Privacy Policy | GiaNet Media
Last updated: 21/07/2026
Privacy Policy
Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003, as amended by Legislative Decree 101/2018 (the "Privacy Code"), GiaNet Media provides this Privacy Policy to users who browse and use the services available on the website gianetmedia.com.
1. Data Controller
The Data Controller is:
- Giannetta Francesco (sole proprietorship) — GiaNet Media
- Registered address: Via Canonico Martire Schito 13, 73028 Otranto (LE), Italy
- VAT number: 04410590758
- Tax code (Codice Fiscale): GNNFNC81C09G751T
- Email: [email protected]
- Certified email (PEC): [email protected]
The Controller operates under the Italian flat-rate tax scheme ("regime forfettario", Law 190/2014): invoices issued do not include VAT.
For any request concerning the processing of personal data, data subjects may contact the Controller at the email address indicated above.
2. Categories of Personal Data Collected
In connection with the use of the website and the services offered, GiaNet Media may collect and process the following categories of personal data:
2.1 Data provided upon registration and account use
- First and last name (or company name)
- Email address
- Password (stored in encrypted form)
- Data related to the workspace and any collaborators associated with the account
- Language and theme (light/dark) preferences, managed via technical cookies
2.2 Payment data
When purchasing services, subscriptions, or credit packages through the payment provider Stripe, payment card data and related billing information are collected and processed directly by Stripe. GiaNet Media does not receive or store full payment card data, but receives from Stripe the information necessary to confirm the outcome of the transaction (e.g., amount, payment status, transaction ID) and the data required to issue an electronic invoice.
2.3 Data provided through the contact form
The contact form collects the name, email address, and any message entered by the user. The form is protected by the anti-spam service Cloudflare Turnstile, which performs an automated check to distinguish genuine requests from automated/bot traffic.
2.4 Browsing data
During normal browsing of the website, technical data may be collected (IP address, browser type, operating system, pages visited, date and time of access) as well as technical cookies necessary for the website to function (language selector, light/dark theme, authentication session). For further details, please refer to the Cookie Policy (see section 9).
2.5 Data related to support, orders, and reviews
- Content of support tickets opened by the user
- Order history and electronic invoicing data
- Reviews submitted by the user, if any
- Data related to the referral/affiliate program, including requests for withdrawal of earned commissions (e.g., data necessary to process payouts)
2.6 Content uploaded by the user
Where the user uploads content (files, images, text) in connection with the use of the services, such content is processed solely for the purpose of providing the requested service.
3. Purposes of Processing and Legal Bases
Personal data is processed for the following purposes:
3.1 Performance of a contract or pre-contractual measures (Art. 6.1.b GDPR)
- Creation and management of the user account and reserved area
- Provision of purchased services (video/photo production, web agency, graphic/brand design, audio/music, publishing, "La Ozza" B&B bookings, etc.)
- Management of purchases via Stripe and related payments
- Management of customer support tickets
- Management of the referral/affiliate program and payout requests
3.2 Legal obligation (Art. 6.1.c GDPR)
- Issuance of electronic invoices and compliance with tax and accounting obligations
- Retention of accounting records for the period required by law
3.3 Consent of the data subject (Art. 6.1.a GDPR)
- Any marketing communications or newsletters, where active, subject to specific consent, which may be withdrawn at any time
- Publication of reviews with attribution of the username, where specific consent is requested at the time of submission
3.4 Legitimate interest of the Controller (Art. 6.1.f GDPR)
- Website security, fraud prevention, and protection against abuse and cyberattacks (e.g., via Cloudflare Turnstile)
- Technical improvement of services and resolution of technical issues
4. Processing Methods and Security
Personal data is processed using IT and telematic tools, following logic strictly related to the purposes indicated above, and in any case in a manner that ensures the security and confidentiality of the data.
GiaNet Media adopts appropriate technical and organizational security measures to prevent loss, unlawful or improper use, and unauthorized access to data, including:
- Encryption of passwords and communications (HTTPS protocol)
- Data access limited to authorized personnel and collaborators, within the scope of the purposes indicated above
- Use of service providers (Stripe, Cloudflare, hosting providers) that adopt internationally recognized security standards
5. Recipients of Data and External Data Processors
Personal data may be disclosed, to the extent strictly necessary for the purposes described above, to the following parties, appointed as data processors where applicable pursuant to Art. 28 GDPR:
- Stripe, Inc. — for online payment processing and invoicing
- Cloudflare, Inc. — for security services, anti-spam protection (Turnstile), and content delivery
- Website hosting and technical infrastructure providers
- Email service providers, for sending transactional communications (e.g., registration confirmation, service notifications)
- The Controller's accountant and other professionals engaged for tax, accounting, and legal compliance
- Technical providers operating within the Trovido Network, limited to shared platform services (e.g., centralized account management), in compliance with the principles of data minimization and purpose limitation
- Public authorities, where required by law
Data is not disclosed to third parties except as indicated above, and is not shared with third parties for third-party marketing purposes without specific consent.
6. Transfers of Data Outside the EU
Some of the providers listed above (in particular Stripe and Cloudflare) may process personal data outside the European Economic Area (EEA), in particular in the United States. In such cases, the transfer is based on adequate safeguards provided for by the GDPR, such as the Standard Contractual Clauses approved by the European Commission, or other transfer mechanisms recognized as adequate under applicable law.
Users may request further information on the safeguards adopted by contacting the Controller at the address indicated in Section 1.
7. Data Retention Period
Personal data is retained for the time strictly necessary to achieve the purposes for which it was collected, and in particular:
- Account data is retained for the duration of the contractual relationship and, thereafter, for the time necessary to protect the Controller's interests in connection with any liability related to service management
- Accounting and invoicing data is retained for the period required by applicable tax and civil law (generally 10 years)
- Support ticket data is retained for the time necessary to handle the request and for a limited subsequent period for service quality purposes
- Data processed on the basis of consent is retained until such consent is withdrawn
8. Rights of the Data Subject
As a data subject, the user has the right, pursuant to Articles 15-22 of the GDPR, to obtain from the Controller, where applicable:
- Access to their personal data (Art. 15)
- Rectification of inaccurate or incomplete data (Art. 16)
- Erasure of data ("right to be forgotten"), in the cases provided for by law (Art. 17)
- Restriction of processing (Art. 18)
- Data portability, i.e., the right to receive data in a structured, machine-readable format and to transmit it to another controller (Art. 20)
- Objection to processing, in particular for direct marketing purposes or where processing is based on the Controller's legitimate interest (Art. 21)
- Withdrawal of consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal
To exercise these rights, data subjects may write to [email protected].
Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), based at Piazza Venezia 11, 00187 Rome, Italy, if they believe that the processing of their personal data is contrary to applicable law (www.garanteprivacy.it).
9. Cookies
The website uses technical cookies necessary for basic functionality (authentication, language selector, light/dark theme) and, where applicable, third-party cookies related to the services described in this Privacy Policy (e.g., Cloudflare Turnstile, Stripe). For detailed information on the cookies used, their purposes, and how to manage preferences, please refer to the Cookie Policy published on the website.
10. Changes to this Privacy Policy
GiaNet Media reserves the right to modify or update this Privacy Policy, in whole or in part, including as a result of changes in applicable law. Any changes will be published on this page, indicating the date of the last update. Users are encouraged to periodically review this page.
Last updated: July 20, 2026