Privacy Notice

Last updated: 02/08/2026

This notice explains how Sarfatti Strategy processes the personal data of users of sarfattistrategy.com and of the services offered through the site. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR").

For each category of data it states why we process it, the legal basis that permits us to, who may receive it and how long we keep it. Your rights and how to exercise them are at point 9.

This is a translation provided for convenience. The service is operated from Italy and governed by Italian and EU law: in case of any discrepancy, the Italian version of this notice prevails.

1. Data controller

The controller of the personal data collected through the site is the operator of Sarfatti Strategy. You can contact us at [email protected].

For anything concerning personal data, including the rights described at point 9, write to [email protected].

No Data Protection Officer has been appointed, as the conditions in Article 37 GDPR do not apply. Please use the contact details above.

2. What data we process

We process only the categories listed below. We do not process special categories of data under Article 9 GDPR and we do not ask you to provide them.

CategorySpecific dataSource
Account dataEmail address, password (stored only as a hash), first and last name, profile picture if uploaded, chosen track (Bachelor or Master), interface language, account creation and last update dates.Provided by you at sign-up or later from your profile.
Booking dataFor consultations: name, email address, phone number if given, chosen date and time, plan of interest, any notes you add. For tutoring sessions: user, date and time, duration, amount, assigned tutor, any notes.Provided by you when booking.
Subscription and payment dataPlan type, related track, subscription status, start and expiry dates, payment outcomes, remaining tutoring credits.Generated by your use of the service and received from the payment provider.
Simulation activity dataAnswers given, correct and incorrect answers, scores, time spent per question and per category, status and date of each attempt, language used, question order.Generated automatically while you use the simulations and the question bank.
Affiliate programme dataPersonal affiliate code, click and conversion counts, commissions earned. For each click on an affiliate link: visitor IP address, browser user agent, landing page, date and time.Generated by use of affiliate links. Clicks are recorded only after consent to non-essential cookies (point 6).
Technical and browsing dataIP address, browser and operating system, date and time of requests, pages requested, data held in server and network security logs.Collected automatically by the infrastructure serving the site.
Communication dataThe content of emails and support requests you send us, and their metadata.Provided by you.

We never see your payment card details. Card number, expiry and security code are collected and processed directly by the payment provider on its own pages: we receive only the outcome of the transaction and the data needed for invoicing and support.

3. Why we process it and on what legal basis

Article 6 GDPR permits processing only where one of the legal bases it lists applies. For each purpose, the basis we rely on is stated below.

PurposeLegal basis
Creating and running your account, authenticating you, keeping your session active.Performance of the contract to which you are party: Art. 6(1)(b) GDPR.
Delivering the services purchased: simulations, question bank, marking, performance statistics, tutoring sessions, consultations.Performance of the contract: Art. 6(1)(b) GDPR.
Handling bookings, confirmations, reminders, cancellations and rescheduling.Performance of the contract: Art. 6(1)(b) GDPR.
Managing subscriptions, payments, renewals, refunds and related support.Performance of the contract: Art. 6(1)(b) GDPR.
Issuing and retaining tax and accounting records.Compliance with a legal obligation: Art. 6(1)(c) GDPR.
Recording clicks on affiliate links and attributing a purchase to the affiliate who generated it.Consent: Art. 6(1)(a) GDPR and Art. 122 of Legislative Decree 196/2003. You may withdraw it at any time (point 6).
Keeping the site secure, preventing abuse, unauthorised access and fraud, maintaining technical logs.Our legitimate interest in protecting the service and its users: Art. 6(1)(f) GDPR.
Establishing or defending a legal claim, in or out of court.Our legitimate interest in protecting our rights: Art. 6(1)(f) GDPR.
Measuring site traffic in aggregate, anonymous form.Our legitimate interest in understanding how the site performs. Measurement uses no cookies and no individual identifiers (point 6).

Providing account, booking and payment data is necessary to enter into and perform the contract: without it we cannot activate the service. Providing data that depends on consent is entirely optional, and refusing does not affect your access to the services in any way.

