Document version: privacy-closed-test-v1
Status: Release-candidate text for CDR Apps-hosted closed testing
Effective date: 2026-09-04T20:20:13.000Z
This Privacy Policy explains how personal data is processed in connection with FuoriSerie.
1. Data controller
The data controller is CDR APPS DI RUSU COSMIN DUMITRU ("CDR Apps").
Business and legal information is available at https://cdrapps.com/legal/legal-notice.html.
Privacy enquiries and data-protection requests: [email protected]
General support: [email protected]
Formal certified email (PEC): [email protected]
2. Scope and adult-only status
This Policy applies to personal data processed through the FuoriSerie app and FuoriSerie service during the closed-testing release.
FuoriSerie is strictly for users aged 18 or older and is not directed to children.
The current eligibility step may ask for a date of birth to determine whether the user is at least 18. The date entered for that eligibility check is not stored by FuoriSerie at that stage.
3. Categories of data processed
Depending on the features used and enabled, FuoriSerie may process the following categories.
3.1 Authentication and account data
This can include:
- Firebase Authentication user identifier;
- email address;
- email-verification state;
- authentication provider information, such as email/password or Google Sign-In;
- display name or profile name returned by a federated authentication provider, where available;
- backend account status;
- account role;
- account-creation and service timestamps; and
- security or account-integrity metadata required to operate the service.
FuoriSerie requires verified email and an active account status for protected service access.
3.2 Public profile data
If you create or use a public profile, the service may process:
- opaque public profile identifier;
- public username;
- optional display name;
- optional biography;
- optional avatar URL;
- optional country code;
- optional city;
- discoverability setting; and
- profile creation/update timestamps.
Country and city are coarse location information and are included only when the user chooses to share that profile information.
3.3 Garage, vehicle and media data
FuoriSerie includes Garage-related features for vehicle records, photos, build journals, modifications and specifications.
The current architecture keeps substantial private Garage and media content local to the user's device unless a feature clearly indicates that selected information is being uploaded, synchronized, published, or otherwise processed through a cloud-backed service.
Local app data can include vehicle descriptions, photos, build-journal entries, modifications, specifications and related media.
FuoriSerie accesses photos or videos from the device only when the user deliberately invokes a supported media-selection feature. In the current Android release, these flows use the system/gallery picker for selected media; FuoriSerie does not request broad Android photo/video-library permissions and does not continuously scan the user's media library. Selected media may be copied into FuoriSerie-managed local app storage for the feature the user requested.
If a user deliberately publishes or uploads selected vehicle-related content through a cloud-backed public feature, that selected content is processed as service or User Content data under this Policy.
3.4 User-generated content and social data
Where public or social functionality is enabled, CDR Apps may process content that users submit or make available, such as:
- profile text and public vehicle-related information;
- photos, videos, posts or other published media where enabled;
- Club or Meet information where cloud-backed functionality is enabled;
- content identifiers and timestamps; and
- visibility or publication state.
The exact data processed depends on the feature actually enabled in the release.
3.5 Reports, blocks, moderation and appeals
Where safety functionality is enabled, CDR Apps may process:
- the reporting user's account identifier;
- the reported public user/profile or content identifier;
- report category and user-provided explanation;
- block relationships;
- moderation state and enforcement records;
- moderation notes where authorized;
- appeal statements;
- timestamps, revisions and operation identifiers; and
- limited audit information needed to maintain safety and integrity.
Incoming block relationships and private moderation information are not intended to be exposed publicly.
3.6 Policy-acceptance evidence
When the service requires acceptance of current policies, CDR Apps may process:
- the authenticated account identifier;
- the exact Terms version accepted;
- the exact Community Rules version accepted;
- trusted acceptance time; and
- bounded application version/build evidence.
The Privacy Policy is notice-only in this policy-acceptance system. The acceptance record is not a blanket consent to personal-data processing.
3.7 Subscription-capability data
FuoriSerie may process backend entitlement/capability state used to determine which features or limits apply to an account.
The closed-testing release does not currently provide an active paid-subscription purchase flow. Accordingly, this Policy does not describe an active FuoriSerie payment-card or purchase-processing flow.
If paid subscriptions are activated later, this Policy and the purchase disclosures will be updated before launch where required.
3.8 Security, integrity and technical data
CDR Apps may process technical information needed to authenticate requests, protect the service and prevent abuse, including:
- application and build version;
- Firebase Installation ID (FID), a per-installation identifier generated and used by Firebase services;
- Firebase App Check / Play Integrity-derived integrity results or tokens as handled by the relevant service;
- request metadata;
- technical error or security information made available through the backend infrastructure;
- operation identifiers used for idempotency or abuse prevention; and
- timestamps.
