Privacy Policy

This page explains what personal data we collect through danphotostudio.com, why we collect it, how long we keep it and what you can do about it.

Taking bookings · Milan and on tour

This page explains what personal data we collect through danphotostudio.com, why we collect it, how long we keep it and what you can do about it. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

Last updated: 4 August 2026.

Who processes your data

The data controller is Daniele Dentamaro Fotografo, Italian VAT number 08846350968, registered at Via Conservatorio 30, 20122 Milan (MI), Italy — with a second location at Via Marco Pacuvio 47, 72100 Brindisi (BR), Italy.

For anything concerning your data, write to dan@danphotostudio.com or call +39 351 793 2905. No Data Protection Officer has been appointed, as the conditions requiring one do not apply.

When you write through the contact form

When you fill in the contact form we collect what you type — first name, last name, email address, phone number (optional) and the text of your message — together with a record of the consent you gave by ticking the box.

Alongside these, for security reasons and to understand how you found us, the system automatically records:

  • your IP address and the type of browser and device you are using;
  • the address of the page you sent the message from, and the path of pages you visited on our site beforehand (up to 30, with the time of each visit);
  • the referring website, if you arrived from an external link, and any advertising campaign parameters in the address, including Google, Meta and Microsoft click identifiers;
  • an approximate location — country, region, city and postcode — derived from your IP address using a database installed on our own server, without querying any external service.

Why we do this. What you type is used to reply to you and to discuss the work you are proposing: the legal basis is your consent (Art. 6(1)(a) GDPR), given by ticking the box and withdrawable at any time. The technical data collected automatically protects the site from automated submissions and helps us understand which content leads people to get in touch: the legal basis here is our legitimate interest (Art. 6(1)(f) GDPR) in defending the site and running it well.

Providing your data is optional, but without a name, an email address and a message we cannot reply. The phone number is genuinely optional — it is only there if you would rather be called back.

When you receive a selection gallery

If you are a client and we send you a private link to choose the shots from a shoot, we process your name and email address (entered by us, from what we already agreed with you), the photographs you select, any notes you write on individual shots, and the date and time of your visits to the gallery.

The gallery can only be reached through a secret address and is not indexable by search engines. For gallery visits we record neither your IP address nor your browser.

If you buy additional shots beyond those included in your package, payment happens on Stripe‘s pages, not ours. We pass Stripe your email address, the amount and a reference to the gallery. Your card details never pass through our site and we never store them: they stay with Stripe, which acts as an independent controller for its part. Of the payment we keep only the transaction identifier, the amount, the date and the number of shots purchased.

Why we do this. To perform our contract with you (Art. 6(1)(b) GDPR) and, for invoices and accounting records, to comply with a legal obligation (Art. 6(1)(c) GDPR).

How long we keep your data

  • Contact form enquiries: 24 months from our last exchange with you, then deleted. If you become a client in the meantime, the next point applies.
  • Client, gallery and selection data: for the duration of our working relationship and, afterwards, for the 10 years Italian law requires for accounting and tax records.
  • Messages flagged as spam: kept so we can improve our filters, and deleted within 24 months in any case.
  • Cookies and similar technologies: for the periods listed in the section below.

Who else sees your data

We do not sell your data and we do not pass it to third parties for their own marketing. It is accessible to the suppliers who provide the technical services the site needs, acting either as processors on our behalf or as independent controllers:

  • VHosting Solution S.r.l. — hosting for the website and email. Servers are located in Italy.
  • Google Ireland Ltd. — visitor statistics through Google Tag Manager and Google Analytics 4; playback of the videos embedded in our articles through YouTube; the studio map, embedded from Google Maps. Tag Manager also fires a Google Ads tag, which links visits to advertising campaigns. All of these start only after you have given consent.
  • Stripe Payments Europe Ltd. — payment handling for additional shots.
  • jsDelivr — the content delivery network the site loads some interface components from; doing so discloses your IP address to that provider.
  • Advisers, our accountant and other professionals assisting us, strictly as far as necessary.

