Privacy Policy

Privacy Policy – My Luxury Experiences

Last updated: July 25, 2026

This privacy policy describes how we process the personal data of users who visit and use the myluxuryexperiences.it website, including its various language versions, hereinafter referred to as the “Site.”

This privacy notice is provided pursuant to Articles 12, 13, and, where applicable, 14 of EU Regulation 2016/679, hereinafter referred to as the “GDPR,” and in accordance with current Italian legislation on the protection of personal data.

1. Data Controller

The Data Controller is:

PhoenITx S.r.l.
Via Pietro Calvi 2
20129 Milan – Italy
Tax ID and VAT Number: 06466860969
Email: amministrazione@phoenitx.it

My Luxury Experiences – MLE is a publishing project created and managed by PhoenITx S.r.l.

Requests regarding the protection of personal data and the exercise of rights under the GDPR may be sent to the email address listed above.

2. Types of Data Processed
2.1 Browsing Data

During normal use of the Website, the computer systems and software procedures used to operate it collect certain data whose transmission is implicit in the use of Internet protocols.

The following may fall into this category:

IP address;
date and time of the request;
requested page;
referring page URL;
browser and device type;
operating system;
technical identifiers;
server response codes;
information regarding the session, security, and operation of the Site.

This data is used to facilitate navigation, ensure the security of the Site, identify anomalies and malfunctions, and obtain aggregate statistical information.

2.2 Data Provided Through the Contact Form

When a user fills out the form on the Contact Us page, the following information may be collected:

Name:
Email address:
Subject of the message:
Message content:
Any additional information provided voluntarily.

Providing this information is optional, but failure to provide the necessary information may prevent the Data Controller from responding to your request.

Users are asked not to include sensitive information in their messages—such as information regarding health, religious or political beliefs, union membership, sexual orientation, or other protected categories—unless it is strictly necessary.

2.3 Communications Sent via Email

The voluntary sending of messages to the addresses published on the Website entails the processing of the sender’s email address, the content of the message, and any other data that may be transmitted.

2.4 Data Contained in Articles and Editorial Content

The website publishes articles, interviews, photographs, quotes, and information about people, professionals, businesses, lodging facilities, restaurants, designers, tourism industry professionals, and other subjects of editorial interest.

Such information may include:

provided directly by the individuals concerned;
received from press offices and communications agencies;
gathered during interviews, visits, events, or editorial activities;
obtained from press releases, institutional websites, and publicly available sources;
produced directly by the editorial staff.

The processing is carried out in accordance with the principles of freedom of expression and information, the relevance of the published information, the rights of the individuals concerned, and the provisions applicable to publishing activities.

2.5 Cookies and Similar Technologies

The Site uses technical cookies and may use, depending on the user’s preferences, statistical cookies, embedded content, and other tracking tools.

Detailed information regarding:

name and purpose of cookies;
providers;
categories;
duration;
legal bases;
how to give, refuse, or withdraw consent;

are available in the Cookie Policy, which can be accessed from the website’s footer and the “Manage Consent” panel.

3. Purposes and Legal Bases
3.1 Operation and Security of the Site

Technical and browsing data are processed for the following purposes:

to enable users to browse the Site;
to ensure the pages function properly;
to protect accounts, systems, and infrastructure;
to prevent fraud, abuse, and unauthorized access;
to diagnose errors and malfunctions;
to exercise or defend the Data Controller’s rights.

The legal basis is the Data Controller’s legitimate interest in ensuring the proper functioning and security of the Website, pursuant to Article 6(1)(f) of the GDPR.

3.2 Responding to Contact Requests

The data provided by the user is processed for the following purposes:

respond to inquiries;
handle publishing proposals;
evaluate collaboration opportunities;
handle professional or business communications;
provide the requested information.

The legal basis is the implementation of measures taken at the request of the data subject, pursuant to Article 6(1)(b) of the GDPR, or the Data Controller’s legitimate interest in managing the communications received.

3.3 Publishing and Information Activities

The data contained in the articles is processed for the following purposes:

create and distribute editorial content;
document places, events, activities, projects, and trends;
publish interviews and in-depth articles;
highlight experiences, facilities, and key players in the sector;
maintain the Site’s editorial archive.

The legal basis is the Data Controller’s legitimate interest in carrying out its publishing activities and exercising freedom of expression and information, in compliance with applicable law.

Requests for correction, updating, anonymization, de-indexing, or deletion regarding editorial content will be evaluated taking into account the rights of the data subject, the timeliness and relevance of the news, the public or documentary interest, and freedom of information.

3.4 Statistics and Measurement of Website Usage

The Site may use statistical tools connected via Google Site Kit or other similar services.

When such tools are not strictly necessary or involve the use of identifiers and tracking technologies, they are enabled only after the user has given consent.

The legal basis is consent, pursuant to Article 6(1)(a) of the GDPR.

Consent may be withdrawn at any time using the “Manage Consent” option, without affecting the lawfulness of any processing carried out prior to the withdrawal.

3.5 Embedded Content and Social Media

The Site may display content from external platforms, specifically posts and profile content from the My Luxury Experiences Instagram account.

When external content is activated, the user’s browser may connect to the provider’s servers and transmit data such as:

IP address;
page visited;
device and browser information;
identifiers or cookies already present on the device;
any information related to the user’s social media account.

Services that are not strictly necessary are enabled based on the preferences the user has selected via the cookie banner.

3.6 Google Fonts

This website uses fonts provided by Google Fonts.

Loading fonts may result in a connection to the provider’s servers and the transmission of technical information, including the IP address. Activation of the service is managed according to the preferences expressed by the user through the consent management system.

If the fonts are subsequently hosted directly on the Website’s server, this external link will no longer be necessary.

