Last updated: 20 August 2026
This Privacy Policy explains how personal data is collected, used and protected when you visit gabrielesaveri.com, contact us or purchase digital products through the website.
Personal data is processed in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and applicable Italian data protection legislation.
1. Data Controller
The Data Controller is:
Gabriele Saveri
Voc. Lanciano 48b
06025 Nocera Umbra (PG)
Cod. Fiscale: SVRGRL73H03F205D
Partita Iva: 03245580547
Email: info@gabrielesaveri.com
For any question concerning this Privacy Policy or the processing of your personal data, you may contact the Data Controller at the email address above.
2. Personal Data We May Collect
Depending on how you use the website, we may process the following categories of personal data.
Website and technical data
When you visit the website, the hosting platform, server and website software may automatically process technical information necessary to provide and secure the service, including:
- IP address;
- browser and device information;
- operating system;
- date and time of requests;
- requested pages and resources;
- server and security logs;
- technical information relating to errors or website performance.
Contact data
If you contact us by email or through a contact form, we may process information such as:
- name;
- email address;
- information contained in your message;
- any other information you voluntarily provide.
Purchase and order data
When you purchase a digital product, we may process information necessary to complete and administer the transaction, including:
- name;
- email address;
- billing information, where required;
- products purchased;
- order amount;
- order date and status;
- transaction or payment reference;
- download history and access information;
- information necessary to provide customer support.
The website does not normally receive or store complete payment card details. Payment credentials are processed by the relevant payment service provider.
3. Purposes and Legal Bases
Personal data may be processed for the following purposes.
Operating and securing the website
Technical data may be processed to:
- provide the website and its functionality;
- maintain security;
- prevent fraud and abuse;
- diagnose technical problems;
- maintain server and security logs.
The legal basis is the legitimate interest of the Data Controller in operating and protecting the website and, where necessary, providing a service requested by the user.
Responding to enquiries
Data provided when contacting us is processed in order to respond to enquiries, requests or communications.
The legal basis is taking steps at your request and, where applicable, the legitimate interest in managing communications relating to the website and professional activities.
Processing purchases
Personal data provided during checkout is processed in order to:
- process the order;
- receive confirmation of payment;
- provide access to purchased digital files;
- send transactional communications;
- maintain purchase and download records;
- provide customer support.
The legal basis is the performance of a contract or taking steps at your request prior to entering into a contract.
Legal and accounting obligations
Certain transaction and administrative information may be retained where necessary to comply with applicable tax, accounting, consumer protection or other legal obligations.
The legal basis is compliance with a legal obligation.
Fraud prevention and legal claims
Where necessary, information relating to transactions, website access or communications may be processed to prevent fraudulent activity, protect the website or establish, exercise or defend legal claims.
The legal basis is the legitimate interest of the Data Controller and, where applicable, compliance with legal obligations.
4. Digital Shop
The website uses an e-commerce system to manage the sale and delivery of digital products.
Information relating to orders may therefore be processed in order to:
- create and manage orders;
- verify payment status;
- generate download access;
- enforce download limits;
- send purchase confirmations;
- manage refunds or disputes where applicable;
- provide technical and customer support.
Only information reasonably necessary for these purposes is processed.
5. Payment Providers
Payments are processed through third-party payment service providers selected by the customer from the options available at checkout.
These may include services such as PayPal and other payment methods made available through the payment infrastructure used by the website, including card payments and supported digital wallets.
Payment providers may independently process personal and financial information according to their own terms and privacy policies.
The website does not normally store complete credit or debit card numbers.
6. Transactional Emails
When you make a purchase, the website may send transactional emails necessary to complete or administer the order.
These may include:
- purchase confirmations;
- payment information;
- download links;
- information relating to an order;
- customer support communications.
Transactional emails are part of the service requested by the customer and are not marketing communications.
7. Marketing Communications
Personal data will not be used to send promotional or marketing communications unless there is an appropriate legal basis and, where required, you have provided your consent.
Where consent is used, you may withdraw it at any time.
Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
8. Cookies and Similar Technologies
The website may use cookies and similar technologies necessary for its operation, security, shopping functionality, checkout and payment processing.
Other cookies or tracking technologies, if present, will be managed in accordance with applicable law and, where required, activated only after obtaining the user’s consent.
More detailed information about the cookies and technologies actually used by the website will be provided in the Cookie Policy.
9. Recipients of Personal Data
Personal data may be made accessible, where necessary, to service providers involved in operating the website and providing its services.
These may include:
- website hosting and infrastructure providers;
- website and e-commerce software providers;
- payment service providers;
- email and transactional communication services;
- technical support and website maintenance providers;
- professional advisers where necessary;
- public authorities or other entities where disclosure is required by law.
Such recipients receive only the information reasonably necessary for their respective functions and process personal data according to the role and obligations applicable to them.
10. International Data Transfers
Some service providers used by the website may process personal data outside the European Economic Area.
Where personal data is transferred to a country outside the European Economic Area, appropriate safeguards will be used where required by the GDPR, such as:
- an adequacy decision adopted by the European Commission;
- Standard Contractual Clauses approved by the European Commission;
- other legally recognised transfer mechanisms.
The specific transfer arrangements depend on the service providers actually involved in processing the relevant data.
11. Data Retention
Personal data is retained only for as long as reasonably necessary for the purposes for which it was collected and to comply with applicable legal obligations.
In particular:
Order and transaction records may be retained for the period required by applicable tax, accounting and legal obligations.
Customer support and correspondence may be retained for the period reasonably necessary to manage the request and any subsequent dispute or legal requirement.
Technical and security logs are retained for the period reasonably necessary for website security, troubleshooting and fraud prevention.
Consent records, where applicable, may be retained for as long as necessary to demonstrate compliance with applicable legal requirements.
At the end of the applicable retention period, personal data will be deleted, anonymised or otherwise made no longer identifiable unless further retention is required by law.
12. Data Security
Appropriate technical and organisational measures are used to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
However, no internet transmission or electronic storage system can be guaranteed to be completely secure.
13. Your Rights
Subject to the conditions established by the GDPR, you may have the right to:
- obtain confirmation as to whether your personal data is being processed;
- access your personal data;
- request correction of inaccurate or incomplete personal data;
- request deletion of your personal data;
- request restriction of processing;
- object to certain processing;
- receive personal data in a structured, commonly used and machine-readable format where the right to data portability applies;
- withdraw consent at any time where processing is based on consent;
- lodge a complaint with the competent supervisory authority.
Requests concerning your personal data may be sent to:
We may need to verify your identity before responding to a request.
14. Right to Lodge a Complaint
If you believe that the processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority.
In Italy, the supervisory authority is the:
Garante per la protezione dei dati personali
You may also have the right to contact the supervisory authority of the EU Member State in which you habitually reside, work or where the alleged infringement occurred.
15. Third-Party Websites
The website may contain links to external websites or services.
This Privacy Policy applies only to gabrielesaveri.com.
The Data Controller is not responsible for the privacy practices of third-party websites. Users should review the privacy information provided by those services before providing personal data.
16. Automated Decision-Making
The website does not intentionally use personal data to make decisions based solely on automated processing that produce legal effects or similarly significant effects on users.
Automated technical processes may nevertheless be used for ordinary functions such as payment processing, fraud prevention, security or digital delivery.
17. Children’s Data
The website and digital shop are not specifically directed at children.
Personal data relating to children is not intentionally collected for marketing purposes.
If you believe that personal data relating to a child has been provided through the website inappropriately, please contact info@gabrielesaveri.com.
18. Changes to This Privacy Policy
This Privacy Policy may be updated when necessary to reflect changes to the website, digital shop, service providers or applicable legal requirements.
The date of the most recent revision will be shown at the top of this page.
19. Contact
For questions about this Privacy Policy or requests concerning your personal data, please contact:
Gabriele Saveri
info@gabrielesaveri.com