1. Data Controller
The data controller is: Silvia Fossati Email: privacy@silviafossati.com Website: silviafossati.com2. Personal Data Collected
We may collect the following personal data:- First and last name
- Email address
- Phone number
- Home or billing address
- Other information provided voluntarily through contact or registration forms
2.1 Passkeys / Biometric Login (WebAuthn)
If you choose to enable biometric login (Passkey) on your device, we process additional technical data required to provide this feature:- WebAuthn credential identifier (credential ID) and related technical authentication metadata (e.g., public key material and counters required by the standard)
- Device identifier generated locally to recognize the current device (see Cookies/LocalStorage section)
- Device label (a short description derived from browser/OS information, e.g., “macOS • Chrome”)
- User agent (browser information) and timestamps (e.g., last used)
3. Purpose of Processing
We process your data for the following purposes:- Responding to inquiries or bookings
- Communicating about events, courses, or professional training
- Sending newsletters and promotional materials, where enabled and with your consent (when required)
- Technical management of the website
- Website security, fraud prevention, and abuse prevention
- Compliance with legal or fiscal obligations
3.1 Purpose of Passkeys / Biometric Login
We process Passkey-related data to:- Allow you to log in without entering a password (passwordless login)
- Improve account security and reduce the risk of credential theft
- Detect and prevent misuse (e.g., abnormal login attempts)
3.2 Adaptive Security & Protected Areas
We use an adaptive security system to protect restricted areas of the website. When accessing protected sections (for example members-only or account-restricted pages), we may automatically apply additional security measures such as:- Session integrity verification
- Device recognition
- Risk-based authentication controls
- Temporary post-login security prompts (such as Passkey suggestions)
4. Legal Basis for Processing
We process your data based on:- Your consent (e.g., newsletter/marketing communications, where required)
- Performance of a contract or pre-contractual measures (e.g., providing requested services or managing your account)
- Compliance with legal obligations
- Legitimate interests in operating, maintaining, and securing the website, user accounts, and protected areas (including adaptive authentication, Passkey/biometric login, and anti-abuse systems)
5. Processing Methods and Retention
Processing is carried out using electronic and, where necessary, manual tools, in a secure and confidential manner. Data is retained for the time necessary to achieve the purposes for which it was collected, and in accordance with applicable law.5.1 Retention for Passkeys / Biometric Login
Passkey-related data (credential IDs and related technical metadata, device label, and device identifiers) is retained:- for as long as your account remains active and the Passkey is enabled, or
- until you remove your Passkey(s) via your user profile or request deletion, or
- as required for security and legal purposes (where applicable)
6. User Rights
You have the right to:- Access your personal data
- Rectify or erase your data
- Restrict or object to processing
- Data portability
- Withdraw consent at any time (where consent is the legal basis)
7. Disclosure to Third Parties
Personal data is not sold. However, data may be shared with third-party service providers for the following purposes:- Newsletter delivery and marketing campaign management (e.g., email marketing tools), where enabled
- Technical or administrative support of the website (hosting, maintenance, troubleshooting)
- Security and abuse-prevention services (e.g., reCAPTCHA Enterprise, where active)
8. Newsletter and Marketing
If you subscribe to our newsletter or consent to receive promotional communications (where required), we use your data to send information about events, professional training and digital marketing and/or digital consulting-related activities. Subscription is optional, and you can withdraw your consent at any time using the unsubscribe link in each email or by writing to: privacy@silviafossati.com.9. Cookie Policy
This website uses technical cookies and, with your consent where required, third-party analytics and marketing cookies. Consent management is handled via the plugin Cookie Notice & Compliance for GDPR/CCPA.9.1 Passkeys / Biometric Login: Cookies & LocalStorage
These identifiers may also be used to determine whether additional security verification is required when accessing protected sections of the website. To support Passkeys and device recognition, we may use:- LocalStorage to store a technical device identifier in your browser (e.g., a key such as
cas_device_id_v1). - A corresponding technical cookie to make the same device identifier available to the server for security checks (see table below).
