// privacy

Privacy notice on the processing of personal data

Last updated: 20 July 2026

This page explains how personal data is processed through the website and its contact form.

1. Data controller

The data controller is Matteo Taccini, operator of the Vipra Studio project.

Address for privacy-related communications:Via Giolitti 26, Livorno, Italy.

Email:matteo@viprastudio.com

2. Scope of this notice

This notice describes the processing of personal data carried out through www.viprastudio.com and, in particular, through its contact form. It is provided pursuant to Articles 12 and 13 of Regulation (EU) 2016/679.

3. Data processed

The following data may be collected through the form:

  • name or company name;
  • email address;
  • website address, if provided;
  • selected type of request;
  • message content;
  • any additional information voluntarily entered by the user.

During the website's normal operation, technical providers may also process connection and security data, such as the IP address, date and time of the request, requested resource, user agent and information needed to prevent abuse and ensure service delivery.

The form is not intended to collect passwords, credentials, documents, health data, judicial data or other special categories of personal data. Users are asked not to include them. Any unnecessary information received accidentally will be deleted as soon as reasonably possible, unless its retention is required by law.

4. Purposes and legal bases

Data is processed to:

a) receive, review and respond to the user's request, as well as prepare any requested activities or proposals before entering into a contract. The legal basis is Article 6(1)(b) of the GDPR;

b) protect the website, form and communications from spam, abuse, fraud and attempted compromise. The legal basis is the controller's legitimate interest in security and service continuity, pursuant to Article 6(1)(f) of the GDPR;

c) comply with any legal obligations or lawful requests from authorities. The legal basis is Article 6(1)(c) of the GDPR;

d) establish, exercise or defend a legal claim. The legal basis is the controller's legitimate interest, pursuant to Article 6(1)(f) of the GDPR.

Data received through the form is not sold, publicly disclosed, used for commercial profiling, or automatically added to newsletters or promotional communications.

5. Provision of data

Fields marked as required are necessary to identify and properly handle the request. The website field is optional.

Failure to provide the required data prevents the request from being sent or handled.

Submitting the form does not require privacy consent: the processing needed to respond is carried out on the basis of the user's request and any requested pre-contractual measures.

6. Processing methods and security

Processing is carried out mainly by electronic means and in accordance with the principles of lawfulness, fairness, transparency, data minimization, accuracy and storage limitation.

Technical and organizational measures proportionate to the risk are adopted, including HTTPS connections, access restrictions, anti-spam protection, input validation and updates to the services used.

However, no Internet-connected system can be considered free from every possible risk.

7. Recipients and providers

To the extent necessary, data may be processed by:

  • Netlify, as the provider of hosting, form handling and request notifications;
  • Zoho, as the email service provider;
  • Wix, solely for domain registration and the technical management of the domain and DNS, without access to the content of requests submitted through the form;
  • professionals bound by confidentiality, only when necessary to comply with legal obligations or protect a right;
  • public authorities in the cases provided for by law.

Providers that process data on behalf of the controller operate under the applicable agreements and instructions. Data is not publicly disclosed.

8. International transfers

Some providers may process data outside the European Economic Area.

Where applicable, these transfers take place on the basis of an adequacy decision, the EU-US Data Privacy Framework, standard contractual clauses approved by the European Commission, or other safeguards provided for by the GDPR.

Netlify governs the processing of customer data through its Data Processing Agreement. Zoho states that it uses data protection agreements also based on standard contractual clauses for transfers subject to the GDPR.

Further information:

9. Retention

Requests that do not result in a contractual relationship are retained for no longer than 12 months after the last meaningful interaction, both in the Netlify dashboard and in the Zoho mailbox.

Unnecessary, duplicate, clearly abusive or irrelevant messages may be deleted sooner.

If a request leads to a contractual relationship, dispute or legal obligation, the relevant data may be retained separately for the period needed to perform the relationship, comply with legal obligations and protect the controller's rights.

Removal from backup copies follows each provider's technical deletion cycles.

10. Data subject rights

Where provided for by the GDPR, the data subject may request:

  • access to their personal data;
  • rectification of inaccurate data;
  • erasure;
  • restriction of processing;
  • objection to processing based on legitimate interest;
  • data portability, where applicable;
  • information about the recipients to whom the data has been disclosed.

Requests may be sent to:
matteo@viprastudio.com

Before responding, the controller may request only the information strictly necessary to verify the identity of the person making the request.

11. Complaint

The data subject may lodge a complaint with the Italian Data Protection Authority:

https://www.garanteprivacy.it/

This right does not affect the possibility of seeking any other administrative or judicial remedy provided by law.

12. Anti-spam filters and automated processes

The form uses automated anti-spam checks provided by Netlify, including a honeypot field and the Akismet filter.

These checks are used solely for security and abuse prevention and do not produce decisions with legal or similarly significant effects on the user.

If a legitimate request is not delivered, the user may contact:
matteo@viprastudio.com

No profiling or automated decision-making with legal or similarly significant effects is carried out.

13. Cookies and tracking technologies

As of the date of this notice, the website's code does not set cookies and does not use analytics, advertising pixels, social widgets, profiling, local storage or other technologies intended to track users.

For this reason, no cookie consent banner is displayed.

Infrastructure providers may process technical connection and security data according to their respective roles and privacy notices, as described in the previous sections.

Before introducing analytics, embedded content, CAPTCHA, advertising tools or other technologies capable of storing or reading information on the user's device, the website will undergo a new privacy assessment and, where necessary, this notice and the methods used to obtain consent will be updated.

14. Changes

This notice may be updated following regulatory, technical or organizational changes.

The updated version will be published on this page together with its date.