Data Protection
Privacy Policy
Information on the processing of personal data in accordance with Regulation (EU) 2016/679 and applicable Italian legislation. Last updated: 19 August 2026.
1. Data controller
Parish of Sant’Agabio in Novara
Corso Milano 27, 28100 Novara (NO), Italy
Email: parrocchiasantagabio@gmail.com
Telephone: 0321 627032
For matters relating to the protection of personal data, you may use the same contact details.
2. Scope and principles
This privacy notice applies to the Parish’s website, public forms, the Members’ Area, publishing functions, email notifications and related technical tools. Data processing is carried out in accordance with the principles of lawfulness, fairness, transparency, data minimisation, purpose limitation and security.
Third-party websites and services accessible via external links are governed by their respective privacy policies.
3. Data processed
Technical and browsing data
The server and application systems may process IP addresses, date and time, requested pages or functions, browser and device information, security logs, technical errors and data necessary to prevent misuse and ensure service continuity.
Data provided by the user
Depending on the service used, the following data may be processed: first name and surname, telephone number, email address, content of communications, notes, data relating to the event or request, and any other information provided voluntarily.
Special categories of data
Certain pastoral services may involve the processing of data capable of revealing religious beliefs, such as information on the sacraments, pastoral requests or the content of a Mass intention. Such information is processed only to the extent necessary, with restricted access and the utmost confidentiality.
Data relating to users of the Restricted Area
For authorised users, the following data may be processed: identification details, role, email address, logins, actions carried out, IP address, technical browser information, and data relating to diagnostics and security.
4. Purposes and legal bases
- Management of enquiries, registrations and communications: carrying out the activities requested by the data subject and organising pastoral or administrative services.
- Religious, pastoral and sacramental activities: for special categories of data, processing within the scope of the legitimate activities of a religious organisation with adequate safeguards, in the cases provided for in Article 9(2)(d) of the GDPR; where this condition does not apply, another condition provided for by law is used, including explicit consent where necessary.
- Legal and administrative obligations: compliance with obligations to which the Parish is subject.
- Website security, prevention of misuse, protection of systems and defence of rights: the Parish’s legitimate interest and, where applicable, the establishment, exercise or defence of a legal claim.
- Operational notifications and acknowledgements of receipt: management of the request submitted and internal organisation of the service.
- Non-essential services or further processing: consent, where required by law.
5. Online forms and requests
Catechism
The form may collect details of the parent or guardian, contact details, the child’s details, date of birth, year group, information on the sacraments and notes. The online request is preliminary and is handled by the school office.
Mass intentions
The form collects the applicant’s contact details, stated preferences, the text of the intention and any notes. Submission registers the request in the system.
Event registrations
When an event is open for registration, the form can collect the participant’s name, contact details, number of participants and any notes. Once registration closes, the form is deactivated from the public page, whilst requests already received remain manageable in the Members’ Area in accordance with the applicable retention criteria.
Enquiries and other requests
The data is used to process, manage and respond to the enquiry.
If the user provides a valid email address, the system may send a brief automatic confirmation of receipt. For Mass intentions, the confirmation simply states that the request has been recorded.
6. Children and catechism
Services aimed at children and young people are managed with the involvement of a parent or guardian. The catechism form requires that the minor’s details be provided by a responsible adult and asks that only relevant information be supplied.
Where online processing directly involving a child is based on consent, the rules of the GDPR and Italian legislation on the age of digital consent apply; the website does not use this mechanism to replace parental involvement in catechism enrolments.
7. Photographs and videos
The website may document celebrations, pastoral activities, youth clubs, catechism classes, Caritas, groups and community initiatives. Publication is assessed in relation to the context, the purpose, the dignity of the individuals concerned and any authorisations that may be required.
Particular care is taken with regard to minors. Where necessary, authorisation is obtained from those exercising parental responsibility. Requests for notification or removal may be sent to the Data Controller’s contact details.
8. Restricted Area, CMS and Logs
The Restricted Area is intended exclusively for authorised users. The system logs administrative and publishing operations for security, traceability and technical management purposes. Successful logins and failed attempts, user modifications, editorial activities, backups and diagnostic results may be logged.
