How we handle information
Privacy Policy
A clear account of what information NonProfit.it processes, why it is needed and the rights you can exercise.
Updated 21 March 2026 · version 2.4
Data controller
The controller of personal data is Gabriele Masetti, founder of NonProfit.it, a privately operated information service and directory of Italian nonprofit organizations. The public service is free to access and does not require an account.
For any privacy request, including the exercise of GDPR rights, write to privacy@nonprofit.it. A Data Protection Officer has not been appointed because the conditions set out in Article 37 GDPR do not apply to the current processing activities.
Information we collect
The information collected depends on how you use the website. We apply data minimization and do not ask visitors to create an account.
- Technical browsing information, such as minimized or pseudonymized IP data, request time, pages viewed, browser and operating system, used for security, operation and aggregate statistics.
- Information voluntarily entered when submitting an organization, including the organization’s details and the submitter’s name, email address and relationship with the organization.
- Functional preferences stored only in your browser, including theme, language, accessibility settings and saved organizations.
Purposes and legal bases
Personal data is processed only for specific purposes and under the legal bases provided by Article 6 GDPR.
- Operating and securing the public directory: legitimate interests under Article 6(1)(f) GDPR.
- Reviewing organization submissions and contacting the submitter when clarification is needed: consent under Article 6(1)(a) GDPR.
- Producing aggregate or minimized usage statistics to improve the service: legitimate interests under Article 6(1)(f) GDPR.
Data retention
We keep personal data only for as long as necessary for the purpose for which it was collected.
- Aggregate browsing statistics are retained for no longer than 12 months.
- Organization information may become part of the public directory after review; it is separated from the submitter’s personal details.
- A submitter’s name and email address are retained only while a submission is being handled and, in any event, for no longer than 12 months after receipt.
Your rights
Under the GDPR you may request access, correction, deletion, restriction or portability of your personal data, and you may object to processing based on legitimate interests. You may also withdraw consent without affecting earlier lawful processing.
Send requests to privacy@nonprofit.it. We normally respond within 30 days. You may also lodge a complaint with the Italian Data Protection Authority at garanteprivacy.it.
International transfers
Data is hosted primarily on infrastructure located in the European Union. Some technical providers may process limited information in third countries for support, maintenance or service operation.
Where an international transfer occurs, it is governed by Articles 44–49 GDPR and appropriate safeguards, including Standard Contractual Clauses where required.
Service providers
Technical providers may act as processors under Article 28 GDPR where applicable. The current service uses Supabase for database infrastructure, Netlify for hosting and content delivery, and Umami for privacy-focused usage statistics. An up-to-date list is available on request.
Changes to this notice
This notice may be updated to reflect changes to the service, applicable law or processing practices. The current version and update date are always published on this page; material changes may also be highlighted on the website.

