Little Kids Studio
ARCHIVEABOUTSERVICESCONTACT
Little Kids Studio
ARCHIVEABOUTSERVICESCONTACT
ItalianoEnglish

Privacy Policy

Information on the processing of personal data provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and Italian Legislative Decree 196/2003 (“Privacy Code”).

Last updated: 27 August 2026

This is a courtesy translation. In the event of any discrepancy, the Italian version shall prevail.

1. Data controller

The data controller is Mattia Francesco Mancioppi, with registered address at Via Umberto Boccioni 15, 52100 Arezzo (AR), Italy, VAT no. 02527380519 (hereinafter the “Controller” or “Little Kids Studio”).

Contact for any matter concerning personal data: email fmancioppi@gmail.com.

The Controller has not appointed a Data Protection Officer (DPO), as the conditions set out in Article 37 GDPR do not apply.

2. Scope

This notice describes the processing of personal data of users who browse the website https://www.littlekidsstudio.com (the “Website”) and of those who use the contact form available on it. It does not extend to other websites that may be reached through links, for which the respective privacy notices apply.

3. Personal data processed

3.1 Browsing data

The computer systems and software procedures used to operate the Website acquire, during their normal operation, certain data whose transmission is implicit in the use of Internet communication protocols: IP address, date and time of the request, URL of the requested resources, numerical code indicating the status of the server response, size of the response, browser type and operating system (user agent) and referring page (referrer).

This data is processed by the hosting provider in order to deliver the pages and to ensure the security of the Website. It is not associated with identified users, but by its very nature it could, through processing and association with data held by third parties, allow users to be identified.

The images and videos on the Website are delivered through content delivery networks (CDN) operated by third-party providers (Sanity and Cloudinary, see section 6). Loading such content necessarily involves the transmission to the provider’s servers of the technical connection data (IP address, user agent) of the user’s device.

3.2 Data voluntarily provided by the user

Through the contact form on the “Contact” page the user may provide the following data: full name, email address, telephone number, company name (optional), type of service of interest and message (optional). The date and time of submission are also recorded.

The optional, explicit and voluntary sending of messages to the Controller’s contact addresses entails the acquisition of the sender’s address, which is necessary to reply, as well as any other personal data contained in the communication.

3.3 Cookies and tracking tools

The Website does not use profiling cookies, analytics tools, tracking pixels or fingerprinting techniques, whether first- or third-party. For full details please refer to the Cookie Policy.

4. Purposes and legal bases of processing

PurposeDataLegal basis
Enabling the technical operation of the Website, delivering its content and ensuring its security (prevention of unauthorised access, cyber-attacks and fraud)Browsing dataLegitimate interest of the Controller in the proper functioning and security of the Website (Art. 6(1)(f) GDPR)
Responding to requests for information, contact or quotations submitted through the contact form or by email, and managing the related communicationsData voluntarily providedSteps taken at the request of the data subject prior to entering into a contract (Art. 6(1)(b) GDPR)
Complying with obligations under laws, regulations or EU legislation, or with requests from the authoritiesAll dataCompliance with a legal obligation (Art. 6(1)(c) GDPR)
Establishing, exercising or defending legal claimsAll dataLegitimate interest of the Controller (Art. 6(1)(f) GDPR)

The Website does not send newsletters or marketing communications. Any promotional communications will be sent only with the data subject’s explicit consent (Art. 6(1)(a) GDPR), which may be freely withdrawn at any time.

5. Nature of the provision of data

The provision of browsing data is implicit in the use of the Website. The provision of the data marked as mandatory in the contact form is necessary in order to follow up the request: failure to provide it makes it impossible to reply. The provision of optional data is free and its absence does not affect the handling of the request.

6. Processing methods, recipients and processors

Data is processed using IT and telematic tools, with logic strictly related to the purposes indicated and through the adoption of appropriate security measures pursuant to Article 32 GDPR (including encryption of communications via HTTPS and access control to systems).

