Information on the
processing of personal data
pursuant to art. 13 of EU Regulation 679/2016 (GDPR)
Last updated: July 6, 2026
1. Data Controller
The Data Controller of personal data is: Danny Buccilli, Via Monte Corvo 23, 67035 Pratola Peligna (AQ), Italy, VAT number: 02143720668, E-mail: info@dannybuccilli.com, PEC (certified email): danny.buccilli@legalmail.it, Phone: +39 327 4588049
2. Types of data collected and purposes of processing
a) Website navigation
During website navigation www.dannybuccilli.com technical data (IP address, browser type, visited pages, access times) are automatically collected through hosting (Cloudflare) and traffic analysis systems. These data are processed to ensure the proper functioning of the site and for aggregate statistical purposes.
Legal basis: legitimate interest of the Data Controller (art. 6, par. 1, let. f, GDPR).
b) Contact form and requests for information
The data voluntarily provided through the contact form (name, e-mail address, any telephone number and message) are processed to respond to user requests.
The data sent via the form is transmitted and processed through the Make (Celonis) automation platform, which acts as a Data Processor, in order to deliver the request to the Data Controller via e-mail. If the user gives explicit consent, via the optional checkbox, to receive communications about future services, events, and updates, the contact data may also be used for these purposes. Legal basis for this latter purpose: consent of the data subject (art. 6, par. 1, let. a, GDPR).
Legal basis: execution of pre-contractual measures at the request of the data subject (art. 6, par. 1, let. b, GDPR).
c) Registration for courses and events
When registering for courses, events, and coaching or facilitation sessions, identification and contact data (name, surname, e-mail, telephone number, billing data) are collected. These data are processed to:
fulfill the contractual obligations deriving from the registration; issue invoices and fulfill tax and accounting obligations; manage any complaints, disputes or litigation; allow the International Coach Federation (ICF) audits relating to the total amount of training hours provided.
Legal basis: contractual fulfillment (art. 6, par. 1, let. b), legal obligation (art. 6, par. 1, let. c) and legitimate interest (art. 6, par. 1, let. f, GDPR).
d) Booking calls and video calls
For booking calls and video calls, the Data Controller uses the CalendarBridge service, which allows the user to select a time and provides the necessary data (name, email address) for the confirmation and management of the appointment. CalendarBridge acts as a Data Processor.
Legal basis: execution of pre-contractual measures at the request of the data subject (art. 6, par. 1, let. b, GDPR).
e) Promotional communications and newsletters
The e-mail address provided upon purchasing a service may be used to send promotional communications regarding similar services, pursuant to art. 130, paragraph 4, of Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 (so-called soft spam). The interested party can object at any time by sending an e-mail to info@dannybuccilli.com.
Legal basis: legitimate interest (art. 6, par. 1, let. f, GDPR) and art. 130, paragraph 4, Legislative Decree 196/2003 (Italy).
f) Photo and video recordings during courses and events
With the express consent of the interested party, given during registration, images and videos recorded during courses or events may be published for promotional and professional purposes. Those who do not wish to be filmed must communicate this at least 30 days before the start of the course by writing to info@dannybuccilli.com.
Legal basis: consent of the data subject (art. 6, par. 1, let. a, GDPR).
g) "Insieme, conosciamo i nostri Sé" Newsletter (Substack)
On some pages of this site there is a subscription form for the newsletter "Insieme, conosciamo i nostri Sé", jointly curated by Danny Buccilli and Marzia Iori as joint data controllers.
The form is provided by Substack Inc., a platform based in the United States, and is loaded only after your explicit consent: before clicking on the load button, no data is transmitted to Substack. By loading the form, Substack receives your IP address and may install its own technical cookies.
If you choose to subscribe, your email address is transmitted to Substack Inc., which acts as a data processor. Data transfer to the United States is covered by adequate safeguards: Substack adheres to the EU-U.S. Data Privacy Framework and includes Standard Contractual Clauses in its Publisher Agreement.
For all details on data processing related to the newsletter (purposes, retention, rights), consult the dedicated privacy policy: newsletter privacy policy. You can unsubscribe at any time from the link at the bottom of each email.
Legal basis: consent of the data subject (art. 6, par. 1, let. a, GDPR).
3. Data recipients
Personal data are not subject to public disclosure. They may be communicated to the following categories of recipients:
- Accountants and tax consultants, to fulfill accounting and tax obligations.
- International Coach Federation (ICF), for audits of the total amount of training hours provided.
- Lawyers and legal consultants, in the event of complaints, disputes, or litigation.
- Airtable (Formagrid Inc, 1 Front Street, San Francisco, CA 94111, USA), used by the Data Controller for the organizational management of courses and participants. Airtable acts as a Data Processor pursuant to art. 28 GDPR, based on a Data Processing Addendum (DPA) compliant with the GDPR and including the Standard Contractual Clauses (SCC) adopted by the European Commission for data transfers to third countries.
- TeamSystem S.p.A. (Via Sandro Pertini 88, 61122 Pesaro (PU), Italy — VAT No. 01035310414), provider of the "Fatture in Cloud" invoicing software used by the Data Controller for the management of invoices and customer billing data. TeamSystem S.p.A. acts as a Data Processor pursuant to art. 28 GDPR, based on the Master Data Processing Agreement (MDPA) and special processing conditions (DPA) integrated into the product's terms of service. Processing takes place entirely within the European Union.
- Make (Celonis Inc.), an automation platform used by the Data Controller for the management and forwarding of data collected through the contact form, quote requests, and registration forms for courses and events. Make acts as a Data Processor pursuant to art. 28 GDPR, based on a Data Processing Agreement (DPA) compliant with the GDPR. For data transfers to third countries, Make relies on the Data Privacy Framework and, subsidiarily, on the Standard Contractual Clauses (SCC) adopted by the European Commission.
