Last updated: August 6, 2025
Francesco Sapio – privacy@redhogstudio.com
| Context | Data collected |
|---|---|
| Contact form |
|
| Newsletter / Direct-e-mail marketing | e-mail address, name/surname (when provided) |
| Site analytics & security |
|
| Activity | Purpose | GDPR legal basis | Retention |
|---|---|---|---|
| Responding to contact-form enquiries | Evaluate and reply to requests, prepare pre-contractual offers. | Art. 6 (1)(b) – pre-contractual steps at data-subject request. | 24 months after last interaction. |
| Sending newsletters / DEM | Inform about news, promotions, events. | Art. 6 (1)(a) – consent (separate, granular). | Until consent is withdrawn or address bounces; verified every 24 months. |
| Web analytics (Matomo, self-hosted) | Measure audience, improve content, detect anomalies. | Art. 6 (1)(f) – legitimate interest; we employ IP-anonymisation and privacy-enhanced settings. | Raw logs 90 days; aggregated stats 13 months. |
| Spam/bot filtering (Google reCAPTCHA) | Protect forms against automated abuse. | Art. 6 (1)(f) – legitimate interest in security. | Up to 6 months, per Google policies. |
| Server hosting & backup | Operate website, ensure integrity, disaster recovery. | Art. 6 (1)(f) – legitimate interest. | Backups max 30 days; server logs 7-30 days. |
Provision of mandatory fields on the contact form and newsletter sign-up is necessary to receive a reply or the requested communications; failure to provide them prevents us from delivering the service.
| Recipient (processor / sub-processor) | Service | Location | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Web-hosting (VPS) | Germany | In-EEA; DPA in place. |
| Google LLC – Google Drive | Cloud backup & file collaboration | USA | EU-US Data Privacy Framework & SCCs. |
| Google LLC – reCAPTCHA | Bot mitigation | USA | EU-US DPF & SCCs (JavaScript executed client-side). |
No other third parties receive personal data unless required by law or to defend legal claims.
Under Articles 15-22 GDPR you may at any time:
To exercise rights, write to privacy@redhogstudio.com or the postal address above. We may verify your identity before acting.
You may lodge a complaint with the Italian Supervisory Authority (Garante per la Protezione dei Dati Personali) or with your local EU authority.
We do not engage in automated decision-making producing legal or similarly significant effects.
We implement HTTPS/TLS, strong access controls, encryption at rest for backups on Google Drive, server hardening, regular patching and logging per industry best practice. Hetzner data centres are ISO 27001-certified.
We may revise this Privacy Policy to reflect changes in legislation or our processing activities. Updated versions will be published on this page; material changes will be highlighted for at least 30 days.
© 2025 RED HOG STUDIO srl - All Rights Reserved
Designed to impress by Backdoor