Via S. Elia 144, 70033 Corato (BA), Italy080 8722584

Navigation

Privacy Policy

Last updated: 17 September 2026

Privacy information under Articles 12, 13 and, where applicable, 14 of Regulation (EU) 2016/679 (GDPR) and applicable Italian law, including Legislative Decree 196/2003, as amended.

1. Data controller

The controller is VASALLUCCI GIOVANNI, an individual business operating under the commercial name Arredo Interni Vasallucci, with its registered office and business address at Via S. Elia 144, 70033 Corato (BA), Italy. VAT number: IT04420150726. Italian tax code: VSLGNN65T20A285E.

Website: https://arredointernivasallucci.it. For privacy enquiries and to exercise your rights, write to info@arredointernivasallucci.it. Telephone: +39 080 8722584. Mobile: +39 339 4090143. You may also write to the business address above.

2. Scope and sources of personal data

This policy covers personal data processed through the website, including browsing, contact requests, technical operation, security, administration and optional external content. It also covers correspondence arising from requests received. Third-party websites reached through links have their own privacy information.

Data is supplied directly by the individual or generated through use of the website and its services. If a request contains another person’s data, such as a business contact’s details, that information comes from the sender. Such data is processed only insofar as relevant to the request, and the controller provides information to the individual within the periods prescribed by Article 14 GDPR where applicable, subject to statutory exceptions. Anyone providing another person’s data must be entitled to do so and should provide only necessary information.

3. Categories of personal data

  • Browsing and technical data: IP address, request date and time, requested resource, HTTP status, referrer where available, browser and device information, and data in server, error and security logs.
  • Contact data: name, email address, optional telephone number and subject, message, language and submission date and time, together with information in subsequent correspondence.
  • Anti-abuse and CAPTCHA data: random visitor identifier, IP-derived and email-derived HMAC values, message fingerprints, temporary counters, challenges, solutions, verification tokens and technical information needed for security checks.
  • Administrative data: authorised account details, protected credentials, roles, sessions, authentication and security events, editing history and technical preferences.
  • Consent and preferences: consent-schema version, External content choice, choice date and expiry; selected light/dark appearance and functional browser information.
  • Google Maps data: only after External content is authorised, connection and browser/device data, page-origin context and interactions that the service may receive.

The form does not intentionally request special-category data, such as health information, religious beliefs or political opinions. Please do not include unnecessary sensitive information or irrelevant information about other people.

4. Contact requests and legal bases

Name, email address and message are required; telephone number and subject are optional. We use this information to manage your request, provide information and respond, including relevant follow-up correspondence.

For quotation requests and other pre-contractual enquiries, the legal basis is Article 6(1)(b) GDPR: steps taken at the individual’s request before entering into a contract. For other ordinary correspondence and protection against abuse, Article 6(1)(f) GDPR may apply, based on the legitimate interests in responding to communications and protecting the business and its services, taking individuals’ rights into account. Any processing required by law is based on Article 6(1)(c) GDPR.

No separate marketing consent is required to send an ordinary enquiry. Contact information is not used for newsletters or promotional campaigns; any future service of that kind would require a separate process and appropriate privacy information.

5. Anti-spam protection and CAP CAPTCHA

The form uses honeypot checks, security nonces, rate limits and duplicate-submission controls. A first-party cookie binds validation to a random visitor identifier. The server uses IP-derived and email-derived HMAC values, message fingerprints and short-lived counters. These are protected or pseudonymised technical identifiers: they are not anonymous data.

CAP CAPTCHA is operated by Mediavobis di Ardito Alfredo, with servers in Italy, through captcha-cap.mediavobis.com. The browser requests a challenge and computes a solution; the server then verifies a token to authorise submission. The service may receive the IP address, technical request and browser information, challenge outcomes and information necessary to detect abuse. Verification instrumentation may evolve: this description does not imply that no device-side processing occurs. The form’s message text is not sent to CAP for verification.

The purpose is to protect the requested service, prevent spam and harmful automated submissions, and maintain security. The legal basis is the controller’s legitimate interests under Article 6(1)(f) GDPR. Storage strictly necessary for these checks supports the secure provision of the requested service and is not conditional on consent to optional content. The short retention periods are set out in section 12 and the Cookie Policy.

6. Email communications

Form submissions are delivered to info@arredointernivasallucci.it through the email service operated by Mediavobis di Ardito Alfredo in Italy. Requests and replies are processed to manage correspondence on the legal bases described in section 4.

Email metadata and delivery logs may be processed to transmit and secure communications and troubleshoot delivery problems. These technical controls serve the legitimate interests in secure, reliable communications under Article 6(1)(f) GDPR.

7. Hosting, logs and security

The website is hosted on infrastructure operated by Mediavobis di Ardito Alfredo in Italy. Access, error and security logs may contain IP addresses, dates and times, requested resources, response status, referrer and user-agent information, together with information needed to diagnose technical events.

This information is processed to deliver the website, troubleshoot faults, protect systems and users, and prevent or investigate abuse. The legal basis is the controller’s legitimate interests in the operation and security of the website under Article 6(1)(f) GDPR.

8. Google Maps and External content

Google Maps is optional and blocked before consent: simply visiting the page does not load the map. It loads only after the External content category has been authorised, including through the “Load Google Maps” button. Consent under Article 6(1)(a) GDPR is the legal basis for this loading.

Once authorised, Google may receive your IP address, browser and device data, information about the page-origin context and interactions with the map. Google may use cookies or similar technologies and process data outside the European Economic Area (EEA). Information about processing and applicable safeguards is available in Google’s Privacy Policy and its related transfer documentation.