9.2 reCAPTCHA Enterprise (Google)
We may use Google reCAPTCHA Enterprise to protect forms and authentication flows from spam, abuse, fraud and automated attacks. When reCAPTCHA Enterprise is active, Google may collect and process technical information, which can include IP address, user agent/browser information, interaction signals, submitted form context, token validation data and other data necessary to assess risk. This processing is performed by Google as a third-party provider.9.2.1 Loading the enterprise.js file (security measure)
To operate, reCAPTCHA Enterprise requires loading a script file commonly referred to as enterprise.js.
- We load this script only when necessary to protect specific features of the website or service, such as contact forms, registration, login, password recovery or other authentication-related flows, and solely for security, fraud-prevention and anti-abuse purposes.
- In this website implementation, to reduce the risk of technical blocking, interference or tampering by cookie-consent tools, privacy plugins, security plugins, content filters or browser-level restrictions, the script may be made available through technical delivery methods under our control as a technical resource required for security and operational reliability.
- This controlled or site-hosted delivery method is used to improve the reliability of the security feature and does not change the security purpose of the processing.
- Even where the script file is made available through controlled or site-hosted technical delivery, reCAPTCHA Enterprise may still involve technical communications with Google’s infrastructure for risk analysis, token validation, fraud prevention and abuse prevention.
- We treat and document this implementation as a necessary security measure aimed at protecting the website, its forms and its authentication-related features against spam, abuse, unauthorized activity and automated attacks.
9.3 Main Technical Cookies (Summary Table)
| Cookie / Key | Purpose | Type | Typical Duration | Category |
|---|---|---|---|---|
wordpress_logged_in_* |
Keeps you logged in and recognizes authenticated sessions. | Cookie | Session / days (depending on “Remember me”) | Essential |
wordpress_sec_* |
Security/auth cookie for the administration area. | Cookie | Session / days | Essential |
wordpress_test_cookie |
Checks whether cookies are enabled. | Cookie | Session | Essential |
pll_language |
Stores your language preference (if multilingual features are enabled). | Cookie | Months | Essential / Functional |
wp-settings-* wp-settings-time-* |
Stores user interface preferences (mainly admin/editor settings). | Cookie | Months / 1 year | Essential / Functional |
cas_device_id (and localStorage cas_device_id_v1) |
Technical identifier used to recognize the current device for Passkey-related checks and security. | Cookie + LocalStorage | Up to 12 months (typical) | Essential / Security |
cas_just_logged_in |
Temporary flag to manage post-login prompts (e.g., Passkey suggestion). | Cookie | Short-lived | Essential / Functional |
cas_passkey_prompt_dismissed_v1 |
Remembers whether the user dismissed the Passkey security prompt to avoid repeated display | LocalStorage | Up to 12 months | Essential / Security |
hu-consent (or similar) |
Stores cookie consent choices. | Cookie | Varies (e.g., days/months) | Essential (Consent management) |
_GRECAPTCHA / Google reCAPTCHA Enterprise storage |
Used by Google reCAPTCHA Enterprise, where active, to support anti-bot checks, token validation and risk assessment. | Cookie / local storage / request signals | Variable, managed by Google | Security / Anti-spam |
enterprise.js / reCAPTCHA Enterprise script |
Security script required, where active, to generate and validate reCAPTCHA Enterprise tokens and support risk assessment for protected forms and authentication-related features. On this website it may be made available through controlled or site-hosted technical delivery to reduce blocking by cookie-consent, privacy or security tools. | Script / technical request | Not a persistent cookie by itself; related security requests and signals may be processed according to the reCAPTCHA Enterprise configuration and Google’s applicable documentation | Security / Anti-abuse |
Managing Consent
On your first visit, a banner informs you about cookie usage and allows you to:- Accept all cookies
- Reject non-essential cookies
- Customize your preferences