Privacy Policy

Privacy Policy

Last updated: June 15, 2026
This document is drafted pursuant to UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and Federal Decree-Law No. 26 of 2025 on Child Digital Safety (primary applicable laws, as the Data Controller is established in Abu Dhabi, UAE). Regulation (EU) 2016/679 (GDPR) and Legislative Decree 196/2003 apply extraterritorially insofar as the website targets Italian citizens residing in the UAE.

1. Data Controller

The Data Controller for personal data collected through the website maxsalvato.com is:

Massimiliano Salvato (Max Salvato)
Address: Abu Dhabi, United Arab Emirates (UAE)
Email: [email protected]
Website: www.maxsalvato.com

Regulatory framework. The Data Controller is established in Abu Dhabi (UAE); therefore, the primary applicable law is the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL). EU Regulation 2016/679 (GDPR) applies extraterritorially pursuant to Art. 3(2) insofar as the website targets Italian citizens (EU data subjects) and monitors their behavior, even if they are physically residing in the UAE. The Controller is committed to compliance with both regulatory frameworks, applying the more protective standard on a case-by-case basis.

2. Categories of Data Processed and Purposes

2.1 Browsing data

The computer systems and software procedures on which this website is based acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This category includes IP addresses, browser and operating system type, URI of requested resources, request time, and other parameters relating to the visitor’s operating system.

These data are used solely for the purpose of obtaining anonymous statistical information on the use of the website and for monitoring its correct operation. They are deleted immediately after processing.

2.2 Registration to the “Italiani ad Abu Dhabi” Community

Through the registration form on the website, users can request access to the “Italiani ad Abu Dhabi” WhatsApp community. The data collected are:

  • First and last name
  • Email address
  • WhatsApp phone number (with international prefix)
  • User type (Resident / Tourist)
  • Consent to receive community communications (newsletter)
  • Date and time of registration and confirmation

Purpose: registration management, manual review of the request, sending the WhatsApp community access link, periodic community communications, annual verification of Abu Dhabi residency (with possible removal from the community in case of no response or negative response), access to the reserved area of the website via magic-link.

Legal basis: explicit consent of the data subject (Art. 6(1)(a) GDPR), expressed by checking the consent box in the registration form.

Retention: data are retained for the duration of the community membership and deleted within 30 days of removal or upon request by the data subject.

2.3 Automated email communications

In relation to community management, the website automatically sends the following types of emails:

  • Notification of receipt of the registration request
  • Annual residency verification (“Do you still live in Abu Dhabi?”)
  • Up to three reminders in case of no response to the verification
  • Notification of removal from the community
  • Magic-link for access to the reserved area of the website

Emails are sent via the SMTP server of Aruba S.p.A. (smtps.aruba.it), an Italian email provider with servers located in Italy.

2.4 Newsletter / Community communications

If the user has expressed consent to receive community-related communications (option “Yes” in the registration form), their email address may be used to send updates, news, and notices related to the “Italiani ad Abu Dhabi” community.

Legal basis: explicit consent (Art. 6(1)(a) GDPR).
Withdrawal: consent may be withdrawn at any time by writing to [email protected] or using the unsubscribe link in any communication.

2.5 Informational and presentation pages

The following pages of the website (About Me, Max Salvato Apps, Links, Home, Tourists) are exclusively informational or presentational. They do not contain contact forms nor collect personal data beyond the browsing data described in section 2.1 and the cookies described in section 2.6.

The Links and Max Salvato Apps pages contain links and icons to third-party social platforms (Instagram, YouTube, LinkedIn, X/Twitter, Pinterest, Threads). By clicking these links, users leave the website and access platforms subject to their respective privacy policies, over which the Controller has no control.

The Contact Form 7 plugin is installed in the system but is not currently used on any public page of the website. Should it be activated in the future, this policy will be updated to include the relevant purpose and legal basis.

2.6 Cookies and tracking technologies

For full details on the cookies used by the website, please refer to the Cookie Policy. In summary, the website uses:

  • Technical / functional cookies: necessary for the correct operation of the website (WordPress sessions, language preferences, authentication status).
  • Analytical cookies: via Google Analytics 4 (with IP anonymization), to analyze traffic in aggregate form.
  • Third-party cookies: Cloudflare (security and CDN), Google Tag Manager.

Cookie consent management is handled by the Complianz plugin, which displays a banner on first access and allows users to accept, reject, or customize their preferences.

3. Third-Party Services

The website uses the following third-party services that may process users’ personal data, including data transferred to non-EU third countries (USA). Such transfers are carried out in compliance with GDPR safeguards (standard contractual clauses, adequacy decisions, or equivalent mechanisms).

