DOCUMENT / LEGAL
Privacy Policy
How we process the personal data of people who visit this site and contact us, under EU Regulation 2016/679.
Data controller
The data controller is Prima-studio — independent web studio, based in Milan, Italy, VAT no. 14854090967.
For any request concerning personal data, write to prima-studio@outlook.com.
Data we collect
We collect only the data needed to reply and keep the website working.
- Data you provide: name, email, optional phone number, project name, business description, goals, style preferences, timing, indicative budget and anything else you enter in the contact form or an email.
- Technical browsing data: IP address, browser and device type, pages visited and the date and time of the request. These are automatically recorded by the server hosting the site.
- Measurement data: only if you consent through the banner. This is aggregated page-usage data. If you do not consent, it is not collected.
We do not collect special categories of data under Article 9 GDPR and ask you not to enter them in the form.
Why we process data and the legal basis
| Purpose | Legal basis |
|---|---|
| Reply to requests received through the form or by email | Pre-contractual measures at your request — Art. 6(1)(b) GDPR |
| Manage a potential contractual relationship and related obligations | Performance of a contract and legal obligations — Art. 6(1)(b) and (c) |
| Ensure website security and operation through technical logs | Legitimate interest — Art. 6(1)(f) |
| Measure website use in aggregated form | Consent — Art. 6(1)(a), withdrawable at any time |
Contact form
Fields marked as required are necessary for us to reply. Without them we cannot process the request. Other fields are optional and only help us understand the project.
We use brief data solely to prepare a response and possible proposal. We do not disclose it to third parties for marketing and do not add you to a newsletter.
Cookies and measurement
This site uses cookies and local storage technologies that are strictly necessary for operation and, only with consent, measurement tools. Details are in the Cookie Policy, where you can change your preferences at any time.
Who may access the data
Data is processed by Prima-studio and may be processed on our behalf and instructions by technical suppliers acting as processors under Article 28 GDPR:
- the hosting provider that stores the site and technical logs;
- the email service provider;
- any service used to receive forms;
- accounting and tax advisers for legal obligations.
Data is neither published nor sold. It may be disclosed to public authorities only where required by law.
Transfers outside the European Union
We prefer suppliers that process data within the European Economic Area. If a supplier transfers data to a third country, this takes place under a European Commission adequacy decision or Standard Contractual Clauses, with supplementary safeguards where necessary.
How long we keep data
- Requests that do not become projects: up to 24 months after the last contact.
- Contractual relationships: for the relationship and then for the periods required by law, normally 10 years for tax records.
- Technical server logs: for the period required for security, normally a few months.
- Cookie preferences: up to 12 months, after which they are requested again.
Your rights
At any time you may ask us to:
- provide access to your data (Art. 15);
- correct inaccurate or incomplete data (Art. 16);
- erase it where applicable (Art. 17);
- restrict processing (Art. 18);
- provide it in a readable format or transfer it (Art. 20);
- object to processing based on legitimate interest (Art. 21);
- withdraw measurement consent without affecting browsing.
We reply within one month. To exercise your rights, write to prima-studio@outlook.com.
Complaint to a supervisory authority
If you believe processing breaches the law, you may lodge a complaint with the Italian Data Protection Authority at garanteprivacy.it or the authority in the EU Member State where you live.
Security
The website is served over an encrypted HTTPS connection. We use appropriate technical and organisational measures to protect data from unauthorised access, loss or disclosure. No system is infallible; if a breach poses a high risk to your rights, we will notify you as required by Article 34 GDPR.
Changes to this notice
We may update this document to reflect legal or organisational changes. The version in force is always the one published on this page, with the update date shown above.