Privacy Policy

Last updated: August 5, 2026 — version 5.0 (previous: August 3, 2026, v4.1)

What changed in version 5.0: earlier versions described the Website as having no server-side component and stated that form data never left the user's browser. Since 3 August 2026 the Website uses a serverless function (/api/lead) that receives contact-form data and forwards it by email to the Controller. This version corrects that description and documents the processing, the recipients (including Resend) and the applicable safeguards in full. If you submitted a form between 3 and 5 August 2026 and want the data deleted, simply write to the contacts in §7.

Data Controller:

Andrea Piani (sole trader / empresario individual)
NIE: Z2331796-S
Registered address: Tijarafe, Santa Cruz de Tenerife — Canary Islands, Spain
Email: andreapiani.dev@gmail.com
Phone: +39 351 624 8936 · +34 619 500 367

This Privacy Policy describes how the website www.andreapiani.com (hereinafter "Website") collects, uses, and protects users' personal data, in compliance with the General Data Protection Regulation (GDPR - EU Regulation 2016/679).

The Website is a static site hosted on Vercel with one single serverless function (/api/lead), which exists solely to deliver contact-form submissions to the Controller by email. There is no database, no analytics or tracking, no profiling cookies, no chatbot and no AI assistant. Since 5 August 2026 the Website also serves all of its own assets (fonts, images, stylesheets, scripts) from its own domain, so merely browsing it triggers no request to any third-party server. The amount of personal data processed is therefore minimal, as described below.

1. Types of Data Collected

The Controller collects the following types of personal data:

1.1 Data Provided Voluntarily by the User (contact forms)

The Website's contact and quote-request forms collect the data you type — typically:

Read this before filling in a form. When you press submit, the data you entered leaves your device and reaches the Controller by emailwhether or not you go on to send the WhatsApp message. If you fill in a form and then change your mind on the WhatsApp screen, the data has already been delivered.

Step by step:

  1. Typing — while you type, the data stays in your browser.
  2. Submission — on submit, a script of the Website (assets/js/lead-capture.js) collects the completed fields and sends them over HTTPS to the serverless function /api/lead, running on the Vercel infrastructure.
  3. Delivery — the function composes an email and delivers it to the Controller through the transactional email service Resend (Resend Inc., USA). The email lands in the Controller's Gmail mailbox. If you provided a valid email address, it is set as the message's Reply-To.
  4. WhatsApp (optional) — in parallel, your browser opens WhatsApp with a pre-filled message. This step is your choice: if you complete it, the message also transits through Meta Platforms Ireland Ltd. If you do not, step 3 has happened anyway.

There is no database: the data is not stored by the serverless function or on any server of the Website — the only stable copy is the email in the Controller's mailbox. It is not passed to any CRM, marketing-automation platform or third-party form service, and it feeds no profiling and no marketing lists. Legal basis: pre-contractual measures at your request (Art. 6.1.b GDPR) — your consent is not required for this purpose, and for that reason it is not requested; what you are owed is information, which is given here and in short form underneath every form.

1.2 Navigation Data

The Website performs no analytics and no tracking: no statistics endpoint, no measurement cookie, no logging of pages visited or clicks. Simply browsing the Website does not cause the Controller to store your IP address.

The following technical data is nevertheless processed:

1.3 Cookies and Local Storage

The Website uses:

For more details, see our Cookie Policy.

2. Purpose of Processing and Legal Basis

Purpose Legal Basis (GDPR) Retention Period
Respond to quote/contact requests (incl. delivery of the form via /api/lead and Resend) Performance of pre-contractual measures (Art. 6.1.b GDPR) 24 months from last contact; no storage on the Website side (transit only)
Form security and abuse prevention (per-IP rate limit, anti-spam honeypot) Legitimate interest (Art. 6.1.f GDPR) IP in volatile memory for 60 seconds, never written to disk
Send commercial communications/newsletter Explicit consent (Art. 6.1.a GDPR) Until consent withdrawal
Tax and accounting compliance Legal obligation (Art. 6.1.c GDPR) — law of the Controller's country of establishment (Spain: Ley 58/2003, Código de Comercio art. 30) and, for relationships governed by Italian law, DPR 633/1972 and art. 2220 Civil Code 6 years from the last accounting entry (10 years where Italian law applies)
Hosting and delivery of the static site (technical connection logs at the hosting provider Vercel) Legitimate interest (Art. 6.1.f GDPR) — security and availability of the service According to the hosting provider's retention policy