Login credentials are personal and must not be shared. Permissions are differentiated according to role.
9. Email notifications
The site features a notification centre which, depending on the configured settings, can alert the Secretariat, the Administrator and the Parish Priest in the event of new requests, logins to the Restricted Area, failed login attempts, diagnostic issues, changes to user accounts, backup errors or new publications.
Notifications can be sent via the Google Workspace/Gmail API if connected, or via the server’s email function. The notification log stores essential data on the outcome of the delivery, the recipients and the type of event. Deleting the site’s log does not remove copies of emails already delivered to recipients’ inboxes, which are subject to the retention policies of the relevant email service.
10. Offensive or potentially unlawful content
Requests containing profanity, vulgar language, insults or other offensive content may not be considered. In the event of threats, harassment or content that may constitute unlawful behaviour, the Parish may retain the information strictly necessary for security purposes, the protection of its rights or the fulfilment of legal obligations and, where appropriate, report such matters to the relevant authorities.
12. Recipients and service providers
Data may be processed by priests, the secretariat, administrators, staff and other authorised persons, exclusively within the limits of their respective roles. It may also be processed by providers of hosting, email, maintenance or other technical services operating in accordance with the role set out by law.
Data may be disclosed to public bodies or authorities where required by law or necessary for the protection of rights and security. An up-to-date list of external data processors may be requested from the Data Controller.
13. International transfers
The use of international service providers or technical resources, including any Google or CDN services, may involve the processing of technical data or content outside the European Economic Area. In such cases, processing takes place on the basis of the mechanisms and safeguards provided for by the GDPR and the applicable terms and conditions of the service provider.
14. Retention
The Parish applies different retention criteria depending on the purpose. The retention periods are subject to review and may be amended where necessary to comply with legal obligations, to safeguard rights, for security reasons, or to meet documented pastoral needs.
| Data | Standard retention period | Criterion |
|---|---|---|
| Catechism enquiries | 12 months | From the closure of the online request. Any data transferred to pastoral or sacramental records is subject to its own rules. |
| Mass intentions | 12 months | From the date the request is closed. |
| Event registrations | 12 months | From the date the request was closed. |
| Contact enquiries | 12 months | From the date the case is closed. |
| Email notification log | 6 months | From the date the delivery status is recorded. |
| Log of successful logins to the Members’ Area | 90 days | From the time the access is recorded, unless there are incidents or documented security requirements. |
| Register of administrative changes | 24 months | From the date of the recorded operation, for traceability and security purposes. |
| Google Workspace logs | 6 months | From the date the technical operation was recorded. |
| Full website backups | 90 days | Automatic rotation, except for copies that are exceptionally required for recovery or protection. |
Completed requests may be temporarily protected from automatic deletion where there is a documented need, for example due to threats, harassment, disputes, incidents or the protection of rights. The need for such protection must be reviewed periodically.
Automatic deletion applies to the website’s operational data and does not automatically apply to sacramental registers, canonical archives or other pastoral archives, which have their own purposes and retention rules.
15. Security and Backups
The Parish adopts proportionate technical and organisational measures, including access control, personal credentials, role-based permissions, session protection, logging of operations, backups and diagnostics. However, no IT system can eliminate all risks.
16. Rights of the data subject
In the cases provided for by the GDPR, the data subject may request access, rectification, erasure, restriction of processing, data portability and objection, as well as withdraw consent where processing is based on consent. The exercise of these rights may be subject to the conditions and exceptions provided for by law.
Requests may be sent to the Data Controller’s contact details. Before providing data or processing a request, it may be necessary to verify the identity of the applicant.
17. Complaints
The data subject has the right to lodge a complaint with the Data Protection Authority and to bring the matter before the competent judicial authority.
18. External services and links
The website contains links to external services and websites. In particular, links to Google Maps only open the external service when the user selects them. Once you leave the Parish’s website, the terms and conditions and privacy policies of the external provider apply.
19. Updates and references
This policy is updated whenever the website’s functions, providers or the regulatory framework change. The published version indicates the date of the last update.