Website Privacy Policy
Last updated: 12 August 2026
This Privacy Policy explains how personal data are collected and processed when you visit luigicoppolaconsulting.com, request information or resources, subscribe to email communications, book a call, or contact Luigi Coppola through the channels available on this website.
1. Data controller
The data controller is:
Italian Vacation Homes di Luigi Coppola
Registered address: Via Alberto da Giussano 12, 25032 Chiari (BS), Italy
VAT number: IT04197900980
Electronic invoicing code (SDI): M5UXCR1
Certified email (PEC): italianvacationhomes@pec.it
Telephone: +39 348 333 1667
General email: luigi.coppola@italianvacationhomes.it
Email for privacy enquiries and exercise of data protection rights: info@luigicoppolaconsulting.com
The business is represented by Luigi Coppola, legal representative, Italian tax code CPPLGU79D27B157O, domiciled at Via Alberto da Giussano 12, 25032 Chiari (BS), Italy.
For any question concerning this Privacy Policy or the processing of your personal data, you may contact the data controller at info@luigicoppolaconsulting.com.
2. Personal data we process
Depending on how you use the website and its services, we may process the following categories of personal data:
- identification and contact details, such as your name, surname, email address and telephone number;
- information you voluntarily provide when you send a message, request information, download a resource, complete a questionnaire or request a consultation;
- information related to the property, purchase or service for which you are seeking assistance;
- newsletter and resource-request data, including subscription status, consent records and unsubscribe requests;
- email delivery, opening and click data, where these functions are enabled;
- booking details provided when arranging a telephone call or consultation;
- technical and browsing data, such as IP address, browser, device, operating system, pages visited, date and time of access, referring page and technical logs;
- cookie preferences and records of the consent choices made through the website;
- information exchanged when you choose to contact us through email, telephone, WhatsApp or a third-party booking service.
Please do not submit health data, financial account information, identification documents, special-category data or other confidential information unless it is genuinely necessary and has been specifically requested through an appropriate channel.
3. Purposes, legal bases and retention periods
3.1 Responding to enquiries and providing requested services
Your personal data may be processed to:
- respond to your questions and requests;
- provide information about the services offered;
- assess your needs;
- arrange a call or consultation;
- take steps at your request before entering into a contract;
- prepare a proposal or quotation;
- manage any resulting professional or contractual relationship;
- provide the requested consultancy or assistance.
The legal basis is Article 6(1)(b) GDPR, as the processing is necessary to perform a contract or take pre-contractual measures at your request.
Where processing is necessary to comply with accounting, tax, administrative or other legal requirements, the legal basis is Article 6(1)(c) GDPR.
Enquiries that do not result in a professional relationship are normally retained for no longer than 24 months after the last meaningful contact, unless a longer period is necessary to establish, exercise or defend a legal claim.
Contractual, administrative and tax records are retained for the period required by applicable law, which is generally 10 years in Italy.
3.2 Delivering requested resources
When you request a guide, report, checklist, book-related resource or other material, your personal data may be processed to:
- register your request;
- deliver the requested resource;
- send service communications relating directly to that request;
- verify the correct delivery of the resource;
- prevent abuse or repeated automated requests.
The legal basis is Article 6(1)(b) GDPR, as the processing is necessary to provide something specifically requested by you.
Records connected with the delivery of a resource may normally be retained for up to 24 months.
Requesting a resource does not automatically authorise the use of your data for unrelated promotional communications unless this is clearly stated and you have provided a valid marketing consent.
3.3 Newsletter and marketing communications
Only if you provide specific consent, your name and email address may be used to send:
- newsletters;
- educational articles and resources;
- information about buying or owning property in Italy;
- updates concerning Luigi Coppola’s services;
- invitations, business updates and promotional communications.
The legal basis is Article 6(1)(a) GDPR: your consent.
Providing marketing consent is optional. Refusing consent does not prevent you from contacting us, receiving a requested service or entering into a professional relationship.
You may withdraw your consent at any time by:
- clicking the unsubscribe link included in every marketing email; or
- writing to info@luigicoppolaconsulting.com.
Withdrawing consent does not affect the lawfulness of any processing carried out before the withdrawal.
Newsletter data are retained until you withdraw your consent, unsubscribe or the communication service is discontinued. Inactive contacts may be reviewed and removed periodically.
Minimal suppression data may be retained after unsubscribing to ensure that your request not to receive further communications continues to be respected.
