Data controller: Alessandro Tofani, Via Venezia 58, 56038 Ponsacco (PI), Italia.
VAT number IT02081540508 · info@rodion.it
Last updated: 10 September 2026
What I collect, and when
Two things only, and neither happens on its own.
- If you write to me through the contact form: the name you give, your email address and the text of your message. Along with those, the IP address the submission comes from and the browser type are recorded, because they are what protects the form from automated submissions.
- If you simply browse: the server logs the requests it receives, as any web server does, with IP address, date, requested page and browser. They keep the site running and make abuse visible.
There is no profiling, no behavioural advertising, and I neither sell nor share data with anyone.
Why I process them
- To answer your message: pre-contractual measures or responding to your request — Article 6(1)(b) GDPR.
- Security of the site and the form: legitimate interest in not having my inbox filled by robots — Article 6(1)(f) GDPR.
Where they end up
Messages sent through the form are stored in the site database, hosted on a server in the European Union, and at the same time forwarded by email to info@rodion.it. I am the one who reads them, nobody else lays eyes on them.
The form's anti spam check is Cloudflare Turnstile (Cloudflare, Inc.), which receives the IP address and some technical browser data at the moment of sending. The typefaces come from Google Fonts (Google Ireland Limited), which receives the IP address when the page loads. For transfers to the United States these providers state that they rely on the Data Privacy Framework and on standard contractual clauses.
For how long
Messages stay for as long as the conversation makes sense, and in any case no longer than 24 months from the last contact, unless they have become part of a working relationship with its own tax obligations. Server logs are rotated periodically.
Google data: Calendar and YouTube
Users of the Rodion dashboard may connect their Google account for two optional features, each enabled only at their request through Google's consent screen:
- Google Calendar (calendar.readonly and calendar.events scopes): Rodion reads the list of calendars and busy times to offer free slots on the booking page, and creates on the calendar the appointment a visitor books. It does not read the content of other events, nor modify or delete them.
- YouTube (youtube.readonly and youtube.upload scopes): Rodion reads the list of videos on the user's channel to import them as pages of their website, and uploads to their channel the videos the user selects and confirms, with the title and visibility they chose.
How this data is protected. Data travels only over encrypted connections (HTTPS/TLS). The access credentials issued by Google (tokens) are stored encrypted at rest in Rodion's database on a server in the European Union; the encryption key is kept outside the database and is not included in its backups. Tokens are used exclusively by the server for the operations described above: they are never sent to the browser, displayed in the interface, written to logs or shared with third parties. They are not used for advertising nor to train artificial-intelligence models. Server access is restricted to the data controller, with key-based authentication.
Retention. Tokens are kept only while the connection is active. Users can disconnect their Google account at any time from the dashboard (Settings → Booking, or Social → Accounts → Disconnect): the tokens are deleted immediately. The same happens when access is revoked from myaccount.google.com/permissions. Appointments already created remain on the user's calendar and videos already uploaded remain on their channel, because they belong to the user.
Google policies. Rodion's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Your rights
You can ask me to access your data, correct it, delete it, restrict its processing, object to processing, and receive a copy in a readable format. Write to info@rodion.it: I answer, within a month, usually much sooner.
If you think something is wrong, you can turn to the Italian data protection authority, the Garante per la protezione dei dati personali (garanteprivacy.it).
Cookies
What they are and what they do is in the Cookie Policy. In short: before consent, none.