Skip to content

Privacy Policy

Notice on the Processing of Personal Data collected through this website
Last revised: July 23, 2026

1. Introduction and regulatory references
This notice describes the processing of personal data collected through this website, including data acquired by means of cookies, tracking technologies and — where present — contact forms and any other features that may be active on the site.
This notice is addressed to anyone who accesses or uses this website, describing how the user’s personal data is collected, used and protected, as well as the rights granted by law.
These provisions do not concern other websites, pages or online services accessible through external links that may be present on the site, in respect of which you are invited to consult the relevant privacy notices.
This notice is provided in compliance with the principal national and international regulations on the protection of personal data, including:

  • Regulation (EU) 2016/679 (GDPR) and Directive 2002/58/EC, known as the ePrivacy Directive
  • UK General Data Protection Regulation (UK GDPR), Data Protection Act 2018, Privacy and Electronic Communications Regulations (PECR) and Data (Use and Access) Act 2025 (DUAA)
  • Swiss Federal Act on Data Protection (nFADP / FADP)
  • Canadian Personal Information Protection and Electronic Documents Act (PIPEDA)
  • Other regulations that may be applicable.

2. Who manages your data and how can you contact us?
Your personal data is processed by:
AMERICAN SCHOOLS ABROAD INC
Via del Carota 23/25 - 50012 Bagno a Ripoli (FI)
americanschoolsabroad@pec.it
VAT ID: IT04029390483

For any information concerning the processing of personal data or to exercise the rights granted by law, data subjects may contact the Data Protection Officer (DPO) appointed by the Data Controller.

The DPO can be reached at the following contact details:
Email: dpo@isfitaly.org

The DPO acts as a point of reference for matters relating to the protection of personal data, ensuring compliance with the applicable legal provisions and providing support to users and supervisory authorities.

3. On what legal bases do we process your data?
The processing of personal data collected through this site (including data collected by means of cookies, similar technologies, contact forms and any other features that may be active on the site) is based on one or more of the following legal bases:

  1. Performance of pre-contractual or contractual measures: where processing is necessary to respond to user requests, provide requested services and, where the site so provides, manage orders, accounts or contractual relationships.
  2. Compliance with legal obligations: where processing is necessary to comply with tax, accounting, administrative or security obligations or with requests from the authorities.

A further legal basis, the legitimate interest of the Data Controller, may be used for specific purposes (e.g. ensuring IT security, preventing fraud, protecting the Data Controller’s rights in legal proceedings).

Failure to accept or the withdrawal of consent may limit certain features or services of the site.

4. What data do we collect when you visit the site?
While browsing this site, the following data may be collected, including by means of cookies and similar technologies such as pixel tags, web beacons, local storage and equivalent technologies – namely:

  • Navigation and technical data: information such as IP address, device identifiers, data relating to the operating system and browser, requested URLs, connection times, technical logs, technical preferences, and usage data collected through cookies and tracking technologies (pixel tags, web beacons, local storage and equivalent tools).

  • Identifying data provided voluntarily: information entered in the digital forms on the site (e.g. first name, last name, e-mail, telephone) and/or provided by sending e-mails or through other contact channels, used to respond to requests, provide services and any consultations.

5. How do we process your data, how do we protect it and how long do we keep it?
The personal data collected through this site is processed mainly by electronic and digital means in accordance with the principles of lawfulness, fairness, data minimisation, integrity and confidentiality.

Appropriate technical and organisational measures are adopted to prevent unauthorised access, loss, alteration or unauthorised disclosure of data, including:

  • Encryption of communications (https): communications between your browser and the site are protected by HTTPS encryption, a measure aimed at reducing the risk of interception or manipulation of the data transmitted during browsing;
  • Log monitoring: the system records and monitors accesses and activities in order to detect suspicious or unauthorised attempts and ensure the security of the data;
  • Periodic backups: data is copied and stored periodically to protect it from any accidental loss or technical incidents;
  • Security audits and checks: security checks and tests are carried out regularly to identify and correct any system vulnerabilities;
  • Restriction of data access to duly authorised persons only: access to personal data is permitted exclusively to authorised and trained personnel, in compliance with internal security policies.

