← Back Home

Privacy and GDPR

PERSONLIS — version 1.0 of 10 August 2026

This notice is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree No. 196/2003, as amended by Legislative Decree No. 101/2018 (Privacy Code).

1. Who processes your data

Data controllerLAPOFEIMH DI PEGNA FABIO LUIGI — Via Castellaro 25, 47843 Misano Adriatico (RN), Italy — VAT No. 04776290407
To exercise your rightslegal@personlis.com
To report abuselegal@personlis.com

No Data Protection Officer has been appointed because the conditions in Article 37 GDPR do not apply. If they become applicable, the officer's name will be published on this page.

2. What PERSONLIS is, briefly

PERSONLIS allows a living person to build their own digital avatar while alive, using a photograph and a recording of their voice, and to decide in advance what should happen to that avatar after their death.

The service is for adults only. You register while alive and on your own behalf. Creating an avatar from another person's face or voice without their documented consent, as described in section 6, is not permitted.

3. What data we collect and where it goes

DateSourceStorage location
Email address and passwordyou, when registeringFirebase Authentication
Name, language, preferencesyou, through your profileFirestore users/{uid}
Photograph of the face used for the avataryou, when creating your avatarStorage content_photos/{uid}/avatar.jpg
Voice recording lasting ten to twenty secondsyou, when creating your avatarStorage content_videos/{uid}/voce.m4a
Avatar references and voice languagegenerated by the systemFirestore avatar/{uid}
Dated copy of each consent given or withdrawngenerated by the systemFirestore consensi/{uid}/versioni
Photo and voice choices and withdrawals, with date, version, language and accepted textsgenerated by the user’s choicesFirestore consensiAvatar/{uid}/eventi
Content of conversations with the avataryou, during callsFirestore ricordi/{uid}/voci
Personal archive: texts, photos, videos, documentsyou, through the archive sectionFirestore legacy/{uid}/oggetti and Storage
People you authorise after your deathyou, through the post-mortem directiveFirestore eredi/{uid}/persone
Technical data: device model, app version, errorscollected automaticallyFirebase
Payments, subscriptions and balanceData supplied by you and Stripe and generated by the serviceStripe and Firestore: customer, subscription and payment identifiers, plan, status, periods, remaining credit and usage data. We use these to provide the service, account for credit and handle support, withdrawal and refunds. Full card details are handled by Stripe.
Administrative and legal correspondenceYou and other people contacting usAruba mailboxes; withdrawal requests and their outcomes are also recorded in Firestore, with identification data, declaration, date, period and relevant balance.

3.1 An important clarification about the archive

The personal archive of texts and materials stays in Firebase and is not sent to the avatar engine through the archive workflow. The engine does use the avatar photo and voice, questionnaire answers and relevant memories, session content and camera images sent on request. Providers involved are described in section 7.

4. Photo and voice: personal data and consent

Facial photographs and voice recordings are personal data. Using them to create and animate an avatar or generate a synthetic voice does not automatically constitute processing of biometric data under Article 9 GDPR. The definition in Article 4(14) concerns data resulting from specific technical processing that allows or confirms unique identification; for biometric data, Article 9 applies when processing is intended to uniquely identify a natural person.

We require separate consents to create and use the avatar and synthetic voice under Articles 6(1)(a) and 7 GDPR, using the checkboxes described in Avatar Consent. Where processing falls within Article 9, explicit consent under paragraph 2(a), or another applicable condition provided by that Article, is also required.

5. Why we process your data and on what legal basis

PurposeLegal basisIf you decline
Create and manage your accountperformance of the contract, Article 6(1)(b)the service cannot be used
Store your personal archiveperformance of the contract, Article 6(1)(b)you cannot use the archive
Build your avatar from your photographconsent, Article 6(1)(a); where applicable, explicit consent, Article 9(2)(a)no avatar; the rest of the service remains unchanged
Create a synthetic voice that imitates yoursconsent, Article 6(1)(a); where applicable, explicit consent, Article 9(2)(a)no voice; the rest of the service remains unchanged
Process your words to generate repliesconsent, Article 6(1)(a)the avatar cannot hold conversations
Apply your post-mortem directiveconsent, Article 6(1)(a), and Article 2-terdecies of the Italian Privacy Codethe closure rule in section 9 applies
Verify that the face and voice are yourslegal obligation and legitimate interest in preventing crime, Articles 6(1)(c) and 6(1)(f)the avatar is not delivered
Security, abuse prevention, diagnosticslegitimate interest, Article 6(1)(f)
Tax and accounting compliancelegal obligation, Article 6(1)(c)
Managing designated people’s dataLegitimate interest in managing the designation, Article 6(1)(f), subject to assessing and documenting the balance with the individuals’ rightsDesignated people may exercise their rights, including the right to object

