Privacy policy pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR)
Last updated: 15 August 2025
I. Name and address of the controller
The controller within the meaning of the General Data Protection Regulation and other national data protection laws of the Member States as well as other data protection provisions is: Dolomiten Tennis Academy s.s.d – Società Sportiva Dilettantistica a R. L. represented by the legal representative Andrea Bianchi Don Bosco Street 17 39042 Bressanone (BZ), Italy E-mail: dolomiten-tennis@rolmail.net Telephone: +39 338 186 3961 Website: https://dolomiten-tennis.it (hereinafter “we” or “us”).
II. Scope
This privacy policy explains the nature, scope and purpose of the processing of personal data (hereinafter “data”) within our online offering under the domain academy.dolomiten-tennis.it (hereinafter “Website”) and the related processing activities.
III. Principles of data processing (Art. 5 GDPR)
Your personal data is always processed in accordance with the principles laid down in Art. 5 GDPR. This particularly includes:
- Lawfulness, fairness and transparency (Art. 5(1)(a) GDPR): Processing takes place on a valid legal basis and in a manner you can understand.
- Purpose limitation (Art. 5(1)(b) GDPR): Data is collected and processed only for specified, explicit and legitimate purposes.
- Data minimisation (Art. 5(1)(c) GDPR): We only process data that is relevant and limited to what is necessary for the respective purpose.
- Accuracy (Art. 5(1)(d) GDPR): We take appropriate measures to ensure that inaccurate data is erased or rectified without delay.
- Storage limitation (Art. 5(1)(e) GDPR): Data in personal form is only stored as long as necessary for the processing purposes or due to legal obligations.
- Integrity and confidentiality (Art. 5(1)(f) GDPR): We protect your data through appropriate technical and organisational measures against unauthorised processing, loss or destruction.
- Accountability (Art. 5(2) GDPR): We are responsible for compliance with these principles and can demonstrate it.
IV. Legal bases and purposes of processing
Art. 6(1)(b) GDPR provides the legal basis for processing operations necessary for the performance of a contract to which you are party or in order to take steps prior to entering into a contract (e.g. enquiries about our courses). This particularly concerns the receipt and administration of course registrations.
Art. 6(1)(c) GDPR applies where processing is necessary for compliance with a legal obligation to which we are subject. This includes, for example, statutory retention obligations under tax and commercial law.
Art. 6(1)(f) GDPR legitimises processing for the purposes of our legitimate interests or those of a third party, provided that your interests or fundamental rights and freedoms requiring the protection of personal data do not override them. Our legitimate interests include:
- Ensuring the technical functionality, stability and security of our Website.
- Preventing fraud and defending against attacks on our IT systems.
- Providing a user-friendly Website, for example by storing language settings.
Within the required balancing of interests we have ensured that our interest in the processing does not outweigh potential risks to your rights and freedoms.
V. Processing activities, data categories and retention periods
V.1 Provision of the Website (Firebase Hosting)
Purpose: Secure and high-performance delivery of web content, error analysis and threat prevention.
Data categories: IP address, access timestamp, requested resources (URLs), referrer URL, browser and operating system information (user agent), HTTP status codes.
Legal basis: Art. 6(1)(f) GDPR.
Retention: Log data is generally retained for up to 30 days and then deleted unless longer storage is required to clarify a security incident (e.g. an attack).
V.2 Course registration and contract execution (Cloud Firestore)
Purpose: Receipt, management and execution of course registrations as well as internal organisation and preparation of invoicing.
Data categories: Master and contact data (name, e‑mail, telephone), contract data (selected courses, dates), registration timestamp.
Legal basis: Art. 6(1)(b) GDPR; for subsequent retention Art. 6(1)(c) GDPR.
Retention: For the duration of the contractual relationship. After the contract ends, retention takes place within statutory retention periods (e.g. 10 years under Italian civil and tax law for accounting-relevant documents).
V.3 E-mail communication (EmailJS)
Purpose: Automated sending of transactional e‑mails (e.g. registration confirmations, organisational notices) within performance of the contract.
Data categories: E‑mail address, name, message content and technical transmission metadata.
Legal basis: Art. 6(1)(b) GDPR.
