Version 2026-08-05.1 · Last updated: 5 August 2026
Privacy notice
This notice explains which personal data the Pianoconcerto Forum processes, why it is processed, how long it is kept and which rights you can exercise. It applies to forum.pianoconcerto.it and, where connected features are involved, pianoconcerto.it.
The Cookie Policy separately explains cookies, local storage, session storage and third-party embedded content. The Terms of Use govern participation in and moderation of the community.
1. Controller and contact
The controller identified for the service is Pianoconcerto.it.
For privacy questions and requests concerning personal data: info@pianoconcerto.it.
No data protection officer has been appointed where the legal requirements for such appointment do not apply. If one is appointed, their details will be added here.
2. Scope and services
This notice covers registration, sign-in, profiles, discussions, replies, reactions, reports, private messages, drafts, attachments, search, notifications, service email, moderation, administration and features connected to the forum.
It does not govern third-party websites opened through a link or external player. Once you choose to load external content, that provider may process data under its own notice and settings.
3. Data we process
| Category | Examples | Notes |
|---|---|---|
| Account and identity | Public name, email address, protected password, internal identifier, account status, minimum-age declaration, Terms version and acceptance time, avatar, signature, biography and profile fields. | Passwords are never stored in plain text. We do not request date of birth from new members; dates collected under the previous form may remain in historical accounts until deletion or an applicable request, and are not public. |
| Preferences | Language, display settings, theme, reading mode, notification and email preferences. | The account language is stored with the account so it can be restored at the next sign-in. |
| Published content | Discussion titles, text, formatting, quotes, links, images, audio, video, attachments and related metadata. | Visibility depends on the forum section, discussion and profile settings. |
| Messages and drafts | Private messages, recipients, attachments, drafts and data needed to save or restore a draft. | Private content is available only to authorised participants and, in the limited cases described below, authorised staff. |
| Security and moderation | Reports, sanctions, restrictions, bans, access events, IP address, user agent, technical identifiers and abuse-control results. | Some records are needed to prevent abuse, investigate incidents and demonstrate decisions. |
| Technical data | Cookies, session and CSRF tokens, presence indicators, request data, errors, performance data and security logs. | These are not used to sell advertising profiles. |
4. Sources of data
Most data comes directly from you when you create an account, complete your profile, publish content, send a message, use a form or change a preference. Some data is generated by the service, such as security logs, tokens, delivery results and automated moderation outcomes.
We may also receive data when another user quotes, reports or messages you, or when a technical provider responds to a requested operation.
5. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Create and manage the account, authenticate members and provide publishing, editing and account features. | Performance of the service contract or pre-contractual steps requested by you. |
| Provide private messages, drafts, notifications, followed discussions, quotes and essential service communications. | Performance of the service and legitimate interest in providing expected community features. |
| Obtain the mandatory minimum-age declaration and retain evidence of it without collecting date of birth. | Pre-contractual steps, performance of the Terms and applicable legal obligations. |
| Prevent spam, bots, fraud, abuse, illegal content and unauthorised access. | Legitimate interest in service and community security, and legal obligations where applicable. |
| Moderate content and accounts, process reports and appeals and apply forum rules. | Legitimate interest in running an orderly community and complying with applicable obligations. |
| Remember optional preferences, load external content or perform non-essential measurement. | Consent, which can be withdrawn at any time. |
| Protect rights, investigate incidents and respond to authorities. | Legitimate interest and legal obligations. |
6. Age and minors
Independent registration is reserved for people aged at least 14, subject to any different applicable rule. At registration we request only a mandatory declaration that this condition is met and retain its date and time: we neither request nor store a date of birth for new members.
Some historical accounts may still contain a date of birth supplied through the previous form. It is not public and, while retained, may be used for protections already applicable to those profiles; it is not requested for new accounts.
We do not knowingly request data from children below the permitted age. A parent, guardian or affected person may contact us if they believe data was collected contrary to this rule.
7. Public content and profiles
Public names, avatars, signatures, profiles and published content may be visible according to the relevant settings and forum rules. Do not publish an address, telephone number, identity document, password, health information or other personal data that you do not want to share.
Published content is processed to display, protect, moderate, search and preserve discussion continuity. Quotes or excerpts copied into another user’s reply may remain even if the original is later changed or anonymised.
The IP address used to publish a post is retained in encrypted form for security and abuse prevention. It is not public: only authorised administrators may view it, and it is detached from the post when the account is anonymised.
8. Private messages, drafts and staff access
Private messages are processed to deliver communication, retain the conversation and provide notifications. An unpublished draft remains associated with its account and is not visible to other users.
For safety and abuse prevention, private messages may undergo automated checks. Only when a check indicates a likely violation with high confidence may an expressly authorised administrator inspect the flagged conversation. Access is limited to that purpose and recorded in an audit log; it is not a general right to read private messages.
9. Automated processing and RunAI
When a feature requires it, public text and related metadata may be sent server-to-server to configured RunAI services for translation, semantic search, summarisation, writing assistance, abuse classification and text-to-speech. Media is processed only when the relevant pipeline requires it.
