Privacy policy
LAST UPDATED ON AUG 4, 2026
Introduction
This Privacy Policy explains how Ariel Heller ("I", "me", "my", or the "Data Controller") collects, uses, stores, and protects personal data when you visit arihell.it (the "Website"), contact me through the Website, or otherwise interact with the services provided through it.
I am committed to protecting your privacy and processing personal data in a transparent, fair, and lawful manner, in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and any other applicable data protection legislation.
This Privacy Policy applies exclusively to this Website unless otherwise stated.
Definitions
For the purposes of this Privacy Policy: "Personal Data" means any information relating to an identified or identifiable natural person as defined in Article 4(1) GDPR. "Processing" means any operation performed on Personal Data, whether or not by automated means, including collection, recording, storage, use, disclosure, or deletion. "Data Subject" means the individual to whom the Personal Data relates. "Data Controller" means the natural or legal person who determines the purposes and means of the processing of Personal Data. "Website" means arihell.it, including all of its pages and content. "Third Party" means any natural or legal person other than the Data Subject, the Data Controlle
1. Data Controller
The Data Controller responsible for the processing of personal data is:
Ariel Heller
Lungotevere di Pietra Papa, 159
00146 Rome (RM)
Italy
Email: arieheller@yahoo.com
For any questions regarding this Privacy Policy or the processing of your personal data, you may contact the Data Controller using the email address above.
2. Categories of Personal Data Collected
Depending on how you interact with the Website, I may collect and process different categories of personal data.
3. Personal Data Provided Voluntarily
When you choose to contact me through the contact form or by email, you may voluntarily provide information including:
first and last name;
email address;
company or organisation (where applicable);
any information contained in your message;
any additional information you choose to provide during our communications.
Providing this information is entirely voluntary; however, failure to provide the requested data may prevent me from responding to your enquiry.
Usage Data
When you browse the Website, certain information may be collected automatically to ensure the proper functioning, security, and performance of the Website.
This information may include:
IP address (processed where technically necessary);
browser type and version;
operating system;
device information;
language preferences;
pages visited;
referring website;
date and time of access;
interaction with Website content;
technical diagnostic information.
This information is generally collected in aggregated or anonymised form whenever possible and is not used to identify individual users unless required for security purposes or by law.
Data Collected Through Communications
If you communicate with me via email or through the Website, I may retain records of:
correspondence;
attachments voluntarily submitted;
follow-up communications;
information necessary to manage and respond to your request.
Such information is processed solely for purposes connected with the communication itself.
4. Purposes of Processing and Legal Bases
Personal data is processed only where a valid legal basis exists under the GDPR.
Depending on the circumstances, personal data may be processed for the following purposes.
Responding to Enquiries
Personal data submitted through the contact form or by email is processed to respond to requests, provide information, or continue communications initiated by the user.
Legal basis
Article 6(1)(b) GDPR – processing necessary to take steps at the request of the data subject prior to entering into a contract;
Article 6(1)(f) GDPR – legitimate interest in managing communications and professional enquiries.
Operating, Securing and Improving the Website
Technical and usage data may be processed to:
ensure the proper operation of the Website;
prevent malicious activity;
maintain Website security;
monitor technical performance;
improve usability and accessibility.
Legal basis
Article 6(1)(f) GDPR – legitimate interest in ensuring the security, reliability, and continuous improvement of the Website.
Compliance with Legal Obligations
Personal data may be processed where necessary to comply with applicable legal obligations, court orders, regulatory requirements, or requests from competent public authorities.
Legal basis
Article 6(1)(c) GDPR – compliance with a legal obligation.
Establishment, Exercise or Defence of Legal Claims
Where necessary, personal data may also be processed to establish, exercise, or defend legal claims.
Legal basis
Article 6(1)(f) GDPR – legitimate interest in protecting legal rights and interests.
5. Methods of Processing
Personal data is processed using appropriate technical and organisational measures designed to ensure a level of security appropriate to the risks involved.
Processing may be carried out using electronic, digital, or, where necessary, paper-based means and is limited to the purposes described in this Privacy Policy.
Access to personal data is restricted to persons or service providers who require such access for legitimate operational purposes and who are subject to appropriate confidentiality obligations where applicable.
6. Recipients of Personal Data
Personal data may be disclosed, where necessary and in accordance with applicable law, to carefully selected third parties acting on behalf of the Data Controller or independently where required for the provision of specific services.
Depending on the purposes described in this Privacy Policy, personal data may be shared with:
website hosting and infrastructure providers;
website development and maintenance providers;
providers of analytics and performance monitoring services;
email service providers;
professional advisers, including legal, accounting, or tax consultants, where disclosure is necessary;
competent judicial, administrative, or regulatory authorities where disclosure is required by law or necessary for the protection of legal rights.
These recipients process personal data only to the extent necessary for the performance of their respective services and, where required, under contractual arrangements ensuring compliance with applicable data protection legislation.
Personal data is never sold to third parties.
7. Website Analytics
The Website uses Framer Analytics to measure overall Website performance and visitor interactions.
According to Framer, this analytics solution is designed to operate without the use of cookies or persistent identifiers and provides aggregated statistical information regarding Website usage.
Analytics information may include:
page visits;
traffic sources;
browser and device categories;
approximate geographic region;
technical performance metrics.
