Controller and contact details
The controller is Giulio Schiavo, VAT IT03504180831, Via Consolare Antica, 24 — 98071 Capo d’Orlando (ME), Italy. Contact [email protected] for privacy enquiries and rights requests.
Information and purposes
The contact form collects your name, email, optional website and message to answer your enquiry, arrange an initial conversation and consider a possible engagement. Name, email and message are needed to handle the enquiry. Please do not include sensitive information unrelated to your request.
Servers may log IP addresses, request times, pages, browser details and errors to operate and protect the service. If you accept statistical cookies, Google Analytics 4 processes visit, page and interaction information, browser identifiers and technical device details. Form values and messages are not sent to Analytics. Your browser also stores your cookie choice, its date and version.
Legal bases
Service enquiries are handled to take steps at your request before entering a contract (Article 6(1)(b) GDPR). Other correspondence and security rely on the legitimate interests of responding and protecting the service (6(1)(f)); legal duties rely on 6(1)(c). Analytics relies on optional, revocable consent (6(1)(a)). Refusing statistics does not prevent browsing or sending an enquiry. The form does not subscribe you to newsletters or promotional campaigns.
Private archive and providers
Each submission is stored separately in the private Concrete CMS Express archive and is accessible only to the controller and authorised personnel. Concrete software does not receive messages as an external service.
SupportHost hosts the website and processes technical data, databases and backups as part of its service. Google provides the email service used for correspondence. Brevo handles contact-form emails and stores contacts’ email addresses. Names and messages remain in the website archive. Technical contractors access only information needed for their assigned work.
For EEA users, Google Analytics is provided by Google Ireland Limited. Information is not sold or made public and may be disclosed to authorities where legally required.
Retention
Enquiries and correspondence are retained until the request and any related negotiations have concluded, then deleted or anonymised when no longer needed, except documentation required for legal obligations or legal claims. If an engagement begins, its documentation follows the applicable contractual and administrative retention requirements.
Technical data is retained as needed to operate and secure the service, according to server settings; backups follow the hosting rotation cycle. Cookie choices remain valid for 180 days. Analytics cookies are configured in the tag for up to 180 days without automatic renewal. The Google Analytics 4 property is configured to retain event data for 2 months and user data for 14 months. These periods are separate from cookie duration.
Transfers outside the EEA
Google and, when used, Brevo may involve companies or infrastructure outside the EEA. Transfers must rely on applicable GDPR safeguards, such as adequacy decisions, the EU–US Data Privacy Framework for certified recipients or standard contractual clauses. Ask the controller for information on activated providers and relevant safeguards.
Your rights
Where applicable under Articles 15–22 GDPR, you can request access, rectification, erasure, restriction and portability, and object to processing based on legitimate interests. You can withdraw cookie consent without affecting earlier lawful processing, and complain to the Italian data protection authority. No automated decisions with legal or similarly significant effects are envisaged. Contact [email protected]; requests are normally answered within one month, subject to lawful extensions.
Cookie choices and changes
Use “Cookie preferences” in the footer to change your choice. See the Cookie Policy for details. This notice will be updated when the website’s processing changes.
Anti-spam protection
Contact forms use Cloudflare Turnstile to distinguish legitimate requests from automated submissions. Cloudflare processes technical connection and device information for this security check. The check is required to send a message. More information is available in the Cloudflare Turnstile Privacy Addendum.