Privacy Policy: Data Handling and GDPR Protocol
Last updated: March 2026
This privacy policy explains how this site handles data in line with Regulation (EU) 2016/679 (GDPR) and the Italian Privacy Code under Legislative Decree 196/2003, as amended by Legislative Decree 101/2018.
Scope of Data Collection (Zero-PII Protocol)
This site applies the data minimisation principle under Art. 5(1)(c) GDPR. We do not collect personally identifiable information (PII) such as full names or financial details.
| Data Category | Status | Details | Retention |
|---|---|---|---|
| Server Logs | Collected (Automatically) | IP address, browser User-Agent, timestamp, referring URL | Deleted every 30 days — strictly for DDoS protection and technical analysis |
| Financial Data | No Collection | No payment gateway is integrated — no card or transaction details are processed | N/A |
| Tracker Telemetry | Not collected | Spin sequences are processed locally through JavaScript — nothing is transmitted to our servers | Browser cache — cleared when the tab is closed |
| Email Correspondence | Collected (Voluntarily) | Email address and message content if you contact us | Retained until the request is resolved, then permanently deleted |
| Technical Cookies | Collected (Automatically) | Cookies strictly required for site functionality (language preferences, session handling) | Session duration or up to 12 months |
| Analytics Cookies | Collected (With Consent) | Anonymous traffic analysis cookies, if activated by the user through the cookie banner | Up to 26 months — can be disabled at any time |
| Profiling Cookies | No Collection | We do not use profiling or proprietary advertising cookies | N/A |
Data Controller
The data controller can be identified through the contact details listed in the Contacts section of the site. For any request related to data protection, please use the dedicated email address shown in the Contact Us area.
Legal Basis for Processing
| Type of Processing | Legal Basis | Reference |
|---|---|---|
| Server logs (IP, User-Agent) | Legitimate interest — site security | Art. 6(1)(f) GDPR |
| Necessary technical cookies | Legitimate interest — site operation | Art. 6(1)(f) GDPR |
| Analytics cookies | User consent | Art. 6(1)(a) GDPR |
| Email correspondence | Pre-contractual steps taken at the request of the data subject | Art. 6(1)(b) GDPR |
Recipients and Data Transfers
| Recipient | Type | Data Shared | Transfer Basis |
|---|---|---|---|
| Hosting provider | Data processor | Server logs | Art. 28 GDPR processing agreement — servers located in the EU |
| Google Analytics (if enabled) | Data processor | Anonymised browsing data | User consent + Standard Contractual Clauses |
| Email provider | Data processor | Correspondence content | Art. 28 GDPR processing agreement |
We do not sell, assign, or share personal data with third parties for marketing purposes. No data is transferred to third countries outside the safeguards provided under GDPR Chapter V.
Cookie Policy
Technical Cookies (No Consent Required)
These cookies are strictly necessary for the site to function. They cannot be disabled.
| Cookie | Purpose | Duration |
|---|---|---|
session_id | User session handling | Session |
lang_pref | Language preference | 12 months |
cookie_consent | Stores the user's cookie choice | 12 months |
Analytics Cookies (Consent Required)
These are activated only after explicit consent through the cookie banner. They are used to understand site usage in aggregated and anonymised form.
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
_ga | Google Analytics | User distinction (anonymised) | 26 months |
_gid | Google Analytics | User distinction (anonymised) | 24 hours |
IP anonymisation is enabled by default. To disable analytics cookies, update your preference in the cookie banner or through your browser settings.
Your Rights Under GDPR
As a data subject, you have the right to:
| Right | Description | Reference |
|---|---|---|
| Access | Obtain confirmation of whether your personal data is being processed and receive a copy | Art. 15 GDPR |
| Rectification | Correct inaccurate or incomplete personal data | Art. 16 GDPR |
| Erasure | Request deletion of personal data ("right to be forgotten") | Art. 17 GDPR |
| Restriction | Request restriction of processing | Art. 18 GDPR |
| Portability | Receive data in a structured, commonly used, machine-readable format | Art. 20 GDPR |
| Objection | Object to processing based on legitimate interest | Art. 21 GDPR |
| Withdrawal of consent | Withdraw consent for analytics cookies at any time | Art. 7(3) GDPR |
To exercise your rights, send a request through the site's Contacts section. A response will be provided within 30 days.
Right to Lodge a Complaint
You have the right to lodge a complaint with the competent supervisory authority:
Piazza Venezia 11 — 00187 Rome, Italy
Email: protocollo@gpdp.it
Data Security
Data is protected through the following measures:
| Measure | Details |
|---|---|
| Encryption | HTTPS/TLS connection across the entire site |
| Restricted access | Only authorised personnel can access server logs |
| Automatic deletion | Server logs are deleted automatically every 30 days |
| Anonymisation | IP addresses are anonymised by default in analytics cookies |
Minors
This site is not intended for anyone under the age of 18. We do not knowingly collect data from individuals below 18 years of age. The site content is informational in nature and intended for an adult audience.
Changes to This Policy
This policy may be updated from time to time. The date of the latest update is shown below. Any material changes will be communicated through a visible notice on the site.
Last updated: March 2026