Privacy Policy
Effective Date: May 10, 2025
This website is a personal project managed solely by me, Antonino Romito (the data controller reachable through this website’s contact page). Its purpose is to share my artistic journey and offer those interested the opportunity to receive updates about my artwork.
This privacy policy applies solely to this website and any of its subdomains that do not have their own separate privacy policies.
If a subdomain has its own privacy policy, that policy governs the data practices for that subdomain and takes precedence over this one.
Please note that this policy does not apply to third-party platforms (such as YouTube) that may be linked from this site. We encourage you to review the privacy policies of any external sites you visit.
1. Privacy & Data Collection
What I Collect
I collect certain technical data from visitors to help ensure the safety and functionality of my site. This includes:
-
Pages visited
-
How visitors interact with the site
-
IP addresses and device/browser information
Why I Collect It
This data is collected for two primary purposes:
-
Security – To detect and prevent misuse, automated abuse, or threats
-
Statistics – To better understand how the site is being used (aggregated data only)
How I Collect It
I use cookies and similar technologies to collect and store this data. By continuing to use this site, you consent to this processing. If you do not agree, please refrain from using the website.
Legal Basis: Legitimate interests (Article 6(1)(f) GDPR) – for security and site functionality.
2. Use of Security and Analytics Technologies
This website uses essential cookies and custom-developed tracking mechanisms for security and performance monitoring. These technologies help detect malicious behavior (e.g., bots or automated scraping) and ensure the site functions as intended.
Data collected may include:
-
Pages visited and time spent
-
Download attempts and frequency of actions
-
Interaction patterns
-
Anonymized identifiers or hashed IP tokens
These systems are used only to:
-
Protect the integrity and availability of the website
-
Monitor unusual or abusive behavior
-
Improve stability and performance
No personal data is used for marketing or profiling. Data is not shared with third parties and not used to make decisions about individual users.
Legal Basis: Legitimate interests (Article 6(1)(f) GDPR) – to maintain website security and performance.
3. Promotion and Internal Banners
The site may display banners or visual highlights related to:
-
My artistic work and process
- My Art Catalog Download
-
Painting techniques and courses
-
Educational content hosted on this website or on subdomains I control
- External websites (marked as Sponsored)
These banners are:
-
Shown equally to all visitors (not personalized)
-
Fully managed within this website
-
Non-intrusive and purely informational
No personal data is collected or used to target or customize these banners.
Some banners may link to external sites. These are not under my control, and I recommend reviewing their privacy policies before interacting
4. Email Updates
If you choose to subscribe to my updates, you voluntarily provide your email address.
Subscription Options
You may choose one of the following:
-
Relevant Progress – Receive updates when a painting has made meaningful progress and when it’s completed.
-
Work Completion Only – Only receive updates once a painting is fully completed.
You may subscribe to one option per email. You can change your preference or unsubscribe at any time using the links included in each email.
Activation Required
After subscribing, you will receive an Activation email. You must click the activation link to activate your subscription. Unconfirmed email addresses are automatically deleted after the expiration time indicated in the confirmation email.
Legal Basis:
-
Consent (Article 6(1)(a) GDPR) – for subscription and confirmation.
-
Performance of a contract (Article 6(1)(b) GDPR) – for sending requested update emails.
5. Email Storage and Security
Your email is stored in encrypted form in my database.
-
It is only accessible to me through a secure, private admin section
-
It is never shared with third parties
-
It is used solely to send the updates you requested
-
You will never receive third-party advertising or unrelated content
For added security, this website may adapt content availability based on visitor behavior. For example, suspicious or automated activity may restrict access to certain areas. This behavior-based adjustment is local, non-commercial, and does not involve profiling or user tracking.
While I take appropriate precautions, no online system is entirely secure. If you have concerns, you are advised not to subscribe.
Legal Basis: Legitimate interests (Article 6(1)(f) GDPR) – for secure data storage and service provision.
6. Your Rights
Under the General Data Protection Regulation (GDPR), you have the right to:
-
Access your personal data
-
Request correction or deletion
-
Withdraw consent at any time
-
Object to processing
-
Lodge a complaint with a data protection authority
To exercise any of these rights, please contact me through the website’s contact page.
Right to Erasure (Data Deletion Request)
In accordance with the General Data Protection Regulation (GDPR), you have the right to request the deletion of any personal data I may hold about you, including your email address and any associated comments.
If you no longer wish to receive email updates, you may unsubscribe at any time using the link found inside my emails. Unsubscribing will permanently delete your email address from my database.
If you have the ability to submit comments on the website, the email will also include a “Delete My Data” link. Clicking this link will take you to a form where you can enter your email address to request complete data deletion.
