Privacy notice
Last updated: 31 July 2026. Written in accordance with Regulation (EU) 2016/679.
In brief. The course is free. We do not ask you for payment, we do not collect payment data and no payment system is connected to this site. We ask for your name, email, business sector and city, and keep what you do in the course: the lessons you complete, quiz results and the notes you write. We do not sell your data to anyone. For anything concerning your data, write to info@manumagistro.it.
1. Who processes your data
The data controller is the entity that decides why and how your data are used, and it is the one you contact to exercise your rights.
⛔ Data controller: TO BE DEFINED
⛔ TO BE DEFINED ⛔
As of today, the entity responsible for these data has not yet been decided. This is where the company name, legal form, registered office, Italian VAT number and, if appointed, the data protection officer must appear. As long as this point remains open, the notice is a draft and the site is not open to the public.
The address to write to for any data-related matter, today and later, is info@manumagistro.it. The course is hosted at academy.magistroconsulting.com.
2. What we collect
2.1 What you write when you sign up
- Name. It is used to address you in emails and to write your name on the final certificate.
- Email address. It is also your user name for logging in.
- Password. We do not store it: we keep only a fingerprint calculated with the bcrypt algorithm, from which the password cannot be recovered. None of us can read it, and if you forget it the only option is to reset it.
- Your business sector (for example restaurant, shop, professional practice) and city.
2.2 The two optional checkboxes
There are two checkboxes in the sign-up form. They are unchecked by default, independent of each other, and the course is complete even if you do not tick either one.
- «I want a consultant to contact me about a free preview of my website.»
- «I want to receive Academy emails: a reminder if I do not log in for a while and other course communications.»
For every choice, we keep the exact text you saw, the date, time and version of the form, as they were when you decided. We also keep the refusal and any later withdrawals in the same way: the burden of proving consent is ours, and without this history we could not show what each person really saw and chose.
2.3 What is generated while you take the course
- Progress. Which lessons you completed and when.
- Quiz. Your score, the total number of questions and whether you passed the test.
- Notes. The notes you write in the lessons. Only you can read them: we do not use them for anything else.
- Activity days. The dates when you opened the course, which are used to calculate consecutive days and achievements.
- Certificate. The code and the date it was generated.
- Settings. Whether you turned on the weekly summary, your time zone and the record of service emails already sent, which is used to avoid sending them to you twice.
2.4 Technical data
- Two technical cookies, described in section 5.
- A counter for emails sent in the last hour, which prevents the sign-up form from being used to target someone else's address with messages.
- The logs of the server that serves the pages, which contain the IP address of the person connecting, as on any website. In the course database, however, the IP address is not stored.
2.5 What we do not collect
- No payment data. The course is free: there are no cards, no bank accounts and no payment system connected to this site.
- No profiling cookies and no third-party analytics system. There is no advertising in the course and we do not track your behaviour on other websites.
- No special categories of data among those in Article 9 of the Regulation: we do not ask you anything about health, opinions, beliefs or private life. We do not ask for your date of birth or a document either.
3. Why we use them, and on what basis
- To provide you with the course. Name, email and password are used to create your access and let you log in. Progress, quizzes, notes and the certificate are the course itself. Legal basis: performance of the contract, Article 6.1.b.
- For service emails. The verification code, the welcome email, the password reset if you request it, guidance on how to get started in the first days, and the certificate email when you finish. Legal basis: performance of the contract, Article 6.1.b.
- For the reminder after a month of absence. It is sent only if you ticked the second checkbox. Legal basis: your consent, Article 6.1.a.
- For the weekly summary. It is sent only if you turn it on from your personal page, and is turned off from the same place. Legal basis: your consent, Article 6.1.a.
- To have a consultant contact you. Only if you ticked the first checkbox. Legal basis: your consent, Article 6.1.a.
- For security. The sending limit, technical cookies and server logs are used to protect access and prevent abuse. Legal basis: our legitimate interest in keeping the service secure, Article 6.1.f.
- To be able to demonstrate consent. The history described in section 2.2 exists because the Regulation requires us to prove that consent was given, in Article 7.1. Legal basis: legal obligation, Article 6.1.c.
We do not make any automated decision about you and do not carry out profiling.
4. Emails you may receive
We set them all out clearly, so that you know in advance what to expect.
- For everyone who signs up: the address verification code, the welcome email, three emails in the first seven days telling you where to start, the certificate email when you finish the course and the password reset when you request it.
- Only if you ticked the second checkbox: a reminder when you do not log in for thirty days.
- Only if you turn it on yourself: the Monday summary with your progress for the week.
