1. Data controller
The controller responsible for personal data processed through this website is:
- Legal name
- Insert full legal name, trading as Koltsoff
- Address
- Insert business address
- VAT number
- Insert Partita IVA
- hello@koltsoff.com
The three marked fields must be replaced with the operator’s registered details. They cannot be inferred safely from the website.
2. Data, purposes and legal bases
Enquiries
If you use the contact form or email Koltsoff, the website processes your name, email address, message, and any information you choose to include. This data is used to answer your enquiry, discuss your needs, and take steps you request before entering into a possible contract. The legal basis is Article 6(1)(b) GDPR.
Providing this information is voluntary, but without a valid email address and enough detail about your enquiry, Koltsoff may be unable to respond. Please do not include sensitive or unnecessary personal data in your message.
Website security and delivery
The hosting environment may generate technical logs containing information such as IP address, request date and time, requested resource, browser details, and error or security events. The contact form also uses an IP-derived, pseudonymous rate-limit record and a short-lived session identifier to prevent abuse and forged requests. Processing is based on Koltsoff’s legitimate interest in operating a secure and reliable website under Article 6(1)(f) GDPR.
Legal obligations and claims
Information may be retained or disclosed where necessary to comply with a legal obligation under Article 6(1)(c) GDPR, or to establish, exercise, or defend legal claims under Koltsoff’s legitimate interests.
No automated decision-making or profiling is carried out through this website.
3. Recipients and transfers
Personal data may be handled only where needed by authorised persons and service providers supporting website hosting, email delivery, IT security, maintenance, or professional advice. These providers act under their own legal role or, where applicable, as processors bound by data-protection obligations. Data may also be disclosed to public authorities where required by law.
Koltsoff does not sell personal data. If a service provider processes data outside the European Economic Area, the transfer will be based on an adequacy decision or another safeguard permitted by Chapter V GDPR, such as the European Commission’s standard contractual clauses. Further information about applicable safeguards can be requested by email.
4. How long data is kept
- Enquiries are normally kept for up to 24 months after the last meaningful contact, unless they become part of a client relationship or must be retained longer for legal claims or obligations.
- The contact-form security token expires after one hour; its browser session cookie expires when the browsing session ends.
- The form’s anti-abuse rate-limit entries cover a rolling one-hour period.
- Hosting and security logs are kept according to the host’s configured retention period and, unless an incident requires longer preservation, should not be retained for more than 12 months.
When the relevant period ends, data is deleted or anonymised unless continued retention is legally required.
5. Your rights
Subject to the conditions in the GDPR, you may ask for access to your personal data, correction, deletion, restriction of processing, portability, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time; this website does not currently rely on consent for the activities described above.
To exercise a right, email hello@koltsoff.com. Koltsoff may request information needed to verify your identity and will normally respond within one month.
You may also lodge a complaint with the Garante per la protezione dei dati personali or another competent supervisory authority in the EU Member State where you live, work, or believe an infringement occurred.
6. Security, links and updates
Appropriate technical and organisational safeguards are used to reduce the risk of unauthorised access, loss, misuse, or alteration. No internet service can guarantee absolute security.
This website may link to third-party websites. Their operators are responsible for their own privacy practices. This policy may be updated if the website, providers, or legal requirements change. The revision date at the top identifies the current version.
For information about the site’s technical cookie, see the Cookie Policy.