
PERSONLIS — version 1.0 of 10 August 2026
This notice is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree No. 196/2003, as amended by Legislative Decree No. 101/2018 (Privacy Code).
| Data controller | LAPOFEIMH DI PEGNA FABIO LUIGI — Via Castellaro 25, 47843 Misano Adriatico (RN), Italy — VAT No. 04776290407 |
|---|---|
| To exercise your rights | legal@personlis.com |
| To report abuse | legal@personlis.com |
No Data Protection Officer has been appointed because the conditions in Article 37 GDPR do not apply. If they become applicable, the officer's name will be published on this page.
PERSONLIS allows a living person to build their own digital avatar while alive, using a photograph and a recording of their voice, and to decide in advance what should happen to that avatar after their death.
| Date | Source | Storage location |
|---|---|---|
| Email address and password | you, when registering | Firebase Authentication |
| Name, language, preferences | you, through your profile | Firestore users/{uid} |
| Photograph of the face used for the avatar | you, when creating your avatar | Storage content_photos/{uid}/avatar.jpg |
| Voice recording lasting ten to twenty seconds | you, when creating your avatar | Storage content_videos/{uid}/voce.m4a |
| Avatar references and voice language | generated by the system | Firestore avatar/{uid} |
| Dated copy of each consent given or withdrawn | generated by the system | Firestore consensi/{uid}/versioni |
| Photo and voice choices and withdrawals, with date, version, language and accepted texts | generated by the user’s choices | Firestore consensiAvatar/{uid}/eventi |
| Content of conversations with the avatar | you, during calls | Firestore ricordi/{uid}/voci |
| Personal archive: texts, photos, videos, documents | you, through the archive section | Firestore legacy/{uid}/oggetti and Storage |
| People you authorise after your death | you, through the post-mortem directive | Firestore eredi/{uid}/persone |
| Technical data: device model, app version, errors | collected automatically | Firebase |
| Payments, subscriptions and balance | Data supplied by you and Stripe and generated by the service | Stripe and Firestore: customer, subscription and payment identifiers, plan, status, periods, remaining credit and usage data. We use these to provide the service, account for credit and handle support, withdrawal and refunds. Full card details are handled by Stripe. |
| Administrative and legal correspondence | You and other people contacting us | Aruba mailboxes; withdrawal requests and their outcomes are also recorded in Firestore, with identification data, declaration, date, period and relevant balance. |
The personal archive of texts and materials stays in Firebase and is not sent to the avatar engine through the archive workflow. The engine does use the avatar photo and voice, questionnaire answers and relevant memories, session content and camera images sent on request. Providers involved are described in section 7.
Facial photographs and voice recordings are personal data. Using them to create and animate an avatar or generate a synthetic voice does not automatically constitute processing of biometric data under Article 9 GDPR. The definition in Article 4(14) concerns data resulting from specific technical processing that allows or confirms unique identification; for biometric data, Article 9 applies when processing is intended to uniquely identify a natural person.
We require separate consents to create and use the avatar and synthetic voice under Articles 6(1)(a) and 7 GDPR, using the checkboxes described in Avatar Consent. Where processing falls within Article 9, explicit consent under paragraph 2(a), or another applicable condition provided by that Article, is also required.
