Notice
Privacy Policy
Last updated: 6 September 2026 · Version v2
1. Data Controller
The data controller is Studio di Registrazione Liotta Matteo, VAT ID 10755761219, with its office at Via Pigna 76, Parco Correale — 80128 Naples (NA), Italy. Contacts: [email protected] · certified email [email protected] · +39 389 470 4304.
2. Data processed and purposes
- Contact / booking form: name, email, phone, message. Purpose: to respond to requests and manage bookings. Legal basis: performance of pre-contractual measures / legitimate interest in responding to enquiries.
- Members area account: email address, password stored only in hashed form (never in clear text), email verification status, login sessions. Purpose: to create your account, authenticate you and give you access to the course you purchased. Legal basis: performance of the contract (art. 6.1.b GDPR).
- Purchase and invoicing: name or company name, email, Italian tax code or VAT number, address, postcode, city, province, SDI recipient code or certified email address, amount, VAT, any discount code, transaction identifiers at Stripe (checkout session and payment intent ids), date and IP address hash of the request for immediate delivery with waiver of the right of withdrawal, version of the terms of sale accepted. Card details never pass through our servers: they are collected and stored directly by Stripe. Purpose: to complete the purchase, issue the invoice and keep proof of the agreement. Legal basis: performance of the contract (art. 6.1.b) and legal obligation under tax law (art. 6.1.c GDPR).
- Course usage: progress per lesson, seconds watched, last playback position, active viewing sessions, technical browser identifier (fingerprint) and device label (e.g. "Chrome on Windows"). Purpose: to let you resume a video where you left it, unlock the certificate on completion and limit the number of devices connected to the same account. Legal basis: performance of the contract and the Controller's legitimate interest in protecting the course from unauthorised use (art. 6.1.f GDPR).
- Certificate of completion: first and last name as given at the time of issue, public verification code, issue date. Purpose: to issue the certificate and allow it to be verified. Legal basis: performance of the contract.
- Security alerts: type of anomaly detected on video access (e.g. exceeding the device limit), IP address hash, date. No blocking is automatic: alerts are reviewed by a person. Legal basis: legitimate interest in the security of the service (art. 6.1.f GDPR).
- Browsing data: IP addresses (anonymised / hashed), user agent, referrer, pages visited. Purpose: security, diagnostics and, with consent, statistics. Legal basis: legitimate interest (security) and consent (statistics).
- Cookie consent log: consent action, accepted/rejected categories, IP hash, timestamp, notice version. Purpose: to demonstrate the proper acquisition of consent (art. 7 GDPR).
3. Marketing emails
If you tick the dedicated box at checkout — optional, never pre-ticked and kept separate from any other statement — we process your email address and the hash of your IP address to send you updates about the courses. Legal basis: your consent (art. 6.1.a GDPR). It is not a condition of purchase and leaving it unticked has no consequence. The emails are sent through Resend, Inc. (United States), appointed as data processor, on the basis of the Standard Contractual Clauses. You can withdraw your consent at any time, with immediate effect: from the "Unsubscribe" link at the bottom of every email, from the dedicated section of your profile in the members area, or by writing to the controller; withdrawal does not affect the lawfulness of emails already sent. Proof of consent (date, version of the text accepted, IP hash) is kept for 5 years after withdrawal too: it is the only way to show, if challenged, why you had received those emails. Service emails tied to your purchase — receipt, address verification, certificate — are not marketing: they are sent to perform the contract and do not depend on this consent.
4. Retention
Contact form data is kept for the time necessary to handle the request and in any case no longer than 24 months. Cookie consent logs are kept for 13 months, in line with the Italian Data Protection Authority guidelines. Orders, billing data and invoices are kept for 10 years from issue, as required by art. 2220 of the Italian Civil Code and tax law: for this data, erasure is not possible before that term expires. Your account, course access and lesson progress remain until you ask for the account to be closed; an issued certificate and its verification code stay on record afterwards too, because the code must remain verifiable by anyone you show it to. Connected devices, viewing sessions and security alerts are kept while the account is active and are deleted when it is closed; you can also revoke a device yourself at any time from the dedicated section of the members area. Proof of consent to marketing emails is kept for 5 years, including after withdrawal.
