Back to home

Privacy Policy.

Notice given to visitors and exhibitors under Articles 13 and 14 of Regulation (EU) 2016/679.

Last updated 15/09/2026
01

Data controller

The data controller is Michele Tufano, Viale Sorrento 61, 60019 Senigallia (AN), Italia — VAT number 02845390422, tax code TFNMHL66L14B715Q. For any matter concerning personal data the contact address is tufanomichele@gmail.com. No data protection officer has been appointed, as the conditions set by law do not apply.

02

Data processed

Visitors: first name, last name, email address, country, password generated by the site and stored as a non-reversible hash, registration date, number and date of the latest entry. Exhibitors: first name, last name, email, telephone, booth name, city, country, booth description, logo, genres and formats handled, declared shipping and payment methods, registration date. Items on sale: artist, title, label, catalogue number, year, format, condition, price, notes and photographs uploaded by the exhibitor. Activity during the fair: entry and exit times, presence in individual booths, messages exchanged in the booth chat together with the name of the person writing them. Payments: amount, currency, outcome and transaction identifiers returned by PayPal.

03

Data the site does not collect

The site does not record visitors' IP addresses, does not build browsing profiles of its own and never receives the card or account details used for payment: the payment takes place entirely on PayPal's pages, which return only the outcome and the transaction code. Technical server logs are kept by the hosting provider under its own privacy notice.

04

Purposes and legal bases

Creating and managing the account, sending the password, access to the halls, opening and running the booth, use of the chat and the video calls: performance of the contract, Article 6(1)(b). Handling the booth payment and tax and accounting obligations: legal obligation, point (c). Replying to requests sent through the contact form and password recovery: performance of the contract and legitimate interest in replying, points (b) and (f). Recording entries and presence in the booths, which allows exhibitors to see who is visiting their booth and the organiser to measure how the fair is going: performance of the contract and legitimate interest of the organiser and the exhibitors, points (b) and (f). Visit statistics and advertising installed by third parties: consent, point (a), which may be withdrawn at any time.

05

Nature of the provision of data

The data requested in the registration forms is needed to create the account, enter the fairs and, for exhibitors, open the booth: without it the service cannot be provided. Data the exhibitor chooses to publish in the booth beyond the required fields, such as the logo, the description and the telephone number, remains optional.

06

Recipients of the data

Data is not transferred to third parties for purposes of their own. Besides the controller, it is accessible to: exhibitors, who see the name of the visitors present in their booth and the messages received in the chat; the hosting provider that runs the site and the database; PayPal for the booth payment; Google for visit statistics, advertising, page fonts and the delivery of service emails; the Jitsi Meet service for video calls in the booths; the jsDelivr and Cloudflare delivery networks, from which the browser downloads the graphic libraries of the site. Whatever the exhibitor publishes in the booth, including name, logo, description and items, is publicly visible. Data may also be disclosed to the authorities in the cases provided for by law.

07

Customer data processed by exhibitors

In their private area exhibitors can write order notes for their customers, entering the customer's name and email address, and send them by email from the site. For this processing the exhibitor is an independent controller and is answerable for the data entered and for the notice to be given to their own customers; the site operator acts as a processor and merely stores the note and forwards the message.

08

Transfers outside the European Union

Some of the providers listed belong to groups based in the United States. Transfers are made on the basis of an adequacy decision of the European Commission or of the standard contractual clauses adopted by the Commission, with the additional safeguards declared by the provider.

09

Retention period

Account data and published content are kept for as long as the account is active; on a deletion request the account and the linked data are erased within thirty days, except for documents that must be kept by law. Entry times, presence in the booths and chat messages are kept for twelve months after the fair closes. Order notes remain available to the exhibitor until deleted or until the account is closed. Payment data and accounting documents are kept for ten years, as required by Article 2220 of the Italian civil code. The log of emails sent by the site is kept for twelve months.

10

Your rights

Data subjects have the rights set out in Articles 15 to 22 of the Regulation: access to their data, rectification, erasure, restriction of processing, portability and objection to processing based on legitimate interest. Consent given for non-technical cookies may be withdrawn at any time, without affecting the lawfulness of processing carried out before the withdrawal. Requests should be sent to tufanomichele@gmail.com and are answered within one month.

11

Complaint to the supervisory authority

Anyone who believes that their data is being processed in breach of the Regulation may lodge a complaint with the Italian data protection authority, Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, or bring the matter before a court.

12

Automated decision-making

No decisions are taken solely on the basis of automated processing that produce legal effects on data subjects or similarly affect them. The site carries out no profiling on behalf of the controller.

13

Minors

The service is not addressed to children under fourteen. The controller does not knowingly collect data of children below that age and deletes it as soon as it becomes aware of it.

14

Security and changes

The site is served over an encrypted HTTPS connection, passwords are stored as non-reversible hashes, the automatic sign-in code is stored in the database as a hash only, and the administration area is protected by personal credentials. Breaches entailing a risk for data subjects are notified under Articles 33 and 34 of the Regulation. This notice may be amended to reflect new features of the site or changes in the law: the version published on this page, with the date shown above, is the one that applies.