Preamble
With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as "data") that we process, for what purposes, and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as "online services").
The terms used are not gender-specific.
Last updated: June 5, 2026
Table of Contents
Preamble
Data Controller
Overview of Processing Activities
Relevant Legal Bases
Security Measures
Transfer of Personal Data
International Data Transfers
General Information on Data Storage and Deletion
Rights of Data Subjects
Provision of the Online Service and Web Hosting
Use of Cookies
Contact and Inquiry Management
Changes and Updates
Definitions
Data Controller
David Cenciarini / DOMUS & INGEGNO
Voc. Pistrino, 3
06012, Città di Castello, Italy
Email address: info@domusingegno.com
Overview of Processing Activities
The following overview summarizes the types of data processed, the purposes of processing, and the data subjects.
Types of Data Processed
Contact details
Content data
Usage data
Metadata, communication data, and process data.
Log data.
Categories of data subjects: Communication partners.
Users.
Purposes of processing: Communication.
Security measures.
Organizational and administrative procedures.
Feedback.
Provision of our online services and user-friendliness.
Information technology infrastructure.
Relevant legal bases:
Relevant legal bases according to the GDPR: Below you will find an overview of the legal bases under the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or establishment. If more specific legal bases apply in individual cases, we will inform you of these in the privacy policy.
Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR) - The data subject has given consent to the processing of their personal data for one or more specific purposes.
Contractual performance and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract.
Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
Applicability of data protection regulations in the country of establishment: In the country where the controller is established, national data protection regulations also apply in addition to the General Data Protection Regulation (GDPR).
Security Measures
In accordance with legal requirements, and taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as access to, input of, disclosure of, and ensuring the availability and separation of the data. Furthermore, we have established procedures that guarantee the exercise of data subject rights, the erasure of data, and responses to data breaches. We also consider the protection of personal data during the development and selection of hardware, software, and processes, in accordance with the principles of data protection by design and by default.
These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as access to, input of, disclosure of, and ensuring the availability and separation of the data. Securing online connections through TLS/SSL encryption technology (HTTPS): To protect user data transmitted via our online services from unauthorized access, we rely on TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission.