Privacy Policy pursuant to Art. 13 GDPR

Welcome to www.institutgrainesdesanges.com. This privacy policy describes how personal data of users who visit the website and use its services is processed.

1. Data Controller

The Data Controller is:
Company Name: Institut International Graines Des Anges di Akakpo Mama Amavi
Owner: Akakpo Mama Amavi
Registered Address: Viale Fratelli Cairoli, 15, 31100 Treviso (TV)
Privacy Contact Email: [email protected]
Certified Email (PEC): [email protected]
VAT Number: 05386170269
Tax Code: KKPMMV77T71Z351S

2. Browsing Data and IT Security

The IT systems used to operate this website automatically collect certain personal data during normal operation, the transmission of which is implicit in the use of Internet communication protocols (e.g. IP addresses, device parameters, request times).
This data is used for:

  • Anonymous statistics: Monitoring the correct functioning of the website.
  • Security: Establishing responsibility in the event of potential cybercrimes and protecting the website from attacks (e.g. SPAM, DDoS). To this end, the website may use traffic analysis technologies (e.g. Cloudflare or Firewall) that filter anomalous requests, acting in the Legitimate Interest of the Controller (Art. 6.1.f GDPR) to protect the infrastructure.

3. Hosting and Distribution Infrastructure (CDN)

To ensure maximum performance and security, this website uses an architecture that may include:

  • Hosting / Origin Server: The website is hosted on infrastructure (VPS/Dedicated) managed by OVHcloud (France/EU), acting as Data Processor. The servers are located within the European Economic Area (EEA), in compliance with the security standards required by the GDPR.
  • Distribution and Security Network (CDN): Traffic to this website may be filtered and distributed by Cloudflare, Inc. (USA/Global) or similar services. These services act as a "Reverse Proxy" to protect the website from DDoS attacks and malicious access. Although Cloudflare is a US company, it adheres to the Data Privacy Framework (DPF), ensuring adequate levels of protection for the transfer of data (IP addresses and system logs) necessary for security.

4. Local Resources and Absence of Tracking

Unlike most websites, this site is designed according to the Privacy by Default principle:

  • No Google Fonts: Typefaces are hosted locally on our server (Self-hosted). No calls are made to Google servers to load fonts.
  • No Analytics Services: We do not use Google Analytics or other measurement tools that install cookies or track user browsing behaviour.
  • No Embedded Content: We do not load videos (YouTube/Vimeo) or maps (Google Maps) directly into pages to avoid third-party tracking. Links to these platforms are simple external hyperlinks.

5. Anti-Spam Protection (Without Profiling)

To protect contact forms from automated submissions (Bots), we use a privacy-friendly system:

  • Honeypot Technique: Invisible fields in the form that, if filled in (by bots), automatically block the submission without processing any personal data.

6. Links to External Websites

The website contains hyperlinks to external websites (e.g. Google Maps for directions, Social Networks, partner websites). By clicking on these links, the user leaves this domain. The Controller is not responsible for data processing carried out by these external websites, which are governed by their respective privacy policies.
The social buttons on the website are simple static links and do not use third-party cookies until they are clicked.

7. Voluntarily Provided Data

Through the forms on the website, the following personal data is collected:

  • Name
  • Email
  • Phone
  • Message.

Purpose: To respond to requests for information, support or pre-contractual enquiries.
Legal Basis: Performance of pre-contractual measures taken at the request of the data subject (Art. 6.1.b GDPR).

The user undertakes not to send sensitive or judicial data (e.g. health data, political opinions) via the contact form, as they are not necessary for the purposes of the service.

8. Cookie Policy and Tracking Tools

This website does not use profiling or marketing cookies.
Only technical cookies or session identifiers strictly necessary for the transmission of communication over the network and for security are used. In compliance with current regulations, the installation of such technical tools does not require prior user consent (no cookie banner required).

9. Processing Methods and Storage

Personal data is processed using automated tools. Requests submitted via the form are securely stored in the website's database (hosted in the EU) to ensure backup and traceability of the request, in addition to being forwarded via email to the Controller. Security measures (firewall, restricted access, HTTPS protocol) are in place to prevent data loss or unauthorised access.

10. Retention Period

Data will be retained in accordance with the principle of limitation (Art. 5 GDPR):

  • Contact requests (Leads): Data will be deleted 12 months after the last interaction or the closure of the request, should no contractual relationship follow.
  • Administrative/Client Data: In the event of a contractual relationship, data will be retained for 10 years due to civil and tax legal obligations.

11. Place of Processing and Data Transfer

Data processing takes place at the server locations indicated in section 3 (EU/France).
For email management, the Controller may use providers (e.g. Google/Microsoft) that operate globally. In such cases, the transfer of data to Third Countries (e.g. USA) takes place in compliance with the Data Privacy Framework (DPF) or after signing the Standard Contractual Clauses (SCC) approved by the European Commission.
Furthermore, data may be shared with tax consultants, accountants or legal professionals for the accounting and administrative obligations necessary in the event of a contractual relationship.
These parties operate, depending on the case, as duly appointed Data Processors or as independent Data Controllers.

12. Rights of the Data Subject

At any time, you may exercise the rights provided by Articles 15-22 of the GDPR (access, rectification, erasure, restriction, portability, objection) by sending a request to the Controller's email. You also have the right to lodge a complaint with the Data Protection Authority (www.garanteprivacy.it).

Ultimo aggiornamento: April 2026