Privacy Policy of ugovita.com

Last updated: 9 September 2026

This Privacy Policy explains how personal data relating to visitors and users of www.ugovita.com (the “Website”) is collected, used, stored and protected.

The Website is operated by Ugo Vita, freelance professional based in Italy, acting as Data Controller under Regulation (EU) 2016/679 (“GDPR”).

This Privacy Policy has been prepared in accordance with Regulation (EU) 2016/679, Italian Legislative Decree No. 196/2003, as subsequently amended, the rules implementing Directive 2002/58/EC on privacy and electronic communications, including Article 122 of the Italian Privacy Code, and the applicable guidelines and decisions of the Italian Data Protection Authority (“Garante per la protezione dei dati personali”).

1. Data Controller

The Data Controller is:

Ugo Vita
Website: www.ugovita.com
Country: Italy
Email: idea@ugovita.com

Requests concerning privacy or the exercise of data protection rights may be sent to the email address above.

Given the nature and scale of the processing activities currently carried out through the Website, a Data Protection Officer (“DPO”) has not been appointed.


2. Scope of this Privacy Policy

This Privacy Policy applies to personal data processed through the Website and its related services.

It does not apply to third-party websites or services that may be accessible through external links appearing on the Website. Such third parties process personal data in accordance with their own privacy policies and terms.

The Website is primarily a professional portfolio and information website through which visitors may view Ugo Vita’s work and services and contact him regarding potential professional collaborations.

The Website does not currently provide:

  • user registration or personal user accounts;
  • e-commerce or online payment services;
  • public comments or discussion forums;
  • newsletter subscription;
  • automated credit or eligibility decisions;
  • user profiling carried out directly by Ugo Vita for advertising purposes.

3. Categories of personal data processed

Depending on how the Website is used, the following categories of personal data may be processed.

3.1 Browsing and technical data

The computer systems and software procedures used to operate the Website may automatically acquire technical information as part of their normal operation.

This information may include:

  • IP address;
  • date and time of access;
  • requested URL or resource;
  • HTTP request information;
  • response status;
  • browser type and version;
  • operating system;
  • device information;
  • screen characteristics;
  • referring page or website;
  • technical identifiers;
  • information necessary for the security and proper operation of the Website.

Some of this information may constitute personal data under applicable data protection legislation.

These data are mainly processed to operate the Website, ensure its security, detect technical problems, prevent abuse, spam and cyberattacks and generate technical and statistical information.

3.2 Data submitted through the contact form

The Website contains contact forms that visitors may use to request information or discuss potential projects or professional collaborations.

The information that may be collected includes:

  • name;
  • email address;
  • company or organisation, where provided;
  • type of service or area of interest selected by the user;
  • content of the message;
  • any additional information voluntarily included in the message.

Fields marked as mandatory are necessary in order to process and respond to the request.

Visitors are requested not to include unnecessary sensitive information or special categories of personal data, such as health information, political opinions, religious beliefs, biometric data or other particularly sensitive information, in the message field.

3.3 Data provided through direct email communications

If a visitor contacts the Data Controller directly by email, personal data contained in the message, email headers, signature and any attachments will be processed in order to respond to the communication and, where applicable, manage a professional or pre-contractual relationship.

3.4 Cookie and consent preference information

The Website uses a consent management platform to record the user’s choices regarding cookies and other tracking technologies.

Depending on the configuration and service plan used, information processed for this purpose may include:

  • consent identifier;
  • consent status;
  • categories of cookies accepted or rejected;
  • date and time of the choice;
  • country or approximate geographic information;
  • pseudonymised or otherwise minimised technical identifiers.

This information is used to remember the visitor’s choices and, where necessary, demonstrate that valid consent has been obtained.

Further information is provided in the Website’s Cookie Policy and through the cookie settings interface.


4. Purposes and legal bases of processing

Personal data are processed only where an appropriate legal basis exists under Article 6 GDPR.

Responding to contact and project enquiries

Data submitted through the contact form or by email are processed in order to:

  • respond to requests;
  • provide information about services;
  • assess possible collaborations;
  • prepare quotations or proposals;
  • take steps requested by the user before entering into a possible professional agreement.

