Privacy policy
Last revised: June 2026
This notice is provided pursuant to Regulation (EU) 2016/679 (GDPR) for those who consult the website https://www.gdprsuite.eu. This notice concerns this website only and not other web addresses the user may reach through links.
Data controller
The "controller" of the processing of data relating to identified or identifiable persons who access and browse this website is Nicola Fabiano (privacy [at] gdprsuite.eu).
Purposes and legal basis of the processing
The processing of personal data arising from the use of the website is based on the following purposes and legal bases:
| Aspect | 1. Browsing data (web server logs) | 2. Web analytics statistics (cookie-less Matomo) | 3. Voluntary email communications |
|---|---|---|---|
| Purpose | Information security, prevention of unauthorised access, detection of attack attempts and monitoring of the correct operation of the website | Collection of aggregate statistics to understand use of the website, improve the user experience and optimise content | Responding to requests sent spontaneously by the user via email |
| Legal basis | Art. 6(1)(f) GDPR | Art. 6(1)(f) GDPR | Art. 6(1)(b) GDPR |
| Retention | Maximum 7 days (automatic deletion) | 12 months (in aggregate, anonymous form) | Strictly necessary time, no later than 30 days after the reply |
Data processed
Browsing data
Access to and navigation within this website takes place through a web browser. The IT systems responsible for the operation of this website acquire, in the course of their normal operation, certain data whose transmission is implicit in the use of Internet communication protocols. By their nature, some data necessary for Internet browsing could allow users to be identified through processing and association with data held by third parties. This refers in particular to IP addresses (anonymised) or domain names of the computers used by users connecting to this website, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the type of browser and operating system used, etc.
These data are used solely to obtain anonymous statistical information on the use of the website, to monitor its correct operation and to ensure system security. Web server log data are retained for a maximum of 7 days, after which they are automatically deleted. The data may be used to ascertain liability in the event of computer crimes against the website, at the request of the judicial authority.
Data provided voluntarily by the user
The optional, explicit and voluntary sending of email to the addresses shown on this website entails the acquisition of the sender's address, needed to reply, as well as any other personal data contained in the message. Such data are processed solely to reply to the messages sent and to handle any related requests. Failure to provide personal data for communications or for sending requests prevents them from being handled. Data are retained for the time strictly necessary for the purposes for which they are processed, no later than 30 days after the reply.
Cookies
This website does not install any cookie on the user's device.
No technical, preference, analytics, profiling or advertising cookies are used. The web analytics service is configured in a fully cookie-less manner (see Matomo Web Analytics for technical details).
Matomo Web Analytics
This website uses Matomo to collect aggregate and anonymous browsing statistics (as specified in the purposes table).
Privacy-first configuration implemented
- ✓ No cookie installed on the user's device
- ✓ Anonymisation of IP addresses (last 2 bytes masked)
- ✓ Respect for the browser "Do Not Track" (DNT) signal
- ✓ Aggregate data not attributable to the individual
- ✓ No sharing with third parties
- ✓ Matomo server hosted in the European Union
User control over tracking
As the website is fully cookie-less, no specific consent is required or possible. Users may nonetheless signal their wish not to be tracked by enabling the "Do Not Track" (DNT) option in their browser settings: Matomo is configured to respect this signal and, where present, performs no measurement.
Privacy by Design: cookieless approach
This website has adopted a privacy-first approach in full compliance with the principle of privacy by design (Art. 25 GDPR), thereby ensuring:
- ✓ Maximum respect for privacy: no cookie installed on the user's device
- ✓ No consent required: no data collection subject to Art. 122 of the Italian Privacy Code
- ✓ No intrusive banner: no blocking of access to content
- ✓ Full transparency: no profiling or advertising tracking
- ✓ Regulatory compliance: full adherence to GDPR, the ePrivacy Directive and the Italian Privacy Code
- ✓ Minimisation principle: only strictly necessary data are collected (Art. 5(1)(c) GDPR)
- ✓ Respect for Do Not Track: the browser DNT signal is honoured server-side
Browsing statistics are collected through Matomo in a cookie-less configuration with strong anonymisation.
Recipients
The personal data collected by this website following its consultation are not communicated to recipients or categories of recipients.
Retention period of personal data
Data collected by the website are retained for the following periods:
- Web server logs: maximum 7 days, then automatic deletion
- Matomo analytics data: 12 months in aggregate, anonymous form
- Email requests: time strictly necessary to handle the request, no later than 30 days after the reply
Retention periods comply with the storage limitation principle (Art. 5(1)(e) GDPR).
Transfer of data to non-EU countries
This website does not share data with services located outside the European Economic Area (EEA).
All servers and services used (hosting, Matomo analytics) are located in the European Union, ensuring full compliance with the GDPR provisions on international transfers.
Security measures
Visitors'/users' data are processed lawfully and fairly, adopting appropriate security measures to prevent unauthorised access, disclosure, modification or destruction of data.
The security measures implemented include:
- Encryption of communications: SSL/TLS certificate to protect data in transit
- Anonymisation: masking of IP addresses at source
- Access restriction: log access limited to authorised personnel only
- Regular backups: backup copies to ensure data availability
- Monitoring: detection systems for unauthorised access and attack attempts
In addition to the Controller, in some cases data may be accessed by categories of persons involved in the organisation of the website or by external parties (such as third-party technical service providers, hosting providers), duly appointed as processors pursuant to Art. 28 GDPR.
Rights of data subjects
Data subjects may exercise the following rights provided by Articles 15 to 22 of Regulation (EU) 2016/679:
- Right of access (Art. 15): obtain confirmation of the existence of personal data and receive a copy
- Right to rectification (Art. 16): obtain correction of inaccurate data
- Right to erasure (Art. 17): obtain erasure of data ("right to be forgotten")
- Right to restriction (Art. 18): obtain restriction of processing
- Right to portability (Art. 20): receive data in a structured format
- Right to object (Art. 21): object to processing based on legitimate interest
To exercise these rights, requests should be addressed to: privacy [at] gdprsuite.eu
The Controller will respond to the request without undue delay and in any case within one month of its receipt.
Right to lodge a complaint
Data subjects who consider that the processing of their personal data carried out through this website infringes Regulation (EU) 2016/679 have the right, pursuant to Art. 77 GDPR, to lodge a complaint with the Italian Data Protection Authority:
Garante per la protezione dei dati personali
Piazza Venezia, 11 - 00187 Roma, Italy
Tel. +39 06.696771
Email: garante@gpdp.it
PEC: protocollo@pec.gpdp.it
Website: https://www.garanteprivacy.it