Privacy Policy
Last updated: July 17, 2026
1. Controller and scope
The data controller is READING RETREATS IN RURAL ITALY A.P.S. (the “Association”, “we”, “us”), Codice Fiscale 91154310378, RUNTS registration no. 122511. Registered office: c/o Savi Consulting SRL - STP, Via Pietro Nenni 6/B, 46100 Mantova (MN), Italy. Operational location: Via Macchina Fissa 107, 46034 Borgo Virgilio (MN), Italy.
This notice applies to readingretreats.com, membership and event workflows, stay and internship enquiries, visits, newsletters, donations, and related communications. It is provided under Articles 12–14 of Regulation (EU) 2016/679 (“GDPR”) and applicable Italian data-protection law.
2. Data we process and where it comes from
- Identity and contact data: name, email, telephone number, address, city, postcode, country, nationality, date and place of birth, and Italian tax code where required.
- Membership data: application, membership number, dates and status, declarations accepting the Statute and applicable terms, and internal admission or governance records.
- Minor and guardian data: the minor’s details and the guardian’s identity, relationship, contact details, tax code, signature, and consent where a paper application is submitted.
- Event, visit, stay, and internship data: selected event, visit date or time, arrival and departure dates, number of guests, interests, experience, motivation, messages, attendance, and related organisational information.
- Payment and donation data: amount, currency, payment status and method, transaction, order or capture identifiers, fee and contribution breakdown, and refund status. Card and bank credentials are entered directly with PayPal and are not stored by us.
- Communications and consent data: messages, email delivery information, newsletter preference, consent source and text version, timestamps, unsubscribe events, and limited evidence needed to demonstrate the choice.
- Technical and security data: IP address and approximate location available to our hosting or security providers, request headers, browser and device information, user agent, timestamps, form-security results, short-lived rate-limit identifiers, and server or error logs.
- Media and content: photographs, recordings, testimonials, or other material supplied or authorised for association communications.
- Administrator data: account identifiers, role, authentication and multi-factor status, session-security events, and audit information for authorised Association personnel.
We normally obtain data directly from you or, for minors, from a guardian. We may also receive transaction status from PayPal, unsubscribe or delivery events from EmailOctopus, and records created by authorised Association personnel. Please do not place health information, political or religious views, or other special-category data in free-text fields unless we specifically request it and explain the applicable basis.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Answer contact, stay, internship, accessibility, or other requests and take requested pre-contractual steps. | GDPR Art. 6(1)(b); our legitimate interest in handling communications, Art. 6(1)(f), where no contract is contemplated. |
| Receive and decide membership applications, maintain the member register, administer members, and carry out statutory governance. | Art. 6(1)(b) and (c); obligations under the Civil Code, Legislative Decree 117/2017 and other rules applicable to APS entities; legitimate organisational interests under Art. 6(1)(f). |
| Organise events, visits, stays, internships, capacity, attendance, safety communications, confirmations, cancellations, and any agreed service. | Art. 6(1)(b) and (c), and Art. 6(1)(f) for proportionate safety and organisational needs. |
| Process membership-fee payments, voluntary donations, accounting, reconciliation, refunds, and fraud prevention. | Art. 6(1)(b), (c), and (f); legal obligations include accounting, tax, anti-fraud, and record-keeping duties. |
| Send service, application, payment, event, and policy communications. | Art. 6(1)(b), (c), and, where appropriate, Art. 6(1)(f). |
| Send newsletters and manage subscription preferences. Optional email-open or link-click measurement is used only where enabled and lawfully covered by consent. | Consent, Art. 6(1)(a). Evidence of consent and suppression records may be retained under Art. 6(1)(c) and (f). Consent can be withdrawn at any time. |
| Publish photographs, testimonials, or other identifiable member or participant content. | Consent, Art. 6(1)(a), unless another basis is clearly communicated for the specific context. Consent withdrawal does not affect earlier lawful use. |
| Deliver, secure, troubleshoot, back up, and protect the site and information systems, including bot checks, rate limits, access controls, and incident response. | Our legitimate interests in availability and security, Art. 6(1)(f), and legal obligations, Art. 6(1)(c). Strictly necessary device storage is used under Art. 122 of the Italian Privacy Code. |
| Establish, exercise, or defend legal claims and respond to competent authorities. | Art. 6(1)(c) and (f); if special-category data is involved, Art. 9(2)(f) where applicable. |
Where we rely on legitimate interests, we assess necessity, proportionality, and the effect on your rights. You may ask for information about that assessment and object as explained below.
