Last updated: August 5, 2026 — version 5.0 (previous: August 3, 2026, v4.1)
What changed in version 5.0: earlier versions described the Website as having no server-side component and stated that form data never left the user's browser. Since 3 August 2026 the Website uses a serverless function (/api/lead) that receives contact-form data and forwards it by email to the Controller. This version corrects that description and documents the processing, the recipients (including Resend) and the applicable safeguards in full. If you submitted a form between 3 and 5 August 2026 and want the data deleted, simply write to the contacts in §7.
Data Controller:
Andrea Piani (sole trader / empresario individual)
NIE: Z2331796-S
Registered address: Tijarafe, Santa Cruz de Tenerife — Canary Islands, Spain
Email: andreapiani.dev@gmail.com
Phone: +39 351 624 8936 · +34 619 500 367
This Privacy Policy describes how the website www.andreapiani.com (hereinafter "Website") collects, uses, and protects users' personal data, in compliance with the General Data Protection Regulation (GDPR - EU Regulation 2016/679).
The Website is a static site hosted on Vercel with one single serverless function (/api/lead), which exists solely to deliver contact-form submissions to the Controller by email. There is no database, no analytics or tracking, no profiling cookies, no chatbot and no AI assistant. Since 5 August 2026 the Website also serves all of its own assets (fonts, images, stylesheets, scripts) from its own domain, so merely browsing it triggers no request to any third-party server. The amount of personal data processed is therefore minimal, as described below.
The Controller collects the following types of personal data:
The Website's contact and quote-request forms collect the data you type — typically:
Read this before filling in a form. When you press submit, the data you entered leaves your device and reaches the Controller by email — whether or not you go on to send the WhatsApp message. If you fill in a form and then change your mind on the WhatsApp screen, the data has already been delivered.
Step by step:
assets/js/lead-capture.js) collects the completed fields and sends them over HTTPS to the serverless function /api/lead, running on the Vercel infrastructure.There is no database: the data is not stored by the serverless function or on any server of the Website — the only stable copy is the email in the Controller's mailbox. It is not passed to any CRM, marketing-automation platform or third-party form service, and it feeds no profiling and no marketing lists. Legal basis: pre-contractual measures at your request (Art. 6.1.b GDPR) — your consent is not required for this purpose, and for that reason it is not requested; what you are owed is information, which is given here and in short form underneath every form.
The Website performs no analytics and no tracking: no statistics endpoint, no measurement cookie, no logging of pages visited or clicks. Simply browsing the Website does not cause the Controller to store your IP address.
The following technical data is nevertheless processed:
/api/lead function reads the request's source IP (X-Forwarded-For header) and keeps it in volatile memory for 60 seconds for the sole purpose of rate-limiting submissions and blocking automated floods. The IP is never written to disk, never included in the email sent to the Controller and never linked to the form data. Legal basis: legitimate interest in the security of the service (Art. 6.1.f GDPR, Recital 49).The Website uses:
cookie_consent cookie existed only to remember an answer to a consent banner that had nothing to consent to, and both have been removed.For more details, see our Cookie Policy.
| Purpose | Legal Basis (GDPR) | Retention Period |
|---|---|---|
Respond to quote/contact requests (incl. delivery of the form via /api/lead and Resend) |
Performance of pre-contractual measures (Art. 6.1.b GDPR) | 24 months from last contact; no storage on the Website side (transit only) |
| Form security and abuse prevention (per-IP rate limit, anti-spam honeypot) | Legitimate interest (Art. 6.1.f GDPR) | IP in volatile memory for 60 seconds, never written to disk |
| Send commercial communications/newsletter | Explicit consent (Art. 6.1.a GDPR) | Until consent withdrawal |
| Tax and accounting compliance | Legal obligation (Art. 6.1.c GDPR) — law of the Controller's country of establishment (Spain: Ley 58/2003, Código de Comercio art. 30) and, for relationships governed by Italian law, DPR 633/1972 and art. 2220 Civil Code | 6 years from the last accounting entry (10 years where Italian law applies) |
| Hosting and delivery of the static site (technical connection logs at the hosting provider Vercel) | Legitimate interest (Art. 6.1.f GDPR) — security and availability of the service | According to the hosting provider's retention policy |
Personal data is processed using IT and telematic tools, in compliance with GDPR security measures. Processing is carried out:
Content-Security-Policy restricting resource loading to the Website's own domain, X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy, Permissions-Policy, Strict-Transport-Security); no third-party assets; origin checks, per-IP rate limiting and an anti-spam honeypot on the form function; service credentials held in the hosting provider's environment variables and never in the published source codeYour personal data may be communicated to:
No third party receives data merely because you open a page. Since 5 August 2026 the Website serves all of its assets (fonts, images, stylesheets, scripts) from its own domain: there are no longer any requests to Google Fonts, Unsplash, Flickr or other external CDNs. Browsing the Website therefore discloses your IP address only to the hosting provider (Vercel), as is technically unavoidable for any website. Every other recipient listed above comes into play only if you take an action: submitting a form, clicking a WhatsApp link, or sending an email.
Transfers outside the EU: Some providers (Vercel, Resend, Google/Gmail and, where applicable, Meta/WhatsApp) may process data in the USA. There are no transfers to China or to any other non-EU country. Such transfers occur through:
Your personal data will never be publicly disclosed or sold to third parties for commercial purposes.
As a data subject, you have the right to:
Obtain confirmation of the existence of your personal data and receive a copy.
Correct inaccurate or incomplete data.
Obtain deletion of your data (right to be forgotten), subject to legal obligations.
Restrict processing in specific cases provided by GDPR.
Receive your data in a structured, commonly used, machine-readable format.
Object to processing based on legitimate interest or for marketing purposes.
Withdraw consent at any time (without prejudice to the lawfulness of processing based on consent before its withdrawal).
Lodge a complaint with the Data Protection Authority.
How to Exercise Your Rights:
You can send a request via email to: andreapiani.dev@gmail.com
We will respond within 30 days of receipt of the request, as provided by Art. 12.3 GDPR.
The Controller adopts adequate technical and organizational security measures to protect personal data from unauthorized access, loss, destruction, or disclosure, including:
The Website sets no cookies at all and uses no analytical or profiling cookies. For detailed information on:
See our Cookie Policy.
The Website's services are not directed at minors under 16 years of age. We do not knowingly collect personal data from minors. If you believe a minor has provided personal data, contact us for immediate deletion.
This Privacy Policy may be updated periodically for regulatory compliance or service changes. Changes will be published on this page with an update of the date at the top. We invite you to regularly consult this page.
For any questions about the Privacy Policy or to exercise your rights:
Andrea Piani
Email: andreapiani.dev@gmail.com
Phone: +39 351 624 8936 · +34 619 500 367
Address: Piazza della Repubblica, 19 20124 Milano (MI), Italy
Supervisory Authority (Italian Data Protection Authority - Garante Privacy):
Garante per la Protezione dei Dati Personali
Piazza Venezia 11, 00187 Rome, Italy
Website: www.garanteprivacy.it
Email: garante@gpdp.it
© 2026 Andrea Piani · NIE Z2331796-S · Tijarafe, Santa Cruz de Tenerife · Islas Canarias 🌴