⚠ DRAFT — This document is a draft and has no legal value.
For legal purposes, only the Italian version (tos_privacy_it.md) is authoritative.
PRIVACY POLICY — DCmove
(Privacy Policy — pursuant to EU Regulation 2016/679 — GDPR)
Version 2.0 — draft — 2026
1. DATA CONTROLLER
Dervet s.r.l. Via Trescore 32/a 26020 Palazzo Pignano (CR) — Italy VAT: IT01433620190 E-mail: privacy@dervet.com Phone: +39 0373 386450 Website: https://www.dervet.com
2. SCOPE OF THIS POLICY
This policy describes how Dervet collects, uses, stores and protects the personal data of users who register and use the DCmove platform, comprising:
- The DCmove mobile app for Android and iOS;
- The cloud backend at
be.dcmove.cloud; - Bluetooth (BLE) communication between the app and physical devices.
The platform enables remote control, configuration and monitoring of IoT devices (industrial door operators, sliding and roller shutter systems) manufactured or distributed by Dervet.
3. CATEGORIES OF PERSONAL DATA PROCESSED
3.1 Data provided at registration
When creating an account, the following data is collected: - First and last name - E-mail address - Username - Password (stored in encrypted, non-readable form)
3.2 Data relating to registered devices
For each device registered on the platform: - Serial number and MAC address (technical identifiers) - Name, location and description assigned by the user - Installed firmware version - Operational status, errors, diagnostic data - Open/close cycle counter and wear data - Estimated next maintenance date - Technical service contact details, if entered by the user - Custom logo, if uploaded by the user
3.3 Log and diagnostic data
Device operation automatically generates: - System logs (device status text messages) - Door event logs (open, close, errors, with timestamps and event codes) - MQTT messages (IoT communication protocol, stored temporarily) - Diagnostic snapshots of the device's electrical inputs/outputs
This data is purely technical and does not contain personal information other than the association with the device registered by the user.
3.4 Support request data
If the user submits a support request via the app: - Title and description of the reported issue - Automatic device diagnostic data - Door event log at the time of the report - Up to 3 photographs attached by the user
3.5 Technical connection data
During use of the Service, the following is processed automatically: - IP address of the user's device - Session token - Bluetooth hardware identifier of the physical device (BLE local configuration only)
3.6 Data NOT collected
The platform does not collect: - GPS location data - Phone number (not required by the app registration process) - Special category data (health, biometric, political, etc.) under Art. 9 GDPR - Data relating to minors - Data for advertising or commercial profiling purposes
4. PURPOSES AND LEGAL BASIS FOR PROCESSING
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Creating and managing the user account | Performance of contract — Art. 6(1)(b) |
| Providing the service | Performance of contract — Art. 6(1)(b) |
| Authentication and access security | Contract / legitimate interest — Art. 6(1)(b)(f) |
| Sending service e-mails | Performance of contract — Art. 6(1)(b) |
| Technical support request management | Performance of contract — Art. 6(1)(b) |
| Firmware updates (OTA and BLE) | Performance of contract — Art. 6(1)(b) |
| Retention of functional logs for fault diagnosis | Legitimate interest of the Controller — Art. 6(1)(f) |
| Compliance with legal obligations | Legal obligation — Art. 6(1)(c) |
The Controller does not carry out automated decision-making or profiling under Art. 22 GDPR.
5. RECIPIENTS OF DATA
Personal data is neither sold nor transferred to third parties.
The entire platform infrastructure is managed directly by Dervet on its own hardware located in Italy. No third-party cloud services are used.
Data may be disclosed exclusively to: - Dervet's authorised technical and administrative staff - Public authorities, in case of legal obligation or judicial order
6. TRANSFER OF DATA OUTSIDE THE EUROPEAN UNION
Personal data is not transferred outside the European Union. All data is stored and processed on servers located in Italy, managed directly by Dervet.
7. RETENTION PERIODS
| Data category | Retention period |
|---|---|
| Active account data | Duration of the contract + 10 years (fiscal/legal obligations) |
| Cancelled account data | Immediate anonymisation of personal data |
| Device system logs | 12 months from generation |
| Door event logs | 12 months from generation |
| MQTT messages | 90 days from generation |
| Support tickets + attachments | 3 years from ticket closure |
| OTP PIN for password reset | Maximum 1 hour from generation |
| Session tokens | Invalidated at logout or after 30 days of inactivity |
8. RIGHTS OF THE DATA SUBJECT
As a data subject under Arts. 15–22 GDPR, the user has the right to:
- Access (Art. 15): obtain confirmation of processing and a copy of personal data
- Rectification (Art. 16): request correction of inaccurate or incomplete data
- Erasure (Art. 17): request deletion of personal data
- Restriction (Art. 18): request that processing be restricted
- Data portability (Art. 20): receive data in a structured, machine-readable format
- Objection (Art. 21): object to processing based on legitimate interest
To exercise rights, contact:
E-mail: privacy@dervet.com Post: Dervet s.r.l., Via Trescore 32/a, 26020 Palazzo Pignano (CR), Italy
The Controller will respond within 30 days.
The data subject also has the right to lodge a complaint with the relevant supervisory authority.
9. DATA SECURITY
Dervet implements appropriate technical and organisational measures, including:
- Encrypted data transmission (HTTPS/TLS)
- Bluetooth communication encryption (AES-128)
- Passwords stored as irreversible hash (PBKDF2)
- Role-based access control (Administrator, Manufacturer, Installer, User)
- Session token authentication
- Infrastructure entirely managed by Dervet, without cloud intermediaries
10. MINORS
The DCmove Service is intended exclusively for persons aged 18 or over. Dervet does not knowingly collect personal data of minors.
11. UPDATES TO THIS POLICY
This policy may be updated following regulatory or service changes. Registered users will be informed of significant changes via e-mail or in-app notification.
Version 2.0 — draft — 2026