Each consent is freely given, specific, informed and withdrawable at any time without having to give a reason. Withdrawal does not affect the lawfulness of earlier processing. Each consent and withdrawal is recorded with the date, time and version of the text you read.

5.1 Questionnaire: health, religion and politics

Every answer is optional. We request explicit consent under Articles 6(1)(a) and 9(2)(a) GDPR to store information about health, religious beliefs and political opinions in memories and use it to personalise the avatar’s replies. The box beside “Fill in” is initially unticked; selecting its wording opens the full text. Without consent, fields in the three groups cannot be edited and display “Consent missing”. Unticking the box withdraws consent and replaces those groups’ answers with that wording through the questionnaire’s save function. Other questions remain available. Choices and withdrawals are recorded with the server date and time and a version identifier that also specifies language and consent status; the version identifies the text presented.

6. The face and voice must be yours

Before photos and voice are used for the avatar, PERSONLIS requests a declaration of ownership or permission and two separate consents. Boxes are not preselected for anyone who has not yet made a choice.

Choices are linked to the account and recorded with server date and time, version, language and displayed wording. New choices do not replace previous records. A declaration by someone uploading another person’s material does not replace that person’s consent: the uploader must hold demonstrable permission for this use.

A consent video, advance submission of documents or a fixed 24-hour wait are not generally required. If a use is disputed, we may request evidence of permission and consider suspending the disputed use.

Read the details

If photo or voice consent is withdrawn, the controller stops using the affected material and manually deletes it without undue delay. Withdrawal does not delete the account or affect the lawfulness of previous processing.

7. Who we share your data with

We do not sell your data or use it for advertising. We use the following providers to deliver the service; their roles depend on the processing performed.

ProviderProcessing and role
Google — Firebase / Google CloudAccounts and storage of profiles, answers, materials, consents and administrative data. Applicable terms depend on the Firebase service; Firestore, Authentication, Storage and Functions fall under Google Cloud terms. Location depends on the service and settings: not all processing is restricted to the EU.
ModalRunning the avatar engine: photos, voice, questionnaire answers and session content. Compute is configured in a European region; this does not exclude processing outside the EU. Modal documentation states, among other things, that application logs are stored in the United States.
GroqAudio transcription, reply generation and analysis of camera images sent on request. It also receives necessary context, which may include questionnaire answers and memories. Inference content is normally not retained; reliability and abuse monitoring may require retention for up to 30 days, unless longer retention is legally required. This limit does not apply uniformly to metadata and other features. Retention options depend on account settings.
StripePayments and subscriptions. Stripe acts as a processor for some operations and as an independent controller for others, including legal obligations and fraud prevention.
ArubaEmail hosting and support and legal correspondence, including withdrawal requests, receipts, consent withdrawals and post-mortem directives. It processes addresses, message contents and any attachments sent.

Data may also be disclosed to accounting and legal professionals and to authorities as provided by law.

7.1 Transfers outside the European Union

Services may involve transfers outside the European Economic Area, including to the United States. Standard agreements published by Groq, Modal, Google and Stripe provide transfer mechanisms such as standard contractual clauses and, where applicable, adequacy decisions. Availability of these agreements alone does not establish individual account settings or mean that all data stays in Europe. Information about applicable safeguards can be requested at legal@personlis.com.

8. How long we retain data

DateRetention
Account, profile, archivewhile your account is active
Photograph and voice recordingUntil withdrawal of consent or account deletion; following withdrawal, manual deletion without undue delay as described in section 6.
Conversationsuntil consent is withdrawn or the account is deleted
Temporary files on the computer animating the avatarEnding a call does not guarantee immediate deletion of all temporary files. Removal depends on the execution environment and cleanup procedures; provider logs follow separate conditions.
Declaration and consent registerWithin 60 days after the processing to which the consent evidence relates has ended.
Tax documentsTen years from the last entry for accounting documents subject to this obligation, under Article 2220 of the Italian Civil Code.
Technical security logsOperational records managed by the controller follow the period below; provider logs follow their respective conditions described in section 7.
Balance data and operational recordsDeletion within 60 days after account closure and completion of any pending payments or refunds.
Withdrawal requests and related correspondenceDeletion within 60 days after the case is concluded, except documents required for accounting obligations.

