Privacy policy
This page explains how we handle the personal data of people who visit this site, send a request through the contact form or sign up to the newsletter. It is written under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended by Italian Legislative Decree 101/2018 (the Italian Privacy Code).
The site is bilingual and speaks to people interested in buying restored farmhouses in Le Marche, in Italy and abroad. Here you will find what we collect, why we collect it, how long we keep it, who we share it with and what you can do about it.
Last updated: 3 September 2026.
Who handles your data
The data controller is the party that decides why and how data is handled. For this site that is:
- Company name: to be confirmed: full company name from the chamber of commerce record
- VAT number: to be confirmed: VAT number
- REA number and chamber of commerce: to be confirmed: REA number and chamber of commerce of registration
- Registered office: to be confirmed: full address of the registered office
- Email for privacy matters: to be confirmed: company email address for exercising data protection rights
- Telephone: to be confirmed: company telephone number
- Certified email (PEC): to be confirmed: certified email address (PEC)
- Contact person: Roberto Brasili
The items in square brackets have not yet been confirmed by the controller. While they stay this way, this page is published with a noindex instruction and should not be treated as final.
What data we collect
We collect only the data we need to let you browse the site, to reply to you and, if you agree, to understand how the site is used. We do not collect special categories of data, such as data about health, political opinions or religious beliefs, and we ask you not to put such data in the message field.
Browsing data and technical logs. When you open a page, the servers that host the site record technical data needed to run the site and keep it secure: IP address, date and time of the request, the page requested, browser and operating system type, and the outcome of the request. The IP address is also read from the x-forwarded-for header to apply an anti-abuse rate limit on the forms: that value stays in the server memory for the length of the rate limit window, which is one minute, and we do not store it anywhere else.
Contact form. On the Contact page we collect the following fields.
- Purpose of the request: a specific farmhouse, a site visit, a consultation
- The farmhouse you are interested in, if you arrive from a property page (optional)
- Budget range: under 150,000 euro, 150,000 to 300,000, 300,000 to 500,000, over 500,000
- Time frame: 3 months, 6 months, 12 months, just exploring
- First name (required)
- Last name (required)
- Email (required)
- Telephone (optional)
- Free-text message, up to 2,000 characters (optional)
- Browsing language, Italian or English
- The tick box confirming that you have read this page
The budget range and the time frame say something about what you can spend and when you intend to spend it. This is data that concerns you closely: we ask for it because it helps us see whether we can be useful to you and which properties to suggest, only the controller and the suppliers listed below can see it, and we do not use it to build profiles or to charge different people different prices.
The form also contains a hidden field called "website" which must stay empty. It is there to stop automated submissions: it is not data about you and it is not kept.
Newsletter. In the footer of every page you can sign up to the newsletter. In that case we collect only your email address.
Measurement. Google Analytics 4 and Meta Pixel are prepared in the site code, but they are loaded only if you choose to consent to the "measurement" category in the cookie banner. If you do not consent, the network request to those suppliers never starts: it is not just a cookie that is not written, it is the script that is never asked for.
Third-party content. Call booking through Calendly and the catalogue map from Mapbox sit behind a block with a preview and a "Show" button. Until you press that button, no data goes to those suppliers.
Why we handle it and on what legal basis
Every use of data has a purpose and a precise legal basis. The table sets them side by side, together with how long we keep the data.
