Privacy policy
Version 2026-09-23, published September 23, 2026
What this programme holds about you, why, and what you can do about it. It is short because we collect little.
Who is responsible
SAS Startup Lab, a programme of SAA School of Management at the University of Turin, decides what is collected and why. The registered entity and the contact address for data protection questions are published here before launch; until then, write to the programme address on the site and it will reach the same people.
What is collected
Your name and email, so there is an account and a way to reach you. If you enrol: your nationality, whether you are a student, your university and field of study — used for cohort reporting and turned into anonymous aggregates after twelve months. Which evenings you attended. A phone number only if you choose to give one. If you join a team: what your mentor writes about you, and the scores the final-day panel gives your team. Nothing in a special category under Article 9 is collected, and the form states a minimum age of eighteen.
Why it is allowed
Your account and everything needed to run the programme rest on the contract between you and the programme — Article 6(1)(b). Reporting on cohort composition rests on legitimate interest, with the balancing reasoning written down. Certificates rest on legitimate interest too: a credential nobody can check is not a credential. Marketing email rests on your consent alone, asked separately and never bundled with anything else.
Who else sees it
Four companies, each under a data-processing agreement and each configured to an EU region: Supabase holds the database, Vercel runs the site, Hostinger sends the email, and Sentry receives error reports with names, emails and request bodies stripped out before they leave. Nobody else. Your certificate is different by design: anyone you give the code to can verify it, and they see your name, the programme and the dates, and nothing more.
How long it is kept
Three years after the last cohort you took part in, for your account, your attendance and your team records. Twelve months for reporting fields, after which they become aggregates that identify nobody. Twelve months for email delivery logs. Twenty-four months for the security audit log. Consent records for three years after the consent ends, because that is the proof that it was given. Certificates are kept indefinitely and deliberately — see below.
What you can do
Download everything held about you from your account, as a single file, whenever you like. Correct what is wrong by editing it directly. Ask for erasure, and choose what happens to a certificate you earned: revoked and erased with everything else, or kept in minimal form — your name, the programme, the dates and the code — so it still verifies. Withdraw a consent in one click. Object to a use. Every request is logged with its date, so the one-month legal deadline is provable. You may also complain to the Garante per la protezione dei dati personali.
How it is protected
Every table enforces who may read each row inside the database, not only in the pages, and an automated suite checks that by asking as four different people. The session cookie cannot be read by any script. The rules that matter — checking in, issuing a certificate, booking a mentor, recording a score — are enforced by the database, so a request that skips the interface is held to the same rule.
When this changes
The version above changes with it. If a change alters what you agreed to, you are asked again rather than assumed to agree; consents you gave stay attached to the version of this text that was on the screen when you gave them.
Getting in touch
Write to the programme, and say what you want to do — see your data, correct it, delete it, or object. If you write from an address the programme does not recognise, you will be asked to confirm it first: answering an unverified request would itself be a breach.