GDPR – Data Protection Information

Last updated: 31.December 2025


1. Controller Pursuant to Art. 4(7) GDPR

The controller responsible for the processing of personal data is:

Name: Juraj Michna
Address: Skalnata ulica 361/15 Velka Lomnica 059 52 Slovakia
Email: info@iltedescoartigiano.com
Phone: +49 160 5507621


2. Scope of This Information

This GDPR information explains how personal data is processed in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

It applies to:

  • Visitors of this website

  • Individuals contacting us via contact form, email, phone, or messaging services

  • Business partners and prospective customers


3. Categories of Personal Data Processed

The following categories of personal data may be processed:

  • Identification data (name)

  • Contact data (email address, phone number, address)

  • Communication data (message content, enquiry details)

  • Technical data (IP address, browser type, device information, access time)

  • Usage data (website interaction, cookie data)


4. Sources of Personal Data

Personal data is obtained from:

  • Data subjects directly (contact form, email, phone, messaging services)

  • Automated collection through the use of cookies and analytics tools

  • Technical logs generated by website hosting and security systems


5. Purposes of Processing

Personal data is processed for the following purposes:

  • Responding to enquiries and communication requests

  • Preparation of offers and provision of services

  • Website operation, stability, and security

  • Statistical analysis and website optimization

  • Fulfilment of legal and regulatory obligations


6. Legal Basis for Processing (Art. 6 GDPR)

Processing is based on the following legal grounds:

  • Art. 6(1)(b) GDPR – performance of a contract or pre-contractual measures

  • Art. 6(1)(a) GDPR – consent (e.g. cookies, analytics)

  • Art. 6(1)(f) GDPR – legitimate interests (website operation, security)

  • Art. 6(1)(c) GDPR – compliance with legal obligations


7. Legitimate Interests (Art. 6(1)(f) GDPR)

Where processing is based on legitimate interests, these include:

  • Ensuring website functionality and security

  • Preventing misuse and fraud

  • Improving services and user experience

These interests do not override the fundamental rights and freedoms of data subjects.


8. Recipients of Personal Data

Personal data may be disclosed to:

  • Hosting and IT service providers (e.g. Hostinger)

  • Analytics and technical service providers

  • Professional advisors where legally required

All recipients are contractually obligated to comply with GDPR requirements.


9. Data Transfers to Third Countries

Personal data may be transferred to countries outside the EU or UK (e.g. when using third-party services such as analytics or embedded content).

Such transfers take place only where:

  • An adequacy decision exists, or

  • Appropriate safeguards (e.g. Standard Contractual Clauses) are in place


10. Data Retention Periods

Personal data is stored only for as long as necessary for the respective purpose or as required by law.

  • Enquiry and communication data: deleted after completion of communication

  • Contract-related data: retained in accordance with statutory retention periods

  • Technical and log data: stored for security and operational purposes only


11. Rights of Data Subjects

Under GDPR, data subjects have the right to:

  • Access personal data (Art. 15 GDPR)

  • Rectification of inaccurate data (Art. 16 GDPR)

  • Erasure (“right to be forgotten”) (Art. 17 GDPR)

  • Restriction of processing (Art. 18 GDPR)

  • Data portability (Art. 20 GDPR)

  • Objection to processing (Art. 21 GDPR)

  • Withdrawal of consent at any time (Art. 7(3) GDPR)

Requests can be addressed to the contact details provided above.


12. Obligation to Provide Data

The provision of personal data is voluntary.
However, failure to provide required data may result in the inability to respond to enquiries or provide services.


13. Automated Decision-Making

No automated decision-making or profiling pursuant to Art. 22 GDPR takes place.


14. Data Security Measures

Appropriate technical and organizational measures are implemented to ensure a level of security appropriate to the risk, including protection against unauthorized access, loss, or destruction of data.


15. Right to Lodge a Complaint

Data subjects have the right to lodge a complaint with a supervisory authority.

For EU-based processing, this includes:

  • Italian Data Protection Authority (Garante per la Protezione dei Dati Personali)
    or another competent supervisory authority in the EU or UK.


16. Amendments

This GDPR information may be updated to reflect legal, technical, or organizational changes.
The current version is published on this website.