PRIVACY POLICY – THE ITALIAN
ACADEMY (The Academy s.r.l.)
Information Notice pursuant to Article 13 of EU Regulation No. 2016/679 (GDPR)
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website, enroll in our language courses, or apply for our International Foundation Year (FY) program.
1. DATA CONTROLLER
The Data Controller is The Academy S.r.l., with its registered office in Via San Giovanni alle Catacombe n. 7, 96100 Syracuse (SR), Italy. For any privacy-related inquiries, the Data Controller can be contacted at: privacy@theitalianacademy.com.
2. SCOPE OF THIS POLICY AND DATA COLLECTED
Depending on the services you request, we collect different types of data:
A. General Language Courses & Standard Users
- Personal Information: Name, surname, email address, phone number, nationality, date of birth.
B. International Foundation Year (IFY) Applicants & Students Due to the academic and administrative requirements of the FY program, we process additional documentation via our secure application portals:
- Academic & Identity Data: Passport copy, High School Diploma (including CIMEA Statement of Comparability, if applicable), academic transcripts, English language certificates (e.g., IELTS), age, and gender.
- Financial Data: Payments for application fees and tuition are processed exclusively via certified third-party global payment gateways. The Italian Academy does not store, process, or retain any sensitive credit card or banking information on its servers.
- Special Categories of Data (Art. 9 GDPR): We do not systematically collect sensitive data. However, if a student explicitly requests “Learning Accommodations” due to specific health conditions or disabilities, such medical data will be processed strictly upon the student’s explicit consent, exclusively to provide the necessary academic support.
3. PURPOSES AND LEGAL BASIS OF PROCESSING
Your data is processed for the following purposes:
- Service Provision & Pre-contractual Measures (Art. 6.1.b GDPR): To evaluate IFY applications, manage enrollment, provide academic instruction, and organize housing.
- Legal Obligations (Art. 6.1.c GDPR): To comply with Italian administrative, tax, and public security laws.
- Marketing & Promotional Activities (Art. 6.1.a GDPR): Only upon your explicit, opt-in consent, to send you newsletters, updates, and promotional material. You may revoke this consent at any time without affecting your academic enrollment.
4. SPECIAL PROVISIONS FOR FOUNDATION YEAR STUDENTS (DATA SHARING)
To ensure full compliance with the rigorous procedures of the Italian Higher Education system, IFY student data is subject to specific sharing protocols:
- Partner Universities (Independent Data Controllers): Upon successful pre-screening of your application by The Italian Academy, your academic and personal data will be shared with the relevant Partner University chosen by the student. The Partner University will process your data as an Independent Data Controller for the purpose of final academic validation and the issuance of the Letter of Eligibility.
- Immigration and Government Portals: Immigration procedures and official portal registrations (including the Universitaly portal and Embassy visa applications) remain the student’s sole and independent responsibility. The Italian Academy provides advisory support but does not act as an intermediary on governmental platforms.
- Housing and Local Compliance: Data required for housing and local legal compliance (e.g., Police registration under the Italian T.U.L.P.S. law) will be accessed by our Student Affairs and Housing departments, and shared with local authorities, solely upon confirmed enrollment.
5. PROTECTION OF MINORS
The Italian Academy applies strict measures to protect minors. For candidates who are under 18 at the time of application (but will turn 18 before the end of the program), the processing of data and the formalization of the enrollment require the mandatory submission of a Legal Guardian Assignment Form, duly signed by a parent or legal guardian.
6. DATA SECURITY AND IT ARCHITECTURE
We implement robust technical and organizational measures (Privacy by Design and by Default) to secure your data:
- Segregation of Data (Role-Based Access Control): Sensitive documents (such as Passports and Academic Transcripts) are securely stored on our encrypted corporate Cloud servers (Google Workspace) and are accessible only to authorized personnel.
- Educational Platforms: For daily academic management, we utilize dedicated educational platforms (ScuolaSemplice for attendance/grading and SA Learn/Google Classroom for study materials). To enforce data minimization, only essential identifier data (Name, Surname, and Academic Track) are transferred to these platforms.
7. AUTHORISED PERSONS AND DATA PROTECTION OFFICER (DPO)
Authorised Persons (Incaricati del Trattamento):
Your personal and academic data is processed exclusively by internal employees and designated staff members of The Italian Academy who have been formally authorized to process personal data (Authorised Persons). These individuals operate strictly under the direct authority and documented instructions of the Data Controller. All authorized personnel are bound by rigorous confidentiality agreements, operate under the principle of least privilege (Role-Based Access Control), and undergo mandatory, continuous training on GDPR compliance and data security protocols.
Data Protection Officer (DPO):
In compliance with Article 37 of the GDPR, and considering the nature, scope, context, and purposes of our international educational activities, which may include the systematic processing of specific data categories (e.g., health records for learning accommodations) to ensure equal access to education, The Italian Academy has officially appointed a Data Protection Officer (DPO). The DPO monitors our internal compliance with data protection laws, advises on privacy impact assessments, and acts as the official point of contact for Data Subjects and Supervisory Authorities. For any specific inquiries regarding the safeguarding of your data, the DPO can be contacted directly at: dpo@theitalianacademy.com.
8. DATA RETENTION
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements. Specifically, student records will be kept for the duration of the enrollment and for a maximum period of 10 years thereafter, as mandated by Italian civil and tax law. Data collected for marketing purposes will be deleted after 36 months of inactivity or upon your opt-out.
