Website: www.syracuseacademy.org

Information notice: pursuant to Article 13 of EU Regulation 2016/679 (GDPR) and applicable Italian privacy law.

Last updated: 22 January 2026

1. Data Controller

Company name: The Academy Srl

VAT/Tax ID: IT00731730891

Registered address: Via San Giovanni alle Catacombe 7, Siracusa (SR), Italy

Legal representative: Ann Philomena Byrne

Contact email: privacy@academysiracusa.com

Phone: +39 0931 61424

2. Data Protection Officer (DPO)

DPO: Not appointed. For any request or information, please contact the Data Controller using the details above.

3. What personal data we collect

Data you provide via Website forms (contact/lead forms):

  • Name
  • Surname
  • Email
  • Phone / Telephone
  • Age
  • Nationality
  • Country / State
  • Gender

Data you provide via Typeform (if used):

  • Name
  • Surname
  • Email
  • Phone / Telephone
  • Age
  • Nationality
  • Country / State
  • Gender
  • Passport data (only if provided and required for admissions/administrative purposes)

Technical and usage data: IP address (or part of it), device identifiers, browser type, operating system, pages visited, time spent, referring pages, clicks and interactions, and similar usage data collected through cookies and similar technologies, subject to your preferences.

The Academy Srl processes personal data only for the purposes described below and does not resell personal data to third parties.

  • Handling enquiries and contact requests: to respond to information requests and messages submitted through forms. Legal basis: performance of pre-contractual measures and/or legitimate interest.
  • Registration, admissions and service management: to manage registration requests, admissions enquiries, reservations (if applicable), service delivery, assistance, complaints handling, and related administration. Legal basis: contract/pre-contractual measures and, where required, legal obligation.
  • Administrative, accounting and legal obligations: to comply with applicable laws and regulations. Legal basis: legal obligation.
  • Fraud prevention and security: to protect the Website, prevent abuse and ensure technical operation. Legal basis: legitimate interest.
  • Analytics (measurement and Website improvement): to understand Website performance and improve content and user experience using analytics tools. Legal basis: consent (for non-essential cookies/trackers).
  • Marketing and advertising measurement: to measure ad performance, run remarketing/retargeting and build audiences through advertising partners. Legal basis: consent (for marketing cookies/trackers).
  • Promotional activities on services/products similar to those requested or purchased (where applicable): limited to similar services and subject to your right to object. Legal basis: legitimate interest, where permitted by law.
  • Commercial promotion of different services/products (where applicable): via email, SMS or phone, only where you have provided consent and you may withdraw it at any time. Legal basis: consent.
  • Profiling (where applicable): analysis of interactions and preferences to propose commercial messages aligned with your interests, only if you provide explicit consent. Legal basis: consent.

5. Website structure and tools in use

CMS and theme: WordPress with Divi theme.

Primary purpose of the Website: lead generation and data collection through lead forms.

Tracking and measurement tools (subject to cookie preferences):

  • Google Site Kit (including Google Analytics)
  • Google Tag Manager
  • Meta/Facebook Pixel
  • Google Ads tags
  • TikTok tracking tools (if enabled)

Third-party functionalities that may process data:

  • Typeform forms
  • Gravatar (Automattic) for avatars, if enabled
  • YouTube embedded content

6. Scope of communication and recipients

Personal data may be communicated to third parties only when necessary for the purposes described above and/or to comply with legal obligations.

Categories of recipients may include:

  • Public bodies and authorities, where required by law
  • Consultants and service providers strictly connected to administrative, accounting, security, educational activities, and services related to reception and transportation (where applicable)
  • IT/hosting, maintenance, security and technical support providers
  • Analytics and advertising providers (only subject to consent where required)

External providers may act as data processors on behalf of the Data Controller or, in some cases, as independent controllers, depending on the service.

7. Transfer of personal data outside the EEA

Some third-party providers may process data outside the European Economic Area. Where applicable, transfers are carried out using appropriate safeguards required by GDPR (for example, Standard Contractual Clauses) and/or other legally recognised mechanisms.

