Privacy Policy
INFORMATION ON THE PROCESSING OF PERSONAL DATA
Pursuant to Article 13 of EU Regulation No. 2016/679 – GDPR
This page describes the processing operations performed on the personal data of the users visiting the website www.lauraclarke.it (from now on the website), which can be accessed at the Internet address https://lauraclarke.it/. The information provided does not concern other websites, pages or online services that can be accessed via hyperlinks that may be published on the website but which relate to external resources.
- DATA CONTROLLER
The data controller is Laura Gail Clarke, VAT no. 17988341008; email lauragclarke@gmail.com
- DATA PROCESSOR
The list of data processors appointed by the data controller is available on request at the following address: lauragclarke@gmail.com.
- METHODS OF PROCESSING PERSONAL DATA
The processing of personal data, provided and/or acquired, will be inspired by the principles of lawfulness, fairness and transparency as well as by the protection of their confidentiality in accordance with the provisions of current legislation. The data controller also undertakes to restrict the purposes of the data processing to those strictly necessary for the use of the website and the fulfilment of contractual objectives; to ensure that the data are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed; accurate and, where appropriate, kept up to date; kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
- CATEGORIES OF DATA AND PURPOSES OF THE PROCESSING
4.1 DATA COMMUNICATED BY THE USER
Sending messages, on the basis of the user’s free, voluntary, explicit choice, to the contact form entails the acquisition of the sender’s contact information (First Name, Surname, email address), which is necessary for the Controller to provide a reply.
4.2 NAVIGATION DATA
The computer systems and software procedures used to operate this website acquire, during normal operation, some navigation data that are transmitted implicitly in the use of Internet communication protocols. These are data relating to telematic traffic which by their very nature cannot be immediately associated with identified subjects, but through processing or association with data held by third parties could allow users / visitors to the website to be identified (such as, for example, IP addresses, type of browser and operating system used by the user, time of request to access the web pages). These data are used only for anonymous statistical information relating to visits to the website or to verify its correct functioning.
These data are stored by the company Aruba S.p.A. – via San Clemente, 53 – 24036 Ponte San Pietro (BG) https://www.datacenter.it/home.aspx
4.3 COOKIES AND OTHER TRACKING SYSTEMS
With regard to cookies, please read the Full Information on the use of Cookies (link).
The owner of this website undertakes not to transfer the stored data to third parties except to the competent authorities upon formal request in the event of detection of unlawful acts.
- PURPOSES AND LEGAL BASIS OF THE PROCESSING
Use of the content and technical functionalities of the website
Purpose: To allow the user to correctly view the web pages, navigate the website and access the requested content.
Legal basis: Art. 6, par. 1, lett. b) GDPR – the processing is necessary for the execution of pre-contractual measures taken at the request of the data subject.
Website security and prevention of unauthorised access
Purpose: To monitor the integrity of the website, prevent intrusion, abuse, cyberattacks or unauthorised access.
Legal basis: Art. 6(1)(f) GDPR – legitimate interest of the data controller to ensure the security of information systems and prevent malicious activity.
Collection of technical logs and anonymised browsing data
Purpose: To keep track of technical activities (IP address, time, requested URL, browser type) for diagnostic, management and service improvement purposes.
Legal basis: Art. 6(1)(f) GDPR – legitimate interest of the data controller in the proper functioning of the website and the management of technical logs.
Technical cookies
Purpose: to enable the proper functioning of the website and its essential functions (e.g. session management, setting preferences, access to protected content, computer security).
Legal basis: Art. 6, par. 1, lett. b) GDPR – the processing is necessary for the provision of the service requested by the user (website navigation).
The consent of the user is not required, as these cookies are indispensable for the use of the website and are among those considered ‘exempt’ under the Italian Data Protection Authority’s Cookie Guidelines and other tracking tools (July 2021).
Analytics cookies (not third-party or anonymised)
Purpose: to collect information in aggregate and anonymised form on the use of the website by users (e.g. number of visits, most viewed pages, dwell time), for the sole purpose of carrying out internal statistical monitoring and improving the content quality.
Legal basis: Art. 6, par. 1, lett. f) GDPR – legitimate interest of the data controller in producing anonymous statistics to optimise the use of the website and its content.
Consent is not required provided that the cookies are either first/party cookies or third-party cookies that have been anonymised in such a way that the user cannot be identified (e.g. IP anonymisation on Google Analytics).
Handling of requests via the contact form
Purpose: To respond to requests for information, clarification or quotes sent via the contact form on the website.
Legal basis: Art. 6, par. 1, lett. b) GDPR – execution of pre-contractual measures at the request of the data subject; alternatively, Art. 6, par. 1, lett. f) GDPR – legitimate interest of the data controller in managing contact information.
- RECIPIENTS OF THE DATA
The recipients of the data collected during the course of visiting the website are the subjects appointed as data processors by the data controller pursuant to Art. 28 GDPR, who operate according to precise and binding instructions provided by the data controller, characterised by obligations of confidentiality and security. The list of data processors is available upon specific request by the user. Data processing is carried out using mixed, automated and manual methods, but the decision-making process takes place, in any case, following an autonomous decision by the data controller or data processor, in the manner described above.