3. Processing Methods

Personal data is processed using IT and telematic tools, in compliance with GDPR security measures. Processing is carried out:

4. Data Communication and Disclosure

4.1 Data Recipients

Your personal data may be communicated to:

No third party receives data merely because you open a page. Since 5 August 2026 the Website serves all of its assets (fonts, images, stylesheets, scripts) from its own domain: there are no longer any requests to Google Fonts, Unsplash, Flickr or other external CDNs. Browsing the Website therefore discloses your IP address only to the hosting provider (Vercel), as is technically unavoidable for any website. Every other recipient listed above comes into play only if you take an action: submitting a form, clicking a WhatsApp link, or sending an email.

Transfers outside the EU: Some providers (Vercel, Resend, Google/Gmail and, where applicable, Meta/WhatsApp) may process data in the USA. There are no transfers to China or to any other non-EU country. Such transfers occur through:

4.2 No Public Disclosure

Your personal data will never be publicly disclosed or sold to third parties for commercial purposes.

5. Your Rights (Art. 15-22 GDPR)

As a data subject, you have the right to:

📄 Right of Access (Art. 15)

Obtain confirmation of the existence of your personal data and receive a copy.

✏️ Right of Rectification (Art. 16)

Correct inaccurate or incomplete data.

🗑️ Right to Erasure (Art. 17)

Obtain deletion of your data (right to be forgotten), subject to legal obligations.

⏸️ Right to Restriction (Art. 18)

Restrict processing in specific cases provided by GDPR.

📦 Right to Data Portability (Art. 20)

Receive your data in a structured, commonly used, machine-readable format.

🚫 Right to Object (Art. 21)

Object to processing based on legitimate interest or for marketing purposes.

🔄 Withdrawal of Consent (Art. 7.3)

Withdraw consent at any time (without prejudice to the lawfulness of processing based on consent before its withdrawal).

⚖️ Right to Lodge a Complaint (Art. 77)

Lodge a complaint with the Data Protection Authority.

How to Exercise Your Rights:

You can send a request via email to: andreapiani.dev@gmail.com

We will respond within 30 days of receipt of the request, as provided by Art. 12.3 GDPR.

6. Data Security

The Controller adopts adequate technical and organizational security measures to protect personal data from unauthorized access, loss, destruction, or disclosure, including:

7. Cookies and Similar Technologies

The Website sets no cookies at all and uses no analytical or profiling cookies. For detailed information on:

See our Cookie Policy.

8. Minors

The Website's services are not directed at minors under 16 years of age. We do not knowingly collect personal data from minors. If you believe a minor has provided personal data, contact us for immediate deletion.

9. Changes to the Privacy Policy

This Privacy Policy may be updated periodically for regulatory compliance or service changes. Changes will be published on this page with an update of the date at the top. We invite you to regularly consult this page.

10. Contact and Complaints

For any questions about the Privacy Policy or to exercise your rights:

Andrea Piani
Email: andreapiani.dev@gmail.com
Phone: +39 351 624 8936 · +34 619 500 367
Address: Piazza della Repubblica, 19 20124 Milano (MI), Italy

Supervisory Authority (Italian Data Protection Authority - Garante Privacy):

Garante per la Protezione dei Dati Personali
Piazza Venezia 11, 00187 Rome, Italy
Website: www.garanteprivacy.it
Email: garante@gpdp.it

← Back to Homepage

© 2026 Andrea Piani · NIE Z2331796-S · Tijarafe, Santa Cruz de Tenerife · Islas Canarias 🌴