DONATE →
Version p0-default · Updated on 2026-05-25

Privacy Policy

How Strongers collects, processes and protects personal data.

1. Who we are (Data Controller)

Strongers Social Club ETS is the data controller for data collected via strongers.org and connected services. For any privacy question contact us directly.

  • Titolare del trattamento: Strongers Social Club ETS
  • Sede legale: Via Ruggero Fiore 38, 00136 Roma (RM)
  • CF: 96564050589 · P.IVA: 17380961007
  • RUNTS Rep.: 122206
  • Contatto privacy: privacy@strongers.org

2. Processing purposes and legal basis

We process your data only for clear purposes declared below. Each processing has a specific legal basis (art. 6 GDPR) and a defined retention period.

Purpose Data collected Legal basis Retention
Newsletter (eventi, bandi ricerca, magazine) Nome, email Consenso (art. 6.1.a GDPR) Fino a revoca + 30gg cancellazione
Donazioni (carta, PayPal, IBAN, 5×1000) Nome, email, importo, dati pagamento (gestiti da Stripe/PayPal) Esecuzione contratto (art. 6.1.b) + obblighi fiscali (art. 6.1.c) 10 anni (obblighi fiscali ETS)
Iscrizione eventi sportivi Nome, cognome, email, telefono, dati evento Esecuzione contratto (art. 6.1.b) 5 anni dalla partecipazione
Form contatto / partnership Nome, email, messaggio Legittimo interesse a rispondere (art. 6.1.f) 24 mesi
Analytics anonimizzato (Matomo on-prem) IP anonimizzato (ultimi 16 bit), URL visitate Consenso (art. 6.1.a) 14 mesi (Matomo default)
Tracciamento attribuzione (cookie _st_attr) Session token anonimo, sorgente, campagna Consenso (art. 6.1.a) 30 giorni

3. Legal bases for processing

Our legal bases are: (a) your explicit consent for newsletter and analytics; (b) contract performance for donations and event registrations; (c) legal obligations for retention of donation receipts (10 years); (f) legitimate interest in responding to messages you send us spontaneously.

4. Recipients and processors

To provide the site services we rely on external providers appointed as processors under art. 28 GDPR. All are European or comply with EU adequacy standards:

  • Stripe Payments Europe Ltd. (Dublino) — processing pagamenti carta. Privacy Stripe
  • PayPal (Europe) S.à r.l. et Cie, S.C.A. (Lussemburgo) — processing pagamenti PayPal. Privacy PayPal (caricato solo on-intent, vedi §7)
  • Brevo (Sendinblue SAS) (Parigi) — invio newsletter e transactional email. Privacy Brevo
  • Matomo (self-hosted Hetzner GmbH, Falkenstein DE) — analytics anonimizzato, dati su server europei sotto controllo Strongers
  • Hetzner Online GmbH (Germania) — hosting infrastruttura. Server EU-only, sub-processor minimi.

We do not transfer your data outside the European Economic Area (EEA). All providers operate EU servers.

5. Retention periods

We keep your data only as long as necessary for the declared purposes. When the period expires, data is irreversibly deleted or anonymized. See the 'Retention' column of the processing table.

6. Your GDPR rights

GDPR guarantees you full control over your data. You can exercise the following rights at any time, free of charge.

How to exercise your rights

You can exercise any right below by simply sending an email. No complex forms required.

  • Diritto di accesso (art. 15) — sapere quali dati trattiamo
  • Diritto di rettifica (art. 16) — correggere dati inesatti
  • Diritto alla cancellazione / oblio (art. 17) — far rimuovere i tuoi dati
  • Diritto di limitazione (art. 18) — sospendere il trattamento
  • Diritto alla portabilità (art. 20) — ricevere i tuoi dati in formato leggibile
  • Diritto di opposizione (art. 21) — opporsi al trattamento basato su interesse legittimo
  • Revoca del consenso (art. 7.3) — ritirare il consenso in qualsiasi momento

📧 Come esercitare: scrivi a privacy@strongers.org indicando il diritto che vuoi esercitare. Risposta garantita entro 30 giorni.

You always have the right to lodge a complaint with the Italian Data Protection Authority: Garante Privacy.

8. Security

Data is protected by mandatory HTTPS, email hashing for anonymous matching, versioned consent audit trail. Passwords follow the Argon2id standard. Infrastructure is hosted in Germany (Hetzner) under direct Strongers control, with no undisclosed external sub-processors.

9. Changes to this policy

When we update this policy we publish a new version with the update date. If changes are substantial and concern consent-based processing, we will ask you again to confirm your preferences.

Versione attuale: p0-default · Last update: 2026-05-25