Privacy Policy

Last update: August 9, 2026

This privacy notice describes how the personal data of users who visit chiarabevents.com or use the contact and quote request forms are processed, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and applicable Italian law.

1. Data Controller

The Data Controller is CHIARAB EVENTS SRL, represented by Chiara Beninati, headquartered at Via Luigi De Luca, 71, 98051 Barcellona Pozzo di Gotto (ME), Italy.

A Data Protection Officer (DPO) has not been appointed. For any privacy-related requests, you can contact the Data Controller directly at the contacts indicated above.

2. Personal data processed

The site may process the following categories of data:

  • Browsing and technical data: IP address, date and time of the request, visited URLs, browser and device type, operating system, referrer, technical logs, online identifiers, and information necessary for the security and proper functioning of the site.
  • Voluntarily provided data: first name, last name, email address, phone number, and content of messages sent through the forms.
  • Data related to the event or quote request: date and location of the event, approximate number of guests, organizational preferences, approximate budget, and other information the user decides to communicate.
  • Data related to consent: preferences expressed through the cookie banner and technical identifiers necessary to document or comply with such choices.

Please do not submit special categories of data pursuant to art. 9 GDPR through the forms, unless strictly necessary and previously agreed upon.

3. Purposes and legal bases

Operation, security and abuse prevention

Technical data is processed to deliver the site, keep it secure, prevent fraud, spam, unauthorized access and diagnose problems. The legal basis is the legitimate interest of the Data Controller in the security and continuity of its services, as well as compliance with any legal obligations.

Responses to contacts and requests for quotes

Data submitted by the user is used to respond to requests, prepare personalized proposals, organize appointments and carry out pre-contractual activities requested by the data subject. The legal basis is the execution of pre-contractual or contractual measures.

Management of the contractual relationship and administrative obligations

When an assignment is entrusted, data is processed to perform the service, manage suppliers and organizational activities, comply with tax, accounting and legal obligations and protect the rights of the Data Controller. The legal bases are the execution of the contract, compliance with legal obligations and, where applicable, the legitimate interest in defending one's rights.

Statistics and measurement

With prior consent, the site uses Google Analytics 4 to measure traffic and site usage. Google Analytics 4 provides for IP address anonymization by default. In the absence of consent, related non-essential cookies and scripts are blocked according to the banner configuration.

Measurement of advertising campaigns

With prior consent, Google Ads and related technologies may be used to measure campaign conversions and evaluate their effectiveness. The site does not make solely automated decisions that produce legal effects or similarly significant effects on the user.

The site currently does not send newsletters and does not manage contacts via WhatsApp.

4. Nature of provision

Providing data marked as mandatory in the forms is necessary to respond to the request. Failure to provide it may make it impossible to provide the requested feedback or quote. Optional data allows for a more accurate response.

5. Processing methods and security measures

Data is processed with electronic tools and, when necessary, manually, according to principles of lawfulness, fairness, transparency, minimization and limitation of storage. Technical and organizational measures proportional to the risk are adopted, including access protections, updates, backups, recording of security events and encryption of communications via HTTPS.

6. Retention periods

  • Contact and quote requests that do not result in a contractual relationship are kept for the time necessary for management and subsequent feedback and, as a rule, no longer than 24 months from the last contact, except for disputes or legal obligations.
  • Data relating to customers, contracts, invoices and administrative obligations are kept for the duration of the relationship and for the subsequent period required by civil, tax and accounting law, usually 10 years.
  • Technical and security logs are kept for the time strictly necessary to ensure the functioning of the site, prevent abuses and investigate incidents, except for further retention needs related to security events or legal obligations.
  • Data relating to cookies, Analytics, Ads and consent preferences follow the periods indicated in the Cookie Policy and in the settings of the respective services.

7. Recipients and data processors

Data may be processed by authorized personnel and suppliers who support the Data Controller in managing the site and activity, such as hosting and infrastructure providers, maintenance personnel, email providers, administrative and legal consultants, anti-spam and security services, as well as statistical and advertising platforms. These subjects operate, depending on the case, as data processors pursuant to art. 28 GDPR or as independent controllers.

Technical services present may include WordPress, Contact Form 7, Complianz, Cloudflare, Google Analytics, Google Ads, Google Fonts and Instagram content. The updated list of technologies and their purposes is reported in the Cookie Policy.

8. Transfers to third countries

Some technology providers may process data outside the European Economic Area. In such cases, the transfer is based on an adequacy decision, the Standard Contractual Clauses approved by the European Commission, or another mechanism provided for by Articles 44 and following of the GDPR, with additional measures when necessary. More information can be requested by contacting the Data Controller.

9. Cookies and consent management

Strictly necessary cookies are used without consent to allow the operation and security of the site. Statistical or marketing cookies and scripts are activated only after a positive choice by the user. Preferences can be changed at any time via the “Manage consent” button on the site. For details on cookies, services, duration, and categories, consult the Cookie Policy.

10. Data subject rights

In cases provided for by the GDPR, the data subject can exercise the rights to:

  • access personal data and obtain a copy;
  • rectify or update inaccurate data;
  • delete data;
  • restrict processing;
  • object to processing based on legitimate interest;
  • data portability, when applicable;
  • withdraw consent at any time, without affecting the lawfulness of processing prior to withdrawal;
  • file a complaint with the Data Protection Authority.

Requests can be sent to info@chiarabevents.com or to the certified email (PEC) address chiarabevents@pec.it. The Data Protection Authority can be reached via the website garanteprivacy.it.

11. Minors

ChiaraB Events services are not aimed at minors and the site does not knowingly collect personal data from minors. If a parent or guardian believes that a minor has submitted personal data, they can contact the Data Controller to request its deletion.

12. Changes to the privacy policy

The Data Controller may update this privacy policy to adapt it to regulatory, organizational, or technical changes. The updated version is published on this page with the revision date indicated.

Scroll to Top
Richiedi un preventivo