Privacy Policy
Your privacy matters. Here is how I process your personal data, transparently and in compliance with the GDPR.
Data controller
The controller of the personal data collected through this site is Defilippi Guido, registered office at Strada Val Villata 4, 10090 Gassino Torinese (TO), Italy, VAT no. 10221630014.
For any question regarding the processing of your personal data, and to exercise the rights described in section 7, you can write to privacy@guidoparquet.com or call +39 347 788 6561.
This notice is provided pursuant to Articles 13 and 14 of EU Regulation 2016/679 (GDPR) and to Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018. The controller has not appointed a Data Protection Officer (DPO), as the conditions set out in Art. 37 GDPR do not apply.
Types of data collected
This site collects the personal data that the user voluntarily provides by filling in the contact form in the "Contact" section. Specifically: name, email address, phone number and a free-text description of the project or request.
No profiling or third-party marketing cookies are used, and there are no user-tracking systems, statistics or analytics of any kind. Every resource that makes up these pages — text, images, stylesheets and web fonts — is served from this site’s own domain: while browsing normally, your browser contacts no third-party server. The only exception is the anti-bot service described in section 9, which is present only on the "Contact" page.
Every request to this site — not only submitting the form — passes through the Cloudflare Workers edge infrastructure, which records the visitor’s IP address, the browser User-Agent and the address of the requested page in its technical logs, solely to ensure the security of the service (rate limiting, anti-abuse) and to diagnose errors. Because the site pre-loads the links that appear on screen to make navigation faster, the logs may also contain addresses of pages you never actually opened. This technical data is not used for profiling or marketing.
When the contact form is submitted, the IP address and the User-Agent are also copied into the "request metadata" block of the notification email sent to the controller, so that abusive submissions can be traced: they therefore also pass through the email service named in section 6 and remain in the controller’s mailbox, for the periods set out in section 5.
Purposes of processing
The data provided via the contact form is processed solely to respond to the user’s requests, provide quotes, arrange surveys and manage any subsequent business relationship.
The same purpose covers the automatic confirmation message sent to the email address entered in the form: it contains your name and the controller’s contact details, does not repeat the text of your message and is not a commercial communication. If this confirmation fails to arrive, your request has still been received and will be handled.
The data will in no case be used for direct marketing, newsletters or profiling, nor shared with third parties for their own purposes.
Legal basis for processing
The processing of the data you provide through the contact form is based on the performance of pre-contractual measures taken at your request (Art. 6(1)(b) of EU Regulation 2016/679 — GDPR): the data is necessary to reply to you, prepare a quote and arrange a possible site survey.
The box you tick in the form confirms that you have read this notice: it is not the legal basis of the processing, and no record of that acceptance is stored on the controller’s systems.
Providing the data is optional; however, without the data marked as required, I will not be able to follow up on the contact request.
The logging of the IP address, User-Agent and requested page in technical logs, as well as the anti-abuse measures described in section 11, rely instead on the controller’s legitimate interest (Art. 6(1)(f) GDPR) in ensuring the security of the infrastructure and diagnosing technical issues.
Storage methods and retention
Data is processed with IT tools, using logic strictly related to the stated purposes and adopting security measures appropriate to ensure its confidentiality and integrity: traffic served exclusively over HTTPS, protective headers on the pages served, anti-abuse filtering and rate limiting on the form endpoint, and no storage of the form’s content in any database (the data exists only for the time needed to send the email).
Data collected via the contact form is received and kept in the controller’s mailbox for as long as necessary to handle the request and, if it leads nowhere, for a maximum of 24 months from the last contact, after which the messages are deleted. If the request leads to a contract, the necessary data is retained for the periods required by Italian civil and tax law (10 years).
Technical logs generated by the Cloudflare infrastructure (Workers + edge), containing IP address, User-Agent and requested page, are retained according to the provider’s retention policy, at the end of which they are automatically deleted. The anti-abuse counters based on the IP address last for different periods depending on their purpose: 60 seconds for the rate limit, one hour for the maximum number of hourly submissions, and up to 24 hours for the enforced pause that follows repeated rejected attempts. They delete themselves automatically when they expire.
The copy of the IP address and User-Agent contained in the notification email does not follow the log retention: it stays inside the email message and is therefore kept for the periods stated above for form data, as well as at the providers that transmit and host it, according to their respective retention policies.
Data recipients and technical providers
Personal data is not disclosed to third parties for commercial purposes. It may be processed by the controller’s collaborators, bound to confidentiality, and by technical service providers appointed as data processors under Art. 28 GDPR.
In particular, the following sub-processors are used to operate this site and its contact form:
Cloudflare, Inc. (USA) — provides the site’s distribution and protection infrastructure (Cloudflare Workers + Static Assets), the Cloudflare Turnstile anti-bot service used on the contact form, and the anti-abuse counters. In this context Cloudflare also processes the visitor’s IP address as the counting key of the rate limiters and, where the temporary Cloudflare KV store is enabled, keeps it for one hour together with the number of submissions made. When the form is submitted, the site’s server sends Cloudflare the token generated by the anti-bot widget together with your IP address, in order to verify it. Cloudflare also provides the email service (Cloudflare Email Service) used to deliver the notification of your request to the controller: the data entered in the form and the technical metadata of the request (IP address and User-Agent) pass through it.