Email communications and subscription records are managed through Brevo.
Where enabled, Brevo may collect technical information about email delivery, openings and clicks. These data are used to measure the effectiveness of communications, troubleshoot delivery problems and improve the relevance of the content sent.
3.4 Website operation, security and abuse prevention
Technical data may be processed to:
- operate and maintain the website;
- ensure its security and availability;
- diagnose technical errors;
- prevent fraud, spam, abuse and unauthorised access;
- maintain security logs;
- create backups;
- protect the rights, systems and information of the data controller and website users.
The legal basis is Article 6(1)(f) GDPR, namely the legitimate interest of the data controller in ensuring the security, integrity and proper functioning of the website and its services.
Technical and security logs are retained only for as long as necessary for security, maintenance and troubleshooting purposes. They are normally retained for no longer than 12 months, unless a security incident, investigation or legal requirement justifies a longer period.
3.5 Audience measurement with Google Analytics 4
Subject to your consent, the website may use Google Analytics 4 to understand how visitors use the website and improve its content, navigation and technical performance.
Depending on the configuration and consent granted, Google Analytics may process information such as:
- pages viewed;
- approximate geographic location;
- device and browser information;
- date, time and duration of visits;
- interactions with website content;
- source through which the user reached the website;
- technical identifiers and IP-related information.
The legal basis is Article 6(1)(a) GDPR: your consent.
Google Analytics and any related non-essential identifiers are disabled before consent through the website’s consent-management system.
You may refuse or withdraw your consent without losing access to the essential parts of the website.
Event-level data are retained according to the retention period configured in the Google Analytics account and only for as long as necessary for audience measurement and website improvement.
Aggregated reports may be retained for a longer period when they no longer directly identify individual users.
You may change or withdraw your cookie preferences at any time through the cookie settings available on the website.
3.6 Compliance with legal obligations and protection of rights
Personal data may also be processed to:
- comply with applicable laws and regulations;
- respond to legitimate requests from public authorities;
- fulfil accounting, tax and administrative obligations;
- detect or prevent unlawful conduct;
- establish, exercise or defend legal claims.
The relevant legal bases are:
- Article 6(1)(c) GDPR, where processing is required to comply with a legal obligation;
- Article 6(1)(f) GDPR, where processing is necessary for the legitimate interest of the data controller in protecting its rights.
The data are retained for the period required by applicable law or until the relevant limitation period has expired.
4. How personal data are collected
Personal data may be collected directly from you when you:
- submit a form;
- request a resource;
- subscribe to email communications;
- request or book a consultation;
- send an email;
- telephone us;
- contact us through WhatsApp;
- provide information during a professional conversation.
Technical data and cookie preferences may be collected automatically when you browse the website, subject to the choices you make through the cookie banner.
If you contact us or book a call through an external service, that provider may also process your personal data under its own privacy policy and terms of service.
5. Recipients and service providers
Personal data may be accessed by authorised personnel and by external service providers where this is necessary to operate the website or provide the requested service.
These recipients may include:
- Hosting4Agency, for website hosting and related technical services;
- Brevo, also known as Sendinblue, for resource delivery, newsletter subscriptions and email communications;
- Google, for Google Analytics 4 and related technical services, subject to your consent;
- Complianz, as the software used to collect and record cookie preferences;
- WordPress and providers involved in website maintenance, security, backups and anti-spam protection;
- Calendly or another booking provider, when you choose to use an external booking page;
- Meta and WhatsApp, when you voluntarily use WhatsApp to contact us;
- IT consultants and technical support providers;
- accountants, legal advisers, insurers and other professional consultants;
- competent public authorities, courts or law enforcement bodies where disclosure is required by law.
Service providers receive only the data necessary to perform their assigned functions.
Where required by the GDPR, service providers are appointed as data processors under Article 28 GDPR and process personal data according to documented instructions from the data controller.
Some third-party providers may act as independent data controllers for their own purposes. When you use their services, their own privacy policies and contractual conditions also apply.
Personal data are not sold to third parties.
6. International data transfers
Some providers used by the website, including Google, Meta, WhatsApp and Calendly, may process personal data outside the European Economic Area or make data accessible from third countries.
Where required, these transfers are carried out using one of the mechanisms permitted by Chapter V GDPR, including:
- an adequacy decision adopted by the European Commission;
- the European Commission’s Standard Contractual Clauses;
- participation in an applicable recognised data-transfer framework;
- another lawful safeguard provided by the GDPR.
