Operational version: 11 August 2026. Controller: Safe House ETS (Italian fiscal code / Codice Fiscale 96629270586). This is the live policy for the website and CRM; it may be refined after legal review (registered address, DPO, Aruba email product details).
1. Data controller
The controller is Safe House ETS, a Third Sector entity (ETS), Codice Fiscale 96629270586.
- Public website: https://safehouse.community
- CRM (staff use): https://crm.safehouse.community
- Privacy / general contact: info@safehouse.community
- Registered address: Italy — full address to be completed in the next revision
No Data Protection Officer (DPO) is appointed at the time of publication; if appointed, contact details will be added here.
2. Scope
This notice covers:
- visitors and users of safehouse.community (forms, donations, cookies);
- processing in Safehouse CRM (EspoCRM) used by authorised staff;
- Google Calendar and Google Drive integrations connected to the CRM (OAuth for staff Google accounts).
The website and CRM run on the same VPS (Aruba Cloud, Italy).
3. Data we process and purposes (public website)
3.1 Browsing
Technical connection data (IP address, user-agent, security logs) to deliver the site, prevent abuse and ensure security. Legal basis: legitimate interest (GDPR Art. 6(1)(f)) and legal obligations where applicable.
3.2 Contact and volunteer forms
Name, email, phone (if provided), message and related preferences. Purpose: respond to and handle the request. Basis: pre-contractual steps / legitimate interest; explicit consent on the form where required.
3.3 Online donations (Stripe)
Donor data (e.g. name, email, amount, donation metadata). Card data does not pass through our servers — payments are handled by Stripe. We may store donation metadata in the CRM (ledger / reporting) for accounting and association transparency. Basis: donation relationship / legal accounting duties.
3.4 “5 per mille” information
Publishing our fiscal code does not collect additional personal data beyond normal browsing.
3.5 Cookie consent
We store cookie preferences and an audit log (hashed IP and user-agent, accepted categories, timestamp). Basis: demonstrating consent (ePrivacy / GDPR).
4. Cookies
On the public site we use essential cookies (session, CSRF security, consent preference). Marketing/analytics cookies are not currently active; if introduced later, they will load only after consent. Details: Cookie policy.
The staff CRM uses only essential authentication/session cookies: no cookie banner is shown on the CRM.
5. Google API Services — Safehouse CRM (Calendar & Drive)
This section is also intended for Google Cloud OAuth verification and the Google API Services User Data Policy (Limited Use).
Application: Safehouse CRM — GoogleIntegration extension on EspoCRM (crm.safehouse.community).
Users: authorised Safe House ETS staff only (not the general public).
Google user data the app may access (OAuth scopes in use):
- basic Google account identity (
openid,email,profile); - Google Calendar — read/write calendars and events to export/sync CRM meetings, calls, tasks and relevant dates;
- Google Drive with limited scope
drive.file— only files created or opened by the app (not the user’s entire Drive).
How we use Google data: solely to provide staff integration features (e.g. saving CRM events to the user’s Google Calendar, calendar sync, Drive operations allowed by the scope). OAuth tokens are stored server-side in EspoCRM External Accounts and are not exposed to the browser as secrets.
What we do not do: we do not sell Google data; we do not use it for advertising; we do not transfer it to unrelated third parties; we do not use Google user data to train generalised AI/ML models.
Safe House ETS complies with the Google API Services User Data Policy, including Limited Use.
Disconnect and deletion: staff can disconnect Google under CRM → External Accounts. On disconnect, tokens are invalidated/removed per the integration; CRM business records remain subject to internal retention rules.
6. Safehouse CRM (EspoCRM) — internal processing
The CRM holds association records and activities (contacts, members, volunteers, donations/reporting, desk cases, etc.) for Safe House ETS institutional purposes. Recipients: authenticated users under role/ACL controls. Bases: legitimate interest / legal duties / performance of relationships with data subjects, as applicable.
7. Processors and providers
- Hosting: Aruba Cloud VPS (Italy) — website and CRM on the same server.
- Email: Aruba email services linked to the VPS/domain (exact product to be confirmed).
- Payments: Stripe (controller/processor roles per Stripe’s terms).
- Google: Google Ireland / Google LLC for Calendar and Drive APIs when staff connect their account.
8. International transfers
Hosting and email are in Italy/EU where possible. Stripe and Google may involve international transfers with appropriate safeguards (SCCs / applicable frameworks). See those providers’ privacy notices for details.
9. Retention
- Technical / security logs: as needed for security and law (typically months, longer if investigating an incident).
- Form messages: as needed to handle the request and reasonable follow-up.
- Donation / accounting data: per civil and tax retention rules.
- Cookie consent audit (hashes): to demonstrate consent (typically 12–24 months or until policy renewal).
- Google tokens: while the external account remains connected.
10. Your rights
You may exercise rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent (where applicable) by emailing info@safehouse.community. You may lodge a complaint with the Italian Data Protection Authority (Garante) or your local supervisory authority in the EEA.
11. Updates
We may update this notice for technical or legal changes. The date above and the page “Updated” field show the published revision.