This notice describes how the personal data of users who browse and use the website www.tommasovolker.com/en are processed. This notice is provided pursuant to EU Regulation 2016/679, concerning the protection of natural persons with regard to the processing of personal data, and the applicable Italian legislation on the protection of personal data.
1. Data Controller
The Data Controller is the owner of the domain associated with the website. The Data Controller may be contacted for any request concerning the processing of personal data and the exercise of the data subject’s rights.
2. Types of data processed
While browsing and using the website, the following categories of personal data may be processed.
a. Browsing data
The computer systems and software procedures used to operate the website may acquire, during their normal operation, certain technical data whose transmission is implicit in the use of Internet communication protocols.
This category includes, by way of example:
* IP address;
* type of browser used;
* operating system;
* name of the Internet provider;
* date and time of access;
* pages visited;
* technical data relating to browsing and website operation.
These data are used to allow the correct display of the website, ensure IT security, obtain aggregated statistical information and prevent possible abuse.
b. Data voluntarily provided by the user
The optional, explicit and voluntary sending of communications by email, contact form, messaging links or other contact details available on the website entails the acquisition of the data necessary to respond to the user’s requests.
The following data may be processed, by way of example:
* name or pseudonym;
* email address;
* telephone number, if provided;
* content of the message;
* any other data voluntarily entered by the user in the communication.
The user is invited not to send unnecessary data, third-party data or particularly confidential information, unless this is essential in relation to the request submitted.
c. Cookies and tracking tools
The website may use technical cookies necessary for the proper functioning of the pages and services offered.
Any analytics cookies, profiling cookies, advertising tools, pixels, third-party plugins or other tracking tools will be used only within the limits provided for by current legislation and, where necessary, subject to the user’s prior consent.
For further information, the user may consult the website’s Cookie Policy.
3. Purposes of processing
Personal data are processed using electronic and digital tools.
a. to allow browsing and proper use of the website;
b. to ensure the security, maintenance and proper technical functioning of the website;
c. to respond to requests sent by the user via email, contact form or other channels indicated on the website;
d. to manage any subsequent communications with the user;
e. to prevent spam, abuse, unauthorized access or unlawful activities;
f. to comply with obligations provided for by law, regulations or requests from competent authorities;
g. to protect the rights of the Data Controller in the event of any disputes.
The website does not use users’ personal data for direct marketing purposes, newsletter delivery, commercial profiling or disclosure to third parties, unless otherwise specified in a separate notice and, where necessary, subject to the user’s prior consent.
4. Legal basis for processing
The processing of personal data is based on the following legal grounds:
* Article 6(1)(b) GDPR, when processing is necessary to respond to a user’s request or to take pre-contractual measures requested by the user;
* Article 6(1)(f) GDPR, for the legitimate interest of the Data Controller in ensuring the functioning, security and protection of the website;
* Article 6(1)(c) GDPR, when processing is necessary to comply with legal obligations;
* Article 6(1)(a) GDPR, where the user’s consent is required, for example for any non-technical cookies, tracking tools, marketing or optional processing activities.
5. Special categories of data
The website is not intended to collect special categories of personal data, such as data relating to health, religious, political or trade union beliefs.
The user is invited not to include such information in communications sent through the website, unless this is strictly necessary in relation to the request made.
If the user voluntarily provides data falling within special categories, such data will be processed exclusively within the limits necessary to manage the request and, where required by law, on the basis of the explicit consent of the data subject.
6. Processing methods
Personal data are processed using electronic and digital tools.
The Data Controller adopts appropriate technical and organizational measures to protect personal data against loss, unlawful or improper use, unauthorized access, disclosure, alteration or destruction.
Processing is carried out in accordance with the principles of lawfulness, fairness, transparency, minimization, storage limitation, integrity and confidentiality.
7. Provision of data
The provision of browsing data is necessary for the technical consultation of the website.
The provision of data via email, contact form or other communication channels is optional, but necessary to allow the Data Controller to receive and manage the user’s request.
Failure to provide the necessary data may prevent the Data Controller from responding to the request received.
8. Retention period
Personal data will be stored for the time strictly necessary to achieve the purposes for which they were collected.
In particular:
* technical browsing and security data are retained for the time necessary for the functioning and protection of the website;
* data sent through voluntary communications will be retained for the time necessary to manage the request and, as a rule, for no longer than 12 months from the last communication;
* data necessary to comply with legal obligations or to protect the rights of the Data Controller may be retained for the period provided for by the applicable legislation or for the time necessary to manage any disputes.
9. Recipients of the data
Personal data may be processed by:
* the Data Controller;
* persons authorized by the Data Controller;
* technical service providers;
* hosting providers;
* website managers;
* email service providers;
* providers of security, anti-spam, technical maintenance or statistical analysis services;
* consultants or professionals, where necessary;
* public authorities or subjects legally entitled to receive the data.
Personal data will not be sold, disseminated or disclosed to third parties for unauthorized commercial purposes.
10. Transfer of data outside the European Economic Area
Personal data are preferably processed within the European Economic Area.
If certain technical services used by the website involve the transfer of data to countries outside the European Economic Area, such transfer will take place in compliance with the safeguards provided for by the GDPR, including adequacy decisions, standard contractual clauses or other legal instruments permitted by current legislation.
11. Cookies
The website may use technical cookies necessary for browsing and for the proper functioning of the pages.
The use of non-technical cookies or similar tools, such as non-anonymized analytics cookies, profiling cookies, advertising tools, pixels or third-party services, will take place only in the cases and according to the methods permitted by current legislation.
The user may manage or disable cookies through their browser settings.
12. Third-party services
The website may integrate links, buttons, plugins or services provided by third parties, such as messaging services, social networks, maps, anti-spam tools, statistical analysis systems, payment platforms or other external services.
Interaction with such services may involve the processing of personal data by the respective providers, according to their own privacy policies.
The Data Controller invites the user to consult the privacy policies of any third-party services used.
13. Links to external websites
The website may contain links to external websites.
The Data Controller is not responsible for the content, security or privacy practices adopted by third-party websites, platforms or services that may be accessed through links on the website.
14. Rights of the data subject
The user may exercise at any time the rights provided for by Articles 15 et seq. of the GDPR, including:
* right of access to personal data;
* right to rectification;
* right to erasure;
* right to restriction of processing;
* right to object to processing;
* right to data portability, where applicable;
* right to withdraw consent, where processing is based on consent;
* right to lodge a complaint with the Italian Data Protection Authority.
To exercise their rights, the user may contact the Data Controller at the following address: tommasovolker@proton.me
15. Changes to this notice
The Data Controller reserves the right to amend or update this notice at any time, including as a result of regulatory, technical or organizational changes.