Notice
Privacy Policy
Last updated: 1 July 2026
This notice explains how personal data of visitors to somax.studio (the “Site”) is processed, in accordance with Regulation (EU) 2016/679 (GDPR).
1. Data controller
The data controller is Luca Orlandi.
For any matter concerning your personal data you can contact the controller through the contact form.
2. What data we process, why, and on what legal basis
a) Browsing data (server logs)
In normal operation the Site’s systems collect data whose transmission is inherent to internet protocols: IP address, browser type, date and time of the request, pages visited. This data is used only to ensure the correct functioning and security of the Site and, in aggregate form, for technical statistics.
- Purpose: operation and security of the Site.
- Legal basis: legitimate interest of the controller (Art. 6.1.f GDPR).
- Processor: Aruba S.p.A., hosting provider.
b) Contact form data
When you use the contact form you voluntarily provide your name, email address and the content of your message. This data is used solely to read and reply to your request. The message reaches us by email; the Site has no database.
- Purpose: to respond to the requests you send us.
- Legal basis: handling your request / pre-contractual steps and, where applicable, your consent (Art. 6.1.b/a GDPR).
- Provision: optional, but without this data we cannot reply to you.
c) Form anti-spam protection (Cloudflare Turnstile)
To protect the contact form from automated submissions (spam/bots) we use Cloudflare Turnstile. The service verifies that a submission comes from a human and, for this purpose, processes some technical data (IP address, browser and interaction information). Turnstile is privacy-oriented and is not used for profiling or advertising.
- Purpose: form security, prevention of abuse and spam.
- Legal basis: legitimate interest of the controller (Art. 6.1.f GDPR).
- Provider: Cloudflare, Inc. (USA), acting as processor.
3. Cookies
The Site uses only necessary technical cookies. No profiling or third-party advertising cookies are used. For details see the Cookie Policy.
4. Recipients of the data
Data is not disclosed publicly. It may be processed, on our behalf and within their respective purposes, by providers supplying us technical services (in particular the hosting provider Aruba S.p.A. and the anti-spam service Cloudflare, Inc.), appointed as processors. Data is never sold or transferred to third parties.
5. Transfers outside the EU
The use of Cloudflare may involve the transfer of some technical data to third countries (USA). Such transfers take place on the basis of adequate safeguards under the GDPR (Standard Contractual Clauses and/or adherence to the EU-US Data Privacy Framework).
6. Retention period
- Contact messages: kept for as long as needed to handle the request and any related obligations, and in any case no longer than necessary for the purposes.
- Technical logs: kept for a limited period according to the hosting provider’s policies.
7. Your rights
As a data subject you have the right, within the limits of the law, to: access your data, request its rectification or erasure, obtain its restriction, object to the processing, request portability and, where processing is based on consent, withdraw it at any time (Arts. 15-22 GDPR).
You can exercise these rights at any time through the contact form. You also have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).
8. Changes to this notice
We may update this notice over time. The version published on this page, with its date, is the one in force.