Privacy & Cookie Notice

Last updated: 29 September 2026

This page explains which personal data the site indoorcyclingitalia.it collects, why it collects them and what you can do to control them. It is written in plain language, as required by the European data protection regulation (GDPR, Reg. EU 2016/679).

1. Who processes your data

The data controller is Indoor Cycling Italia, VAT 13490390963, based in Bergamo.

You can contact the controller at lucafrigeni.mi@gmail.com or on WhatsApp at +39 351 302 8372.

2. What data we collect

We collect the data you give us only when you choose to: by filling in the contact form or the video courses waiting list (below), or by creating access to the class area (point 2.3). Added to those are the server's ordinary technical logs (point 2.1), which are created automatically on every visit, as on any website.

DataWhy it is neededRequired
NameTo address you properlyYes
EmailTo reply to youYes
PhoneTo get back to you more quickly, if you preferNo
Service of interestTo understand what you needYes
MessageThe content of your requestYes
IP addressRecorded with the submission, for security and to prevent abuseAutomatic

The site shows no advertising. To find out how many people visit it, it uses an anonymous counter that sets no cookies, described at point 6.1. Only if you accept it from the cookie banner, it also uses the Meta pixel to measure the results of its own ads on Instagram and Facebook (point 6.2): without your consent nothing is sent to Meta.

2.1 Technical server logs

The server that hosts the site (Aruba) automatically records, for every page requested, the IP address, the date and time, the page visited and the type of browser. This is how any web server normally works: the logs exist for security and for diagnosing faults, not to identify people or build profiles. These logs are managed by Aruba according to its own retention policies.

2.2 Backup copy of the requests

If, because of a temporary fault of the mail service, a request cannot be sent, its content is saved in a file on the server so that it is not lost. The file is not accessible from the web and is protected both by the server configuration and by the format in which it is written. It is opened only to recover the requests left behind and is then cleared, within the time limits indicated at point 4 at the latest.

2.3 The class area

If you create access to the video courses area, in addition to the above we process:

DataWhy it is needed
NameTo address you inside the area
EmailTo recognise you when you sign in, and to check whether you are on the waiting list
Password (if you sign in with email and password)To protect your access. Nobody sees it, not even the controller: it is stored only as an irreversible code, from which the password cannot be worked out
Only if you choose “Continue with Google”: name, email (and whether Google has verified it), profile picture, the identifier of your Google account and, for business Google accounts, the organisation's domainTo create your access and recognise you the next times, without a password. We do not receive your Google password, nor your contacts, your mail or any other content of your account
Classes watched, where you stopped, completed and favourite classesSo that you can pick up where you left off, on any device
Subscription status and expiry dateTo know whether you have access to the classes
A fingerprint of your email (the same kind of code described at point 2.4, from which the email cannot be read)To give only one free place to each mailbox, even if the address is written in different ways
IP address and time of sign inRecorded automatically by the sign in system, for security

2.4 The video courses waiting list

The waiting list form works like the contact form. In addition, to count the places available and to recognise you when you activate free access, the server keeps an fingerprint of your email address: a code calculated from the address, which does not contain it and from which it cannot be read. When you activate access, the class area asks the site whether that fingerprint is on the list: only the fingerprint travels, never the email.

You can also join the list from the form of an ad on Instagram or Facebook. In that case your name and email are collected by Meta inside the form and made available to the controller, who handles them like the requests sent from the site (point 4) and puts only the fingerprint of the email on the list, as above. For the data collected in the form, Meta Platforms Ireland Limited is an independent controller: it uses them according to its own privacy policy, for example to prefill future forms. If you join this way, you have 30 days to activate free access to the class area with the same email: if you do not, the fingerprint is removed from the list and the place goes back to whoever is waiting.

2.5 Newsletter

The forms have two optional boxes, separate from the one to be contacted back. If you do not tick them the form works just the same and you only receive the answer to your request.

