Ricette, tecniche e storie dal laboratorio
Tutto Pasticceria

Privacy and Cookie Policy

Last updated: 20 July 2026.

This notice, provided under Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”), explains how personal data are processed through Tutto Pasticceria Magazine.

1. Controller and scope

The controller is SP QUALITY S.r.l., VAT no. 11043610010, Strada Cebrosa 25, 10036 Settimo Torinese (TO), Italy. Telephone: +39 011 040 0062. Privacy requests: [email protected].

This notice covers the Magazine. Following a link to tuttopasticceria.it takes you to a separate e-commerce site governed by its own privacy notice and terms.

2. Data, purposes and legal bases

Browsing, operation and security

Systems may record IP address, date and time, requested URL, referrer, browser, device and response status to display the site, diagnose errors, prevent abuse and protect services and users. The legal basis is the controller’s legitimate interest in operating and securing the Magazine (Article 6(1)(f) GDPR).

Contact requests

When you use the form, we process name, email, subject, message and necessary technical data to reply. The legal basis is taking steps at your request or providing the requested service (Article 6(1)(b)) and, for general correspondence, legitimate interest in managing and documenting communications (Article 6(1)(f)). The form does not automatically subscribe you to a newsletter.

Article comments

To publish and moderate a comment, we process display name, non-public email, optional website, text, date, IP address and user agent. Processing is necessary to provide the user-requested feature; moderation, security, spam prevention and protection against abuse also rely on legitimate interest (Articles 6(1)(b) and 6(1)(f)). The checkbox beside the form acknowledges this notice and is not marketing consent. Do not submit special-category data or unnecessary personal data about minors or third parties.

ActiveLayer anti-spam

Comments and forms are protected by ActiveLayer, a service provided by ActiveLayer LLC. To assess spam, the service may receive the submission content, name, email address, IP address, user agent, form and site metadata and, because the relevant options are enabled, technical signals about the environment and submission behaviour. The legal basis is the Controller’s legitimate interest in preventing spam and abuse (Article 6(1)(f) GDPR). Automated classification may approve, moderate or mark a submission as spam, without legal or similarly significant effects; contact us if a genuine message is blocked. See the ActiveLayer privacy notice.

Local preferences and external media

“Save article” uses tpm-saved-posts local storage until items or browser data are removed. Coupon dismissal uses tpm-coupon-dismissed-at for 30 days. These preferences remain on the device and do not create a server-side profile. YouTube or Vimeo videos are blocked until you choose to load them; the provider may then receive device and visit data under its own notice.

3. Cookies and similar technologies

The Magazine does not currently use profiling, behavioural advertising or analytics cookies. Polylang uses the technical pll_language cookie to remember the selected language for up to one year; its value is the language code and it is not used for profiling. WordPress may use technical session, security and authentication cookies for authorised users. If you select the optional checkbox below a comment, the browser may remember name, email and website for up to one year. The local storage described above supports user choices. Any future non-essential tool will require prior consent through a dedicated panel and an update to this notice.

4. Recipients and processors

Data may be handled by authorised staff and necessary providers of hosting and infrastructure, email/SMTP, maintenance, backup, security and anti-spam. Providers processing data on the controller’s behalf are bound under Article 28 GDPR where applicable. Data are not sold or shared for third parties’ own advertising. Disclosure to authorities or advisers may occur where required by law or to protect a right.

5. Transfers outside the EEA

ActiveLayer LLC may process data in the United States. Transfers outside the European Economic Area are subject to the safeguards stated by the provider, including standard contractual clauses where applicable; information and a copy of the safeguards may be requested from the Controller. After you voluntarily activate a video, the safeguards stated by the relevant provider also apply.

6. Retention

  • technical and security logs: as needed for operation and security, normally no more than 90 days unless an incident, authority request or legal claim requires longer;
  • contact requests: up to 12 months after closure, unless a contract, legal duty or dispute requires longer;
  • comments: IP address and user agent are anonymised after 90 days; email is removed or anonymised after 24 months; public name and text remain while the article is published or until a request compatible with freedom of expression, legal duties and third-party rights;
  • ActiveLayer: local verification records are automatically deleted after 30 days; detection data and logs retained by the provider may be kept for up to 90 days, unless the account is configured differently or legal or security needs require otherwise;
  • backups: until overwritten within the service’s technical rotation, with restricted access and restoration only when necessary.

7. Required data

Required fields are necessary to send a request or comment. Without them the relevant function is unavailable, but the Magazine remains readable. Optional data may be omitted.

8. Rights and complaints

You may request access, correction, erasure, restriction and applicable portability, and object to processing based on legitimate interests. Where processing is based on consent, it may be withdrawn without affecting earlier lawful processing. You may complain to the Italian Data Protection Authority. Email [email protected]; we normally respond within one month and may request reasonable identity verification.

9. Children

The Magazine is not intended to collect children’s data deliberately. A person with parental responsibility may ask us to remove data that may have been submitted.

10. Security and updates

Risk-appropriate measures include updates, access controls, data minimisation, backups and anti-spam protection. No system is risk-free. This page is updated when services or processing change; the date above identifies the current version.