CDR Apps does not use these controls to certify a user's vehicle or real-world identity.
3.9 Support communications
If you contact CDR Apps, we process the information you provide in the communication, your contact details, and information needed to investigate and respond.
Do not send unnecessary sensitive personal information in a support request.
4. Purposes and legal bases
CDR Apps processes personal data only where a lawful basis applies.
Providing the FuoriSerie service — Article 6(1)(b) GDPR
Data necessary to create and maintain an account, authenticate the user, provide requested profile or community functions, maintain account settings, process policy acceptance, and perform requested account actions is processed as necessary to provide the service and perform the user agreement.
Security, abuse prevention and platform integrity — Article 6(1)(f) GDPR
CDR Apps has legitimate interests in protecting accounts, preventing unauthorized access, enforcing integrity controls, detecting abuse, preventing fraud, maintaining reliable operation, investigating credible reports, and protecting users and the service.
Where legitimate interests are relied upon, CDR Apps must balance those interests against the rights and freedoms of affected individuals.
Moderation, safety and enforcement — Articles 6(1)(f) and, where applicable, 6(1)(c) GDPR
Reports, blocks, moderation records, enforcement evidence and appeals may be processed to protect users, enforce the service rules, prevent abuse, establish or defend legal claims, and comply with legal duties.
Legal obligations — Article 6(1)(c) GDPR
CDR Apps may process or preserve information where necessary to comply with an applicable legal obligation, lawful authority order, accounting duty, consumer-protection duty, or other binding legal requirement.
Consent — Article 6(1)(a) GDPR, only where specifically requested
Where a future optional processing operation legally requires consent, CDR Apps will request that consent separately and allow it to be withdrawn as required by law.
Acceptance of the Terms or Community Rules is not treated as consent for unrelated optional processing.
5. Public information
Information a user deliberately makes public can be seen by other users according to the relevant feature and discoverability controls.
A public profile may expose the public username and any optional public profile information the user has chosen to provide. User-selected country and city can make a user's approximate location apparent.
Users should not publish private addresses, another person's precise live location, identification documents, financial information, private contact information belonging to another person, or other information they do not have the right to disclose.
6. Local-device processing
Private Garage and media functionality currently relies substantially on local-device storage.
Local processing can still involve personal data even when the information is not sent to CDR Apps. Users remain responsible for device security, operating-system backups, shared-device access, and deletion of local files outside CDR Apps' control.
Uninstalling the app or clearing app data can affect locally stored content. Cloud-backed account or public data must be managed through the applicable account or service controls rather than assumed to be removed merely by uninstalling the app.
7. Service providers and recipients
CDR Apps uses service providers to operate FuoriSerie. Depending on the active feature, these include Google/Firebase services used for:
- Firebase Authentication;
- Google Sign-In;
- Cloud Functions;
- Cloud Firestore;
- Firebase App Check and Android Play Integrity-related integrity protection; and
- related hosting, security and backend infrastructure.
Service providers process data under their applicable terms and data-protection arrangements.
CDR Apps may also disclose information to competent public authorities where legally required; to professional advisers where reasonably necessary for legal claims or compliance and subject to appropriate duties; or to another controller in connection with a legally valid business reorganization, subject to applicable data-protection requirements.
CDR Apps does not sell personal data.
The closed-testing release is not described as using advertising technology or personal-data profiling for behavioural advertising.
8. International data transfers
Some service providers may process data in countries outside the European Economic Area.
Where Chapter V GDPR applies, CDR Apps relies on a lawful transfer mechanism made available for the relevant processing, such as an adequacy decision, approved contractual safeguards including Standard Contractual Clauses, or another mechanism permitted by law, together with supplementary measures where required.
9. Retention
CDR Apps does not invent a single retention period for all FuoriSerie information. Different records are retained according to purpose, necessity and legal requirements.
The current retention criteria are:
- Account/authentication data: while the account is active and then for the period reasonably necessary to complete deletion, security, legal or dispute-related obligations.
- Public profile and cloud-backed User Content: until deleted by the user where available, removed through account deletion, removed by enforcement, or no longer necessary for the feature, subject to narrow legal or safety retention requirements.
- Private local Garage/media data: according to the user's device and local app-data lifecycle unless selected content is intentionally uploaded or published.
- Reports, blocks, moderation and appeal information: for as long as reasonably necessary to investigate abuse, protect users, enforce the rules, prevent repeated abuse, establish or defend legal claims, or comply with legal duties, after which data should be deleted or de-identified when no longer required.