8. Special categories of personal data

The Academy Srl does not request special categories of personal data (such as health data or data revealing racial or ethnic origin, religious beliefs, political opinions, etc.). If, for specific services, such data become necessary, you will receive prior notice and, where required, you will be asked to provide specific consent.

9. Methods of processing and retention

Processing is carried out using electronic and/or paper-based means, in compliance with the principles of lawfulness, fairness, transparency, purpose limitation and data minimisation.

Retention: personal data are kept for the time necessary to achieve the purposes for which they are collected and processed, and in any case according to applicable legal obligations.

  • Contacts/leads: retained for the time necessary to manage the request and follow-up activities, and in any case no longer than 36 months of inactivity, unless a longer retention is required due to an ongoing relationship or legal obligations.
  • Administrative/accounting data: retained according to legal obligations.
  • Marketing and profiling: retained until consent is withdrawn and in any case no longer than necessary for the purposes pursued.

Unnecessary data: if you send data not requested or not necessary, The Academy Srl will delete them as soon as possible.

10. What happens if you do not provide required data

Providing personal data is generally voluntary, but if you do not provide the data identified as necessary in the relevant form, the Data Controller may be unable to process your request, provide the requested information, or proceed with the requested service/admissions steps.

11. Your rights

You may exercise the rights provided by GDPR Articles 15 to 22, including:

  • to obtain confirmation as to whether personal data are being processed
  • to access your personal data
  • to request rectification of inaccurate data
  • to request deletion of data (where applicable)
  • to request restriction of processing
  • to object to processing, including for direct marketing
  • to request data portability (where applicable)
  • to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal
  • to lodge a complaint with the competent supervisory authority

How to exercise your rights: send a written request to The Academy Srl at the registered address or email privacy@academysiracusa.com.

12. Automated decision-making

The Academy Srl does not adopt automated decision-making processes producing legal effects on individuals, including profiling, unless you have provided explicit consent where applicable and unless such processing is specifically described at the time of collection.

This Website uses cookies and similar technologies to ensure technical functionality, measure performance and, subject to consent, deliver advertising and remarketing.

1. What cookies are

Cookies are small text files stored on your device when you visit a website. Similar technologies (pixels, tags, SDKs) may also collect information about your device and browsing behaviour.

  • Technical cookies (strictly necessary): required for core Website functionality and security.
  • Analytics cookies (optional): used to understand how visitors interact with the Website.
  • Marketing cookies (optional): used for advertising measurement, remarketing and audience building.
  • Third-party cookies (optional or conditional): set by third-party services integrated into the Website.

3. Cookies and third-party tools in detail

Technical cookies:

  • WordPress / Divi: cookies necessary to provide Website features and administration.
  • YouTube embedded content: technical cookies may be used to deliver video content; additional cookies may be set by YouTube depending on your interaction.

Analytics (subject to consent):

  • Google Analytics via Google Site Kit: helps us measure Website traffic and interactions.
  • Google Tag Manager: used to manage scripts and tags; it may deploy tags that set cookies depending on your consent choices.

Marketing/Advertising (subject to consent):

  • Meta/Facebook Pixel: conversion tracking, remarketing and ad performance measurement.
  • Google Ads: conversion measurement, remarketing and campaign optimisation.
  • TikTok: advertising measurement and remarketing tools (if enabled).

Third-party services:

  • Typeform: when you fill out a Typeform form, Typeform processes your submission data and may use cookies/trackers for service delivery and security.
  • Gravatar (Automattic): if enabled, may process identifiers to show avatars associated with email addresses.

You can accept, refuse, or customise cookies through the cookie banner shown on your first visit, and you can update your preferences at any time via the Website cookie settings.

Cookie settings link: [INSERT “Cookie Settings” LINK LOCATION, e.g., footer]

If you have consented to analytics or marketing cookies, you can withdraw your consent at any time by changing your cookie settings. Withdrawal does not affect processing already carried out before withdrawal.

6. Updates

We may update this Privacy & Cookie Policy to reflect changes in our processing activities, tools or legal requirements. The “Last updated” date will be revised accordingly.