Privacy Policy
Last updated: 24 September 2026
1. Data controller
Treats S.r.l., VAT no. IT14704660969, Via San Francesco d'Assisi 15, 20122 Milan, Italy. For anything concerning your data, write to treats.milano@gmail.com.
We have not appointed a Data Protection Officer (DPO): it is not required for our activity.
2. What data we process
Workshop and event bookings: – first and last name, email and phone number; – invoicing details: tax code, or company name and VAT number, address, SDI recipient code or PEC; – activities booked, number of seats, payments, refunds, cancellations and attendance (check-in).
Access to "My bookings": your email and a one-time sign-in link.
Waiting list: the email you sign up with and your language.
Gift cards: name and email of the buyer; name, email and message for the recipient, if the buyer chooses to provide them; the gift card code and credit movements.
Discount codes: the code used and, for codes valid once per person, the email that used it.
Shop: name, email, phone number, shipping or billing address and products purchased.
Contact requests: name, email and the message you send us.
Payment data: card numbers and wallet credentials are collected and processed only by Stripe. We only receive the payment outcome, the amount and a reference.
Visit statistics, only if you accept them: pages viewed, where the visit comes from (for example a search engine), device and browser type, approximate city or country and, if you book or buy something, the amount, order code and what you bought, through Google Analytics. We don't send Google names, emails or phone numbers, and we strip from page addresses the parameters that could identify you.
Technical data: our servers' operational logs may contain the email and code of a booking, to troubleshoot problems. The log of requests to the website (page requested, date and time, referring page, browser type) is also used to count, in aggregate only, visits and reads by search engines and AI assistants. We do not log visitors' IP addresses.
3. Why we process it and on what legal basis
- Managing bookings, payments, cancellations, refunds, gift cards and shop orders, and sending you service messages (confirmations, reminders, changes): performance of our contract with you (Art. 6(1)(b) GDPR).
- Issuing invoices and keeping accounts: legal obligation (Art. 6(1)(c) GDPR).
- Letting you know when a seat opens up, if you join a waiting list: your consent (Art. 6(1)(a) GDPR), which you can withdraw through the link in every email.
- After an activity, asking how it went, inviting you to leave a review and telling you about similar activities: legitimate interest, within the limits of Art. 130(4) of the Italian Privacy Code (email only, only to people who have booked, for similar activities). You can object at any time, through the link at the bottom of every email or by writing to us.
- Visit statistics (Google Analytics), to understand which pages and activities people find most interesting and improve the website: your consent (Art. 6(1)(a) GDPR and Art. 122 of the Italian Privacy Code), which you can withdraw at any time from "Cookie preferences" at the bottom of every page.
- Aggregate counts from the log of requests to the website (no IP addresses or cookies), to understand how search engines and AI assistants read the website: legitimate interest (Art. 6(1)(f) GDPR).
- Website security, fraud and abuse prevention, backups: legitimate interest (Art. 6(1)(f) GDPR).
- Protecting our rights in case of disputes: legitimate interest (Art. 6(1)(f) GDPR).
We don't use your data for profiling or targeted advertising, and we don't sell it.
4. Do you have to give us your data?
Name, email, phone number and invoicing details are needed to book: without them we cannot confirm the booking or issue the invoice the law requires. We need your phone number to reach you if something changes about the activity.
The recipient's details for a gift card, the message and joining the waiting list are optional.
5. Who receives the data
- Authorised Treats staff and the hosts running the activities: they receive the names and contact details of their own participants, to organise the activity and record attendance.
- Amazon Web Services EMEA SARL: hosts the website, the booking system, databases, backups and email delivery, in data centres in the European Union (Milan and Ireland).
- Stripe Payments Europe Ltd (Ireland): processes payments and refunds. For fraud prevention and payment regulations Stripe acts as an independent controller: see stripe.com/privacy.
- Google (Gmail email service): for correspondence when you write to us or reply to one of our emails.
