← back to the site

Privacy policy

This website measures its own traffic. There is no Google Analytics, no advertising network and no third-party script, and no element of the page is fetched from any other server — no typeface, no video player, no social button. The code performing the measurement forms part of the website, and the data it produces is held in a database on the same server that serves the page. One category of data leaves this server, and only where the user sends it: the content of a message submitted through the contact form, which is transmitted by email.

Data controller

The data controller is Emanuele Frascella, Taranto, Italy, VAT no. 03462650734. The website is operated by a single natural person; no organisation stands behind it and no data protection officer has been appointed, neither being required at this scale.

Requests concerning any matter described in this notice, including those listed under rights of the data subject , may be submitted through the contact form . Messages are delivered directly to the controller’s mailbox, and a reply discloses the controller’s address.

Data collected, and the purposes

Collection takes place only with the consent of the data subject, and only after that consent has been given. None of the items listed below is measured before the banner has been answered, and a refusal maintains that condition: the measurement code is not downloaded at all. Refusal carries no consequence — the website behaves identically in either case.

Sections reached, and the length of time each remained on screen
To determine whether the page merits scrolling.
Scroll depth reached — 25%, 50%, 75%, 100%
The same question, stated more bluntly.
Whether a biography row was opened, whether the work corridor was traversed, and whether an outbound link was followed
To determine which parts of the page hold attention.
Whether the contact form was displayed, whether entry began, and whether it was submitted
To determine at which point the form loses users.
Device type, operating system and browser, recorded as three short labels such as mobile, ios, safari. The full identifying string transmitted by the browser is read, reduced to those three labels, and discarded.
To establish the environments in which the website must render correctly.
Screen and window dimensions, language, time zone
The same question, in greater detail.
The name of the referring website — its host alone, therefore google.com rather than the query entered — together with any campaign parameters present on the link. The full address offered by the browser is read in order to extract the host, and is then discarded.
To establish the origin of visits.
A two-letter country code, and only where the network placed in front of the website has already determined one and declares it. No lookup is performed and no database exists for that purpose, so this field is frequently empty.
To establish the countries in which the website is read. No city, no coordinates, nothing more granular.

The contact form

Consent does not apply here. The user enters a name, an email address and a message; submission constitutes the request itself, and a refusal to read it would disregard the user rather than protect them. All three fields are mandatory: a message that can be neither read nor answered is not a message, and the form will not submit without them. No other field exists, concealed or otherwise, save for a decoy input completed only by automated agents.

The content of the message is transmitted by email to the controller and is never written to the database. It then remains in the controller’s mailbox for as long as the correspondence warrants, which is a matter of judgement rather than a fixed schedule, and it is deleted on request. The email address is also used to maintain a fifteen-minute cooldown, so that a repeated submission is not sent twice — the same kind of small file used by the IP throttle described below, named after a hash of the address rather than the address itself.

Data not collected

IP addresses are never written to the database. No table recording a visit provides a column to hold one. They serve a single purpose: counting requests, so that no single machine can flood the contact form or the counter. Even there the address is not recorded — it is hashed, and the hash is the name of a small file holding a number. Those files are removed once they have gone a couple of hours untouched.

Stated precisely, this being a claim worth verifying: the web server placed in front of the application keeps its own access log, as does every web server on the internet, and a line in such a log contains an address. That is infrastructure, not measurement. It is never joined to anything described in this notice, and this database holds one row containing an IP address — that of the controller, from the controller’s own sign-ins, described below.

There is no profiling, no automated decision-making, no tracking across other websites and no attempt to establish the identity of the user. The identifier held in pf_vid is a random number without meaning outside this website. No name, no email address and no account is associated with it, there being no visitor accounts to associate.

Cookies

Name Function Retention Consent required
pf_consent Records the answer given to the banner — affirmative or negative, and the numbered request to which it relates — so that the question is not put again until that request changes. Written by the page itself, and the only cookie present before an answer has been given. 6 months No. It exists in order to record a choice, a refusal included.
pf_vid A random number distinguishing one browser from another, so that a return visit is not counted as a second person. Written by the server, and only once consent has been given. 13 months, renewed on each visit Yes
pf_sid Groups the events of a single visit. A new one begins after 30 minutes of inactivity. 30 minutes Yes
pf_admin Authenticates the controller to the administrative dashboard. It is issued only against a correct password and therefore never reaches a visitor’s browser. 7 days No. Technical, and not a visitor’s cookie.

All four are first-party: set on this domain, returned only to this domain, and unreadable by any other party. There are no others — no advertising cookie, no embedded video player, no social button — and no information concerning the visit is held in the browser’s local storage in their place.