You may request further information about the safeguards applicable to the processing of your personal data by writing to info@luigicoppolaconsulting.com.
7. Cookies and similar technologies
The website uses technical cookies and similar technologies that are necessary for its operation.
Subject to the user’s consent, it may also use analytics or other non-essential technologies.
The cookie banner allows users to:
- accept non-essential cookies;
- refuse non-essential cookies;
- select individual categories;
- change or withdraw their choices later.
Refusing non-essential cookies does not prevent access to the main contents and essential functions of the website.
For the current list of cookies, providers, purposes and durations, please refer to the separate Cookie Policy available on this website and generated and maintained through Complianz.
The Cookie Policy forms an integral part of this Privacy Policy.
8. Whether providing personal data is mandatory
Providing the data marked as necessary in an enquiry, resource request or booking process is required to receive a response or obtain the requested service.
If you do not provide these data, we may be unable to process your request.
Providing personal data for newsletters and promotional communications is optional. Refusing or withdrawing marketing consent has no effect on your ability to use the other services available through the website.
9. Automated decision-making
The data controller does not use personal data collected through this website to make decisions based solely on automated processing that produce legal effects or similarly significant consequences for users within the meaning of Article 22 GDPR.
The website does not carry out automated credit assessments, eligibility decisions or profiling that produces legal or similarly significant effects.
10. Your rights
Subject to the conditions established by the GDPR, you may request:
- confirmation as to whether your personal data are being processed;
- access to your personal data and a copy of them;
- correction of inaccurate or incomplete personal data;
- deletion of your personal data;
- restriction of processing;
- data portability, where applicable;
- objection to processing based on legitimate interests;
- withdrawal of consent at any time;
- information about the safeguards used for international data transfers.
You also have the right to object at any time to the processing of your personal data for direct marketing purposes.
To exercise your rights, email:
info@luigicoppolaconsulting.com
Your request should contain enough information to allow us to identify the relevant data and understand the right you wish to exercise.
We may ask you to provide information reasonably necessary to verify your identity and prevent unauthorised access to personal data.
Requests will be handled within the time limits established by the GDPR.
Exercising your rights is normally free of charge. However, the GDPR permits a reasonable fee or refusal where a request is manifestly unfounded or excessive, particularly because of its repetitive nature.
11. Complaints to a supervisory authority
If you believe that your personal data have been processed unlawfully, you have the right to lodge a complaint with the Italian Data Protection Authority:
Garante per la protezione dei dati personali
Website: www.garanteprivacy.it
You may also contact the competent supervisory authority in the EU Member State where you live, work or believe that an infringement has occurred.
We encourage you to contact us first at info@luigicoppolaconsulting.com so that we can examine and, where appropriate, resolve the issue.
12. Security
The data controller adopts technical and organisational measures appropriate to the nature of the personal data processed and the risks involved.
These measures are intended to protect personal data against:
- unauthorised or unlawful access;
- accidental loss;
- destruction;
- alteration;
- unauthorised disclosure;
- misuse.
Access to personal data is limited to authorised persons and providers who need the information to perform their duties.
However, no method of online transmission or electronic storage can guarantee absolute security.
Users should avoid sending unnecessary confidential, sensitive or special-category data through ordinary website forms, email or WhatsApp.
13. Third-party websites and services
The website may contain links to websites, platforms or services operated by third parties.
When you follow one of these links, the third party may collect and process personal data under its own privacy policy.
This Privacy Policy does not govern the processing carried out independently by those third parties. The data controller is not responsible for their websites, security measures or privacy practices.
You should review the relevant privacy information before submitting personal data to an external service.
14. Children
The website and the services promoted through it are intended for adults.
We do not knowingly collect personal data from children through newsletter, resource-request or consultation forms.
If you believe that a child has provided personal data through the website without appropriate authorisation, please contact us at info@luigicoppolaconsulting.com.
We will assess the matter and delete the data where required by applicable law.
15. Changes to this Privacy Policy
This Privacy Policy may be updated to reflect:
- changes to the website or its services;
- the introduction or removal of service providers;
- changes to the way personal data are processed;
- legal or regulatory developments;
- new guidance from supervisory authorities.
The latest version will always be published on this page and identified by the “Last updated” date shown at the top.
Where appropriate, material changes may also be highlighted through the website or communicated through other suitable channels.