You can turn off the Monday summary whenever you want from your personal page. To stop the others, or to withdraw either consent, write to info@manumagistro.it: we handle it manually, and from that moment you will no longer receive anything optional.
5. Cookies
We use only two cookies, both technical and necessary for the website to work. They do not require prior consent because the course cannot work without them.
- Session cookie. It contains the marker showing that you have logged in, so you do not have to log in again on every page. It lasts thirty days, can be read only by the server and not by the browser, and disappears when you log out.
- Form-protection cookie. It prevents another site from taking actions on your behalf while you are logged in. It lasts for the duration of the browser session.
There are no advertising cookies, third-party cookies or cookies that follow you elsewhere.
6. Who else sees your data
We do not sell, rent or transfer your data to anyone for commercial purposes. They are seen only by:
- The provider hosting the server and the provider delivering the emails. They process the data on our behalf, only to make the service work, and are bound by a contract requiring them to do so.
- A consultant from the Magistro network, but only if you ticked the first checkbox. In that case they receive your name, email, sector and city, and use them only to contact you and offer you the free website preview. If you did not tick the checkbox, no consultant receives your data.
- Anyone who has your certificate code. The certificate verification page is public and shows your name, code and date: it is used to allow a third party to check that the certificate is authentic. Only you have the code, and you decide whom to show it to.
- The judicial authority or the competent authorities, if a legal obligation requires us to do so.
Technical providers are listed in full, with their respective contracts, in the processing register. If processing involves a transfer outside the European Economic Area, it takes place only to countries covered by an adequacy decision of the European Commission or on the basis of standard contractual clauses, and you can request a copy by writing to the contact address.
7. How long we keep them
- Your account and its contents remain for as long as your account exists. If you ask us to close it, we delete your data within thirty days of the request.
- The consent history remains afterwards as well, because it is proof of a choice you made and is needed to defend both of us if one day someone disputes it. It contains your choice, the date and the text you saw.
- The certificate remains valid and verifiable afterwards as well, unless you ask us otherwise: that is the point of a certificate anyone can check.
- The technical server logs remain for the time needed for security and fault diagnosis, and are then overwritten.
There is no button in the course that deletes your account: we delete it manually when you ask us to, and confirm by email when it is done.
8. Your rights
The Regulation gives you rights that you can exercise at any time, free of charge.
- Access (Article 15): request a copy of the data we have about you.
- Rectification (Article 16): have anything that is wrong or incomplete corrected.
- Erasure (Article 17): request that your data be deleted.
- Restriction (Article 18): request that they remain frozen while a dispute is ongoing.
- Portability (Article 20): receive them in a format readable by another program.
- Objection (Article 21): object to processing we carry out based on our legitimate interest.
- Withdrawal of consent (Article 7.3): remove either of the two ticks at any time. What was done before remains lawful, but it stops from that moment onwards.
To exercise them, write to info@manumagistro.it. We reply within thirty days. If the request is complex, the deadline may be extended to ninety days, and in that case we will tell you first.
If you think that your data are being handled improperly, you can make a complaint to the Italian Data Protection Authority (garanteprivacy.it) or to the supervisory authority in the country where you live. You can do so without writing to us first, but a message to the address above is usually the quickest route.
9. How we protect data
- The connection to the website is encrypted with HTTPS.
- Passwords are stored only as a bcrypt fingerprint, with a high work factor: not even the person administering the system can read them.
- The session cookie cannot be read by the browser and is not sent to other websites.
- Forms are protected against requests created by third parties.
- The number of emails and login attempts is limited to stop anyone trying to guess a password or flood an inbox.
No measure makes a system secure forever. If a breach occurs that puts your rights at risk, we will tell you and notify the Italian Data Protection Authority, within the deadlines set out in Articles 33 and 34 of the Regulation.
10. Minors
The course is aimed at people who run a business, and therefore at adults. It is not intended for people under sixteen and we do not knowingly ask a minor for data. If you realise that this has happened, write to us and we will delete everything.
11. Artificial intelligence tools
The course teaches you to use artificial intelligence programs from other companies, such as ChatGPT, Gemini or Claude. When you use them, you use them directly, on their websites and with your own account: what you write in them does not pass through our servers and we do not see it. The relationship is between you and that company, under its rules.
What it is advisable never to write in those programs, starting with your customers' personal data, is explained in the page on the use of artificial intelligence.
12. Changes to this privacy notice
If the service changes or the law changes, this privacy notice changes with them. When the change affects something substantial, we will tell you by email at least fifteen days beforehand. The version in force is always this page, with the date at the top. The text of the consent checkboxes has its own recorded version: if it changes, the choices made before remain on record as they were.