Data is retained according to the following timeframes:

  • Cookie preferences and consents: retained for 180 days, as set out in the Cookie Policy on this site.
  • Navigation and technical data: retained for the time strictly necessary for security purposes and, as a rule, no longer than 12 months, after which it is deleted or anonymised, save for longer periods imposed by legal obligations or by the need to establish, exercise or defend a right in legal proceedings.
  • Data connected to any contractual relationships established with the Data Controller: where they exist, it is retained for the duration of the relationship and, thereafter, for the time required by the applicable legal obligations (for example in accounting and tax matters).
  • Data entered through forms or specific requests: retained for the time necessary to respond to the request and to fulfil the related purpose, and thereafter for any period required by legal obligations.

6. Who can receive your data?
The following may access the personal data collected through this site, within the limits of their respective responsibilities and purposes:

  • Authorised internal persons designated by the Data Controller, duly instructed on privacy and security matters;
  • Suppliers and third parties appointed as Data Processors (for example: technical providers and IT services, site maintenance, e-mail providers, consultants, where applicable);
  • Third parties that provide services integrated into the site (e.g. fonts, maps, image display), which may process technical data as independent controllers in accordance with their own notices (in which case please also consult the individual notices of such third parties);
  • Competent public authorities and supervisory bodies, within the limits imposed by law or in order to comply with requests from the judicial authority;

The updated list of external recipients can be made available on request by writing to the Data Controller’s contact details.

7. Where can your data be transferred?
The personal data collected through this site may be processed within the European Union / European Economic Area. In some cases, the use of third-party services may involve a transfer to third countries. Where transfers to the United States take place, these are made to providers that adhere to the EU-US adequacy framework (Data Privacy Framework) or, failing that, on the basis of Standard Contractual Clauses.

For transfers subject to the UK GDPR, lawfulness is based on the United Kingdom’s adequacy decisions (for the United States, the UK Extension to the EU-US Data Privacy Framework, the so-called “UK-US Data Bridge”, limited to certified providers) or on appropriate safeguards such as the International Data Transfer Agreement (IDTA) or the UK Addendum to the Standard Contractual Clauses, subject to a transfer risk assessment based on the “data protection test” criterion (protection not materially lower than that of the United Kingdom).

Countries to which transfers may take place outside the European Economic Area: United States

8. What are your rights regarding the data collected?
The user, under the applicable legislation, has the right to:

  • Obtain confirmation as to whether or not personal data concerning them is being processed and, if so, obtain access to that data and the related information (right of access).
  • Request the rectification, updating or erasure of data that is inaccurate or no longer necessary (right to rectification and erasure).
  • Request the restriction of, or object to, the processing of data, including for promotional/profiling purposes, where provided for.
  • Request the portability of data in a structured and interoperable format (where technically possible).
  • Withdraw at any time any consent given, without affecting the lawfulness of processing based on consent carried out before the withdrawal (for example for the sending of commercial communications or newsletters, where active).
  • Withdraw the consent given to the use of non-technical cookies and to the processing of data collected through tracking tools.
  • Exercise the right to opt out of the “sale/sharing” of personal data, where provided for by US and Canadian laws.
  • Report any irregularities or abuses to the competent supervisory authorities.

To exercise these rights, it is sufficient to send a request to the Data Controller’s contact details. The Data Controller will respond without undue delay and, in any case, within one month of receiving the request, a period that may be extended by a further two months in the case of particular complexity or a high number of requests, in which case the data subject will be informed.

In the United Kingdom, the time limit for responding may be paused where the Data Controller reasonably requests the information needed to confirm the user’s identity or to clarify the subject of the request; the Data Controller carries out reasonable and proportionate searches in order to comply with access requests.

9. How is minors’ data processed?
The protection of minors is a fundamental priority.

This site is not directed at minors and does not intentionally collect their data through its forms. Where, in the context of a request or query, the user provides personal data relating to third parties — including any minors — they must ensure that they are authorised to do so; such data will be processed within the limits and for the purposes of the request, in compliance with the applicable legislation. For requests for rectification, restriction or erasure, you may write to the Data Controller’s contact details.

10. How can you make reports or complaints to the authorities?
If you believe that the processing of your personal data through this site does not comply with the applicable legislation, you may lodge a complaint free of charge with the competent supervisory Authorities, including:

For users in the United Kingdom, before approaching the competent supervisory authority, it is possible to lodge a complaint directly with the Data Controller, who will handle it according to a documented procedure and provide a response within the timeframes provided for by the applicable legislation.

11. How do we inform you of changes to this notice?
This notice is subject to periodic revision to reflect regulatory changes or modifications to the services offered through the site. Any significant change will be communicated through this page.
Last revised: July 23, 2026