You can withdraw your consent to measurement while staying subscribed, or unsubscribe completely, at any time: by writing to the address in point 1 or, for the newsletter, through the link at the bottom of every email. Every choice is recorded with its date.

3. Why we may process them (legal basis)

4. How long we keep them

The requests we receive stay in the mailbox for the time needed to handle them and, if the contact goes no further, they are deleted within 24 months. If instead you become a client, the data are kept for the time required by tax and accounting obligations (10 years).

The backup copy described at point 2.2 is emptied as soon as the requests have been recovered and in any case within 6 months. When you exercise the right to erasure, the check covers both the mailbox and that file.

The class area data (point 2.3) are kept for as long as you keep your access. You can ask for them to be deleted at any time by writing to the address at point 1: the account, your progress, the subscription and the records of your sign ins kept in the database are deleted together. In addition, Supabase keeps technical logs for the operation of its own service, which delete themselves within one week at most.

The waiting list fingerprint (point 2.4) is needed only for the free phase of the video courses: it is kept for as long as that phase lasts and, when it closes, the archive is emptied. If you joined from the form of an ad and do not activate access within 30 days, it is removed earlier. It is also deleted earlier if you withdraw your consent or ask for it to be deleted, even if you never created access to the class area. The copy stored with your subscription (point 2.3) is instead kept for as long as you keep your access, and is deleted together with the account.

The data collected by the Meta pixel (point 6.2) are kept by Meta according to its own privacy policy; the _fbp cookie stays in your browser for at most 90 days, or until you withdraw your consent.

The newsletter name and email (point 2.5) are kept until you unsubscribe or withdraw your consent. After that, the address stays only in the list of people who no longer want to receive it, so that we do not write to you again by mistake.

5. Who else sees them

Your data are neither sold nor transferred. They are accessed only by:

If you choose to write on WhatsApp, the conversation takes place on the platform of Meta and remains subject to the terms and the privacy notice of Meta: the site neither records nor keeps anything of that exchange.

Without your consent this site uses no profiling cookies and no statistics cookies: the visit count described at point 6.1 works without cookies. The only marketing tool is the Meta pixel (point 6.2), which starts only if you press “Accept” in the banner shown on your first visit. “Accept” and “Reject” carry the same weight, and closing the banner with the X counts as a rejection.

Apart from that, the site uses only technical tools, which do not require prior consent (art. 122 of the Italian Privacy Code):

The typefaces and the libraries used by the class area are hosted directly on this server: no request to download them is forwarded to Google or to any other external provider.

6.1 Counting visits

To know how many people visit the site and which pages they read, Cloudflare Web Analytics (Cloudflare, Inc.) is used. It is a tool without cookies: it stores nothing on your device, it creates no identifiers that follow you from one visit to the next and it does not recognise you on other sites. The data are aggregated: number of visits, pages viewed and referring site.

One thing should be said plainly: to count the visit your browser contacts a Cloudflare server, which at that moment sees your IP address. Cloudflare uses it for the count and does not keep it in a form that can be traced back to you. As there are neither cookies nor profiling, this measurement does not require prior consent and stays outside the cookie banner. If you prefer not to be counted, turn on your browser's Do Not Track option: the site respects it and in that case does not load the tool at all.

6.2 Meta pixel (only with your consent)

Only if you press “Accept” in the banner does the site load the Meta pixel, provided by Meta Platforms Ireland Limited (Block J, Serpentine Avenue, Dublin 4, Ireland). Until then your browser does not contact Meta in any way.

7. Your rights

You may at any time ask to:

To exercise them write to lucafrigeni.mi@gmail.com: you will receive an answer within 30 days. If you believe your data are being processed improperly you can contact the Italian data protection authority (Garante per la protezione dei dati personali).

8. Changes

If this notice changes, the update date at the top of the page will be changed accordingly. Do read it again from time to time.

← Back to the site