Legal basis: Article 6(1)(b) GDPR – processing necessary to take steps at the request of the data subject prior to entering into a contract.

Consent is therefore not normally the legal basis required merely to respond to a contact or quotation request.

Website operation and technical administration

Technical and browsing data may be processed in order to provide the Website, diagnose technical problems, maintain functionality and ensure network and information security.

Legal basis: Article 6(1)(f) GDPR – legitimate interest of the Data Controller in providing a functional, reliable and secure Website.

Prevention of spam, abuse and cyberattacks

Technical data may be processed to identify automated traffic, malicious activity, unauthorised access attempts, spam and other security threats.

Legal basis: Article 6(1)(f) GDPR – legitimate interest in protecting the Website, its systems and users.

Compliance with legal obligations

Personal data may be processed where necessary to comply with legal, regulatory, accounting, tax or judicial obligations applicable to the Data Controller.

Legal basis: Article 6(1)(c) GDPR.

Website analytics

Where Google Analytics or similar analytics technologies require access to or storage of information on the user’s device and do not qualify for the exemption applicable to strictly technical tools, they are activated only after the user has provided the appropriate consent through the cookie management system.

Legal basis: Article 6(1)(a) GDPR – consent, together with the applicable rules concerning cookies and other tracking technologies.

Consent may be refused or withdrawn at any time without affecting access to the essential functions of the Website.

Third-party multimedia and interactive content

Where embedded services such as YouTube or Google Maps use non-essential cookies, identifiers or other tracking technologies, their activation is subject to the visitor’s prior choice where required by applicable law.

Legal basis: Article 6(1)(a) GDPR – consent, where required.

Recording cookie preferences

Information necessary to store, respect and demonstrate the user’s privacy choices may be processed in order to comply with applicable data protection and electronic communications rules.

Legal basis: Article 6(1)(c) GDPR and, where applicable, Article 6(1)(f) GDPR.


5. Contact Form 7

The Website uses Contact Form 7 to provide its contact forms.

The information entered by the user is used for the sole purpose of transmitting the request to the Data Controller and allowing a response.

In its standard configuration, Contact Form 7 does not create an independent archive of submitted messages in the WordPress database. Messages are transmitted through the Website’s email infrastructure.

If additional message-storage plugins or integrations are introduced in the future, this Privacy Policy will be updated where necessary.

The contact form is protected against automated submissions and spam through Cloudflare Turnstile.


6. Cloudflare Turnstile

The Website uses Cloudflare Turnstile, a security service provided by Cloudflare, to distinguish legitimate human interactions from automated or malicious traffic and to protect the contact forms from spam and abuse.

Turnstile may process technical signals such as:

  • IP address;
  • user-agent information;
  • TLS or network-related characteristics;
  • website/site key information;
  • origin of the request;
  • other technical security signals.

These data are used for bot detection and security purposes and are not used by the Data Controller for advertising or behavioural profiling.

For the provision of Turnstile to the Website, Cloudflare may act as a processor on behalf of the Website operator. Cloudflare may also process certain information as an independent controller where this is necessary for improving its security and bot-detection systems, in accordance with its own privacy documentation.

Purpose: spam prevention, security and abuse prevention.

Legal basis: Article 6(1)(f) GDPR – legitimate interest in protecting the Website and its communication channels.

Where Turnstile’s technical storage or access is strictly necessary to provide the requested security function, it is treated as a necessary technology and does not depend on consent for advertising or analytics cookies.


7. Google Analytics

The Website may use Google Analytics 4 (“GA4”), provided by Google, to obtain statistical information regarding Website use.

Google Analytics may process information including:

  • pages viewed;
  • sessions and interactions;
  • approximate geographical area;
  • device type;
  • operating system;
  • browser characteristics;
  • screen resolution;
  • traffic source;
  • interaction events;
  • technical identifiers associated with the browser or device.