4. Who we share data with

We do not sell your data and we do not pass it to third parties for their own purposes. We do use suppliers who process data on our behalf, appointed as processors under Article 28 GDPR, and parties acting as independent controllers for obligations imposed on them by law.

SupplierActivityData involved
SupabaseDatabase, authentication system and server-side application functions.All account, booking, subscription, simulation activity and affiliate data. The database is located in the eu-west-3 (Unione europea, Parigi) region.
CloudflareSite hosting, content delivery network, DNS, attack protection and aggregate traffic measurement.Technical and browsing data, IP address.
StripePayments, subscriptions and the billing portal.Identification and contact data needed for the transaction, card data collected directly by Stripe, payment history.
ResendSending service emails: confirmations, reminders, account messages.Email address, name, content of the message.
BrevoSending email communications and managing the related lists.Email address, name.
NamecheapEmail service on the domain.Content and metadata of the emails you exchange with us.
DiscordInternal operational notifications to our team about new sign-ups and bookings.Email address and essential booking details.

Data may also be shared with professionals advising us on accounting, tax and legal matters, and with public authorities where disclosure is required by law or necessary to establish or defend a legal claim.

Tutors assigned to individual sessions are given access only to the data needed to deliver the session assigned to them.

5. Transfers outside the European Economic Area

The database holding your account, booking and simulation data is located in the European Union, in the eu-west-3 (Unione europea, Parigi) region. Storage alone therefore involves no transfer to a third country for that data.

Some of the suppliers listed at point 4 are, however, companies established in the United States and may access or process data outside the European Economic Area. The GDPR permits such transfers only where adequate safeguards are in place.

On 10 July 2023 the European Commission adopted an adequacy decision on the EU-U.S. Data Privacy Framework under Article 45 GDPR: transfers to United States organisations certified under that framework need no further authorisation. The General Court of the European Union confirmed the decision's validity on 3 September 2025. Stripe and Cloudflare appear on that list as active participants.

For suppliers not covered by the adequacy decision, transfers rely on the standard contractual clauses adopted by the European Commission under Article 46(2)(c) GDPR, as provided for in the data processing agreements in place with each of them.

You can request a copy of the safeguards applied by writing to [email protected].

6. Cookies and tracking tools

Article 122 of Legislative Decree 196/2003 allows information to be stored on your device, or already stored information to be accessed, only with your consent. Tools strictly necessary to provide a service you have explicitly requested are exempt.

The site uses the following tools, and no others.

ToolTypePurpose and duration
Authentication sessionTechnical, no consent requiredBrowser local storage. Keeps you signed in across pages. Persists until you log out or the session expires.
Language and track preferenceTechnical, no consent requiredBrowser local storage. Remembers your interface language and whether you selected the Bachelor or Master track, so you are not asked on every visit.
Record of your cookie choiceTechnical, no consent requiredBrowser local storage. Stores the choice you make in the banner so it is not shown again. Necessary precisely in order to honour your decision.
ref_codeAttribution cookie, consent requiredFirst-party cookie, 30 days. Records the code of the affiliate who referred you, so that a commission can be credited if you purchase. Set only if you consent, and deleted if you refuse or withdraw.
Cloudflare Web AnalyticsAggregate measurement, no cookiesSets no cookie, writes no identifier to your device and does not track individual visitors. It produces only aggregate statistics on page views and traffic sources.
PostHog (product analytics)Without consent: cookieless measurement. With consent: analytics cookiesProvided by PostHog, with data stored in the European Union (Frankfurt). Until you make a choice, and if you refuse, it runs in cookieless mode: it writes no identifier to your device and produces aggregate statistics on page views and navigation steps, on the basis of our legitimate interest in understanding how the site is used (Art. 6(1)(f) GDPR). If you consent, it sets first-party cookies that allow visits to be linked to the same person and the browsing session to be recorded for usability analysis, on the basis of your consent (Art. 6(1)(a)). Your IP address is not retained. You can withdraw consent at any time through the "Cookie preferences" link.

