Privacy Policy

Last updated: 27 mar 2026

1. Data Controller

This website is operated by YOUTRAINING di D’Angelo Tommaso, VAT No. 02305400810, with registered office at Piazza Castello, 1 – 91011 Alcamo (TP), Italy.

For any question regarding this Privacy Policy or the processing of personal data, you can contact:

Email: info@tommasodangelo.it
Phone: +39 328 9317686

2. Scope of this notice

This Privacy Policy explains how personal data are processed when you:

  • browse this website;
  • submit an inquiry through the contact form;
  • contact us directly by email or other communication channels made available on the website in relation to photography services.

3. Categories of personal data collected

Depending on how you interact with the website, we may collect and process the following personal data:

  • identification and contact data, such as name, partner’s name, phone number and email address;
  • event-related information, such as wedding date, venue or area in Sicily, and the content of your inquiry;
  • any other information you choose to include in your message;
  • technical and browsing data that may be collected automatically by hosting, security or website management systems, such as IP address, browser type, device information, date and time of access, and basic log data, only to the extent necessary for the operation and security of the website.

4. Purposes of processing

Your personal data may be processed for the following purposes:

a. To respond to inquiries and requests for information or quotations
This includes reviewing your contact request, replying to you, and taking steps at your request before the possible conclusion of a contract.

b. To manage pre-contractual communications and service-related follow-up
This includes exchanging information necessary to understand your request and assess availability for photography services.

c. To comply with legal, tax, accounting or administrative obligations
Where applicable, some data may be processed to comply with obligations imposed by law.

d. To protect the security and proper functioning of the website
Technical data may be processed to ensure website security, prevent abuse, detect malicious activity, and maintain service integrity.

5. Legal basis for processing

The legal bases for the processing described above are:

  • Article 6(1)(b) GDPR – processing necessary in order to take steps at your request prior to entering into a contract, for contact and quotation requests;
  • Article 6(1)(c) GDPR – processing necessary for compliance with legal obligations, where applicable;
  • Article 6(1)(f) GDPR – processing necessary for the legitimate interests of the Controller in protecting the website, ensuring its security, and managing communications in an efficient and orderly way.

6. Provision of data

Providing personal data is voluntary.

However, the information requested in fields marked as mandatory is necessary for us to properly evaluate and respond to your inquiry. If you do not provide the required data, we may not be able to reply or provide the requested information.

7. Methods of processing

Personal data are processed using electronic and, where necessary, paper-based tools, in compliance with the principles of lawfulness, fairness, transparency, data minimisation, confidentiality and security.

Appropriate technical and organisational measures are adopted to reduce the risk of unauthorised access, disclosure, alteration or loss of personal data.

8. Retention period

Personal data submitted through the contact form or by direct communication are retained for the time necessary to manage your inquiry and any related pre-contractual communications.

After that, data may be retained only for the period reasonably necessary:

  • to document communications;
  • to protect the Controller’s rights;
  • to comply with legal, tax, administrative or accounting obligations;
  • or for other purposes required or permitted by applicable law.

If your inquiry leads to a booking or contractual relationship, personal data may be retained for the duration of that relationship and for the additional period required by applicable law.

Technical log data may be retained for the period necessary for security, maintenance and diagnostic purposes, according to the criteria applied by the relevant hosting and technical service providers.

9. Recipients and categories of recipients

Personal data may be processed by persons authorised by the Controller and, where necessary, by third-party service providers acting on behalf of the Controller, including for example:

  • website hosting providers;
  • website maintenance or technical support providers;
  • email and communication service providers;
  • CRM, contact form or business management tools used to receive, organise and manage inquiries, including Studio Ninja, where used for this purpose;
  • professional advisors, where necessary for administrative, legal or organisational purposes.

Personal data will not be disclosed to the public.

10. Transfers outside the European Economic Area

Where personal data are processed by service providers located outside the European Economic Area, or where data are otherwise transferred outside the EEA, such transfers will take place only in accordance with applicable data protection law and, where required, on the basis of appropriate safeguards, such as an adequacy decision or the Standard Contractual Clauses approved by the European Commission.

11. Data subject rights

Under the GDPR, you have the right to:

  • request access to your personal data;
  • request rectification of inaccurate or incomplete data;
  • request erasure of your personal data, where applicable;
  • request restriction of processing, where applicable;
  • object to processing, where applicable;
  • request data portability, where applicable;
  • lodge a complaint with the competent supervisory authority.

If you are located in Italy, the competent supervisory authority is the Garante per la Protezione dei Dati Personali.

12. How to exercise your rights

To exercise your rights or request further information about the processing of your personal data, you may contact:

Email: info@tommasodangelo.it

The Controller may request information necessary to verify your identity before processing your request.

13. Automated decision-making

No automated decision-making or profiling is carried out through this contact form.

14. Changes to this Privacy Policy

This Privacy Policy may be updated from time to time in order to reflect legal, technical or organisational changes.

The latest version will always be available on this page.