Account deletion starts removal of the profile, photo, voice, memories, archive and authorised-person list. This does not mean immediate deletion of all engine temporary files or provider logs. Consent records, administrative and payment data, balance and withdrawal requests may remain: closing the account does not automatically delete them.

The controller manually applies these deletion periods. In a concrete dispute, only necessary data are retained until it is resolved. These periods form the controller’s adopted retention procedure; they do not imply automatic system deletion.

Files deleted from Firebase Storage remain recoverable for 7 days through the provider’s soft-delete feature. This period starts when the file is deleted, not when the user submits a request.

9. What happens after your death

The GDPR does not apply to deceased persons' data (Recital 27), but Article 2-terdecies of the Italian Privacy Code provides that the rights under Articles 15 to 22 GDPR relating to a deceased person's data may be exercised by anyone with an interest of their own, anyone acting as the data subject's representative, or for family reasons deserving protection.

This is why we ask you, while alive, to write a post-mortem directive. The full rules are in the dedicated document: Post-mortem Directive. In summary:

  1. You choose between complete deletion and preservation of the avatar.
  2. If you choose preservation, you name one or more people and specify exactly what they may do.
  3. Access uses the credentials entrusted by the user and follows the directive’s instructions. Designated people do not have separate accounts or individual technical permissions; designation does not automatically transfer the account holder’s personal consents.
  4. If you leave no directive, once your death is verified, the avatar is suspended and subsequently deleted. Control does not automatically pass to family members.

Article 2-terdecies also states that a prohibition imposed by the data subject must not adversely affect third parties' exercise of property rights arising from the data subject's death, or their right to defend their interests in court.

9.1 Designated people’s data and privacy notice

The user supplies identification and contact data and instructions concerning designated people. These are processed to manage the designation and related communications, based on the legitimate interest described above. The controller manually emails the Article 14 GDPR notice to the designated person within one month of their details being entered, or at first contact if earlier. The user’s declaration that they have informed or intend to inform the person does not replace this delivery. The need to retain these data ends when the designation is removed or its purpose is fulfilled, except in a concrete dispute.

The designated person’s first and last name, date of birth, relationship to the user and contact details are used to distinguish people with the same name and compare the details of the person contacting us, or whom we contact, with the designation. An identity document is requested during verification, not when the designation is entered, to establish that the person matches. Declared details alone do not constitute conclusive proof of identity.

10. Artificial intelligence

PERSONLIS generates images, voice and text using artificial intelligence systems. We do not make automated decisions producing legal effects concerning you under Article 22 GDPR. Information about the use of artificial intelligence, content labelling and service limitations is in the dedicated document: Artificial Intelligence Notice.

11. Your rights

At any time, you may ask us to:

  1. provide access to your data and a copy — Article 15;
  2. correct it if it is inaccurate — Article 16;
  3. delete it — Article 17;
  4. restrict its processing — Article 18;
  5. provide it in a machine-readable format or transfer it — Article 20;
  6. stop processing based on legitimate interests following your objection — Article 21;
  7. withdraw previously given consent at any time — Article 7(3).

Write to legal@personlis.com. We respond within one month, extendable by two months for complex requests, with notice to you.

If you believe processing infringes the Regulation, you may lodge a complaint with the Italian Data Protection Authority, Piazza Venezia 11, 00187 Roma, or bring proceedings before a judicial authority.

12. Minors

The service is for adults only. If we learn that an account belongs to a minor, we close it and delete the data. Anyone who believes a minor has registered can report it to legal@personlis.com.

13. Security

Encrypted transmission; access to data limited to the account that created it through Firebase security rules; access to the computer animating the avatar only after the user's identity has been verified; deletion of temporary files at the end of each call.

14. Changes

If we change this notice, we publish the new version on this page with a new date. If a change concerns a purpose requiring consent, we ask for it again before applying the change.