5. Recipients
Data may be processed by the following providers, appointed as data processors pursuant to art. 28 GDPR: Hetzner Online GmbH (Germany, EU) for hosting of the site, the database and the video files, all of which remain on servers within the European Economic Area; Cloudflare, Inc. (United States, with Cloudflare Germany GmbH for the EU) for DNS, CDN and attack protection, which sees the IP address and request metadata — standard contractual clauses; InTasca Srls (Italy, EU) for development, maintenance and technical management of the site; Stripe Payments Europe, Ltd. (Ireland, EU), together with its affiliate Stripe, Inc. (United States), for collecting payments by card, Apple Pay and Google Pay: card details are collected directly by Stripe, which also processes them as an independent controller for anti-money-laundering and anti-fraud obligations under its own privacy notice — standard contractual clauses; Resend, Inc. (United States) for sending service emails and, with consent, marketing emails — standard contractual clauses; Google Ireland Ltd. (Ireland, EU), with Google LLC (United States), for Google Tag Manager and Google Analytics 4, active only if authorised by the user via the cookie banner. Billing data is also disclosed to the Controller's tax adviser and, for mandatory electronic invoicing, to the Italian Revenue Agency through the Interchange System (SdI). The server is managed with Coolify, software installed on the same Hetzner machine: it involves no disclosure of data to third parties. Course videos are hosted on our own infrastructure and served through signed, expiring links, with no third-party video platform; fonts are served from our own domain and generate no requests to Google Fonts. Data is never transferred or sold to third parties for their own purposes.
6. Data Processor (art. 28 GDPR)
InTasca Srls, as provider of the technical and digital services of the site, is appointed as Data Processor pursuant to art. 28 of Regulation (EU) 2016/679, processing data on behalf of the Controller solely for purposes related to the management and maintenance of the website.
- Registered office: Via Nuova Poggioreale, Torre 7 snc — 80143 Naples (NA)
- Certified email: [email protected]
- Tax / VAT ID: 11039821217
- REA: NA - 1150116
The relationship is formalised by a specific Data Processing Agreement pursuant to art. 28 GDPR.
7. Data Protection Officer (DPO)
The Controller has assessed that, pursuant to art. 37 GDPR, the conditions that make the appointment of a Data Protection Officer mandatory do not apply, since the processing does not take place on a large scale, does not concern special categories of data or data relating to criminal convictions, and is not the core activity of a public authority.
8. Non-EU transfers
Some transfers of data to third countries — in particular the United States, via Cloudflare, Inc., Resend, Inc., Stripe, Inc. and, if authorised by the user, Google LLC — are carried out on the basis of the Standard Contractual Clauses approved by the European Commission with Decision 2021/914/EU and, where the provider has joined it, the EU-US Data Privacy Framework (adequacy decision of 10 July 2023). Hosting of the site, the database and the video files (Hetzner, Germany) and technical management (InTasca Srls, Italy) remain entirely within the European Economic Area. The user may withdraw consent to the use of non-essential cookies at any time via the preferences panel.
9. Security measures (art. 32 GDPR)
Technical and organisational measures adequate to ensure a level of security appropriate to the risk are in place: encrypted HTTPS/TLS 1.2+ communications, account passwords stored only as hashes and never in clear text, SHA-256 anonymisation and hashing of IP addresses in consent logs and security alerts, video access through signed links expiring after 2 hours and a limit on the number of devices connected to a single account, card details never passing through or stored on our servers, access to administrative areas via HTTP Basic authentication over an encrypted channel, regular system updates, and hosting on Hetzner infrastructure located in the European Economic Area.
10. Records of processing (art. 30 GDPR)
The Controller maintains a Record of processing activities pursuant to art. 30 §1 GDPR. InTasca Srls, as Processor, maintains its own record pursuant to art. 30 §2 GDPR. Both are made available to the supervisory authority on request.
11. Rights of the data subject
You may exercise the rights provided by arts. 15-22 GDPR (access, rectification, erasure, restriction, portability, objection) at any time by writing to [email protected]. You have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).
12. Cookies
For detailed information on cookies and equivalent technologies, please consult the Cookie Policy.