You may withdraw consent at any time through “Cookie preferences” in the footer by disabling External content and saving. The map is removed; withdrawal does not affect the lawfulness of earlier processing and cannot retrieve data already transmitted. Arredo Interni Vasallucci does not control Google’s subsequent independent processing.

The separate “Open directions in Google Maps” link opens the external service only following a user action. Following it takes you away from this website, and the destination service’s information and settings apply.

9. WordPress administration

Public registration is disabled. Data about administrators and other authorised operators is processed for website management, authentication, security, attribution of edits and technical preferences. The legal basis is the legitimate interests in managing and protecting the website under Article 6(1)(f) GDPR, without prejudice to any legal obligations or arrangements governing relationships with those operators.

Authentication cookies and administrative preferences relate to access to and use of restricted functions: ordinary visitors are not assigned administrator cookies merely by browsing. Public comments, trackbacks and pingbacks are disabled.

10. Recipients and technical suppliers

Data may be accessed, insofar as needed for their tasks, by people authorised by the controller, hosting, maintenance and email suppliers, the CAPTCHA/security provider and, when external content is authorised, Google. Data may also be disclosed to legal or administrative advisers, authorities or other parties where required by law or necessary to protect rights. Personal data is not sold.

Mediavobis di Ardito Alfredo is the identified technical supplier for hosting, email and CAP, and may process personal data on the controller’s behalf where applicable. Suppliers are selected and instructed according to their respective roles under applicable data-protection law; an updated list of any processors may be requested from the controller.

11. International transfers

The hosting, email and CAPTCHA infrastructure identified for this project is located in Italy. Following consent, Google Maps may involve processing or transfers outside the EEA. These operations are subject to the provider’s applicable transfer mechanisms and safeguards, described in its documentation, including adequacy decisions or standard contractual clauses where relevant. We do not state that every processing operation necessarily remains in Italy or the EEA. Please also consult external providers’ policies and contact the controller for available information about relevant safeguards.

12. Retention periods

The controller adopts the following retention periods according to the purposes and any exceptions described:

  • Ordinary contact requests: 12 months after the last communication.
  • Enquiries associated with quotations or contracts: for the duration of the relationship and subsequently for up to 10 years where necessary to establish, exercise or defend rights or comply with legal and accounting obligations.
  • SMTP delivery logs: 30 days.
  • Web server and security logs: 90 days, unless longer retention is needed for a documented security incident or legal obligation.
  • Routine backups: 90 days, subject to backup rotation.
  • CAPTCHA token replay-prevention data: 24 hours.
  • Other anti-spam information: between 10 minutes and one day depending on its function; specifically, duplicate-message fingerprints for 10 minutes, rate counters for 15 minutes and the visitor identifier for one day.
  • Consent preference: six months; the current implementation sets a maximum of 180 days from the choice.
  • Administrative accounts: until access is no longer required, subject to documents and records that must be retained by law.

The light/dark appearance preference remains on the device until the user removes it; other browser-storage durations are specified in the Cookie Policy. Retention of data processed independently by Google is governed by the provider’s information.

Exceptionally, relevant data may be retained longer for disputes, legal obligations, investigations or requests from authorities, only insofar as necessary. At the end of the applicable period, data is deleted or rendered effectively anonymous; backups are deleted through their rotation cycle and are not intended for routine use.

13. Whether providing data is mandatory

Without your name, email address and message, the form cannot be submitted and the enquiry cannot be handled properly. Telephone number and subject may be omitted. Strictly necessary technical information is processed to deliver and protect the service; blocking its storage may prevent secure form submission. External content consent is optional: refusing it does not prevent browsing or contacting us and only prevents the embedded map from loading.

14. Automated decisions

The website does not make decisions based solely on automated processing that produce legal or similarly significant effects under Article 22 GDPR. Anti-abuse systems may automatically reject or delay suspicious submissions, but do not make legally significant decisions about individuals. If you experience difficulty, you can contact us by email or telephone.

15. Your rights

Where applicable and subject to Articles 15–22 GDPR, you may request access to your data and processing information, correction of inaccurate data, completion of incomplete data, erasure and restriction of processing. You may obtain portability of data you have provided where automated processing is based on consent or a contract and the other legal conditions are met.

You may object to processing based on legitimate interests on grounds relating to your particular situation. The controller will assess the request under Article 21 GDPR, including any compelling legitimate grounds or need to protect legal claims. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal. Safeguards concerning automated decisions also apply where relevant.

These rights are not absolute: they depend on the legal basis, context and statutory exceptions. Send requests to info@arredointernivasallucci.it. Only information necessary to verify your identity may be requested. A response is normally provided within one month; any extensions within the limits of the GDPR will be communicated with reasons.

You may lodge a complaint with the Garante per la protezione dei dati personali, the competent Italian Data Protection Authority, through www.garanteprivacy.it. You also retain the right to complain to another competent supervisory authority under the GDPR, particularly where you habitually reside, work or consider an infringement to have occurred, and to seek a judicial remedy. This English translation does not change the application of Italian law.

16. Children

The website and contact service are not specifically directed at children. Do not submit information about minors unless it is necessary and you are legally authorised to provide it.

17. Security measures

Technical and organisational measures proportionate to the risks are used, including access controls, authentication, anti-abuse protections, data minimisation, protected connections where provided and backup management. Measures are assessed in light of the services and risks; no system can guarantee absolute security.

18. Changes and further information

This policy may be updated to reflect changes to services, processing or legislation. The revision date appears at the beginning of the page. Material changes to services or purposes requiring consent may result in preferences being requested again. For cookies, similar technologies and control of your choices, see the Cookie Policy.

Cookie preferences

Necessary storage is always active. You can change or withdraw your choice at any time.

Allows external services such as Google Maps to load. These providers may receive device and connection information.

Privacy Policy

Cookie Policy