Privacy Policy
Last updated: 08/09/2026
This notice explains what happens to personal data on https://lucaprata.com/. It is written under articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended.
The short version: this Site sells professional services. It collects what an order needs, it uses no advertising or analytics trackers, and it does not sell or share data for anyone else’s marketing.
1. Who is responsible
The data controller is:
P.IVA: 10637600965
Piazza IV Novembre, 4 20124 Milano MI
Italy
Email: info@lucaprata.com
Tel: +390173280479
Sito: lucaprata.com/
Write to info@lucaprata.com for anything in this notice, including to exercise the rights in clause 8. No Data Protection Officer is appointed: the processing does not meet the conditions in art. 37 GDPR.
2. What is collected, why, and on what legal basis
2.1 Booking and buying a service
When you book a slot and pay, the following is collected: name, email address, company name, country, VAT number, the topic chosen, the service chosen, the slot chosen, and any note you write.
- Purpose: to form and perform the contract — confirming the slot, taking payment, doing the work, answering you.
- Legal basis: art. 6(1)(b) GDPR, performance of a contract or steps taken at your request before entering one.
- Consequence of not providing it: the order cannot be placed. The email address in particular is required, because the invoice and the confirmation go to it.
Do not put special-category data (health, beliefs, and the rest of art. 9 GDPR) in the free-text note. It is not needed and it will be deleted.
2.2 Invoicing and accounting
The billing details and the transaction record are kept because they must be.
- Purpose: issuing invoices, tax and accounting obligations, electronic invoicing to the Italian Revenue Agency where required.
- Legal basis: art. 6(1)(c) GDPR, compliance with a legal obligation.
2.3 Payment
Payment happens on a page operated by easy Gateway, the payment platform of LANGA Corporation S.r.l., and is completed by the payment provider you choose. Card numbers are never transmitted to, stored by, or visible to this Site. This Site receives the outcome of the payment, the amount, the method and the reference — not your card or account credentials.
- Legal basis: art. 6(1)(b) GDPR for the payment itself; art. 6(1)(c) for the anti-fraud and record-keeping duties that bind payment providers.
2.4 The free intro call
A request for the free call collects name, email, company and topic, and is handled by email.
- Legal basis: art. 6(1)(b) GDPR, steps taken at your request before entering a contract.
2.5 Security, logs and abuse prevention
The server records the usual technical data of any web request: IP address, date and time, page requested, browser and operating system reported, and the referring page. Requests to the ordering endpoint are rate-limited per IP address to stop abuse.
- Purpose: keeping the Site up, diagnosing faults, blocking abuse and attacks.
- Legal basis: art. 6(1)(f) GDPR, legitimate interest in the security and availability of the Site — an interest that does not override your rights, because the data is technical, kept briefly, and not used to build any profile of you.
2.6 Cookies and similar technologies
Only strictly necessary and functional storage is used by default. Nothing that is not strictly necessary is set before you consent to it. The detail is in the Cookie Policy.
- Legal basis: art. 6(1)(f) GDPR and art. 122 of Legislative Decree 196/2003 for strictly necessary storage; art. 6(1)(a) GDPR, consent, for anything else.
3. What is not done
- No advertising, no advertising cookies, no remarketing, no advertising identifiers.
- No analytics or audience-measurement service.
- No sale of personal data, and no disclosure to third parties for their own marketing.
- No newsletter unless you ask for one; there is none at present.
- No automated decision-making and no profiling within the meaning of art. 22 GDPR.
4. Who else sees the data
Data is seen only by people and companies that need it, each bound by contract or by law:
- LANGA Corporation S.r.l. — hosting, site maintenance and the easy Gateway payment platform. Servers in the European Union.
- Payment providers, according to the method you choose: Stripe (card), PayPal, Satispay, and the receiving bank for SEPA transfers. Each is an independent controller for its own anti-fraud and regulatory duties and publishes its own notice.
- The Italian Revenue Agency and the accountant, for invoicing and tax.
- Google Ireland Ltd — the Site loads its typefaces from Google Fonts. Your browser therefore connects to
fonts.googleapis.comandfonts.gstatic.com, and Google receives your IP address and the technical headers of that request. No cookie is set by this and no account of yours is involved. If you would rather this did not happen, a browser extension that blocks those two hosts prevents it; the Site stays usable. - Public authorities, where the law requires it.
Suppliers acting on instructions are appointed as processors under art. 28 GDPR. A current list of processors can be requested at the address in clause 1.
5. Transfers outside the European Economic Area
The hosting and the ordering data stay in the EU. Some payment providers and Google operate infrastructure outside the EEA, notably in the United States. Where that happens the transfer relies on the Standard Contractual Clauses approved by the European Commission, and where applicable on the EU–US Data Privacy Framework, together with the supplementary measures those providers document. You may ask for a copy of the safeguards used.
6. How long it is kept
| Invoices and accounting records | 10 years, as required by art. 2220 of the Italian Civil Code and tax law |
| Orders and correspondence about an engagement | the duration of the engagement plus 5 years, the limitation period for contractual claims |
| Requests for the free call that lead nowhere | 12 months |
| Credentials or access given for the work | only while the work needs them, then destroyed |
| Server and security logs | up to 12 months, then deleted or aggregated |
| Cookie consent record | 6 months, then you are asked again |
When a period ends the data is deleted or irreversibly anonymised.
7. Security
The Site is served over HTTPS only. Access to the systems holding this data is limited to named people, over authenticated channels. Payment credentials never reach this Site. Backups are taken before any change to the systems, and every change is verified by checksum. Cryptographic material is held outside the web root and never appears in a log.
No system is perfect. If a breach is likely to result in a risk to your rights, the Garante per la protezione dei dati personali is notified within 72 hours and you are told without undue delay where the risk is high, as art. 33 and 34 GDPR require.
8. Your rights
Under articles 15 to 22 GDPR you may ask for: access to your data and a copy of it; rectification of anything inaccurate; erasure; restriction of processing; portability in a machine-readable format; and you may object to processing based on legitimate interest. Where processing rests on consent, you may withdraw it at any time, without affecting what was lawful before.
Write to info@lucaprata.com. You get an answer within one month, extendable by two months for a complex request, in which case you are told why. There is no charge unless the request is manifestly unfounded or excessive.
Erasure cannot be granted for data that must be kept by law, such as issued invoices, for as long as the law requires it.
You may also complain to the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma, garanteprivacy.it, or to the supervisory authority of the EU country where you live or work.
9. Children
The services are sold to businesses and to adults. The Site is not directed at children and personal data of people under 16 is not knowingly collected. If it reaches us, it is deleted.
10. Changes
This notice may change. The current version is always the one on this page and the date at the top is its date. A change that materially affects you is announced on the Site before it takes effect.