4. Required and optional information
Fields marked as required are needed to answer the request, verify eligibility, process an application or payment, satisfy legal duties, or organise an activity. Without them, we may be unable to process the request, admit a member, confirm a registration, or issue the required records. Newsletter consent, publication consent, non-required messages, and any donation above zero are optional and do not determine membership admission.
5. Automated checks and decisions
The site performs automated validation, duplicate, age, payment-status, reservation-expiry, capacity, fraud, and security checks. These support the requested workflow but are not used to make decisions based solely on automated processing that produce legal or similarly significant effects under GDPR Article 22. Membership admission is decided by the Association’s competent body or delegate in accordance with the Statute.
6. Recipients and service providers
Access is limited to authorised Association personnel and the following recipients to the extent necessary:
| Recipient | Use and data involved | Role |
|---|---|---|
| Vercel | Hosting, content delivery, serverless gateway, WAF and BotID; request, device, security, log and form-traffic data. | Processor for our hosted service; controller for its separate account or service operations. |
| Supabase | Database, backend functions and administrator authentication; membership, person, event, payment, consent and administrative records. | Processor. |
| PayPal | Payment and donation processing, fraud and regulatory checks; transaction, payer, account, device and payment-instrument data. We receive transaction references and status, not full card credentials. | Independent controller for its payment processing. |
| Resend | Transactional and enquiry email delivery; recipient, subject, message content and delivery metadata. | Processor. |
| EmailOctopus | Newsletter list and campaigns; name, email, subscription status, delivery, bounce, unsubscribe and, where enabled, open/click data. | Processor. |
| Upstash | Short-lived Redis rate-limit counters. Email, tax-code, token, order or similar subjects are HMAC-pseudonymised before being used as keys. | Processor. |
| Cloudflare R2 | Storage and delivery of site media, including authorised images, and restricted encrypted-at-rest database backups. Public media requests expose normal network metadata to Cloudflare. | Processor for stored content; controller for limited service-security operations. |
| GitHub Actions | Automated database-backup execution. A database copy is processed transiently on a restricted workflow runner before upload to R2. | Processor/service provider under the applicable account terms. |
| Google Maps | Interactive location map loaded only after cookie consent; IP address, device/browser data, referrer, identifiers and interaction data may be processed by Google. | Independent controller. |
| Google Fonts and Fontshare | Some HTML email clients may request remote font resources, disclosing normal request metadata. Public website fonts are self-hosted. | Independent recipients for those resource requests. |
| placehold.co | Remote placeholder images on limited content pages; IP address, user agent, referrer and request time. | Independent recipient for resource delivery. |
We may also disclose data to accountants, legal or technical advisers, insurers, banks, public authorities, RUNTS or other bodies where necessary and lawful. Links to social media, accommodation providers, PayPal, Google Maps, or other external sites are user-initiated; the third party’s own notice applies after you follow the link. We do not sell personal data.
7. International transfers
Some providers and subprocessors may process data outside the European Economic Area. Where we are responsible for the transfer, we use an applicable adequacy decision, including the EU–US Data Privacy Framework where valid and applicable, European Commission Standard Contractual Clauses, and supplementary contractual, organisational, or technical safeguards. Provider locations and subprocessors can change. You may request information about the applicable transfer mechanism and a copy of the relevant safeguards, subject to necessary redactions.
