DONATE →
Automated translation under legal review. In case of discrepancy, the Italian version prevails.
Version p1-2026-06-29 · Updated on 2026-07-27

Privacy Policy

How Strongers collects, processes and protects personal data.

1. Who we are (Data Controller)

Strongers Social Club ETS is the data controller for data collected via strongers.org and connected services. For any privacy question contact us directly.

  • Data Controller: Strongers Social Club ETS
  • Registered office: Via Ruggero Fiore 38, 00136 Roma (RM)
  • CF: 96564050589 · P.IVA: 17380961007
  • RUNTS Rep.: 122206
  • Privacy contact: info@strongersc.com

2. Processing purposes and legal basis

We process your data only for clear purposes declared below. Each processing has a specific legal basis (art. 6 GDPR) and a defined retention period.

Purpose Data collected Legal basis Retention
Newsletter (events, research grants, magazine) Name, email Consent (Art. 6.1.a GDPR) Until withdrawal + 30-day deletion
Donations (card, PayPal, IBAN, 5×1000) Name, email, amount, payment data (handled by Stripe/PayPal) Contract performance (Art. 6.1.b) + tax obligations (Art. 6.1.c) 10 years (ETS tax obligations)
Sports event registration First name, last name, email, phone, event data Contract performance (Art. 6.1.b) 5 years from participation
Contact / partnership form Name, email, message Legitimate interest in replying (Art. 6.1.f) 24 months
Anonymised analytics (Matomo on-prem) Anonymised IP (last 16 bits), visited URLs Consent (Art. 6.1.a) 14 months (Matomo default)
Attribution tracking (_st_attr cookie) Anonymous session token, source, campaign Consent (Art. 6.1.a) 30 days
"Attributed Citation" / Research Watch cards (public clinical trial registries) Only structured factual fields from the registry; no individual personal data (investigators/contacts/sites excluded) Legitimate interest (Art. 6.1.f) — attributed scientific information As long as the content is published; removed upon change/withdrawal of the source
Email communication personalisation (subject/content adapted per segment) Engagement with our emails (opens, clicks), language, audience segment Legitimate interest (Art. 6(1)(f)) Until promo consent withdrawal / objection under Art. 21
Email tracking (opens and clicks in campaigns) Open pixel, clicks on tracked links, user-agent, date and time Consent (Art. 6(1)(a) GDPR + Art. 122 Italian Privacy Code) Until consent is withdrawn
Anti-bot protection of public forms (Cloudflare Turnstile) IP address, technical browser signals, verification token Legitimate interest (Art. 6(1)(f)) — preventing abuse and spam Data processed by Cloudflare only for the verification; nothing stored by Strongers

2.1 "Attributed Citation" information cards (Research Watch)

We publish "Attributed Citation" information cards reporting facts recorded in public clinical-trial registries (initial version: ClinicalTrials.gov), in attributed form and with a link to the source. We process only structured factual fields (study code, phase, status, condition, intervention, dates, enrolment) and do not store or publish investigators, contacts, e-mails, clinical sites or individual officials. Any processing of publicly available professional personal data is residual and incidental and relies on legitimate interest (Art. 6(1)(f) GDPR) in accurate attributed scientific information and source verifiability, in compliance with data minimisation. No health data of identified individuals is processed (Art. 9 GDPR does not apply) and there is no profiling. You may object to the processing at any time by writing to info@strongersc.com (reply within 30 days).

2.2 Communication personalisation

To make our communications more relevant, we may adapt the subject and content of emails (newsletter, campaigns) based on your level of interaction with our previous messages (opens, clicks — collected only if you have granted consent to email tracking, see §2.3) and your audience segment. This personalisation relies on legitimate interest (Art. 6(1)(f) GDPR) in communicating effectively; it is based solely on your interaction with our emails — no cross-site tracking, no special categories (Art. 9), no automated decisions with legal effects (Art. 22). You can object at any time (Art. 21) by writing to info@strongersc.com or by disabling promotional communications: objecting also disables personalisation.

