Privacy Policy of Siena Art Institute

Last updated: 08/08/2026

Data Controller

Siena Art Institute
Via Enea Silvio Piccolomini 2, 53100 Siena (SI) — C.F./P.IVA 92055650524
Controller contact email: office@sienaart.org

Types of Data collected

Among the personal data processed by this website, either directly or through third parties, are: IP address, usage data; IP address, usage data, data entered in forms; email address, name; usage data, online identifiers. Complete details on each type of data are provided in the sections dedicated to the individual services. Data may be provided voluntarily by the user (for example by filling in a contact form) or collected automatically while browsing (for example usage data and technical identifiers).

Users who choose not to provide certain data may be unable to use the corresponding services (for example, a contact request cannot be answered without contact details).

Purposes and legal bases of processing

Data are processed for the following purposes:

For processing based on consent (art. 6.1.a GDPR), such as non-technical cookies, consent may be withdrawn at any time without affecting the lawfulness of processing carried out beforehand.

Methods and place of processing

Processing is carried out using IT and telematic tools, with security measures adequate to prevent unauthorised access, disclosure, modification or destruction of the data. In addition to the Controller, the data may be accessed by authorised internal parties and by external providers appointed, where necessary, as data processors (art. 28 GDPR), such as hosting and technical service providers. The data are processed at the Controller's operating offices and at the data centres of the providers listed in this policy.

Where a service involves the transfer of data outside the EU (in particular to the United States), the transfer takes place on the basis of adequacy decisions of the European Commission or standard contractual clauses (arts. 45 and 46 GDPR).

Retention period

Data are kept for the time necessary for the purposes for which they were collected: data provided to answer a request are kept for the time needed to handle it and for any legal obligations; data collected on the basis of consent are kept until consent is withdrawn, unless further retention obligations apply.

Third-party services used by this website

Google Analytics 4

Provider: Google Ireland Limited. Purpose: aggregate statistics on website usage. Data processed: usage data, online identifiers. Transfers to Google LLC (USA) are covered by the EU-US Data Privacy Framework. Provider's privacy notice: https://policies.google.com/privacy.

Meta Pixel

Provider: Meta Platforms Ireland Ltd. Purpose: ad measurement and remarketing. Data processed: usage data, online identifiers. Possible transfer to Meta Platforms Inc. (USA) under the Data Privacy Framework. Provider's privacy notice: https://www.facebook.com/privacy/policy.

MailerLite (newsletter)

Provider: MailerLite Limited (Ireland). Purpose: newsletter subscription management, at the user's request. Data processed: email address, name. Provider's privacy notice: https://www.mailerlite.com/legal/privacy-policy.

Google Fonts

Provider: Google Ireland Limited. Purpose: display of typefaces. Data processed: IP address, usage data. Provider's privacy notice: https://policies.google.com/privacy.

Vercel (hosting)

Provider: Vercel Inc. (USA). Purpose: website hosting, content delivery network and technical infrastructure (technical logs and cookieless analytics). Data processed: IP address, usage data. Transfer to Vercel Inc. (USA): the provider states in its privacy notice that it is certified under the EU-US Data Privacy Framework. Provider's privacy notice: https://vercel.com/legal/privacy-notice.

Supabase (database and backend)

Provider: Supabase, Inc. (USA). Purpose: website database, content storage and authentication of the reserved area. Data processed: IP address, usage data, data entered in forms. Transfers outside the EU are governed by standard contractual clauses (EU Decision 2021/914) incorporated in the provider's DPA (supabase.com/legal/dpa). Provider's privacy notice: https://supabase.com/privacy.

Record of consents

When the user gives consent through the website forms (for example by subscribing to the newsletter or sending a contact request), the Controller keeps evidence of the consent (date, form filled in and content transmitted) in order to demonstrate that it was given, pursuant to art. 7 GDPR. These records are kept for as long as the consent remains active and for the applicable limitation periods.

Rights of the user

Under articles 15-22 GDPR, users have the right to obtain from the Controller access to their data, rectification, erasure, restriction of processing and portability, as well as the right to object to processing and to withdraw any consent given. Requests should be addressed to office@sienaart.org.

Users also have the right to lodge a complaint with the competent supervisory authority: for Italy, the Garante per la protezione dei dati personali (www.garanteprivacy.it).

Cookies

This website uses cookies and similar tools. The full notice is available in the Cookie Policy.

Changes to this policy

The Controller may amend this policy at any time by publishing the updated version on this page. The date of the last update is shown at the top.