8. Retention
| Record | Retention criterion |
|---|---|
| Contact, stay, and internship enquiries | For handling and follow-up, ordinarily no more than 24 months after the last meaningful contact, unless the relationship continues or longer retention is needed for a claim. |
| Membership, guardian, and statutory records | For the membership relationship and afterward for the period required to maintain the statutory member register, document the Association’s legal history, meet Third Sector obligations, and handle claims. Accounting components are generally retained for 10 years. |
| Payment, donation, refund, and accounting records | Generally 10 years from the relevant accounting entry, or longer if a dispute, audit, or legal hold requires it. Completed PayPal webhook payloads in the operational inbox are automatically removed after 90 days. |
| Event and visit records | For organisation and follow-up, ordinarily up to 24 months after the activity; financial, membership, safety, or claim evidence may be retained for the corresponding statutory or limitation period, generally up to 10 years. |
| Newsletter records | Active contact data until unsubscribe or deletion. A minimal suppression record and consent evidence may be retained for the period needed to honour the objection and demonstrate compliance. Pending confirmation requests and their metadata are removed after 30 days; EmailOctopus replay identifiers after 30 days. |
| Security data and rate limits | Only for the relevant security window and subsequent incident review. Upstash counters expire with their configured window, usually minutes or hours and no more than 24 hours for current public rules. Security logs may be kept longer if needed to investigate an incident. |
| Media and publication permissions | While the content is used and for a proportionate archival period, unless consent is withdrawn or another legal basis or legal hold applies. |
| Backups | Under a restricted disaster-recovery rotation based on security, recovery, and legal-retention needs. Data removed from live systems is not restored for ordinary use and expires from backups at the next applicable rotation unless a legal hold applies. |
At the end of the relevant period, data is deleted, anonymised, or access is restricted. A documented legal hold overrides ordinary deletion only for as long as necessary.
9. Cookies and similar technologies
We use strictly necessary cookies, local storage, session storage, and security technologies. Google Maps is blocked until you consent. We do not use website analytics or advertising pixels. Names, purposes, durations, and controls are described in our Cookie Policy.
10. Minors
Online membership and event forms are intended for adults. A person under 18 must use the dedicated paper procedure countersigned by a parent or legal guardian. We limit minor and guardian data to admission, safety, participation, and legal requirements. We do not knowingly send direct marketing to minors or publish an identifiable minor’s image without the required guardian authorisation and a lawful basis.
11. Security
We use role-based access, administrator multi-factor authentication, short sessions, transport encryption, database access policies, input validation, anti-bot and rate-limit controls, restricted backups, and provider contracts. No internet service can guarantee absolute security. Please notify us promptly if you believe your information or an Association communication has been compromised.
12. Your rights
Subject to the GDPR’s conditions and exceptions, you may:
- request access to and a copy of your data;
- request correction, completion, erasure, or restriction;
- receive data you provided in a structured, commonly used, machine-readable format and request portability where applicable;
- object, on grounds relating to your situation, to processing based on legitimate interests, and object at any time to direct marketing;
- withdraw consent at any time without affecting processing already lawfully performed; and
- not be subject to a solely automated decision with legal or similarly significant effects where Article 22 applies.
Contact us using the details below. We may ask for proportionate identity verification and normally respond within one month; the GDPR permits an extension of up to two further months for complex or numerous requests, with notice. Rights may be limited where the law requires retention or protects another person’s rights.
You may also lodge a complaint with the Italian Data Protection Authority (Garante) or another competent supervisory authority, and you retain the right to a judicial remedy.
13. Changes to this notice
We may update this notice when our activities, providers, or legal duties change. The date at the top is a manually maintained publication date and does not change automatically. Material changes will be highlighted through an appropriate channel where required. Previous processing remains governed by the notice and legal basis applicable at that time.
Contact the controller
Privacy requests: info@readingretreats.com
PEC: readingretreatsinruralitaly@pec.it
Postal address: Via Pietro Nenni 6/B, 46100 Mantova (MN), Italy