2.3 Email tracking (opens and clicks)

Our campaign emails may include an open pixel and tracked links that let us measure whether a message was opened and which links were clicked. This tracking is off by default and is enabled only with your explicit consent (Art. 6(1)(a) GDPR and Art. 122 of the Italian Privacy Code, in line with European authorities' guidance, including the Garante and the CNIL). Without your consent we insert no pixel, do not rewrite links, and no open or click is recorded. You can grant or withdraw this consent at any time from the preference centre, reachable via the link in the footer of every email. Withdrawal takes effect immediately: even already-sent emails stop being tracked. Email tracking is independent of your subscription: you can turn it off and still receive newsletters and events.

3. Legal bases for processing

Our legal bases are: (a) your explicit consent for newsletter, analytics and email tracking; (b) contract performance for donations and event registrations; (c) legal obligations for retention of donation receipts (10 years); (f) legitimate interest in responding to messages you send us spontaneously and in personalising email communications based on your engagement with our messages, where you have granted consent to email tracking (§2.3).

4. Recipients and processors

To provide the site services we rely on external providers appointed as processors under art. 28 GDPR. All are European or comply with EU adequacy standards:

  • Stripe Payments Europe Ltd. (Dublin) — card payment processing. Stripe Privacy
  • PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg) — PayPal payment processing. PayPal Privacy (loaded only on-intent, see §7)
  • Brevo (Sendinblue SAS) (Paris) — newsletter and transactional email delivery. Brevo Privacy
  • Matomo (self-hosted, Hetzner GmbH, Falkenstein DE) — anonymised analytics, data on European servers under Strongers' control
  • Hetzner Online GmbH (Germany) — infrastructure hosting. EU-only servers, minimal sub-processors.
  • Cloudflare, Inc. — anti-bot verification (Turnstile) on public forms: processes IP address and technical browser signals to tell people apart from bots. Certified under the EU-U.S. Data Privacy Framework. Cloudflare Privacy

We do not transfer your data outside the European Economic Area (EEA): the providers listed above operate EU servers, with one exception — the Cloudflare Turnstile anti-bot verification may process your IP address on Cloudflare's global infrastructure, safeguarded by the EU-U.S. Data Privacy Framework and standard contractual clauses (Art. 46 GDPR).

5. Retention periods

We keep your data only as long as necessary for the declared purposes. When the period expires, data is irreversibly deleted or anonymized. See the 'Retention' column of the processing table.

6. Your GDPR rights

GDPR guarantees you full control over your data. You can exercise the following rights at any time, free of charge.

How to exercise your rights

You can exercise any right below by simply sending an email. No complex forms required.

  • Right of access (Art. 15) — know which data we process
  • Right to rectification (Art. 16) — correct inaccurate data
  • Right to erasure / to be forgotten (Art. 17) — have your data removed
  • Right to restriction (Art. 18) — suspend the processing
  • Right to data portability (Art. 20) — receive your data in a readable format
  • Right to object (Art. 21) — object to processing based on legitimate interest
  • Withdrawal of consent (Art. 7.3) — withdraw consent at any time

📧 How to exercise: write to info@strongersc.com stating the right you wish to exercise. Response guaranteed within 30 days.

You always have the right to lodge a complaint with the Italian Data Protection Authority: Garante Privacy.

8. Security

Data is protected by mandatory HTTPS, email hashing for anonymous matching, versioned consent audit trail. Passwords follow the Argon2id standard. Infrastructure is hosted in Germany (Hetzner) under direct Strongers control, with no undisclosed external sub-processors.

9. Changes to this policy

When we update this policy we publish a new version with the update date. If changes are substantial and concern consent-based processing, we will ask you again to confirm your preferences.

Current version: p1-2026-06-29 · Last update: 2026-07-27