1. Data Controller

The Data Controller is REA S.r.l., with registered office at
 Via Vincenzo De Marinis, 16 – 70021 Acquaviva delle Fonti (BA),
 e-mail: contact@reaspace.com
 (hereinafter, the “Controller” or “REA Space”).

This privacy policy applies to the website: www.reaspace.com
 (hereinafter, the “Website”).

Through the Website, the following categories of personal data are processed:

  1. Data voluntarily provided by the user via the “Contact Us” form
  • Name
  • E-mail address
  • Message content (which may potentially include additional personal data that the user decides to share).

  1. Browsing data (technical logs)
     The IT systems and software procedures used to operate the Website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols (e.g. IP address, date and time of access, requested page, etc.).
     These data are used in aggregate form for security purposes and to ensure the proper functioning of the Website.

The Website does not include user account registration and does not provide newsletter subscription at the moment.

Personal data are processed for the following purposes:

  1. Handling contact requests
  • To respond to requests for information, commercial enquiries, collaboration or support sent through the contact form.
  • Legal basis: performance of pre-contractual measures adopted at the data subject’s request (Art. 6(1)(b) GDPR) and/or the Controller’s legitimate interest in replying to users’ requests (Art. 6(1)(f) GDPR).

  1. Website security and abuse prevention

  • To ensure the security of the Website, prevent fraudulent or unlawful use and ascertain responsibility in case of cyber offences against the Website.
  • Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR).

Personal data are not used for marketing purposes or newsletter sending, unless a different notice is provided and a specific consent is collected in the future.

Personal data are processed for the following purposes:

  1. Handling contact requests
  • To respond to requests for information, commercial enquiries, collaboration or support sent through the contact form.
  • Legal basis: performance of pre-contractual measures adopted at the data subject’s request (Art. 6(1)(b) GDPR) and/or the Controller’s legitimate interest in replying to users’ requests (Art. 6(1)(f) GDPR).

  1. Website security and abuse prevention

  • To ensure the security of the Website, prevent fraudulent or unlawful use and ascertain responsibility in case of cyber offences against the Website.
  • Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR).

Personal data are not used for marketing purposes or newsletter sending, unless a different notice is provided and a specific consent is collected in the future.

  • Providing the data marked as mandatory in the contact form (name, e-mail, message) is necessary in order to submit the request; if such data are not provided, the Controller will not be able to respond.
  • Providing any additional information in the message is optional, but may be helpful for properly handling the request.
  • Data sent via the contact form will be stored for the time strictly necessary to handle the request and, in any case, for no longer than 2 months from the last relevant contact, unless a longer retention period is required for the protection of the Controller’s rights (e.g. in case of disputes).
  • Browsing data are ordinarily kept for technical periods that are limited in time, unless logs are needed for security reasons or legal obligations.
  • Personal data may be accessed by:

    • Authorised personnel of the Controller, duly instructed and bound by confidentiality obligations.
    • Third-party service providers (for example: hosting providers, e-mail service providers, website maintenance companies), acting as Data Processors pursuant to Art. 28 GDPR, where applicable.

    Personal data are not disseminated and are not sold or transferred to third parties for marketing purposes.

As a rule, data are processed within the European Economic Area (EEA).

If the Controller makes use of service providers located in countries outside the EU/EEA, any transfer of personal data to such countries will take place in compliance with Articles 44 et seq. GDPR, by adopting appropriate safeguards (such as adequacy decisions of the European Commission or Standard Contractual Clauses).

Further information on the safeguards in place can be obtained by contacting the Controller at: contact@reaspace.com.

Under Articles 15–22 GDPR, the data subject may exercise the following rights at any time:

  • Right of access: obtain confirmation as to whether or not personal data concerning them are being processed and, if so, access to such data.
  • Right to rectification: request the correction of inaccurate data or the completion of incomplete data.
  • Right to erasure (“right to be forgotten”) in the cases provided for by the GDPR.
  • Right to restriction of processing in the cases provided for by the GDPR.
  • Right to object to processing based on the Controller’s legitimate interest.
  • Right to data portability, where applicable.

To exercise these rights, the data subject may contact the Controller at:
 contact@reaspace.com,
 specifying “Request under GDPR” in the subject line and indicating the right they wish to exercise.

The data subject also has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) or with the competent supervisory authority of the EU Member State of their habitual residence, place of work or place of the alleged infringement.

The Website may use technical cookies that are strictly necessary for its proper functioning and for the provision of the services requested by the user.

If in the future the Website uses profiling cookies or third-party analytics cookies that are not anonymised, the user will be shown an appropriate cookie banner requesting consent, with a link to a dedicated Cookie Policy explaining in detail:

This Privacy Policy may be updated or amended. In case of substantial changes, the Controller will provide appropriate notice on the Website.

Users are invited to periodically review this page in order to stay informed about any updates.

Last update: 4 December 2025