Notice

Privacy Policy

This page explains what personal data this website collects, why, for how long, and what you can ask for at any time. It is provided under Article 13 of EU Regulation 2016/679 (GDPR).

Last updated: 24 September 2026

This is an English translation, provided for your convenience. The Italian version is the legally binding one and prevails in case of any discrepancy.

1. Who handles the data

The data controller is Nicola Da Lio, based at Via Frassinelli 156 B, 30030 Martellago (VE), Italy, VAT number IT 04101760272, who can be contacted at info@nicoladalio.it.

No Data Protection Officer (DPO) has been appointed: none of the cases set out in Article 37 of the GDPR applies.

2. Data collected simply by visiting

Browsing does not require you to identify yourself, and the site uses no analytics, tracking or profiling tools. There are no third-party cookies: typefaces, photographs and videos are served directly by this site, without calling any external service.

Like every website, the provider hosting these pages records connection data for technical and security reasons — IP address, date and time of the request, the page requested, the type of browser. This processing is based on the legitimate interest in keeping the service working and secure (Art. 6(1)(f) GDPR). These logs are kept by the provider[name of the hosting provider] for[retention period].

The site saves only technical information on your device: the choice you make on the cookie banner, where you came to the site from — used only if you then write to us — and, if a notice appears, the fact that you have already seen it. Each of them is described in the Cookie Policy.

When someone opens the WhatsApp chat from the site without filling in any form, the site records only the page and the time of the click, with no data that could identify who made it: it tells us how much that button is used.

3. Data you send us

The contact form

The form at the bottom of the home page sends what you write to this site, where it reaches Nicola directly and is kept in the private area used to manage the site: your answers, the page you wrote from, the time it was sent, the text of the consent you ticked and, if you came from another site or a campaign, where you came from. The same applies when you answer the questions the site asks before opening WhatsApp, and when you leave your name and email to download a document. To protect the form from automated submissions, only a non-reversible fingerprint of the IP address is kept, and only for as long as it takes to limit repeated submissions.

We process the data you send us — name, email, phone number if given, date and place of the wedding, and whatever you have chosen to tell us — in order to reply and, should we reach an agreement, to carry out the photography service. The legal basis is the performance of pre-contractual measures and then of the contract (Art. 6(1)(b) GDPR).

Providing this data is voluntary, but without a name and an email address it is simply not possible to reply to you.

The wedding photographs

If you entrust us with a commission, the photographs taken are personal data in every respect, and they often concern people other than the couple as well. They are processed in order to perform the contract; any publication of them — on the website, in the portfolio, on social media — takes place only with separate, written and revocable consent, collected together with the contract and never taken for granted.

4. Who the data is shared with

The data is neither disclosed nor sold. It may be processed on our behalf, under contractual confidentiality obligations, by the suppliers the business needs: the host of the website and of the messages sent through the form, the email provider, the accountant, and any printing laboratories. An up-to-date list of data processors can be requested at the address given in section 1.

[To be completed] — if any of these suppliers processes data outside the European Economic Area, this must be stated here together with the safeguard that makes the transfer lawful (usually the European Commission’s Standard Contractual Clauses).

5. For how long

  • Enquiries that go no further: two years from the last contact, after which they are deleted.
  • Client data: ten years from the end of the relationship, to meet civil-law and tax obligations.
  • Photographs: kept for as long as needed for delivery and for the backup archive, and in any case deleted at your request, except where needed to defend a right in court.
  • Cookie choice: one year, after which you will be asked again.

6. What you can ask for

Articles 15 to 22 of the GDPR give you the right to access your data, to have it rectified or erased, to restrict its processing, to data portability, and to object to processing based on legitimate interest. Where processing is based on consent, you can withdraw it at any time, without affecting the lawfulness of what was done before.

To exercise these rights, simply write to info@nicoladalio.it. We reply within one month. If you believe the processing breaches the Regulation, you can lodge a complaint with the Garante per la protezione dei dati personali (the Italian Data Protection Authority) or take the matter to court.

7. Automated decisions

No profiling and no automated decision-making within the meaning of Article 22 of the GDPR takes place.

8. Changes

If the site changes — for example, if an analytics tool were added — this page will be updated before the change comes into effect, and the date at the top will make it clear.

Back to the home page

Message me on WhatsApp