Home

Privacy Policy

Last updated: 29 June 2026

This policy describes how personal data is processed within the ORAMA platform, in accordance with the applicable data protection legislation (GDPR and the Swiss Federal Act on Data Protection).

Data controller

  • GLOBAMIND SA — C.so San Gottardo 46E, 6830 Chiasso, Switzerland (CHE-183.479.959).
  • For any request regarding data processing: info@globamind.com.

Data processed

  • Access credentials and username.
  • E-mail addresses used for contact and support.
  • Company consumption and activity data and, where present, personal data of third parties uploaded by the client to the platform.
  • Technical browsing information, including IP address and browser data.

Purposes and legal basis

  • Provision of the service, on the basis of performance of the contract.
  • Pre-contractual and support communications, on the basis of legitimate interest.
  • Platform security and abuse prevention, on the basis of legitimate interest.
  • Compliance with legal and regulatory obligations.
  • Any marketing communications, only upon explicit consent, which may be withdrawn at any time.

Methods and security

Data is processed using electronic tools and appropriate security measures. Passwords are stored solely in encrypted (hashed) form.

Processors and third parties

  • The platform relies on cloud infrastructure and hosting providers (in particular the application provider and the database/authentication provider) acting as data processors, on servers located within the EU/EEA or Switzerland.
  • When the client uploads company data, GLOBAMIND acts as a data processor on behalf of the client, who is the controller of such data.

Retention

Data is retained for the duration of the service relationship and, thereafter, for the periods required by tax and legal obligations.

Your rights

  • You may exercise the rights of access, rectification, erasure, restriction, objection and portability, and withdraw consent, by writing to info@globamind.com.
  • You may also lodge a complaint with the competent supervisory authority (in Italy, the Garante per la protezione dei dati personali; in Switzerland, the Federal Data Protection and Information Commissioner — FDPIC).