Legal · GDPR

Privacy Policy

Information notice provided under articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018, describing how Capri Sound Experience processes personal data collected through this website. Last updated: 27 May 2026.

1. Data controller

The data controller (“titolare del trattamento”) is ErcoCongress S.r.l., operating the brand Capri Sound Experience.

  • Registered office: Capri (NA), Italy.
  • VAT / Codice Fiscale: IT 07565460636.
  • Camera di Commercio di Napoli — REA NA 633401.
  • Email: caprisoundexperience@gmail.com.
  • PEC (certified email): available on request via the email above.

A Data Protection Officer (DPO) has not been formally designated as processing does not meet the thresholds of article 37 GDPR. Privacy requests are handled directly by the controller at the address above.

2. Categories of personal data processed

  • Identification and contact data voluntarily submitted via the production brief form: name, email, phone / WhatsApp number.
  • Event data voluntarily submitted: date, venue, guest count, event type, requested services, atmosphere notes and free-text message.
  • Technical and navigation data: IP address, user agent, request timestamps, page accessed and basic request metadata, collected automatically by the hosting provider and security layer to operate the site and prevent abuse.
  • Communication content exchanged via email or WhatsApp after you contact us through the channels published on this website.

We do not knowingly process special categories of data (article 9 GDPR), data of minors under 16, or location data beyond what is strictly needed to fulfil an event request.

3. Purposes and legal bases

  • a) Reply to your brief and prepare a proposal. Legal basis: pre-contractual measures taken at the data subject’s request and performance of a contract (art. 6.1.b GDPR).
  • b) Manage email and WhatsApp correspondence. Legal basis: pre-contractual measures and legitimate interest (art. 6.1.b and 6.1.f GDPR) in answering business enquiries.
  • c) Operate, secure and improve the website. Legal basis: legitimate interest of the controller (art. 6.1.f GDPR) in ensuring availability, integrity and protection from abuse, with measures proportionate to the risk.
  • d) Comply with legal obligations (accounting, tax, response to authorities). Legal basis: art. 6.1.c GDPR.

No automated decision-making or profiling under article 22 GDPR is performed.

4. Data recipients and processors

Personal data may be processed by the following categories of recipients, appointed as processors under article 28 GDPR or acting as autonomous controllers where applicable:

  • Hosting and infrastructure: Vercel Inc. (United States), provider of the platform hosting this website.
  • Email delivery and SMTP relay used to forward brief submissions to the controller’s mailbox.
  • Messaging: WhatsApp Ireland Ltd / Meta Platforms when you initiate a conversation through the WhatsApp link.
  • Professional consultants (accounting, legal) bound by confidentiality.
  • Public authorities, where requested by law.

Data are never sold and are not used for marketing profiling.

5. Transfers outside the EEA

Some processors (notably the hosting provider and messaging platform) may process data in countries outside the European Economic Area, including the United States. Transfers are made on the basis of (i) the European Commission adequacy decision for the EU–US Data Privacy Framework, where the recipient is certified, or (ii) Standard Contractual Clauses adopted by the Commission (Decision 2021/914) together with supplementary measures as appropriate. A copy of the safeguards can be requested by email.

6. Retention

  • Brief submissions and related correspondence: retained for the time needed to evaluate and run the event, and then for up to 24 months to handle follow-ups and references, unless a longer term is justified by an active contract or a legal obligation.
  • Accounting and tax records linked to executed contracts: 10 years as required by Italian law (art. 2220 c.c.).
  • Server and security logs: short-term retention (typically up to 30 days), unless required as evidence.

7. Your rights

You can exercise the following rights at any time by writing to caprisoundexperience@gmail.com:

  • access to your data (art. 15 GDPR);
  • rectification (art. 16) and erasure (art. 17);
  • restriction of processing (art. 18);
  • data portability (art. 20);
  • objection to processing based on legitimate interest (art. 21);
  • withdrawal of any consent given (without affecting the lawfulness of processing carried out before withdrawal).

You also have the right to lodge a complaint with the Italian Supervisory Authority — Garante per la Protezione dei Dati Personali, Piazza Venezia 11, 00187 Roma — or with the Authority of your country of residence.

8. Security

We apply technical and organisational measures appropriate to the risk: HTTPS in transit, access control on management systems, least privilege, periodic review of vendors and limited data exposure.

9. Intellectual property — photos and videos

All photos, videos and audiovisual content published on this site are property of ErcoCongress Srl or licensed for use by the rights holders. Reproduction, downloading, scraping or commercial reuse without prior written authorisation is prohibited. See the Terms of Use for details.

10. Updates to this policy

This policy is reviewed periodically. The “last updated” date at the top reflects the most recent revision; significant changes will be highlighted on the website.

← Back to Capri Sound Experience