Last updated: 3 September 2026. Version 1.0.
This Privacy Policy explains what personal data Artevivo Magazine collects when you use artevivomagazine.com, why we collect it, how long we keep it, who else sees it, and what you can require us to do about it. It is written to satisfy Articles 13 and 14 of Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”) and Italian Legislative Decree No. 196/2003 as amended by Legislative Decree No. 101/2018 (the Italian Privacy Code).
We have tried to write it in language a reader can actually follow. Where a legal term is unavoidable, it is explained.
1. Who is responsible for your data
The data controller (titolare del trattamento) is:
Artevivo Edizioni S.r.l.
Via Giuseppe Ripamonti 44, 20141 Milano (MI), Italy
Partita IVA IT12874650961
Email: [email protected]
PEC: [email protected]
Telephone: +39 02 8734 6120
Because of the scale and nature of our processing, we are not required to appoint a Data Protection Officer under Article 37 GDPR and have not appointed one. Data protection matters are handled by the address above, and a named contact will respond to you.
2. The data we collect
2.1 Data you give us deliberately
- Email correspondence. When you write to any of our published addresses we receive your email address, your name if you give it, and whatever you put in the message and its attachments.
- Comments. If commenting is enabled on an article and you leave a comment, we receive the display name you choose, your email address, your comment text, your IP address and your browser user-agent string. WordPress stores this, and an anonymised string created from your email address (a hash) may be sent to the Gravatar service to see whether you have a public avatar.
- Newsletter subscription. If we operate a newsletter and you subscribe, we receive your email address and the date, time and IP address of your consent, which we are required to retain as proof that consent was given.
- Pitches and contributions. If you pitch or write for us, we receive your name, contact details, biography, published samples and, if we commission you, the payment and tax details necessary to pay you and to comply with Italian tax law.
- Commercial enquiries. Company name, contact person, contact details and the content of the enquiry.
2.2 Data collected automatically
- Server logs. Our hosting provider records, for every request, the IP address, the date and time, the page or file requested, the HTTP status code, the number of bytes served, the referring URL where present, and the user-agent string. This is standard web-server behaviour and cannot be switched off without switching off the site.
- Cookies and similar technologies. Described in detail in our Cookie Policy, which forms part of this notice.
- Technical characteristics of your device reported by your browser: screen size, language preference, operating system and, where analytics are running, approximate location derived from a truncated IP address at city or regional level. We do not collect precise geolocation and never ask your browser for it.
2.3 Data we do not collect
We do not knowingly collect special category data under Article 9 GDPR — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation. Please do not send us such data. We do not collect payment card details on this site; any payment to us happens through a bank transfer or a third-party processor with its own privacy notice.
3. Why we process it, and on what legal basis
Article 6 GDPR requires a lawful basis for every processing operation. Ours are as follows.
- To deliver the website to your browser and keep it available and secure — legitimate interests, Article 6(1)(f). Our interest is in operating a publication and defending it against attack; this is a routine expectation of anyone visiting a website, and the data involved is minimal.
- To answer your correspondence — legitimate interests, Article 6(1)(f), or the steps taken at your request prior to entering a contract, Article 6(1)(b), where you are pitching or contracting with us.
- To publish and moderate comments — consent, Article 6(1)(a), given when you submit the comment, together with our legitimate interest in preventing abuse and spam.
- To send a newsletter — consent, Article 6(1)(a), withdrawable at any time by the unsubscribe link in every message.
- To run analytics — consent, Article 6(1)(a), obtained through the cookie banner before any non-essential script is loaded.
- To display advertising, where it is served by a third party — consent, Article 6(1)(a).
- To pay contributors and keep accounting records — performance of a contract, Article 6(1)(b), and compliance with a legal obligation, Article 6(1)(c), in particular Italian civil and tax law.
- To respond to copyright notices and legal claims and to establish, exercise or defend legal claims — legal obligation, Article 6(1)(c), and legitimate interests, Article 6(1)(f).
Where we rely on legitimate interests, we have carried out a balancing assessment weighing our interest against your rights and freedoms, and you may ask us to explain the outcome of that assessment for any specific processing operation.
4. Journalistic processing
Artevivo Magazine is a publication. Article 85 GDPR and Article 136 of the Italian Privacy Code, together with the rules of professional conduct on processing for journalistic purposes annexed to the Code, permit derogations from certain data protection obligations where personal data is processed for journalistic expression.
In practice this means that where we write about a named person in an article — an artist, a curator, a museum director, a public official — we process that person’s data on the basis of the public interest in the subject matter, and certain rights (notably the right to erasure and the right of access to journalistic sources) may be limited so far as necessary to protect the freedom of expression and information. We apply the essentiality test: we publish personal information about identifiable people only where it is essential to the story, and we do not publish private facts that have no bearing on the public matter being reported.
This derogation applies only to our editorial content. It does not affect your rights in respect of the data we hold about you as a reader, subscriber, correspondent or contributor.
5. Who else sees your data
We do not sell personal data, and we do not disclose it for anyone else’s independent marketing purposes. Data is shared only with the following categories of recipient:
- Our hosting provider, which necessarily processes all traffic to the site, acting as a data processor under Article 28 GDPR.
- Our email provider, which transmits and stores our correspondence.
- Our newsletter platform, if and when a newsletter is operated.
