LEGAL

Privacy Policy

Last updated: April 2026Italian law · L. 431/1998 / GDPR

1. Data controller

The controller of your personal data is inCASA Servizi Immobiliari S.r.l. (dati societari in arrivo), P.IVA/C.F. ———, with registered office at ———, Milano, Italia, operating the website https://www.incasaimmobiliare.it.

For any question regarding this policy or the processing of your personal data you can contact us at info@incasaimmobiliare.it or by post at the address above.

2. Data we process

Depending on how you use the platform, we process the following categories of personal data, provided directly by you:

  • Identification and contact data: first and last name, email address, phone number, and identity document (carta d'identità, passport or codice fiscale).
  • Solvency and application documentation, according to your applicant profile (employed, self-employed, student or retired): payslips (buste paga), dichiarazione dei redditi, pension statements, bank statements, employment or study documentation.
  • Reservation and payment data: reserved property, amounts paid, payment references and invoicing data.
  • Account and usage data: login credentials (password stored in hashed form), language and theme preference, and the documents you choose to keep in your personal wallet.
  • Technical data: an anonymous first-party session identifier used solely for aggregated visit statistics on our own site (see section 9, Cookies).

We do not request or process special categories of data (art. 9 GDPR), and we ask you not to include such data in the documents you upload.

4. Recipients

We never sell your personal data. Your data are disclosed only to:

  • The landlord (locatore) of the property you apply for, to the extent necessary to assess your application and conclude the tenancy.
  • Banking and payment entities, to process the payments and refunds you make or receive.
  • IT and hosting service providers who support the operation of the platform (server hosting, email delivery, image hosting), acting as processors under contracts pursuant to art. 28 GDPR and only on our instructions.
  • Public authorities where a legal obligation requires it: the Agenzia delle Entrate (registration of the tenancy agreement) and other tax authorities, among others.

No other transfers of data to third parties take place without your consent, unless required by law.

5. International transfers

As a rule, our service providers process data within the European Union / European Economic Area. If a specific provider (for example, an email delivery or push notification service) processes data outside the EEA, we ensure that the transfer is covered by an adequacy decision of the European Commission or by appropriate safeguards under arts. 44 ss. GDPR, in particular the Standard Contractual Clauses approved by the Commission. You may request information about the safeguards applied by writing to info@incasaimmobiliare.it.

6. Retention periods

We keep your data only as long as necessary for each purpose:

  • Rejected applications, and pending applications that did not lead to a reservation, are automatically deleted — including the uploaded solvency documents — 90 days after their last update.
  • Data relating to confirmed reservations, tenancy contracts and invoices are kept for the limitation periods established by Italian tax and civil law (in general, 10 years under art. 2946 Codice Civile for contractual claims, and the periods set by tax law for accounting records).
  • Documents you store in your personal wallet remain available until you delete them or close your account; they are never removed by the automatic application cleanup.
  • Account data are kept while your account is active and, after closure, blocked for the period needed to meet legal responsibilities.

7. Your rights

Under the GDPR (EU 2016/679) and the Codice Privacy (D.Lgs. 196/2003, as amended by D.Lgs. 101/2018) you have the right to:

  • Access your personal data.
  • Rectify inaccurate or incomplete data.
  • Erase your data when they are no longer necessary (cancellazione).
  • Object to processing based on legitimate interest (opposizione).
  • Restrict the processing in the cases provided by law (limitazione).
  • Receive your data in a structured, machine-readable format and transmit them to another controller (portabilità).
  • Withdraw any consent given, at any time, without affecting prior processing.

To exercise these rights, write to info@incasaimmobiliare.it or to our postal address, indicating the right you wish to exercise. If we have reasonable doubts about your identity, we may ask you for a copy of your identity document solely to verify it. We will respond within one month, extendable by two further months for complex requests, as provided in art. 12 GDPR.

8. Complaints before the Garante

If you consider that the processing of your data infringes data protection law, you have the right to lodge a complaint with the Italian supervisory authority: Garante per la Protezione dei Dati Personali, Piazza Venezia 11, 00187 Roma, www.garanteprivacy.it. We would nonetheless appreciate the opportunity to resolve any concern first — you can always write to us at info@incasaimmobiliare.it.

9. Cookies

We only use first-party cookies and similar technologies, strictly limited to:

  • Essential cookies required for authentication and session management — without them you cannot log in.
  • A preference cookie that remembers your language (EN/IT) and theme choice.
  • An anonymous first-party session identifier used solely for aggregated visit statistics on our own site; it does not identify you personally and is not shared with anyone.

We do not use third-party tracking, analytics or advertising cookies, and we do not perform cross-site tracking or profiling. Because only essential and preference cookies of our own are used, no cookie consent banner from third parties is required; you can delete cookies at any time from your browser settings.

10. Security

We apply technical and organisational measures appropriate to the risk (art. 32 GDPR): the documents you upload are stored on private servers outside the public web root and can only be retrieved through time-limited, cryptographically signed (HMAC) links; access to personal data is restricted to authorised personnel who need it to provide the service; passwords are stored in hashed form; and communications with the platform are encrypted in transit. In the unlikely event of a security breach involving risk to your rights, we will notify the Garante and, where required, yourself, in accordance with arts. 33 and 34 GDPR.

11. Updates to this policy

We may update this policy when the platform, our providers or the applicable regulations change. The version in force is always published on this page; where a change is material, we will inform you through the platform or by email. Last revision: the date shown on this page.

Questions?

Our team in Milan is happy to walk you through any part of this document.

WhatsApp — we reply in < 1h