Last updated: 16 September 2026
This notice describes the processing of personal data when visiting alessiosferro.dev. The website does not use advertising, profiling, analytics or data collection forms.
1. Data controller
The data controller is Alessio Sferro, Palermo, Italy. For privacy-related requests, email sferro.alessio@gmail.com.
2. Data processed while browsing
When you visit the website, the systems that make it available may automatically receive technical data required for communication and security, including IP address, request date and time, requested page, browser, operating system, user-agent and diagnostic information.
The controller does not use this data to identify visitors, build profiles or measure individual behaviour.
3. Purposes and legal basis
Technical data is processed solely to:
- deliver the pages you request;
- keep the website secure and available;
- prevent abuse, harmful automated traffic and technical problems.
Processing related to website security and operation is based on the controller’s legitimate interest in providing a secure service under Article 6(1)(f) GDPR. Storage that is strictly necessary on the user’s device falls under the exemption in Section 122(1) of the Italian Privacy Code.
4. Hosting and recipients
The website is published through OpenAI Sites and delivered using Cloudflare infrastructure. These providers may process technical data needed for delivery, network security and protection under their respective agreements and notices.
Fonts, stylesheets and JavaScript libraries are served directly from alessiosferro.dev. Loading a page does not require a connection to Google Fonts or jsDelivr.
5. Cookies
The website only uses strictly necessary technical cookies. It does not use profiling, marketing or analytics cookies.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
__cf_bm | Cloudflare | Protection from harmful automated traffic and security management. | 30 minutes of inactivity |
Because this cookie is strictly necessary for website security and delivery, prior consent is not required. This is why the website does not display a consent banner.
6. Retention
The __cf_bm cookie expires after 30 minutes of inactivity. The controller does not maintain a separate visitor archive. Any technical logs are retained by the providers only according to the time periods and criteria required for security, diagnostics and service delivery, as described in their notices and applicable agreements.
7. International transfers
Technical providers may process data outside the European Economic Area. Where applicable, those transfers must rely on an adequacy decision or another safeguard under Articles 44 and following of the GDPR, such as standard contractual clauses.
8. External links
The website contains ordinary links to LinkedIn and GitHub. No content from these platforms is embedded in the pages. Their services receive data only when you choose to open one of those links and apply their own privacy notices.
9. Your rights
Where provided by the GDPR, you may request access, correction, deletion, restriction or object to processing and receive information about how your data is handled. Send requests to the address above. You also have the right to lodge a complaint with the Italian Data Protection Authority.
10. Changes
This notice may be updated when features, providers or applicable law change. The date shown at the beginning identifies the latest revision.