Privacy Policy

Last updated: August 14, 2026

This page tells you what happens to your personal data when you leave us an address for the newsletter, or when you write to us. It is a legal document, but we would like it to be genuinely readable: if anything here is unclear, ask us and we will explain it.

Who handles your data

The data controller is Santa Bona Srl, with its registered office at Via Piave 30, 31020 Vidor (TV), Italy — VAT number IT05581590261. It is the company that runs the Abbazia di Santa Bona; on this page we simply call it the Abbazia.

On any matter concerning your data you can write to us at abbazia@abbaziadisantabona.com or telephone +39 393 3654898. We have not appointed a data protection officer: the Abbazia answers you directly, at the same contact details.

When we collect your data

We ask for data that identifies you on two occasions only, both of them of your own choosing: when you subscribe to the newsletter and when you send us an email. There is no account to create, there is nothing to buy, and we do not profile you.

Reading these pages, by contrast, does not require you to tell us who you are. The server that hosts us does keep a technical access log — IP address, date and time, page requested, browser type — because without that log there is no way to keep the service running, nor to notice an attack. We are the controller of it, and it rests on our legitimate interest in keeping the site secure and reachable (art. 6(1)(f) of the GDPR). We do not consult them to identify our readers, and we do not cross-reference them with anything else described on this page.

Those records are created by the server that hosts the site: without them the site could not run at all. Nobody reads them routinely. The server rotates them on its own: at regular intervals it closes the current file, stores a compressed copy of it and deletes the original. The pace of that rotation is set by the provider hosting the site, which holds the records on our behalf as our data processor; the archived copy, however, sits in our own space, and for that one we decide how long it lasts, keeping it to the minimum needed to notice a fault or an abuse. We do not move them anywhere else, we do not cross-reference them with other data, and we do not use them for anything else. If you would like to know how many days that currently amounts to, write to us and we will tell you.

Subscribing to the newsletter

The form at the foot of the page asks you for one thing only: your email address. No name, no telephone number, no other field. Beside it you will find a box to tick, by which you give your consent, and a link to this page, so that you can read it before you decide.

The newsletter tells the story of the Abbazia: the days on which we open our doors, the restoration work, the seasons of the garden and, now and then, the possibility of celebrating a wedding or an event here — so they are also messages in which we offer you our spaces. We write seldom, a few times a year, and always from this address. The consent we ask of you covers exactly this: to send you anything else, we would come back and ask you again.

Along with the address, the site notes down a few technical details of the submission: the date and time, your IP address, an indication of the browser and device you are using, the page from which you sent the form, the language you were reading it in, and the exact wording of the box you ticked. The language is what lets us write to you in the same one you read us in. They are not there to know you better: they are there to show, should you or the authority ever ask, that consent was given, when it was given, and in what words it was framed.

Before you receive anything at all, you have to confirm. A message reaches you with a link to open: only after that step are you subscribed. If you do not open it, we will never write to you. This is what is known as double opt-in, and it serves us both: you, because no one can subscribe in your place; us, because a clear record remains of what you wanted.

The form defends itself against automated submissions, with an invisible decoy field and a check on how quickly it is filled in. These are checks internal to the site: no outside service is consulted, and there is no image puzzle to get past. Anything written in the decoy field is discarded and never enters our records. If a submission fails those checks, the site holds a counter of the attempts for one day, tied to a code derived from your IP address: it does not contain the address in the clear, it is not kept alongside your name or your email, and it serves only to stop someone who keeps trying. If the submission goes through, none of it is kept at all.

If one of these checks were to mistake a genuine submission for an automated one, your message would not be lost: it would be set aside, marked as suspect, and we would read it ourselves. It follows the same retention rules as the other subscriptions and is deleted along with them. The form, moreover, installs no cookies and does not ask your browser to contact any third-party site.

If you write to us

When you write to the address published on the site, or fill in the booking form, your contact details reach us together with everything you have chosen to tell us: the wedding date you have in mind, the number of guests, whatever you need to know. We use that information to reply to you and to prepare for our meeting, and for nothing more. An address that reaches us by email never ends up in the newsletter: the only way to subscribe to that is through the form.

Why we process this data, and on what grounds

Every processing operation needs a reason recognised by law. These are ours.

