💙 First ReNU Association in Italy — Discover our mission
Sindrome ReNU Italia APS
Privacy & GDPR

Privacy Policy

Last updated: June 2026 · Version 2.1

1. Data Controller

Sindrome ReNU Italia APS
Social Promotion Association
Email: info@sindromerenu.it
PEC: sindromerenuitalia@legalmail.it
Tel (Segreteria): +39 327 763 4894
Tel (Presidenza): +39 335 730 1206
Website: www.sindromerenu.it

Data Protection Officer (DPO)

Avv. Francesco Conti
Appointed by the Board of Directors on 9 June 2026 pursuant to Art. 37 GDPR (EU Reg. 2016/679).

To exercise your rights or for any matter relating to the processing of personal data, contact the DPO directly:
dpo@sindromerenu.it

2. Personal Data Collected

PurposeDataLegal basis
Information requestsNome, email, messaggioConsent (Art. 6.1.a GDPR)
Association membershipNome, cognome, email, città, dati bambinoContract (Art. 6.1.b GDPR)
DonationsNome, email, importoLegal obligation (Art. 6.1.c GDPR)
Family stories (health data)Child name, story, photosExplicit consent (Art. 9.2.a GDPR)
Site navigation (logs)IP, browser, pagine visitateLegitimate interest (Art. 6.1.f GDPR)

3. Health Data (Special Category)

The site processes health data relating to children with ReNU Syndrome. This data falls under the special categories of Art. 9 GDPR and is processed exclusively with:

  • Explicit and informed consent of the data subject or parent/guardian
  • Health protection and family support purposes
  • Enhanced security measures (encryption, limited access)
  • Limited retention and deletion on request

4. Your Rights (Arts. 15-22 GDPR)

Right of Access
You can request a copy of your data (Art. 15)
Right of Rectification
You can correct inaccurate data (Art. 16)
Right of Erasure
Right to be forgotten (Art. 17)
Right of Restriction
You can restrict processing (Art. 18)
Right of Portability
You can receive your data in structured format (Art. 20)
Right of Objection
You can object to processing (Art. 21)
How to exercise your rights: Write to info@sindromerenu.it. We will respond within 30 days. You may also lodge a complaint with the Italian Data Protection Authority (Garante).

5. Cookies and Tracking Technologies

This site uses only technical cookies necessary for its operation. No profiling or marketing cookies are used. No Google Analytics or other behavioural analysis tool is integrated.

CookieTypeDurationPurpose
sessionTechnicalSessionNavigation
cf_clearanceTechnical (Cloudflare)30 daysCDN Security
cookie_consentTechnical (preferences)365 daysStores cookie banner choice

External CDN CSS/JS resources

The site loads CSS stylesheets (Tailwind, FontAwesome) from the jsDelivr.net CDN service, operated by ProspectOne (Poland/EU). This may involve transmission of your IP address to the CDN server on first page load. No profiling cookies are set by these services. Typography fonts are served by the operating system (no Google Fonts request).

You can manage cookies in your browser settings.

6. Retention Periods

  • • Contact data/information requests: 2 years from receipt
  • • Association membership data: for the duration of membership + 5 years
  • • Donation data: 10 years (tax obligation)
  • • Family stories: until consent is withdrawn
  • • Navigation logs: 12 months

7. Data Security

Data is processed with appropriate technical and organizational security measures: HTTPS/TLS transmission, hosting on Cloudflare Pages (ISO 27001 certified infrastructure), access limited to authorized personnel, cryptographic hashing of IP addresses (SHA-256, non-reversible). Transfers to Cloudflare Inc. (USA) are lawful based on Cloudflare's certification under the EU-US Data Privacy Framework (European Commission adequacy decision 2023/1795 of 10 July 2023) — a sufficient and autonomous legal basis pursuant to Art. 45 GDPR, requiring no Standard Contractual Clauses.

8. Data Processors and Third Parties (Art. 28 GDPR)

For certain technical and operational activities, Sindrome ReNU Italia APS uses third parties. Some are appointed Data Processors pursuant to Art. 28 GDPR (processing data on behalf of the Controller); others are independent data controllers (processing data for their own purposes, independently of the Controller).

Data Processors (Art. 28 GDPR)

Party Role Data processed Location Safeguards
Website Technical Manager Website development and technical management, database and admin panel All database data (contacts, memberships, stories, donations) 🇮🇹 Italia DPA Contract Art. 28 GDPR
Brevo SAS (ex Sendinblue) Transactional email notifications (not yet active) Name, email, message 🇫🇷 Francia — UE DPA (Art. 28 GDPR)

Third Parties — Independent Data Controllers

The following parties process technical visitor data (e.g. IP addresses, network data) as part of their own services, acting as independent data controllers. The Association does not instruct these parties on such processing and cannot restrict it; please refer to their respective privacy policies.

Party Service Data processed independently Location US transfer basis
Cloudflare, Inc. CDN, network security, DDoS protection, Pages hosting Visitor IPs, HTTP headers, routing data (for own security purposes) 🇺🇸 USA EU-US DPF ✓
jsDelivr CDN (ProspectOne) CSS/JS file delivery (Tailwind, FontAwesome) Visitor IP at page load 🇵🇱 Polonia — UE EU processing

DPF = EU-US Data Privacy Framework (European Commission adequacy decision 2023/1795, 10 Jul. 2023). Cloudflare is DPF certified: data transfers to the USA are lawful without Standard Contractual Clauses. For data that Cloudflare processes as independent controller, please refer to its Privacy Policy: www.cloudflare.com/privacypolicy/

Supervisory Authority

You have the right to lodge a complaint with the Italian Data Protection Authority:

www.garanteprivacy.it