Privacy Policy
Last updated: June 2026 · Version 2.1
1. Data Controller
Social Promotion Association
Email: info@sindromerenu.it
PEC: sindromerenuitalia@legalmail.it
Tel (Segreteria): +39 327 763 4894
Tel (Presidenza): +39 335 730 1206
Website: www.sindromerenu.it
Data Protection Officer (DPO)
Avv. Francesco Conti
Appointed by the Board of Directors on 9 June 2026 pursuant to Art. 37 GDPR (EU Reg. 2016/679).
To exercise your rights or for any matter relating to the processing of personal data, contact the DPO directly:
dpo@sindromerenu.it
2. Personal Data Collected
| Purpose | Data | Legal basis |
|---|---|---|
| Information requests | Nome, email, messaggio | Consent (Art. 6.1.a GDPR) |
| Association membership | Nome, cognome, email, città, dati bambino | Contract (Art. 6.1.b GDPR) |
| Donations | Nome, email, importo | Legal obligation (Art. 6.1.c GDPR) |
| Family stories (health data) | Child name, story, photos | Explicit consent (Art. 9.2.a GDPR) |
| Site navigation (logs) | IP, browser, pagine visitate | Legitimate interest (Art. 6.1.f GDPR) |
3. Health Data (Special Category)
The site processes health data relating to children with ReNU Syndrome. This data falls under the special categories of Art. 9 GDPR and is processed exclusively with:
- Explicit and informed consent of the data subject or parent/guardian
- Health protection and family support purposes
- Enhanced security measures (encryption, limited access)
- Limited retention and deletion on request
4. Your Rights (Arts. 15-22 GDPR)
5. Cookies and Tracking Technologies
This site uses only technical cookies necessary for its operation. No profiling or marketing cookies are used. No Google Analytics or other behavioural analysis tool is integrated.
| Cookie | Type | Duration | Purpose |
|---|---|---|---|
| session | Technical | Session | Navigation |
| cf_clearance | Technical (Cloudflare) | 30 days | CDN Security |
| cookie_consent | Technical (preferences) | 365 days | Stores cookie banner choice |
External CDN CSS/JS resources
The site loads CSS stylesheets (Tailwind, FontAwesome) from the jsDelivr.net CDN service, operated by ProspectOne (Poland/EU). This may involve transmission of your IP address to the CDN server on first page load. No profiling cookies are set by these services. Typography fonts are served by the operating system (no Google Fonts request).
You can manage cookies in your browser settings.
6. Retention Periods
- • Contact data/information requests: 2 years from receipt
- • Association membership data: for the duration of membership + 5 years
- • Donation data: 10 years (tax obligation)
- • Family stories: until consent is withdrawn
- • Navigation logs: 12 months
7. Data Security
Data is processed with appropriate technical and organizational security measures: HTTPS/TLS transmission, hosting on Cloudflare Pages (ISO 27001 certified infrastructure), access limited to authorized personnel, cryptographic hashing of IP addresses (SHA-256, non-reversible). Transfers to Cloudflare Inc. (USA) are lawful based on Cloudflare's certification under the EU-US Data Privacy Framework (European Commission adequacy decision 2023/1795 of 10 July 2023) — a sufficient and autonomous legal basis pursuant to Art. 45 GDPR, requiring no Standard Contractual Clauses.
8. Data Processors and Third Parties (Art. 28 GDPR)
For certain technical and operational activities, Sindrome ReNU Italia APS uses third parties. Some are appointed Data Processors pursuant to Art. 28 GDPR (processing data on behalf of the Controller); others are independent data controllers (processing data for their own purposes, independently of the Controller).
Data Processors (Art. 28 GDPR)
| Party | Role | Data processed | Location | Safeguards |
|---|---|---|---|---|
| Website Technical Manager | Website development and technical management, database and admin panel | All database data (contacts, memberships, stories, donations) | 🇮🇹 Italia | DPA Contract Art. 28 GDPR |
| Brevo SAS (ex Sendinblue) | Transactional email notifications (not yet active) | Name, email, message | 🇫🇷 Francia — UE | DPA (Art. 28 GDPR) |
Third Parties — Independent Data Controllers
The following parties process technical visitor data (e.g. IP addresses, network data) as part of their own services, acting as independent data controllers. The Association does not instruct these parties on such processing and cannot restrict it; please refer to their respective privacy policies.
| Party | Service | Data processed independently | Location | US transfer basis |
|---|---|---|---|---|
| Cloudflare, Inc. | CDN, network security, DDoS protection, Pages hosting | Visitor IPs, HTTP headers, routing data (for own security purposes) | 🇺🇸 USA | EU-US DPF ✓ |
| jsDelivr CDN (ProspectOne) | CSS/JS file delivery (Tailwind, FontAwesome) | Visitor IP at page load | 🇵🇱 Polonia — UE | EU processing |
DPF = EU-US Data Privacy Framework (European Commission adequacy decision 2023/1795, 10 Jul. 2023). Cloudflare is DPF certified: data transfers to the USA are lawful without Standard Contractual Clauses. For data that Cloudflare processes as independent controller, please refer to its Privacy Policy: www.cloudflare.com/privacypolicy/
Supervisory Authority
You have the right to lodge a complaint with the Italian Data Protection Authority:
www.garanteprivacy.it