Privacy Policy | GiaNet Media
Last updated: 09/08/2026
Privacy Policy
Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003, as amended by Legislative Decree 101/2018 (the "Privacy Code"), GiaNet Media provides this Privacy Policy to users who browse and use the services available on the website gianetmedia.com.
1. Data Controller
The Data Controller is:
- Giannetta Francesco (sole proprietorship) — GiaNet Media
- Registered address: Via Canonico Martire Schito 13, 73028 Otranto (LE), Italy
- VAT number: 04410590758
- Tax code (Codice Fiscale): GNNFNC81C09G751T
- Email: [email protected]
- Certified email (PEC): [email protected]
The Controller operates under the Italian flat-rate tax scheme ("regime forfettario", Law 190/2014): invoices issued do not include VAT.
For any request concerning the processing of personal data, data subjects may contact the Controller at the email address indicated above.
2. Categories of Personal Data Collected
In connection with the use of the website and the services offered, GiaNet Media may collect and process the following categories of personal data:
2.1 Data provided upon registration and account use
- First and last name (or company name)
- Email address
- Password (stored in encrypted form)
- Data related to the workspace and any collaborators associated with the account
- Language and theme (light/dark) preferences, managed via technical cookies
2.2 Payment data
When purchasing services, subscriptions, or credit packages through the payment provider Stripe, payment card data and related billing information are collected and processed directly by Stripe. GiaNet Media does not receive or store full payment card data, but receives from Stripe the information necessary to confirm the outcome of the transaction (e.g., amount, payment status, transaction ID) and the data required to issue an electronic invoice.
2.3 Data provided through the contact form
The contact form collects the name, email address, and any message entered by the user. The form is protected by the anti-spam service Cloudflare Turnstile, which performs an automated check to distinguish genuine requests from automated/bot traffic.
2.4 Browsing data
During normal browsing of the website, technical data may be collected (IP address, browser type, operating system, pages visited, date and time of access) as well as technical cookies necessary for the website to function (language selector, light/dark theme, authentication session). For further details, please refer to the Cookie Policy (see section 9).
2.5 Data related to support, orders, and reviews
- Content of support tickets opened by the user
- Order history and electronic invoicing data
- Reviews submitted by the user, if any
- Data related to the referral/affiliate program, including requests for withdrawal of earned commissions (e.g., data necessary to process payouts)
2.6 Content uploaded by the user
Where the user uploads content (files, images, text) in connection with the use of the services, such content is processed solely for the purpose of providing the requested service.
3. Purposes of Processing and Legal Bases
Personal data is processed for the following purposes:
3.1 Performance of a contract or pre-contractual measures (Art. 6.1.b GDPR)
- Creation and management of the user account and reserved area
- Provision of purchased services (video/photo production, web agency, graphic/brand design, audio/music, publishing, "La Ozza" B&B bookings, etc.)
- Management of purchases via Stripe and related payments
- Management of customer support tickets
- Management of the referral/affiliate program and payout requests
3.2 Legal obligation (Art. 6.1.c GDPR)
- Issuance of electronic invoices and compliance with tax and accounting obligations
- Retention of accounting records for the period required by law
3.3 Consent of the data subject (Art. 6.1.a GDPR)
- Any marketing communications or newsletters, where active, subject to specific consent, which may be withdrawn at any time
- Publication of reviews with attribution of the username, where specific consent is requested at the time of submission
3.4 Legitimate interest of the Controller (Art. 6.1.f GDPR)
- Website security, fraud prevention, and protection against abuse and cyberattacks (e.g., via Cloudflare Turnstile)
- Technical improvement of services and resolution of technical issues
4. Processing Methods and Security
Personal data is processed using IT and telematic tools, following logic strictly related to the purposes indicated above, and in any case in a manner that ensures the security and confidentiality of the data.
GiaNet Media adopts appropriate technical and organizational security measures to prevent loss, unlawful or improper use, and unauthorized access to data, including:
- Encryption of passwords and communications (HTTPS protocol)
- Data access limited to authorized personnel and collaborators, within the scope of the purposes indicated above
- Use of service providers (Stripe, Cloudflare, hosting providers) that adopt internationally recognized security standards
5. Recipients of Data and External Data Processors
Personal data may be disclosed, to the extent strictly necessary for the purposes described above, to the following parties, appointed as data processors where applicable pursuant to Art. 28 GDPR:
- Stripe, Inc. — for online payment processing and invoicing
- Cloudflare, Inc. — for security services, anti-spam protection (Turnstile), and content delivery
- Website hosting and technical infrastructure providers
- Email service providers, for sending transactional communications (e.g., registration confirmation, service notifications)
- The Controller's accountant and other professionals engaged for tax, accounting, and legal compliance
- Technical providers operating within the Trovido Network, limited to shared platform services (e.g., centralized account management), in compliance with the principles of data minimization and purpose limitation
- Public authorities, where required by law
Data is not disclosed to third parties except as indicated above, and is not shared with third parties for third-party marketing purposes without specific consent.