Why What data Legal basis For how long
Sending you the Abbazia’s newsletter: news, open days, restoration work and proposals for weddings and events Email address Your consent, art. 6(1)(a) of the GDPR For as long as you remain subscribed
Being able to show that consent was given, when, and in what words Address, date and time, IP address, browser and device, page of origin, page language, wording of the box ticked A legal obligation: the GDPR requires us to be able to do so — art. 6(1)(c), read together with art. 7(1) Twenty-four months from the submission
Preventing a removed address from being subscribed again by mistake Email address, held by Mailchimp on a separate list Our legitimate interest in honouring your withdrawal, art. 6(1)(f) For as long as our Mailchimp account remains active, unless you ask for complete deletion
Replying to those who write to us and preparing for a possible event Email address and content of the message Steps taken at your request before entering into an agreement, art. 6(1)(b); for correspondence that does not concern an event, our legitimate interest in answering those who approach us, art. 6(1)(f) Twenty-four months, unless the enquiry leads to an event
Keeping automated submissions out of the form Content of the decoy field; after a suspicious submission, a counter of attempts tied to a code derived from the IP address alone Our legitimate interest in protecting the site, art. 6(1)(f) The decoy field is not kept; the counter of attempts, one day
Running the site and defending it against attacks Technical access log: IP address, date and time, page requested, browser type Our legitimate interest in keeping the site secure and reachable, art. 6(1)(f) The server rotates the records at regular intervals and archives a compressed copy in our own space: for that copy we set how long it lasts, at the minimum useful. We keep none elsewhere.

How consent is given, and how it is taken back

Consent to the newsletter is given by ticking the box in the form and confirming from the message that reaches you. It is freely given and conditions nothing: you can write to us, visit the Abbazia and be married here without ever having subscribed.

Taking it back is just as simple, and costs you a single click. At the foot of every message we send you there is a link to unsubscribe. Alternatively, write to us at abbazia@abbaziadisantabona.com: you need only ask, without explaining why. We will stop at once.

Withdrawal takes effect from that moment onwards. It does not make unlawful what we did before, while consent was there: the messages already sent remain lawful.

Who we pass your data to

The newsletter is prepared and sent with Intuit Mailchimp. The contract governing the processing is signed with The Rocket Science Group LLC d/b/a Mailchimp, of Atlanta, Georgia, United States: it is therefore a processor within the meaning of art. 28 of the GDPR, which holds the addresses of subscribers and sends the messages on our behalf, bound by a contract that requires it to process the data only on our instructions. Its privacy notice can be read at intuit.com/privacy/statement.

The exchange with Mailchimp takes place between our server and theirs. Your browser never contacts mailchimp.com while you are on these pages: this is why the form sets no cookies and calls for no consent to tracking. Our cookie policy says as much, in a section of its own.

Besides Mailchimp, your data may be accessed — for no longer than maintenance requires — by the provider that hosts the site, whose servers on the plan we have chosen are in Brussels, Belgium, and therefore within the European Union, and by those who look after its technical upkeep: they too are processors, and bound to confidentiality.

Like any provider of this kind, the company hosting the site may in turn rely on its own technical suppliers, bound by the same contract and the same obligations. If you would like to know who they are, just ask us: we will find out and tell you. Beyond that chain, the address you leave with us goes to no one: we do not disclose it for advertising, we do not pass it on and we do not sell it.

Cookies are a separate matter: if — and only if — you consent to the “Statistics” or “Marketing” categories, the services listed in the cookie policy receive data about your browsing. Those are processing operations described there; they concern the pages you read and not your newsletter subscription, and they stay switched off until you authorise them yourself. We would hand your data to the authorities only if a law obliged us to.

The transfer to the United States

This is the point on which we want to be precise, because it is the most delicate one in this notice.

Entrusting the newsletter to Mailchimp means that your address leaves the European Union and is stored on servers in the United States. The United States is a third country: its laws do not in themselves guarantee the same protection you have within the Union, and that is a circumstance you should know about before you subscribe.

The transfer rests on two bases. The first is the adequacy decision adopted by the European Commission on 10 July 2023, which recognises equivalent protection for United States companies certified under the Data Privacy Framework. Our provider is not certified in its own name: it is covered by the certification of its parent company, Intuit Inc., in the list kept by the United States Department of Commerce, where it is named among the entities that certification covers. The contract commits Mailchimp to relying on the Framework precisely for the data it processes on our behalf. The second is the standard contractual clauses approved by the Commission, which Mailchimp includes in its own contract and which would go on applying even if that decision were one day annulled, as has already happened to the two arrangements that preceded it. They are the clauses of European Commission Implementing Decision (EU) 2021/914, and they form part of the data processing agreement signed with Mailchimp: if you would like to read them, you will find the full text at mailchimp.com/legal/data-processing-addendum; if you would rather have a copy from us, simply ask at abbazia@abbaziadisantabona.com and we will send you one.