Service Provider Purpose Data processed Privacy Policy
Google Analytics 4 Google LLC (USA) Statistical traffic analysis IP (anonymized), pages visited, device, browser policies.google.com/privacy
Google Tag Manager Google LLC (USA) Management of tracking tags and scripts Browsing data (via managed tags) policies.google.com/privacy
Google Search Console Google LLC (USA) SEO performance monitoring Aggregated search queries, click data (anonymous) policies.google.com/privacy
Google AdSense Google LLC (USA) Contextual advertising (if active) Advertising cookies, browsing data policies.google.com/privacy
YouTube (video gallery) Google LLC (USA) Display of embedded YouTube videos IP, YouTube/Google cookies on widget load policies.google.com/privacy
Cloudflare Cloudflare, Inc. (USA) CDN, security, performance optimization, Turnstile CAPTCHA IP, HTTP headers, traffic data cloudflare.com/privacypolicy
Cloudflare Turnstile Cloudflare, Inc. (USA) Anti-bot verification / CAPTCHA in forms IP, browser behavioral data cloudflare.com/privacypolicy
Akismet Automattic, Inc. (USA) Anti-spam filter for comments Comment content, IP, commenter email automattic.com/privacy
Imagify WP Media SAS (France, EU) Automatic image optimization Image files uploaded to the website imagify.io/privacy-policy
Aruba SMTP Aruba S.p.A. (Italy, EU) Sending transactional and community emails Recipient email address, message content aruba.it – Privacy Policy
Elfsight YouTube Gallery Elfsight (USA) YouTube video gallery widget IP, browsing data on widget load elfsight.com/privacy-policy

For US-based Google services, data are transferred in compliance with Standard Contractual Clauses (SCC) approved by the European Commission and the EU–US Data Privacy Framework (where applicable).

International data transfers (UAE PDPL). The Controller is established in the UAE. Personal data are transferred to the following third countries:

  • Italy / EU (Aruba S.p.A., hosting and SMTP servers): the EU provides a data protection framework recognized as adequate at international level; the transfer is therefore permitted under the UAE PDPL.
  • USA (Google, Cloudflare, Automattic/Akismet, Elfsight): transfer takes place via standard contractual clauses (SCC) entered into by the respective providers, in compliance with the UAE PDPL and the GDPR.

Under the GDPR (extraterritorial application), transfers from the EU to the UAE — for example when a user accesses the website from Italy — are covered by the same safeguard mechanisms.

4. Legal Basis for Processing – Summary

Purpose Legal basis (Art. 6 GDPR)
Registration and management of the WhatsApp community Explicit consent (Art. 6(1)(a))
Service emails (magic-link, annual verification, removal) Performance of a contract / legitimate interest (Art. 6(1)(b)/(f))
Newsletter and community communications Explicit consent (Art. 6(1)(a))
Responding to contact form requests Pre-contractual measures / legitimate interest (Art. 6(1)(b)/(f))
Statistical traffic analysis (Google Analytics 4) Consent (Art. 6(1)(a)) – subject to acceptance of analytical cookies
Website security (Cloudflare, Akismet, Turnstile) Legitimate interest (Art. 6(1)(f))
Advertising (Google AdSense) Consent (Art. 6(1)(a)) – subject to acceptance of advertising cookies
Event companions/minors data Parental/guardian consent of the registering member (Arts. 6(1)(a) and 8 GDPR)

5. Processing Methods and Security Measures

Personal data are processed using computer and electronic means, in compliance with the technical and organizational security measures required by the GDPR. In particular:

  • The website is protected by an SSL/TLS certificate (encrypted HTTPS connection).
  • The infrastructure is managed via Cloudflare, which provides DDoS protection, application firewall, and network optimization.
  • Registration forms are protected by Cloudflare Turnstile to prevent automated submissions (spam/bots).
  • Emails are sent via encrypted SMTP connection (TLS, port 587) to Aruba servers.
  • Member data are stored in the WordPress database of the website, accessible only to the Controller via protected credentials.
  • Authentication tokens (magic-link, verification links) are generated with HMAC-SHA256 and have limited time validity.
  • Website access passwords are never shared; member authentication is exclusively via magic-link.

6. Data Retention

Data category Retention period
Community member data (name, email, WhatsApp, type) For the duration of membership + 30 days from removal
Email sending logs Not retained (logging function disabled)
Google Analytics 4 data 14 months (GA4 default setting)
Cloudflare cookies (security) Session / max 30 days (see Cloudflare documentation)
Contact form data Retained in the Controller’s inbox for the time strictly necessary to respond
Browsing data (server logs) Deleted immediately after statistical processing
Event companion data (including minors: name, surname, age) Max 12 months from the event; early deletion upon parental/guardian request

7. Rights of the Data Subject

As a data subject (EU or UAE resident), you have the right to:

