Privacy Notice
Last updated: 02/08/2026
This notice explains how Sarfatti Strategy processes the personal data of users of sarfattistrategy.com and of the services offered through the site. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR").
For each category of data it states why we process it, the legal basis that permits us to, who may receive it and how long we keep it. Your rights and how to exercise them are at point 9.
This is a translation provided for convenience. The service is operated from Italy and governed by Italian and EU law: in case of any discrepancy, the Italian version of this notice prevails.
1. Data controller
The controller of the personal data collected through the site is the operator of Sarfatti Strategy. You can contact us at [email protected].
For anything concerning personal data, including the rights described at point 9, write to [email protected].
No Data Protection Officer has been appointed, as the conditions in Article 37 GDPR do not apply. Please use the contact details above.
2. What data we process
We process only the categories listed below. We do not process special categories of data under Article 9 GDPR and we do not ask you to provide them.
| Category | Specific data | Source |
|---|---|---|
| Account data | Email address, password (stored only as a hash), first and last name, profile picture if uploaded, chosen track (Bachelor or Master), interface language, account creation and last update dates. | Provided by you at sign-up or later from your profile. |
| Booking data | For consultations: name, email address, phone number if given, chosen date and time, plan of interest, any notes you add. For tutoring sessions: user, date and time, duration, amount, assigned tutor, any notes. | Provided by you when booking. |
| Subscription and payment data | Plan type, related track, subscription status, start and expiry dates, payment outcomes, remaining tutoring credits. | Generated by your use of the service and received from the payment provider. |
| Simulation activity data | Answers given, correct and incorrect answers, scores, time spent per question and per category, status and date of each attempt, language used, question order. | Generated automatically while you use the simulations and the question bank. |
| Affiliate programme data | Personal affiliate code, click and conversion counts, commissions earned. For each click on an affiliate link: visitor IP address, browser user agent, landing page, date and time. | Generated by use of affiliate links. Clicks are recorded only after consent to non-essential cookies (point 6). |
| Technical and browsing data | IP address, browser and operating system, date and time of requests, pages requested, data held in server and network security logs. | Collected automatically by the infrastructure serving the site. |
| Communication data | The content of emails and support requests you send us, and their metadata. | Provided by you. |
We never see your payment card details. Card number, expiry and security code are collected and processed directly by the payment provider on its own pages: we receive only the outcome of the transaction and the data needed for invoicing and support.
3. Why we process it and on what legal basis
Article 6 GDPR permits processing only where one of the legal bases it lists applies. For each purpose, the basis we rely on is stated below.
| Purpose | Legal basis |
|---|---|
| Creating and running your account, authenticating you, keeping your session active. | Performance of the contract to which you are party: Art. 6(1)(b) GDPR. |
| Delivering the services purchased: simulations, question bank, marking, performance statistics, tutoring sessions, consultations. | Performance of the contract: Art. 6(1)(b) GDPR. |
| Handling bookings, confirmations, reminders, cancellations and rescheduling. | Performance of the contract: Art. 6(1)(b) GDPR. |
| Managing subscriptions, payments, renewals, refunds and related support. | Performance of the contract: Art. 6(1)(b) GDPR. |
| Issuing and retaining tax and accounting records. | Compliance with a legal obligation: Art. 6(1)(c) GDPR. |
| Recording clicks on affiliate links and attributing a purchase to the affiliate who generated it. | Consent: Art. 6(1)(a) GDPR and Art. 122 of Legislative Decree 196/2003. You may withdraw it at any time (point 6). |
| Keeping the site secure, preventing abuse, unauthorised access and fraud, maintaining technical logs. | Our legitimate interest in protecting the service and its users: Art. 6(1)(f) GDPR. |
| Establishing or defending a legal claim, in or out of court. | Our legitimate interest in protecting our rights: Art. 6(1)(f) GDPR. |
| Measuring site traffic in aggregate, anonymous form. | Our legitimate interest in understanding how the site performs. Measurement uses no cookies and no individual identifiers (point 6). |
Providing account, booking and payment data is necessary to enter into and perform the contract: without it we cannot activate the service. Providing data that depends on consent is entirely optional, and refusing does not affect your access to the services in any way.
4. Who we share data with
We do not sell your data and we do not pass it to third parties for their own purposes. We do use suppliers who process data on our behalf, appointed as processors under Article 28 GDPR, and parties acting as independent controllers for obligations imposed on them by law.
| Supplier | Activity | Data involved |
|---|---|---|
| Supabase | Database, authentication system and server-side application functions. | All account, booking, subscription, simulation activity and affiliate data. The database is located in the eu-west-3 (Unione europea, Parigi) region. |
| Cloudflare | Site hosting, content delivery network, DNS, attack protection and aggregate traffic measurement. | Technical and browsing data, IP address. |
| Stripe | Payments, subscriptions and the billing portal. | Identification and contact data needed for the transaction, card data collected directly by Stripe, payment history. |
| Resend | Sending service emails: confirmations, reminders, account messages. | Email address, name, content of the message. |
| Brevo | Sending email communications and managing the related lists. | Email address, name. |
| Namecheap | Email service on the domain. | Content and metadata of the emails you exchange with us. |
| Discord | Internal operational notifications to our team about new sign-ups and bookings. | Email address and essential booking details. |
Data may also be shared with professionals advising us on accounting, tax and legal matters, and with public authorities where disclosure is required by law or necessary to establish or defend a legal claim.