Resend, Inc. (USA) — used only for the automatic "noreply" confirmation email sent to the address entered in the form. Only your name and your email address pass through Resend, solely to deliver that message: not the text of your request, nor your IP address, nor your User-Agent. If delivery fails, the error message returned by the provider — which may contain the recipient’s address — is recorded in the technical logs and follows the retention described in section 5.
Some providers are based in the United States. Data transfers outside the European Economic Area take place on the basis of the safeguards under Art. 44 et seq. GDPR: the adequacy decision covering the EU-US Data Privacy Framework, for providers that have joined it, and/or the Standard Contractual Clauses (SCC) approved by the European Commission.
Rights of the data subject
At any time the user may exercise the rights under Articles 15-22 GDPR, including: access, rectification, erasure ("right to be forgotten"), restriction of processing, objection and data portability.
To exercise these rights, or to object to processing based on legitimate interest, simply send a request to the contact details given in section 1. The controller will respond within the terms set by law.
One useful clarification for access or portability requests: for security reasons, in the message archived by the controller any web addresses, domain names and IP addresses contained in your free text are rendered non-clickable (neutralised). The information itself is unchanged, but its form may differ from the text you originally typed — and it is that copy you would be given.
The data subject also has the right to lodge a complaint with the supervisory authority (in Italy, www.garanteprivacy.it) if they believe the processing infringes applicable law.
Cookies and tracking technologies
This site does not use profiling cookies or third-party advertising trackers. The only cookies present are technical ones: those set by the Cloudflare platform for operation and security (__cf_bm, cf_clearance) and a first-party cookie named "lang", written by the site itself only if you manually select a language and sent to the site’s server with every request so that pages can be served in the language you chose. Being strictly necessary, they do not require prior consent under Art. 122 of the Italian Privacy Code.
The site also uses the browser’s sessionStorage for a single key, "theme", which stores your manual choice of the light/dark theme and is cleared when you close the tab; without such a choice, your device setting is followed. localStorage is not used. sessionStorage is not a cookie and its content is never sent to any server; the language preference, by contrast, is not kept in local storage but in the "lang" cookie described above.
No resources are loaded from third-party servers: even the web fonts used by these pages are hosted on this site’s own domain, so that your IP address is not disclosed to any external provider merely because you visited the site.
The full list of cookies, with purposes and duration, is in the Cookie Policy linked in the site footer.
Anti-bot protection (Cloudflare Turnstile)
To protect the contact form from automated submissions (bots, spam) Cloudflare Turnstile is used, a verification service provided by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA).
The Turnstile widget is loaded from Cloudflare’s servers (challenges.cloudflare.com) as soon as the contact form appears on screen, therefore before you type or submit anything: already at that point Cloudflare receives your IP address, the User-Agent, some technical signals from your browser and device and your interaction timing, solely to distinguish human users from automated software. When the form is submitted, the site’s server sends Cloudflare the token generated by the widget together with your IP address in order to verify it. Cloudflare states it does not use this data for advertising or profiling.
The legal basis is the controller’s legitimate interest in protecting the site and its users from abuse (Art. 6(1)(f) GDPR). More information: www.cloudflare.com/privacypolicy and developers.cloudflare.com/turnstile.
External links (WhatsApp and Google profile)
The site may include a direct link to the WhatsApp messaging service (wa.me domain), which lets the user start a conversation with the controller.
This is a simple outbound hyperlink: until the user clicks, no cookie is set and no data is sent to WhatsApp or Meta Platforms, Inc. From the moment of the click, WhatsApp’s terms of use and privacy policy apply (www.whatsapp.com/legal).
Of the same nature, where the relevant details have been filled in, the site may link to the business’s Google profile ("Find me on Google Maps" and the invitation to leave a review): here too, no data is sent to Google until you click, after which Google’s own privacy policy applies (policies.google.com/privacy).
Anti-abuse measures and absence of automated decision-making
To protect the contact form from automated submissions and abuse, the site’s server automatically runs a few technical checks when the form is submitted, with no human assessment involved:
Counting attempts and submissions per IP address: a maximum number of attempts per minute and one submission every 60 seconds; once the attempts are used up, an enforced pause kicks in that grows longer each time it is repeated, up to a maximum of 12 hours. Where the hourly cap is also enabled, a ceiling on submissions per hour applies. These counters are stored in a temporary Cloudflare KV store with the IP address as the only key and delete themselves on expiry, in any case within 24 hours.
Checking the domain of the email address you entered against a list of temporary ("disposable") mailbox providers: if the domain is on the list, the submission is refused.
Checking the browser User-Agent against a list of known automated clients and verifying, through the Origin and Referer headers, that the request really comes from this site.
Hidden fields (honeypot) invisible to human visitors and normally filled in only by automated software: if they are filled in, the request is discarded without being forwarded.
These checks rely on the controller’s legitimate interest in the security of the site and the service (Art. 6(1)(f) GDPR). Their only possible effect is the refusal of the form submission, which can always be worked around by contacting the controller directly using the details in section 1.
Beyond what is described here, personal data is not subject to any automated decision-making or profiling within the meaning of Art. 22 GDPR.
Changes to this policy
The controller reserves the right to update or amend this policy at any time, reflecting the changes on this page. Users are invited to consult it periodically.
Last updated: July 2026.