Privacy Policy
Last updated: August 12, 2026
This privacy policy describes how Omniaweb S.r.l.s processes the personal data of users of the omniamarketing.it website, in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and Legislative Decree 196/2003, as amended by Legislative Decree 101/2018 (“Privacy Code”).
1. Data Controller
The Data Controller is Omniaweb S.r.l.s, VAT No. 09553001216, with registered office at Vico Bagnara, 4 — 80135 Naples. For any inquiries regarding the processing of personal data, please write to info@omniamarketing.it. Given the size of the organization, there is no mandatory requirement to appoint a Data Protection Officer (DPO) pursuant to Article 37 of the GDPR; the related functions are carried out directly by the Data Controller.
2. What Data Do We Collect?
Depending on how you interact with the site, we may collect:
- Contact information — name, email address, phone number (optional), and the content of your message, when you fill out the contact form or the information request pop-up.
- Newsletter subscription data — email address, when you voluntarily subscribe to receive updates from our blog.
- Tax information — address, ZIP code, city, and tax ID number, only if necessary to issue accounting documents for an ongoing contractual relationship.
- Anonymous personalization data — a randomly generated identifier, the name you optionally provide, and the categories of content you visit, stored only on your device and never transmitted to our servers. Full details are available in the Cookie Policy.
- Technical browsing data — IP address, browser and device type, and pages visited, collected automatically by the hosting infrastructure for security purposes and to ensure the proper functioning of the service, and stored in system logs for a limited period.
3. Purposes and Legal Bases for Data Processing
| Purpose | Legal Basis |
|---|---|
| To respond to contact requests or requests for quotes | Pre-contractual measures at your request (Art. 6.1.b GDPR) |
| To provide a service that has already been requested | Performance of the contract (Art. 6.1.b GDPR) |
| Accounting and tax compliance | Legal obligation (Art. 6.1.c GDPR) |
| Sending the newsletter | Consent (Art. 6.1.a GDPR), which may be revoked at any time |
| Anonymous content personalization | Consent (Art. 6.1.a GDPR), revocable at any time |
| Technical security, prevention of misuse, system logs | Legitimate interest of the Data Controller (Art. 6.1.f GDPR) |
4. Recipients and External Data Processors
Your data may be processed, on our behalf and in their capacity as data processors pursuant to Article 28 of the GDPR, by the following service providers:
- Supabase Inc. — database hosting and file storage (portfolio images/videos). It provides a GDPR-compliant Data Processing Addendum.
- Resend — sending transactional emails and newsletters. It is certified under the EU-U.S. Data Privacy Framework, the transfer mechanism deemed adequate by the European Commission in its decision of July 10, 2023.
- Application hosting provider — technical operation of the website and related security logs.
We do not sell or transfer your personal data to third parties for marketing purposes by entities other than ourselves.
5. Data Transfers Outside the EU
Some of the suppliers listed in section 4 have their headquarters or infrastructure in the United States. In these cases, data transfers are carried out on the basis of appropriate safeguards pursuant to Chapter V of the GDPR: the provider’s participation in the EU-U.S. Data Privacy Framework, or, failing that, the adoption of the Standard Contractual Clauses approved by the European Commission via Implementing Decision (EU) 2021/914.
6. Retention Period
- Contact requests: up to 24 months from the last contact, unless otherwise required by law.
- Newsletter subscription: until you unsubscribe, which you can do with a single click in every email.
- Accounting and tax data: 10 years, as required by civil and tax laws.
- Anonymous personalization data: remains only on your device, never on our servers; you can delete it yourself at any time (see point 9).
- Technical system logs: generally no longer than 6 months, unless there are proven security needs or the need to investigate criminal offenses.
7. Data Security
We implement appropriate technical and organizational measures to protect data from unauthorized access, loss, or disclosure: encrypted HTTPS connections, professional hosting infrastructure, and access to the administrative area that is protected by authentication and restricted to authorized personnel.
8. Minors
This website is not intended for children under the age of 16, and we do not knowingly collect data from children. If you believe a child has provided us with personal information, please contact us to have it removed.
9. Manage Your Preferences
For anonymous content personalization (based on consent), you can enable or disable it at any time directly from here:
Gestisci le tue preferenze
Caricamento…
10. Your Rights
At any time, and without having to provide a reason, you have the right to:
- access your personal data (Art. 15 GDPR);
- request that it be corrected or updated (Art. 16 GDPR);
- request the erasure of your personal data (Art. 17 GDPR);
- request that processing be restricted (Art. 18 GDPR);
- object to the processing (Art. 21 GDPR);
- request data portability (Art. 20 GDPR);
- withdraw previously given consent, without affecting the lawfulness of processing carried out prior to the withdrawal (Art. 7.3 GDPR).
To exercise these rights, simply write to info@omniamarketing.it. We will respond within 30 days, as required by Art. 12 of the GDPR.
If you believe that the processing of your data violates applicable law, you have the right to file a complaint with the competent supervisory authority: the Italian Data Protection Authority — Piazza Venezia, 11, 00187 Rome, certified email (PEC) protocollo@pec.gpdp.it, website www.garanteprivacy.it.
11. Changes to This Privacy Policy
This privacy policy may be updated from time to time, for example, in the event of regulatory changes or new services offered by the website. The date of the last update is indicated at the top of the page.