Privacy Policy

Last updated: 16 September 2026

This page explains how Club Mary Poppins – Scuola Bruno Munari processes the personal data of visitors to clubmarypoppins.com and of those who use the services offered through the site, under Regulation (EU) 2016/679 (“GDPR”) and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.

1. Who processes your data

Data controller
Club Mary Poppins S.r.l. – Scuola Bruno Munari
Via San Donato, 1/a – 43122 Parma (PR), Italy
Phone: +39 0521 233643
Email: info@clubmarypoppins.com
Certified email (PEC): clubmarypoppins.srl@legalmail.it
VAT number and tax code: 02620060349

For any request concerning your data you can write to direzione@clubmarypoppins.com.

2. What data we collect, why, and for how long

2.1 Browsing the site

The systems that run this website automatically collect some data whose transmission is inherent in the use of Internet protocols: IP address, date and time of the request, page requested, outcome of the request, browser type and operating system.

  • Purpose: operating the site, keeping it secure and detecting misuse or malfunctions.
  • Legal basis: the controller’s legitimate interest in the security and correct operation of the site (Art. 6.1.f GDPR).
  • Retention: server logs are kept for a maximum of 30 days and then overwritten automatically.

2.2 Contact form

When you fill in the form on the Contact page we collect your name and surname, email address, telephone number, subject and message.

  • Purpose: replying to your enquiry.
  • Legal basis: responding to your request, therefore pre-contractual measures or legitimate interest in replying (Art. 6.1.b/f GDPR).
  • Retention: the message reaches us by email and is kept for as long as needed to handle the enquiry and, if a relationship follows, for its duration. Otherwise no longer than 24 months.
  • Nature of provision: optional, but without these details we cannot reply to you.

2.3 Private area for families and staff

To give access to the private area we process name, surname, email address, telephone number and password (stored in encrypted form and not readable by us). We also record which documents have been assigned to each user, the date of the last login, whether shared documents have been opened, and any comments the user posts in the dedicated sections.

  • Purpose: enabling access to the private area, making documents and communications available to enrolled families, teachers and school staff, managing the enrolment or employment relationship.
  • Legal basis: performance of the existing relationship and pre-contractual measures (Art. 6.1.b GDPR).
  • Retention: for the duration of the relationship and thereafter for the period required by law (generally 10 years for administrative and accounting records).

2.4 Newsletter

If you subscribe to the newsletter we process your name, surname, email address and telephone number. For each message sent we also record whether the newsletter was opened and which links were clicked.

  • Purpose: sending you news and updates about the school’s activities and measuring, in aggregate form, how effective those communications are.
  • Legal basis: your consent (Art. 6.1.a GDPR), which you may withdraw at any time.
  • Retention: until consent is withdrawn or you unsubscribe.
  • How to unsubscribe: use the link at the bottom of every message or write to direzione@clubmarypoppins.com.

2.5 Cookies

The site uses technical cookies and, with separate optional consent, Google Analytics for statistics and Google Maps for the school map. Purposes, cookies, lifetimes and withdrawal options are described in the Cookie Policy.

3. Children’s data

This website is not intended for direct use by children and does not knowingly collect children’s data through its public forms. Matters concerning the children enrolled at the school are handled directly with parents or guardians, outside this website, under a dedicated privacy notice provided at enrolment.

Any documents published in the private area that relate to children are accessible only to users who have been expressly authorised.

4. Who we share data with

Data may be processed by persons authorised by the controller (administrative and teaching staff, within the limits of their duties) and disclosed to external providers acting as data processors under Art. 28 GDPR:

  • the hosting and infrastructure provider for the website;
  • the email service provider used to send communications;
  • the provider of technical development and maintenance services for the website.

Data is neither disseminated nor sold to third parties for their own commercial purposes.

5. Transfers outside the European Union

The servers hosting the website and its database are located within the European Union.

Essential site resources are hosted on our servers. Google Maps and Google Analytics are loaded only after consent to the relevant category and may involve processing data outside the European Economic Area. The services’ terms and safeguards are described in Google’s privacy policy; details and consent controls are in our Cookie Policy.

6. Your rights

You may exercise the rights set out in Articles 15–22 GDPR at any time:

  • access: find out whether we process your data and obtain a copy;
  • rectification: correct inaccurate data or complete it;
  • erasure: request deletion of your data, where applicable;
  • restriction: request that processing be suspended;
  • portability: receive your data in a machine-readable format;
  • objection: object to processing based on legitimate interest;
  • withdrawal of consent: at any time, without affecting the lawfulness of processing already carried out.

To exercise them, write to direzione@clubmarypoppins.com. If you have a PEC account of your own you can write to ours, clubmarypoppins.srl@legalmail.it: sent from one PEC account to another, your request carries legally recognised proof of the date we received it. You do not have to use PEC, and there is no form to fill in: your request is valid however it reaches us. We reply without undue delay and in any case within one month of receipt; where the request is particularly complex that period may be extended by two further months, in which case we tell you within the first month and explain why.

If you believe the processing infringes data protection law, you have the right to lodge a complaint with the Italian supervisory authority, Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome – www.garanteprivacy.it), or to bring proceedings before the courts.

7. How we protect your data

The site is reachable only over an encrypted connection (HTTPS). Passwords are stored using non-reversible hashing algorithms. Access to data is restricted to authorised persons, and documents in the private area are delivered only after the requesting user’s permissions have been verified.

8. Changes to this notice

This notice may be updated to reflect changes in the law or in the services offered. The version in force is always the one published on this page, together with the date it was last updated.