- Policy-acceptance evidence: for as long as reasonably necessary to administer the account and demonstrate the applicable contractual acceptance, including applicable legal-claims periods.
- Security and integrity records: for as long as reasonably necessary to investigate security events, prevent abuse and protect the service.
- Support correspondence: for the time reasonably necessary to resolve the request and manage related legal or operational follow-up.
- Backups: according to technically necessary backup and recovery cycles, after which deleted data should age out unless lawful retention is required.
FuoriSerie may retain a minimal, UID-free username retirement record where necessary to prevent impersonation or unsafe username reuse. Such a record is designed not to expose the former account owner.
When a fixed retention period is legally or operationally selected for a specific record class, CDR Apps will document and apply it consistently.
10. Account deletion
FuoriSerie includes an account-deletion architecture intended to remove or de-identify account-linked service data and then remove the authentication account after required cleanup succeeds.
Deletion may cover, as applicable:
- account and entitlement records;
- policy-acceptance data;
- public-profile bindings;
- public profile data;
- public username ownership mapping; and
- other cloud-backed account-linked information included in the active deletion lifecycle.
A minimal de-identified username retirement record may remain to reduce impersonation or abusive reuse.
Deletion can be limited or delayed only where a valid reason applies, such as a binding legal obligation; establishment, exercise or defence of legal claims; a narrow safety or moderation investigation; prevention of fraud or abuse where retention is necessary and proportionate; or technically necessary backup cycles.
11. Security
CDR Apps uses technical and organizational controls appropriate to the current service architecture, including:
- authenticated backend operations;
- verified-email requirements for protected service access;
- backend-enforced account status and authority boundaries;
- Firebase App Check / Play Integrity protection for callable operations where enforced;
- strict server-side request and persistence validation;
- least-authority separation between account roles and subscription capabilities;
- fail-closed safety and policy gates; and
- transport and infrastructure security controls provided by the relevant cloud services.
No internet service can guarantee absolute security. Users should keep account credentials and devices secure.
12. Automated technical decisions
FuoriSerie uses automated technical checks for authentication, App Check/integrity validation, input validation, account-status enforcement, policy gating, duplicate-operation prevention, and other security or service controls.
These controls are intended to operate and protect the service. The current closed-testing design is not intended to make a decision based solely on automated processing that produces legal effects or similarly significant effects concerning a user within the meaning of Article 22 GDPR.
If materially different automated decision-making is introduced, CDR Apps will update the applicable notice and safeguards before activation where required.
13. Your data-protection rights
Subject to the conditions and exceptions in applicable law, you may have the right to:
- obtain confirmation whether personal data concerning you is processed and access that data;
- correct inaccurate or incomplete data;
- request deletion;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive applicable data in a portable format where the portability conditions apply;
- withdraw consent at any time where processing is based on consent, without affecting processing lawfully carried out before withdrawal; and
- receive the safeguards applicable to certain international transfers.
To exercise a right, contact [email protected]. CDR Apps may need to verify that the request relates to the correct account or person before disclosing or changing data.
You also have the right to lodge a complaint with a competent supervisory authority. In Italy, the authority is the Garante per la protezione dei dati personali.
14. Reports involving other people
A report may contain information about the reporting user, the reported user, the relevant content and the alleged conduct.
Do not include unnecessary personal information in a report. Report information is used to assess safety, Community Rules, legal and enforcement issues and is not intended to be made public.
Where revealing the reporting person's identity would be unnecessary or unsafe, CDR Apps should avoid disclosing it except where disclosure is legally required.
15. Law-enforcement and emergency requests
CDR Apps may preserve or disclose personal data when required by a valid and binding legal request or where another lawful basis applies.
CDR Apps does not provide a user with permission to engage in illegal activity and does not convert user content into CDR Apps-approved conduct merely because it appears on FuoriSerie.
Where CDR Apps becomes aware of information that triggers a mandatory reporting duty under applicable law, it may make the required report to the competent authority.
16. Changes to this Policy
CDR Apps may update this Policy when the data-processing activities, service features, processors, legal requirements, or safeguards change.
Material changes will be communicated through an appropriate channel.
A Privacy Policy update is a notice change. Where a separate processing activity requires consent or another specific user action, CDR Apps will request that action separately rather than treating general Terms acceptance as consent.
17. Contact
Data controller: CDR APPS DI RUSU COSMIN DUMITRU
Business/legal details: https://cdrapps.com/legal/legal-notice.html
Privacy: [email protected]
Support: [email protected]
PEC: [email protected]
End of privacy-closed-test-v1.