Privacy & Cookie Notice
Last updated: 29 September 2026
This page explains which personal data the site indoorcyclingitalia.it collects, why it collects them and what you can do to control them. It is written in plain language, as required by the European data protection regulation (GDPR, Reg. EU 2016/679).
1. Who processes your data
The data controller is Indoor Cycling Italia, VAT 13490390963, based in Bergamo.
You can contact the controller at lucafrigeni.mi@gmail.com or on WhatsApp at +39 351 302 8372.
2. What data we collect
We collect the data you give us only when you choose to: by filling in the contact form or the video courses waiting list (below), or by creating access to the class area (point 2.3). Added to those are the server's ordinary technical logs (point 2.1), which are created automatically on every visit, as on any website.
| Data | Why it is needed | Required |
|---|---|---|
| Name | To address you properly | Yes |
| To reply to you | Yes | |
| Phone | To get back to you more quickly, if you prefer | No |
| Service of interest | To understand what you need | Yes |
| Message | The content of your request | Yes |
| IP address | Recorded with the submission, for security and to prevent abuse | Automatic |
The site shows no advertising. To find out how many people visit it, it uses an anonymous counter that sets no cookies, described at point 6.1. Only if you accept it from the cookie banner, it also uses the Meta pixel to measure the results of its own ads on Instagram and Facebook (point 6.2): without your consent nothing is sent to Meta.
2.1 Technical server logs
The server that hosts the site (Aruba) automatically records, for every page requested, the IP address, the date and time, the page visited and the type of browser. This is how any web server normally works: the logs exist for security and for diagnosing faults, not to identify people or build profiles. These logs are managed by Aruba according to its own retention policies.
2.2 Backup copy of the requests
If, because of a temporary fault of the mail service, a request cannot be sent, its content is saved in a file on the server so that it is not lost. The file is not accessible from the web and is protected both by the server configuration and by the format in which it is written. It is opened only to recover the requests left behind and is then cleared, within the time limits indicated at point 4 at the latest.
2.3 The class area
If you create access to the video courses area, in addition to the above we process:
| Data | Why it is needed |
|---|---|
| Name | To address you inside the area |
| To recognise you when you sign in, and to check whether you are on the waiting list | |
| Password (if you sign in with email and password) | To protect your access. Nobody sees it, not even the controller: it is stored only as an irreversible code, from which the password cannot be worked out |
| Only if you choose “Continue with Google”: name, email (and whether Google has verified it), profile picture, the identifier of your Google account and, for business Google accounts, the organisation's domain | To create your access and recognise you the next times, without a password. We do not receive your Google password, nor your contacts, your mail or any other content of your account |
| Classes watched, where you stopped, completed and favourite classes | So that you can pick up where you left off, on any device |
| Subscription status and expiry date | To know whether you have access to the classes |
| A fingerprint of your email (the same kind of code described at point 2.4, from which the email cannot be read) | To give only one free place to each mailbox, even if the address is written in different ways |
| IP address and time of sign in | Recorded automatically by the sign in system, for security |
2.4 The video courses waiting list
The waiting list form works like the contact form. In addition, to count the places available and to recognise you when you activate free access, the server keeps an fingerprint of your email address: a code calculated from the address, which does not contain it and from which it cannot be read. When you activate access, the class area asks the site whether that fingerprint is on the list: only the fingerprint travels, never the email.
You can also join the list from the form of an ad on Instagram or Facebook. In that case your name and email are collected by Meta inside the form and made available to the controller, who handles them like the requests sent from the site (point 4) and puts only the fingerprint of the email on the list, as above. For the data collected in the form, Meta Platforms Ireland Limited is an independent controller: it uses them according to its own privacy policy, for example to prefill future forms. If you join this way, you have 30 days to activate free access to the class area with the same email: if you do not, the fingerprint is removed from the list and the place goes back to whoever is waiting.
2.5 Newsletter
The forms have two optional boxes, separate from the one to be contacted back. If you do not tick them the form works just the same and you only receive the answer to your request.
- Newsletter: if you tick it, your name and email join the list of people who receive news, courses and offers from Indoor Cycling Italia. Every email has a link at the bottom to unsubscribe with one click.
- Measurement: it appears only if you choose the newsletter. The newsletters contain an invisible image (pixel) and links that tell whether an email was opened and which links were clicked. With your consent this data is linked to your address, to understand what interests you and write to you less and better. Without your consent opens and clicks are only counted anonymously and in total (for example "40 opens overall"), without knowing who opened.
You can withdraw your consent to measurement while staying subscribed, or unsubscribe completely, at any time: by writing to the address in point 1 or, for the newsletter, through the link at the bottom of every email. Every choice is recorded with its date.
3. Why we may process them (legal basis)
- Your consent (art. 6.1.a GDPR), which you give by ticking the box before sending the form.
