Legal
Privacy policy
The short version
- I am Giovanni Perri, a sole trader in Italy. I am the controller of the personal data described here, and you can reach me by email.
- The contact form collects your name, email, company, website, which package you are interested in and your message. I use it to reply to you and to keep a record of the enquiry.
- The newsletter is double opt-in: nothing is sent until you confirm, and every email has an unsubscribe link.
- Analytics runs only if you accept analytics cookies. No advertising, no cross-site tracking, no profiling, and nothing is sold or shared for marketing.
- A short list of named providers processes data for me. Two of them are in the United States, under the EU–US Data Privacy Framework.
- You can ask me for a copy of your data, or to correct or delete it, at any time. I reply within one month.
1. Who I am
I am Perri Giovanni, trading as Giovanni Perri, a sole trader registered in Italy (ditta individuale). My Partita IVA is IT 03133680342 and I am based in Parma, Italy. I am the controller of the personal data described in this policy. Where I say “I” or “me” below, that is who I mean.
For anything to do with your data, email giovanniperri86@gmail.com. this address moves to a giovanniperri.com mailbox before launch
This policy replaces any earlier policy published under a previous trading name.
I am established in Italy, so the EU General Data Protection Regulation and the Italian Privacy Code (Legislative Decree 196/2003) apply to me. Most of the people who read this site and get in touch are in the United Kingdom, so the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations apply as well. I do not run two standards. Everything below applies to everyone, wherever you are.
I am a sole trader, so I do not have a data protection officer, and I am not required to appoint one.
2. What this policy covers
This policy covers the website at giovanniperri.com, including the blog, the contact form, the newsletter sign-up and the emails I send in reply.
It does not cover two things. The first is the work itself: if you become a client, the personal data inside your own systems is governed by our written engagement agreement rather than by this page, and section 3.7 explains the difference. The second is other people’s websites. When you follow a link from here to Calendly, LinkedIn or anywhere else, you are on their site under their policy.
3. What I collect, why, and on what basis
The law requires a lawful basis for each thing I do with your data. The ones I rely on are: taking steps at your request before entering a contract, and performing a contract once there is one (Article 6(1)(b)); my legitimate interests, where they are not overridden by your rights (Article 6(1)(f)); your consent (Article 6(1)(a)); and complying with a legal obligation (Article 6(1)(c)). Each activity below says which one applies.
I do not collect special category data, I do not buy data about you from anyone, and I do not build profiles or make automated decisions about you.
3.1 When you send the contact form
The form asks for your name, your email address, your company, your website, which package you are interested in, and your message. Company and website are there because they are what make an enquiry answerable. Your browser also completes a Cloudflare Turnstile check, and my server sends the resulting token and your IP address to Cloudflare to verify it.
What happens next: the submission goes from my server to an automation workflow at n8n, which stores it in a database at Supabase, emails it to me, and sends you an automatic acknowledgement so you know it arrived. I then reply myself.
Why: to answer you, and to take the steps you have asked for before we might work together. Basis: Article 6(1)(b), steps taken at your request before a contract. For keeping the enquiry on record afterwards, so I know who has approached me and what was discussed, my legitimate interest under Article 6(1)(f) in running and evidencing my own business, balanced against your right to object and to have it erased.
3.2 When you book a call
Every “Book a discovery call” button is an ordinary link that opens my Calendly page in a new tab. There is no Calendly embed on this site and no Calendly script runs here, so nothing reaches Calendly until you click.
If you have already typed your name and email into the contact form, that link carries them, along with campaign parameters, so the booking form arrives filled in. Once you are on Calendly, Calendly decides what it collects there and is its own controller for it, under its own privacy notice. What comes back to me is the booking: your name, your email address, the time you chose, and anything you wrote in their form. I hold that under this policy.
Why: to hold the call you booked. Basis: Article 6(1)(b), steps taken at your request.
3.3 When you subscribe to the newsletter
The sign-up asks for your email address and nothing else. The subscription is double opt-in: your address goes to Mailchimp, Mailchimp emails you a confirmation link, and you are only subscribed once you click it. If you never click, nothing is sent and the pending record expires. Mailchimp also records the date, time and IP address of the sign-up and the confirmation, which is how I can evidence that consent was given.
Every email has an unsubscribe link, one click, no questions. Unsubscribing does not affect anything sent before it.
Why: to send you the newsletter you asked for. Basis: your consent, Article 6(1)(a), together with PECR regulation 22 in the United Kingdom and Article 130 of the Italian Privacy Code.
3.4 When you email me directly
If you email me, I hold your message, your address and anything you attach, in my mailbox. I keep correspondence while I am dealing with it and for a reasonable period afterwards, so that I can pick up a thread months later. Basis: legitimate interests in answering you and in keeping a record of what was said. If the exchange is about a possible piece of work, Article 6(1)(b) applies as well.
