPR). Where processing is based on your consent, you can withdraw it at any time, without affecting what was done before.
Your right to object (Art. 21 GDPR). You can object at any time, on grounds relating to your particular situation, to processing based on our legitimate interest.
How to exercise them: write to our DPO at privacy@biztems.it, or to info@biztems.it. We reply within one month, which can be extended by two months for complex requests, in which case we tell you (Art. 12 GDPR). To protect your data we may ask you to confirm your identity. If you are a venue’s guest, see section 6.
Complaints: if you believe the processing breaches the law, you can lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it), or with the supervisory authority of the EU country where you live or work, or go to court (Arts. 77 and 79 GDPR).
We make no decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).
11. Security
We protect data with appropriate technical and organisational measures: encrypted connections (HTTPS), dashboard access with personal credentials and roles that limit what each person sees, passwords stored only in a non-reversible encrypted form, the keys to venues’ networks encrypted in the database, and infrastructure in the European Union. If a personal data breach occurs, we handle and notify it as Arts. 33 and 34 GDPR require.
12. Changes to this policy
We may update this policy when the service or the law changes. The date at the top of the page shows the latest change; if the changes are significant, we also tell customers by email.