Privacy Policy

Information on the processing of personal data pursuant to Regulation (EU) 2016/679 (GDPR)

01

Data Controller

Company Overall Media S.r.l.
Registered office Via Savoia, 78 - 00198 Roma
VAT number IT12274411003
02

Introduction

okDesk is the mobile and desktop companion application for the okTicket ticketing service. It is used exclusively by cashiers and box office staff at museums, theatres, parks, and cultural venues. It is not intended for the general public.

This policy describes what data the app collects, how it is processed, and what rights you have under the GDPR.

03

Data Collected & Purposes

Authentication Data

Data Email, password (transmitted and not stored in plain text on device)
Purpose App access, session management
Legal basis Performance of contract (okTicket service)
Device storage The session token is encrypted with AES-256-CBC and stored locally. All session data is deleted on logout.
Server storage Until the account is deleted by the administrator

User Identity Data

Data First name, last name, user group/role
Purpose Operator identification, permission management
Legal basis Performance of contract

Device Data

Data Device type, operating system and version, manufacturer, model, app version
Collection Automatically at login
Purpose Security (session identification), technical compatibility, debugging
Legal basis Legitimate interest (service security)
We do not collect IMEI, MAC address, advertising identifiers, or GPS data.

Point-of-Sale Transaction Data

Data Transaction serial number, date/time, payment method (cash/card), amount, item details, cash received, change
Purpose Point-of-sale management, tax compliance
Legal basis Legal obligation (tax documentation), performance of contract
Retention Indefinite (tax obligation)

Customer Data

Optional
Data Customer name, email, phone, booking notes, number of visitors, visit date
Collection Manually entered by the cashier only when needed, never collected automatically
Purpose Associating the transaction with a customer, booking management
Legal basis Performance of contract, consent (optional entry)
This data is optional. The app functions fully without collecting it.

Booking Data

Data Sequential number, booking type, status (confirmed/validated/refunded/cancelled), customer data (if present), ticket QR code
Purpose Entry validation, booking management
Legal basis Performance of contract

Statistical Data

Data Daily, monthly, and yearly sales summaries aggregated by product
Purpose Business reporting
Legal basis Performance of contract
04

Where Data is Transmitted

Server All operational data is transmitted to www.okticket.it via encrypted HTTPS connections
Server location European Union
Third parties Data is not shared with third parties. There are no analytics, advertising, crash reporting, or tracking SDKs of any kind.
Cookies The app does not use cookies. Authentication is handled via tokens.
05

Data Stored on Device

The app stores the following data locally to enable offline functionality. All data is deleted on logout.

Data Encrypted Deleted on logout
Access token Yes (AES-256) Yes
User permissions No Yes
User settings No Yes
Transactions No Yes
Bookings No Yes
Product catalog No Yes
Printer configuration No Yes
UI preferences (theme, layout) No Yes
Application logs No Yes

The encryption key is stored in the operating system's secure keystore (Keychain on iOS/macOS, KeyStore on Android, Credential Manager on Windows).

Each user's data is isolated in separate folders: a user cannot access another user's data on the same device.

06

App Permissions

Android

Permission Reason
Internet Communication with the okTicket server
Network state Detecting connection availability for offline mode
Precise location Required by third-party libraries for printer discovery. The app does not collect location data.

iOS

Permission Reason
Local network Discovery of thermal printers on the local network
Camera QR code scanning for ticket validation
Location Required by third-party libraries. The app does not collect location data.
Bluetooth Required by third-party libraries. The app does not use Bluetooth.
Photo library Required by third-party libraries. The app does not access photos.
07

Data Security

We adopt the following technical measures to protect your data:

Encryption in transit

All communications occur exclusively via HTTPS

Encryption at rest

Session token encrypted with AES-256-CBC with random IV per token

Secure keystore

Encryption key stored in the operating system's secure keystore

Data isolation

User data isolated on shared devices

Auto-lock

Automatic lock after inactivity with PIN protection

Biometric authentication

Fingerprint and Face ID support

08

Data Deletion

On logout

All user data is deleted from the device: token, permissions, transactions, bookings, statistics, preferences, and cache.

On uninstall

All app data is removed from the device by the operating system.

On server

To request server-side data deletion and exercise the right to be forgotten (GDPR Art. 17), contact privacy@overallmedia.it.

09

Minors

okDesk is a professional application intended exclusively for cashiers and box office staff. It is not directed at individuals under 18 years of age and does not knowingly collect data from minors.

10

Your Rights

Under Regulation (EU) 2016/679 (GDPR), you have the right to:

Art. 15 Right of access

Obtain confirmation of processing and access your personal data

Art. 16 Right to rectification

Obtain correction of inaccurate personal data

Art. 17 Right to erasure

Obtain deletion of your personal data

Art. 18 Right to restriction

Obtain restriction of data processing

Art. 20 Right to portability

Receive your data in a structured, machine-readable format

Art. 21 Right to object

Object to the processing of your personal data

To exercise your rights, you may contact the Data Controller at privacy@overallmedia.it.

You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) (www.garanteprivacy.it).

11

Changes to this Policy

This policy may be updated to reflect changes in data processing practices or regulatory requirements. Any changes will be published on this page with the corresponding update date.

We encourage you to periodically review this page to stay informed about how we protect your data.