Ai sensi degli artt. 13 e 14 del Regolamento (UE) 2016/679 per gli utenti del sito simoneblax.com. Ultimo aggiornamento: 20 settembre 2026. In caso di difformità prevale la versione italiana. English version below
Titolare del trattamento
Il Titolare del trattamento è Pagotto Simone, ditta individuale, che opera con il nome commerciale Blax (Simone Blax), P. IVA IT11852300018, 10147 Torino (TO), Italia. Contatto: hello@simoneblax.com.
Il Titolare non è iscritto al Registro delle imprese. Non è stato nominato un Responsabile della protezione dei dati (DPO), non ricorrendo i presupposti dell'art. 37 del GDPR.
Quadro normativo
Il trattamento avviene nel rispetto del Regolamento (UE) 2016/679 (GDPR), del D.Lgs. 30 giugno 2003, n. 196 (Codice in materia di protezione dei dati personali), come modificato dal D.Lgs. 10 agosto 2018, n. 101, e dei provvedimenti del Garante per la protezione dei dati personali.
Dati trattati, finalità e basi giuridiche
Dati di navigazione. I sistemi che gestiscono il sito acquisiscono, nel normale funzionamento, dati la cui trasmissione è implicita nell'uso dei protocolli di comunicazione: indirizzo IP, data e ora della richiesta, pagina richiesta, browser e sistema operativo. Sono usati per il funzionamento e la sicurezza del sito. Base giuridica: legittimo interesse del Titolare (art. 6, par. 1, lett. f, GDPR).
Comunicazioni volontarie. Se scrivi al Titolare, lo contatti per telefono o messaggio, o prenoti una call tramite il servizio di prenotazione integrato nel sito (TidyCal), il Titolare tratta i dati che scegli di comunicare, ad esempio nome, recapiti e contenuto del messaggio, per rispondere alla richiesta e, se ne nasce un rapporto, per gestirlo. Base giuridica: esecuzione di misure precontrattuali adottate su richiesta dell'interessato e di un contratto (art. 6, par. 1, lett. b, GDPR).
Prenotazione di una call. Quando prenoti tramite TidyCal, il servizio (Sumo Group Inc.) invia una email di conferma a te e al Titolare, registra la prenotazione nella propria dashboard e aggiunge l'evento al calendario Google del Titolare (Google Calendar). I dati che hai inserito (ad esempio nome, email, data e ora) restano salvati in entrambi i luoghi fino alla cancellazione, che avviene su tua richiesta.
Cookie e strumenti di terze parti. Gli strumenti di analisi e di marketing sono caricati solo dopo il tuo consenso. Base giuridica: consenso (art. 6, par. 1, lett. a, GDPR; art. 122 del D.Lgs. 196/2003). Il dettaglio è nella Cookie Policy.
Obblighi di legge. Se si instaura un rapporto contrattuale, i dati necessari alla fatturazione e agli adempimenti fiscali sono trattati per adempiere un obbligo di legge (art. 6, par. 1, lett. c, GDPR).
Natura del conferimento
I dati di navigazione sono necessari al funzionamento del sito. La comunicazione dei dati nelle richieste di contatto è facoltativa, ma senza di essa non è possibile rispondere. Il consenso ai cookie di analisi e di marketing è facoltativo: il rifiuto non impedisce di consultare il sito.
Conservazione
I dati di navigazione sono conservati per il tempo strettamente necessario, secondo le impostazioni del fornitore di hosting. I dati delle richieste di contatto e delle prenotazioni che non portano a un rapporto professionale sono conservati fino a quando ne chiedi la cancellazione, che il Titolare esegue senza ritardo e comunque entro un mese. I dati dei clienti sono conservati per la durata del rapporto e per i dieci anni successivi (prescrizione ordinaria, art. 2946 del Codice civile). Google Analytics conserva i dati degli eventi per 2 mesi e i dati a livello di utente per 14 mesi, secondo le impostazioni dell'account. La documentazione contabile e fiscale è conservata per dieci anni (art. 2220 del Codice civile). La durata dei cookie è indicata nella Cookie Policy.
Destinatari
I dati non sono diffusi. Possono essere trattati da: il fornitore del servizio di hosting (Aruba S.p.A.), che tratta i dati per conto del Titolare per erogare il servizio; il fornitore del servizio di prenotazione (TidyCal) e Google, per il calendario su cui viene registrata la prenotazione (Google Calendar); i fornitori degli strumenti di analisi e di marketing (Google, Hotjar, Meta), solo se hai dato il consenso; il Sistema di Interscambio e l'Agenzia delle Entrate, per la fatturazione elettronica.
Trasferimenti extra UE
Alcuni fornitori hanno sede o infrastrutture fuori dallo Spazio economico europeo, in particolare negli Stati Uniti. Il trasferimento si fonda sulla Decisione di esecuzione (UE) 2023/1795 (Data Privacy Framework) per i fornitori che vi aderiscono: Google LLC e Meta Platforms, Inc. risultano tra i partecipanti certificati (elenco dei partecipanti). Per gli altri fornitori extra SEE, come Sumo Group Inc. (TidyCal), il trasferimento si basa sulle garanzie che ciascun fornitore adotta ai sensi degli artt. 45 e 46 del GDPR (decisione di adeguatezza o clausole contrattuali standard), come indicato nelle loro informative.
I tuoi diritti
Ai sensi degli artt. da 15 a 22 del GDPR puoi chiedere l'accesso ai tuoi dati, la rettifica, la cancellazione, la limitazione del trattamento, la portabilità, e opporti al trattamento. Puoi revocare in ogni momento il consenso prestato (art. 7, par. 3, GDPR), senza pregiudicare la liceità del trattamento precedente. Per esercitare i diritti scrivi a hello@simoneblax.com: la risposta arriva entro un mese (art. 12, par. 3, GDPR).