| Purpose | Legal basis | If you decline |
|---|---|---|
| Create and manage your account | performance of the contract, Article 6(1)(b) | the service cannot be used |
| Store your personal archive | performance of the contract, Article 6(1)(b) | you cannot use the archive |
| Build your avatar from your photograph | consent, Article 6(1)(a); where applicable, explicit consent, Article 9(2)(a) | no avatar; the rest of the service remains unchanged |
| Create a synthetic voice that imitates yours | consent, Article 6(1)(a); where applicable, explicit consent, Article 9(2)(a) | no voice; the rest of the service remains unchanged |
| Process your words to generate replies | consent, Article 6(1)(a) | the avatar cannot hold conversations |
| Apply your post-mortem directive | consent, Article 6(1)(a), and Article 2-terdecies of the Italian Privacy Code | the closure rule in section 9 applies |
| Verify that the face and voice are yours | legal obligation and legitimate interest in preventing crime, Articles 6(1)(c) and 6(1)(f) | the avatar is not delivered |
| Security, abuse prevention, diagnostics | legitimate interest, Article 6(1)(f) | — |
| Tax and accounting compliance | legal obligation, Article 6(1)(c) | — |
| Managing designated people’s data | Legitimate interest in managing the designation, Article 6(1)(f), subject to assessing and documenting the balance with the individuals’ rights | Designated people may exercise their rights, including the right to object |
Each consent is freely given, specific, informed and withdrawable at any time without having to give a reason. Withdrawal does not affect the lawfulness of earlier processing. Each consent and withdrawal is recorded with the date, time and version of the text you read.
Every answer is optional. We request explicit consent under Articles 6(1)(a) and 9(2)(a) GDPR to store information about health, religious beliefs and political opinions in memories and use it to personalise the avatar’s replies. The box beside “Fill in” is initially unticked; selecting its wording opens the full text. Without consent, fields in the three groups cannot be edited and display “Consent missing”. Unticking the box withdraws consent and replaces those groups’ answers with that wording through the questionnaire’s save function. Other questions remain available. Choices and withdrawals are recorded with the server date and time and a version identifier that also specifies language and consent status; the version identifies the text presented.
Before photos and voice are used for the avatar, PERSONLIS requests a declaration of ownership or permission and two separate consents. Boxes are not preselected for anyone who has not yet made a choice.
Choices are linked to the account and recorded with server date and time, version, language and displayed wording. New choices do not replace previous records. A declaration by someone uploading another person’s material does not replace that person’s consent: the uploader must hold demonstrable permission for this use.
A consent video, advance submission of documents or a fixed 24-hour wait are not generally required. If a use is disputed, we may request evidence of permission and consider suspending the disputed use.
If photo or voice consent is withdrawn, the controller stops using the affected material and manually deletes it without undue delay. Withdrawal does not delete the account or affect the lawfulness of previous processing.
We do not sell your data or use it for advertising. We use the following providers to deliver the service; their roles depend on the processing performed.
| Provider | Processing and role |
|---|---|
| Google — Firebase / Google Cloud | Accounts and storage of profiles, answers, materials, consents and administrative data. Applicable terms depend on the Firebase service; Firestore, Authentication, Storage and Functions fall under Google Cloud terms. Location depends on the service and settings: not all processing is restricted to the EU. |
| Modal | Running the avatar engine: photos, voice, questionnaire answers and session content. Compute is configured in a European region; this does not exclude processing outside the EU. Modal documentation states, among other things, that application logs are stored in the United States. |
| Groq | Audio transcription, reply generation and analysis of camera images sent on request. It also receives necessary context, which may include questionnaire answers and memories. Inference content is normally not retained; reliability and abuse monitoring may require retention for up to 30 days, unless longer retention is legally required. This limit does not apply uniformly to metadata and other features. Retention options depend on account settings. |
| Stripe | Payments and subscriptions. Stripe acts as a processor for some operations and as an independent controller for others, including legal obligations and fraud prevention. |
| Aruba | Email hosting and support and legal correspondence, including withdrawal requests, receipts, consent withdrawals and post-mortem directives. It processes addresses, message contents and any attachments sent. |
Data may also be disclosed to accounting and legal professionals and to authorities as provided by law.
