Privacy Policy Regarding the Processing of Personal Data Collected Through This Website
Last Updated: April 16, 2026
1. Introduction and Legal References
This privacy policy explains how we process personal data collected through this website, including data obtained through cookies, tracking technologies, and—where applicable—contact forms, restricted areas, digital services, and electronic financial transactions.
This policy is intended for anyone who accesses or uses this website, describing how we collect, use, and protect your personal data, as well as the rights granted by law.
These provisions do not apply to other websites, pages, or online services accessible via external links that may be present on the site; for those, please consult the relevant privacy policies.
This policy is provided in compliance with the main national and international regulations regarding the protection of personal data, including:
- Regulation (EU) 2016/679 (GDPR)
- Other applicable regulations.
2. Who processes your data and how can you contact us?
Your personal data is processed by:
Alessandra Catalioti
Dirschauer Str. 4 – 10245 Berlin
alessandra.catalioti@gmail.com
For any information regarding the processing of personal data or to exercise your rights under the law, data subjects may contact the Data Controller.
3. On what legal grounds do we process your data?
The processing of personal data collected through this website (including data collected via cookies, similar technologies, contact forms, restricted areas, digital services, and transactions, where applicable) is based on one or more of the following legal grounds:
- Performance of a service or pre-contractual activity requested by the user via the contact forms provided;
- Compliance with legal obligations, regulations, or rules;
- The user’s express consent regarding commercial communications;
An additional legal basis, the Data Controller’s legitimate interest, may be used for specific purposes (e.g., ensuring cybersecurity, preventing fraud, protecting the Data Controller’s rights in legal proceedings).
Failure to accept or the withdrawal of consent may reduce or limit certain features or personalized services.
4. What data do we collect when you visit the site?
While browsing this site, the following data may be collected, including through cookies and similar technologies such as pixel tags, web beacons, local storage, and equivalent technologies:
- Browsing and technical data: information such as IP address, device identifiers, operating system and browser data, requested URLs, connection times, technical logs, technical preferences, and usage data collected via cookies and tracking technologies (pixel tags, web beacons, local storage, and equivalent tools).
- Identifying data provided voluntarily: information entered into digital forms on the site (e.g., first name, last name, email, phone number) and/or provided via email or other contact channels, used to respond to requests, provide services, offer advice, and—with prior consent—to send informational and commercial communications.
- Data communicated via social media integrations and third-party platforms: data transmitted through social media features (logins, plugins, sharing, etc.), processed in accordance with the rules of the relevant platforms as well as this policy.
- Data related to purchases, payments, and financial transactions: collected only if the website offers paid services and managed in accordance with specific security precautions.
- Data related to user registration and access for restricted areas and dedicated features.
- Data related to reviews and feedback: information provided by filling out review forms or using feedback collection systems on the website, including ratings, comments, opinions expressed, any responses to specific questions, and other data intentionally entered by the user during the review process.
5. How do we process your data, how do we protect it, and how long do we retain it?
Personal data collected through this website is primarily processed using electronic and digital tools in accordance with the principles of lawfulness, fairness, data minimization, integrity, and confidentiality.
Appropriate technical and organizational measures are implemented to prevent unauthorized access, loss, alteration, or unauthorized disclosure of data, including:
- Communication encryption (HTTPS): Communications between your browser and the website are protected by HTTPS encryption, which prevents the interception or tampering of data exchanged while browsing;
- Log monitoring: the system records and monitors access and activity to detect suspicious or unauthorized attempts and ensure data security;
- Periodic backups: data is periodically copied and archived to protect it from accidental loss or technical incidents;
- Security audits and checks: security checks and tests are performed regularly to identify and correct any system vulnerabilities;
- Restriction of data access to duly authorized individuals only: access to personal data is permitted exclusively to authorized and trained personnel, in accordance with internal security policies.
Data is retained for the following periods:
- Cookie preferences and consents: retained for 180 days, in accordance with the Cookie Policy on this website.
- Browsing and technical data: retained only for the time necessary to ensure the security, integrity, and functionality of the website, and subsequently anonymized or aggregated.
- Data collected for contractual and transactional purposes: retained for the period required by applicable laws (e.g., tax or accounting regulations).
- Data processed for marketing purposes: retained until consent is revoked or a request for deletion is made.
- Data entered via forms or specific requests: retained for the time necessary to respond or fulfill the relevant purpose.
6. Who can receive your data?
The following may access the personal data collected through this website, within the limits of their respective responsibilities and purposes:
- Internal personnel authorized by the Data Controller, who have received proper training on privacy and security;
- Suppliers and third parties designated as Data Processors (e.g., technical providers, IT companies, customer service firms, consultants, payment service providers, and logistics providers, where applicable);
- Business partners, third parties, and affiliates, exclusively for promotional/marketing purposes if you have provided specific consent or exercised your right to opt-out where applicable;
- Entities providing plugins, social networks, and services for interacting with external platforms, which may process personal data according to their own criteria as independent data controllers (in such cases, please also consult the individual privacy policies of these third parties);
- Competent public authorities and supervisory bodies, within the limits imposed by law or to comply with requests from judicial authorities;
The updated list of external recipients can be made available upon request by writing to the Data Controller’s contact details.
7. Where can your data be transferred?
Personal data collected through this website may be processed and transferred—in accordance with the purposes indicated—to the following countries:
to countries belonging to the European Economic Area (EEA), Switzerland, or other countries recognized by the competent authorities as providing a level of protection “adequate” under the law;
Updated list of “trusted” countries:
EU
Switzerland
8. What are your rights regarding the data collected?
Under applicable law, you have the right to:
- Obtain confirmation as to whether or not personal data concerning you is being processed and, if so, to access such data and related information (right of access).
- Request the correction, updating, or deletion of inaccurate or no longer necessary data (right to rectification and erasure).
- Request the restriction of processing or object to the processing of data, including for promotional or profiling purposes, where applicable.
- Request the portability of data in a structured and interoperable format (where technically possible).
- Withdraw consent given for the use of non-technical cookies and for the processing of data collected via tracking tools.
- Report any irregularities or abuses to the competent supervisory authorities.
To exercise these rights, simply send a request to the Data Controller’s contact details; the Data Controller will respond within the timeframes set forth in the applicable local regulations.
9. How is children’s data processed?
The protection of children is a top priority.
The services and content on this website are not intended for individuals under the age of 18.
We do not knowingly collect personal data from children without the verifiable consent of a parent or legal guardian.
If a parent or guardian believes that a child has provided personal data without authorization, they may request its removal, updating, or restriction of processing by writing to the contact information provided in this policy.
10. How can you file reports or complaints with the authorities?
If you believe that the processing of your personal data through this website does not comply with applicable law, you may file a complaint free of charge with the relevant supervisory authorities, including:
How do we notify you of changes to this policy?
This policy is subject to periodic review to ensure compliance with regulations or to reflect changes in the services offered through the website. Any significant changes will be communicated on this page.
Last revised: April 16, 2026