Retention: For as long as communication is necessary and up to 12 months for documentation and evidence purposes unless longer statutory obligations apply.
V.4 Technically necessary cookies / Web storage
Purpose: Ensuring essential functionalities of the Website. For these cookies, pursuant to § 25(2) TTDSG (or equivalent national regulations) no consent is required.
Processing:
| Name | Provider | Purpose | Retention |
|---|---|---|---|
| .pll_language | Dolomiten Tennis Academy s.s.d | Stores the selected language setting | 1 year |
| cookieConsent | Dolomiten Tennis Academy s.s.d | Stores the selection of cookie settings (necessary / analytics) | 6 months |
| _ga_XXXXXXXXXX | Google Ireland Limited | Google Analytics – distinguishes users and stores session information (only with consent) | 2 years |
Where these cookies may (also) concern personal data, we inform you in the following sections. You can delete individual cookies or the entire cookie store via your browser settings. You will also find information and instructions on how to delete these cookies or block their storage in advance.
Depending on your browser provider you can find the necessary information at the following links:
- Microsoft Edge: More information
- Mozilla Firefox: More information
- Google Chrome: More information
- Opera: Mehr Infos
- Safari: More information
VI. Recipients of data and processors (Art. 28 GDPR)
We only disclose your data to third parties where this is necessary for the stated purposes and permitted by law. We use external service providers as processors acting under our instructions. They were carefully selected and are contractually bound to data protection by a data processing agreement pursuant to Art. 28 GDPR.
- Google Ireland Limited, Dublin, Ireland: Processor for Firebase Hosting and Cloud Firestore.
- EmailJS (USA): Processor for sending e‑mails.
- Internal departments: Access is granted only to those employees who require it to fulfil their contractual and legal duties (role-based need-to-know principle).
VII. Data transfers to third countries (Art. 44 et seq. GDPR)
Use of the above-mentioned services (Google, EmailJS) may involve a transfer of data to servers in third countries, in particular the USA. There is no adequacy decision by the EU Commission for the USA within the meaning of Art. 45 GDPR. We therefore ensure an adequate level of data protection through appropriate safeguards pursuant to Art. 46 GDPR. This is primarily achieved by concluding the EU Commission’s Standard Contractual Clauses (SCC). Where necessary these are supplemented by additional technical and organisational measures (e.g. encryption of data in transit and at rest, strict access controls) to mitigate potential risks arising from access by authorities in the third country.
VIII. Rights of the data subject (Art. 15–21 GDPR)
- the right of access to the personal data concerning you (Art. 15 GDPR);
- the right to rectification of inaccurate data (Art. 16 GDPR);
- the right to erasure (‘right to be forgotten’) under the conditions of Art. 17 GDPR;
- the right to restriction of processing under the conditions of Art. 18 GDPR;
- the right to data portability in a structured, commonly used and machine-readable format (Art. 20 GDPR);
- the right to withdraw consent at any time with effect for the future (Art. 7(3) GDPR);
- the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on Art. 6(1)(f) GDPR (Art. 21 GDPR).
To exercise your rights, please contact us informally using the contact details stated in Section I.
IX. Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you consider that the processing of personal data concerning you infringes the GDPR. The supervisory authority primarily competent for us is: Garante per la protezione dei dati personali Piazza Venezia 11, 00187 Rome, Italy Website: https://www.garanteprivacy.it
X. Obligation to provide data and automated decision-making
The provision of data required for course registration and execution is contractually necessary. Without this data a contract cannot be concluded. No automated decision-making including profiling within the meaning of Art. 22 GDPR takes place.
Changes to our privacy policy
We reserve the right to adapt this privacy policy so that it always complies with current legal requirements or to implement changes to our services in the privacy policy, e.g. when introducing new services or updating the Website. Your subsequent visit will then be subject to the new privacy policy.
Questions to the data protection contact
If you have questions about data protection please send us an e‑mail or contact the person responsible for data protection in our organisation:
Dolomiten Tennis Academy s.s.d , represented by:
Andrea Bianchi
Telephone: 0039 338 1863961
E-mail: dolomiten-tennis@rolmail.net
or
via contact form on our Webseite (dolomiten-tennis.it)
Privacy policy of 15.08.2025
