Privacy Policy
Last updated: March 20, 2026
This notice is provided pursuant to Article 13 of Regulation (EU) 2016/679 (“GDPR”) to those who visit the website www.ondinadelpezzo.com and/or contact the Data Controller through the channels available on the website.
1. Data Controller
The Data Controller is:
Ondina del Pezzo
Email: artist@ondinadelpezzo.com
Phone: +39 333 45 99 511
Certified Email (PEC): ondina.delpezzo@pec.it
2. Types of Data Processed
The website may process the following categories of personal data:
- identification and contact data voluntarily provided by the user, such as first name, last name, email address, and phone number;
- the content of messages or requests sent through forms, email, or other contact details available on the website;
- technical browsing data, such as IP address, date and time of the request, browser and device information, and access logs;
- any additional data that the user may choose to provide voluntarily.
3. Purposes of Processing and Legal Basis
a) Managing contact requests and information inquiries
To respond to requests, messages, questions, or contacts sent by the user.
Legal basis: performance of pre-contractual measures taken at the request of the data subject and/or the legitimate interest of the Data Controller in managing incoming communications.
b) Technical management and website security
To ensure the proper functioning of the website, system security, the prevention of unauthorized access, technical errors, and unlawful activities.
Legal basis: legitimate interest of the Data Controller.
c) Compliance with legal obligations
To comply with obligations established by laws, regulations, or requests from competent authorities.
Legal basis: legal obligation.
d) Protection of the Data Controller’s rights
To establish, exercise, or defend a right in judicial or extrajudicial proceedings.
Legal basis: legitimate interest of the Data Controller.
4. Nature of the Provision of Data
The provision of data marked as necessary for sending requests or messages is optional; however, failure to provide such data may make it impossible to respond to the user’s request.
5. Methods of Processing
The processing is carried out using IT, electronic, and, where necessary, paper-based tools, according to logic strictly related to the purposes indicated above, and by adopting appropriate technical and organizational measures to protect personal data.
6. Recipients of the Data
The data may be communicated, within the limits strictly relevant to the purposes indicated above, to:
- technical and IT service providers;
- hosting providers and entities managing web infrastructure, website maintenance, and security;
- professional consultants, where necessary;
- authorities or public bodies, where required by law.
Such parties may act, depending on the circumstances, as independent data controllers or as data processors appointed pursuant to Article 28 GDPR.
7. Transfer of Data to Non-EU Countries
Data is processed mainly within the European Economic Area.
If, for technical or organizational reasons, some services involve the transfer of data to countries outside the EU, such transfers will take place in compliance with the safeguards provided by the GDPR, including adequacy decisions or standard contractual clauses, where applicable.
8. Data Retention Period
Data will be retained for the time strictly necessary to pursue the purposes for which it was collected and, in particular:
- contact requests: up to 12 months from the handling of the request, unless further retention is necessary in connection with subsequent communications;
- technical data and security logs: for the time strictly necessary for technical, maintenance, and security purposes, unless legal obligations or the need to investigate unlawful acts require longer retention;
- data processed to comply with legal obligations: for the period required by the applicable law.
9. Rights of the Data Subject
The data subject may exercise, in the cases provided for by Articles 15–22 GDPR, the following rights:
- access to personal data;
- rectification of inaccurate data;
- erasure of data;
- restriction of processing;
- objection to processing;
- data portability, where applicable;
- withdrawal of consent, where processing is based on consent, without affecting the lawfulness of processing carried out before such withdrawal.
To exercise these rights, the data subject may contact the Data Controller using the contact details provided in this notice.
10. Complaint to the Supervisory Authority
The data subject also has the right to lodge a complaint with the Italian Data Protection Authority, according to the procedures indicated on the website of the competent authority.
11. Cookies and Other Tracking Tools
The website may use technical cookies necessary for the proper functioning of its pages.
If the website also uses non-anonymized analytics cookies, profiling cookies, pixels, or third-party tracking tools, such tools must be managed through a specific notice and, where required, through the user’s prior consent via a compliant banner/cookie manager.
Important note: this section must be checked and adapted based on the tools actually installed on the website.
12. Changes to this Notice
The Data Controller reserves the right to update this Privacy Policy at any time. Any changes will be published on this page together with the date of the latest update.
Short wording for the contact form checkbox
I declare that I have read the Privacy Policy and understood the processing of my personal data for the handling of my request.