Information on the processing of personal data

Empress Reverie

Last updated: 29 August 2026


1. Data Controller

The Data Controller is Giulia Luzzi, a natural person, organiser of the Empress Reverie event, resident in Rome, Italy.

Email: giulia.luzzi2207@outlook.it

All communications concerning the processing of personal data, including requests to exercise the rights referred to in section 17, should be addressed to this email address.


2. Scope of this notice

This notice describes how the personal data of the following people are processed:

  • visitors to the empressreverie.com website;
  • people who submit an application to attend the Empress Reverie event;
  • people who, following approval of their application, purchase a ticket;
  • people who attend the event.

This notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”).

The event takes place on 4 February 2027 at Aman Venice โ€” Palazzo Papadopoli, Calle Tiepolo 1364, Venice.

The website is hosted on the WordPress.com platform. The application and selection process, and the subsequent ticketing, are carried out through the Weezevent platform (section 8).

The use of cookies and third-party tools is described in the Cookie Policy, a separate and complementary document (section 14).

2.1 Minimum age

Attendance at the event is reserved for people who are at least 18 years old. The Controller does not knowingly collect personal data of people under 18 and does not envisage any processing directed at minors.

2.2 Temporal scope

This notice governs new applications and subsequent processing, within its respective scope.

For applications already collected before this notice was published, the notice applicable at the time of collection remains the reference. Data collected in that phase are not automatically used for purposes beyond those for which they were collected. No promotional communication is addressed to applicants who were not approved.


3. Categories of data processed

3.1 Core data

  • first name
  • last name
  • email address
  • telephone number

The telephone number may be used to manage the application and the event.

3.2 Data collected through the application form

The application form, hosted on the Weezevent platform, also collects:

  • the first name and last name of the person who would attend the event, where different from the person completing the form;
  • the answers to the questions configured in the form.

The answers are collected as part of the application and selection process and may be taken into account when assessing the application.

Applicants are asked not to include unnecessary information in free-text answers, in particular information of a particularly sensitive nature which is not requested.

3.3 Data relating to the ticket purchase

For approved applicants who proceed to purchase, the data necessary to manage the purchase and attendance are processed: first name, last name, email address, telephone number and any data required for invoicing (section 5). Depending on the payment channel that will be made available, the data required to confirm that payment has been made may be processed.

3.4 Information on allergies, intolerances and dietary requirements

Attendees may voluntarily communicate information on allergies, intolerances or dietary requirements, where necessary to organise the dinner correctly (section 12.2). No general collection of health-related information takes place. Where such information reveals health data, the processing is subject to the existence of the condition provided for by applicable law.

3.5 Data processed at the event

The data necessary to manage entry and to organise the evening are processed (section 12), together with photographs and video recordings (section 11).

Entry to the event requires a check that the name on the admission title matches the identity document presented at the door. The document is shown and checked on the spot: no copy is retained.

3.6 Technical and browsing data

While browsing the website and the ticketing widget, technical data are processed as described in section 14 and in the Cookie Policy.

3.7 Direct communication data

Where a data subject writes to the Controller, the data contained in the communication are processed in order to reply to the request. Requests may also be received through the social media channels used by the organisation.


4. Application and selection process

Attendance at Empress Reverie does not take place through the open purchase of a ticket: access to the event is preceded by an application and selection process.

4.1 The application

The application is a request to attend and costs โ‚ฌ0.00.

  • It is not equivalent to purchasing a ticket.
  • It does not guarantee access to the event.
  • It does not constitute an admission title.

4.2 The assessment

Giulia Luzzi personally assesses the applications. The final decision is taken personally by the Controller.

The information collected through the form questions may be used within the application and selection process.

No profiling and no segmentation of applicants is carried out, and no automated decision-making exists.

4.3 The outcome

The outcome of the application and assessment procedure is communicated by email to the address indicated by the applicant.

  • If approved: notification of the positive outcome and instructions with the link to proceed with the ticket purchase.
  • If not approved: notification of the negative outcome.

4.4 The full path

Free application โ†’ personal assessment โ†’ approval or non-approval โ†’ notification of the outcome โ†’ if approved, possible ticket purchase โ†’ attendance at the event.

4.5 Events on the ticketing platform

Event Function
E2013965 application and assessment phase
E2113445 official event

5. Ticket purchase following approval

The ticket may be purchased only after the application has been approved.

Any purchase of the ticket will be made in accordance with the arrangements and on the economic terms communicated by the Controller at the time the purchase is made available.

The Controller does not receive and does not retain full payment card details or other complete financial data of the purchaser. The Controller processes the data resulting from the payment transaction limited to what is necessary to confirm that payment has been made and to comply with administrative, accounting and tax obligations.

The admission title is personal: the purchaser’s data are also processed for the name check at the door (point 3.5).

5.1 Invoicing

An invoice is issued on request. Invoicing data are used exclusively for:

  • issuing the invoice;
  • administrative management;
  • tax obligations relating to the purchase.

6. Purposes of processing

a) Managing the application and selection process โ€” receiving the application, personal assessment, notification of the outcome.

b) Managing the ticket purchase.

c) Invoicing and administrative and tax obligations.

d) Managing entry and organising the event โ€” list of attendees, name check at the door, access to the venue, table seating, organisation of the dinner.

e) Managing dietary requirements communicated voluntarily.

f) Service communications (section 9).

g) Future communications addressed exclusively to purchasers (section 10).

h) Photographs and video recordings โ€” documentation, communication and promotion of Empress Reverie (section 11).

i) Managing contact requests and requests to exercise data subject rights.

l) Operation and security of the website and of the ticketing platform.

m) Establishing, exercising or defending a legal claim, and complying with requests from authorities in the cases provided for by law.