On your first visit a banner appears that follows the guidelines on cookies and other tracking tools adopted by the Italian Data Protection Authority on 10 June 2021. It lets you accept or refuse using commands of identical size, emphasis and colour, and it can be closed using the command marked with an X: in that case only the default settings remain, meaning no non-essential cookies.

Continuing to browse, scrolling the page or doing nothing does not count as consent. Access to content is in no way conditional on accepting non-essential cookies.

You can change or withdraw your choice at any time through the "Cookie preferences" link at the bottom of every page. Withdrawal does not affect the lawfulness of processing carried out beforehand. You can also delete cookies already set from your browser settings.

7. How long we keep data

We keep data only as long as necessary for the purposes for which it was collected, and afterwards for any period the law requires us to retain it or during which it may be needed to establish or defend a legal claim.

DataRetention period
Account and profile dataFor the duration of the relationship. If the account is deleted, data is erased except what must be retained to comply with legal obligations.
Simulation activity dataFor the duration of the relationship, as it forms the record of your progress. Erased when the account is deleted.
Consultation and tutoring bookingsFor as long as needed to deliver the service and deal with its consequences, and in any event within the retention periods for contractual records.
Tax and accounting records and payment dataFor the period required by the applicable tax and accounting rules on retention of records.
Affiliate programme data and recorded clicksFor as long as needed to calculate and settle commissions and handle any disputes about them.
ref_code cookie30 days from being set, or until consent is withdrawn if sooner.
Technical and security logsFor as long as strictly necessary for security purposes, according to the settings of the infrastructure suppliers listed at point 4.

8. Minors

Our services are also aimed at students preparing for university admission, who may be under 18.

Article 8 GDPR and Article 2-quinquies of Legislative Decree 196/2003 provide that, in Italy, a minor who has reached the age of fourteen may validly consent to the processing of their personal data in relation to information society services offered directly to them. Below the age of fourteen, processing based on consent is lawful only where consent is given by the holder of parental responsibility.

The capacity to consent to data processing is separate from the capacity to enter into a contract, which is dealt with in the Terms and Conditions.

If you believe a minor has provided personal data without the required consent, write to [email protected]: we will check and delete it.

9. Your rights

The GDPR gives you the following rights, which you can exercise free of charge.

  • Access (Art. 15): obtain confirmation that processing is taking place and a copy of the data, together with information on purposes, recipients and retention periods.
  • Rectification (Art. 16): correct inaccurate data and complete incomplete data.
  • Erasure (Art. 17): have data deleted in the cases provided for, including where it is no longer needed or consent has been withdrawn.
  • Restriction (Art. 18): require that data only be stored and not otherwise processed, in the cases provided for.
  • Portability (Art. 20): receive, in a structured, commonly used and machine-readable format, the data you provided that we process on the basis of consent or contract, and have it transmitted to another controller.
  • Objection (Art. 21): object at any time, on grounds relating to your particular situation, to processing based on legitimate interest.
  • Withdrawal of consent (Art. 7(3)): withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand.

To exercise these rights write to [email protected]. We will respond without undue delay and in any event within one month of the request, extendable by two months where the request is particularly complex, in which case we will tell you.

We do not carry out automated decision-making producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 GDPR. Automatic scoring and the statistics on your weaker areas are the very service you asked for and do not give rise to decisions of that kind.

10. Complaint to the supervisory authority

If you consider that the processing of your data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority under Article 77 GDPR. In Italy the competent authority is the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, garanteprivacy.it.

You also retain the right to an effective judicial remedy under Article 79 GDPR, regardless of any complaint.

11. Security

We apply appropriate technical and organisational measures under Article 32 GDPR. These include encrypted connections in transit across the whole site, passwords stored as hashes and never in clear text, row-level access rules on the database preventing one user from reading another's data, and administrative access restricted to authorised personnel.

12. Changes to this notice

We may update this notice to reflect changes to the services, to our suppliers or to the law. The date at the top shows when it was last updated. Where changes materially affect the processing we will give you reasonable advance notice and, where required, ask for fresh consent.