Privacy Policy – Vegan Pastry Academy
Last updated: June 8, 2026
This Privacy Policy describes how the personal data of users who visit or use the Vegan Pastry Academy website (hereinafter the "Site"), including the Academy and Club services, is collected, used, stored, and protected.
The processing of personal data is carried out in compliance with EU Regulation 2016/679 (GDPR), Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018, and further applicable regulations.
1. Data Controller
The Data Controller is:
Alessia Luisa
Via Spluga 55
22063 Cantù (CO)
Italy
VAT Number: 03964290138
Email: info@veganpastryacademy.com
2. Types of Data Collected
2.1 Data provided directly by the user
The Site may collect the following data voluntarily provided by the user:
- first and last name
- email address
- billing address
- tax data where required
- account login credentials
- content sent via contact forms
- messages sent via private chat
- reviews, comments, photos, or content posted in the community
- newsletter and marketing preferences
2.2 Data collected automatically
During navigation, the following may be collected:
- IP address
- browser and device type
- operating system
- browser language and device language preferences
- pages visited
- date and time of access
- time spent on pages
- technical logs
- site usage events
- authentication and security data
2.3 Technologies used by the Site
The Site uses its own and third-party technologies, including:
Proprietary technologies
- technical cookies
- localStorage
- sessionStorage
- authentication tokens
- session security systems
Used for:
- user login
- session maintenance
- access to the personal area
- account security
- proper functioning of the site
- storing site language or language preferences detected by the browser
Third-party technologies
- Google Analytics
- Meta Pixel
- Brevo
- YouTube
- Vimeo
- external payment providers
3. Purpose of processing and legal basis
Personal data is processed for the following purposes.
3.1 Account registration and personal area access
To allow account creation, login, and management of the reserved area.
Legal basis: execution of a contract.
3.2 Sale of digital products
To allow the purchase and use of:
- online courses
- eBooks
- digital recipes
- Club subscriptions
- purchased services
Legal basis: execution of a contract.
3.3 Club subscription management
For activation, automatic renewal, deadline management, and access to reserved contents.
Legal basis: execution of a contract.
3.4 Customer assistance and post-purchase support
To respond to requests sent via email, form, or private chat.
Legal basis: contract and legitimate interest.
3.5 Community and user content
To allow publication of reviews, comments, photos, and interactions in community areas.
Legal basis: user consent and contract.
3.6 Newsletters and promotional communications
For sending email marketing, offers, news, and commercial communications related to the Site's services.
Communications may also be personalized based on the language selected by the user, the language version of the Site used, or the language preferences detected during navigation.
Legal basis: consent revocable at any time.
3.7 Traffic analysis and site improvement
To analyze the use of the Site, performance, usability, and proper technical functioning, including language preferences and technical localization of the browser, in order to improve the browsing experience and content delivery.
Legal basis: consent, where required by applicable law on cookies and tracking tools.
3.8 Remarketing and advertising
For personalized advertising campaigns and conversion measurement.
Legal basis: consent.
3.9 Site security and abuse prevention
For account protection, prevention of fraud, unauthorized access, and improper use.
Legal basis: legitimate interest.
3.10 Legal and tax obligations
For invoicing, accounting, and regulatory compliance.
Legal basis: legal obligation.
4. Data recipients
Data may be processed by external suppliers operating as data processors or independent data controllers, including:
- hosting and server infrastructure providers
- Google Analytics
- Meta
- Brevo
- Stripe
- PayPal
- Klarna
- YouTube
- Vimeo
- tax or legal consultants where necessary
The Data Controller does not sell personal data to third parties.
5. Extra-EU data transfer
Some suppliers may process data outside the European Economic Area.
In such cases, the transfer occurs through tools compliant with applicable legislation, including:
- adequacy decisions
- Standard Contractual Clauses (SCC)
- further guarantees provided by law
6. Data retention
Personal data is kept for the time necessary for the purposes for which it is collected.
User account
Kept as long as the account remains active or the platform remains operational, subject to deletion requests where applicable.
Purchases and order history
Kept as long as the Site and purchased services remain operational, as well as for administrative, tax, and legal protection obligations.
Private chat and assistance
Kept as long as the account and platform remain active or for the time necessary to manage the customer relationship.
Community and published contents
Kept until removal of the content, account deletion, or request by the data subject, subject to legal obligations.
Newsletter
Until consent is revoked or unsubscribed.
Technical data and security
For the time necessary for system security and abuse prevention.
7. Data security
The Data Controller adopts adequate technical and organizational measures, including:
- secure HTTPS connection
- access control
- periodic backups
- server protection
- anti-abuse systems
- secure authentication tokens
8. Rights of the data subject
Within the limits provided by applicable law, the user may request:
- access to personal data
- rectification
- deletion
- limitation of processing
- objection
- portability
- revocation of consent
- complaint to the competent Supervisory Authority
9. Minors
The Site is not intended for users under 16 years of age, unless a different minimum age is provided by local law.
Data from minors is not knowingly collected.
10. Third-party sites and services
The Site may contain links or embedded content from external platforms.
These entities operate according to their own privacy policies.
11. How to exercise your rights
For privacy requests or the exercise of rights:
📩 info@veganpastryacademy.com
12. Changes to this Policy
This Privacy Policy may be updated at any time.
Changes will be effective from publication on the Site.
The date of the last update is indicated at the beginning of the document.