Privacy Policy
Last updated: 28/08/2026
This policy describes how Mailly Marche ("the Data Controller", "we") collects, uses and protects the personal data of visitors to the maillymarche.com website and of clients requesting photography services.
1. Data Controller
Mailly Marche
Freelance photographer
Porlezza (Como) - ITALY
Email: maillyphotographer@gmail.com
SIRET: 98890923000019
2. What data we collect
- Contact details: name, surname, email, phone number, provided through the contact form or by email/phone when requesting information or booking a session.
- Data related to the photography service: information about the pregnancy, expected due date, family composition, address for at-home sessions, needed to organise the shoot.
- Photographic images: photographs taken during sessions, which may include images of adults and minors (newborns and children).
- Browsing data: IP address, device and browser type, pages visited, collected automatically through cookies and analytics tools (see Cookie Policy).
- Data collected through online advertising: interactions with our Meta Ads and Google Ads campaigns.
3. Purposes and legal basis of processing
- Responding to information and quote requests — Pre-contractual steps taken at the data subject's request
- Organising and carrying out the photography service — Performance of a contract
- Publishing photographs on the website, Instagram and Facebook (portfolio) — Explicit consent, collected via a separately signed release form
- Sending promotional communications (if activated in the future) — Consent of the data subject
- Managing Meta Ads / Google Ads advertising campaigns — Consent via the cookie banner
- Tax and accounting obligations — Legal obligation
For photographs including minors, publication only takes place with the prior written consent of both parents/guardians, collected through the photo release form signed before or during the session.
4. Recipients of the data
Data may be shared with:
- Wix.com Ltd., the provider of the website hosting platform;
- Meta Platforms Inc. (Facebook/Instagram), for page management and advertising campaigns;
- Google LLC, for Google Ads and analytics tools;
- The accountant/tax advisor, for administrative purposes;
- Public authorities, where required by law.
Some of these providers (Meta, Google) may transfer data to countries outside the EU (United States). Such transfers rely on the standard contractual clauses approved by the European Commission or other adequate safeguards provided by these vendors.
5. Retention periods
- Contact details of people who do not become clients: up to 12 months from the last contact.
- Clients' contractual and tax data: for the period required by applicable tax regulations.
- Photographs: retained as specified in the photography service contract and the release form signed by the client.
6. Data subject rights
As a data subject, you have the right to:
- access your personal data;
- request its rectification or deletion;
- restrict or object to its processing;
- request data portability;
- withdraw your consent at any time (including for the publication of images), without affecting the lawfulness of processing carried out before the withdrawal;
- lodge a complaint with the competent supervisory authority (in Italy, the Garante per la protezione dei dati personali; in France, the CNIL).
To exercise these rights, write to: maillyphotographer@gmail.com
7. Data security
We implement appropriate technical and organisational measures to protect data against unauthorised access, loss or disclosure, including the security measures provided by the Wix platform.
8. Changes to this policy
This policy may be updated periodically, for example following the opening of the Italian tax position. The date of the last update is shown at the top of the document.
9. Reference to Swiss data protection law (FADP/nFADP)
Since the website and advertising campaigns also target an audience based in Switzerland (particularly in the Lugano area), the processing of personal data of individuals located in Switzerland is also subject to the Swiss Federal Act on Data Protection (FADP), in addition to the GDPR. The FADP grants data subjects rights that are substantially equivalent to those under the GDPR (access, rectification, deletion, objection). Should large-scale processing targeted at the Swiss market occur, the Data Controller will, if necessary, consider appointing a representative in Switzerland under the FADP.

_edited_edited_edit.png)