Privacy Policy
This notice explains how personal Data is processed when you browse the VIRO Music Entertainment website or contact us, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Italian law.
Last updated: August 21, 2026
1. Data Controller
VIRO Music Entertainment S.r.l.Piazza Sannazzaro 200, 80122 Napoli (NA), Italy
VAT and Tax Code 10863461215 · REA NA-1137729
Email: info@viromusic.com
No Data Protection Officer has been appointed, as the Controller does not currently consider the appointment mandatory for the processing described in this notice.
2. Scope of this Policy
This Policy applies to this website and its contact channels. It does not govern third-party websites and platforms reached through external links, which process Data under their own privacy notices.
3. Data We Process
Navigation and technical Data
When the site is accessed, the web server and hosting infrastructure may automatically process technical information such as IP address, date and time of access, requested URL, response status, browser and device information, referring page, and security or error logs. This information is necessary to deliver the site, maintain its security, and diagnose technical issues.
Data provided when contacting us
If you contact VIRO by email or through a contact functionality, we may process your name, email address, professional role, the content of your message, and any information or files you voluntarily provide. Please do not send special-category Data or confidential third-party material unless it is genuinely necessary and you are authorized to do so.
External platform interactions
The site contains ordinary links to Spotify, YouTube and Instagram. No player, social plug-in or third-party iframe is loaded on this site. Those platforms receive Data only when you choose to follow a link and then operate as independent Data controllers under their respective policies.
4. Purposes, Legal Bases and Retention
| Purpose | Legal basis | Retention |
|---|---|---|
| Delivering the website, preventing abuse, ensuring security and troubleshooting. | Legitimate interest of the Controller under Art. 6(1)(f) GDPR. | Technical logs are normally retained for up to 30 days, unless a security incident or legal requirement justifies longer retention. |
| Responding to enquiries and evaluating possible professional or commercial relationships. | Steps taken at the Data subject's request before entering into a contract under Art. 6(1)(b) GDPR; where not applicable, legitimate interest under Art. 6(1)(f) GDPR. | Up to 12 months after the request is closed, unless a relationship begins or longer retention is needed to protect a right. |
| Complying with legal, accounting or regulatory obligations and establishing, exercising or defending legal claims. | Art. 6(1)(c) and, where applicable, Art. 6(1)(f) GDPR. | For the period required by law or necessary to protect rights, ordinarily up to 10 years where the relevant statutory period applies. |
5. Nature of Data Provision
Navigation Data is processed automatically as part of normal internet communications. Providing contact Data is voluntary, but without the information needed to understand and answer a request, VIRO may be unable to respond.
6. Processing Methods and Security
Data is processed mainly by electronic means, according to principles of lawfulness, fairness, transparency, minimization and storage limitation. VIRO adopts technical and organizational measures appropriate to the risk. No internet transmission or storage system can, however, be guaranteed as absolutely secure.
7. Recipients
Data may be accessed by authorized personnel and by providers supporting hosting, infrastructure, security, IT maintenance and email services. Where required, such providers act as processors under Art. 28 GDPR. Data is not sold or publicly disclosed, except where required by law or a competent authority.
8. Transfers Outside the EEA
If a provider processes personal Data outside the European Economic Area, VIRO will rely on a lawful transfer mechanism under Chapter V GDPR, such as an adequacy decision or Standard Contractual Clauses, together with any supplementary safeguards required by the circumstances.
9. Your Rights
Subject to the conditions of the GDPR, you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time without affecting prior processing. You may exercise your rights by writing to info@viromusic.com. VIRO may request information necessary to verify your identity.
10. Automated Decisions and Profiling
The site does not carry out automated decision-making or profiling producing legal or similarly significant effects.
11. Complaints
You may lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) through garanteprivacy.it, without prejudice to any other administrative or judicial remedy.
12. Changes
This Policy may be updated to reflect legal, technical or organizational changes. The current version and its update date will always be published on this page.