Privacy Statement

Privacy Statement

Last updated: 03/06/2026

  1. Who We Are

Your Italian Trip, operated by Mirella Capece (“we”, “us”, “our”), is committed to protecting your personal data and respecting your privacy.

Data Controller

Mirella Capece
Your Italian Trip
Email: mirella.advisory@gmail.com


This Privacy Statement explains how we collect, use, store, and protect your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable Swedish data protection laws.

  1. What Personal Data We Collect

We may collect and process the following categories of personal data:

Information You Provide Directly

  • Full name
  • Email address
  • Telephone number
  • Billing and invoicing information
  • Information submitted through contact forms
  • Information contained in emails or other communications
  • Language preferences and information relevant to the requested service

Booking and Service Information

When you book a session, we may collect:

  • Booking details
  • Appointment dates and times
  • Attendance records
  • Cancellation or rescheduling requests
  • Payment status
  • Service-related communications

Technical Information

When you visit our website, certain technical information may be processed automatically, including:

  • IP address
  • Browser type and version
  • Device information
  • Security-related information
  • Cookie preferences
  • Website usage information generated through cookies or similar technologies where applicable

For further details, please see our Cookie Policy.

  1. How We Obtain Your Personal Data

We obtain personal data:

  • Directly from you when you contact us, submit an enquiry, or make a booking;
  • Through communications relating to booked sessions;
  • Through our website and cookie management system;
  • Through service providers involved in delivering our services.
  1. Purposes and Legal Bases for Processing

We process personal data only where a lawful basis exists under Article 6 GDPR.

Purpose

Legal Basis

Responding to enquiries and communications

Legitimate Interest (Art. 6(1)(f))

Managing bookings and scheduling sessions

Contract Performance (Art. 6(1)(b))

Delivering conversation practice sessions

Contract Performance (Art. 6(1)(b))

Managing cancellations, rescheduling requests, and attendance records

Contract Performance (Art. 6(1)(b))

Issuing invoices and maintaining accounting records

Legal Obligation (Art. 6(1)(c))

Website security and fraud prevention

Legitimate Interest (Art. 6(1)(f))

Defending legal claims and enforcing contractual rights

Legitimate Interest (Art. 6(1)(f))

Managing cookie preferences and consent records

Legal Obligation and Consent

Where processing is based on consent, you may withdraw your consent at any time.

  1. Booking, Attendance, and Cancellation Records

To administer our services and comply with our Terms and Conditions, we may maintain records relating to:

  • Session bookings
  • Attendance
  • Cancellations
  • Rescheduling requests
  • No-show events
  • Payment status
  • Service-related communications

These records are necessary to perform our contractual obligations, administer our cancellation policy, and establish, exercise, or defend legal claims where necessary.

  1. Third-Party Service Providers

We use trusted third-party providers to support our operations.

These providers may process personal data on our behalf only for the purposes described in this Privacy Statement and subject to appropriate contractual safeguards.

Examples include:

Google Meet

Online sessions are delivered through Google Meet.

When participating in online sessions, Google may process technical information such as:

  • IP addresses
  • Device information
  • Connection metadata

Such processing is subject to Google’s own privacy practices.

Fortnox

Fortnox is used for invoicing, accounting, and financial administration.

Website Hosting and Technical Services

Our website hosting providers and technical service providers may process personal data necessary to operate and secure the website.

Security and Anti-Spam Services

Where used, security services such as Google reCAPTCHA help protect the website against abuse and fraudulent activity.

Third-Party Venues and Suppliers

Where a booked service requires a third-party venue or supplier, limited personal information may be shared when necessary to arrange the requested service.

We do not sell personal data to third parties.

  1. International Data Transfers

Some service providers may process personal data outside the European Economic Area (EEA).

Where such transfers occur, we ensure that appropriate safeguards are in place, including:

  • European Commission adequacy decisions;
  • Standard Contractual Clauses (SCCs);
  • Other lawful transfer mechanisms permitted under GDPR.

You may contact us for additional information regarding these safeguards.

  1. Cookies and Similar Technologies

Our website uses cookies and similar technologies.

Some cookies are strictly necessary for website functionality, security, and user preferences.

Where non-essential cookies are used, they are activated only after obtaining the user’s consent through our cookie management platform.

For detailed information regarding:

  • cookie categories;
  • cookie retention periods;
  • third-party cookies;
  • consent management;

please consult our Cookie Policy.

The information contained in this Privacy Statement and our Cookie Policy is intended to be consistent and complementary.

  1. How Long We Retain Personal Data

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected.

Examples include:

Data Category

Retention Period

General enquiries

Up to 24 months

Booking and attendance records

Up to 3 years after the last session unless longer retention is required

Accounting and invoicing records

As required by Swedish accounting and tax legislation

Consent records

Until consent is withdrawn and for an appropriate period thereafter for compliance purposes

Legal claims documentation

For the duration necessary to establish, exercise, or defend legal claims

Retention periods may be extended where required by law.

  1. Consequences of Not Providing Personal Data

Certain personal data is necessary for us to provide our services.

If you choose not to provide information required for booking, invoicing, or communication purposes, we may be unable to provide the requested services.

  1. Your Rights Under GDPR

Under GDPR, you have the right to:

  • Access your personal data;
  • Request correction of inaccurate personal data;
  • Request deletion of personal data in certain circumstances;
  • Request restriction of processing;
  • Object to processing based on legitimate interests;
  • Request data portability where applicable;
  • Withdraw consent at any time where processing is based on consent.

To exercise your rights, please contact us using the contact details provided above.

  1. Right to Lodge a Complaint

If you believe that your personal data has been processed in violation of applicable data protection laws, you have the right to lodge a complaint with a supervisory authority.

If the business is established in Sweden, the relevant supervisory authority is:

Integritetsskyddsmyndigheten (IMY)
Box 8114
104 20 Stockholm
Sweden

You may also contact the supervisory authority in your country of residence within the European Union.

  1. Data Security

We implement appropriate technical and organizational measures designed to protect personal data against:

  • Unauthorized access;
  • Loss;
  • Misuse;
  • Disclosure;
  • Alteration;
  • Destruction.

While no system can guarantee absolute security, we regularly review and update our security measures.

  1. Age Requirement

Our services are intended exclusively for adults aged 18 years and older.

We do not knowingly collect personal data from individuals under the age of 18.

If we become aware that personal data relating to a child has been collected inadvertently, we will take appropriate steps to delete such information.

  1. Changes to This Privacy Statement

We may update this Privacy Statement from time to time to reflect legal, technical, or operational developments.

The latest version will always be available on our website together with the effective date shown at the top of this document.