[ LEGAL / PRIVACY / 2026 ]
PRIVACY POLICY
What we collect and why.
01 / WHO WE ARE
This site is operated by Alessandro Mandruzzato (the "Controller"), an individual, based in Monaco and on the French Riviera.
The Controller can be reached at alessandromandruzzato13@gmail.com.
This policy is written in plain language. It has legal force under the GDPR (EU 2016/679) and applicable Italian legislation.
02 / WHAT WE COLLECT
When you write to us by email, we keep the email address you write from, your name (if provided), the message body and any attachments.
When you browse the site, our hosting provider (Vercel Inc., with EU servers) records anonymous technical logs: truncated IP address, user-agent, requested URL, timestamp. These are used to keep the site running and secure.
We do not use profiling cookies. We do not use analytics tools that track users over time. See also the Cookie Policy.
03 / WHY WE USE IT (LEGAL BASIS)
Emails you send are used to reply to you and manage the conversation (legal basis: execution of a request from the data subject, art. 6.1.b GDPR).
Vercel logs are processed under the legitimate interest of running the site safely (art. 6.1.f GDPR).
We do no profiling, no automated marketing, no automated decisions.
04 / WHO WE SHARE IT WITH
Emails pass through Google (Gmail, EU/US servers under Standard Contractual Clauses). The site is hosted by Vercel Inc. (EU/US servers).
We do not sell, transfer or share your data with third parties for marketing purposes.
We may share data only when required by law (judicial authority request) or to defend ourselves in court.
05 / HOW LONG WE KEEP IT
Emails are kept for the duration of the conversation and up to 24 months from the last interaction, after which they are archived or deleted on request.
Vercel technical logs are kept according to Vercel's own policy (typically 30 days).
06 / YOUR RIGHTS
Under the GDPR you can ask, at any time, for:
— access to your data;
— rectification of inaccurate data;
— erasure ("right to be forgotten");
— restriction of processing;
— portability in a structured format;
— objection to processing.
To exercise these rights, write to alessandromandruzzato13@gmail.com. We reply within 30 days.
You also have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it) or with the competent authority in your country of residence.
07 / SECURITY
Data is protected by standard technical measures: HTTPS, two-factor authentication on critical accounts, encrypted backup. No system is perfect: in case of a meaningful breach, we will notify you within 72 hours as required by art. 33 GDPR.
08 / MINORS
This site is not intended for users under 16. We do not knowingly collect data from minors. If you are a parent and believe your child has sent us data, write and we will remove it.
09 / UPDATES
This policy may change. The current version is shown at the bottom of the page. Material changes are announced via a homepage notice for at least 30 days.
Current version: 2026-05-01.