Privacy Policy
How Strongers collects, processes and protects personal data.
1. Who we are (Data Controller)
Strongers Social Club ETS is the data controller for data collected via strongers.org and connected services. For any privacy question contact us directly.
- Data Controller: Strongers Social Club ETS
- Registered office: Via Ruggero Fiore 38, 00136 Roma (RM)
- CF: 96564050589 · P.IVA: 17380961007
- RUNTS Rep.: 122206
- Privacy contact: info@strongersc.com
2. Processing purposes and legal basis
We process your data only for clear purposes declared below. Each processing has a specific legal basis (art. 6 GDPR) and a defined retention period.
| Purpose | Data collected | Legal basis | Retention |
|---|---|---|---|
| Newsletter (events, research grants, magazine) | Name, email | Consent (Art. 6.1.a GDPR) | Until withdrawal + 30-day deletion |
| Donations (card, PayPal, IBAN, 5×1000) | Name, email, amount, payment data (handled by Stripe/PayPal) | Contract performance (Art. 6.1.b) + tax obligations (Art. 6.1.c) | 10 years (ETS tax obligations) |
| Sports event registration | First name, last name, email, phone, event data | Contract performance (Art. 6.1.b) | 5 years from participation |
| Contact / partnership form | Name, email, message | Legitimate interest in replying (Art. 6.1.f) | 24 months |
| Anonymised analytics (Matomo on-prem) | Anonymised IP (last 16 bits), visited URLs | Consent (Art. 6.1.a) | 14 months (Matomo default) |
| Attribution tracking (_st_attr cookie) | Anonymous session token, source, campaign | Consent (Art. 6.1.a) | 30 days |
| "Attributed Citation" / Research Watch cards (public clinical trial registries) | Only structured factual fields from the registry; no individual personal data (investigators/contacts/sites excluded) | Legitimate interest (Art. 6.1.f) — attributed scientific information | As long as the content is published; removed upon change/withdrawal of the source |
| Email communication personalisation (subject/content adapted per segment) | Engagement with our emails (opens, clicks), language, audience segment | Legitimate interest (Art. 6(1)(f)) | Until promo consent withdrawal / objection under Art. 21 |
| Email tracking (opens and clicks in campaigns) | Open pixel, clicks on tracked links, user-agent, date and time | Consent (Art. 6(1)(a) GDPR + Art. 122 Italian Privacy Code) | Until consent is withdrawn |
| Anti-bot protection of public forms (Cloudflare Turnstile) | IP address, technical browser signals, verification token | Legitimate interest (Art. 6(1)(f)) — preventing abuse and spam | Data processed by Cloudflare only for the verification; nothing stored by Strongers |
2.1 "Attributed Citation" information cards (Research Watch)
We publish "Attributed Citation" information cards reporting facts recorded in public clinical-trial registries (initial version: ClinicalTrials.gov), in attributed form and with a link to the source. We process only structured factual fields (study code, phase, status, condition, intervention, dates, enrolment) and do not store or publish investigators, contacts, e-mails, clinical sites or individual officials. Any processing of publicly available professional personal data is residual and incidental and relies on legitimate interest (Art. 6(1)(f) GDPR) in accurate attributed scientific information and source verifiability, in compliance with data minimisation. No health data of identified individuals is processed (Art. 9 GDPR does not apply) and there is no profiling. You may object to the processing at any time by writing to info@strongersc.com (reply within 30 days).
2.2 Communication personalisation
To make our communications more relevant, we may adapt the subject and content of emails (newsletter, campaigns) based on your level of interaction with our previous messages (opens, clicks — collected only if you have granted consent to email tracking, see §2.3) and your audience segment. This personalisation relies on legitimate interest (Art. 6(1)(f) GDPR) in communicating effectively; it is based solely on your interaction with our emails — no cross-site tracking, no special categories (Art. 9), no automated decisions with legal effects (Art. 22). You can object at any time (Art. 21) by writing to info@strongersc.com or by disabling promotional communications: objecting also disables personalisation.
2.3 Email tracking (opens and clicks)
Our campaign emails may include an open pixel and tracked links that let us measure whether a message was opened and which links were clicked. This tracking is off by default and is enabled only with your explicit consent (Art. 6(1)(a) GDPR and Art. 122 of the Italian Privacy Code, in line with European authorities' guidance, including the Garante and the CNIL). Without your consent we insert no pixel, do not rewrite links, and no open or click is recorded. You can grant or withdraw this consent at any time from the preference centre, reachable via the link in the footer of every email. Withdrawal takes effect immediately: even already-sent emails stop being tracked. Email tracking is independent of your subscription: you can turn it off and still receive newsletters and events.
