Skip to main content

Privacy and Cookie Policy

Pursuant to EU Regulation 2016/679 (GDPR) and Italian Legislative Decree 196/2003, as amended

Last updated: 27 May 2026

This English version is a courtesy translation. The Italian version is canonical and prevails in case of discrepancy.

1. Data Controller

The Data Controller for the processing of personal data is: Luca Grella

Residence
Via Boifava 62, 20142 Milano - Italy
Italian Tax Code
GRLLCU96A25B819B
E-mail
privacy@graeysound.com

2. Personal Data Collected via the Contact Form

Through the contact form on this website only the personal data voluntarily provided by the user are collected. Submitting the form also requires explicit acceptance of this policy.

Data collected

Request type (artist / company)

Required

Yes

Purpose

Routing the request

Data collected

Name

Required

Yes

Purpose

User identification

Data collected

E-mail address

Required

Yes

Purpose

Replying to the enquiry

Data collected

Message

Required

Yes

Purpose

Handling the enquiry

Data collected

Services of interest (artist only)

Required

Yes (artist)

Purpose

Qualifying the request

Data collected

"Other" details (artist only)

Required

Conditional

Purpose

Specifying the custom request

Data collected

Company name (company only)

Required

Yes (company)

Purpose

Identifying the client

Data collected

Privacy acceptance timestamp

Required

Automatic

Purpose

Proof of consent

3. Purpose and Legal Basis of Processing

Personal data are processed for the following purposes:

3.1 Responding to contact requests

Purpose: managing and responding to enquiries submitted via the contact form.

Legal basis: performance of pre-contractual measures taken at the request of the data subject (Art. 6(1)(b) GDPR) and/or legitimate interest of the Data Controller (Art. 6(1)(f) GDPR).

3.2 Legal obligations

Purpose: complying with obligations arising from law, regulation, or EU legislation.

Legal basis: legal obligation (Art. 6(1)(c) GDPR).

3.3 Anonymous website analytics

Purpose: measuring website traffic and usage patterns to improve the service. No personal data is collected; all measurements are anonymised at collection time (page URL, referrer, browser type, OS, device type, and country derived from IP address; the IP address itself is never stored).

Legal basis: legitimate interest of the Data Controller (Art. 6(1)(f) GDPR). Since no personal data is processed, the ePrivacy cookie consent requirement does not apply.

4. Methods of Processing

Personal data are processed by electronic and/or automated means, following logics strictly related to the stated purposes and, in any case, in a manner that ensures the security and confidentiality of the data, in compliance with the organisational, physical, and logical measures required by applicable regulations. Data are stored on AWS infrastructure located in the Frankfurt (eu-central-1) region, within the European Union.

5. Data Retention Period

Personal data collected via the contact form will be retained for the time strictly necessary to handle the request and, in any event, for a period not exceeding 24 months from the last meaningful contact with the data subject, unless a longer retention period is required by law.

At the end of the retention period, the data will be deleted or irreversibly anonymised.

6. Disclosure and Transfer of Data

Personal data will not be disseminated. They may be disclosed to:

Cloud hosting and infrastructure provider
Amazon Web Services EMEA SARL (Luxembourg) acting as data processor, for infrastructure hosting and transactional e-mail delivery. All data are processed in the Frankfurt (eu-central-1) region.
Consultants and professionals
Within the scope of advisory and consultancy relationships (e.g. accountant, lawyer).
Anonymous analytics provider
Umami Software Inc. (USA), acting as data processor, for cookie-free anonymous website analytics via cloud.umami.is. Only anonymised, non-personal data is transmitted (page URL, referrer, browser, OS, device type, country). IP addresses are not stored.
Competent authorities
Where required by law or upon request by such authorities.

Contact form data will not be transferred to third countries outside the European Union. Contact form processing takes place on AWS infrastructure in the Frankfurt (eu-central-1) region (EU). Anonymous analytics data is processed by Umami Software Inc. (USA); as this data contains no personal data, GDPR transfer restrictions do not apply.

7. Data Subject Rights

Under Articles 15-22 of the GDPR, the data subject has the right to:

  1. access their personal data and obtain a copy thereof;
  2. obtain the rectification of inaccurate data or the completion of incomplete data;
  3. obtain the erasure of their data (right to be forgotten), where the conditions set out by law are met;
  4. obtain the restriction of processing;
  5. receive their data in a structured, commonly used, and machine-readable format (data portability);
  6. object at any time to processing based on legitimate interest;
  7. withdraw consent at any time, without affecting the lawfulness of processing carried out on the basis of consent prior to its withdrawal;
  8. lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali).

To exercise these rights, the data subject may send a written request to: privacy@graeysound.com

9. Changes to this Policy

The Data Controller reserves the right to amend this Privacy and Cookie Policy at any time, providing adequate notice by publishing the updated version on this website. Users are encouraged to review this page periodically.