top of page

Privacy policy

The purpose of this document (hereinafter the "Privacy Policy") is to inform Users about personal data, understood as any information that allows the identification of a physical person (hereinafter the "Personal Data"), collected by the website (hereinafter the "Application").

The Data Controller, as subsequently identified, may amend or simply update all or part of this Policy by informing Users. The amendments and updates will be binding as soon as they are published on the Application. The User is therefore invited to read the Privacy Policy each time he/she accesses the Application.

In case of non-acceptance of the changes made to the Privacy Policy, the User must cease using this Application and may request the Data Controller to remove his/her Personal Data.

  • Personal data collected by the Application

The Data Controller collects the following types of Personal Data:

  • Content and information provided voluntarily by the User 

    • Contact and content data: this is the Personal Data that the User voluntarily provides to the Application during its use, such as personal data, contact details, access credentials to the services and/or products provided, personal interests and preferences and other personal content, etc.

Failure by the User to provide Personal Data, for which there is a legal or contractual obligation or if they are a necessary requirement for the use of the service or for the conclusion of the contract, will make it impossible for the Owner to provide all or part of its services.

The User who communicates to the Owner Personal Data of third parties is directly and exclusively responsible for their origin, collection, processing, communication or dissemination.

  • Data and content acquired automatically during the use of the Application: 

    • Technical data: during their normal operation, the computer systems and software procedures used to operate this Application may acquire some Personal Data whose transmission is implicit in the use of Internet communication protocols. This information is not collected in order to be associated with identified Users, but by its very nature could, through processing and association with Data held by third parties, allow Users to be identified. This category includes IP addresses, or domain names used by Users connecting to the Application, URI (Uniform Resource Identifier) notation addresses of the resources requested, the time of the request, the method used to submit the request to the server, the size of the file obtained, etc.

    • Usage Data: Personal Data relating to the use of the Application by the User may also be collected, such as the pages visited, the actions performed, the functions and services used.

  • Personal data collected through cookies or similar technologies:

The Application uses cookies, web beacons, unique identifiers and other similar technologies to collect Personal Data about the pages, links visited and other actions performed when using our services. They are stored and then retransmitted on the next visit by the same User.

The User can view the full Cookie Policy at the following address:


The Personal Data collected may be used for the performance of contractual and pre-contractual obligations and for legal obligations as well as for the following purposes:

  • External management of payments by credit card, bank transfer or other instruments: to manage Users' payments through external platforms that acquire payment data without the Application owner having access.

  • Sending emails or newsletters and mailing list management: to contact the User with emails containing commercial and promotional information relating to the Application.

  • Treatment modes

The processing of Personal Data is carried out by means of computer and/or telematic tools, with organizational methods and logics strictly related to the indicated purposes.

In some cases, also subjects involved in the organization of the Data Controller (such as, for example, personnel management, sales staff, system administrators, etc.) or external subjects (such as IT companies, service providers, postal couriers, hosting providers, etc.) may have access to Personal Data. These subjects, if necessary, may be appointed as Data Processors by the Data Controller, as well as have access to the Personal Data of the Users whenever necessary and will be contractually obliged to keep the Personal Data confidential.

An updated list of Responsible Persons can be obtained by emailing

  • Legal basis of the treatment

The processing of Personal Data relating to the User is based on the following legal bases:

  • the consent given by the User for one or more specific purposes;

  • the processing is necessary for the performance of a contract with the User and/or the execution of pre-contractual measures

  • the processing is necessary to fulfil a legal obligation to which the Data Controller is subject

  • the processing is necessary for the performance of a task carried out in the public interest or for the exercise of public powers vested in the Data Controller

  • the processing is necessary for the pursuit of the legitimate interest of the Owner or of third parties

  • the processing is necessary for the pursuit of a vital interest of the Controller or a third party.

However, you can always ask the Data Controller to clarify the legal basis of each processing at

  • Location

Personal Data are processed at the operational headquarters of the Data Controller and in any other place where the parties involved in the processing are located. For further information, please contact the Data Controller at the following email address or at the following postal address Case Sparse, Strada Provinciale Martignano Caprarica, Martano - Lecce.

  • Security measures

The Processing is carried out according to methods and with instruments suitable to guarantee the security and confidentiality of Personal Data, the Data Controller having adopted adequate technical and organizational measures that guarantee, and allow to demonstrate, that the Processing is carried out in compliance with the reference legislation.

  • Data Retention Period

Personal Data will be kept for the period of time necessary to fulfill the purposes for which it was collected.

In particular, Personal Data will be stored for the entire duration of the contractual relationship, for the execution of the inherent and consequent fulfillments of the same, for the respect of the applicable legal and regulatory obligations, as well as for own or third parties' defensive purposes.

If the processing of Personal Data is based on the User's consent, the Data Controller may retain the Personal Data until the consent is revoked.

Personal Data may be retained for a longer period if necessary to comply with a legal obligation or by order of an authority.

All Personal Data will be deleted or stored in a form that does not allow the User to be identified within 30 days of the end of the storage period. Upon expiration of this period, the right of access, cancellation, rectification and the right to portability of Personal Data may no longer be exercised.

  • Automated decision-making processes

All Personal Data collected will not be subject to any automated decision-making process, including profiling, that may produce legal effects for or significantly affect the individual.

  • User Rights

Users may exercise certain rights with respect to Personal Data processed by the Data Controller. In particular, the User has the right to:

  • withdraw consent at any time;

  • oppose the processing of their Personal Data;

  • access their Personal Data;

  • verify and request rectification;

  • obtain the limitation of the treatment;

  • obtain the cancellation of their Personal Data;

  • receive their Personal Data or have them transferred to another data controller;

  • to lodge a complaint with the data protection supervisory authority and/or take legal action.

In order to exercise their rights, Users may address a request to the contact details of the Controller indicated in this document. Requests are made free of charge and processed by the Controller as soon as possible, in any case within 30 days.

  • Data Controller

The Data Controller is Sophia Irene Mapai, Case Sparse, Strada Provinciale Martignano Caprarica, Martano - Lecce, e-mail address

  • Data Protection Officer (DPO)

The person responsible for the protection of personal data is

  • Sophia Irene Mapai, Case Sparse, Strada Provinciale Martignano Caprarica. Martano - Lecce, e-mail address

Last update: 15/10/2022

bottom of page