Last updated: September 14, 2026. This policy is written to comply with the EU General Data Protection Regulation (GDPR) 2016/679 and applicable ePrivacy rules on cookies and online advertising.
The data controller for this site is GTAVIANI Consulting, Milan, Italy (P.IVA IT12220360965). For any privacy request, use our contact form.
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Email, hashed password, name (optional) | Create and secure your reader account | Performance of a contract (1)(b) |
| Amazon order code, order receipt file | Verify you own a copy of the book | Performance of a contract (1)(b) |
| Comments, reviews, ratings you post | Run the comments & reviews feature | Performance of a contract (1)(b) |
| Notification preferences | Send only the emails you asked for | Consent (1)(a) |
| Chapter view counts | Aggregate analytics only — no per-user tracking | Legitimate interest (1)(f) |
This site uses a strictly necessary session cookie to keep you logged in — no consent banner is required for that under the ePrivacy rules, since it's essential to the service you asked for.
We do not currently run advertising campaigns on Google Ads, Meta (Facebook/Instagram) or LinkedIn for this site. If we start any such campaign in the future:
Your uploaded receipt is kept for 12 months from registration, then permanently deleted. Your account data is kept as long as your account is active. Failed login/signup attempt logs (IP address only, for rate limiting) are kept for a few days and then overwritten.
We do not sell your personal data. It is shared only with service providers acting on our behalf, under a data processing agreement: our email delivery provider (Brevo, for account and notification emails) and our hosting provider. If advertising is enabled in the future, Google, Meta and LinkedIn will be added here as processors/recipients (see section 3).
Where a service provider is located outside the European Economic Area, we rely on the safeguards required by GDPR (such as the European Commission's Standard Contractual Clauses or an adequacy decision) before any personal data is transferred.
You have the right to: access the personal data we hold about you; correct inaccurate data; request erasure ("right to be forgotten"); restrict or object to processing; receive a copy of your data in a portable format; and withdraw consent at any time where processing is based on consent. You can exercise most of these directly from your profile (password change, account deletion) or via our contact form for anything else.
Deleting your account removes your personal data; any comments you left stay online but are shown under "Former reader" instead of your name, so the discussion isn't erased for other readers. You also have the right to lodge a complaint with your national data protection authority (in Italy, the Garante per la Protezione dei Dati Personali).
Passwords are stored hashed, never in plain text. Receipt files are stored outside public access and are never linked from any page. Access is served over HTTPS.
This site is intended for business readers (CEOs, executives) and is not directed at children. We do not knowingly collect data from anyone under 16.
We may update this policy as the site evolves (for example, before enabling any advertising described in section 3). The "last updated" date at the top will always reflect the latest version.