3.7 Compliance with Legal Obligations and Protection of Rights

Data may be processed for the following purposes:

to comply with legal obligations;
to respond to requests from authorities;
to prevent and investigate illegal activities;
to exercise or defend a right in court or out of court.

The legal basis is compliance with a legal obligation, pursuant to Article 6(1)(c) of the GDPR, or the Data Controller’s legitimate interest in protecting its rights.

4. Nature of the contribution

Providing data via the contact form or by email is optional.

However, failure to provide the required information may prevent the Data Controller from responding to the request or acting on the communication.

Consent to statistical cookies, embedded content, and non-essential technologies is optional. Refusal does not prevent you from browsing the Site normally, but may make certain features or content provided by third parties unavailable.

5. Methods of Processing

The data is processed using computer and telecommunications systems in accordance with the following principles:

lawfulness, fairness, and transparency;
purpose limitation;
data minimization;
accuracy;
storage limitation;
integrity and confidentiality.

The Data Controller implements technical and organizational measures appropriate to the risk, designed to protect the data from loss, destruction, alteration, unauthorized disclosure, or unlawful access.

6. Retention Periods

Data is stored according to the following criteria:

Technical and security data: for the time necessary for operation, security, and the management of any anomalies or misuse, and, as a general rule, for no longer than 12 months, unless required for the purposes of investigation or the protection of a right.

Contact requests: for the time necessary to respond to and handle the communication, and, as a general rule, no later than 12 months after the conclusion of the contact.

Communications related to professional relationships or collaborations: for the duration of the relationship and thereafter for the period required by civil, tax, and accounting laws.

Preferences and evidence of consent: for the period specified in the Cookie Policy or as long as necessary to demonstrate the user’s choices.

Editorial content: for as long as it remains relevant, current, or of editorial, historical, or documentary value.

Data necessary for the protection of a right: until the statute of limitations expires or until any dispute is resolved.

7. Recipients of the Data

The data may be processed or disclosed, to the extent necessary, to:

staff and collaborators authorized by PhoenITx S.r.l.;
managers, authors, and editorial contributors;
hosting and IT infrastructure providers;
email service providers;
entities responsible for the maintenance, security, and technical support of the Website;
providers of software, plugins, and web services;
administrative, tax, and legal consultants;
providers of statistical services, social media, and embedded content;
public authorities or competent bodies, when required by law.

Entities that process personal data on behalf of the Data Controller are appointed, where necessary, as data processors pursuant to Article 28 of the GDPR.

8. Major Suppliers and External Services

Depending on the features that are actually enabled and the preferences expressed by the user, the Site may interact with services provided by:

Aruba S.p.A., for hosting and technical infrastructure;
Google, for Google Fonts, Google Site Kit, and any related analytics services;
Meta Platforms, for Instagram and embedded social media content;
providers of the WordPress plugins used for forms, security, consent management, and technical functionality.

A detailed list of the services that use cookies or similar technologies is provided in the Cookie Policy.

9. Transfers Outside the European Economic Area

Some technology or social media providers may process personal data in countries outside the European Economic Area.

When necessary, the transfer is carried out on the basis of one of the legal bases set forth in Articles 44 and following of the GDPR, such as:

European Commission adequacy decisions;
EU-US Data Privacy Framework, for participating and certified recipients;
Standard Contractual Clauses;
additional safeguards provided for by applicable law.

Users may request more information about data transfers by writing to the Data Controller.

10. Links to External Sites

Articles may contain links to websites for hotels, restaurants, tourist facilities, professionals, companies, social networks, and other external platforms.

PhoenITx S.r.l. does not control how these third parties process users’ personal data. Before using external services or providing personal data, users are encouraged to review the relevant privacy policies.

11. Minors

The Website is not specifically intended for minors and does not offer services designed to intentionally collect their personal data.

If the Data Controller becomes aware of the unnecessary collection of data relating to a minor, it will take appropriate measures to limit or cease the processing of such data, unless the publication is justified within the scope of its editorial activities and in accordance with applicable law.

12. Automated Decision-Making Processes

The Data Controller does not engage in automated decision-making or profiling activities that produce legal or similarly significant effects on users.

Any statistical or technical classification of visits does not result in individual decisions with such effects.

13. Rights of the Data Subject

In the cases provided for in Articles 15–22 of the GDPR, the data subject may request:

confirmation of the existence of personal data concerning the individual;
access to the data and information regarding its processing;
correction or updating of inaccurate data;
erasure of data;
restriction of processing;
objection to processing based on legitimate interest;
data portability, where applicable;
withdrawal of previously given consent;
information on safeguards applied to international transfers.

Requests may be sent to:

amministrazione@phoenitx.it

The Data Controller will respond within the timeframes set forth by law. The rights provided for under the GDPR may be subject to limitations applicable to publishing activities, freedom of expression and information, and the protection of the rights of third parties.

14. Complaint to the Data Protection Authority

Any data subject who believes that the processing of their personal data is in violation of the law may file a complaint with:

Data Protection Officer

This is without prejudice to the right to seek recourse before the competent judicial authority.

15. Managing Cookie Preferences

Users can change or revoke their preferences at any time by using the link or the “Manage Consent” button available on the Site.

The withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.

For detailed information on cookies and other tracking tools, please refer to the Cookie Policy. The Data Protection Authority requires that non-technical tools be managed in accordance with the user’s choices and that it be possible to refuse or withdraw consent through accessible means.

16. Changes to This Privacy Policy

The Data Controller may periodically update this Privacy Policy to bring it into compliance with:

regulatory changes;
changes to the services used;
organizational changes;
new processing activities or features on the Site.

The updated version will be posted on this page, along with the date of the last update.