Privacy Policy
Last updated: 27 September 2026
Courtesy translation. The binding version of this notice is the Italian one, available at tammis.it/privacy.html. In the event of any discrepancy, the Italian text prevails.
This notice is provided under art. 13 of Regulation (EU) 2016/679 (the “GDPR”) to anyone who interacts with the tammis.it website and, in particular, to anyone who sends a request through the contact form. It describes what data we collect, why and how we process it.
1. Data controller
Tammis, Italy
Email: bennisanas39@gmail.com
For any request concerning your personal data you can write to the email address above.
2. What data we process
When you send a request through the contact form we process the data you enter voluntarily:
- Your name and, if given, the name of your business;
- Your email address;
- Your phone number (optional field, only if you fill it in);
- The type of site requested and the content of the message you write.
In addition, purely for the technical operation and security of the site, the systems that host it may automatically record some browsing data (e.g. IP address, browser type, date and time of the request), as described in the Cookie Policy.
3. Purposes and legal basis
| Purpose | Legal basis |
|---|---|
| Replying to your request and providing you with a quote or information | Pre-contractual measures taken at your request (art. 6.1.b GDPR) |
| Handling any follow-up communication relating to the request | Legitimate interest in following up on the contact (art. 6.1.f GDPR) |
| Ensuring the security and correct operation of the site | Legitimate interest (art. 6.1.f GDPR) |
| Complying with legal obligations (e.g. tax obligations, where a contract is entered into) | Legal obligation (art. 6.1.c GDPR) |
Providing the data marked as mandatory (name and email) is necessary for us to reply to you: without it we cannot act on your request.
4. How we process the data and who we share it with
The data is processed by electronic means, with appropriate security measures. It is not disclosed publicly or sold to third parties. To deliver the service we rely on suppliers acting as data processors:
| Supplier | Role |
|---|---|
| Vercel Inc. | Hosting of the site and the infrastructure that receives the form data |
| Resend (Plus Five Five, Inc.) | Sending the notification email generated by the form |
| Google (Gmail) | The mailbox where we receive and store the requests |
The data may also be disclosed to advisors or authorities where this is necessary to comply with legal obligations.
5. Transfers outside the European Union
Some of the suppliers listed above (e.g. Vercel, Resend, Google) are based in the United States or may process data outside the European Economic Area. In those cases the transfer takes place on the basis of the appropriate safeguards provided for by the GDPR, such as the Standard Contractual Clauses of the European Commission and/or adherence to the EU-US Data Privacy Framework.
6. How long we keep the data
We keep the form data for as long as it takes to handle your request and, where it does not lead to a working relationship, for a maximum of 24 months, unless a longer period is needed to defend a legal claim or to comply with the law. If the request leads to a contract, the data is kept for the duration of that relationship and for the periods required by law afterwards (e.g. tax obligations, normally 10 years).
7. Your rights
As a data subject you may exercise at any time the rights set out in arts. 15-22 of the GDPR:
- access to your data and to information about the processing;
- rectification of inaccurate data or completion of incomplete data;
- erasure (the “right to be forgotten”), in the cases provided for;
- restriction of processing;
- objection to processing based on legitimate interest;
- data portability;
- withdrawal of consent, where the processing is based on it, without affecting the lawfulness of processing carried out beforehand.
To exercise your rights, write to bennisanas39@gmail.com. You also have the right to lodge a complaint with the competent supervisory authority (in Italy, the Garante per la protezione dei dati personali).
8. Automated decision-making
We do not carry out automated decision-making that produces legal effects on data subjects.
9. Changes to this notice
We may update this notice over time. The version published on this page, with the last-updated date at the top, is the one in force.