To ensure the security of your request, we will send a confirmation email to the address provided. Only after clicking the confirmation button in that email will your email address and any eventual linked comments be permanently deleted.
This process ensures that deletion requests can only be completed by the rightful owner of the email address and prevents unauthorized removal of data.
Once your data is deleted, it cannot be recovered. However, it may still exist in system backups for a limited time. These backups are maintained solely for security and disaster recovery purposes. They are not used for any active processing and are automatically purged periodically.
In accordance with the General Data Protection Regulation (GDPR), you have the right to request the deletion of any message you sent me through my contact form, in this case each deletion request will be assessed on a case-by-case basis to determine whether the data can be fully erased or if it must be retained for legitimate purposes, such as legal obligations, security, or record-keeping.
Please note: When you post a comment using an arbitrary display name, and later unsubscribe, your email is deleted. As such, your comment becomes anonymous and can no longer be associated with you or deleted under GDPR rights unless you request its removal before unsubscribing.
7. Terms of Use
I reserve the right to:
-
Cancel any individual subscription at any time, without notice, and for any reason.
-
Discontinue the update service entirely at my sole discretion
By subscribing, you agree to the terms of this Privacy Policy.
No Warranty:
This service is provided “as is” without any warranties, express or implied. I do not guarantee uninterrupted or error-free service.
Limitation of Liability:
I am not liable for any damages or losses arising from your use of this service or inability to receive updates.
8. Contact Form Data Collection
When you use the contact form on this website, the data you submit — including your name, email address, and message content — is collected solely to process your inquiry and provide a response.
Your message is stored securely in the website’s database and is not used for marketing purposes. It becomes part of my personal correspondence archive.
You may request the deletion of your data at any time by contacting me directly via the contact page. I will delete your data unless I have a legitimate reason to retain it, such as:
-
Preventing misuse (e.g., spam or abuse)
-
Fulfilling legal obligations (e.g., recordkeeping or compliance)
-
Ensuring site security or integrity
Although I take care to implement strong technical and organizational measures to protect your information, no online system can be entirely secure. If you are uncomfortable sharing sensitive information through the form, you’re welcome to reach out through other means.
Legal Basis:
-
Consent (Article 6(1)(a) GDPR) – for voluntary submission of contact form data.
-
Legitimate interests (Article 6(1)(f) GDPR) – for abuse prevention and site security.
-
Legal obligation (Article 6(1)(c) GDPR) – where retention is required by law.
9. Comments
If you choose to subscribe to my updates on this website, you may also be allowed to write comments. Commenting is a feature granted only to subscribers who have been assigned a trusted status based on internal criteria.
I reserve the right, at my sole discretion, to decide who is allowed to write comments. Access to commenting can be granted, restricted, or revoked at any time without notice or explanation.
When submitting a comment, you may enter any name of your choice to be displayed publicly. This name is arbitrary and not linked directly to your email address. The email address you use to subscribe is not shown publicly and is used solely for verification and communication purposes.
Please note:
-
Comments are reviewed and may be moderated to prevent spam and abuse.
-
I reserve the right to remove any comment, at any time, for any reason and without prior notice.
-
If you unsubscribe, your email address is deleted. As a result, previously submitted comments become anonymous and can no longer be linked to you. They will not be removed unless deletion is requested before unsubscribing.
By posting a comment, you agree to respectful and lawful participation. Abuse, spam, or inappropriate behavior may lead to restriction or removal of your ability to comment.
10. Data Security and Responsibility
I take appropriate technical and organizational measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction.
However, please note that no system or electronic storage connected to the internet is 100% secure. While I strive to protect your data, I cannot guarantee its absolute security.
By using this website and providing your information, you acknowledge and accept these risks. If you have concerns about sharing your personal data, you are free to withhold such data or contact me through alternative means.
11. International Data Transfers
Some of your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). This may happen, for example, when I use services such as Gmail (for email communication) or website hosting providers whose servers may be located in non-EU countries.
Whenever such transfers occur, I ensure that appropriate safeguards are in place to protect your data in accordance with Articles 44 to 49 of the General Data Protection Regulation (GDPR). These safeguards typically include the use of Standard Contractual Clauses (SCCs) approved by the European Commission, which legally oblige the recipient to protect your personal data to EU standards.
12. Legal Compliance
This policy is designed to comply with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws. If any part of this policy conflicts with applicable law, the law takes precedence.
13. Changes to This Privacy Policy
I may update this Privacy Policy from time to time to reflect changes in legal requirements, services, or data processing practices.
When this happens, the updated version will be published on this page with a revised date.
You are encouraged to review this policy periodically to stay informed about how your personal data is protected.
14. Contact
If you have any questions about this policy, my Cookie Policy, or your personal data, please contact me via the website’s contact page.