9. DATA SUBJECT RIGHTS
Under Articles 15-22 of the GDPR, you have the right at any time to:
- Request access to and a copy of your personal data;
- Request rectification or erasure of your personal data;
- Request the restriction of processing;
- Object to the processing of your data (especially for direct marketing);
- Exercise the right to data portability;
- Withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
- Lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali).
To exercise these rights, please submit a written request to privacy@theitalianacademy.com.
Cookie Policy
Last updated: 13/07/2026
1. What cookies and similar technologies are
Cookies are small files or identifiers stored by a browser while a website is being visited. Similar technologies include local storage, pixels, tags, SDKs and online identifiers. They may be used to operate the website, remember preferences, measure visits and assess the effectiveness of advertising campaigns.
2. Who uses cookies
This website is operated by The Academy S.r.l., VAT number IT00731730891, which may be contacted at info@theitalianacademy.com. Some cookies are set directly by the website, while others are set by third-party providers.
3. Cookie categories
- Technical and functional cookies: enable security, navigation, forms, checkout, payment and storage of preferences. Strictly necessary cookies may be used without consent. Non-essential functional cookies are managed according to the banner configuration.
- Analytics cookies: help us understand how the website is used, which pages are visited and which channels generate traffic. They are activated only with consent, except for genuinely anonymous solutions without online identifiers where permitted.
- Marketing cookies: enable advertising measurement, remarketing, audience creation, attribution and campaign personalisation. They are activated only with consent.
4. Services and technologies used
| Service | Category | Provider | Purpose | Examples | Indicative duration |
|---|---|---|---|---|---|
| WordPress / Elementor | Technical | Website service providers | Page operation, sessions, security and technical preferences. | session cookies, technical preferences and login cookies for authenticated users | Session or according to configuration |
| TIA Privacy & Cookie Manager | Technical | The Academy S.r.l. | Store the user’s consent preferences. | tia_pcm_consent / localStorage | 180 days |
| Stripe | Technical / payment | Stripe | Fraud prevention, security and payment processing. | __stripe_mid, __stripe_sid and similar technical identifiers | According to Stripe configuration; some identifiers may last up to approximately one year |
| Typeform | Technical / functional | Typeform | Display and submission of forms and questionnaires. | Typeform session and preference identifiers | Session or according to Typeform configuration |
| HubSpot | Technical and/or marketing | HubSpot | CRM, forms, chat, visit analytics, attribution and automation. | hubspotutk, __hstc, __hssc, __hssrc, messagesUtk | From the session duration to several months, depending on the function and configuration |
| Google Analytics 4 | Analytics | Measure website use, performance, traffic sources and conversions. | _ga, _ga_*, _gid and similar identifiers | From approximately 24 hours to two years, depending on configuration | |
| Google Tag Manager | Technical container | Manage and distribute configured tags. GTM does not determine the purposes of the tags it loads. | Normally no cookies of its own; it may load other services | Depends on the configured tags | |
| Google Ads | Marketing | Campaign measurement, conversions, remarketing and attribution. | _gcl_au, IDE and similar advertising identifiers | From several days to several months, depending on configuration | |
| Meta / Facebook Pixel | Marketing | Meta Platforms | Measure campaigns, attribute conversions and create custom audiences. | _fbp, _fbc and similar identifiers | Generally up to approximately three months, depending on configuration |
| TikTok Pixel | Marketing | TikTok | Campaign measurement, attribution, optimisation and audience creation. | _ttp, ttcsid_*, ttclid and similar identifiers | Up to approximately thirteen months for some cookies, depending on configuration |
| UTM parameters | Analytics / marketing | The Academy and analytics/CRM providers | Attribute visits, enquiries and conversions to campaigns and channels. | URL parameters and any storage performed by analytics or CRM services | Depends on the service that stores them |
| Zapier | Normally no required front-end cookies | Zapier | Transfer data between services and automate configured workflows. | It may not set cookies on the website; it processes data sent through integrations | According to workflow and service configuration |
| Website email and forms | Technical / contractual | The Academy and email/CRM providers | Send enquiries, registrations, bookings and communications. | No specific cookie is necessarily required; submitted data is processed | According to the purposes and periods described in the Privacy Policy |
Cookie names and durations may change as a result of provider updates, website configuration, browser settings and country-specific features. The table should be reviewed periodically by performing an actual scan of the website.
5. Google Consent Mode v2
When enabled, the website communicates the user’s consent status to Google tags through parameters including analytics_storage, ad_storage, ad_user_data and ad_personalization. Before a choice is made, these parameters are denied unless a category has been configured by the Controller as always active. Tags configured in Google Tag Manager must respect these preferences.
6. Forms, CRM, payments and automation
Stripe is used to process payments and prevent fraud. Typeform and/or website forms may collect first name, last name, email address, telephone number, postal address, city, state or region, country and other information needed to process an enquiry or registration. HubSpot may manage contacts, CRM records, forms, email, attribution and automations. Zapier may transfer data between applications configured by the Controller. These processing activities are also described in the Privacy Policy.
7. How to change or withdraw consent
On the first visit, users may accept all cookies, reject non-essential cookies or customise individual categories. The preferences panel may be reopened at any time by using the “Manage privacy” button or the following control:
Withdrawal prevents new loads controlled by this plugin. Third-party cookies that have already been stored may also need to be removed through the browser settings or the relevant provider’s controls.
8. Browser settings
Browsers allow users to view, delete or block cookies. Blocking all technical cookies may prevent forms, restricted areas, checkout and payments from working correctly. Consult the help documentation of the browser being used to manage these settings.
9. Updates to this Cookie Policy
This Cookie Policy may be updated when services, configurations or applicable laws change. Where changes are substantial, users may be asked to provide consent again.