Privacy
Last updated: 13 September 2026
Who I am, and how to reach me
This site is mine. My name is Giovanni Ventulini, Italian VAT number 05443670285, Via Luxardo 30, Padua, Italy. I am the data controller for everything collected here.
You can write to me at drventulinigiovanni@gmail.com. I answer myself; there is no front desk.
I have no data protection officer, and I am not required to have one. I am telling you rather than leaving it out: a name put there to fill a line would be worse than the empty line.
What you send me
The application form has six fields, and I collect nothing else.
Alongside the six there is one hidden field whose only job is to stop automated submissions: a person never sees it and never fills it in, and whatever lands in it is not read by anyone, me included.
Here are the six.
- your name;
- the email address I reply to;
- your phone number, because most of the time I would rather call you;
- the sport or the activity you practise;
- the town you live in, which tells me whether I can come to you;
- your account of what you would like to go back to doing.
Why I use it, and on what legal basis
What you write is what I need in order to answer you and to work out whether I can be useful to you. I use it for nothing else, I send no marketing, and I sell it to no one.
The legal basis is Art. 6.1.b GDPR: steps taken at your request before entering into a contract. There is no consent to give and no box to tick, because without those details your request would not exist.
If you don’t give them to me, I can’t answer you. That is the only consequence, and it ends there.
One thing I ask you not to write
Your account does not need medical reports, test results or details about your health. Write me how you move today and what you would like to go back to doing: that is the part I read first.
If something medical is involved, we talk about it on the phone. The form is not the right place for it.
And if you write it anyway, nothing bad happens: I keep it with the same care as the rest, and I pass it to no one.
Who else sees it
The site runs on Vercel. The email is sent through Resend and lands in a Google mailbox, which is the one I open. If you become a client, my accountant sees the invoices.
They are suppliers, not recipients: none of them uses what you wrote for purposes of their own, and none of them sells it.
The servers where your details come to rest are in the European Union.
The anti-spam check, and why it is there
On the two form pages — the Italian application and its English twin — there is an anti-bot check by Cloudflare called Turnstile. It asks you to click nothing, and most of the time you will not notice it.
To tell a person from an automated program, Cloudflare reads four signals: your IP address, the TLS fingerprint of the connection, your browser’s User-Agent header, and the site key together with the address of the page you are on. They are strictly necessary to tell a person from a bot, and Cloudflare states that it cannot directly identify anyone from them.
What Cloudflare does with those four signals is set out in its Turnstile Privacy Addendum. I point you to it because referencing it is a condition of using the invisible mode, not a courtesy I am paying you.
Cookies: none
This site writes no cookies. No traffic statistics, no social buttons, no embedded map: the typefaces are served by the site itself, from its own domain.
Not even the anti-spam check on the form page writes anything to your device.
That is why you find no window to close when you arrive: there is nothing to accept.
How long I keep it
If your request goes no further, I keep what you wrote for twelve months from the last contact between us, and then I delete it.
If you become a client, accounting and tax records stay for ten years, because Art. 2220 of the Italian Civil Code requires it, and they stay for that alone.
These two periods are my own proposal, written down because a privacy notice with no time limits is not a privacy notice. If they change, this page changes first.
What you can ask me for
At any time you can ask me for any of the things listed below, and you don’t have to explain why.
You do it by writing to the address in the first section: I answer within a month, and almost always much sooner. If you think I am getting it wrong and my answer does not satisfy you, the complaint goes to the Italian data protection authority, the Garante per la protezione dei dati personali.
- to see what data I hold about you (Art. 15 GDPR);
- to have it corrected, if it is wrong (Art. 16);
- to have it erased (Art. 17);
- to restrict how it is used (Art. 18);
- to receive it in a readable file, or to have it passed to someone else (Art. 20);
- to object to the use I make of it (Arts. 21 and 22).
No automated decisions
I read the applications myself, one at a time. There is no system that ranks them, filters them out or gives them a score.
I do no profiling and I make no automated decisions: Art. 13.2.f GDPR says it has to be stated, and in my case it is simply how I work.