1. Data controller
Teresita Piacentini — Atelier modArch
Via S. Nicola 7, 25082 Botticino (BS), Italy
VAT no. 03869230981 · REA BS-569998
Email: [email protected]
Phone: +39 329 763 3425
2. Categories of data collected
This website contains no contact forms and does not collect personal data through form submissions. The categories of data processed are the following:
- Contact data: the data you voluntarily choose to provide when you contact us by email, phone or WhatsApp — typically name, contact details, company/brand and the description of the project. The website only displays the studio's contact details: it is you who decide whether, how and what to communicate.
- Technical navigation data: IP address, user agent, pages visited, timestamp, country of origin — handled by the Cloudflare CDN and necessary for the operation and security of the website (security logging and abuse mitigation).
- Analytics data: aggregate, anonymous traffic statistics collected with a first-party system (davix-hits, on Cloudflare Workers). We record the page visited, the referring site, the type of contact clicked (email, phone, WhatsApp) and scroll depth. Google Analytics is not installed, no cookies are used, and no profiling or identification of individual visitors takes place.
3. Purposes and legal basis of processing
- Responding to contact requests and managing pre-contractual relations — legal basis: performance of pre-contractual measures at the data subject's request (Art. 6(1)(b) GDPR).
- Performance of any contractual relationship and fulfilment of the resulting tax and accounting obligations — legal basis: performance of a contract to which the data subject is a party (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)).
- Technical security of the website and prevention of abuse — legal basis: legitimate interest of the controller (Art. 6(1)(f)).
- Protection of the confidentiality of third-party projects — legal basis: contractual obligation (NDAs with clients) and legitimate interest in protecting professional secrecy.
4. Retention periods
- Contact data with no contractual follow-up: retained for 24 months from the last communication, unless earlier deletion is requested.
- Data linked to a contract: retained for 10 years from the end of the relationship, in accordance with Italian tax and civil law (Art. 2220 of the Civil Code and Presidential Decree 633/72).
- Cloudflare technical logs: retained in accordance with Cloudflare's policies (max. 30 days for standard logs).
5. Recipients (processors and sub-processors)
Data may be disclosed to the following parties, acting as data processors under Art. 28 GDPR:
- Cloudflare, Inc. (San Francisco, USA · EU-US Data Privacy Framework certified) — Cloudflare Pages hosting, CDN, security and technical logs. privacy policy.
- Google LLC (Google Maps embed on the contact page) — loading the map sends your IP address to Google. privacy policy. The map is loaded only on the /contatti/ page.
- Meta Platforms Ireland Ltd. — if you choose to contact us through the WhatsApp link on the website, the conversation and related data are processed by WhatsApp/Meta under their terms. privacy policy.
- Aruba S.p.A. — management of the controller's domain name and certified email (PEC).
- Davix Studio (anonymous davix-hits statistics, hosted on Cloudflare Workers in the EU) — receives the page visited, the referring site and the type of contact clicked, in aggregate form and without identifying the visitor.
- Cloudflare Workers AI (site chat assistant) — the text you type into the chat is sent to a language model hosted by Cloudflare to generate the reply. Do not enter confidential information or third-party personal data into the chat: for NDA-covered projects use email or phone.
- Calendly LLC — if you book a call from the site, your name, email and time zone are processed by Calendly. privacy policy.
Data is not disclosed to third parties for marketing purposes nor sold to third parties. The details of client projects are never shared with any other party, in line with NDA obligations.
6. Transfers outside the EU
Some providers (Cloudflare, Google) are based or have infrastructure in the United States. Transfers take place on the basis of adequate safeguards under Chapter V GDPR: the European Commission's standard contractual clauses (SCC) and/or adherence to the EU-US Data Privacy Framework.
7. Data subject rights
Under Articles 15–22 GDPR, the data subject has the right to:
- access their personal data (right of access);
- request its rectification or completion (rectification);
- request its erasure (right to be forgotten), subject to legal retention obligations;
- request restriction of processing;
- receive the data in a structured format (portability);
- object to processing based on legitimate interest;
- where processing is based on consent, withdraw it at any time, without affecting the lawfulness of processing carried out beforehand.
To exercise these rights, write to [email protected] with "GDPR" in the subject line. We respond within 30 days.
The data subject also has the right to lodge a complaint with the competent supervisory authority: the Italian Garante per la protezione dei dati personali — Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it.
8. Cookies and tracking technologies
The website uses only the following cookies / technologies:
- Cloudflare technical cookies (
__cf_bm, cf_clearance) — purpose: security, bot mitigation, delivery optimisation. Strictly necessary, no consent required (Art. 122(1) Legislative Decree 196/2003).
- No analytics or profiling cookies. No Google Analytics is installed, and no social tracking pixels are installed. The anonymous statistics rely on
sessionStorage, which is cleared when the browser is closed.
The statistics described above are anonymous, aggregate and require no consent. The notice shown on arrival only signals the use of technical cookies; on dismissal it stores a cck entry in localStorage so it does not reappear. Google Maps is not loaded automatically: it starts only if you ask for it. Should the controller activate profiling or third-party cookies in the future, prior consent compliant with the Garante's Cookie Guidelines (10 June 2021) will be requested.
9. Confidentiality of client projects (NDA)
Atelier modArch works under a contractual NDA for every client. Project files (patterns, technical sheets, garment images) are never published on this website, are not uploaded to shared cloud services and are not disclosed to any party other than the client. Even after the end of the contractual relationship, the confidentiality obligation remains in force under the terms of each individual NDA.
10. Changes to this notice
This privacy notice may be updated to reflect regulatory or organisational changes. The date of the latest update is shown at the bottom. We recommend checking this page periodically.
Last updated: 14 May 2026