Privacy policy
Last Updated: June 27, 2026
Welcome to Studio Utaini. Transparency is one of our founding pillars: we completely reject unnecessarily complex legal jargon. This page explains exactly what personal data we collect, why we collect it, how we protect it, and what your rights are, in strict compliance with EU Regulation 2016/679 (GDPR) and the UK-GDPR.
1. Data Controller
The Data Controller for the personal data collected through this website is:
Name/Corporate Name: Luca Cavallini – Studio Utaini
Registered Fiscal Address: via E. De Amicis, 41/7 – 20045 – Lainate (MI) – Italy
VAT Number: IT13241450967
Contact Email: [email protected]
2. Types of Data Collected
We strictly collect data that is necessary to deliver our advisory services and optimize our digital infrastructure:
Data provided voluntarily by the user: First name, last name, professional email address, and information regarding your property or business (captured via our application/contact form or through direct email communications).
Technical and navigation data: IP address, browser information, operating system version, approximate geographical location (country level), internal browsing history, and interaction logs (clicks and time spent on pages).
3. Purpose of Processing and Legal Basis
We process your personal data exclusively for the following purposes:
| Purpose | Data Used | Legal Basis (GDPR) |
| Inquiry Management & Onboarding: Processing applications submitted via the contact form to evaluate potential project collaborations. | Name, email, business data. | Performance of pre-contractual measures (Art. 6.1.b GDPR). Initiated voluntarily by the user. |
| Security & Fraud Prevention: Active site monitoring to block hacking attempts, spam, and unauthorized access. | IP address, system logs. | Legitimate interest of the Data Controller (Art. 6.1.f GDPR) to maintain a secure digital ecosystem. |
| Performance Analysis: Understanding how users interact with our site to optimize its structure and performance. | Anonymized or aggregated navigation data (truncated IP). | Legitimate interest (Art. 6.1.f GDPR) to run non-invasive proprietary analytics. |
| Targeted Marketing & Advertising (Google Ads): Intercepting high-intent users interested in our services via search networks in targeted geographical areas (UK and Scandinavia). | IP address, tracking cookies. | Explicit consent (Art. 6.1.a GDPR) provided via the cookie consent banner. |
| Audience Engagement & Newsletter (Substack): Delivering insights, briefings, and sector monitoring upon explicit request. | Name, email address. | Explicit consent (Art. 6.1.a GDPR) granted at the time of subscription. |
| Multimedia Content Playback: Allowing the playback of case-study video assets embedded on our pages. | Third-party technical and tracking cookies (YouTube). | Explicit consent (Art. 6.1.a GDPR) granted via the cookie banner. |
4. Data Security and Protection Measures
Your digital footprint is secure. We apply rigorous logical and technological security protocols to prevent data loss, illicit use, or unauthorized access:
Encryption: The website operates under an SSL certificate (HTTPS protocol). All data transmitted via forms is fully encrypted.
Access Control: Backend access to the website is strictly restricted to the administrator using secure, verified credentials.
Active Monitoring: We run the professional security system WordFence, which performs continuous malware scans, monitors live traffic to identify malicious bots, and deploys structural barriers against brute-force attacks.
5. Data Sharing and Third-Party Services
We do not sell, trade, or rent your personal data to external entities. To operate our digital architecture efficiently, we utilize verified third-party suppliers who act as Data Processors:
Infrastructure & Security: Cloudflare (optimization and protection) and WordFence (WordPress security).
Statistical Analysis: Matomo Analytics (configured locally to respect user privacy without mass tracking or behavioral profiling).
Integrations & Media: YouTube (for embedding case-study video assets) and Google Fonts (for typography display).
Advertising: Google Ads (for high-intent search network campaigns).
Newsletter & Mailing List: Substack (for managing our broadcasting database).
International Data Transfers: Some of these external services (Google, YouTube, Substack) are headquartered in the United States. Data transfers are executed in strict compliance with the European Union’s Standard Contractual Clauses (SCCs) and the EU-U.S. / UK-U.S. Data Privacy Framework.
6. Retention Period
We store your personal data only for the timeframe strictly required to fulfill the processing purposes:
Contact form data that does not convert into active project contracts is completely erased within 12 months.
Data linked to marketing and newsletter services is stored until you choose to revoke your consent (which can be exercised instantly via the opt-out link at the bottom of every email).
Technical security logs are automatically overwritten or deleted within 90 days.
7. Your Operational Rights
As a data subject, the GDPR and UK-GDPR grant you total control over your information. You may exercise the following rights at any time by emailing [email protected]:
Access: Request to know if your data is being processed and obtain a full copy.
Rectification: Correct inaccurate, outdated, or incomplete data.
Erasure (Right to be Forgotten): Request the definitive removal of your data from our active databases.
Restriction & Objection: Object to processing on legitimate grounds or request a restriction on how your data is handled, including direct marketing profiling.
Withdrawal of Consent: Instantly revoke any processing built upon your previous consent.
You also maintain the absolute right to lodge a formal complaint with a supervisory authority. In Italy, this is the Garante per la Protezione dei Dati Personali (GPDP); in the United Kingdom, it is the Information Commissioner’s Officer (ICO).
8. Policy Amendments
We reserve the right to update this privacy policy to reflect ongoing technical site iterations or legislative adjustments. In the event of material changes that alter how your personal data is managed, you will be prompted to grant your explicit consent again via the cookie banner upon your next visit.