3.5 Security and abuse prevention
Cloudflare serves this site and keeps ordinary server logs for a short period: IP address, the page requested, the time, the browser and device type. That is how a site stays online under attack, and there is no way to run one without it.
On the contact form I also run the Turnstile check described in 3.1, a hidden field that only an automated script would fill in, and a cap on how many submissions can come from one network in a short period. the limiter is meant to store a keyed hash of your IP address rather than the address itself — to confirm against /api/contact once it is built
Why: to keep the site up and to stop the contact form being used to send spam. Basis: legitimate interests in securing my systems and preventing abuse.
3.6 Analytics
There is no analytics running on this site yet. The rest of this section describes what will run once it is switched on, and the table in section 4 will list it from the moment it does. Until then, nothing in it is loaded and no request reaches any analytics provider.
Analytics is PostHog, on its European cloud in Frankfurt. It loads only after you have accepted analytics cookies. If you refuse, or if you simply never answer the banner, the script is never loaded and no request is made to PostHog at all.
Automatic capture is switched off, which means PostHog does not record every click and keystroke it can see. What it records is page views and a short, fixed list of events: clicking a call to action, starting the contact form, submitting it, subscribing to the newsletter, clicking through to the booking page, and opening a case study. Alongside those it holds the page address, the page you arrived from, any campaign parameters in the link, your browser and device type, and an approximate location worked out from your IP address at country and region level.
I use this to see which pages get read and which calls to action get used. I do not use it for advertising, I do not track you across other websites, I do not attempt to identify you, and I do not sell or share any of it. PostHog processes it in the EU only, on my instructions, under a data processing agreement.
Basis: your consent, which will be asked for by a banner in the same change that switches analytics on. A Cookie settings link in the footer of every page will let you withdraw it at any time, exactly as easily as you gave it.
3.7 When we work together
This section is a signpost, not the detail. Once we are working together, what I do with personal data is set by our written engagement agreement, not by this page.
In most engagements I also handle personal data that belongs to your business: the events in your analytics, the contacts in your CRM, the subscribers in your email tool. For that data you are the controller and I act as your processor, working on your instructions under written data processing terms, which are part of the engagement agreement. I do not use your customers’ data for my own purposes, and I do not keep it after the engagement ends beyond what those terms allow.
3.8 Reading the blog
Nothing is collected when you read a post beyond the server logs in 3.5. There are no comments, no embedded players, no share buttons that call home, and no third-party scripts on the page. The typefaces are served from this site, so loading a page sends nothing to Google or any other font provider.
4. Cookies
The cookie policy is the full account: what each cookie is for, how long it lasts, how the consent banner works and how to change your mind. In short, a few cookies are strictly necessary and are not optional; everything else is off until you switch it on, and today nothing non-essential is set at all. The table below lists what is actually running, and it is generated from the same file the banner reads, so the two cannot disagree.
| Cookie | Set by | Kind | What it does |
|---|---|---|---|
| __cf_bm | Cloudflare | Strictly necessary | Serves and protects the site at the edge. |
| cf_clearance | Cloudflare Turnstile | Strictly necessary | Checks that a human, not a script, is sending the contact form. Only on the contact page. |
| gp_consent | Giovanni Perri | Strictly necessary | Remembers the choice you make here, so I stop asking. |
5. Who I share it with
I share personal data only with the companies that run parts of this site and my working setup. Each acts on my instructions under a written data processing agreement, and none of them may use your data for their own purposes. I do not sell personal data, I do not share it with advertisers, and I never have.
| Provider | What they do for me | Where data is processed | Transfer basis |
|---|---|---|---|
| Cloudflare, Inc. | Hosts and serves the site (Cloudflare Workers), protects it at the edge, and runs the Turnstile check on the contact form | Global edge network; United States | EU–US Data Privacy Framework and its UK Extension, plus Standard Contractual Clauses |
| Supabase, Inc. | The database that stores contact-form enquiries | Frankfurt, Germany (EU) — region to confirm against the Supabase project settings before launch | None needed; processed in the EU |
| n8n GmbH | Workflow automation: passes a form submission to the database, emails me, sends your auto-reply, and adds a newsletter subscriber to Mailchimp | Frankfurt, Germany (EU) — to confirm whether this instance is n8n Cloud or self-hosted, and in which region | None needed; processed in the EU |
| Intuit Mailchimp (The Rocket Science Group LLC) | Sends the newsletter and holds the subscriber list | United States | EU–US Data Privacy Framework and its UK Extension, plus Standard Contractual Clauses |
| PostHog, Inc. | Counts page views and the events listed in section 3.6, once you have accepted analytics cookies | Frankfurt, Germany (EU Cloud) | None needed; processed in the EU |
| Google Ireland Limited (Google Workspace) | Carries my email, so any message to or from me sits in that mailbox | Republic of Ireland (EU), with support access from the United States — to confirm which provider carries the giovanniperri.com mailbox | EU–US Data Privacy Framework and its UK Extension, plus Standard Contractual Clauses |
| Calendly LLC | Runs the booking page my “Book a discovery call” links open. Calendly is its own controller for what you type there; it is my processor for the booking it passes back to me | United States | EU–US Data Privacy Framework and its UK Extension, plus Standard Contractual Clauses |
Beyond that list, I may disclose personal data to my accountant and other professional advisers under a duty of confidence, where the law or a public authority requires it, and to a buyer if I ever sell the business, in which case this policy continues to apply until they tell you otherwise.