Hai diritto di proporre reclamo al Garante per la protezione dei dati personali (art. 77 GDPR), Piazza Venezia 11, 00187 Roma, garanteprivacy.it.
Decisioni automatizzate e minori
Il Titolare non adotta processi decisionali automatizzati, compresa la profilazione, ai sensi dell'art. 22 del GDPR. Gli strumenti di marketing di terzi, se li autorizzi, seguono le informative dei rispettivi fornitori. Il sito non è rivolto a minori di 14 anni (art. 2-quinquies del D.Lgs. 196/2003).
Modifiche
Questa informativa può essere aggiornata. La data dell'ultima versione è in alto nella pagina.
Under Arts. 13 and 14 of Regulation (EU) 2016/679, for users of simoneblax.com. Last update: 20 September 2026. Courtesy translation: the Italian version prevails.
Data controller
The data controller is Pagotto Simone, sole proprietorship, trading as Blax (Simone Blax), VAT IT11852300018, 10147 Turin (TO), Italy. Contact: hello@simoneblax.com.
The controller is not registered in the Italian Business Register. No Data Protection Officer (DPO) has been appointed, as the conditions of Art. 37 GDPR are not met.
Legal framework
Processing complies with Regulation (EU) 2016/679 (GDPR), Italian Legislative Decree no. 196 of 30 June 2003 (Personal Data Protection Code), as amended by Legislative Decree no. 101 of 10 August 2018, and the measures of the Italian Data Protection Authority (Garante).
Data processed, purposes and legal bases
Browsing data. The systems running the site collect, in normal operation, data whose transmission is implicit in the use of communication protocols: IP address, date and time of the request, requested page, browser and operating system. They are used to run and secure the site. Legal basis: legitimate interest of the controller (Art. 6(1)(f) GDPR).
Voluntary communications. If you write to the controller, contact them by phone or message, or book a call through the booking service embedded in the site (TidyCal), the controller processes the data you choose to provide, such as name, contact details and message content, to answer your request and, if a relationship follows, to manage it. Legal basis: steps taken at the data subject's request prior to entering into a contract, and performance of a contract (Art. 6(1)(b) GDPR).
Booking a call. When you book through TidyCal, the service (Sumo Group Inc.) sends a confirmation email to you and to the controller, records the booking in its own dashboard and adds the event to the controller's Google calendar (Google Calendar). The data you entered (for example name, email, date and time) stay saved in both places until deleted, which happens on your request.
Cookies and third-party tools. Analytics and marketing tools load only after your consent. Legal basis: consent (Art. 6(1)(a) GDPR; Art. 122 of Legislative Decree 196/2003). Details are in the Cookie Policy.
Legal obligations. If a contractual relationship begins, the data needed for invoicing and tax compliance are processed to comply with a legal obligation (Art. 6(1)(c) GDPR).
Nature of the provision of data
Browsing data are necessary for the site to work. Providing data in contact requests is optional, but without it a reply is not possible. Consent to analytics and marketing cookies is optional: refusing does not prevent you from browsing the site.
Retention
Browsing data are kept for the time strictly necessary, according to the hosting provider's settings. Data from contact requests and from bookings that do not lead to a professional relationship are kept until you request their deletion, which the controller carries out without delay and in any case within one month. Client data are kept for the duration of the relationship and for the ten years that follow (ordinary limitation period, Art. 2946 of the Italian Civil Code). Google Analytics keeps event data for 2 months and user-level data for 14 months, according to the account settings. Accounting and tax records are kept for ten years (Art. 2220 of the Italian Civil Code). Cookie lifetimes are listed in the Cookie Policy.
Recipients
Data are not disclosed. They may be processed by: the hosting provider (Aruba S.p.A.), which processes data on the controller's behalf to provide the service; the booking service provider (TidyCal) and Google, for the calendar where the booking is recorded (Google Calendar); the providers of analytics and marketing tools (Google, Hotjar, Meta), only if you have given consent; the Italian Exchange System (SdI) and the Revenue Agency, for electronic invoicing.
Transfers outside the EU
Some providers are based or have infrastructure outside the European Economic Area, in particular in the United States. Transfers rely on Implementing Decision (EU) 2023/1795 (Data Privacy Framework) for participating providers: Google LLC and Meta Platforms, Inc. appear among the certified participants (participants list). For other providers outside the EEA, such as Sumo Group Inc. (TidyCal), transfers rely on the safeguards each provider adopts under Arts. 45 and 46 GDPR (adequacy decision or standard contractual clauses), as stated in their notices.
Your rights
Under Arts. 15 to 22 GDPR you may request access to your data, rectification, erasure, restriction of processing, portability, and object to processing. You may withdraw consent at any time (Art. 7(3) GDPR), without affecting the lawfulness of earlier processing. To exercise your rights write to hello@simoneblax.com: you will receive a reply within one month (Art. 12(3) GDPR).
You have the right to lodge a complaint with the Italian Data Protection Authority (Art. 77 GDPR), Piazza Venezia 11, 00187 Rome, garanteprivacy.it.
Automated decisions and minors
The controller does not use automated decision-making, including profiling, under Art. 22 GDPR. Third-party marketing tools, if you allow them, follow their providers' notices. The site is not aimed at children under 14 (Art. 2-quinquies of Legislative Decree 196/2003).
Changes
This notice may be updated. The date of the latest version is at the top of the page.