About this notice
This notice explains how Viglietti Sergio (the “controller”) processes the personal data of people who visit the website Viglietti (https://www.viglietti.com) and of people who contact the controller using the details given on the website.
It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”) and of Italian Legislative Decree 196/2003, the Personal Data Protection Code (the “Italian Privacy Code”), as amended by Legislative Decree 101/2018.
It covers this website only: websites of others that you reach through links have their own notices.
Cookies and other tracking tools are described in the cookie policy, which completes this notice.
Data controller
The controller is Viglietti Sergio.
- Registered office: Via Duca d'Aosta 2a, 18038 Sanremo (IM)
- VAT number: IT01056300088
- REA IM - 89069
- Email for privacy requests: info@viglietti.com
- Phone: +39 0184 51 38 39
If you have questions about this notice or about how your data is processed, you can write to the email address above.
Data Protection Officer (DPO)
The controller has not appointed a Data Protection Officer (DPO). For any question about the processing of your personal data you can write to info@viglietti.com.
What data is processed
Browsing data
The IT systems and software that run the website collect, in the course of their normal operation, some technical data whose transmission is implicit in the use of internet protocols: for example the IP address, the date and time of the request, the page requested, the response status, and the type of browser and operating system. This data is used to run the website, to check that it works properly and to protect it from abuse and cyber attacks. It is not collected to identify you, but it may be used to establish liability in the event of computer crimes against the website.
Data you provide
If you contact the controller, for example by email or by phone, the data you share (such as your name, email address, phone number and the content of your message) is processed to reply to you and to follow up on your request. Please do not send data that your request does not need, especially health data or other special categories of data (Article 9 GDPR).
Cookies and tracking tools
The website uses technical cookies and, only with your consent, other cookies and tracking tools. The details are in the cookie policy.
Purposes, legal bases and retention
| Purpose | Legal basis | Retention |
|---|---|---|
| Running the website, keeping it secure and preventing abuse (browsing data) | The controller's legitimate interest in offering a working and secure website (Article 6(1)(f) GDPR) | For the time strictly needed for these purposes; longer only if needed to establish crimes or abuse |
| Replying to your requests and following up on your contacts | Pre-contractual measures or performance of a contract, if the request concerns products or services (Article 6(1)(b) GDPR); otherwise the controller's legitimate interest in replying (Article 6(1)(f) GDPR) | For the time needed to handle the request and any relationship that follows from it |
| Complying with legal obligations or requests from authorities | Legal obligation (Article 6(1)(c) GDPR) | For the time required by law |
| Establishing, exercising or defending the controller's rights, including in court | The controller's legitimate interest (Article 6(1)(f) GDPR) | Until the limitation periods expire and, if there is a dispute, until it is finally settled |
| Services and tools that require consent (preferences, statistics, marketing) | Consent (Article 6(1)(a) GDPR) | Until you withdraw your consent; the duration of each cookie is stated in the cookie policy |
Where processing is based on legitimate interest, you can object at any time on grounds relating to your particular situation (see “Your rights”).
Services that require consent are described in the “Third-party services” section and in the cookie policy.
Third-party services
The website uses the third-party services described below, grouped by category. For each one you will find who the provider is, what the service does, what data it processes, on what legal basis and where the data is processed, including any transfers outside the European Economic Area, with a link to the provider's privacy notice.
Necessary services work without consent, because they are needed to run the website or to provide a service you have asked for. Preference, statistics and marketing services process your data only after you have given your consent through the banner; you can withdraw it at any time using the “Privacy preferences” link.
Necessary
Cloudflare
This site uses services of Cloudflare, Inc. (United States): the network through which pages are delivered and protected against attacks and automated programs, with the related services (Turnstile check on forms, public cdnjs library). Cloudflare processes the IP address, technical browser data and the requests sent to the site, and may set technical cookies on the site's domain, for example to tell people from automated programs or to remember that an anti-bot check was passed; they are only used for security and operation and do not require consent (Article 122 of the Italian Privacy Code). The processing is based on the controller's legitimate interest in the security and availability of the site (Article 6(1)(f) of Regulation (EU) 2016/679). Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework (European Commission adequacy decision). Cloudflare Privacy Policy
- Legal basis: legitimate interest of the controller (Art. 6(1)(f) GDPR)
- Where the data is processed: Cloudflare's global network (including data centres in the European Union); United States
- Transfer outside the European Economic Area: yes, to the United States, under the EU-U.S. adequacy decision (EU-U.S. Data Privacy Framework)
- Cookies and tools on your device:
__cf_bm(30 minutes)
PHP / Laravel
This site uses its own technical cookies, set by its server (built with PHP/Laravel) and essential for it to work: one protects forms against forged requests, while the session cookie keeps the browsing session across pages. They only contain random or encrypted codes and are not used to profile visitors. The processing is based on the controller's legitimate interest in running a working and secure site (Article 6(1)(f) of Regulation (EU) 2016/679) and does not require consent, because these cookies are strictly necessary (Article 122 of the Italian Privacy Code). They are not used for any other purpose.