For users located in the European Economic Area, Switzerland and the United Kingdom, Google states that individual IP addresses are not logged or stored by Google Analytics. IP information may be used to derive approximate geographical information before being discarded.

Google Analytics is used for statistical and Website-improvement purposes.

The Data Controller does not use Google Analytics to make decisions producing legal or similarly significant effects concerning individual visitors.

Where required by applicable cookie and tracking rules, Google Analytics is activated only after consent has been expressed through the Website’s cookie banner.

The visitor may subsequently withdraw such consent through the Website’s cookie settings.

User-level Analytics data are retained according to the configuration of the relevant GA4 property and, in any event, for no longer than the maximum retention period configured for the service, currently up to 14 months for the relevant user-level data.

The Website should not transmit information such as names, email addresses or message contents to Google Analytics.


8. YouTube embedded videos

The Website uses videos hosted on YouTube, a service operated by Google.

When a YouTube player is activated, Google may receive technical information concerning the visitor and the visitor’s interaction with the embedded content.

Depending on the visitor’s settings and whether the visitor is logged into a Google account, such information may be associated with other information held by Google.

Where technically appropriate, the Website may use YouTube’s privacy-enhanced embedding mode (youtube-nocookie.com) in order to reduce the use of information for personalised browsing and advertising purposes.

Where the activation of embedded YouTube content involves non-essential tracking technologies, such content must not be activated until the visitor has made the appropriate choice through the Website’s consent management system.

Visitors who do not wish to activate embedded YouTube content may continue to use the remainder of the Website.


9. Google Maps

The Website uses Google Maps on the contact page in order to display geographical information.

When Google Maps content is activated, Google may process technical information including the IP address of the requesting device and information relating to the browser and interaction with the map.

Google may process such data in accordance with its own privacy documentation and Google Maps terms.

The Website does not intentionally transmit the contact form content to Google Maps.

Where Google Maps requires non-essential cookies or other tracking technologies, the map should be activated only after the appropriate user choice has been obtained through the Website’s consent management platform.

A visitor may use the contact form and contact the Data Controller without being required to activate Google Maps.


10. CookieYes consent management

The Website uses CookieYes as a Consent Management Platform (“CMP”) in order to:

  • display the cookie information banner;
  • collect cookie preferences;
  • allow users to accept or reject categories of non-essential technologies;
  • store and respect user choices;
  • allow users to change their preferences;
  • provide evidence of consent where required.

CookieYes may process technical information associated with the consent record, which may include a consent identifier, consent status, date and time, country and a minimised or pseudonymised network identifier, depending on the service configuration.

A necessary cookie may be stored in order to remember the user’s cookie preferences.

The retention of consent records depends on the configuration and subscription used and is limited to the period reasonably necessary to demonstrate the visitor’s choices and comply with applicable obligations.


11. Website security – Wordfence

The Website uses Wordfence or equivalent security technologies to protect the WordPress installation against:

  • malicious traffic;
  • brute-force attacks;
  • unauthorised access;
  • malware;
  • exploitation of known vulnerabilities;
  • other security threats.

Security systems may process technical information such as IP addresses, request data, browser or user-agent information, login activity and security event information.

These data are processed only to the extent necessary for Website and network security, fraud and abuse prevention and investigation of security incidents.

Legal basis: Article 6(1)(f) GDPR – legitimate interest of the Data Controller in maintaining the confidentiality, integrity and availability of the Website and its systems.

Where the security provider acts on behalf of the Data Controller, the relationship is governed by the applicable contractual and data-protection arrangements.


12. Hosting and infrastructure

The Website is hosted using infrastructure provided by Aruba S.p.A.

Hosting providers may necessarily process technical and server information in connection with the provision, maintenance, backup, availability and security of the Website.

This may include server logs containing:

  • IP addresses;
  • requested resources;
  • date and time;
  • browser or protocol information;
  • error information;
  • technical security events.

Hosting and infrastructure data are processed for the operation and security of the Website.

The Data Controller selects infrastructure and service providers that provide appropriate organisational and technical safeguards in accordance with applicable data protection requirements.