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Replying to requests sent through the contact form, arranging site visits and consultations | Purpose, farmhouse of interest, budget range, time frame, first name, last name, email, telephone, message, language | Article 6(1)(b) GDPR: steps taken at your request before entering into a contract | to be confirmed: how many months to keep contact requests that do not lead to a negotiation |
| Managing the negotiation with people who decide to go ahead | The same data from the form, plus what you give us during the negotiation | Article 6(1)(b) GDPR: performance of a contract or pre-contractual steps | to be confirmed: retention periods for negotiation and sale files |
| Delivering to the company mailbox the email that carries your request | Content of the form, the email address you give | Article 6(1)(b) GDPR: sending the email is how your request reaches us | In the mailbox for the period given in the row above; at the sending provider, according to its own privacy notice |
| Sending the newsletter with new farmhouses and updates | Email address | Article 6(1)(a) GDPR: consent, which you can withdraw at any time | Until you withdraw consent or unsubscribe. to be confirmed: how long to keep proof of consent after withdrawal |
| Protecting the site from automated submissions and abuse, and keeping technical logs | IP address, date and time, page requested, browser data | Article 6(1)(f) GDPR: legitimate interest in keeping the site available and preventing abuse | IP address in the rate limit: one minute, in server memory. Hosting provider logs: according to Vercel's own periods |
| Making the site work, remembering the language you chose and your cookie choice | NEXT_LOCALE cookie, renovatio.consent local storage | Article 122 of the Italian Privacy Code: technical tools that are strictly necessary and need no consent; Article 6(1)(f) GDPR | NEXT_LOCALE: 1 year. renovatio.consent: 6 months, after which you are asked again |
| Measuring how the site is used and, where active, how campaigns perform | Measurement cookie identifiers, pages viewed, interaction events, technical device data | Article 6(1)(a) GDPR and Article 122 of the Italian Privacy Code: consent given through the banner and revocable | According to the lifetime of each cookie: _ga and _ga_<ID> 2 years, _gid 24 hours, _fbp 3 months |
| Loading the Calendly booking tool and the Mapbox map when you press "Show" | IP address and technical data of the request to the supplier, plus what you enter in the booking form | Article 6(1)(a) GDPR for loading the third-party content; Article 6(1)(b) for the booking you confirm | At the supplier, according to its own privacy notice linked below |
| Defending a legal claim and meeting legal obligations | The data needed in the specific case | Article 6(1)(f) GDPR for defending legal claims; Article 6(1)(c) GDPR for legal obligations, including tax ones | For as long as needed for the defence and, for tax and accounting documents, for the periods set by law |
How long we keep it
We keep data only for as long as it serves the purpose we collected it for, then we delete it or make it anonymous. The specific periods are in the table above.
Some periods depend on organisational choices that the controller still has to make: to be confirmed: retention policy for commercial contacts and negotiation files. Until they are set we give no number: we would rather leave the point open than write a period that is not true.
Documents that the law requires us to keep, such as invoices and accounting records, are kept for the periods set by tax and civil law, even after the relationship ends.
Who else sees your data
We do not sell data and we do not pass it to third parties for their own purposes. It is seen by the people who work for the controller and are authorised to handle it, and by the technical suppliers that make the service possible. Those suppliers act as processors under Article 28 GDPR, or as separate controllers where they decide the purposes of their own tools themselves.
| Supplier | What it does | Where | Privacy notice |
|---|---|---|---|
| Vercel Inc. | Hosts the site, serves the pages and records technical request logs | United States | vercel.com/legal/privacy-policy |
| Resend (Plus Five Five, Inc.) | Sends the transactional emails generated by the contact form | United States | resend.com/legal/privacy-policy |
| Calendly LLC | Provides call booking, loaded only if you press "Show" | United States | calendly.com/legal/privacy-notice |
| Mapbox Inc. | Provides the catalogue map, loaded only if you press "Show" | United States | www.mapbox.com/legal/privacy |
| Meta Platforms Ireland Ltd. | Linked Instagram profile and possible Meta Pixel, active only with your consent | Ireland, with transfers to the United States | www.facebook.com/privacy/policy |
| Google Ireland Ltd. | Possible Google Analytics 4, active only with your consent | Ireland, with transfers to the United States | policies.google.com/privacy |
The typefaces used on the site are served from our own domain: opening a page sends no request to Google Fonts or to any other external font service.
Data may also be shared with the professionals who assist the controller, for example accountants, lawyers or notaries, and with public authorities where the law requires it. to be confirmed: list of external professionals and collaborators who access contact data
Transfers outside the European Union
Some suppliers are based in the United States or transfer data there: Vercel, Resend, Calendly and Mapbox are United States companies; Google and Meta operate in Europe through their Irish entities but transfer data to the United States.
