DOCUMENT VERSION · 0.9.1
How Mytem processes data.
Notice under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and applicable Italian law.
Contact address: Via Orto Limoni 7 - Catania
Privacy contact: developer@mytem.app
Support contact: support@mytem.app
Effective date: 2026-07-26
1. Scope of this notice
This notice describes personal-data processing through the Mytem app, its backend services, restricted back office, mytem.app website, support pages and service email channels. Mytem helps users organise the life cycle of belongings: records, purchase evidence, warranties, maintenance, manuals, recalls, transfers and user-initiated intelligent features.
Records are stored locally on the device by default. A cloud copy is created only when the user enables it for an individual record and chooses which attachments to include.
2. Data we process
- Account data: display name, email address, verification status, derived password value, language preference, account status, roles and sessions.
- Operational and security data: logins, technical identifiers, audit events, notifications, tickets, deletion requests, user-to-user transfers and information required to prevent abuse.
- Credits and digital purchases: balance, ledger entries, purchased product, transaction status, receipt identifiers and store-account references. Mytem does not receive or store full card numbers or payment credentials.
- Item records: brand, model, serial number when entered, purchase, warranty, maintenance, notes, history, manuals, recalls, valuations and service centres.
- User-selected content: photos, labels, receipts, invoices, PDFs, selected purchase-email text and other documents. Mytem does not automatically access the entire device or mailbox.
- Location: coordinates or locality only when the user authorises a nearby-service-centre search. Location is not used for advertising, profiling or continuous tracking.
- Communications: ticket content, service emails and requests sent to support or privacy contacts.
- Website: technical data strictly required to deliver and protect the page. In its current configuration, the website uses no non-essential cookies, behavioural advertising or profiling tools.
3. Purposes and legal bases
- Create, verify and manage the account; synchronise balance, notifications, tickets and transfers; provide requested features: performance of a contract or pre-contractual steps.
- Send verification codes, password-recovery messages, essential communications and security notices: contract performance and the controller’s legitimate interest in service security and continuity.
- Process selected photos, documents or text through user-requested intelligent features: performance of the selected function. The credit cost and data involved are shown before it starts.
- Create and manage optional cloud copies: performance of the feature expressly requested by the user.
- Prevent fraud, abuse, unauthorised access, disputes and incidents: the controller’s legitimate interest, balanced against user rights.
- Manage payments, tax and accounting duties, authority requests or legal claims: legal obligation or legitimate interest, as applicable.
4. Intelligent features and human review
Mytem Intelligence features run only when requested. Selected content may be resized or minimised and transmitted to the Mytem backend and the technology provider required for processing. The output is a proposal to review: it is not a manufacturer certification, appraisal, warranty, official recall or professional advice.
Mytem does not make solely automated decisions producing legal or similarly significant effects on the user. Before saving, the user may correct or reject proposed data. Official sources must be checked for safety, maintenance, recalls and warranties.
5. Manuals, external sources and links
When Mytem identifies a relevant HTTPS link, the app shows the link, source category and check date. The external website remains under its operator’s responsibility. Mytem applies technical checks to exclude local addresses, embedded credentials and manifestly unsuitable sources, but cannot guarantee the future availability, currency or security of every external page.
6. Device permissions
Camera, photos, documents, notifications and location permissions are requested in context. Refusal does not block general use of the app, but the specific feature requiring that permission will not be available. Mytem does not require microphone access for the described features.
7. Cloud copies and unnecessary data
Before upload, users may exclude attachments, serial numbers and prices. Users should not upload passwords, payment codes, identity documents, health information, children’s data or unnecessary third-party information. Mytem is not designed to collect special-category data. User review reduces risk but does not exclude the controller’s legal obligations.
8. Transfers between users
An internal transfer creates an offer reserved for the registered recipient. The record moves only after acceptance. Attachments and information marked private are excluded unless expressly selected. Transfer events and status are recorded for security, support and reconstruction of the operation.
9. Purchases, credits and subscriptions
Digital purchases are processed by Apple App Store or Google Play. Mytem receives the information needed to verify the purchased entitlement, prevent duplication, update the balance and handle support or refunds. Prices, taxes, renewal and payment methods are displayed and managed by the store. Credits are a balance, not a fixed number of operations: each feature displays its cost before confirmation.
10. Recipients and service providers
Authorised people and selected providers may process data only as necessary. Main categories include Aruba for infrastructure, domains and email; AI-processing providers for requested operations; Apple and Google for distribution, operating-system services, notifications and purchases; advisers and authorities where required. Privacy roles depend on the actual service and are governed through the instruments required by law.
Mytem does not sell personal data or share it for third-party behavioural advertising.
11. Transfers outside the EEA
Some providers may process data outside the European Economic Area. Where applicable, mechanisms under Articles 44 et seq. GDPR are used, including adequacy decisions, standard contractual clauses and supplementary measures, according to the provider and actual processing.
12. Retention
- Email-verification codes: normally 15 minutes; password-recovery codes: normally 30 minutes.
- Sessions: normally up to 14 days, unless revoked following logout, password changes, administrative reset or a security measure.
- Temporary intelligent-capture assets: deleted after completion, cancellation or technical expiry, ordinarily within 10 minutes.
- Cloud copies and attachments: until the individual copy or account is deleted.
- Accounts, tickets, transfers and operational data: for the relationship and afterwards only as needed for deletion, duties, disputes or legal claims.
- Tax and accounting data: for the period required by applicable law.
- Security and audit logs: according to minimisation and rotation criteria; records required for investigations, abuse prevention or legal defence may be retained for a further proportionate period.
Backups are protected, not used for ordinary purposes and overwritten through the rotation cycle. Final removal from backups may require completion of that cycle.
13. Security
Measures include HTTPS, scrypt-derived passwords, revocable sessions, role-based access control, rate limiting, audit trails, encryption of cloud copies and configuration secrets, controlled backups and separation of code, runtime and credentials. No measure removes every risk; controls and procedures are updated as the service evolves.
14. Children
Mytem is not directed to children and does not allow independent account creation below the minimum age stated during registration and required by applicable law. The controller may request verification and remove accounts created in breach of that requirement.
15. Rights and complaints
Data subjects may request access, rectification, erasure, restriction, portability, objection and withdrawal of consent where applicable by writing to developer@mytem.app. They may also lodge a complaint with the Italian Data Protection Authority or their competent supervisory authority. Account deletion is available in the app and through the public deletion page.
16. Updates
Material changes are communicated by proportionate means, such as an in-app notice, service email or renewed acknowledgement. The version and effective date identify the applicable text.