13. Cookies and other tracking technologies

The Website uses both technologies that are strictly necessary for operation and security and, subject to user choice where required, optional analytics or third-party technologies.

Strictly necessary cookies and technologies may be used without prior consent where their sole purpose is to enable communication or provide a service expressly requested by the visitor.

Optional analytics, profiling or equivalent tracking technologies are activated only where the conditions required by applicable legislation have been met.

Detailed and dynamically updated information concerning individual cookies, their provider, purpose and duration is provided through the Website’s Cookie Policy and cookie management interface.

Users may change their cookie choices at any time through the consent management tool available on the Website.

Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.


14. Recipients of personal data

Personal data may be accessible, to the extent strictly necessary for their respective activities, to:

  • the Data Controller;
  • hosting and infrastructure providers;
  • email service providers;
  • technical Website maintenance providers, where applicable;
  • security and anti-spam providers;
  • consent management providers;
  • analytics providers, subject to the applicable user choices;
  • providers of embedded multimedia or map services, subject to the applicable user choices;
  • accountants, legal advisers or other professional advisers where necessary;
  • public authorities, courts or law-enforcement authorities where disclosure is required by law.

Service providers processing data on behalf of the Data Controller are appointed or otherwise governed in accordance with Article 28 GDPR where applicable.

The main technology providers currently relevant to the Website may include:

  • Aruba S.p.A. – hosting and infrastructure;
  • Google Ireland Limited / Google LLC – Google Analytics, YouTube and Google Maps;
  • Cloudflare, Inc. – Turnstile and Website security services;
  • CookieYes Limited – consent management;
  • Defiant, Inc. / Wordfence – WordPress security services.

Personal data are not sold by the Data Controller.


15. International transfers of personal data

Some technology providers used by the Website belong to international groups and may process or make data accessible from countries outside the European Economic Area (“EEA”), including the United States.

Where personal data are transferred outside the EEA, such transfers are carried out only where a valid transfer mechanism under Chapter V GDPR exists.

Depending on the provider and processing operation, these mechanisms may include:

  • an adequacy decision adopted by the European Commission under Article 45 GDPR;
  • participation by an eligible US recipient in the EU-U.S. Data Privacy Framework;
  • Standard Contractual Clauses approved by the European Commission under Article 46 GDPR;
  • supplementary contractual, technical or organisational safeguards where required.

At the date of this Privacy Policy, the European Commission recognises participating commercial organisations in the United States under the EU-U.S. Data Privacy Framework as providing adequate protection.

Google LLC and Cloudflare have declared their participation in the EU-U.S. Data Privacy Framework.

Where another valid transfer mechanism is required, the relevant provider’s contractual safeguards will apply.


16. Data retention

Personal data are retained only for as long as necessary for the purpose for which they were collected, taking into account legal obligations and the need to establish, exercise or defend legal claims.

In particular:

Contact and project enquiries

Information received through the contact form or direct email may normally be retained for up to 24 months from the last meaningful communication concerning the enquiry.

If the enquiry results in a professional relationship, information necessary for the contractual, administrative, accounting or legal relationship may be retained for the longer period required under applicable civil, accounting and tax legislation.

Website and security logs

Technical logs are retained for the period reasonably necessary for operation, troubleshooting, security monitoring and prevention or investigation of abuse.

Logs relating to suspected attacks, fraud, unauthorised access or other security incidents may be retained for a longer period where necessary to investigate the incident or establish, exercise or defend legal claims.

Google Analytics

User-level Analytics data are retained according to the configuration of the Google Analytics property and in any case for no longer than the maximum period selected for the service, currently up to 14 months for the relevant user-level data.

Consent records

Cookie preference and consent records are retained for the period reasonably necessary to demonstrate and respect the visitor’s choices and in accordance with the configuration and retention period of the consent management platform.

Data may be retained for a longer period where this is necessary to comply with a legal obligation or an order issued by a competent authority.


17. Mandatory and optional provision of data

Browsing the public areas of the Website does not require users to provide their name or contact details.

Providing data through the contact form is voluntary.