Payment services. In addition to Stripe, for some payment methods — payment of instalments on an accepted quote and renewal of services for existing clients — PayPal (Europe) S.à r.l. et Cie, S.C.A. is used, which receives the data needed to carry out the transaction. GiaNet Media does not store card data.
Automatic translation of text. Anyone publishing a profile in the roster can request automatic translation of their biography and descriptions. To carry this out, the text concerned is sent to Groq, Inc., the language-model provider, which processes it to return the translation. Only the text chosen for translation by the data subject is transmitted: not documents, not tax data, not bank details. The feature is optional and is activated only on explicit request.
Linked calendars. Anyone who chooses to link their calendar shares with Google Ireland Limited or Microsoft Ireland Operations Limited, depending on the service chosen, the data needed to read and write appointments. Linking is optional and can be revoked at any time from your profile.
6. Transfers of Data Outside the EU
Some of the providers listed above (in particular Stripe and Cloudflare) may process personal data outside the European Economic Area (EEA), in particular in the United States. In such cases, the transfer is based on adequate safeguards provided for by the GDPR, such as the Standard Contractual Clauses approved by the European Commission, or other transfer mechanisms recognized as adequate under applicable law.
Users may request further information on the safeguards adopted by contacting the Controller at the address indicated in Section 1.
7. Data Retention Period
Personal data is retained for the time strictly necessary to achieve the purposes for which it was collected, and in particular:
- Account data is retained for the duration of the contractual relationship and, thereafter, for the time necessary to protect the Controller's interests in connection with any liability related to service management
- Accounting and invoicing data is retained for the period required by applicable tax and civil law (generally 10 years)
- Support ticket data is retained for the time necessary to handle the request and for a limited subsequent period for service quality purposes
- Data processed on the basis of consent is retained until such consent is withdrawn
8. Rights of the Data Subject
As a data subject, the user has the right, pursuant to Articles 15-22 of the GDPR, to obtain from the Controller, where applicable:
- Access to their personal data (Art. 15)
- Rectification of inaccurate or incomplete data (Art. 16)
- Erasure of data ("right to be forgotten"), in the cases provided for by law (Art. 17)
- Restriction of processing (Art. 18)
- Data portability, i.e., the right to receive data in a structured, machine-readable format and to transmit it to another controller (Art. 20)
- Objection to processing, in particular for direct marketing purposes or where processing is based on the Controller's legitimate interest (Art. 21)
- Withdrawal of consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal
To exercise these rights, data subjects may write to [email protected].
Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), based at Piazza Venezia 11, 00187 Rome, Italy, if they believe that the processing of their personal data is contrary to applicable law (www.garanteprivacy.it).
9. Cookies
The website uses technical cookies necessary for basic functionality (authentication, language selector, light/dark theme) and, where applicable, third-party cookies related to the services described in this Privacy Policy (e.g., Cloudflare Turnstile, Stripe). For detailed information on the cookies used, their purposes, and how to manage preferences, please refer to the Cookie Policy published on the website.
9-bis. Artist roster, bookings and reviews
If you are an artist on the roster
To publish your profile and let you be booked we process: stage name, biography, photographs and portfolio, trades, genres, instruments and equipment, city and travel distance, fees and links to your public profiles.
To pay you and to meet our legal obligations we also process legal name, tax code, VAT number, FPLS number (the Italian performing-arts pension fund), bank details (IBAN and account holder) or your Stripe account identifier, and the documents required for your trade: SIAE Deejay licence, identity document, insurance, DURC, drone licence, workplace safety certificate.
What is public and what is not. The showcase shows only stage name, photo, trades, city and distance, price range, answers to the trade questions and external links. Never public: tax code, VAT number, FPLS number, bank details and documents. Documents are kept on a disk that is not reachable from the web and are opened only through a protected route.
Legal basis. Performance of the contract (Art. 6(1)(b) GDPR) for the profile and bookings; legal obligation (Art. 6(1)(c)) for tax, social-security data and documents.
Retention. The profile stays as long as you keep it. Tax and social-security data and the related documents are kept for ten years from the last transaction, as required by law: this term prevails over a deletion request, and once it expires the data is deleted without you having to ask.