- CalendarBridge (CalBridge Inc.), a service used for booking and managing calls and video calls. CalendarBridge acts as a Data Processor pursuant to art. 28 GDPR, based on a Data Processing Agreement (DPA) compliant with the GDPR. For data transfers to the United States, CalendarBridge relies on the Standard Contractual Clauses (SCC) adopted by the European Commission, and hosts the data on AWS infrastructure.
- Substack Inc. (548 Market Street, San Francisco, CA 94104, USA), a platform used for the management of the "Insieme, conosciamo i nostri Sé" newsletter and the collection of subscriptions through its specific form, loaded only after explicit consent from the user. Substack processes the subscriber's e-mail address and, upon loading the form, the IP address. As this is a US-based provider, any data transfers to third countries take place in compliance with the guarantees provided by EU Reg. 679/2016, in particular through the Data Privacy Framework and/or the Standard Contractual Clauses (SCC) adopted by the European Commission.
- Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA), provider of the hosting and CDN infrastructure (Cloudflare Pages) on which the website is hosted. Cloudflare processes technical navigation data (IP address, access logs) as a Data Processor pursuant to art. 28 GDPR, on the basis of its own GDPR-compliant Data Processing Addendum. As this is a US-based provider, any data transfers to third countries take place in compliance with the guarantees provided by EU Reg. 679/2016, in particular through the EU-U.S. Data Privacy Framework, to which Cloudflare adheres, and/or the Standard Contractual Clauses (SCC) adopted by the European Commission.
- Revolut Bank UAB (Italian Branch), Italian branch of Revolut Bank UAB — Via Dante 7, 20123 Milan; headquarters Revolut Bank UAB, Konstitucijos pr. 21B, 08130 Vilnius, Lithuania, a credit institution authorized in Lithuania and operating in Italy. Revolut provides the online payment service through which participation and registration fees are collected. Payment data (name, e-mail address, card or account data) are collected directly by Revolut on the checkout page: Revolut processes these data as an independent Data Controller — and not as a Data Processor pursuant to art. 28 GDPR — for its own purposes of payment execution, fraud prevention, and fulfillment of customer due diligence obligations (KYC/AML) required by banking regulations. Processing takes place entirely within the European Union. For more information, please refer to Revolut's privacy policy, available at revolut.com/legal/privacy.
- Meta Platforms Ireland Limited (Merrion Road, Dublin 4, Ireland), provider of the Meta Pixel tool, activated exclusively with consent to the "marketing" category given through the cookie banner. Meta receives browsing data and identifiers and processes them as an independent Data Controller for its own advertising purposes, in accordance with its own privacy policy. Any transfers to the USA take place on the basis of the EU-U.S. Data Privacy Framework. For details, please refer to the Cookie Policy.
4. Data transfer outside the EU
Some third-party service providers used by the Controller (including Airtable, Make, Substack, Cloudflare and — subject to consent to the relevant cookies — Meta and Google, based in the USA) may process personal data outside the European Economic Area. In such cases, the transfer takes place exclusively in compliance with the safeguards provided for by Regulation (EU) 2016/679, in particular through the EU-U.S. Data Privacy Framework, to which Meta and Google adhere, and the Standard Contractual Clauses (SCC) approved by the European Commission, which guarantee a level of protection equivalent to that ensured within the EU.
5. Retention period
Personal data will be stored for the following periods:
| Type of data | Retention period |
|---|---|
| Billing data | 10 years from the invoice issue date |
| Data for legal protection | Up to 5 years from the conclusion of the proceedings |
| Data for promotional newsletter | 2 years from the date of collection |
| Data for training hours (ICF audit) | 5 years from the date of collection |
| Data sent via the contact form | For the time necessary to handle the request and, in case of consent to promotional communications, until consent is withdrawn |
| Site navigation data | According to Cloudflare policy (technical logs retained for a limited period) |
6. Rights of the data subject
Pursuant to articles 15-22 of EU Reg. 679/2016, the data subject has the right to:
- Access: obtain confirmation of the existence of data concerning them and a copy thereof.
- Rectification: obtain the correction of inaccurate data or the integration of incomplete data.
- Erasure ("right to be forgotten"): obtain the cancellation of their data, unless there are legal obligations that require its retention.
- Restriction of processing: request that the processing be limited to certain purposes.
- Data portability: receive their data in a structured, machine-readable format, and transmit them to another data controller (where technically feasible).
- Objection: object to the processing for reasons related to their particular situation, or at any time for direct marketing purposes.
- Withdrawal of consent: withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise their rights, the data subject can send a written request to:
- E-mail: info@dannybuccilli.com
- PEC (certified email): danny.buccilli@legalmail.it
- Regular mail: Danny Buccilli, Via Monte Corvo 23, 67035 Pratola Peligna (AQ), Italy
The Data Controller will respond within 30 days of receiving the request.
7. Right to lodge a complaint
The interested party has the right to lodge a complaint with the Data Protection Authority (Garante per la Protezione dei Dati Personali):
Piazza di Montecitorio, 121 – 00186 Roma
Sito web: www.gpdp.it
PEC: protocollo@pec.gpdp.it
8. Cookies
The site uses technical cookies necessary for its functioning and, only with consent given through the cookie banner, analytics cookies (Google Analytics 4) and marketing cookies (Meta Pixel). Preferences can be changed at any time via the "Cookie Preferences" link in the footer of every page. For the full list of cookies used and all details, see the Cookie Policy.
Effective date: July 6, 2026
This policy completely replaces any previous version.