Privacy Statement
Last updated: 03/06/2026
- Who We Are
Your Italian Trip, operated by Mirella Capece (“we”, “us”, “our”), is committed to protecting your personal data and respecting your privacy.
Data Controller
Mirella Capece
Your Italian Trip
Email: mirella.advisory@gmail.com
This Privacy Statement explains how we collect, use, store, and protect your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable Swedish data protection laws.
- What Personal Data We Collect
We may collect and process the following categories of personal data:
Information You Provide Directly
- Full name
- Email address
- Telephone number
- Billing and invoicing information
- Information submitted through contact forms
- Information contained in emails or other communications
- Language preferences and information relevant to the requested service
Booking and Service Information
When you book a session, we may collect:
- Booking details
- Appointment dates and times
- Attendance records
- Cancellation or rescheduling requests
- Payment status
- Service-related communications
Technical Information
When you visit our website, certain technical information may be processed automatically, including:
- IP address
- Browser type and version
- Device information
- Security-related information
- Cookie preferences
- Website usage information generated through cookies or similar technologies where applicable
For further details, please see our Cookie Policy.
- How We Obtain Your Personal Data
We obtain personal data:
- Directly from you when you contact us, submit an enquiry, or make a booking;
- Through communications relating to booked sessions;
- Through our website and cookie management system;
- Through service providers involved in delivering our services.
- Purposes and Legal Bases for Processing
We process personal data only where a lawful basis exists under Article 6 GDPR.
Purpose
Legal Basis
Responding to enquiries and communications
Legitimate Interest (Art. 6(1)(f))
Managing bookings and scheduling sessions
Contract Performance (Art. 6(1)(b))
Delivering conversation practice sessions
Contract Performance (Art. 6(1)(b))
Managing cancellations, rescheduling requests, and attendance records
Contract Performance (Art. 6(1)(b))
Issuing invoices and maintaining accounting records
Legal Obligation (Art. 6(1)(c))
Website security and fraud prevention
Legitimate Interest (Art. 6(1)(f))
Defending legal claims and enforcing contractual rights
Legitimate Interest (Art. 6(1)(f))
Managing cookie preferences and consent records
Legal Obligation and Consent
Where processing is based on consent, you may withdraw your consent at any time.
- Booking, Attendance, and Cancellation Records
To administer our services and comply with our Terms and Conditions, we may maintain records relating to:
- Session bookings
- Attendance
- Cancellations
- Rescheduling requests
- No-show events
- Payment status
- Service-related communications
These records are necessary to perform our contractual obligations, administer our cancellation policy, and establish, exercise, or defend legal claims where necessary.
- Third-Party Service Providers
We use trusted third-party providers to support our operations.
These providers may process personal data on our behalf only for the purposes described in this Privacy Statement and subject to appropriate contractual safeguards.
Examples include:
Google Meet
Online sessions are delivered through Google Meet.
When participating in online sessions, Google may process technical information such as:
- IP addresses
- Device information
- Connection metadata
Such processing is subject to Google’s own privacy practices.
Fortnox
Fortnox is used for invoicing, accounting, and financial administration.
Website Hosting and Technical Services
Our website hosting providers and technical service providers may process personal data necessary to operate and secure the website.
Security and Anti-Spam Services
Where used, security services such as Google reCAPTCHA help protect the website against abuse and fraudulent activity.
Third-Party Venues and Suppliers
Where a booked service requires a third-party venue or supplier, limited personal information may be shared when necessary to arrange the requested service.
We do not sell personal data to third parties.
- International Data Transfers
Some service providers may process personal data outside the European Economic Area (EEA).
Where such transfers occur, we ensure that appropriate safeguards are in place, including:
- European Commission adequacy decisions;
- Standard Contractual Clauses (SCCs);
- Other lawful transfer mechanisms permitted under GDPR.
You may contact us for additional information regarding these safeguards.
- Cookies and Similar Technologies
Our website uses cookies and similar technologies.
Some cookies are strictly necessary for website functionality, security, and user preferences.
Where non-essential cookies are used, they are activated only after obtaining the user’s consent through our cookie management platform.
For detailed information regarding:
- cookie categories;
- cookie retention periods;
- third-party cookies;
- consent management;
please consult our Cookie Policy.
The information contained in this Privacy Statement and our Cookie Policy is intended to be consistent and complementary.
- How Long We Retain Personal Data
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected.
Examples include:
Data Category
Retention Period
General enquiries
Up to 24 months
Booking and attendance records
Up to 3 years after the last session unless longer retention is required
Accounting and invoicing records
As required by Swedish accounting and tax legislation
Consent records
Until consent is withdrawn and for an appropriate period thereafter for compliance purposes
Legal claims documentation
For the duration necessary to establish, exercise, or defend legal claims
Retention periods may be extended where required by law.
- Consequences of Not Providing Personal Data
Certain personal data is necessary for us to provide our services.
If you choose not to provide information required for booking, invoicing, or communication purposes, we may be unable to provide the requested services.
- Your Rights Under GDPR
Under GDPR, you have the right to:
- Access your personal data;
- Request correction of inaccurate personal data;
- Request deletion of personal data in certain circumstances;
- Request restriction of processing;
- Object to processing based on legitimate interests;
- Request data portability where applicable;
- Withdraw consent at any time where processing is based on consent.
To exercise your rights, please contact us using the contact details provided above.
- Right to Lodge a Complaint
If you believe that your personal data has been processed in violation of applicable data protection laws, you have the right to lodge a complaint with a supervisory authority.
If the business is established in Sweden, the relevant supervisory authority is:
Integritetsskyddsmyndigheten (IMY)
Box 8114
104 20 Stockholm
SwedenYou may also contact the supervisory authority in your country of residence within the European Union.
- Data Security
We implement appropriate technical and organizational measures designed to protect personal data against:
- Unauthorized access;
- Loss;
- Misuse;
- Disclosure;
- Alteration;
- Destruction.
While no system can guarantee absolute security, we regularly review and update our security measures.
- Age Requirement
Our services are intended exclusively for adults aged 18 years and older.
We do not knowingly collect personal data from individuals under the age of 18.
If we become aware that personal data relating to a child has been collected inadvertently, we will take appropriate steps to delete such information.
- Changes to This Privacy Statement
We may update this Privacy Statement from time to time to reflect legal, technical, or operational developments.
The latest version will always be available on our website together with the effective date shown at the top of this document.