Tutors assigned to individual sessions are given access only to the data needed to deliver the session assigned to them.
5. Transfers outside the European Economic Area
The database holding your account, booking and simulation data is located in the European Union, in the eu-west-3 (Unione europea, Parigi) region. Storage alone therefore involves no transfer to a third country for that data.
Some of the suppliers listed at point 4 are, however, companies established in the United States and may access or process data outside the European Economic Area. The GDPR permits such transfers only where adequate safeguards are in place.
On 10 July 2023 the European Commission adopted an adequacy decision on the EU-U.S. Data Privacy Framework under Article 45 GDPR: transfers to United States organisations certified under that framework need no further authorisation. The General Court of the European Union confirmed the decision's validity on 3 September 2025. Stripe and Cloudflare appear on that list as active participants.
For suppliers not covered by the adequacy decision, transfers rely on the standard contractual clauses adopted by the European Commission under Article 46(2)(c) GDPR, as provided for in the data processing agreements in place with each of them.
You can request a copy of the safeguards applied by writing to [email protected].
7. How long we keep data
We keep data only as long as necessary for the purposes for which it was collected, and afterwards for any period the law requires us to retain it or during which it may be needed to establish or defend a legal claim.
| Data | Retention period |
|---|---|
| Account and profile data | For the duration of the relationship. If the account is deleted, data is erased except what must be retained to comply with legal obligations. |
| Simulation activity data | For the duration of the relationship, as it forms the record of your progress. Erased when the account is deleted. |
| Consultation and tutoring bookings | For as long as needed to deliver the service and deal with its consequences, and in any event within the retention periods for contractual records. |
| Tax and accounting records and payment data | For the period required by the applicable tax and accounting rules on retention of records. |
| Affiliate programme data and recorded clicks | For as long as needed to calculate and settle commissions and handle any disputes about them. |
| ref_code cookie | 30 days from being set, or until consent is withdrawn if sooner. |
| Technical and security logs | For as long as strictly necessary for security purposes, according to the settings of the infrastructure suppliers listed at point 4. |
8. Minors
Our services are also aimed at students preparing for university admission, who may be under 18.
Article 8 GDPR and Article 2-quinquies of Legislative Decree 196/2003 provide that, in Italy, a minor who has reached the age of fourteen may validly consent to the processing of their personal data in relation to information society services offered directly to them. Below the age of fourteen, processing based on consent is lawful only where consent is given by the holder of parental responsibility.
The capacity to consent to data processing is separate from the capacity to enter into a contract, which is dealt with in the Terms and Conditions.
If you believe a minor has provided personal data without the required consent, write to [email protected]: we will check and delete it.
9. Your rights
The GDPR gives you the following rights, which you can exercise free of charge.
- Access (Art. 15): obtain confirmation that processing is taking place and a copy of the data, together with information on purposes, recipients and retention periods.
- Rectification (Art. 16): correct inaccurate data and complete incomplete data.
- Erasure (Art. 17): have data deleted in the cases provided for, including where it is no longer needed or consent has been withdrawn.
- Restriction (Art. 18): require that data only be stored and not otherwise processed, in the cases provided for.
- Portability (Art. 20): receive, in a structured, commonly used and machine-readable format, the data you provided that we process on the basis of consent or contract, and have it transmitted to another controller.
- Objection (Art. 21): object at any time, on grounds relating to your particular situation, to processing based on legitimate interest.
- Withdrawal of consent (Art. 7(3)): withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand.
To exercise these rights write to [email protected]. We will respond without undue delay and in any event within one month of the request, extendable by two months where the request is particularly complex, in which case we will tell you.
We do not carry out automated decision-making producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 GDPR. Automatic scoring and the statistics on your weaker areas are the very service you asked for and do not give rise to decisions of that kind.
10. Complaint to the supervisory authority
If you consider that the processing of your data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority under Article 77 GDPR. In Italy the competent authority is the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, garanteprivacy.it.
You also retain the right to an effective judicial remedy under Article 79 GDPR, regardless of any complaint.
11. Security
We apply appropriate technical and organisational measures under Article 32 GDPR. These include encrypted connections in transit across the whole site, passwords stored as hashes and never in clear text, row-level access rules on the database preventing one user from reading another's data, and administrative access restricted to authorised personnel.
12. Changes to this notice
We may update this notice to reflect changes to the services, to our suppliers or to the law. The date at the top shows when it was last updated. Where changes materially affect the processing we will give you reasonable advance notice and, where required, ask for fresh consent.