Information on the Processing of Personal Data pursuant to Article 13 of Regulation (EU) 2016/679 – GDPR
Last updated: 8 September 2026
1. Data Controller
The Data Controller of the personal data collected through the website kirilcholakov.com is:
Kiril Cholakov
Via San Giuliano 21
47921 Rimini (RN), Italy
E-mail: kirilcholakov@gmail.com
2. Types of Data Processed
The website is primarily an informational and presentation website for the artistic activities of Kiril Cholakov.
Through simple browsing of the website, certain technical browsing data necessary for the operation and security of the website may be processed, including, by way of example:
- IP address;
- information relating to the browser and device used;
- date and time of the request;
- pages visited;
- technical information relating to the connection.
Such data is processed primarily to ensure the proper functioning of the website, maintain the security of the infrastructure and prevent any abuse or cyberattacks.
The website does not require user registration or the completion of data collection forms for simple browsing.
Data Voluntarily Provided by E-mail
If the user voluntarily decides to contact the Data Controller using the address kirilcholakov@gmail.com, the Data Controller may acquire the personal data contained in the communication, including the sender’s e-mail address and any additional data voluntarily provided in the message.
Such data will be used exclusively to respond to the request received and for any activities arising from that request.
3. Purposes and Legal Bases of Processing
Personal data may be processed for the following purposes:
a) Website operation and technical management
To ensure the correct display and use of the website, as well as the security and proper functioning of the IT systems.
The legal basis is the legitimate interest of the Data Controller in managing, securing and maintaining its website, pursuant to Article 6(1)(f) GDPR.
b) Responding to users’ communications
To respond to requests voluntarily sent by e-mail.
The legal basis is the performance of pre-contractual measures or, depending on the content of the request, the legitimate interest of the Data Controller in managing and responding to communications received, pursuant to Article 6(1)(b) or (f) GDPR.
c) Compliance with legal obligations
Where necessary, data may be processed to comply with obligations established by law, regulations or European legislation.
The relevant legal basis is compliance with a legal obligation, pursuant to Article 6(1)(c) GDPR.
4. Processing Methods
Personal data is processed using IT and telecommunications tools, in accordance with the principles of fairness, lawfulness, transparency, data minimisation and security.
Appropriate technical and organisational measures are adopted according to the nature of the data processed and the risks associated with the processing.
The data will not be used for user profiling purposes or for advertising purposes through the website, except for any future changes, which will be subject to specific information notices.
5. Disclosure of and Recipients of Data
Personal data may be accessible, to the extent strictly necessary for their respective activities, to entities providing technical services necessary for the operation of the website, including the hosting service provider Tantra Host, as well as any providers of technical and IT services used for the management and maintenance of the website.
Such entities will process the data exclusively for purposes connected with the services provided and, where the relevant requirements are met, as data processors pursuant to Article 28 GDPR.
The data will not be made publicly available or transferred to third parties for commercial or advertising purposes.
6. Data Retention Period
Personal data will be retained for the period necessary to achieve the purposes for which it was collected.
In particular:
- technical browsing data will be retained for the period necessary to ensure the operation and security of the website and IT systems, according to the procedures and time periods established by the relevant technical systems;
- data contained in e-mail communications will be retained for the time necessary to manage the request and, subsequently, for any period necessary to protect the rights of the Data Controller or comply with legal obligations.
7. Cookies and Other Tracking Technologies
The website may use cookies and similar technologies that are strictly necessary for its proper functioning.
Technical cookies, when used exclusively to enable navigation or provide a functionality requested by the user, do not require the user’s consent, without prejudice to the obligation to provide adequate information.
The website is not currently configured, based on the information available at present, to use advertising profiling tools or tracking systems aimed at creating user profiles.
Note: the actual presence and configuration of cookies and any external services will be verified as part of the technical analysis of the website. If cookies or tracking technologies other than technical cookies are used, this section and any Cookie Policy will be updated accordingly. For non-technical tools requiring consent, the Italian Data Protection Authority (Garante) provides for specific information and prior consent requirements.
8. External Services and Embedded Content
The website may contain links to or, where applicable, content provided by external services.
Any processing of data carried out independently by such parties is governed by their respective privacy policies.
In particular, any use of external services involving the transfer of personal data to third parties or countries outside the European Economic Area will be assessed and indicated in the website’s privacy documentation, where applicable.
9. Transfer of Data to Third Countries
The Data Controller does not intentionally transfer personal data to countries located outside the European Economic Area for its own purposes.
Any transfers carried out by technical service providers used by the website will be assessed on the basis of the information and safeguards provided by the relevant providers and in compliance with applicable legislation.
10. Data Subject Rights
The data subject, in the cases provided for by applicable legislation, has the right to:
- obtain confirmation as to whether or not personal data concerning them exists;
- obtain access to their personal data;
- request the rectification of inaccurate data;
- request the erasure of data in the cases provided for by law;
- request the restriction of processing;
- object to processing where the relevant conditions are met;
- obtain data portability in the cases provided for by Article 20 GDPR;
- withdraw any consent given, without affecting the lawfulness of processing carried out before the withdrawal;
- lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali).
The Garante confirms that the privacy notice must indicate the rights of the data subject and the right to lodge a complaint with the supervisory authority.
11. How to Exercise Your Rights
To exercise their rights or to receive information concerning the processing of personal data, the data subject may contact the Data Controller:
Kiril Cholakov
Via San Giuliano 21
47921 Rimini (RN), Italy
E-mail: kirilcholakov@gmail.com
12. Supervisory Authority
A data subject who believes that the processing of their personal data is being carried out in violation of applicable legislation may lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), in accordance with the procedures established by applicable legislation.
13. Updates to the Privacy Policy
This Privacy Policy may be modified or updated to reflect any regulatory, technical or organisational changes relating to the website.
The updated version will be published on this page, indicating the date of the latest update.