If you book an artist
We open an account for you, and we want you to know it. When you book, along with the booking we create an account for the email address you gave us. We do not ask you to register and we do not ask for a password: it lets you find your bookings, receipts and documents without writing to us, and leave a review with a name behind it. You sign in whenever you want with a code sent to that same address, and you can close it at any time from your profile.
Data. Name, email, phone; for invoicing: VAT number or tax code, SDI code and address. We also process the booking details (date, place, fee) and the payment status.
Legal basis. Performance of the contract (Art. 6(1)(b)): the account is the tool through which the service is delivered and documented. We do not ask for consent because it would be fictitious: you cannot book an event without the event being recorded.
Retention. The account stays until you close it; invoicing data is kept for ten years even after closure.
If you leave a review
What you write stays public. The review appears on the artist's profile, visible to anyone, with the score, the text and the signature you chose: full name, first name and initial, or anonymous. You choose before writing, not after reading it on the profile.
You can review only a booking that actually took place and was paid, once, within thirty days. There is no way to leave a review without having booked that artist.
If you change your mind. You can ask us to remove your name: signature and text disappear, the score remains and no longer identifies anyone. We do not delete the whole review because the score is by now part of the artist's professional record, and the artist has no part in your request.
The area price guide
From completed bookings we derive, without names, how much a given trade cost in a given province in a given season, and we publish it in aggregate form: no row allows anyone to be identified. Nothing is published until there are enough bookings for that combination, because with few cases an “average” would in fact be one person's fee. The basis is legitimate interest (Art. 6(1)(f)); you can object and your booking will be excluded.
10. Changes to this Privacy Policy
GiaNet Media reserves the right to modify or update this Privacy Policy, in whole or in part, including as a result of changes in applicable law. Any changes will be published on this page, indicating the date of the last update. Users are encouraged to periodically review this page.
Last updated: July 20, 2026
Affiliate programme
If you arrive at this site via an affiliate link — a link that a person or a business has shared to refer you to our services — and you consent to the "Marketing" category in the cookie banner, we record the visit so that we can credit a commission to whoever referred you.
In that case we process: the link code and the visit identifier, the referring site and programme, the page you arrive from and the one you land on, the time of the click and your IP address. We need the IP address to identify self-referrals and artificially generated clicks: without it, the programme could be manipulated to the detriment of honest affiliates.
The legal basis is your consent (Article 6(1)(a) of the GDPR and Article 122 of the Italian Privacy Code) for storing and reading the cookie, and our legitimate interest (Article 6(1)(f)) solely for anti-fraud checks on data already collected with consent. Without consent we record nothing, and the referral is not registered with us. We retain this data for 90 days; after that period, clicks that have not resulted in a purchase are automatically deleted.
If you register after arriving via an affiliate link, your sign-up is associated with that affiliate so that they can be remunerated. We do not show the affiliate any of your data: they see only counts. And you do not see them.
If you are the affiliate
If you take part in the programme, we process your personal and tax details (name, address, tax code or VAT number, country of residence), the data needed to pay you — the identifier of the connected Stripe account or the PayPal address you provide us — the statistics of your links and your commission history. The legal basis is performance of the contract and, for the tax and social-security aspects, a legal obligation. Accounting records are kept for ten years.
Before every payment we check your name against the European Union's restrictive-measures lists: this is an obligation that applies to anyone making funds available to a third party, not a discretionary choice of ours.
If you promote the programme of a third-party advertiser, the conversion data is processed by us and by the advertiser under joint controllership (Article 26 GDPR): the essential content of the arrangement is available to you, and you may exercise your rights against either party indifferently.
The details of the affiliate cookie, including its name and duration, are set out in this site's Cookie Policy.
Stripe and PayPal process data as independent controllers
We rely on Stripe and PayPal to collect payments and to pay out the amounts owed to affiliates. For the purposes they determine themselves — fraud prevention, anti-money-laundering obligations, payment system security — these providers do not act on our behalf: they are independent controllers and answer for their own choices. Their privacy notices are available at stripe.com/privacy and paypal.com.
We disclose to them only the data the operation requires: for a payment, the transaction and billing details; for a commission payout, the recipient's email address and the amount. Both may process data outside the European Economic Area, on the basis of the standard contractual clauses approved by the European Commission.
Creators' audience data
For creators we manage, we process the audience statistics made available by the platforms (follower counts, views, aggregate data on the audience's age, location and interests). These are aggregate data that do not identify the individual people who follow the creator; we process them to perform the contract (art. 6.1.b GDPR), keep them for the duration of the relationship and for twelve months thereafter, and do not disclose them to third parties except at the creator's instruction, for example in a proposal to a brand.