Privacy Policy
Last updated: 20 June 2026
1. Who we are
This Privacy Policy explains how Centro Ricerche Tai Chi A.S.D. processes the personal data of website users, people requesting information, members, prospective members and minors for whom an application for membership is submitted.
Data Controller:
Centro Ricerche Tai Chi A.S.D.
Via Trenno, 41 - 20151 Milan, Italy
Tax Code: 90032940273
Email:
For any privacy-related request or to exercise your rights, you may contact us at the email address indicated above.
2. Personal data we process
- Browsing data
When users browse the website, technical data necessary for the operation of the pages may be processed, such as IP address, date and time of access, browser type, operating system, pages visited and similar technical information. - Data provided by email, forms or contact requests
If a user contacts the Association or fills in an online form, we may process the data voluntarily provided, such as name, surname, email address, telephone number, message content and any other information included in the request. - Data for membership applications
For membership applications, we may process identification and contact data, including name, surname, place and date of birth, residence, address, tax code, telephone number, email address, teacher or instructor of reference, information relating to the chosen course, membership fee and payments made. - Data relating to minors
In the case of an application for membership concerning a minor, we also process the data of the parent or person exercising parental responsibility, as well as the minor’s data necessary to manage the application, membership, Association activities, administrative obligations and insurance-related requirements. - Health-related data
Where necessary for participation in sports or physical activities, health-related data may be processed, such as medical certificates or fitness certificates, within the limits required by applicable law and by the need to ensure the safety of participants. - Images, photos and videos
During courses, events, seminars or Association activities, photographs or video recordings may be taken. The publication of recognisable images on the website, social networks, information or promotional materials takes place only where an appropriate legal basis exists and, where necessary, after obtaining specific consent. For minors, special care is taken and, where necessary, the consent of the parent or person exercising parental responsibility is requested.
3. Purposes and legal bases of processing
- Website operation and security
We process technical browsing data to ensure the proper functioning of the website, maintain IT security, prevent misuse and solve any technical issues. The legal basis is the legitimate interest of the Controller in managing the website securely. - Replying to requests
We process data provided by email or through forms in order to respond to requests for information, contact, membership or participation in activities. The legal basis is the performance of pre-contractual measures or the legitimate interest in responding to communications received. - Management of membership applications and membership relationship
We process the data of prospective members and members to assess membership applications, manage registration, update the members’ register, organise courses and activities, communicate with members, manage fees and contributions, comply with the Association’s statute and manage relations with teachers, instructors and Association bodies. The legal basis is the performance of the membership relationship or the implementation of measures requested by the data subject before joining the Association. - Tax, accounting, legal and insurance obligations
Certain data are processed to comply with legal obligations, tax and accounting duties, obligations connected with Association management and insurance requirements. The legal basis is compliance with legal obligations to which the Controller is subject. - Association and organisational communications
We may send communications relating to Association life, courses, activities, events, deadlines, payments and useful information for members and prospective members. The legal basis is the performance of the membership relationship or the legitimate interest of the Controller in keeping members and participants informed about activities connected with the Association. - Images and photo/video materials
Images may be processed to document Association activities, describe courses and events, promote the activities of Centro Ricerche Tai Chi and preserve a record of initiatives. The legal basis may be the consent of the data subject or, where permitted, the legitimate interest of the Controller, assessed in light of the rights and freedoms of the persons involved.
4. Online forms and external registration pages
If registration or requests for information are submitted through an online form or an external page linked to the website, the data entered in the form are processed to receive and manage the request.
Technical providers hosting or managing the form, the website, email services or other IT tools may process personal data on behalf of the Controller, within the limits necessary for the operation of the services. Such parties must be authorised or appointed as data processors where required by applicable law.
Users are advised not to include unnecessary data or particularly sensitive information in the form, unless expressly required for managing membership or activities.