However, information marked as mandatory is necessary in order to respond to the request. If such information is not provided, the Data Controller may be unable to process the enquiry.

Consent to optional analytics or third-party tracking technologies is not required in order to access the essential content and functionality of the Website.


18. Processing methods and security

Personal data are processed using electronic and, where necessary, organisational procedures designed to protect them against:

  • unauthorised access;
  • alteration;
  • accidental or unlawful disclosure;
  • destruction;
  • loss;
  • misuse.

The Website uses appropriate security measures which may include encrypted HTTPS connections, access controls, security monitoring, WordPress security tools, anti-spam systems, updates, backups and infrastructure-level protections.

No Internet-based system can guarantee absolute security. The Data Controller nevertheless takes measures proportionate to the nature of the Website and the risks presented by the processing.

Access to personal data is limited to persons and service providers who require such access for legitimate purposes.


19. Special categories of personal data

The Website is not intended to collect special categories of personal data within the meaning of Article 9 GDPR.

Visitors should therefore avoid submitting information concerning, for example:

  • health;
  • racial or ethnic origin;
  • political opinions;
  • religious or philosophical beliefs;
  • trade-union membership;
  • genetic or biometric information;
  • sex life or sexual orientation,

unless strictly necessary and an appropriate legal basis exists.

If unnecessary sensitive information is received inadvertently, the Data Controller may delete it where appropriate.


20. Data relating to minors

The Website promotes professional creative services and is not specifically directed at children.

The Data Controller does not knowingly request personal data from minors through the Website.

If a parent or legal guardian believes that a minor has submitted personal data inappropriately, they may contact the Data Controller to request its deletion where applicable.


21. Automated decision-making and profiling

The Data Controller does not use personal data collected through the Website to make decisions based solely on automated processing that produce legal effects or similarly significantly affect individuals within the meaning of Article 22 GDPR.

The Data Controller does not use information submitted through the contact form for automated profiling.

Third-party analytics or multimedia providers may independently process information according to their own privacy policies and the user’s applicable consent choices.


22. Rights of data subjects

Under Articles 15 to 22 GDPR, where the applicable conditions are met, data subjects have the right to:

  • obtain confirmation as to whether their personal data are being processed;
  • obtain access to their personal data;
  • obtain rectification of inaccurate data;
  • obtain completion of incomplete data;
  • request erasure of personal data;
  • request restriction of processing;
  • receive personal data in a structured, commonly used and machine-readable format where the right to data portability applies;
  • object to processing based on legitimate interests;
  • withdraw consent at any time where processing is based on consent;
  • not be subject, where applicable, to decisions based solely on automated processing that produce legal or similarly significant effects.

Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Requests may be submitted to:

idea@ugovita.com

The Data Controller will normally respond within the time limits established by the GDPR.

Where there are reasonable doubts concerning the identity of the person making the request, additional information may be requested solely for the purpose of confirming their identity.


23. Right to lodge a complaint

Data subjects have the right to lodge a complaint with a competent supervisory authority under Article 77 GDPR if they believe that the processing of their personal data infringes applicable data protection legislation.

For processing subject to Italian law, the competent supervisory authority is:

Garante per la protezione dei dati personali
Italian Data Protection Authority
www.garanteprivacy.it

The right to lodge a complaint is without prejudice to any other administrative or judicial remedy available under applicable law.


24. External websites and services

The Website may contain links to third-party websites, platforms or social networks.

When a visitor voluntarily follows such a link, the third party becomes responsible for the processing carried out through its own website or service.

The Data Controller has no control over the privacy practices of independent third-party websites and recommends reviewing their privacy information before providing personal data.


25. Changes to this Privacy Policy

This Privacy Policy may be updated to reflect:

  • changes to the Website;
  • addition, removal or modification of services and technologies;
  • changes to processing activities;
  • changes to providers;
  • changes to applicable legislation or regulatory guidance.

The current version will always be published on this page together with the date of the latest update.

Where a change materially affects processing based on consent, new consent will be obtained where required by law.

Last updated: 9 September 2026