This Privacy Policy explains how Interni Oltrarno ("we", "us") collects, uses, stores, and protects personal data when you visit our website or contact us about interior design services for Florence apartments and townhouses.
Data Controller
The data controller is Interni Oltrarno, Via de' Guicciardini 18, 50125 Firenze (FI), Italy.
Email: [email protected]
Phone: +39 055 238 7712
Personal Data We Collect
We may collect the following categories of personal data:
- Identity and contact data: name, email address, phone number, postal address, billing address
- Project and property data: apartment location, floor plans, photographs of interiors, wall condition notes, descriptions of existing finishes, antique furniture dimensions, service preferences (full apartment concepts, kitchen living spines, bedroom suites, room refresh, design advisory)
- Communication data: messages sent via contact forms, email, phone, or in-person consultations at our studio or on site
- Contract and payment data: proposal references, invoice details, payment transaction references processed by our payment provider (we do not store full card numbers)
- Technical data: IP address, browser type and version, device information, operating system, pages visited, time spent on pages, referral source (via cookies where enabled)
- Marketing preferences: opt-in status for studio newsletters, project updates, or appointment reminders
- Site visit data: dates and times of on-site reviews at client properties when recorded in our project management system
Purposes and Legal Basis (GDPR)
We process personal data under Regulation (EU) 2016/679 (GDPR) and the Italian Personal Data Protection Code (Codice in materia di protezione dei dati personali, D.Lgs. 196/2003 as amended by D.Lgs. 101/2018) on the following bases:
- Contract / pre-contract steps (Art. 6(1)(b)): responding to enquiries, preparing proposals and fee estimates, performing interior design services including full apartment concepts, kitchen living spines, bedroom suites, room refreshes and design advisory sessions, managing project timelines and contractor coordination
- Legitimate interests (Art. 6(1)(f)): responding to general enquiries, improving our services and website, maintaining studio records, preventing fraud and securing our systems—balanced against your rights and freedoms
- Legal obligation (Art. 6(1)(c)): accounting, invoicing, tax compliance, and regulatory requirements under Italian law including obligations under the Codice Civile and fiscal regulations
- Consent (Art. 6(1)(a)): non-essential cookies, optional marketing communications, and photography consent for portfolio use of completed projects
Cookies and Similar Technologies
Our website uses necessary cookies for basic operation and security. Analytics or preference cookies, if introduced, run only with your consent where required under the ePrivacy Directive and Italian implementation. See our Cookies page for categories, retention periods, and how to withdraw consent.
Data Retention
We retain personal data only for as long as necessary for the purposes described:
- Enquiry and quote data: up to 24 months after the last meaningful contact unless an active client relationship continues
- Project files including floor plans, finish schedules, and site visit notes: for the duration of the project plus 36 months after completion to support warranty queries and follow-up work
- Invoices and related correspondence: for the period required by Italian commercial and tax law (typically 10 years under Art. 2220 Codice Civile and D.P.R. 600/1973)
- Marketing consent records: until you withdraw consent plus a short audit period of 12 months
- Technical and security logs: up to 12 months for security and troubleshooting purposes
- Portfolio photography consent records: for as long as images remain published plus 24 months after withdrawal of consent
Who We Share Data With
We share personal data only as needed with:
- Hosting, email, and form processing providers acting as processors under Article 28 GDPR data processing agreements
- Payment service providers for bank transfers and card transactions
- Contractors, artisans, and suppliers where project coordination requires sharing site access details or specification documents (limited to necessary project information only)
- Professional advisors including accountants and legal counsel where necessary
- Public authorities including the Agenzia delle Entrate when legally obliged
We do not sell personal data. We do not use automated decision-making that produces legal or similarly significant effects.
International Transfers
Where tools or hosts process data outside the European Economic Area, we implement appropriate safeguards such as Standard Contractual Clauses approved by the European Commission (Decision 2021/914), supplementary measures where required following Schrems II guidance, or rely on an adequacy decision. You may request details of transfers relevant to your data by contacting us at the address above.
Security
We apply technical and organisational measures proportionate to the risk, including access controls on studio systems, encrypted transmission (TLS/HTTPS) where available, staff confidentiality obligations, and limited access to client project files. No method of transmission over the internet is completely secure; please avoid sending unnecessary sensitive data by unencrypted email.
Your Rights Under the GDPR
Depending on circumstances, you may have the right to:
- Access your personal data and obtain a copy (Art. 15)
- Rectify inaccurate or incomplete data (Art. 16)
- Erase data in certain cases, such as where it is no longer necessary (Art. 17 — "right to be forgotten")
- Restrict processing in defined situations (Art. 18)
- Data portability for data you provided, where processing is automated and based on contract or consent (Art. 20)
- Object to processing based on legitimate interests or for direct marketing (Art. 21)
- Withdraw consent at any time without affecting prior lawful processing (Art. 7(3))
- Not be subject to solely automated decisions with significant effects, where applicable (Art. 22)
To exercise these rights, contact [email protected]. We respond within one month, extendable by two further months where requests are complex or numerous. We may need to verify your identity before processing your request.
Data Protection Officer
We are not required to appoint a Data Protection Officer under Art. 37 GDPR given the nature and scale of our processing activities. Privacy enquiries are handled by studio management at the contact details above.
Children
Our services are directed at adults. We do not knowingly collect data from children under 16 without verifiable parental consent. Contact us if you believe we have received such data and we will delete it promptly.
Complaints
If you believe your data protection rights have been infringed, you may lodge a complaint with the Garante per la protezione dei dati personali (Italian Data Protection Authority) at garanteprivacy.it or the supervisory authority in your EU country of residence. We encourage you to contact us first so we can address your concern directly.
Changes to This Policy
We may update this Privacy Policy to reflect legal, technical, or operational changes. The "Last updated" date at the top will change accordingly. Material changes may be communicated via email to active clients or a notice on this page.
Questions: [email protected]