Privacy Policy (GDPR)

Last updated: August 19, 2025

1) Data Controller

Data Controller: Salvatore Grammatico
Privacy contact email: s.grammatico69@gmail.com
Address: Roma

The Controller is responsible for decisions regarding the purposes and means of processing personal data collected through this website.

2) Data Collected and Source

We collect and process:

  • Data you provide directly: email (newsletter), name and surname if filled in, and any content of messages sent via forms (requests for information, events, signed copies).
  • Technical/browsing data: IP address, date/time, requested URL, user agent (for security logs and site operation).
  • Embedded third-party content: e.g. YouTube videos (Google Ireland Ltd.). These services may set their own cookies/identifiers. See “Third-party services”.

We do not request special category data (e.g. health, religious beliefs). Please avoid including them in your messages.

3) Purposes, Legal Bases, and Retention

Purpose

Legal basis

Retention

Newsletter / updates (emails about news, events, excerpts)

Consent (Art. 6.1.a GDPR)

Until consent is withdrawn or after 24 months of inactivity

Responding to requests (contact form: info, events, signed copies)

Pre-contractual steps/contract (Art. 6.1.b) and/or legitimate interest to reply (Art. 6.1.f)

12 months after closure of the request

Security and site operation (logs, abuse prevention)

Legitimate interest (Art. 6.1.f)

30–180 days (depending on hosting provider policy)

Legal/tax compliance (if applicable to direct sales)

Legal obligation (Art. 6.1.c)

As required by law

You may withdraw consent at any time (e.g. via “unsubscribe” in emails or by contacting the above email address).

4) Nature of Data Provision

  • Newsletter: providing your email is optional but necessary to receive communications.

  • Contact forms: required fields are necessary to handle your request.

5) Recipients and “Processors”

Data may be processed by external service providers acting as Data Processors (Art. 28 GDPR), including:

  • Website hosting and maintenance: [provider name + country/EU]

  • Email/newsletter service (e.g. [Mailchimp/Brevo/other]) – may involve transfers outside the EU (see §6)

  • Email provider (e.g. Google Workspace / other)

  • Technical/legal consultants if necessary

An updated list of Processors is available upon request.

6) International Data Transfers

Some providers (e.g. newsletter platforms, email services, or YouTube/Google) may process data outside the European Economic Area (EEA). Transfers are based on:

  • European Commission adequacy decisions, or

  • Standard Contractual Clauses (SCCs) with supplementary measures.

More details are available by writing to s.grammatico69@gmail.com.

7) Data Subject Rights

You can exercise your rights under Articles 15–22 GDPR:

  • Access, Rectification, Erasure, Restriction, Portability, Objection to legitimate interest, Withdrawal of consent (without affecting prior processing).

To exercise your rights: write to s.grammatico69@gmail.com. We will respond within 30 days (extendable for complex cases).

You also have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).

8) Minors

This site is aimed at a general audience, not minors. In Italy, consent for information society services is valid from 14 years old (Legislative Decree 101/2018). If we become aware of data collected from minors without valid consent, we will delete it.

9) Security

We adopt adequate technical and organizational measures (backups, access controls, HTTPS encryption, provider access policies). No measure is 100% secure: please share only relevant, non-sensitive information.

10) Automated Decisions and Profiling

We do not perform automated decision-making with legal effects.
Basic segmentation (e.g. language or interests to send more relevant newsletters) may be done based on data you provide or your interactions (opens/clicks). You can object at any time.

11) Third-Party Services (links/embeds)

  • YouTube/Google: embedded videos may set their own cookies/identifiers. See their privacy policy.

  • Amazon: external links to book purchase pages are subject to Amazon’s own privacy policies.

  • Social media: links/buttons to LinkedIn, Facebook, Instagram, or YouTube are subject to their respective policies.

For cookies and similar technologies, see the site’s Cookie Policy.

12) Policy Updates

We may update this Privacy Policy for improvements or legal compliance. Updates will be published on this page with the new “Last updated” date.