6. International transfers
I am in Italy and most of you are in the United Kingdom, so data crosses that border in both directions. It does so on the strength of an adequacy finding rather than any extra paperwork: the European Commission has decided the United Kingdom offers adequate protection, and the United Kingdom has made equivalent regulations for the European Economic Area. Nothing further is needed for data moving between the two.
Some of the providers in section 5 process data in the United States, or can reach it from there. For those I rely on the EU–US Data Privacy Framework and its UK Extension where the provider is certified, and on the European Commission’s Standard Contractual Clauses with the UK International Data Transfer Addendum otherwise, together with an assessment of the transfer. Ask me and I will tell you which mechanism covers which provider.
7. How long I keep it
I keep as little as I can for as long as I need it, and no longer. Ask me to delete something sooner and I will, unless the law requires me to keep a copy.
| Data | Kept for | Then |
|---|---|---|
| A contact-form enquiry: your name, email, company, website, the package and your message | 3 years from our last contact — to confirm with Giovanni | Deleted |
| Your newsletter subscription: your email address and the record of your consent | until you unsubscribe | Removed from the list; Mailchimp keeps a minimal record that you unsubscribed, so you are not added again by mistake |
| Analytics data at PostHog | 12 months — to confirm once the PostHog project exists | Deleted by PostHog |
| Your consent choice, in the gp_consent cookie in your browser | 6 months, then I ask again | Expires; clearing your cookies removes it immediately |
| Correspondence: emails between us, and bookings made through Calendly | 3 years after the last message, unless it relates to work I did for you | Deleted |
| Records relating to a client engagement, including invoices | 10 years, as Italian tax and accounting law requires | Deleted |
| Cloudflare server logs, and the short-lived rate-limit record | Days rather than months, per Cloudflare’s own retention and the limiter’s expiry | Deleted automatically |
Where I have to keep a note that you asked me to delete something, I keep the minimum needed to honour that request and nothing else.
8. Your rights
Under the GDPR and the UK GDPR you have the right to:
- access the personal data I hold about you, and get a copy of it;
- rectify anything inaccurate or incomplete;
- erase it, where I have no overriding reason to keep it;
- restrict what I do with it while a dispute about it is sorted out;
- port data you gave me to another provider, in a machine-readable format;
- object to processing I base on legitimate interests, and to direct marketing at any time, with no reason needed;
- withdraw consent where I rely on it, for the newsletter or for analytics, without affecting what was done before you withdrew it.
To use any of them, email giovanniperri86@gmail.com, ideally from the address you used with me, or tell me how to check it is you. I reply within one month. If a request is genuinely complex I can extend that by up to two further months, and I will tell you if that happens and why. There is no charge unless a request is manifestly unfounded or excessive.
If you are not happy with how I have handled it, you can complain to a supervisory authority. Mine is the Italian Data Protection Authority (Garante per la protezione dei dati personali). If you are in the United Kingdom you can complain to the UK Information Commissioner’s Office (ICO) instead, and if you are elsewhere in the European Economic Area you can go to the authority in your own country. I would rather you gave me the chance to put it right first.
9. Children
This site sells consultancy to companies. It is not aimed at children, and I have no reason to collect data about anyone under 16. If you think a child has sent me personal data, tell me and I will delete it.
10. Changes to this policy
I update this policy when the site or the tools behind it change. The version number and date at the top of the page tell you which one you are reading. This version, 1.0, takes effect on 21 September 2026 and supersedes anything published at thegrowthhustlers.com.
If a change is material, for example switching analytics on or adding a provider, I change the version and the date, and the tables above update themselves because they are generated from the same files the site runs on. For a material change that affects the newsletter, I will say so in the newsletter before it takes effect. Earlier versions are available on request.
11. How to contact me
Perri Giovanni, trading as Giovanni Perri, a sole trader registered in Italy (ditta individuale), Partita IVA IT 03133680342, Parma, Italy.
Email giovanniperri86@gmail.com. I do not publish a street address, because I work from home and the law does not require it. If you need one for a formal notice, ask and I will give it to you.
The cookie policy covers browser storage, and the terms of use cover the site itself.