3. Legal bases for processing
Our legal bases are: (a) your explicit consent for newsletter, analytics and email tracking; (b) contract performance for donations and event registrations; (c) legal obligations for retention of donation receipts (10 years); (f) legitimate interest in responding to messages you send us spontaneously and in personalising email communications based on your engagement with our messages, where you have granted consent to email tracking (§2.3).
4. Recipients and processors
To provide the site services we rely on external providers appointed as processors under art. 28 GDPR. All are European or comply with EU adequacy standards:
- Stripe Payments Europe Ltd. (Dublin) — card payment processing. Stripe Privacy
- PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg) — PayPal payment processing. PayPal Privacy (loaded only on-intent, see §7)
- Brevo (Sendinblue SAS) (Paris) — newsletter and transactional email delivery. Brevo Privacy
- Matomo (self-hosted, Hetzner GmbH, Falkenstein DE) — anonymised analytics, data on European servers under Strongers' control
- Hetzner Online GmbH (Germany) — infrastructure hosting. EU-only servers, minimal sub-processors.
- Cloudflare, Inc. — anti-bot verification (Turnstile) on public forms: processes IP address and technical browser signals to tell people apart from bots. Certified under the EU-U.S. Data Privacy Framework. Cloudflare Privacy
We do not transfer your data outside the European Economic Area (EEA): the providers listed above operate EU servers, with one exception — the Cloudflare Turnstile anti-bot verification may process your IP address on Cloudflare's global infrastructure, safeguarded by the EU-U.S. Data Privacy Framework and standard contractual clauses (Art. 46 GDPR).
5. Retention periods
We keep your data only as long as necessary for the declared purposes. When the period expires, data is irreversibly deleted or anonymized. See the 'Retention' column of the processing table.
6. Your GDPR rights
GDPR guarantees you full control over your data. You can exercise the following rights at any time, free of charge.
How to exercise your rights
You can exercise any right below by simply sending an email. No complex forms required.
- Right of access (Art. 15) — know which data we process
- Right to rectification (Art. 16) — correct inaccurate data
- Right to erasure / to be forgotten (Art. 17) — have your data removed
- Right to restriction (Art. 18) — suspend the processing
- Right to data portability (Art. 20) — receive your data in a readable format
- Right to object (Art. 21) — object to processing based on legitimate interest
- Withdrawal of consent (Art. 7.3) — withdraw consent at any time
📧 How to exercise: write to info@strongersc.com stating the right you wish to exercise. Response guaranteed within 30 days.
You always have the right to lodge a complaint with the Italian Data Protection Authority: Garante Privacy.
7. Cookies and tracking technologies
We use technical cookies (always active, necessary for the operation) and analytics/attribution cookies (activated only with your explicit consent). Third-party scripts (PayPal, Stripe) are loaded on-intent, only after you explicitly click the corresponding payment method.
7.1 Cookie categories
On your first visit, a banner lets you choose which categories to enable. You can change your preferences at any time via the "Manage cookies" link in the footer of every page.
Necessary cookies (always active)
Essential for the website to function. They do not require consent pursuant to Art. 122(1) of Italian Legislative Decree 196/2003 and the Italian DPA (Garante) cookie guidelines (10 June 2021).
| Cookie | Purpose | Duration |
|---|---|---|
| XSRF-TOKEN | CSRF protection (Cross-Site Request Forgery) | Session |
| strongers_org_session | Application session (language, authentication) | Session (2 hours) |
| strongers_cookie_consent | Stores your cookie preferences (accepted categories, version, timestamp) | 12 months |
| strongers_vid | First-party pseudonymous technical browser identifier (controller: Strongers; no third-party access). Purpose: store and enforce your cookie/consent choices, including server-side (fail-closed check before any CAPI send); not used for analytics, profiling or retargeting. Category: technical/necessary. Security: Secure, SameSite=Lax. | 12 months |
Analytics cookies (consent required)
Activated only if you accept the "Analytics" category in the banner. We use Matomo, a self-hosted solution on European servers (Hetzner GmbH, Falkenstein, Germany) under Strongers' full control. The IP address is anonymised (last 16 bits masked). No data is shared with third parties.
