Privacy Policy
pursuant to EU Regulation 2016/679 – GDPR
1. Data Controller
The Data Controller of personal data is:
Full name: Paula Luise Goltzsche
Website: https://www.paulaluise.it
Contact email:
The Data Controller is the sole person with access to the collected personal data and undertakes to process such data in compliance with EU Regulation 2016/679 (GDPR).
2. Personal data processed
Pursuant to Article 4 of EU Regulation 2016/679, “personal data” means any information relating to an identified or identifiable natural person.
The personal data processed include:
first and last name
email address
any data required for invoicing purposes
payment data (processed via external platforms, with no direct access to full card details)
Browsing data
The computer systems and software procedures used to operate this website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols (such as IP addresses, browser type, access times).
Such data are used exclusively for anonymous statistical purposes and for security, and are deleted after processing, except where necessary to ascertain liability in the event of computer-related crimes.
3. Comments
When visitors leave comments on the website, the following data are collected:
the data entered in the comments form
the visitor’s IP address
the browser user agent
These data are collected solely to allow the publication of comments and to prevent spam.
An anonymized string (hash) of the email address may be provided to the Gravatar service.
The Gravatar privacy policy is available on Automattic’s websites.
After comment approval, the profile picture (if any) is publicly visible next to the comment.
4. Media
If images are uploaded to the website, users are advised to avoid uploading images containing embedded location data (EXIF GPS), as visitors may be able to extract such data.
5. Purposes of processing
Personal data are processed for the following purposes:
management of registrations for courses, workshops, events, and community activities
management of contractual and organizational relationships
compliance with legal, tax, and accounting obligations
informational communications related to the services offered
protection of contractual rights
anonymous statistical analysis of website usage
Promotional or informational email communications are sent only with explicit consent and may be withdrawn at any time.
6. Processing of special categories of data
The provision of sensitive data (such as health data, religious or philosophical beliefs, sexual orientation, or political opinions) is neither required nor encouraged.
Should such data be voluntarily provided by the data subject, they will be processed only with explicit consent and in compliance with the safeguards provided by the GDPR.
7. Cookies
The website uses technical cookies necessary for its proper functioning.
In particular:
cookies to save name, email, and website in comments (duration: 1 year)
temporary cookies to verify whether the browser accepts cookies
login cookies (duration up to 2 weeks if “Remember Me” is selected)
cookies for display preferences (duration: 1 year)
technical cookies related to publishing or editing content
Profiling cookies are not used without the user’s consent.
8. Embedded content from other websites
Articles on this website may include embedded content (e.g. videos, images, articles).
Embedded content from other websites behaves in the same way as if the visitor had visited those websites directly, which may collect data, use cookies, and integrate third-party tracking systems.
9. Disclosure to third parties
Personal data are not disclosed.
They may be communicated exclusively to external parties providing technical services essential to the operation of the website and the services offered, appointed as Data Processors, including:
hosting providers
email service providers
security services
Stripe for payment processing
If a password reset is requested, the user’s IP address will be included in the reset email.
10. Data processing for Yogamisù Safer Space (Momoyoga and Stripe)
For the management of registrations, bookings, and access to Yogamisù Safer Space services, the website is integrated with the Momoyoga platform, used for activity organization and user management.
Payments for Yogamisù Safer Space services are processed via Stripe, a platform compliant with EU Regulation 2016/679 (GDPR).
The Data Controller does not have direct access to full payment card details, which are processed exclusively by Stripe in its role as Data Processor.
Personal data processed at this stage may include:
first and last name
email address
information necessary to manage registration and access to services
payment-related data (processed exclusively by Stripe)
Momoyoga and Stripe process personal data solely for purposes related to the provision of the requested services and in compliance with applicable regulations.
Data are not transferred or disclosed to third parties other than those strictly necessary for the technical, administrative, and legal management of the service.
11. Data retention
comments and related metadata are retained indefinitely
registered user data (if any) are retained until a deletion request is made
administrative, tax, and accounting data are retained for up to 10 years, as required by applicable law
12. Nature of data provision
The provision of data is:
mandatory for contractual and legal purposes
optional for informational or promotional purposes
Failure to provide mandatory data will make it impossible to provide the requested services.
13. Data subject rights
The data subject may exercise at any time the rights provided for under Articles 15 et seq. of EU Regulation 2016/679, including:
access to personal data
rectification or erasure
restriction of or objection to processing
data portability
withdrawal of consent
lodging a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali)
Requests may be sent to: [email]
14. Data transfer
Data are processed predominantly within the European Union.
Visitor comments may be checked through an automated spam detection service.