- Your specific consent (art. 6.1.a GDPR, arts. 122 and 130 of the Italian Privacy Code) for the newsletter and, separately, for measuring opens: two optional boxes, separate from the one to be contacted back (point 2.5).
- Your consent to marketing cookies (art. 6.1.a GDPR and art. 122 of the Italian Privacy Code) for the Meta pixel (point 6.2): you give it by pressing “Accept” in the banner and you withdraw it whenever you like from “Cookie preferences”, at the bottom of every page.
- Pre-contractual measures (art. 6.1.b GDPR): replying to a request for information about a service, or to someone asking to join the waiting list (also from the form of an ad), is a preliminary step towards a possible agreement.
- Performance of the service you asked for (art. 6.1.b GDPR): the class area data described at point 2.3 are what let you sign in and train. Without them the service cannot work.
- Legitimate interest (art. 6.1.f GDPR) for the recording of the IP address and for the technical logs: they serve to protect the site from automated submissions and abuse, and to demonstrate that consent was given.
4. How long we keep them
The requests we receive stay in the mailbox for the time needed to handle them and, if the contact goes no further, they are deleted within 24 months. If instead you become a client, the data are kept for the time required by tax and accounting obligations (10 years).
The backup copy described at point 2.2 is emptied as soon as the requests have been recovered and in any case within 6 months. When you exercise the right to erasure, the check covers both the mailbox and that file.
The class area data (point 2.3) are kept for as long as you keep your access. You can ask for them to be deleted at any time by writing to the address at point 1: the account, your progress, the subscription and the records of your sign ins kept in the database are deleted together. In addition, Supabase keeps technical logs for the operation of its own service, which delete themselves within one week at most.
The waiting list fingerprint (point 2.4) is needed only for the free phase of the video courses: it is kept for as long as that phase lasts and, when it closes, the archive is emptied. If you joined from the form of an ad and do not activate access within 30 days, it is removed earlier. It is also deleted earlier if you withdraw your consent or ask for it to be deleted, even if you never created access to the class area. The copy stored with your subscription (point 2.3) is instead kept for as long as you keep your access, and is deleted together with the account.
The data collected by the Meta pixel (point 6.2) are kept by Meta according to its own
privacy policy; the _fbp cookie stays in your browser for at most 90 days,
or until you withdraw your consent.
The newsletter name and email (point 2.5) are kept until you unsubscribe or withdraw your consent. After that, the address stays only in the list of people who no longer want to receive it, so that we do not write to you again by mistake.
5. Who else sees them
Your data are neither sold nor transferred. They are accessed only by:
- Aruba S.p.A., provider of the hosting and of the mail service, acting as data processor. The servers are in the European Union. The emails of the sign in system (the confirmation of your sign up, the link to reset your password) are also sent from the site's mailbox: with no images that record when you open them and no links that track clicks.
- Google Ireland Ltd.: if the requests are delivered to a Gmail mailbox, the provider of the mail service has technical access to them.
- AIYORA Enterprise: a copy of the request is sent to the management system with which the controller organises contacts, so that no request is lost and you can be answered. The management system is hosted on Cloudflare, Inc. (Cloudflare Pages platform), which also acts as sub-processor. Cloudflare adheres to the Data Privacy Framework between the European Union and the United States, the framework that makes the transfer of data to the United States lawful.
- Supabase Pte. Ltd. (Singapore), which provides the database and the sign in system of the class area, acting as data processor. The data at point 2.3 are stored on servers in the European Union, in Frankfurt (Germany). For any access from outside the Union, Supabase applies the Standard Contractual Clauses approved by the European Commission. The list of its sub-processors is published on supabase.com.
- Google Ireland Ltd., only if you choose “Continue with Google”: you confirm the sign in on Google’s page, which then gives us the data listed at point 2.3. What Google does with your account remains governed by Google’s privacy policy.
- Cloudflare, Inc., for the videos: the classes are stored on Cloudflare R2 and reach your device from there. At that moment Cloudflare sees your IP address, as with any content downloaded from the internet. The videos contain none of your data.
- Brevo (Sendinblue SAS, France), the platform that sends the newsletter and, when active, the automatic confirmations of requests sent through the form, acting as data processor: it receives the name and email of subscribers or of people who wrote through the form and, if you consented to measurement, the newsletter opens and clicks linked to your address.
- Anthropic PBC (United States), provider of the artificial intelligence used by the AIYORA Enterprise management system: when the owner asks for a draft reply, name, chosen service and message are sent to write it. The owner reads and sends the draft: no reply goes out on its own. The transfer to the United States takes place with the safeguards required by the GDPR (arts. 44-49).
- Meta Platforms Ireland Limited: only if you accept marketing cookies (point 6.2) and, if you join the waiting list from the form of an ad, for the data collected in the form (point 2.4).
