Skip to main content

Privacy and Cookie Policy

In accordance with the legislation governing the processing of personal data, and in particular Article 13 of Regulation (EU) 2016/679 (“GDPR”) and Legislative Decree No. 196/2003, as amended by Legislative Decree No. 101/2018, this notice provides all useful information to explain the nature and methods of processing personal data provided through consultation of the website “https://www.eleonoraaquili.com/” (hereinafter, also the “Website”).

This notice applies solely to the Website and not to any third-party websites which may be accessed via the relevant links. It may also be subject to periodic updates or amendments, which will be notified through publication on the Website.

For the purposes of this notice, “personal data” means any information relating to an identified or identifiable natural person (the “Data Subject”); a natural person is regarded as identifiable where they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to their identity.

Data Controller and Contact Details

“Data Controller” means the natural or legal person, public authority, service or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

The data controller in respect of the data collected through the Website is Eleonora Aquili, with professional office at Via delle Magnolie 35, 37024, Negrar di Valpolicella (VR), Tax Code QLALNR87C61E388L and VAT No. 05182190230 (the “Controller”).

At any time, the Data Subject may contact the Controller for information concerning the processing of their data, as well as to exercise the rights described in the section below: 

  • by email at Questo indirizzo email è protetto dagli spambots. È necessario abilitare JavaScript per vederlo., or
  • by certified email (PEC) at Questo indirizzo email è protetto dagli spambots. È necessario abilitare JavaScript per vederlo..

Categories of personal data

Browsing Data 

When you visit the Website, our servers temporarily store each access in a log file. In particular, the following technical data is stored until automatic deletion, which takes place after a maximum period of 2 years: the IP address of the requesting computer, the name of the owner of the IP address range, the date and time of access, the website from which access was made (Referer URL), where applicable together with the search term used, the name and URL of the files retrieved, the status code, your computer’s operating system, the browser used, and the transmission protocol used.

Cookies or Similar Technologies

Cookies are information files which the user’s browser automatically stores on the device’s hard drive during visits to the Website and which make it possible to collect information about the user’s browsing activity.

Cookies are stored, according to the user’s preferences, by the individual browser on the specific device used (computer, tablet, smartphone). Similar technologies, such as transparent GIFs and all forms of local storage introduced with HTML5, may also be used to collect information on user behaviour and service usage. Accordingly, below we refer to cookies and all similar technologies simply as “cookies”.

Each cookie has an owner indicating to whom it belongs. The owner corresponds to the domain specified in the cookie. Cookies installed by the Website the user is visiting are referred to as “first-party” cookies, whereas cookies installed by another owner, such as social media platforms or providers of advertising networks or advertising technology, are referred to as “third-party” cookies.

The Website uses technical or functional cookies only, which are essential for the proper functioning of the Website and for the use of certain features. Without technical cookies, the services ordinarily offered through the Website may be partially or wholly inaccessible. As these cookies are necessary for browsing and for use of the requested services, the Controller does not require the Data Subject’s consent for their installation, which takes place automatically upon access to the Website. 

The duration of installed cookies may be limited to the browsing session or may extend for a longer period, including after the user has left the Website. These are known as persistent cookies, and their duration is set by the server at the time they are created. Cookies may nevertheless be disabled, removed or blocked by using the Do Not Track option, where available, or through the browser settings. In that case, it may no longer be possible to access certain areas of the Website or to use some of the services offered.

Below are links to the main browsers for changing session settings.

Chrome 

Firefox

Edge

Opera 

Safari 

With regard to any cookies installed by third parties, you may also manage your settings by visiting the relevant opt-out link (where available), using the tools described in the third party’s privacy policy, or contacting the third party directly.

List of Cookies Used on the Website

Name

Provider

Type

Purpose

Duration

Joomla session cookie (random alphanumeric name)

First party – eleonoraaquili.com

Technical / Functional

Initialises and maintains the user's session and enables the proper functioning and security of the Website, including form functionality.

Session

Completion of the Contact Form

The Website contains a form through which requests may be sent to the Controller. The Controller may therefore process the personal data entered in the form, such as first name, surname and email address, together with any other data and information included in the request.

Users are advised never to enter special categories of data within the meaning of Article 9 GDPR in the free-text fields, such as data concerning physical conditions or health.

Purposes of Processing, Legal Basis, and Nature of the Provision of Data

Browsing Data

The processing of this data enables use of the Website and allows the Controller to ensure the security and stability of the system. In addition, this data may be used to establish liability in the event of cyber offences affecting the Website, attacks on the network infrastructure, or other unauthorised or improper use of the Website.

The provision of this data is mandatory when browsing the Website, and the legal basis for this type of processing is the Controller’s legitimate interest pursuant to Article 6(1)(f) GDPR.

Cookies or Similar Technologies

The provision of data relating to the installation of technical cookies or equivalent technologies is mandatory when browsing the Website; the legal basis for processing this data is the Controller’s legitimate interest pursuant to Article 6(1)(f) GDPR in ensuring the functionality of the Website. Should cookies other than technical cookies be installed, the processing will be based on the Data Subject’s consent, provided through the cookie banner.

Completion of the Contact Form

The provision of data submitted through the form is optional, but necessary in order to enable the Controller to respond to requests.