- TRANSFER OF PERSONAL DATA
Users’ personal data will be processed within the European Union; the data centres of Aruba s.p.a. are located within EU territory. Below is the privacy policy: https://www.aruba.it/documents/tc-files/it/11_it_privacy_policy_aruba_spa.aspx
7.1 TRANSFER OF DATA TO NON-EU COUNTRIES
Users’ personal data will be processed within the European Union; the data centres of Aruba s.p.a. are located within EU territory. Below is the privacy policy: https://www.aruba.it/documents/tc-files/it/11_it_privacy_policy_aruba_spa.aspx
The personal data will be processed within the European Union; the data centres of Aruba are located in Italy (Milan, Arezzo, Rome) and in the Czech Republic (Ktis), and are only handled by technical personnel of the company in charge of the processing. No data is communicated or disclosed to third parties for purposes other than those explicitly functional to the services.
Should it become necessary to transfer personal data to countries outside the European Economic Area (EEA), such operations will be carried out in strict compliance with the provisions set out in Articles 44 to 49 of Regulation (EU) 2016/679. In particular, data may only be transferred to States for which the European Commission has adopted an adequacy decision pursuant to Article 45 GDPR, or – in the absence of such a decision – only on condition that appropriate safeguards have been adopted pursuant to Article 46 GDPR, including, by way of example, standard contractual clauses approved by the European Commission.
In the case of transfer of user data to the United States in relation to the use of IT tools and cloud platforms, the data controller guarantees that it only uses entities registered under the Data Privacy Framework between the European Union and the United States. This adherence allows the guaranteed level of protection to be considered compliant with the requirements of the GDPR, as per the adequacy decision adopted by the European Commission.
Further information on the programme can be found on the European Commission’s institutional website. In any case, the transfer will only take place where strictly necessary for the purposes indicated above and will be based on the principles of lawfulness, fairness and transparency, guaranteeing the data subject the effective exercise of their rights and access to adequate means of redress.
- LINKS TO EXTERNAL SOCIAL MEDIA
This website may contain hyperlinks to pages or profiles on social network platforms (e.g. Facebook, Instagram, LinkedIn, YouTube).
These links are provided solely to facilitate user navigation and promote the online presence of the data controller. By clicking on these links, the user will be redirected to external websites, whose management is under the exclusive responsibility of the respective providers.
Please note that the managers of social networks operate as independent data controllers and that by accessing these platforms, the data subject is subject to the relevant conditions of use and privacy policies.
For more information, please consult the policies made available by each provider:
LinkedIn: https://www.linkedin.com/legal/privacy-policy
The data controller is not responsible for the methods of data processing carried out by third parties, accessible via links from this website.
- STORAGE PERIOD
According to the provisions of art. 5 of the GDPR, letter e), co. 1, the data are stored for a period of time not exceeding the fulfilment of the purposes for which they are processed.
Specifically:
– The data collected for the purpose of carrying out the professional assignment will be retained, according to legal specifications, for the time necessary to fulfil the purposes described in this document and in those connected to it;
– The data collected for the purpose of fulfilling accounting/tax obligations will be retained, according to legal specifications, for the time necessary to fulfil the purposes described in this document and in those connected to it;
– The data collected for purposes that are attributable to the exercise of the legitimate interest of the data controller (always exercised in compliance with the interests or fundamental rights and freedoms of the data subject that require the protection of personal data, in particular if the data subject is a minor) will be retained for the time necessary to satisfy the above. In any case, the user has the right to obtain further information relating to the legitimate interest pursued by the data controller by contacting the data controller herself.
– In any case, the data collected with the user’s consent will be retained until such consent is revoked by the user, except when it is necessary to comply with legal obligations or an order from an authority.
At the end of the storage period, the user’s data will be deleted and/or, where possible and/or permitted, will be anonymised.
- OBLIGATION TO PROVIDE DATA AND CONSEQUENCES
The communication of personal data is a necessary condition for the provision of the services indicated on the website. The user has the right to provide consent to the processing of their personal data; in the event of refusal, it will be possible to continue browsing the website but it will not be possible to provide any of the services offered on this website.
- RIGHTS OF THE DATA SUBJECT
The data subject may exercise at any time, in relation to the data processing described, the rights provided for by the relevant legislation on personal data protection, including the right to:
11.1 Receive confirmation of the existence of personal data and access their content (right of access);
11.2 Update, modify and/or correct personal data (right of rectification);
11.3 Request the deletion or restriction of the processing of data processed in violation of the law, including data that do not need to be retained in relation to the purposes for which they were collected or otherwise processed (right to erasure and right to restriction);
11.4 Object to processing based on legitimate interest (right of opposition);
11.5 Revoke consent, without prejudice to the lawfulness of processing based on consent given before revocation;
11.6 File a complaint with the Supervisory Authority in the event of violation of the regulations on the protection of personal data;
11.7 Receive, upon request, in electronic format a copy of the personal data provided for the services for which consent was given (right to data portability).
To exercise these rights, the user may make a specific request at any time to the data controller indicated in point no. 1.
Last updated: July 2025