- Legal basis: legitimate interest of the controller (Art. 6(1)(f) GDPR)
- Where the data is processed: The server hosting the site
- Transfer outside the European Economic Area: no, the data is processed in the European Economic Area
- Cookies and tools on your device:
viglietti_sergio_session(2 hours),XSRF-TOKEN(2 hours)
Privacy by SKYL4R
This site uses Privacy by SKYL4R, a service of SKYL4R S.r.l. (Italy) that shows the cookie banner and hosts these documents. To remember the choice made in the banner, the technical cookie skyl4r_cs is stored on the device, with the same information in the browser's local storage: the categories chosen, the document versions and a random consent ID. A minimal copy of the choice (random ID, date, categories and versions, with no IP address or browser data) is kept on SKYL4R's servers, in the European Economic Area, so that consent can be demonstrated, as required by Article 7 of Regulation (EU) 2016/679. It is a technical tool that does not require consent (Article 122 of the Italian Privacy Code). Requests to privacy.skyl4r.ai go through the network of Cloudflare, Inc. (United States), a sub-processor of SKYL4R, which receives the IP address and technical traffic data to deliver and protect the requests, and processes these data for a limited period in its data centres in the United States and Europe; Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework (European Commission adequacy decision). The choice can be changed at any time from the Privacy preferences. Cloudflare Privacy Policy
- Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR)
- Where the data is processed: European Economic Area (SKYL4R S.r.l. servers); Cloudflare, Inc. network, with traffic data processed in its data centres in the United States and Europe
- Transfer outside the European Economic Area: yes, to the United States, under the EU-U.S. adequacy decision (EU-U.S. Data Privacy Framework)
- Cookies and tools on your device:
skyl4r_cs(12 months),skyl4r_cs(local storage, until you delete it; the choice expires with the cookie)
Preferences
Google Fonts
This site uses Google Fonts, a service of Google Ireland Limited (Ireland), to display the typefaces of its pages. Google Fonts does not set cookies; to download the fonts, however, the browser connects to Google's servers (fonts.googleapis.com and fonts.gstatic.com) and sends the IP address, the address of the requested resource, the referring page and technical browser data. According to Google, this information is only used to respond to the request and for security, and is not used to profile visitors or for advertising. The fonts are loaded only with the visitor's consent, which can be withdrawn at any time from the Privacy preferences. Data may be transferred to Google LLC in the United States, which is certified under the EU-U.S. Data Privacy Framework (European Commission adequacy decision). Google Privacy Policy
- Legal basis: consent (Art. 6(1)(a) GDPR)
- Where the data is processed: Google servers in the European Union and in other countries, including the United States
- Transfer outside the European Economic Area: yes, to the United States, under the EU-U.S. adequacy decision (EU-U.S. Data Privacy Framework)
Vimeo
This site embeds Vimeo videos, a service of Vimeo.com, Inc. (United States). When an embedded video loads, Vimeo receives the IP address, technical browser data and the page visited, and sets its own cookies on the vimeo.com domain, used for analytics for the video owner, for playback preferences and for protection against automated programs. If the video is embedded with the "dnt" parameter, Vimeo does not set new analytics cookies during playback. The videos are loaded only with the visitor's consent, which can be withdrawn at any time from the Privacy preferences. Vimeo.com, Inc. is certified under the EU-U.S. Data Privacy Framework (European Commission adequacy decision). Vimeo Privacy Policy
- Legal basis: consent (Art. 6(1)(a) GDPR)
- Where the data is processed: United States
- Transfer outside the European Economic Area: yes, to the United States, under the EU-U.S. adequacy decision (EU-U.S. Data Privacy Framework)
- Cookies and tools on your device:
vuid(13 months)
Who may receive the data
Your data may be processed, only for the purposes set out in this notice, by:
- people authorised by the controller (employees and collaborators), bound by confidentiality and instructed on the processing (Article 29 GDPR);
- providers of technical services (for example hosting, email, website maintenance), acting as processors on behalf of the controller under a contract (Article 28 GDPR);
- professionals and advisers (for example tax or legal advisers), in the role set by their engagement;
- the providers of the third-party services described in this notice, as stated for each of them;
- public authorities and other parties, where the law requires it or to establish, exercise or defend a right.