- Website assistant (chatbot): on the website pages you can ask questions to an automated assistant based on artificial intelligence. The questions you type go through the AIYORA Enterprise management system (hosted on Cloudflare) and are sent to Anthropic PBC only to write the answer, which the assistant prepares with the information published by Indoor Cycling Italia. The management system does not keep the text of the conversation, which stays in your browser while the page is open. If you decide to leave your name and contact details, they reach the owner together with your last questions so that you can be contacted, only with your consent, and they are kept like the requests sent from the contact form. If you use the microphone (when available), your voice is transcribed by your browser's speech service (Google or Apple) before being sent as text.
If you choose to write on WhatsApp, the conversation takes place on the platform of Meta and remains subject to the terms and the privacy notice of Meta: the site neither records nor keeps anything of that exchange.
6. Cookies
Without your consent this site uses no profiling cookies and no statistics cookies: the visit count described at point 6.1 works without cookies. The only marketing tool is the Meta pixel (point 6.2), which starts only if you press “Accept” in the banner shown on your first visit. “Accept” and “Reject” carry the same weight, and closing the banner with the X counts as a rejection.
Apart from that, the site uses only technical tools, which do not require prior consent (art. 122 of the Italian Privacy Code):
- the
PHPSESSIDcookie, created when you send a form: its only purpose is to prevent repeated automated submissions (spam), and it deletes itself when you close the browser; - the language you chose and that of the last page you read, saved in your browser's storage, to show you the site and the class area in Italian or English. They contain only the language code, no data about you;
- only if you enter the class area, the sign in session, saved in your browser's storage: it is what keeps you signed in as you move from one class to another, and it is removed when you sign out. If you use Google to sign in, it also holds a temporary code issued by Google, valid for about one hour, which the site does not use;
- your choice in the cookie banner (accept or reject) and its date, saved in your browser's storage, so that you are not asked on every page. If you reject, the banner does not appear again for 6 months;
- only right after you join the waiting list, your email, kept in the storage of the open tab to fill it in for you when you sign up to the class area. It disappears when you close the tab.
The typefaces and the libraries used by the class area are hosted directly on this server: no request to download them is forwarded to Google or to any other external provider.
6.1 Counting visits
To know how many people visit the site and which pages they read, Cloudflare Web Analytics (Cloudflare, Inc.) is used. It is a tool without cookies: it stores nothing on your device, it creates no identifiers that follow you from one visit to the next and it does not recognise you on other sites. The data are aggregated: number of visits, pages viewed and referring site.
One thing should be said plainly: to count the visit your browser contacts a Cloudflare server, which at that moment sees your IP address. Cloudflare uses it for the count and does not keep it in a form that can be traced back to you. As there are neither cookies nor profiling, this measurement does not require prior consent and stays outside the cookie banner. If you prefer not to be counted, turn on your browser's Do Not Track option: the site respects it and in that case does not load the tool at all.
6.2 Meta pixel (only with your consent)
Only if you press “Accept” in the banner does the site load the Meta pixel, provided by Meta Platforms Ireland Limited (Block J, Serpentine Avenue, Dublin 4, Ireland). Until then your browser does not contact Meta in any way.
- What it collects: the pages you visit on this site; some actions, namely the successful sending of a form, joining the waiting list and clicking on WhatsApp or on the email link; browser and device identifiers; the IP address. The site does not send Meta your name, email, phone number or the text of your messages: only the type of page or request.
- Why: to measure how many people arrive from the ads on Instagram and Facebook and what they do on the site, and to show ads to people who have already visited the site.
- Cookie:
_fbp, stored on this site's domain, lasting at most 90 days. - Joint controllership: for the collection of these data and their transmission to Meta, the controller and Meta Platforms Ireland are joint controllers (art. 26 GDPR), under the terms of Meta's business tools. What Meta does afterwards with the data it receives is decided by Meta, as an independent controller, and is described in its privacy policy.
- Transfer outside the EU: the data may reach Meta Platforms, Inc. in the United States, which participates in the EU-U.S. Data Privacy Framework.
- How to change your mind: “Cookie preferences”, at the bottom of every page, reopens the choice. If you withdraw, the pixel is no longer loaded by the following pages and the
_fbpcookie is deleted from your browser.
7. Your rights
You may at any time ask to:
- know which data concerning you are kept (access);
- correct them if they are wrong or incomplete (rectification);
- have them erased (erasure);
- restrict the processing or object to it;
- receive them in a format a computer can read (portability);
- withdraw the consent already given, without this invalidating what was done before.
To exercise them write to lucafrigeni.mi@gmail.com: you will receive an answer within 30 days. If you believe your data are being processed improperly you can contact the Italian data protection authority (Garante per la protezione dei dati personali).
8. Changes
If this notice changes, the update date at the top of the page will be changed accordingly. Do read it again from time to time.
← Back to the site