Notice / Article 13 GDPR
Privacy Policy
This notice explains which personal data may be processed when you visit variune.com, why it is processed and which safeguards apply.
1. Scope of this notice
This notice applies to variune.com and its pages. It does not apply to external ecosystem websites: NexNode Cloud, MWCLIENT, MOVARA and the other projects apply their own notices where available.
The website is editorial and informational. It currently has no user accounts, newsletter, contact form, behavioural advertising or visit analytics.
2. Data controller
- Controller and operator
- M.O. Società a Responsabilità Limitata Semplificata
- VAT and tax code
- 09508751212
- Registered office
- Piazza Montessori 11, 80011 Acerra (NA), Italia
- info@movara.it
Variune Studios is an independent digital project operated by M.O. Società a Responsabilità Limitata Semplificata.
3. Data processed
Browsing and security data
The systems delivering the website receive technical data normally transmitted by internet protocols, including IP address, request date and time, requested resource, response status, HTTP headers, browser and device type, and diagnostic or security events. Variune does not use this data to identify or profile visitors.
Language preference
On the homepage, the server may read the browser's accepted languages and the approximate country code made available by Cloudflare to choose between English and Italian. The feature does not create a profile and Variune does not keep the IP address or country code in a separate database for this purpose. A manual choice is stored for one year in the strictly functional variune_locale cookie.
Data provided voluntarily
Emailing the published email or certified email address entails processing the sender address, message and attachments only to handle the request.
Privacy notice preference
The browser stores the acknowledgement of the cookie notice locally, with its version and expiry. It contains no name, email address or identifier assigned by Variune.
4. Purposes and legal bases
Variune does not carry out solely automated decisions producing legal effects, scoring, profiling, direct marketing or sale of personal data.
5. Provision of data
Technical data is provided automatically during browsing; without it the page cannot be delivered securely. Sending a message is optional, although a reply requires contact details. Blocking local storage or the language cookie may make the notice reappear or reset the language, without preventing access to the content.
6. Recipients, processors and transfers
Technical data may be processed as necessary by hosting, content delivery, security and maintenance providers. The website is hosted through ChatGPT Sites; OpenAI processes hosted data on behalf of the controller under the applicable data processing terms and may use listed subprocessors. Cloudflare provides network delivery and anti-abuse components.
Confidential advisers and public authorities may receive data where required by law. Data is not shared for advertising. Where a provider involves processing outside the EEA, the applicable Chapter V GDPR safeguards may include adequacy decisions or Standard Contractual Clauses under the relevant provider terms.
7. Retention
- Browsing data: for the technical period needed to deliver and protect the website under provider retention rules. Variune does not keep an independent, indefinite browsing log.
- Language preference: the functional cookie lasts up to one year, or less if deleted or replaced by the user.
- Communications: for handling and following up the request, generally no longer than 24 months after the last contact, without prejudice to legal duties or documented defence needs.
- Privacy notice choice: for up to six months, unless the user deletes site data earlier.
8. Data subject rights
Where applicable under Articles 15–22 GDPR, users may request access, rectification, erasure, restriction and portability, and may object to processing. Requests can be sent to info@movara.it or mosrls@pec.cgn.it. The controller normally replies within one month and may request only the information needed to verify identity.
A complaint may be lodged with the Italian Data Protection Authority or with the competent supervisory authority or court.
9. Security and updates
The website applies data minimisation, access controls, encrypted transport and infrastructure safeguards proportionate to the data. Incidents are assessed under Articles 33 and 34 GDPR.
This notice is reviewed when functions, providers or processing activities change. The date above identifies the current version.