The legal basis for processing the data provided through completion of the contact form is the necessity to take steps at the Data Subject’s request prior to entering into a contract, pursuant to Article 6(1)(b) GDPR.

The Controller may also process the data provided in order to prevent abuse and fraud, for the establishment, exercise or defence of the Controller’s rights in legal proceedings, and for the disclosure of data to public bodies and authorities in accordance with statutory and regulatory provisions. In such cases, the legal basis for the processing is, respectively, the Controller’s legitimate interest and compliance with legal obligations, pursuant to Article 6(1)(c) and (f) GDPR.

Methods of Processing 

Personal data will be processed primarily by electronic means, with the adoption of specific security measures designed to prevent any personal data breach, including loss of data, unlawful or improper use, and unauthorised access. However, due to the nature of online transmission, such measures cannot completely limit or exclude any risk of unauthorised access or data loss. For this reason, users are advised to check periodically that they have appropriate software tools to protect data transmission over the network, both incoming and outgoing (such as up-to-date antivirus systems), and that their internet service provider has adopted suitable measures to ensure the security of data transmission over the network (such as firewalls and antispam filters).

Data Retention Period

Browsing data will be retained for a maximum period of 2 years, while further information concerning cookie retention periods is available in the relevant section.

Personal data provided through the contact form will be retained for the time necessary to deal with the relevant request, unless a new and further purpose of processing arises.

Where processing becomes necessary in order to pursue further legitimate interests of the Controller (for example, to prevent abuse and fraud, or for the establishment, exercise or defence of a right) or to comply with legal obligations, the retention period will vary depending on the applicable legal framework.

Thereafter, once the above reasons for processing no longer apply, the data will be deleted, destroyed, or retained in anonymised form.

Recipients of Personal Data and Transfers Outside the EEA

Personal data will never be assigned or sold to third parties, nor disclosed to third parties, except where this is indispensable, and only to the extent strictly necessary to achieve the processing purposes described above.

Accordingly, the data may be disclosed:

  • to public bodies and administrative authorities, for compliance with legal obligations
  • to third-party professionals, consultants, legal advisors or service companies engaged by the Controller for the management or maintenance of the Website. Where the legal conditions are met, such parties are appointed by the Controller from time to time as data processors pursuant to Article 4(8) GDPR. The Data Subject may at any time request from the Controller the updated list of data processors.

Personal data will be processed within the European Economic Area. 

Any transfer of data outside the European Economic Area or to an international organisation will take place in accordance with the applicable legal provisions, in particular the rules set out in Chapter V of the GDPR. In such case, the Controller will provide any further information regarding the conditions underlying the transfer. 

Rights

In relation to the processing of their data, the Data Subject may exercise the rights listed below by submitting a specific request to the Controller using the contact details set out above.

For a better understanding of these rights, please consult Articles 15 et seq. of the GDPR in full.

Right of Access (Article 15 GDPR)

The Data Subject may request confirmation as to whether or not data concerning them is being processed and, if so, may obtain access to their personal data and further information relating to the processing.

Right to Rectification (Article 16 GDPR)

The Data Subject may request that the data provided or otherwise held by the Controller be rectified or completed if inaccurate or incomplete.

Right to Erasure (the so-called “Right to be Forgotten”) (Article 17 GDPR)

The Data Subject may request that data acquired or processed by the Controller be erased without undue delay where, alternatively:

  • it is no longer necessary for the purposes for which it was collected 
  • consent has been withdrawn and there is no other legal basis for the processing 
  • the Data Subject has objected to the processing of their personal data 
  • the data has been processed unlawfully 
  • there is a legal obligation to erase the data.

Right to Restriction of Processing (Article 18 GDPR)

The Data Subject may request restriction of the processing of personal data where one of the following circumstances applies: (i) the Data Subject contests the accuracy of their data, for the period necessary for the Controller to verify its accuracy; (ii) the processing is unlawful and the Data Subject opposes the erasure of the data, requesting instead that its use be restricted; (iii) although the Controller no longer requires the data for processing purposes, it is required for the establishment, exercise or defence of the Controller’s rights in legal proceedings; (iv) the Data Subject has objected to processing pursuant to Article 21(1) GDPR, pending verification as to whether the Controller’s legitimate grounds override those of the Data Subject.

Right to Data Portability (Article 20 GDPR)

The Data Subject has the right (i) to receive their data in a structured, commonly used and machine-readable format, (ii) to have it transmitted directly by the Controller to another controller designated by the Data Subject, where technically feasible, and (iii) to transmit it to another controller without hindrance from the Controller.

Right to Object (Article 21 GDPR)

The Data Subject may object at any time, on grounds relating to their particular situation, to the processing of their data carried out on the basis of Article 6(1)(e) or (f) GDPR, including profiling based on those provisions.

Right Not to Be Subject to Automated Decision-Making (Article 22 GDPR)

The Data Subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.

Right to Withdraw Consent (Article 7, par. 3 GDPR)

The Data Subject may withdraw at any time any consent previously given to the Controller, without affecting the lawfulness of processing based on consent before its withdrawal.

Lastly, the Data Subject always has the right to lodge a complaint with the competent Supervisory Authority.

Last Updated: 14 September 2026