Legal document · Updated on 14 September 2026

Privacy
Policy

This appropriation is intended to cover expenditure on research and innovation in the field of information technology.

Index of contents

01 Data controller

The controller of personal data collected through the website christophercorte.it is:

Christopher Corte
Free professional — UX/UI and Product Strategy consultant
VAT consignment: 05219660239
It is located in Via Gioacchino Rossini, 6A — 37066 Sommacampagna (VR), Italy
E-mail:
This is the website: www.christophercorte.it

For any questions concerning the processing of your personal data, you can contact the controller directly at the above-mentioned email address. Guaranteed reply within 30 days of receipt of the request pursuant to Article 12 GDPR.

02 Data collected and how it is collected

Data provided voluntarily by the user

Through the contact forms on the website, you can voluntarily provide the following personal data:

Date and timeObligatoryPurpose
Name and surnameYes, I did.Identification of the applicant and personalization of the response
E-mail addressYes, I did.Answer to the request, if any, submission of a quote
Name of company or projectNo , it 's not .Contextualization of the request
Description of the project or needVariable by serviceDrafting of the minutes or preparation of the session
Preferences for serviceVariablePersonalization of the offer
Preferred date and time zoneFor bookingsOrganization of the appointment

Failure to provide the mandatory data makes it impossible to provide the requested service.

Navigation data

The computer systems responsible for the operation of the website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of internet communication protocols. This is information such as IP addresses, browser type, operating system, pages visited and access times. This data is processed exclusively for aggregate technical and statistical purposes and is stored for the time strictly necessary. Google Analytics 4 is uploaded only after the analytical consent. Before consent and in case of refusal the site does not load the Google Analytics tag. You can change or revoke the option from the "Manage cookies" command.

Data processed during payment

For prepaid services (UX Business Audit, Mentoring 1:1, UX Crash Course and SMEs Digital Consulting), payment is made by: Striped, PCI-DSS certified external payment platform. The full paper data is collected directly from Stripe. The holder receives the data necessary to identify the customer, service and payment outcome, and uses Aruba to issue and store electronic invoices. Stripe processes the data according to its privacy policy available on stripe.com/privacy.

03 Purposes and legal basis

PurposeLegal basis (art. (GDPR)
Responding to requests for quotes or information (b) — implementation of pre-contractual measures at the request of the person concerned
Management of reservations for paid sessions Article 6 (1) (b) — performance of the contract
Tax and accounting payments Article 6 (1) (c) — Legal obligation
Submission of commercial communications (only with explicit consent) Article 6 (1) (a) — Consent of the person concerned
Prevention of abuse and spam via the website Article 6 (1) (f) — legitimate interest of the holder

The consent given when filling out the contact forms shall be for the processing of data solely to respond to a specific request. It does not involve subscribing to newsletters or sending unsolicited commercial communications.

04 Recipients and data processors

We use the following providers to manage the website, requests and services. When they process data on our behalf, they act as responsible under Art. 28 GDPR; for their own purposes and legal obligations they may act as autonomous holders, according to their respective information.

SubjectRolePurposePrivacy
Formspree Inc.
San Francisco, USA
Controller Receipt and transmission of contact forms Policy
The following is the list of airlines:Security serviceTurnstile: anti-abuse verification of the forms, processing the technical data of the connection and devicePolicy
Striped
Competent entities by service and country
Owner or self-employed person, according to the treatment described in his statement Online payment management Policy
The following is the list of companies listed in Annex II:
Gmail, Calendar, Analytics and multimedia content
Controller Email, calendar availability, images hosted by Google; statistics only by consent Policy
ManufactureService provider; contract role and treatmentAutomation of service requests and communicationsInformation to be provided
Hotjar / ContentsquareProvider of experience analysisMaps and sessions by consent only, content of obscured formsInformation and communication
Mailchimp / IntuitService provider; contract role and treatmentManagement of service-related contacts and emails; promotional communications only with separate consentInformation to be provided
ArubaService provider; contract role and treatmentWebsite hosting and electronic invoicing services and storage of tax documentsInformation to be provided

The data shall not be transferred, sold or disclosed to third parties not specified, nor used for purposes other than those declared.

05 Data transfers outside the EU

Suppliers may also process data outside the European Economic Area. Guarantees depend on the provider and the transfer: applicable adequacy decisions, including the Data Privacy Framework for certified organisations, or standard contractual clauses and measures provided for in processing agreements.

06 Retention periods

Type of dataPeriod of storage
Data from contact forms without contract 12 months from receipt, unless requested for early cancellation
Data on professional benefits awarded 10 years from the end of the professional relationship (tax and civil liability)
Payment data (managed by Stripe) According to the purposes and terms described in the Stripe Information, including applicable regulatory obligations
Navigation log of the server Not more than 30 days, except for security-related requirements

At the expiry of the deadlines, the data shall be deleted or anonymised irreversibly.

07 Your data protection rights

Under Articles 15-22 of the GDPR, you have the right to:

To exercise your rights, write to: the subject 'Exercise of GDPR rights'. We'll respond within 30 days of receiving your request.

09 Changes to this notice

The owner reserves the right to make changes to this notice at any time by advertising it to users on this page. Please consult this page frequently, with reference to the date of last modification at the top of the document.

In the event of substantial changes to data already supplied, the holder shall communicate them by e-mail to the addresses in his possession where possible.

10 Contact

For any matter relating to this privacy policy or the processing of your personal data:

Christopher Corte — Controller
Free work · VAT 05219660239
This appropriation is intended to cover expenditure relating to:
E-mail:
Guaranteed reply within 30 days of receipt of the request pursuant to Article 12 GDPR.

For complaints to the Data Protection Supervisor (Italian supervisory authority, located in Piazza Venezia 11, 00187 Rome): Complaint procedure with the Italian Privacy Guarantee.