Data may also be disclosed to judicial or law enforcement authorities where we are legally required to do so.

Transfers outside the European Union

Google and Stripe belong to groups with companies in the United States, so some data may be processed outside the European Economic Area. These transfers rely on the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework and, in addition, on the Standard Contractual Clauses adopted by the Commission. You may ask us for a copy of the safeguards in place at the address above.

Cookies and tracking technologies

A cookie is a small file a website saves on your device. Some are needed to make pages work, others help us understand how the site is used. Our site also uses the browser’s local storage, which works in a similar way.

Strictly necessary

These do not require your consent, because the site cannot work without them.

  • PHPSESSID — keeps your session active while you browse. Deleted when you close your browser.
  • pll_language — remembers which language you are reading in. It is the only cookie this site sets before any choice of yours. Duration: 365 days.
  • The cmplz_ family — nine cookies (including cmplz_banner-status, cmplz_statistics, cmplz_marketing and cmplz_saved_categories) recording the choice you made on the banner and which categories you accepted. They keep us from asking again on every page, and let us demonstrate what you had agreed to. Duration: 365 days.
  • WordPress technical cookies, set only if you log in as a registered user.

Visit path measurement

These reconstruct which pages you looked at before writing to us, so we can tell which content is actually useful. They are set on our own domain and the data is not shared with third parties.

  • dric_visite (local storage) — a list of the last pages you visited, up to 30. It is only read if you submit the contact form, and stays on your device until you clear your browser data.

Third-party technologies

They stay switched off until you accept them. Before your choice the site does not load them at all: in place of a video or the map you see a panel explaining what is missing and asking whether you want to turn it on. Once you accept, your IP address is disclosed to the provider.

  • Google Tag Manager and Google Analytics 4 — measure, in aggregate form, how many people visit the site and how they move between pages. Cookies _ga and _ga_<ID>, lasting 400 days.
  • Google Ads — Tag Manager also fires an advertising tag, linking a visit to the campaign you arrived from. Cookie _gcl_au, lasting 90 days. We do not run advertising personalised on your behaviour.
  • YouTube — plays the videos embedded in our articles. When a video starts, Google sets the cookies VISITOR_INFO1_LIVE, VISITOR_PRIVACY_METADATA, __Secure-YNID and __Secure-ROLLOUT_TOKEN (180 days) and YSC (until you close the browser).
  • Google Maps — shows the map with the studio address. Loading it discloses your IP address to Google.

All four belong to Google Ireland Ltd. Its privacy notice is at policies.google.com/privacy.

You can change your mind at any time, using the Change preferences control that stays available at the foot of every page, or through your browser settings, where you can block cookies or delete ones already stored. Instructions are available for Chrome, Firefox, Safari and Edge. If you block strictly necessary cookies, parts of the site may stop working properly.

Your rights

At any time you can ask us to:

  • tell you what data we hold about you and give you a copy of it (Art. 15);
  • correct it, if it is wrong or incomplete (Art. 16);
  • erase it (Art. 17) or restrict its use (Art. 18);
  • receive it in a machine-readable format or have it transferred to another controller (Art. 20);
  • object to processing based on our legitimate interest (Art. 21);
  • withdraw the consent you gave us, without affecting the lawfulness of processing carried out before withdrawal.

Just write to dan@danphotostudio.com. We reply within one month; if your request is complex it may take longer, but we will tell you straight away. We do not make automated decisions and we do not carry out profiling that produces legal effects on people.

If you believe your data is being handled unlawfully, you can lodge a complaint with the Italian supervisory authority — Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, garanteprivacy.it — or with the supervisory authority of the EU country where you live or work.

Changes to this notice

If the way we handle data changes, we will update this page and change the date at the top. Please do look back at it from time to time.