Privacy Policy

This Privacy Policy explains how Lamb Bag Rainbow processes personal data when users visit lambbagrainbow.baby, register for courses, or otherwise interact with our services.

Effective Date
As stated in this policy
Scope
All users of our services
Questions?

Purposes of Processing

We use personal data to provide and manage course services, create and maintain user accounts, process registrations and related transactions, communicate about enrolment or support matters, improve site performance, maintain security, prevent misuse, comply with legal obligations, and keep internal records.

Processing is limited to operational, administrative, and compliance purposes described here.

Service Providers

We may share personal data with trusted service providers that support hosting, payment processing, analytics, security, communications, or course administration. These parties act under contractual or operational limits and may process data only for the services they provide to us. We do not authorise them to use the data for unrelated purposes.

Service providers receive only the information needed to perform their assigned functions.
Privacy Contact

Contact Information

Privacy email
Telephone
+39 312 995 8383
Mailing address
Via Arco di San Biagio 19, 00061 Anguillara Sabazia
Privacy contact
GDPR

EU data protection framework

GDPR Notice

Where the GDPR applies, we process personal data on a lawful basis such as performance of a contract, compliance with legal obligations, legitimate interests, or consent where required. We apply data minimisation, purpose limitation, and security measures appropriate to the nature of the processing.

For users in Italy and other EEA locations, this notice is intended to reflect the GDPR rules that apply to our processing of personal data.
This section applies where GDPR governs our processing activities.

Protected individual rights

GDPR Rights

Where the GDPR applies, individuals may request access, rectification, erasure, restriction, portability, or objection, and may withdraw consent where processing is based on consent. A complaint may also be raised with the competent supervisory authority, subject to applicable rules.

GDPR rights are available subject to the conditions and exceptions set out in law.
Personal data

Data We Collect

We may collect identification and contact details, account information, course enrolment and participation data, payment-related records where applicable, communications sent to us, and technical data such as device, browser, and usage information.

The categories of data collected depend on how users interact with the site and course services.
Data sources

Sources of Data

We receive data directly from users when they create an account, register for a course, complete forms, or contact us. We also collect data automatically through site interactions, cookies, and similar technologies, and may receive limited information from payment, hosting, analytics, or other operational providers.

Information is obtained from users, from their use of the site, and from limited service providers involved in operations.
Cookie types

Types of Cookies

We may use essential cookies to operate the site, preference cookies to remember settings, and analytics cookies to understand how the site is used. Cookies may be session-based or persistent, depending on their purpose. Similar technologies may be used for security, performance, and service improvement.

Cookie use is limited to essential functions, preferences, and basic measurement where enabled.
User controls

Cookie Controls

We use standard cookie controls to manage non-essential cookies. Users may block or delete cookies through browser settings, but some site functions may not work properly if essential cookies are disabled. Where required, consent choices can be updated through the cookie settings provided on the site.

Cookie preferences can be adjusted through browser settings and, where available, site controls.
User Rights

Your Rights

Depending on the circumstances, users may have rights to access their data, correct inaccurate information, request deletion, object to certain processing, or ask for restriction or portability. Some requests may be limited where we must retain information for legal, contractual, or security reasons.

Available rights depend on the legal basis and the nature of the processing involved.
Requests

How to Make a Request

To exercise a privacy right, users should submit a clear request using the contact details in this policy and include enough information to identify the relevant data or account. We may ask for additional details to verify identity and to assess the request. If a request is refused in whole or in part, we will explain the reason where required by law.

Requests are handled after reasonable verification of identity and scope.
Data Retention

Retention of Data

We keep personal data only for as long as needed for the purpose for which it was collected, including course administration, recordkeeping, dispute handling, and legal compliance. When data is no longer required, we delete it, anonymise it, or otherwise restrict it in line with applicable law and internal retention practices.

Retention periods are based on the purpose of collection, legal duties, and operational needs.
Policy Updates

Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our services, data practices, or legal requirements. The revised version will apply from the date it is posted unless a different effective date is stated. Where changes are material, we will take reasonable steps to draw attention to them.

We review this notice when our processing practices or legal obligations change.