Legal

Privacy Policy of
graffico.it

Welcome to the privacy policy of graffico.it. This policy will help you understand what data we collect, why we collect it and what your rights are in this regard.

Last modified: 2026-05-14Version: 2026.05.3

Data Controller

Contitolari del trattamento ex art. 26 GDPR: Andrea Fragnelli (P.IVA 04097790366, Via Arturo Toscanini 9, 41030 Bomporto MO) e Lorenzo Angelino (P.IVA 10544921215, Via Stanislao 80, 80126 Napoli NA), congiuntamente operanti come «Graffico». Punto di contatto unico per l'esercizio dei diritti dell'interessato: info@graffico.it.

Via Arturo Toscanini 9, 41030 Bomporto (MO)

Via Stanislao 80, 80126 Napoli (NA)

VAT: 04097790366, 10544921215

Email:info@graffico.it

Data Summary

Automatically collected data

We automatically collect your data, for example when you visit Graffico (di Andrea Fragnelli e Lorenzo Angelino). Includes: IP address, Usage data, Tracking Tools, number of Users, session statistics, device identifiers (user-agent, language, timezone).

Data provided by the User

We collect the data you provide us, for example when you fill out a contact form. Includes: name, email.

Details on the processing of Personal Data

Below are details on how data is collected and the third-party services we use.

Automatically collected data

Monitoring and Stats

We automatically collect your data, for example when you visit graffico.it . Includes: IP address, Usage data, Tracking Tools, number of Users, session statistics, device identifiers (user-agent, language, timezone).

Google Analytics 4

Usage dataTracking Tools

Meta Pixel

Usage dataTracking Tools

Data provided by the User

Support and Feedback

We collect the data you provide us, for example when you fill out a contact form. Includes: name, email.

Contact Form

EmailNameLast NameVarious data

Lawful bases of processing

Each processing purpose relies on a specific lawful basis pursuant to art. 6 GDPR. Below is the mapping declared by the Controller.

Details on the processing of Personal DataLawful bases of processing
Google Analytics 4Explicit consent of the data subject (art. 6.1.a GDPR)
Google AdsExplicit consent of the data subject (art. 6.1.a GDPR)
Meta PixelExplicit consent of the data subject (art. 6.1.a GDPR)
Modulo di ContattoPerformance of a contract or pre-contractual measures (art. 6.1.b GDPR)

Recipients and external data processors

Personal Data may be shared with the data processors listed below. Each processor has been selected for reliability and adequacy of technical and organizational safeguards.

Google LLC

Purpose
Google Analytics 4, Google Ads
Location
US
Transfer legal basis
DPF + SCC 2021/914
Privacy policy
Privacy policy

Meta Platforms Ireland Ltd.

Purpose
Meta Pixel, Conversion API
Location
IE/US
Transfer legal basis
SCC 2021/914
Privacy policy
Privacy policy

EmailJS Inc.

Purpose
Trasmissione form contatti
Location
US
Transfer legal basis
SCC 2021/914

Netlify Inc.

Purpose
Hosting, CDN, Functions
Location
US
Transfer legal basis
DPF

Contentful GmbH

Purpose
Headless CMS (no personal data)
Location
DE

Transfers of Personal Data outside the European Union

Some external processors are based outside the European Economic Area. Transfers occur under adequacy decisions (e.g. EU-US Data Privacy Framework) or Standard Contractual Clauses (SCC 2021/914) adopted by the European Commission, supplemented by additional measures where needed. The User can request a copy of the safeguards by contacting the Controller.

Data Retention

Personal Data is kept only for the time strictly necessary to the purposes for which it was collected.

Contact forms

Fino a richiesta dell'interessato

Analytics data

14m

Marketing data

2y

Automated decision-making and profiling

The Controller does not carry out automated decision-making or profiling that produces legal effects on the data subject or significantly affects them, pursuant to art. 22 GDPR. Any analytics tools (e.g. Google Analytics, Meta Pixel) are used for aggregated measurement and not for individual automated decisions.

Method and place of processing

The Controller takes appropriate security measures to prevent unauthorized access, disclosure, modification or destruction of Personal Data. Processing is carried out using computers and/or IT enabled tools, with organizational methods and logic strictly related to the purposes indicated.

The Data is processed at the Controller's operating offices and in any other places where the parties involved in the processing are located. Unless otherwise stated, Personal Data is processed and stored for the time required by the purpose for which it was collected.

Your Rights (GDPR)

  • Withdraw consent at any time
  • Object to the processing of your Data
  • Access your Data
  • Verify and seek rectification
  • Obtain restriction of processing
  • Obtain erasure or removal
  • Receive your Data or have it transferred to another controller
  • Lodge a complaint with the Supervisory Authority (Italian Garante)

How to exercise rights

Requests should be addressed to the Controller's contact details indicated in this document. The request is free of charge and we will respond as soon as possible.

Supervisory Authority

Pursuant to art. 13.2.d and 77 GDPR, the data subject has the right to lodge a complaint with the competent supervisory authority where they consider that the processing of their personal data infringes applicable law.

Italian Data Protection Authority (Garante per la Protezione dei Dati Personali)

Address
Piazza Venezia 11, 00187 Rome (Italy)
Website
Website

Definitions and legal references

Personal Data

Any information that, directly or indirectly, makes a natural person identified or identifiable.

Usage Data

Information collected automatically through this Application (e.g. IP addresses, time of request, browser used).

Data Controller

The natural or legal person who determines the purposes and means of the processing of personal data.

Cookie

Small portions of data stored within the User's browser.