Legal
Last updated: October 2026
This website is run by a single person, not a company with a data department. This policy describes, in plain terms, what happens to your information when you visit the site or get in touch — and what happens to it afterwards.
The data controller is:
Simona Saguto
Wedding Planner & Designer, sole trader
Registered address
Via Sant’Anna 75, 90044 Carini (PA), Italy
VAT number
07240090824
Phone
There is no appointed Data Protection Officer: the business does not meet the criteria that would require one under Article 37 of the GDPR.
The form on the contact page does not send anything by itself. You fill it in, and it writes a message for you which then opens in WhatsApp. Nothing is stored on this website and nothing reaches me until you press send yourself, in WhatsApp, as you would with any other message.
When you do send it, I receive what you chose to put in it: your names, the service you’re interested in, and whichever of the date, place, guest numbers and notes you filled in. That conversation then lives in my WhatsApp, under WhatsApp’s own terms — see the section on third parties below.
I receive whatever you send me: your email address or phone number, and the content of your message.
The hosting provider keeps standard server logs, which include your IP address, the pages requested, the time, and your browser type. These are generated automatically by any web server and are used for security and to diagnose faults. I do not use them to build any profile of you.
This site has no analytics, no advertising pixels, no tracking of any kind, and no newsletter sign-up.
To reply to your enquiry
Legal basis: steps taken at your request before entering into a contract — Art. 6(1)(b) GDPR.
To plan and deliver your wedding, if we work together
Legal basis: performance of our contract — Art. 6(1)(b) GDPR.
To keep the site running and secure
Legal basis: my legitimate interest in a functioning, protected website — Art. 6(1)(f) GDPR.
To meet tax and accounting obligations
Legal basis: legal obligation — Art. 6(1)(c) GDPR.
Providing your information is entirely voluntary, but without at least a name and a way to reach you I cannot reply.
I do not sell your data and I do not share it for marketing. These are the only parties involved in running the site and my work:
Hosting provider
Stores the website and its server logs. Acts as a data processor on my instructions.
WhatsApp (Meta)
If you choose to write to me there. The conversation is governed by WhatsApp’s own privacy policy, over which I have no control.
Email provider
Handles messages sent to my address.
Accountant
Receives the data strictly needed for invoicing and tax, if we work together.
Suppliers for your wedding
Only with your knowledge, only what each of them needs, and only if we are working together.
I will never pass your details to a venue or supplier who has not been agreed with you, and nobody pays me to be put in touch with you.
If you contact me through WhatsApp, that conversation is processed by Meta, which may transfer data outside the European Union. Meta relies on the EU–US Data Privacy Framework and on Standard Contractual Clauses for these transfers. If you would rather not use WhatsApp, email and telephone are always available and are listed on the contact page.
The site itself loads its typefaces from Google Fonts and one animation library from jsDelivr. Neither sets a cookie, but your browser has to contact them, which means your IP address reaches those servers each time a page loads. Both providers may process that request outside the European Union. Nothing else about you is sent, and neither of them receives anything you type on this site.
This is disclosed rather than made optional: the two resources are part of how the pages are built, so the site tells you plainly that it uses them instead of offering a choice it couldn’t honour. If you would rather not have your IP reach them at all, a browser extension that blocks third-party requests will stop both, and the site will still work.
Enquiries that don’t go anywhere
Up to 24 months, then deleted.
Correspondence with clients
For the duration of the project and 12 months afterwards.
Invoices and accounting records
10 years, as Italian law requires.
Server logs
Normally no more than 12 months.
Photographs of your wedding
Only used publicly with your written permission, and removed on request.
Under Articles 15 to 22 of the GDPR you have the right to:
Write to simona.saguto@hotmail.it and I’ll reply within a month. There is nothing formal about it — a plain email is enough.
If you believe I’ve handled your data badly, you can complain to the Italian supervisory authority, the Garante per la protezione dei dati personali, or to the authority in the country where you live.
This site uses only the technical cookies WordPress needs to work, plus one entry in your browser’s local storage that remembers you’ve already seen the privacy notice, so it doesn’t reappear on every page. There are no advertising or analytics cookies. The details are on the cookie policy page.
If the way the site works changes — a new tool, a new form, anything that touches your data — this page is updated and the date at the top changes with it. Nothing here applies retroactively to data already collected under an earlier version.