Legal

Privacy policy

This policy explains what personal data I collect through this website, why I collect it, how long I keep it and what rights you have. Last updated: [TODO: date of publication].

1. Who is responsible for your data

The data controller is Adamo Morgese, trading as Adamo Morgese Photographer (“I”, “me”).

Address: [TODO Adamo: business address]. VAT number (Partita IVA): [TODO Adamo: VAT number]. Email for privacy requests: [TODO Adamo: email address].

As a sole trader I am not required to appoint a Data Protection Officer. You can contact me directly about anything in this policy.

2. What data I collect

When you send an enquiry through the form on this website, I collect the information you choose to give me:

  • Your names
  • Your email address
  • Your wedding date
  • The place or venue of your wedding
  • The approximate number of guests
  • Your budget
  • How you found me
  • Your message and anything else you write in it

3. Why I use your data and on what legal basis

I use the data from your enquiry to reply to you, check my availability, send you information and a quote, and – if you book – to prepare and carry out our agreement. The legal basis is Article 6(1)(b) GDPR: steps taken at your request before entering into a contract, and the performance of that contract.

If you book, I keep the records required for accounting and tax purposes. The legal basis is Article 6(1)(c) GDPR: compliance with a legal obligation.

To keep the website secure and protect the form against spam, the website processes limited technical data (see section 6). The legal basis is Article 6(1)(f) GDPR: my legitimate interest in running a secure website.

I do not use your data for newsletters or marketing, and I never sell or rent it to anyone.

4. Where your data is stored and who receives it

Your enquiry is stored in the database of this WordPress website and is sent by email to my business mailbox, so that I can reply to you.

The website is hosted by [TODO: hosting provider and server location], and my email is provided by [TODO: email provider]. These providers process data on my behalf under data processing agreements and only as needed to provide their services.

I do not share your data with anyone else, unless you ask me to (for example, to coordinate with your wedding planner or venue) or the law requires it.

5. Transfers outside the European Economic Area

I do not intend to transfer your data outside the EEA. If a service provider processes data outside the EEA, the transfer is protected by an adequacy decision of the European Commission or by the European Commission’s standard contractual clauses. [TODO: confirm once hosting and email providers are fixed]

6. Cookies, analytics and technical data

This website does not use advertising cookies, social media trackers or third-party analytics. The enquiry form is protected against spam without third-party services.

Like any website, the server records standard technical data when you visit – such as your IP address, the date and time, the page requested and your browser type – to keep the site running and secure. These logs are kept for a short period and then deleted. [TODO: confirm log retention and that no analytics or other cookies are added before launch; if any are added, this section and a cookie notice must be updated]

7. How long I keep your data

If your enquiry does not lead to a booking, I delete it [TODO Adamo: e.g. 12 months] after our last contact.

If you book, I keep your contact details and the booking correspondence for as long as needed to deliver your photos and handle any questions afterwards, and I keep invoices and accounting records for as long as Italian law requires. [TODO: confirm retention periods with your accountant]

8. Your rights

Under the GDPR you have the right to:

  • Access the personal data I hold about you
  • Have inaccurate data corrected
  • Have your data erased
  • Restrict how I use your data
  • Receive your data in a portable format
  • Object to processing based on my legitimate interests
  • Lodge a complaint with a supervisory authority – in Italy the Garante per la protezione dei dati personali (www.garanteprivacy.it) – or the authority in the country where you live

9. How to exercise your rights

Write to me at [TODO Adamo: email address]. I will reply within one month. I may ask you to confirm your identity before I act on a request.

10. Security

The website uses an encrypted (HTTPS) connection, access to the website’s administration is restricted, and I take reasonable technical and organisational measures to protect your data against loss and unauthorised access.

11. Changes to this policy

I may update this policy when the website or the law changes. The date at the top shows when it was last updated.