Privacy Policy
Last updated:
This Privacy Policy explains how personal data is processed when you visit the official link page of Giselle (the “Website”). It is provided under Article 13 of Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”) and Legislative Decree 196/2003 (Italian Personal Data Protection Code), as amended by Legislative Decree 101/2018.
1. Data Controller
The data controller is the owner and operator of this Website (the “Controller”, “we”). For anything related to this policy or to your personal data you can contact the Controller through the official contact channels and social profiles linked on the Website.
No Data Protection Officer has been appointed, as one is not required for the processing described here (Art. 37 GDPR).
2. What this Website is
The Website is a single page that lists the official links and social media profiles of Giselle. It has no registration, user accounts, contact forms, comments, newsletter or online shop, and it never asks you to enter personal data.
When you click a link you leave the Website and reach a third-party platform (for example Instagram, Telegram, X or OnlyFans). From that moment your data is processed by that platform under its own privacy policy (see section 5).
3. Personal data we process
3.1 Browsing data
As with any website, the web server that hosts the Website automatically records some technical information every time a page or file is requested. These server logs are kept by our hosting provider and contain:
- the IP address of your device;
- the browser type and version and the operating system (the “user agent”);
- the date and time of the request;
- the page or file requested and the server response (status code, amount of data sent);
- the address of the page you came from (referrer), if your browser sends it.
This data is used only to deliver the pages, keep the Website secure (for example to detect abuse and attacks) and fix technical problems. We do not use it to identify you or to build profiles.
The Website also reads your browser's user agent to recognise the built-in browsers of Instagram, Facebook, Messenger, Threads and TikTok, so that it can open the page in your default browser or explain how to do it. This check happens in real time and its result is not recorded.
3.2 Cookies
The Website does not set any cookies, neither technical nor profiling.
On the page that helps you leave an app's built-in browser, the Website keeps a temporary technical marker in your browser's session storage, so that it tries to open your default browser only once per tab. The marker contains only the address of the page being opened, is never sent to the server and is deleted when the tab is closed. Details are in the GDPR & Cookie Policy.
4. Purposes and legal bases
- Running the Website and keeping it secure (server logs, recognition of in-app browsers): our legitimate interest in offering a working and secure website (Art. 6(1)(f) GDPR). The session-storage marker described in section 3.2 is strictly necessary for this purpose and is therefore exempt from consent under Art. 122(1) of the Italian Personal Data Protection Code.
Browsing data is needed to display the Website, so it cannot be refused while you use it.
5. Who receives the data
The data is processed by the Controller and, for the purposes above, by the following providers:
- Hosting provider: Hostinger International Ltd., which hosts the Website and keeps the server logs as a data processor on our behalf (Art. 28 GDPR).
-
Google Fonts: Google Ireland Limited and Google LLC. The Poppins font is loaded from
fonts.googleapis.comandfonts.gstatic.com: to deliver it, your browser sends your IP address and user agent to Google. -
Content delivery networks (CDN): Tailwind Labs Inc. (
cdn.tailwindcss.com), which delivers the page styles, and Cloudflare, Inc. (cdnjs.cloudflare.com), which delivers an animation library on some pages. To deliver these files they receive your IP address and technical data about the request. - Linked platforms: the services you reach through the links (such as Instagram, Telegram, X and OnlyFans) are independent controllers. The Website does not pass any personal data to them; what they collect when you visit them is governed by their own privacy policies.
Data is not sold and is not disseminated. It may be disclosed to public authorities only when required by law.
6. Transfers outside the European Economic Area
Some of the providers above (Google, Tailwind Labs and Cloudflare) are based in the United States or may process data there. These transfers rely on the European Commission's adequacy decision of 10 July 2023 for companies certified under the EU–US Data Privacy Framework and/or on the Standard Contractual Clauses adopted by the European Commission (Articles 45 and 46 GDPR).
7. How long we keep the data
- Server logs: only for the time strictly necessary for security and operation, according to the retention policy of the hosting provider, after which they are deleted or anonymised. They may be kept longer only when needed to investigate an attack or a crime against the Website.
- Session-storage marker: until the browser tab is closed.
8. Your rights
Under Articles 15 to 22 GDPR you have the right to:
- access your personal data and receive a copy of it (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased (Art. 17);
- restrict the processing (Art. 18);
- receive your data in a structured, commonly used and machine-readable format and transmit it to another controller (Art. 20);
- object at any time to processing based on our legitimate interest (Art. 21);
- lodge a complaint with a supervisory authority: in Italy, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or the authority of the EU country where you live or work.
To exercise your rights, contact the Controller through the contact channels linked on the Website. We will reply without undue delay and in any case within one month, which may be extended by two further months for complex requests (Art. 12(3) GDPR). Because the Website does not collect data that directly identifies you, we may ask for additional information to find the data that concerns you (Art. 11 GDPR).
9. Minors
The Website is not intended for minors. Some of the content reached through its links, in particular on subscription platforms, is reserved for adults aged 18 or over, and access to it is subject to the age checks and terms of those platforms. We do not knowingly collect personal data from anyone under 18. If you believe that a minor has provided us with personal data, please contact us and we will delete it.
10. Automated decision-making
The Website does not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).
11. Changes to this policy
We may update this Privacy Policy when the Website or the applicable law changes. The current version is always published on this page, and the date at the top shows when it was last updated.