The information collected is used exclusively to:
understand how visitors use the Website;
improve Website usability;
optimise performance;
identify technical issues.
Where required by applicable law, additional consent mechanisms will be implemented before introducing analytics technologies requiring user consent.
8. Contact Form
The Website provides a contact form through which users may voluntarily submit enquiries.
When submitting the contact form, users may be asked to provide personal information such as:
name;
email address;
organisation (where applicable);
message content.
This information is used exclusively for the purpose of responding to the enquiry and managing any related communications.
Messages submitted through the contact form are delivered directly to the Data Controller's email account and are not used for marketing purposes.
Providing personal data through the contact form is voluntary; however, failure to provide the requested information may prevent the Data Controller from responding.
9. External Content and Third-Party Services
The Website may incorporate content, resources, or technologies provided by third parties, including externally hosted fonts or similar resources necessary for the proper display and functionality of the Website.
When such resources are loaded, certain technical information—including the user's IP address and browser information—may be transmitted to the respective third-party provider as technically necessary to deliver the requested content.
The Website may also contain links to third-party websites or online services.
The Data Controller has no control over the privacy practices of such third parties and encourages users to consult the relevant privacy policies before using their services.
10. International Data Transfers
Some service providers used to operate the Website may process personal data outside the European Economic Area ("EEA"), the United Kingdom, or Switzerland.
Whenever personal data is transferred internationally, appropriate safeguards are implemented in accordance with Chapter V of the GDPR.
Such safeguards may include:
adequacy decisions adopted by the European Commission;
Standard Contractual Clauses approved by the European Commission;
any additional safeguards required under applicable law.
Users may request further information regarding international transfers by contacting the Data Controller.
11. Data Retention
Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected and to comply with applicable legal obligations.
Retention periods may vary depending on the category of data involved.
In particular:
contact requests are retained for the time necessary to respond to the enquiry and for a reasonable period thereafter in order to manage any related communications;
technical and analytics data is retained only for the period necessary to ensure Website functionality, security, and performance analysis;
correspondence may be retained where necessary to protect legal rights, comply with legal obligations, or maintain appropriate business records.
Once retention is no longer necessary, personal data is securely deleted, anonymised, or otherwise rendered permanently inaccessible unless further storage is required by law.
12. Security Measures
The Data Controller implements appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or unauthorised access.
Such measures are periodically reviewed and updated, taking into account:
the nature of the personal data processed;
the risks associated with the processing;
technological developments;
the cost and feasibility of implementation.
While reasonable efforts are made to protect personal data, no method of electronic transmission or storage can be guaranteed to be completely secure. Consequently, absolute security cannot be guaranteed.
13. Data Subject Rights
Under the General Data Protection Regulation (GDPR), you have the right to exercise the following rights in relation to your personal data, subject to the conditions and limitations established by applicable law.
You have the right to:
obtain confirmation as to whether or not your personal data is being processed;
request access to your personal data and receive a copy of the information held about you;
request the rectification of inaccurate or incomplete personal data;
request the erasure of your personal data where the applicable legal conditions are met;
request the restriction of processing in the circumstances provided for by Article 18 GDPR;
object, on grounds relating to your particular situation, to processing based on the Data Controller's legitimate interests;
receive the personal data you have provided in a structured, commonly used, and machine-readable format and, where technically feasible, request that it be transmitted to another controller (right to data portability);
withdraw your consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before its withdrawal;
lodge a complaint with the competent supervisory authority if you believe that the processing of your personal data infringes applicable data protection legislation.
If you are located in Italy, the competent supervisory authority is the Garante per la Protezione dei Dati Personali. Users residing in other jurisdictions may lodge a complaint with the supervisory authority competent in their country of residence or place of work.
14. How to exercise your rights
Requests relating to the exercise of your rights or questions concerning this Privacy Policy may be submitted at any time by contacting:
Ariel Heller
Email: ARIELHELLER@YAHOO.COM
Requests are processed without undue delay and, in any event, within the time limits established by the GDPR.
Where necessary, the Data Controller may request additional information to verify the identity of the individual submitting the request before providing access to personal data or taking further action.
15. Cookies
The Website may use technical technologies necessary for its operation and, where applicable, analytics technologies or third-party resources.
Detailed information regarding the use of cookies, similar technologies, and users' choices is available in the Cookie Policy, which forms an integral part of this Privacy Policy.
Where required by applicable law, cookies that are not strictly necessary for the operation of the Website will only be used after obtaining the user's prior consent.
16. Changes to this Privacy Policy
This Privacy Policy may be updated from time to time to reflect changes in applicable legislation, regulatory requirements, technological developments, or modifications to the services provided through the Website.
The most recent version will always be published on this page together with the date of the latest update.
Where required by law, users will be informed of material changes through appropriate means.
17. Contact Information
For any questions regarding this Privacy Policy or the processing of personal data, you may contact:
Ariel Heller
Lungotevere di Pietra Papa, 159
00146 Rome (RM)
Italy
Email: ARIELHELLER@YAHOO.COM
Legal Notice
This Privacy Policy applies exclusively to the processing of personal data carried out through arihell.it, unless otherwise specified.
Last updated: 4 August 2026.