5. Who may receive the data
Data may be processed by persons authorised by the Association, such as board members, administrative staff, teachers, instructors and collaborators, within the limits necessary for their respective activities.
Data may also be disclosed, where necessary, to:
- sports bodies, affiliation organisations, federations, sports promotion bodies or registers required by law;
- insurance companies and parties involved in insurance coverage or claims management;
- banks and payment service providers;
- tax, accounting, legal and administrative consultants;
- hosting, email, technical maintenance, cybersecurity and website management providers;
- public, administrative, tax or judicial authorities, where required by law.
Personal data are not sold to third parties.
6. Social networks, maps and third-party services
The website may contain links to external pages or services, such as social networks, photo albums, maps, video platforms or other third-party websites. When users click on such links or interact with these services, data may also be processed by the relevant providers, according to their own privacy policies.
The Association does not directly control the processing carried out by such external platforms. Users are invited to consult the relevant privacy policies.
7. Transfers of data outside the European Economic Area
Some technical providers, online services or social platforms may process data outside the European Economic Area. In such cases, transfers take place only where a legal basis provided by the GDPR exists, such as European Commission adequacy decisions, standard contractual clauses or other safeguards provided by applicable law.
8. Data retention
We retain data only for the time necessary for the purposes for which they were collected and, where required, for the period provided by legal obligations or by the need to protect the Controller’s rights.
- Browsing data: for the time necessary for website operation and security, unless further retention is necessary in the event of anomalies, misuse or security incidents.
- Email or form requests: for the time necessary to respond to and manage the request; normally no longer than 24 months from the last contact, unless further documented needs exist.
- Data of members and prospective members: for the entire duration of the membership relationship and thereafter for the period necessary to comply with legal, tax, accounting, insurance obligations or to protect rights.
- Accounting and payment data: for the period required by applicable tax and civil law.
- Health-related data: only for the time necessary to verify the requirements for participation in activities and for any legal or insurance obligations.
- Data processed on the basis of consent: until consent is withdrawn or for the different period indicated at the time of collection.
- Images published online: for a period consistent with the purpose of documenting or promoting Association activities, unless removal is requested where possible and compatible with the technical characteristics of the channels used.
9. How we protect data
The Controller adopts appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, alteration or unlawful disclosure. Access to data is limited to persons who need it to carry out Association, administrative, technical or legal activities.
10. Minors
Particular attention is paid to the protection of minors’ personal data. Applications for membership concerning minors must be submitted by a parent or by the person exercising parental responsibility.
Any consent for processing that is not necessary for managing membership or Association activities, such as the publication of images or promotional communications, must be collected in a specific and understandable manner, taking into account the minor’s age and the role of the parent or guardian.
11. Cookies and similar technologies
The website may use technical cookies necessary for the operation of the pages and the security of browsing. Any analytical, profiling, marketing cookies or non-essential third-party tools will be used only in accordance with applicable law and, where required, after obtaining the user’s consent.
For detailed information about the cookies actually used by the website, their purposes and how to manage preferences, users should consult the dedicated Cookie Policy, which should be updated following a technical audit of the website.
12. Rights of data subjects
Data subjects may exercise, in the cases provided by the GDPR, the following rights:
- access to personal data;
- rectification of inaccurate data or completion of incomplete data;
- erasure of data;
- restriction of processing;
- objection to processing;
- data portability, where applicable;
- withdrawal of consent, without affecting the lawfulness of processing carried out before withdrawal.
To exercise these rights, users may write to:
The Controller will respond within the time limits provided by applicable law.
13. Complaint to the supervisory authority
Data subjects who believe that the processing of their personal data violates applicable law may lodge a complaint with the Italian Data Protection Authority, according to the procedures indicated on the Authority’s website: www.garanteprivacy.it.
14. Updates to this Privacy Policy
This Privacy Policy may be updated over time, for example in the event of changes to the website, registration forms, services used, Association activities or applicable law. The updated version will be published on this page.