These operations do not transfer ownership of the content or authorise the provider to use it to train its own models. We send only what is needed for the requested operation and do not send passwords, access tokens or API keys. Outputs are tied to the source version and may be deleted or regenerated when the source changes.
Automated systems may flag, classify, delay or temporarily suspend an operation. We do not make an irreversible decision with significant effects solely from a model: contestable sanctions can receive human review and automatic measures are designed to be temporary and reversible.
10. Email and service communications
We may send verification, security, password-recovery, followed-discussion, quote, private-message, moderation and important service emails. The email language follows the language saved in the account; Italian is the default.
Delivery is handled by transactional and bulk email providers. They receive the address, recipient, subject, content and technical data needed for delivery and may process delivery, bounce, complaint and suppression data. Transactional emails are configured without intentional open or click tracking; administrative bulk campaigns may use measurement features of the sending service where enabled.
11. Google reCAPTCHA
Sign-in, registration and password recovery pages, the contact form and site administration use Google reCAPTCHA v3 to distinguish people from automated programs. It may process IP address, browser data, interaction data and other technical signals and returns a reliability score to our server.
It is loaded only where security protection is required. It is provided by Google Ireland Ltd.; Google’s Privacy Policy and Terms of Service apply.
12. Recipients and international transfers
Access is limited to authorised staff and the providers required for hosting, database, storage, backup, security, monitoring, email, RunAI and reCAPTCHA. Elastic Email is used for transactional and bulk email delivery; RunAI is called through the configured api.runai.it endpoint. We do not sell personal data or provide it to data brokers.
Some providers may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, Standard Contractual Clauses or another legal safeguard. Specific provider and safeguard information can be requested from the privacy contact.
13. Retention
| Data | Retention criterion |
|---|---|
| Account and profile | While the account is active or until deletion is requested, except for the minimum data needed for security, legal obligations and audit. |
| Published discussions, posts and attachments | For the life of the archive under forum rules. Account deletion anonymises authorship and does not automatically remove the contributions. |
| Private messages and drafts | While needed for the feature, security or a report. Copies already received by other participants may remain in their history. |
| Security, moderation and audit logs | For a proportionate period needed to prevent repeat abuse, investigate incidents, handle appeals and demonstrate actions; longer where required by law or dispute. |
| Terms acceptance and minimum-age declaration | For the life of the account and afterwards for as long as needed to demonstrate the agreement, handle disputes and comply with applicable obligations. |
| Consent record | For 180 days in the browser, unless deleted earlier or replaced by a new version. |
14. Account deletion and anonymisation of posts
When a member asks to leave the forum, deletion applies to their personal data and account, not to the collective history of discussions. Published discussions, posts and replies do not automatically disappear: they remain so that context, quotes and conversations involving other members remain understandable.
An authenticated member can start the self-service deletion process directly. Before the final confirmation, the forum shows the impact on the account, asks for the current password and an explicit acknowledgement, and lets the member stop without changing anything.
The standard deletion process is:
- disable the account and invalidate active sessions;
- delete or make unusable the email, password, authentication data, personal preferences, signature, avatar and profile information;
- fully anonymise authorship metadata for surviving posts, discussions and replies by detaching the account and replacing the public author with a generic label such as “Removed user”; no profile, avatar, signature or clickable link to the deleted account remains;
- update, remove or regenerate derived processing that is still attributable to the account;
- delete unpublished drafts and data no longer needed, while keeping minimal pseudonymised security and audit records when necessary to prevent abuse or demonstrate an operation.
Anonymisation concerns authorship and attribution metadata. If a member voluntarily included a phone number, email address or other personal data in the body of a post or message, the system cannot always identify it automatically. A specific removal request can be submitted and will be assessed against the rights of other members, security and legal retention duties.
Messages already received by other members may remain in their conversations, and quotes or excerpts copied into other posts may survive anonymisation. Personal data will not remain publicly visible merely to preserve the deleted member’s name.
15. Security
We use proportionate technical and organisational measures, including encrypted connections, password hashing, multi-factor authentication for enabled staff accounts, role-based access, private attachment storage, CSRF and anti-bot protection, rate limiting, session controls, backups and administrative audit logs.
No online service can guarantee absolute security. Contact us promptly if you suspect unauthorised access or a vulnerability, without including passwords or secret keys.
16. Your rights
Subject to applicable law, you may request access, rectification, erasure, restriction, portability, objection to processing based on legitimate interest and withdrawal of consent. Withdrawal does not affect processing already carried out lawfully.
Account deletion is available through the self-service process described in section 14. For other rights, personal data written inside contributions, or if you can no longer sign in, contact the privacy address with the account email and a description of the request. We may ask for reasonable information to verify identity and protect the account. You may also complain to the Italian Data Protection Authority (Garante) or another competent supervisory authority.
17. Changes to this notice
We may update this page when features, providers or legal requirements change. Material changes are announced by updating the version shown at the top. Where required, optional consent will be requested again.