Your data is not disseminated, that is, it is not made available to an indefinite number of people. The up-to-date list of processors is available on request by writing to info@viglietti.com.
Transfers outside the European Economic Area
Some services used by the website involve transferring personal data to countries outside the European Economic Area (EEA). These transfers take place only under the conditions of Chapter V of the GDPR (Articles 44 to 49), namely:
- to countries for which the European Commission has adopted an adequacy decision (Article 45), including the United States for organisations certified under the EU-U.S. Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795; the list of certified organisations is on dataprivacyframework.gov);
- or with appropriate safeguards (Article 46), in particular the standard contractual clauses adopted by the European Commission (Commission Implementing Decision (EU) 2021/914).
For each service, the “Third-party services” section states where the data is processed and which safeguard the transfer relies on. You can ask for information and for a copy of the safeguards in place by writing to info@viglietti.com.
How long data is kept
Your data is kept in a form that allows you to be identified only for as long as needed for the purposes for which it was collected (Article 5(1)(e) GDPR). The criteria for each purpose are set out in the purpose tables of this notice; the duration of cookies is stated in the cookie policy.
Once the purpose has been achieved, the data is deleted or anonymised so that you can no longer be identified. It may be kept longer only where the law requires it (for example for accounting and tax records), to establish, exercise or defend a right, or at the request of an authority: in these cases only the data needed is kept, and only for that purpose.
Data security
The controller applies technical and organisational measures appropriate to the risk, taking into account the state of the art, the costs and the nature of the processing (Article 32 GDPR), to protect your data against destruction, loss, alteration, disclosure or unauthorised access. Only authorised people and processors have access to the data, for the purposes stated.
No measure can rule out every risk. In the event of a personal data breach, the controller acts as provided by Articles 33 and 34 of the GDPR and informs you without undue delay in the cases set out in Article 34, that is, when the breach is likely to result in a high risk to your rights and freedoms.
Your rights
Within the cases and limits set by the GDPR, you can ask the controller for:
- access to your data and to information about the processing (Article 15);
- rectification of inaccurate data or completion of incomplete data (Article 16);
- erasure of your data (Article 17);
- restriction of processing (Article 18);
- portability of the data you have provided (Article 20).
You can object to processing based on legitimate interest, on grounds relating to your particular situation (Article 21(1)), and at any time, without giving reasons, to processing for direct marketing purposes (Article 21(2)). The controller does not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Article 22).
Where processing is based on consent, you can withdraw it at any time, as easily as you gave it (for cookies, using the “Privacy preferences” link); withdrawal does not affect the lawfulness of processing carried out before it (Article 7(3)).
How to exercise your rights
Write to info@viglietti.com. It is free of charge, except for manifestly unfounded or excessive requests (Article 12(5)). The controller replies without undue delay and at the latest within one month of receiving your request; this period may be extended by two further months where necessary, given the complexity or number of requests, in which case you will be told within the first month (Article 12(3)). If there are reasonable doubts about your identity, you may be asked to confirm it.
Complaint to a supervisory authority
If you believe that the processing of your data infringes the GDPR, you can lodge a complaint with the Italian Data Protection Authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the supervisory authority of the EU Member State where you habitually reside or work, or where the alleged infringement took place (Article 77 GDPR). Instructions and the complaint form of the Garante are on its complaints page (in Italian).
You also keep the right to take legal action before the courts (Article 79 GDPR).
Children
The website is not intended for children under 14 and the controller does not knowingly collect their data. For information society services offered directly to children, in Italy a child can consent alone to the processing of their personal data only from the age of 14; below that age, consent must be given by the holder of parental responsibility (Article 8 GDPR and Article 2-quinquies of the Italian Privacy Code).
If you believe that a child under 14 has provided personal data, write to info@viglietti.com to ask for it to be deleted.
Do you have to provide your data?
Apart from browsing data, which is collected automatically so that the website can work, providing your data is optional. However, if you do not provide the data needed to reply to your request or to enter into and perform a contract, the controller may be unable to reply or to perform it; some data may be required by law, for example to issue an invoice.
Consent to non-necessary cookies and tools is free: you can refuse it and keep using the website. Only the features that depend on those services, for example an embedded video or map, may be unavailable until you give your consent.
Changes to this notice
This notice may be updated, for example when the services used by the website, the purposes of processing or the law change. The version in force is always the one published at this address; previous versions remain available, each with its date.
When a change is substantial, for example a new service that requires consent or a new purpose, the cookie banner is shown to you again on your next visit, so that you can review your choices.
Last updated: 25 September 2026.