  • Access (Art. 15 GDPR / Art. 7 UAE PDPL): obtain confirmation of processing and a copy of your data.
  • Rectification (Art. 16 GDPR / Art. 8 UAE PDPL): request correction of inaccurate or incomplete data.
  • Erasure (“right to be forgotten”) (Art. 17 GDPR / Art. 9 UAE PDPL): request deletion of your data, subject to legal obligations.
  • Restriction of processing (Art. 18 GDPR / Art. 10 UAE PDPL): request suspension of processing in certain circumstances.
  • Data portability (Art. 20 GDPR / Art. 11 UAE PDPL): receive your data in a structured, machine-readable format.
  • Objection (Art. 21 GDPR / Art. 12 UAE PDPL): object to processing based on the Controller’s legitimate interest, including direct marketing.
  • Withdrawal of consent (Art. 7 GDPR / UAE PDPL): withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
  • Complaint (Art. 77 GDPR / UAE PDPL): lodge a complaint with the competent supervisory authority.

To exercise your rights, write to: [email protected]
The Controller will respond within 20 working days of receiving the request (deadline under the UAE PDPL, more restrictive than the 30 days under the GDPR).

8. Supervisory Authorities

You have the right to lodge a complaint with the supervisory authority competent in your country of residence.

Primary authority — UAE (for all community members)

UAE Data Office (UAEDO) — federal authority competent under the UAE PDPL, as the Controller is established in Abu Dhabi:
Website: uaedataoffice.gov.ae
Email: [email protected]

The Controller is required to notify the UAE Data Office, without undue delay, of any personal data breach likely to result in a risk to the privacy or security of data subjects, and to directly inform affected data subjects in cases of high risk.

Secondary authority — EU (for data subjects with EU residence or nationality)

Garante per la Protezione dei Dati Personali (Italy) — competent extraterritorially under Art. 77 GDPR for data subjects of Italian nationality or residing in the EU:
Website: www.garanteprivacy.it
Email: [email protected]
PEC: [email protected]

9. Communication and Disclosure of Data

Personal data are not sold, transferred, or disclosed to third parties for commercial purposes. They may be communicated only to service providers acting as Data Processors under Art. 28 GDPR (e.g., Aruba for email sending, Cloudflare for network security), exclusively to the extent necessary for service provision.

Community member data are not visible to other community members. The Controller uses contact details (WhatsApp, email) exclusively for managing community access and service communications.

10. Annual Verification and Removal Process

To keep the community member list up to date, the Controller runs an annual automated verification process. Each active member receives an email asking “Do you still live in Abu Dhabi?”. The member has two options:

  • Confirm: data are updated and membership remains active.
  • I no longer live in Abu Dhabi: data are flagged for removal from the WhatsApp community.

In case of no response, up to three reminders are sent. If no response is received after the third reminder, the member is removed from the community and receives an email notification. Data are deleted from the database within 30 days of removal.

This process is carried out on the basis of the Controller’s legitimate interest in maintaining an up-to-date and relevant community (Art. 6(1)(f) GDPR) and by virtue of the consent given at the time of registration.

11. Data Relating to Minors

Registration to the community and access to the reserved area of the website are reserved for persons over 18 years of age.

However, at events organized by the community, an adult member may register their attendance including companions. Where the event expressly allows minors (“children admitted” option activated by the organizer), the member may list children or minors in their care as companions, providing for each:

  • First and last name
  • Type: “minor”
  • Age (integer)

Legal basis: the minor’s data are provided directly by the parent or legal guardian registering for the event. By entering such data, the parent/guardian declares that they hold parental responsibility and provides consent to processing pursuant to Arts. 6(1)(a) and 8 GDPR, Art. 2-quinquies of Legislative Decree 196/2003, and the UAE PDPL which sets the minimum age for independent consent to data processing at 18 years.

Purpose and processing limitation: companion minors’ data are used exclusively for event logistics (number of participants, possible age-group breakdown) and are not shared with third parties or used for any purpose other than that indicated.

Retention: companion data (including minors) are retained in the event registration for the time strictly necessary for its management and in any case no longer than 12 months from the event. The parent/guardian may request early deletion by writing to [email protected].

UAE Federal Decree-Law No. 26 of 2025 on Child Digital Safety. In compliance with the UAE law on digital safety of minors — in force from January 1, 2026 with a 12-month compliance period — the Controller undertakes to collect data of children under 13 only with explicit, documented, and verifiable parental consent. For minors aged 13 to 18, parental/guardian consent is still required under the UAE PDPL. Registration for events with minor companions falls within this perimeter: the parent completing the form acts as the consenting party.

The Controller does not collect data relating to minors in any context other than those described above. Should it become aware of unintentional processing of data relating to minors outside the cases indicated above, it will proceed with immediate deletion.

12. Changes to this Policy

The Controller reserves the right to modify this Privacy Policy at any time, in particular following regulatory changes or changes to the services used. The updated version will always be available on this page. Material changes will be communicated to community members by email.

Effective date of the latest version: June 15, 2026.