Data leaving this server

The content of a message, where one is submitted. It leaves by SMTP and arrives in the controller’s mailbox. The provider carrying it and the provider hosting that mailbox handle it as a postal service handles a letter; they are in the path because mail cannot be sent without one. That is the entire list.

Loading a page here contacts no other party. Every file the page requires — stylesheets, scripts, images, and the two typefaces in which it is set — is served from this domain, so the browser never announces itself to a server the controller does not operate. There is no analytics vendor, no advertising partner, no CRM, no newsletter tool and no list to which the address is added. The company hosting the server has access to its own disks, as is true of every hosted website, and where a network placed in front of the website supplies a country code, that network sees the traffic as well — see the final row of the data collected.

No data is deliberately transferred outside the European Economic Area. The mail path is the only point at which this could occur, and that depends on the provider carrying the message.

Legal basis and retention

Analytics — consent of the data subject, art. 6(1)(a) GDPR, together with art. 122 of the Codice Privacy in respect of the cookies themselves. Consent may be withdrawn at any time, below, and withdrawal is exactly as straightforward as the giving of it.

Two distinct periods apply, and are worth keeping apart. The identifier held in the browser, pf_vid, lasts 13 months — the ceiling placed by the Garante on an analytics identifier — and is renewed on each return. The rows held on the server are deleted after 400 days, by a job running nightly. The second figure is not the first one rounded; they govern different things, which is why both are stated.

The contact form — art. 6(1)(b): steps taken at the request of the data subject, prior to the existence of any contract. Nothing is stored server-side; the message resides in the controller’s mailbox, as described above.

Flood protection — art. 6(1)(f), the legitimate interest of the controller in a website that remains available. Counters only, expiring within hours.

The consent cookie and the sign-in cookie require no consent at all: art. 122 of the Codice Privacy exempts a cookie strictly necessary to provide the service requested, and recording a refusal is precisely that.

The controller’s own account

The figures are read on a dashboard behind a sign-in, and that sign-in is an account: a name, an email address, a password held only as a hash, and the second factor — the secret used by an authenticator application, together with a set of recovery codes, likewise held as hashes. None of those elements can be replayed as a sign-in on its own, and a code once used is recorded as used and cannot be presented a second time.

Signing in records the sign-in — the time, the address it originated from, the browser used — so that the session may later be recognised and revoked. Those rows are removed when the session expires, within seven days.

None of that constitutes data concerning the visitor: it concerns the controller, and no informativa is owed to oneself. It is set out here for one reason — a notice stating that visitors’ addresses are never stored owes an account of the single place in this database where an address is held.

Rights of the data subject

Under articles 15 to 22 GDPR the data subject may request access to the data held concerning them, its rectification or erasure, or the restriction of its processing, may object to the processing, and may request a copy in a portable format. Under art. 7(3) consent may be withdrawn at any time, without affecting the lawfulness of processing carried out beforehand. Under art. 77 a complaint may be lodged with the Garante per la protezione dei dati personali — garanteprivacy.it — without prior recourse to the controller.

In practice the quickest route is the control below. The “cookies” link in the footer leads there as well: on the portfolio page it reopens the banner in place, while here, and on the dashboard, it moves directly to this block. A refusal by either route deletes the identifiers from the browser immediately, after which nothing further can be linked to the visitor.

Rows already written remain, and carry no name, no address and nothing pointing back to a person. Under art. 11 GDPR a controller who has no reason to hold the additional information required to identify one person within an anonymous set is not obliged to obtain it solely in order to answer a request — which is precisely the present case, and is also why such rows cannot be isolated unprompted. Where their deletion is also sought, the value of the pf_vid cookie should be sent to the controller before it is cleared: it is the only key in existence, and with it the rows can be deleted manually.

Revisions

Rewriting this notice does not place an answer already given back in question. Consent is given to what is collected and why, not to a document, so correcting a sentence or explaining a matter more clearly leaves an existing assent or refusal exactly as valid as it was. What does place the question back is a change to the request itself: a new cookie requiring permission, a third party appearing on the page, a new purpose, a new category of data counted.

The request is therefore numbered, and the number answered is held in the pf_consent cookie alongside the answer. When it changes, every stored answer ceases to have effect and the banner is put again — which is why it changes only for the reasons above. The list below states, for each revision, which kind it was.

  1. 7 August 2026 · request 01 First published, together with the counting it describes. The first request — there was nothing to put again.
  2. 10 August 2026 · request 01 Published in Italian alongside English. Nothing collected changed — only the number of languages in which it is set out. Wording only. Answers already given remained valid.
  3. 10 August 2026 · request 01 Rewritten throughout in an impersonal register. No change to what is collected, to the purposes, or to the retention periods. Wording only. Answers already given remained valid.