- Google Ireland Limited (Google Analytics), only if you accept statistics: it processes them on our behalf. We have turned off data sharing with Google for other purposes, Google Signals and personalised advertising.
- Our accountant, for bookkeeping and invoices, and the courier for shop deliveries.
- Public authorities, where required by law.
Our suppliers process data on our behalf, following our instructions and under contracts compliant with Art. 28 GDPR. The booking system (pretix, open-source software) runs on our own servers: data is not shared with the company that develops it.
6. Transfers outside the European Union
We store data in the European Union. Some suppliers (Stripe, Google, Amazon) belong to groups based in the United States and may, in limited cases, process it there too, for example for technical support or fraud prevention. In those cases the transfer relies on the European Commission's adequacy decision on the EU-U.S. Data Privacy Framework, which these suppliers have joined, or on the Standard Contractual Clauses approved by the Commission (Arts. 45 and 46 GDPR).
7. How long we keep it
- Bookings, orders, invoices, payments and refunds: 10 years, as required for accounting records (Art. 2220 of the Italian Civil Code).
- Gift cards: for as long as the gift card is valid (12 months); accounting records of the sale and use for 10 years.
- Waiting list: until the activity starts, then the entry is deleted automatically; earlier if you leave the list.
- Sign-in links: 30 minutes for customers, 15 for staff; a signed-in session lasts at most 24 hours.
- Log of emails sent (so we never send the same one twice): 6 months.
- Server technical logs: 90 days.
- Backups: on rotation, up to 12 months, encrypted.
- Emails after activities: until you object; we keep your objection so we can respect it.
- Visit statistics: Google Analytics cookies last at most 13 months; in Google Analytics, data about individual visitors is kept for 2 months, after which only totals remain.
- Contact requests: as long as needed to reply.
After these periods, the data is deleted or anonymised.
8. Your rights
At any time you can ask to access your data, correct it, delete it, restrict its processing, receive it in a readable format (portability) and object to processing based on legitimate interest, in particular to emails after activities (Arts. 15–22 GDPR). You can withdraw any consent given, without affecting processing already carried out.
Write to treats.milano@gmail.com: we will reply within one month. To protect your data we may ask you to confirm your identity, for example by replying from the email used to book.
If you believe the processing breaches the law, you can lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, garanteprivacy.it, Piazza Venezia 11, 00187 Rome) or with the authority of the EU country where you live.
9. Cookies and browser storage
Technical tools needed to make the website work, which do not require consent (Italian DPA guidelines of 10 June 2021): – "treats_cliente": keeps you signed in to "My bookings", for at most 24 hours; – "treats_admin": the same for staff, for at most 12 hours; – browser storage (localStorage): the shop cart, the booking form details, so you don't have to type them again, and your choice about statistics ("treats_consenso", 12 months). They stay only on your device and you can clear them from your browser settings.
Visit statistics, only with your consent: Google Analytics 4 (Google Ireland Limited) with the "_ga" and "_ga_MPN6MTL3H1" cookies, which last at most 13 months. Until you accept, Google Analytics is not loaded. You can change your mind at any time from "Cookie preferences" at the bottom of every page: if you withdraw consent we delete those cookies. How Google uses data from sites that use its services: policies.google.com/technologies/partner-sites.
We don't use profiling, advertising or social network cookies. The website fonts are hosted on our own servers.
10. Automated decisions
We don't make decisions about you based solely on automated processing. Stripe may run automated fraud checks on payments: see its privacy notice for details.
11. Security
The website runs only over HTTPS. Access to private areas uses one-time links and short sessions, staff only see what they need, and backups are encrypted and cannot be modified by the server that creates them.
12. Minors
Bookings and purchases are for adults only. If an activity is open to minors, a parent or guardian makes the booking.
13. Changes to this policy
If we change how we process data we update this page and the date at the top. If the changes are significant, we'll also let you know by email.