- Analytics providers, where you have consented.
- Anti-spam services used to filter comments, which necessarily receive the comment, the commenter’s email address and IP address in order to assess whether it is spam.
- Our accountant and, where required, the Italian tax authorities, in respect of contributor and supplier payments.
- Professional advisers, insurers and, where legally compelled, courts, police and public authorities.
Every processor acting on our behalf is bound by a written agreement meeting the requirements of Article 28(3) GDPR, which obliges them to process data only on our documented instructions, to keep it confidential and to apply appropriate security measures.
6. Transfers outside the European Economic Area
Some of the services above are operated by companies established outside the EEA, principally in the United States. Where personal data is transferred outside the EEA, we rely on one of the following safeguards under Chapter V GDPR:
- an adequacy decision of the European Commission covering the recipient country or framework, including the EU–US Data Privacy Framework where the recipient is certified under it; or
- the European Commission’s Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914, supplemented where necessary by additional technical and organisational measures identified through a transfer impact assessment.
You may request a copy of the safeguards applying to a specific transfer by writing to [email protected].
7. How long we keep it
| Server access logs | Up to 12 months, then deleted or aggregated beyond identification. |
| General correspondence | 24 months from the last message in the thread, unless it relates to a matter that must be kept longer. |
| Published comments | For as long as the article remains published, unless you ask for removal. |
| Newsletter subscription data | Until you unsubscribe, plus 12 months to evidence that consent existed and was withdrawn. |
| Rejected pitches | 12 months. |
| Contributor contracts and payment records | 10 years, as required by Article 2220 of the Italian Civil Code and applicable tax rules. |
| Copyright notices and counter-notices | 5 years from resolution. |
| Analytics data | Up to 14 months in identifiable or pseudonymous form. |
Where a legal claim is threatened or pending, the relevant records are retained until it is finally resolved and any appeal period has expired.
8. Your rights
Under Articles 15 to 22 GDPR you have the following rights, exercisable free of charge:
- Access (Art. 15) — to be told whether we hold data about you and, if so, to receive a copy of it and the information in this notice.
- Rectification (Art. 16) — to have inaccurate data corrected and incomplete data completed.
- Erasure (Art. 17) — to have data deleted where it is no longer necessary, where consent is withdrawn and there is no other basis, where you successfully object, or where it has been unlawfully processed. This right does not extend to editorial content protected by the journalistic derogation described in section 4, nor to records we must keep by law.
- Restriction (Art. 18) — to have processing suspended while a dispute about accuracy or lawfulness is resolved.
- Portability (Art. 20) — to receive data you provided to us, where processing rests on consent or contract and is automated, in a structured, commonly used, machine-readable format, and to have it sent directly to another controller where technically feasible.
- Objection (Art. 21) — to object at any time, on grounds relating to your particular situation, to processing based on legitimate interests. Where you object to direct marketing, we must stop immediately and without assessment.
- Withdrawal of consent (Art. 7(3)) — at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Not to be subject to automated decision-making (Art. 22). We do not carry out automated decision-making producing legal or similarly significant effects, and we do not profile readers.
To exercise any of these rights, write to [email protected]. We will respond within one month, extendable by two further months where the request is complex, in which case we will tell you within the first month and explain why. We may ask you for information sufficient to establish that you are who you say you are, but no more than is necessary for that purpose.
9. Complaints
If you are not satisfied with our response, you may lodge a complaint with the Italian supervisory authority:
Garante per la protezione dei dati personali
Piazza Venezia 11, 00187 Roma, Italy
Telephone: +39 06 69677 1
Email: [email protected] — PEC: [email protected]
Website: www.garanteprivacy.it
You may also complain to the supervisory authority of the EU member state where you live or work, or where you believe an infringement occurred, and you have the right to an effective judicial remedy under Article 79 GDPR.
10. Security
We apply technical and organisational measures appropriate to the risk, as required by Article 32 GDPR. These include encryption of traffic in transit using TLS, access control on the content management system with strong authentication, regular software updates, restriction of administrative access to those who need it, and backups held separately from the live environment.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Garante within 72 hours of becoming aware of it as required by Article 33, and we will notify you directly without undue delay where the breach is likely to result in a high risk to you, as required by Article 34.
11. Children
This site is intended for a general adult audience and is not directed at children. Consistent with Article 8 GDPR as implemented in Italy, we do not knowingly collect personal data from children under 14 without the consent of a person holding parental responsibility. If you believe a child has provided us with personal data, write to [email protected] and we will delete it.
12. External links and embedded content
Our articles link to museum, university, foundation and archive websites. Those sites have their own privacy practices, over which we have no control and for which we accept no responsibility.
Articles may also contain embedded content, such as a video or a map. Embedded content from another website behaves exactly as if you had visited that website: it can collect data about you, use cookies, embed additional third-party tracking and monitor your interaction with the embed. Where such an embed is not strictly necessary, it is blocked until you consent through the cookie banner.
13. Changes to this policy
We may amend this policy to reflect changes in law, in the services we use, or in what the site does. The version number and date at the top of this page change with every amendment. Where a change materially affects your rights, we will give notice on the site and, if we hold your email address for that purpose, by email. Continued use of the site after a change takes effect indicates that you have had the opportunity to read it; it does not substitute for consent where consent is the legal basis relied upon.
