Last updated: 21 July 2026.
This notice, provided under Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”), explains how personal data are processed through Tutto Pasticceria Magazine.
1. Controller and scope
The controller is SP QUALITY S.r.l., VAT no. 11043610010, Strada Cebrosa 25, 10036 Settimo Torinese (TO), Italy. Telephone: +39 011 040 0062. Privacy requests: [email protected].
This notice covers the Magazine. Following a link to tuttopasticceria.it takes you to a separate e-commerce site governed by its own privacy notice and terms.
2. Data, purposes and legal bases
Browsing, operation and security
Systems may record IP address, date and time, requested URL, referrer, browser, device and response status to display the site, diagnose errors, prevent abuse and protect services and users. The legal basis is the controller’s legitimate interest in operating and securing the Magazine (Article 6(1)(f) GDPR).
Contact requests
When you use the form, we process name, email, subject, message and necessary technical data to reply. The legal basis is taking steps at your request or providing the requested service (Article 6(1)(b)) and, for general correspondence, legitimate interest in managing and documenting communications (Article 6(1)(f)). The form does not automatically subscribe you to a newsletter.
Article comments
To publish and moderate a comment, we process display name, non-public email, optional website, text, date, IP address and user agent. Processing is necessary to provide the user-requested feature; moderation, security, spam prevention and protection against abuse also rely on legitimate interest (Articles 6(1)(b) and 6(1)(f)). The checkbox beside the form acknowledges this notice and is not marketing consent. Do not submit special-category data or unnecessary personal data about minors or third parties.
Local anti-spam protection
Comments and forms undergo anti-spam checks performed locally within the Magazine’s WordPress installation. To detect abuse, the filter temporarily assesses a hidden field, completion time, number of links, repeated content and submission frequency through a pseudonymous identifier derived from the IP address. The anti-spam filter does not retain message text, name, email address, IP address or user agent; only aggregate counters remain, while technical identifiers and duplicate fingerprints expire within one hour and fifteen minutes respectively. Processing is based on the Controller’s legitimate interest in preventing spam and abuse (Article 6(1)(f) GDPR). A submission may be marked as spam, without legal or similarly significant effects; contact us if a genuine message is blocked. The content is not sent to an external anti-spam provider.
Local preferences and external media
“Save article” uses tpm-saved-posts local storage until items or browser data are removed. Coupon dismissal uses tpm-coupon-dismissed-at for 30 days. These preferences remain on the device and do not create a server-side profile. YouTube or Vimeo videos are blocked until you choose to load them; the provider may then receive device and visit data under its own notice.
Audience measurement with Google Analytics 4
We use Google Analytics 4, a service provided by Google Ireland Limited, only after you have given consent, to produce statistics on use of the Magazine and understand which content is most useful. Processing may cover pseudonymous online identifiers, pages viewed, referral source, language, content type, permitted interactions, browser and device information and approximate location. For users in the European Economic Area, Google states that it uses the IP address to derive approximate location and discards it before logging. We do not send Google your name, email address, form or comment content, User-ID or other directly identifying data.
The legal basis is consent (Article 6(1)(a) GDPR and applicable rules on terminal equipment). The tag remains blocked until you accept the “Measurement and analytics” category. You may refuse or withdraw your choice at any time through “Manage cookie preferences”, without affecting processing already carried out lawfully. Google Signals, advertising features, ads personalisation and cross-domain session linking with the shop are not enabled.
3. Cookies and similar technologies
The Magazine does not use profiling cookies or behavioural advertising. Google Analytics 4 loads only after consent to the “Measurement and analytics” category; refusal does not restrict access to the site. Polylang uses the necessary pll_language cookie to remember the selected language for up to one year. WordPress may use necessary session, security and authentication cookies for authorised users. If you select the optional box below a comment, the browser may remember your name, email and website for up to one year. The local storage items described above support user-requested features.
Your choice is stored in the necessary tpm_privacy_consent cookie for 180 days. After Analytics consent, GA4 may set the first-party _ga cookie to distinguish users pseudonymously and _ga_<id> to maintain session state, by default for up to two years and subject to browser limits. Refusal or withdrawal prevents new Analytics events; withdrawal removes GA4 cookies accessible to the Magazine.
4. Recipients and processors
Data may be handled by authorised staff and necessary providers of hosting and infrastructure, email/SMTP, maintenance, backup, security and anti-spam. Providers processing data on the controller’s behalf are bound under Article 28 GDPR where applicable. Data are not sold or shared for third parties’ own advertising. Disclosure to authorities or advisers may occur where required by law or to protect a right.
For Analytics, Google Ireland Limited acts as a processor under the terms applicable to the service. Data may be handled by other group companies and subprocessors listed by Google. Transfers outside the EEA rely on Google’s applicable contractual safeguards, including standard contractual clauses, or an applicable adequacy decision. Information about safeguards may be requested from the controller.
5. Transfers outside the EEA
The local anti-spam filter does not involve transfers to external providers. After you voluntarily activate a video, the relevant provider may process data outside the European Economic Area under the safeguards described in its own notice.
6. Retention
- technical and security logs: as needed for operation and security, normally no more than 90 days unless an incident, authority request or legal claim requires longer;
- contact requests: up to 12 months after closure, unless a contract, legal duty or dispute requires longer;
- comments: IP address and user agent are anonymised after 90 days; email is removed or anonymised after 24 months; public name and text remain while the article is published or until a request compatible with freedom of expression, legal duties and third-party rights;
- local anti-spam: pseudonymous rate-limit identifiers for up to one hour; pseudonymous duplicate fingerprints for 15 minutes; aggregate counters without message text, email, IP address or user agent retained for technical monitoring and deleted when no longer useful;
- backups: until overwritten within the service’s technical rotation, with restricted access and restoration only when necessary.
- Google Analytics 4: event-level data are currently retained for 2 months and user data for 14 months; aggregated reports may remain available for longer as part of the service. GA4 cookies expire by default after up to two years, unless you refuse or withdraw consent, delete them or the browser applies a shorter limit;
7. Required data
Required fields are necessary to send a request or comment. Without them the relevant function is unavailable, but the Magazine remains readable. Optional data may be omitted.
8. Rights and complaints
You may request access, correction, erasure, restriction and applicable portability, and object to processing based on legitimate interests. Where processing is based on consent, it may be withdrawn without affecting earlier lawful processing. You may complain to the Italian Data Protection Authority. Email [email protected]; we normally respond within one month and may request reasonable identity verification.
9. Children
The Magazine is not intended to collect children’s data deliberately. A person with parental responsibility may ask us to remove data that may have been submitted.
10. Security and updates
Risk-appropriate measures include updates, access controls, data minimisation, backups and anti-spam protection. No system is risk-free. This page is updated when services or processing change; the date above identifies the current version.