These transfers take place with the safeguards set out in Chapter V of the GDPR: where the supplier is certified under the EU-US Data Privacy Framework, on the basis of the European Commission adequacy decision of 10 July 2023; otherwise, on the basis of the standard contractual clauses approved by the European Commission under Article 46(2)(c) GDPR, together with the supplementary measures the supplier states it applies.
You can ask us for a copy of the safeguards in place by writing to the address given in the section on your rights.
Your rights
The GDPR gives you the following rights, which you can exercise free of charge.
- Access (Article 15): find out whether we handle data about you and get a copy of it, together with information about how it is used.
- Rectification (Article 16): correct inaccurate data and complete incomplete data.
- Erasure (Article 17): have data deleted when it is no longer needed, when you withdraw consent or when you successfully object to its use.
- Restriction (Article 18): ask that data be kept but not used, for example while we check whether it is accurate.
- Notification to recipients (Article 19): find out who we told about the rectification, erasure or restriction you obtained.
- Portability (Article 20): receive, in a machine-readable format, the data you gave us on the basis of consent or of a contract, and ask us to send it directly to another controller where that is technically possible.
- Objection (Article 21): object at any time to processing based on legitimate interest, and object without giving reasons where the processing is for direct marketing.
- Automated decisions (Article 22): not be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you. On this site we take no such decisions and we do no automated profiling.
- Withdrawal of consent (Article 7(3)): withdraw consent you have already given at any time, without affecting the lawfulness of what was done before you withdrew it.
To exercise these rights, write to to be confirmed: company email address for exercising data protection rights saying which right you want to exercise. We reply without undue delay and in any case within one month of your request; in complex cases the deadline can be extended by two months, and we then tell you within the first month, as Article 12 GDPR provides. If we cannot identify you from the details you give us, we may ask for further information.
To unsubscribe from the newsletter you can also use the link at the bottom of every email you receive.
Data protection officer
A data protection officer, or DPO, is required only in the cases set out in Article 37 GDPR. As things stand, no appointment appears to have been made and the assessment is still in progress: to be confirmed: confirm whether a DPO has been appointed and, if so, the name and contact details.
Until this point is settled, you can raise any question about personal data directly with the controller, using the contact details at the top of this page.
Complaint to a supervisory authority
If you believe that the handling of your data breaches the GDPR, you can lodge a complaint with the supervisory authority of the country where you live, where you work or where the alleged breach took place, under Article 77 GDPR.
In Italy the authority is the Garante per la protezione dei dati personali (Italian Data Protection Authority), Piazza Venezia 11, 00187 Rome — www.gpdp.it. Your right to go to court remains unaffected.
If you live in another EU country, for example Sweden or the Netherlands, you can contact the national supervisory authority of your own country.
Children
This site is aimed at adults interested in buying a property. We do not offer services directly to children and we do not knowingly collect data about people under the age of 16, which is the threshold set in Italy by Article 2-quinquies of the Italian Privacy Code for consent to information society services.
If you notice that a child has sent us their data, write to the address given in the section on your rights: we will delete it without undue delay.
Security
The site is served over HTTPS only. The forms have a rate limit per IP address and a hidden anti-spam field, and the emails generated by the form reach the company mailbox through the supplier listed in the suppliers table.
We apply technical and organisational measures that are appropriate under Article 32 GDPR. No measure, however, makes a transmission over the internet absolutely secure: please do not put identity documents, bank details or health information in the message field.
Changes to this page
We may update this page when the way we handle data, our suppliers or the law change. The date shown below is always the date of the latest published version.
If a change concerns something based on your consent, or substantially changes the purposes or the recipients, we ask for your consent again: for cookies through the banner, which reappears when the version of your saved choice no longer matches the current one; for the newsletter with a message to the email address you gave us. Minor changes, such as correcting a contact detail, are published here without a separate notice.
Last updated: 3 September 2026.