Privacy Policy
Last updated: July 2026
Data controller
This website is operated by Kristina Mizevich, trading as Codivio Studio — a sole-trader (ditta individuale) registered in Italy. Registered address: Via Andrea Fantoni 21, 24022 Alzano Lombardo (BG), Italy. P.IVA: 04847670165. The data controller for all personal data processed through this site is Kristina Mizevich / Codivio Studio. Contact: [email protected]. A Data Protection Officer (DPO) has not been appointed, as this business does not fall within the categories that require one under Art. 37 GDPR.
Data we collect
We collect only data you actively provide: (a) contact data — name, email address, telephone number and the content of your message, when you write to us by email, WhatsApp or through any contact link on this site; (b) booking data — name, email address and time-zone, collected by Cal.com when you book a free consultation; (c) technical data — IP address, browser type and pages visited, processed automatically by our hosting infrastructure for security and performance purposes. We do not collect special categories of personal data (health, racial origin, political opinions, etc.).
Legal basis and purposes
We process your data on the following legal bases: (i) Art. 6(1)(f) GDPR — legitimate interest: to respond to enquiries and proposals you initiate (our legitimate interest is providing the requested information); (ii) Art. 6(1)(b) GDPR — contract performance: to manage signed project agreements and deliver agreed services; (iii) Art. 6(1)(c) GDPR — legal obligation: to retain invoices and fiscal documents as required by Italian law (D.P.R. 633/1972, Art. 2220 of the Civil Code); (iv) Art. 6(1)(a) GDPR — consent: for optional analytics and marketing cookies (Google Analytics 4, Meta Pixel), as described in the Cookies section below. We do not process your data for marketing, advertising or profiling purposes without your separate, explicit and freely given consent.
Cookies
This site uses the following categories of cookies, managed through our consent banner (Silktide Consent Manager): (1) technical cookies, strictly necessary for operation — a consent-preference cookie valid for 12 months that stores your choices, and session cookies set by the hosting infrastructure that expire when you close your browser; these do not require consent. (2) analytics cookies — Google Analytics 4 (Google Ireland Ltd.), set only if you accept the 'Analytics' category, used to understand in aggregate how visitors use the site. (3) marketing cookies — Meta Pixel (Meta Platforms Ireland Ltd.), set only if you accept the 'Marketing' category, used to measure the effectiveness of our advertising. Until you give consent, analytics and marketing tags remain disabled (Google Consent Mode v2, all signals default to 'denied') and no tracking cookies are placed. If you interact with the booking widget (Cal.com), Cal.com may set its own cookies subject to its own privacy policy. You may change or withdraw your cookie consent at any time via the cookie settings link in the page footer.
Third-party processors
Your data may be processed by the following categories of external processors acting strictly on our behalf under written GDPR-compliant data processing agreements: (a) hosting and CDN provider — Cloudflare, Inc.; (b) email service provider; (c) online booking service — Cal.com, Inc.; (d) instant messaging — WhatsApp (Meta Platforms Ireland Ltd.); (e) web analytics — Google Ireland Ltd. (Google Analytics 4), only with your consent; (f) advertising measurement — Meta Platforms Ireland Ltd. (Meta Pixel), only with your consent. We do not sell, rent, trade or otherwise share your personal data with any third party for their own independent purposes.
International data transfers
Cal.com, Inc. is headquartered in the United States. Transfers of personal data to Cal.com are governed by Standard Contractual Clauses (SCCs) adopted pursuant to European Commission Decision 2021/914. Cloudflare processes data primarily in EU/EEA data centres; transfers outside the EEA are covered by SCCs and Cloudflare's EU Data Processing Addendum. Google and Meta may transfer certain data to the United States; both are certified under the EU-U.S. Data Privacy Framework and additionally rely on SCCs. We do not transfer personal data to countries that lack an EU adequacy decision without first ensuring that appropriate safeguards are in place as required by Chapter V GDPR.
Retention periods
Contact and enquiry data (name, email, messages): retained for 24 months from the date of last interaction, then deleted or anonymised. Booking data (Cal.com): retained in accordance with Cal.com's own retention policy. Contract and fiscal records (invoices, project agreements): retained for 10 years as required by Art. 2220 of the Italian Civil Code and Italian tax legislation. Cookie consent preferences: stored for 12 months.
Your rights
Under Arts. 15-22 GDPR you have the right to: (1) access your personal data (Art. 15); (2) obtain rectification of inaccurate data (Art. 16); (3) obtain erasure of your data where grounds apply — the 'right to be forgotten' (Art. 17); (4) restrict processing in specific circumstances (Art. 18); (5) receive your data in a portable, machine-readable format (Art. 20); (6) object to processing based on legitimate interest, including any profiling (Art. 21). Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3)). To exercise any of these rights write to [email protected]. We will respond within 30 days as required by Art. 12 GDPR, extendable by a further 60 days for complex requests.
Right to complain to the supervisory authority
You have the right to lodge a complaint with the competent data protection supervisory authority at any time, without prejudice to any other administrative or judicial remedy. In Italy, the supervisory authority is the Garante per la Protezione dei Dati Personali: website www.garanteprivacy.it — address Piazza Venezia 11, 00187 Rome, Italy — email [email protected]. If you are resident in another EU member state, you may also lodge a complaint with the supervisory authority of that state.
Automated decision-making
We do not carry out any processing consisting solely of automated decision-making, including profiling, that produces legal effects or similarly significantly affects you, as described in Art. 22 GDPR.
Changes to this policy
We may update this policy at any time to reflect changes in our practices or applicable law. The current version is always available at codivio.studio/privacy with the date of last update. Where changes are material, we will endeavour to notify you directly where we hold your contact details.