Services may involve transfers outside the European Economic Area, including to the United States. Standard agreements published by Groq, Modal, Google and Stripe provide transfer mechanisms such as standard contractual clauses and, where applicable, adequacy decisions. Availability of these agreements alone does not establish individual account settings or mean that all data stays in Europe. Information about applicable safeguards can be requested at legal@personlis.com.
| Date | Retention |
|---|---|
| Account, profile, archive | while your account is active |
| Photograph and voice recording | Until withdrawal of consent or account deletion; following withdrawal, manual deletion without undue delay as described in section 6. |
| Conversations | until consent is withdrawn or the account is deleted |
| Temporary files on the computer animating the avatar | Ending a call does not guarantee immediate deletion of all temporary files. Removal depends on the execution environment and cleanup procedures; provider logs follow separate conditions. |
| Declaration and consent register | Within 60 days after the processing to which the consent evidence relates has ended. |
| Tax documents | Ten years from the last entry for accounting documents subject to this obligation, under Article 2220 of the Italian Civil Code. |
| Technical security logs | Operational records managed by the controller follow the period below; provider logs follow their respective conditions described in section 7. |
| Balance data and operational records | Deletion within 60 days after account closure and completion of any pending payments or refunds. |
| Withdrawal requests and related correspondence | Deletion within 60 days after the case is concluded, except documents required for accounting obligations. |
Account deletion starts removal of the profile, photo, voice, memories, archive and authorised-person list. This does not mean immediate deletion of all engine temporary files or provider logs. Consent records, administrative and payment data, balance and withdrawal requests may remain: closing the account does not automatically delete them.
The controller manually applies these deletion periods. In a concrete dispute, only necessary data are retained until it is resolved. These periods form the controller’s adopted retention procedure; they do not imply automatic system deletion.
Files deleted from Firebase Storage remain recoverable for 7 days through the provider’s soft-delete feature. This period starts when the file is deleted, not when the user submits a request.
The GDPR does not apply to deceased persons' data (Recital 27), but Article 2-terdecies of the Italian Privacy Code provides that the rights under Articles 15 to 22 GDPR relating to a deceased person's data may be exercised by anyone with an interest of their own, anyone acting as the data subject's representative, or for family reasons deserving protection.
This is why we ask you, while alive, to write a post-mortem directive. The full rules are in the dedicated document: Post-mortem Directive. In summary:
Article 2-terdecies also states that a prohibition imposed by the data subject must not adversely affect third parties' exercise of property rights arising from the data subject's death, or their right to defend their interests in court.
The user supplies identification and contact data and instructions concerning designated people. These are processed to manage the designation and related communications, based on the legitimate interest described above. The controller manually emails the Article 14 GDPR notice to the designated person within one month of their details being entered, or at first contact if earlier. The user’s declaration that they have informed or intend to inform the person does not replace this delivery. The need to retain these data ends when the designation is removed or its purpose is fulfilled, except in a concrete dispute.
The designated person’s first and last name, date of birth, relationship to the user and contact details are used to distinguish people with the same name and compare the details of the person contacting us, or whom we contact, with the designation. An identity document is requested during verification, not when the designation is entered, to establish that the person matches. Declared details alone do not constitute conclusive proof of identity.
PERSONLIS generates images, voice and text using artificial intelligence systems. We do not make automated decisions producing legal effects concerning you under Article 22 GDPR. Information about the use of artificial intelligence, content labelling and service limitations is in the dedicated document: Artificial Intelligence Notice.
At any time, you may ask us to:
Write to legal@personlis.com. We respond within one month, extendable by two months for complex requests, with notice to you.
If you believe processing infringes the Regulation, you may lodge a complaint with the Italian Data Protection Authority, Piazza Venezia 11, 00187 Roma, or bring proceedings before a judicial authority.
The service is for adults only. If we learn that an account belongs to a minor, we close it and delete the data. Anyone who believes a minor has registered can report it to legal@personlis.com.
Encrypted transmission; access to data limited to the account that created it through Firebase security rules; access to the computer animating the avatar only after the user's identity has been verified; deletion of temporary files at the end of each call.
If we change this notice, we publish the new version on this page with a new date. If a change concerns a purpose requiring consent, we ask for it again before applying the change.