The Other Side of the Wall

Privacy Policy

Questa pagina è anche disponibile in italiano

Last updated: 26 August 2026

This policy describes how the personal data of those who visit the website
www.theothersideofthewall.org or contact the Data Controller is processed.

It is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian
Legislative Decree 196/2003 (Privacy Code).

As regards cookies and other tracking tools specifically, please refer to the
Cookie Policy, which forms an integral part of this document.

1. Data Controller

Nino Orto
Largo Don Minzoni 1
95047 Paternò (CT) — Italy
E-mail: nino.orto@hotmail.it

The Controller has not appointed a Data Protection Officer (DPO), as the conditions set out in
Article 37 GDPR do not apply. For any request concerning your personal data you may write to the e-mail
address above.

2. What data we process

2.1 Data you provide voluntarily

If you contact us through the form on the website or by writing directly to the Controller’s e-mail
address, we process:

  • your first name;
  • your surname, if you choose to provide it (optional);
  • your e-mail address;
  • the content of the message you send us.

No other data is requested from you. We invite you not to include in your message any information
that is not necessary to formulate your request and, in particular, not to communicate special
categories of personal data within the meaning of Article 9 GDPR (racial or ethnic origin, political
opinions, religious beliefs, data concerning health or sex life).

Providing your first name and e-mail address is necessary in order for us to reply to you: without
them the request cannot be acted upon. Providing your surname is entirely optional.

2.2 Browsing data

The IT systems and software procedures underlying the operation of this website acquire, in the
course of their normal operation, certain data whose transmission is implicit in the use of Internet
communication protocols: IP addresses, browser and operating system type, date and time of the request,
pages requested, and response status codes.

This data is recorded in the server log files and is used solely to ensure the correct functioning
and security of the website. It is not used to identify users, nor is it associated with any other
information.

2.3 Statistical data

The website uses Google Analytics 4 to collect, subject to your consent, aggregate
statistics on browsing activity. Full details are set out in the
Cookie Policy. In the absence of consent, this data is not
collected.

3. Purposes and legal bases

PurposeData processedLegal basis
Responding to contact requests and managing the resulting correspondenceFirst name, surname (if provided), e-mail, message contentLegitimate interest of the Controller in replying to those who contact him, and of the data
subject in receiving a reply (Article 6(1)(f) GDPR)
Ensuring the functioning and security of the website and preventing abuseBrowsing data and system logsLegitimate interest of the Controller in the security of his systems
(Article 6(1)(f) GDPR)
Aggregate statistical analysis of visitsData collected through analytics cookiesYour consent (Article 6(1)(a) GDPR), which may be withdrawn at any time
Compliance with legal obligationsAll the data indicated above, where necessaryLegal obligation (Article 6(1)(c) GDPR)

Data collected through the contact form is not used to send promotional communications or
newsletters
and is not used for any purpose other than the one for which you provided it.

4. How data is processed

Data is processed using IT and telematic tools, applying technical and organisational measures
appropriate to ensure its security, integrity, and confidentiality, and to prevent unauthorised access,
loss, or disclosure. The website is served over an encrypted connection (HTTPS).

Processing is carried out by the Controller and, where necessary, by the parties indicated in
section 6.

5. No profiling or automated decision-making

The Controller does not carry out any profiling of users and does not employ
automated decision-making processes
producing legal effects concerning you or similarly
significantly affecting you, within the meaning of Article 22 GDPR.

6. Recipients of the data

For the purposes set out above, your data may be made accessible to the following parties, appointed
as Data Processors pursuant to Article 28 GDPR:

  • Aruba S.p.A., provider of the hosting and e-mail services, with servers located

    within the European Union;
  • Google Ireland Limited, limited to the statistical data collected through Google

    Analytics and only where you have given your consent.

Data is neither disseminated nor transferred to third parties for commercial purposes. It may be
disclosed to public authorities or to the judicial authorities only in the cases provided for by law.

An up-to-date list of Data Processors is available on request by writing to the Controller.

7. Transfer of data outside the European Union

Data collected through the contact form and the system logs are stored on servers located
within the European Union
and are not transferred to third countries.

The only data that may also be processed outside the European Economic Area is the statistical data
handled by Google, on the basis of the European Commission’s adequacy decision of 10 July 2023
concerning the EU-U.S. Data Privacy Framework and of the Standard Contractual Clauses. Full
details are set out in the Cookie Policy.

8. Retention period

DataRetention
Contact requests (first name, surname, e-mail, message)24 months from the last exchange of correspondence, unless longer retention is necessary to
establish, exercise, or defend a legal claim
System logsAccording to the technical retention periods of the hosting provider, ordinarily no longer
than 12 months
Statistical dataAs set out in the Cookie Policy
Proof of cookie consent1 year

At the end of the periods indicated, data is erased or irreversibly anonymised.

9. Your rights

As a data subject you may exercise at any time the rights provided for by Articles 15-22 GDPR, and in
particular you may:

  • obtain confirmation as to whether or not your data is being processed and

    access that data;
  • obtain the rectification of inaccurate data or the completion of

    incomplete data;
  • obtain the erasure of your data (the “right to be forgotten”) in the cases

    provided for by Article 17;
  • obtain the restriction of processing in the cases provided for by Article 18;
  • receive the data concerning you in a structured, commonly used format and transmit it to another

    controller (data portability, Article 20);
  • object at any time, on grounds relating to your particular situation, to

    processing based on legitimate interest (Article 21);
  • withdraw the consent given for analytics cookies, without affecting the

    lawfulness of processing carried out before the withdrawal.

Requests should be addressed to the Controller at
nino.orto@hotmail.it. The Controller will respond without undue
delay and in any event within one month of receiving the request, a period that may be extended by two
further months in particularly complex cases.

If you believe that the processing of your data infringes applicable law, you have the right to lodge
a complaint with the Italian Data Protection Authority, the Garante per la protezione
dei dati personali (Piazza Venezia 11, 00187 Rome —
www.garanteprivacy.it),
or to bring proceedings before the courts.

10. Minors

The website is not directed at children under the age of 14, and the Controller does not knowingly
collect personal data from children of that age. Should data relating to a minor be found to have been
collected without the consent of the holder of parental responsibility, such data will be erased without
delay.

11. Changes to this policy

The Controller reserves the right to amend or update this policy to reflect changes in legislation or
in the services offered by the website. Each version shows the date of its most recent update at the top
of the page; we invite you to consult it periodically.