Privacy Policy
Last updated: 2026-07-28
This Privacy Policy (hereinafter, the “Policy”) describes the methods of managing the website mariociavarella.com (hereinafter, the “Website”) with reference to the processing of personal data of users who consult it and/or use its features (for example, the contact form). This Policy is provided pursuant to Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”), UK GDPR and other applicable data protection legislation, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) and similar privacy laws worldwide.
Controller and Contact Details
The Data Controller for the processing of personal data collected through this Website is Mario Ciavarella, residing in Italy. For any matters related to data protection, you may contact the Data Controller via email at [email protected].
Key Principles of Data Processing
- This Website does not require user accounts or newsletter subscriptions. Personal data is actively submitted by users in two places only, and both are optional: the contact form and the comment form on articles and projects.
- Comment email addresses are never published. A published comment shows the author name, the text and the date; the email address is stored but is only visible to the site owner.
- I do not sell or share your personal data for monetary or other valuable consideration. Your data is only used for the purposes described in this policy and is never sold to third parties.
- There is no analytics on this Website. Visits are not measured, profiled or shared with an analytics provider. Until July 2026 Google Analytics 4 ran behind an opt-in banner; both were removed, and no cookie banner is shown because there is nothing left to consent to.
- A spam protection service (Cloudflare Turnstile) is used on the contact form and the comment form to prevent automated abuse, operating under the legal basis of legitimate interest.
What I process and why
The processing of Personal Data by the Website is based on specific legal grounds as defined by the GDPR. These legal bases ensure that your data is processed lawfully and transparently. Below, I outline the categories of data processed, the purposes for processing, the corresponding legal basis and typical data retention periods.
The Website primarily serves informational purposes. Nothing below happens unless you choose to write, comment or like: reading a page produces only the server log.
| Category | Purpose | Legal basis | Typical retention |
|---|---|---|---|
| Contact form (name, email, message) | Replying to your request and follow-up. | GDPR art. 6(1)(b) for handling requests; GDPR art. 6(1)(f) for follow-up communications based on the legitimate interest of managing client relationships. | For the time needed to handle the request, plus a reasonable follow-up period. |
| Comments (name, email address, comment text, plus a hashed IP address and a hashed device fingerprint) | Publishing your comment under the article or project, and moderating it. The two hashes are used only to limit abuse and to attribute repeated submissions; they are produced with a secret key and cannot be turned back into your IP address. | Consent (GDPR art. 6(1)(a)) for publishing the comment; legitimate interest (GDPR art. 6(1)(f)) for the anti-abuse hashes. | Kept for as long as the comment remains published. There is no automatic deletion: write to the address below and the comment and its data are removed. |
| Likes (hashed device fingerprint only) | Counting likes on an article or project and preventing the same visitor counting twice. | Legitimate interest (GDPR art. 6(1)(f)) in a functioning counter. | Kept for as long as the like stands. No name, email address or readable IP is stored. |
| Anti-spam (Cloudflare Turnstile token) | Preventing automated abuse of the contact form and the comment form. | Legitimate interest (GDPR art. 6(1)(f)) to ensure the security and integrity of the forms and prevent abuse. | The token is single-use and verified at the moment of submission; it is not stored by the Website. |
| Server logs (IP, user-agent, timestamps) | Security, troubleshooting and service reliability. | Legitimate interest (GDPR art. 6(1)(f)) in operating and securing the Website. | Rotated automatically and discarded oldest-first. The window is bounded by size rather than by date, so it varies with traffic — in the order of days, not months. |
Third-party Services, Cookies and Data Transfers
Service Providers
Depending on your actions and settings, data may be processed by:
- Hosting / infrastructure providers (to deliver the Website and store server logs).
- Email delivery provider (SMTP) (to deliver contact form messages to the site owner).
- Cloudflare, Inc. (Turnstile anti-spam check on the forms; and, where the Website is served through Cloudflare, delivery of the pages).
Cookies and Similar Technologies
The Website sets no cookies for visitors and shows no cookie banner: there are no analytics, advertising or profiling cookies to consent to. The only cookie it can set belongs to the owner's administration area. For details, see the Cookie Policy.
International Data Transfers
Cloudflare may process data outside the European Economic Area (EEA) and United Kingdom. Where applicable, such transfers are based on appropriate safeguards (e.g. Standard Contractual Clauses) and/or other legal mechanisms recognized under GDPR, UK GDPR and applicable data protection laws.
Data Security
The Data Controller implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate: the pseudonymization and encryption of personal data; the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing.
Your Rights as a Data Subject
Under the General Data Protection Regulation (GDPR), UK GDPR and other applicable privacy laws (including CCPA/CPRA for California residents), you are afforded specific rights concerning your personal data. These rights include:
- Right of Access (Art. 15 GDPR): you have the right to obtain confirmation as to whether or not your personal data are being processed and, where that is the case, access to the personal data and further information.
- Right to Rectification (Art. 16 GDPR): you have the right to obtain the rectification of inaccurate personal data concerning you and to have incomplete personal data completed.
- Right to Erasure (‘Right to be Forgotten’) (Art. 17 GDPR): you have the right to obtain the erasure of personal data concerning you without undue delay, under certain conditions.
- Right to Restriction of Processing (Art. 18 GDPR): you have the right to obtain restriction of processing where specific grounds apply.
- Right to Data Portability (Art. 20 GDPR): you have the right to receive the personal data concerning you, which you have provided to a controller, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance.
- Right to Object (Art. 21 GDPR): you have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on legitimate interests. Where personal data are processed for direct marketing purposes, you have the right to object at any time to processing for such marketing.
- Right to Withdraw Consent (Art. 7 GDPR): where processing is based on consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. On this Website the processing based on consent is the publication of a comment: write to the address below and it is removed.
Additional Rights for California Residents
If you are a California resident, under the CCPA/CPRA you have additional rights:
- Right to Know: you can request information about the categories and specific pieces of personal information I have collected about you.
- Right to Delete: you can request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out of Sale/Sharing: as stated in this policy, I do not sell or share your personal information. Therefore, there is no need to opt-out.
- Right to Non-Discrimination: you have the right not to receive discriminatory treatment for exercising your CCPA privacy rights.
- Right to Limit Use of Sensitive Personal Information: I do not process sensitive personal information beyond what is necessary to provide my services.
How to Exercise Your Rights
To exercise any of these rights, please send a written request to the Data Controller via email at [email protected]. I will respond to your request within the timeframes required by applicable law (generally 30 days for GDPR requests and 45 days for CCPA requests).
Supervisory Authorities
You also have the right to lodge a complaint with a supervisory authority:
- EU/Italy: Italian Data Protection Authority — garanteprivacy.it
- United Kingdom: Information Commissioner’s Office (ICO) — ico.org.uk
- California: California Privacy Protection Agency (CPPA) — cppa.ca.gov
Children’s Privacy
The Website is not intended for children under the age of 16. The Data Controller does not knowingly collect personal data from children under 16. If the Data Controller becomes aware that personal data from a child under 16 has been collected without parental consent, reasonable steps will be taken to delete such information promptly. If you believe that I might have any information from or about a child under 16, please contact me at [email protected].
Updates and references
This policy may be updated from time to time. The “Last updated” date at the top indicates when it was last changed. Official sources often referenced for EU/Italy:
- GDPR — Regulation (EU) 2016/679: EUR-Lex
- ePrivacy Directive — Directive 2002/58/EC: EUR-Lex
- Italian Privacy Code — Legislative Decree 196/2003 (as amended): normative page
- Italian DPA cookie guidelines (10 June 2021): docweb 9677876