Last updated 24 August 2026
Personal data
This site uses no cookies and does not identify its visitors. Only two things happen here: an anonymous count of visits, and the sending of the contact form. Both are described in full below.
Who handles the data
The data controller is Testori Alessandra, a sole trader whose registered office is at Via Sopramonte 1, 54100 Massa (MS), Italy.
For anything concerning your data, write to info@28nero.it or call +39 335 64 000 54.
Italian VAT number IT06587840486.
If you only visit the site
Reading these pages leaves behind nothing that could identify you. The site sets no cookies, neither technical nor for profiling, and stores nothing at all in your browser. The typefaces are served by the site itself and not by an outside supplier, and no image, map or social media content is embedded from elsewhere: the links to Instagram, Pinterest and Google Maps are links, and nothing is loaded from them unless you click.
One single file does come from outside, and it is the one that counts visits, described below. It writes nothing to your browser either. That is why there is no cookie banner: nothing is stored on or read from your device, so there is nothing to agree to.
Counting visits
To know how many people read the site and which pages interest them most, it uses Cloudflare Web Analytics, run by Cloudflare, Inc. in the United States. It was chosen precisely because, unlike the more common tools, it uses no cookies and no other client-side storage, and does not follow a visitor over time by IP address, browser type or any other unchanging attribute. What is shown to the studio are overall counts: visits, most read pages, country of origin, type of device. None of them refers to an identifiable person.
To load that file and to count the visit, your IP address does reach Cloudflare, as it does with any address you open. It is not used to recognise you, to build a profile or to follow you from one site to another. The legal basis is the legitimate interest in knowing how many people read these pages (Article 6(1)(f) of Regulation (EU) 2016/679), and you may object to it at any time under Article 21 by writing to the address below.
The pages are published on GitHub Pages (GitHub, Inc., a Microsoft company, in the United States) which, like any hosting service, logs requests to its own servers, IP address included, for security and abuse prevention.
Both companies are outside the European Union. The transfer is covered by the Standard Contractual Clauses approved by the European Commission, and a copy of the safeguards may be requested at the email address above.
If you write through the contact form
What is collected
Name, email address and message are required, because without them there is no way to answer: if you leave them empty the form cannot be sent. Phone and city are optional, and leaving them out changes nothing. The subject chosen from the drop-down menu is added.
The service that receives the form also records some technical data about the submission itself: IP address, time of sending, and the page it came from.
Please do not put anything in the message that reveals health, personal beliefs or other particularly sensitive information: none of it is needed to answer an enquiry about a project.
Why
To read the enquiry and reply to it. The legal basis is the taking of steps at the request of the data subject prior to entering into a contract (Article 6(1)(b) of Regulation (EU) 2016/679). The technical data listed above is used to keep automated and abusive submissions out, and its basis is the legitimate interest in protecting the form from misuse (Article 6(1)(f)).
No marketing messages are sent, the data is not sold or passed to anyone beyond the suppliers named below, and nothing you write is fed to any automated decision or profiling.
Through which services
The site is made of static pages only and cannot process forms: sending is handled by Web3Forms, a service run by Web3Creative, based in India, acting as data processor under an agreement that incorporates the Standard Contractual Clauses approved by the European Commission for transfers to third countries.
Web3Creative in turn relies on these providers:
- Amazon Web Services, Inc.: hosting, storage and email delivery
- Cloudflare, Inc.: content delivery network and protection of the collection endpoint, on its global network
- Hetzner Online GmbH: application infrastructure, in Germany and Finland
- CleanTalk Inc. and Automattic Inc. (Akismet), in the United States: spam filtering. They receive the sender's IP address and email in order to judge whether the message is automated
- Microsoft Corporation (Clarity), in the United States: analysis of how the Web3Forms control panel is used, which may record what is on screen while a submission is being read
The current and complete list is Annex 3 of the Web3Forms Data Processing Agreement. Those of these suppliers that are outside the European Union work under the Standard Contractual Clauses approved by the European Commission, incorporated into that agreement; a copy of the safeguards may be requested at the email address above.
The message is then delivered to the studio's mailbox, hosted by Keliweb S.r.l., in Italy.
For how long
At Web3Forms the submission data is kept for at most three years from the day it is sent, after which it is deleted automatically. The studio can see it in the Web3Forms control panel only for the first thirty days; after that the message lives on in the mailbox alone. In the studio's mailbox the message is kept for as long as it takes to deal with the enquiry and, if it turns into a commission, for the duration of the relationship and the periods required by law thereafter. You may ask for earlier deletion at any time.
Your rights
The Regulation gives everyone the right to know whether data concerning them is being processed and to obtain a copy of it, to have it corrected if inaccurate, to ask for its erasure or restriction, to receive it in a machine-readable format, and to object to the processing (Articles 15 to 22).
To exercise them, write to info@28nero.it. An answer will come within one month, which the Regulation allows to be extended by a further two months for requests that are complex or numerous. You will be told if that happens, and why.
Anyone who believes the processing breaches the Regulation may complain to the Italian Data Protection Authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or take the matter to court.
Changes
If the tools used or the way data is handled should change, this page will be updated and the date at the top will change with it.