Privacy Policy

(GDPR & Italian Privacy Law Compliant)

Last updated: November 6, 2025 

1. Introduction

This Privacy Policy describes how GlobeTalk.online, owned and operated by Federica Centi, collects, uses, and protects personal data in accordance with the General Data Protection Regulation (EU Regulation 2016/679)(“GDPR”) and the Italian Privacy Code (D.lgs. 196/2003, as amended).

By using this website, enrolling in a course, submitting a form, or interacting with our services, you agree to the practices described in this Privacy Policy.

2. Data Controller

The Data Controller is:

GlobeTalk.online – owned by Federica Centi

Address: Pian di Grassina 146, 50012 Bagnolo a Ripoli (FI), Italy

Email: info@globetalk.online

Telephone: +39 378-0025-888

3. Personal Data We Collect

We may collect the following categories of personal data:

a) Data provided voluntarily by the use

  • Name and surname

  • Email address

  • Billing and payment information (via secure third-party gateways)

  • Course enrollment details

  • Messages and enquiries submitted through contact forms

  • Information collected during live classes or tutoring sessions

b) Data collected automatically

Through cookies and similar technologies (only after user consent, where required):

  • IP address

  • Browser type and version

  • Device information

  • Pages visited

  • Time and date of access

c) Data collected for payment purposes

Handled through external PCI-compliant systems such as:

  • Stripe

  • PayPal

(We do not store full credit card data on our servers.)

4. Legal Basis for Processing

We process personal data on the following legal bases:

  • Contract performance (Art. 6.1.b GDPR)

    To manage course registrations, online classes, payments, and account-related actions.

  • Legal obligation (Art. 6.1.c GDPR)

    For accounting, taxation, and administrative purposes required by Italian law.

  • Consent (Art. 6.1.a GDPR)

    For optional activities such as newsletter subscription, cookies requiring consent, or marketing communications.

  • Legitimate interest (Art. 6.1.f GDPR)

    For website security, fraud prevention, and service improvement.

5. Purpose of Processing

Your data is processed exclusively for:

  • Managing course enrolments and online classes

  • Providing customer support

  • Processing payments and issuing invoices

  • Creating and managing user accounts (if applicable)

  • Sending service communications (class reminders, access links, etc.)

  • Improving website functionality and service quality

  • Fulfilling legal obligations

6. Cookies

GlobeTalk.online uses essential, analytical, and functional cookies.

Non-essential cookies are only activated after explicit user consent through our cookie banner, in compliance with GDPR.

For detailed information, please refer to our Cookie Policy.

7. Data Sharing and Third Parties

We may share your data only with trusted third parties essential for service delivery, including:

  • Hosting provider

  • Tutor LMS Pro (course management)

  • Payment processors (Stripe, PayPal)

  • Email service providers (transactional emails)

  • Video conferencing tools (Zoom)

All processors operate under GDPR-compliant agreements.

We do not sell or transfer personal data for commercial purposes.

For detailed information, please refer to our Cookie Policy.

8. Storage Period

We retain your data for:

  • Billing and tax data: 10 years (as required by Italian law)

  • Course information and account data: as long as your account is active

  • Marketing data: until consent is withdrawn

  • Contact form messages: up to 24 months

9. Data Subject Rights (Articles 15–22 GDPR)

You have the right to:

  • Access your personal data

  • Request correction or deletion

  • Withdraw consent at any time

  • Request restriction of processing

  • Object to certain types of processing

  • Request data portability

  • Lodge a complaint with the Italian Data Protection Authority (Garante Privacy)

To exercise your rights, contact: info@globetalk.online

10. Data Security

We implement security measures to protect your data, including:

  • HTTPS encryption

  • Secure servers located in the HK

  • Restricted access

  • Third-party GDPR-compliant processors

11. International Transfers

If international data transfers occur (e.g., through Zoom or cloud services), they are handled according to:

  • Standard Contractual Clauses (SCC)

  • Adequacy decisions

  • Equivalent lawful safeguards

12. Changes to This Privacy Policy

We may update this Privacy Policy to comply with legal requirements or service changes.

Updates will be published on this page with a revised “Last updated” date.