| Cookie | Purpose | Duration |
|---|---|---|
| _pk_id (Matomo) | Visitor identifier for aggregate statistics | 13 months |
| _pk_ses (Matomo) | Current browsing session | 30 minutes |
Attribution cookies (technical, first-party)
First-party technical cookies used to reconnect anonymous visits to subsequent sign-ups (newsletter, events). They contain no identifiable personal data.
| Cookie | Purpose | Duration |
|---|---|---|
| _st | Anonymous session token for visit attribution | 12 months |
| _st_attr | Campaign parameters (UTM source/medium/campaign) | 30 days |
Third-party cookies (on-intent consent)
No third-party cookie is loaded on mere access to the site. The following payment services load their scripts only after an explicit user action (granular on-intent consent, compliant with the Italian DPA (Garante) cookie guidelines, para. 7.2):
| Service | When it activates | Provider privacy |
|---|---|---|
| PayPal (Europe) S.a r.l. | Only after clicking "Load PayPal" on the donations page | Privacy PayPal |
| Stripe Payments Europe Ltd. | Only on redirect to the Stripe checkout page | Privacy Stripe |
| Cloudflare, Inc. (Turnstile) | On pages with public forms, for the Turnstile anti-bot verification | Privacy Cloudflare |
Marketing and profiling cookies (consent required)
Enabled only if you accept the Marketing category in the banner. We use the Meta Pixel and the Meta Conversions API from Meta Platforms Ireland Limited to measure the effectiveness of advertising campaigns on Meta platforms, such as Facebook and Instagram, to correctly attribute conversions, and for retargeting activities. Meta Platforms Ireland Limited is a recipient of the data processed through these tools; for processing that Meta carries out as an independent controller or under the Meta Business Tools Terms, please refer to Meta's privacy policy. The Meta Pixel is not loaded and events sent via the Conversions API are not transmitted until you give explicit consent to the Marketing category. If you do not give consent, or if you withdraw it, we do not send conversion events to Meta through these tools. Once enabled, some data relating to browsing and conversions may be transmitted to Meta, including: conversion events (for example donations, purchases, sign-ups, or form submissions); URLs and pages visited; IP address; user-agent and browser/device information; technical identifiers and Meta cookies/identifiers, where present and permitted; an event identifier (event_id) used for deduplication. When we transmit contact data, such as an email address or phone number, this data is hashed using SHA-256 before being sent and is not transmitted in clear text; hashing does not remove its nature as personal data. The Conversions API allows us to send Meta conversion events directly from our servers, complementing those collected via the browser pixel. Events are marked with a shared identifier that enables deduplication, avoiding double-counting the same conversion. Meta may process data also in the United States; transfers outside the EU take place on the basis of the tools provided for under Articles 44 et seq. of the GDPR, including the Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. The legal basis for this processing is your consent, which you can withdraw at any time via the cookie preferences. We do not sell or share data with third parties for other commercial purposes. Email communication personalisation (see §2.2) is not based on cookies, but solely on your interaction with our emails.
| Cookie | Purpose | Duration |
|---|---|---|
| _fbp (Meta) | Browser identifier for campaign measurement and retargeting | 3 months |
| _fbc (Meta) | Attribution of clicks from Meta ads (present only if you arrive from an ad) | 3 months |
7.2 How to manage cookies
- Cookie banner: on your first visit, choose "Accept all", "Reject all" or "Customise" to select the categories.
- Change preferences: click Manage cookies (also available in the footer of every page).
- Browser: you can block or delete cookies from your browser settings. Note: disabling technical cookies may impair navigation.
7.3 Consent register
Every choice is recorded in the cookie_consent_logs table with: anonymous visitor identifier, accepted/rejected categories, policy version, action (accept all/reject all/customise), anonymised hash of the IP and user agent, and timestamp. This register constitutes proof of consent pursuant to Art. 7.1 GDPR.
8. Security
Data is protected by mandatory HTTPS, email hashing for anonymous matching, versioned consent audit trail. Passwords follow the Argon2id standard. Infrastructure is hosted in Germany (Hetzner) under direct Strongers control, with no undisclosed external sub-processors.
9. Changes to this policy
When we update this policy we publish a new version with the update date. If changes are substantial and concern consent-based processing, we will ask you again to confirm your preferences.
Current version: p1-2026-06-29 · Last update: 2026-07-27