Data may be processed by persons authorised by the Controller pursuant to Article 29 GDPR and by third parties acting as data processors pursuant to Article 28 GDPR, in particular the providers of the technical services required to operate the Website:

ProviderServiceData processedLocation and safeguards
Vercel Inc.
Privacy policy
Hosting and infrastructure of the WebsiteBrowsing data, server logsUnited States: EU-U.S. Data Privacy Framework; Standard Contractual Clauses
Sanity AS
Privacy policy
Content management (CMS) and image deliveryTechnical connection dataNorway (European Economic Area)
Cloudinary Ltd.
Privacy policy
Image and video deliveryTechnical connection dataIsrael: European Commission adequacy decision (2011/61/EU); United States: EU-U.S. Data Privacy Framework
Resend (Plus Five Five, Inc.)
Privacy policy
Sending of the emails generated by the contact form (confirmation to the user and notification to the Controller)Data provided in the contact formUnited States: Standard Contractual Clauses
Google Ireland Limited (Gmail)
Privacy policy
Management of the Controller’s email correspondenceData contained in communicationsIreland (European Economic Area); any transfers to the United States covered by the EU-U.S. Data Privacy Framework and Standard Contractual Clauses

Data may also be disclosed to consultants and professionals (legal, tax) where necessary for the purposes indicated, and to the competent authorities in the cases provided for by law. Personal data is not disseminated.

7. Transfer of data to third countries

Some of the providers listed are located outside the European Economic Area. In such cases the transfer takes place on the basis of an adequacy decision of the European Commission pursuant to Article 45 GDPR (EU-U.S. Data Privacy Framework for certified U.S. providers; Decision 2011/61/EU for Israel) or, failing that, on the basis of the Standard Contractual Clauses approved by the European Commission (Art. 46(2)(c) GDPR; Implementing Decision (EU) 2021/914), supplemented where necessary by additional measures. A copy of the safeguards adopted may be requested from the Controller at the contact details provided.

8. Retention period

  • Browsing data: retained by the hosting provider for the time strictly necessary for technical and security purposes, normally for short periods (indicatively no longer than 30 days), except where required for the investigation of offences or for defence purposes.
  • Contact form data and correspondence: retained for 24 months from the last relevant contact. Where a contractual relationship follows the request, data is retained for the duration of the relationship and, after its termination, for the 10-year period required by Italian civil and tax obligations (Art. 2220 of the Italian Civil Code).

Once these periods have elapsed, data is deleted or anonymised, unless its further retention is necessary for the establishment, exercise or defence of legal claims.

9. Rights of the data subject

Within the limits and under the conditions set out in Articles 15–22 GDPR, the data subject has the right to:

  • obtain confirmation as to whether personal data concerning them is being processed, and access it (Art. 15);
  • obtain the rectification of inaccurate data or the completion of incomplete data (Art. 16);
  • obtain the erasure of data (“right to be forgotten”) (Art. 17);
  • obtain the restriction of processing (Art. 18);
  • receive the data in a structured, commonly used and machine-readable format and transmit it to another controller (portability) (Art. 20);
  • object at any time, on grounds relating to their particular situation, to processing based on legitimate interest (Art. 21);
  • withdraw any consent given, without affecting the lawfulness of processing based on consent before its withdrawal (Art. 7(3));
  • lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, Italy, www.garanteprivacy.it) pursuant to Article 77 GDPR, or bring proceedings before the competent courts (Art. 79).

Requests may be addressed to the Controller by writing to fmancioppi@gmail.com. The Controller will respond without undue delay and in any event within one month of receipt of the request, which may be extended by two months in the cases provided for in Article 12(3) GDPR.

10. Minors

The Website is not directed at children under 14 years of age and the Controller does not knowingly collect personal data from minors (Art. 8 GDPR; Art. 2-quinquies of the Italian Privacy Code). Should the Controller become aware of having received data from a minor without the consent of the holder of parental responsibility, it will promptly delete such data.

11. Automated decision-making

The Controller does not carry out automated decision-making, including profiling, within the meaning of Article 22 GDPR.

12. Changes to this notice

The Controller reserves the right to amend or update this notice, including as a result of changes in legislation or in the services used by the Website. The version in force is the one published on this page, with an indication of the date of the last update. Users are invited to consult it periodically.

Legal references

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR);
  • Italian Legislative Decree no. 196 of 30 June 2003 (Privacy Code), as amended by Legislative Decree no. 101 of 10 August 2018;
  • Guidelines of the Italian Data Protection Authority on cookies and other tracking tools of 10 June 2021;
  • Commission Implementing Decision (EU) 2021/914 (Standard Contractual Clauses);
  • Commission adequacy decision of 10 July 2023 (EU-U.S. Data Privacy Framework).
Little Kids Studio · Mattia Francesco Mancioppi · P.IVA 02527380519
LegalPrivacy PolicyCookie Policy