Risks remain that no contract removes entirely, first among them the possibility that United States authorities may gain access to the data on national security grounds, with remedies for European citizens different from those you would have in Italy. The data at stake here amounts to little — an email address and the proof of your consent — but it is right that you should know this too. If you would rather run no risk at all, do not subscribe to the newsletter: we will still be glad to answer you by email.

How long we keep your data

The newsletter. Your address stays with Mailchimp for as long as you are subscribed. When you unsubscribe we take you off the mailings and Mailchimp keeps you on a list of its own. If someone were one day to type your address into the form again, that alone would not put you back among the subscribers: the confirmation message would reach you once more, and without your reply you would receive nothing. That list remains for the whole time our Mailchimp account is active, is not used to write to you and is not used for anything else; it rests on our legitimate interest in honouring your withdrawal (art. 6(1)(f) of the GDPR). If you would rather no trace of it remained, write to us: we will delete the contact, bearing in mind that from that moment an address typed into the form by mistake could put you back on the list.

The subscriptions recorded by the site. The record the site keeps as proof of consent is deleted automatically after twenty-four months. If you are still subscribed on that day, the proof is not lost: for the whole duration of the subscription Mailchimp keeps the date, the time and the IP address of your confirmation, together with the wording in which your consent was asked for. This is an obligation of ours and not a burden on you: we must be able to demonstrate your consent for the whole time we rely on it.

We make periodic backups of the site, which are snapshots of the entire archive: a deleted record may survive for some time longer inside a backup, until the backup itself is replaced. The backups stay on the server that hosts the site and serve only to put it back on its feet if something goes wrong.

Correspondence. We keep messages for as long as it takes to reply to you and to follow your enquiry through. If your enquiry comes to nothing, we delete them within twenty-four months. If, on the other hand, an event grows out of your message, the paperwork stays for as long as civil and tax law requires.

No profiling, no automated decisions

We do not build profiles. The address you leave with us is not cross-referenced with other sources, and no decision concerning you is taken by a program. Mailchimp could tell us who opens our messages and which links they touch: we have switched those measurements off, so our letters go out without opening pixels and without tracked links. Who reads us, and how, we do not know.

The only tools that watch your browsing are the statistics and marketing cookies described in the cookie policy, which do not start without your consent.

Your rights

Articles 15 to 22 of the GDPR give you a series of rights that you may exercise at any time, free of charge.

Right What you can ask for
Access (art. 15) To know whether we process data concerning you, and to receive a copy of that data
Rectification (art. 16) To correct a wrong address or an incomplete detail
Erasure (art. 17) To ask for your data to be deleted: always, when you withdraw a consent; and in the other cases the article provides for, for example when we no longer need it for the purpose you gave it to us for
Restriction (art. 18) To freeze the processing while we look into an objection of yours
Portability (art. 20) To receive your data in a format another service can read, or to ask us to send it directly to whomever you name, where that is technically possible
Objection (art. 21) To object to those forms of processing that rest on our legitimate interest
Automated decisions (art. 22) Not to be subject to a decision taken solely by a program. We take none here, as we wrote above
Withdrawal of consent (art. 7(3)) To withdraw your consent to the newsletter, as easily as you gave it

To exercise them, a message to abbazia@abbaziadisantabona.com is all it takes. There are no forms to fill in and nothing to pay. We reply within one month; if the request is a complex one that period may be extended by two months, but in that case we will tell you within the first month and explain the reason. Should we have a reasonable doubt about who is writing to us, we may ask you for something more — for instance, to write to us again from the address you left with us. We will do so only where it is genuinely needed, and we will never ask you for documents that have nothing to do with it.

If you wish to turn to the supervisory authority

If you believe your data has been handled improperly, you may lodge a complaint with the Garante per la protezione dei dati personali, the Italian data protection authority, Piazza Venezia 11, 00187 Rome, Italy — garante@gpdp.it, certified email protocollo@pec.gpdp.it, switchboard +39 06 696771, garanteprivacy.it. You may equally take the matter to the ordinary courts. If you live or work in another country of the Union, or if you believe the infringement took place there, you may turn to the supervisory authority of that country: art. 77 of the GDPR leaves the choice to you.

We would be glad, though, if you gave us the chance to put things right first: write to us, and we will try to set matters straight.

Cookies

Cookies and similar technologies have a document all of their own, because the subject is a different one and so are the rules. You will find every detail in the cookie policy, and you can review your choices at any time from the Cookie preferences link at the foot of every page.

Updates

If we change the way we handle your data, we will update this page and the date at the top. When the change matters to those subscribed to the newsletter, we will tell you in a message, rather than leaving you to notice on your own.