Data collected through applications are not used for marketing purposes. The application and selection process is not intended to build a contact base for promotional purposes.


7. Legal bases

The preceding sections describe the processing activities in factual terms. The legal characterisation of each activity is kept separate: it is stated only where sufficiently certain, and expressly left open in all other cases.

Purpose Legal basis
a) Application and selection process Performance of pre-contractual measures taken at the data subject’s request, limited to the data necessary to manage the application and its assessment (Art. 6(1)(b) GDPR). This legal basis does not extend to further processing that is not necessary to manage the application, such as marketing activities or other uses incompatible with the purpose of the application.
b) Ticket purchase and attendance Performance of the contract, limited to the data strictly necessary to manage the purchase and attendance (Art. 6(1)(b) GDPR). This basis does not extend to other processing described in this notice
c) Invoicing, accounting and tax obligations Compliance with applicable legal obligations in administrative, accounting and tax matters (Art. 6(1)(c) GDPR)
d) Entry and organisation of the event Performance of the contract, limited to the data strictly necessary to allow access to the event and to organise the evening for the attending person (Art. 6(1)(b) GDPR). Any information on allergies or intolerances remains subject to point (e)
e) Dietary requirements communicated voluntarily For dietary indications that do not reveal health data: performance of the contract, limited to what is necessary to organise the dinner (Art. 6(1)(b) GDPR). For information revealing health data, communicated on the data subject’s own initiative and not requested by the Controller: the processing presupposes that one of the conditions laid down in Art. 9(2) GDPR is met. The applicable condition is stated to the data subject at the point where the information is collected
f) Service communications Performance of pre-contractual measures taken at the data subject’s request, for communications concerning the application and its outcome, and performance of the contract, for communications concerning purchase, payment, attendance, entry and organisation of the event (Art. 6(1)(b) GDPR). This basis does not extend to the promotional communications referred to in section 10
g) Future communications to purchasers see section 10
h) Photographs and video recordings For ambient and group images: legitimate interest of the Controller, subject to the documented balancing test (point 11.2). For individual promotional portraits: a separate procedure with specific consent where required (point 11.6). The final characterisation remains subject to verification
i) Contact requests and exercise of rights For requests to exercise data subject rights: compliance with a legal obligation to which the Controller is subject (Art. 6(1)(c) GDPR, in relation to Arts. 12 and 15โ€“22 GDPR). For other contact requests: the Controller’s legitimate interest in receiving and replying to communications addressed to it (Art. 6(1)(f) GDPR). Where the request concerns the application or the purchase, the bases stated under (a) and (b) apply
l) Operation and security The Controller’s legitimate interest in ensuring the operation, stability and security of the website and of the tools used, and in preventing abuse (Art. 6(1)(f) GDPR). For tools involving the storage of information on the user’s device, or access to information already stored there, Art. 122 of Legislative Decree 196/2003 also applies, as set out in the Cookie Policy
m) Defence of a legal claim and requests from authorities For establishing, exercising or defending a legal claim: the Controller’s legitimate interest (Art. 6(1)(f) GDPR) and, for any data referred to in Art. 9 GDPR, the condition laid down in Art. 9(2)(f) GDPR. For responding to requests from authorities in the cases provided for by law: compliance with a legal obligation to which the Controller is subject (Art. 6(1)(c) GDPR)

The legal bases stated under (a), (b), (c), (d) and (f) apply exclusively to the processing to which they refer and do not extend to promotional communications, photographs and recordings, any health-related data, cookies or other further processing, the characterisation of which is stated separately.

The service communications referred to under (f) remain in all cases distinct from the promotional communications referred to in section 10.


8. Use of the Weezevent platform

The organisation uses the Weezevent platform to manage the application and selection process and the subsequent ticketing. Data entered by the user are processed through that platform in accordance with its technical arrangements and its own notices.

The application form is integrated into the website by means of a widget and is also accessible through pages hosted on the platform’s domains.

8.1 Processing carried out on behalf of the organiser

Weezevent processes data on behalf of the organiser limited to the services and activities for which that relationship is established by the applicable official documentation.

This statement does not extend automatically to all processing carried out by the platform.

8.2 Processing carried out by the platform for its own purposes

For any processing the platform carries out for its own purposes, reference is made to Weezevent’s official privacy notice, which describes its arrangements, purposes and legal bases.

Weezevent’s official privacy notice: https://weezevent.com/en-gb/privacy-policy/

The division between the processing the platform carries out on behalf of the organiser and that which it carries out for its own purposes follows from the applicable contractual documentation and from the platform’s own notice, to which reference is made. The Controller does not extend point 8.1 to all processing carried out by the platform and does not assert here any division beyond that which follows from that documentation.


9. Service communications

The main communication channel is email.

The necessary communications may be sent regarding: the application; the outcome; approval; purchase; payment; attendance; entry; organisation of the event.

These are service communications, distinct from the future communications referred to in section 10 and not promotional in nature. They are necessary to act on the data subject’s request and to manage the event. The relevant legal basis is stated in section 7(f).

Certain automated communications may be sent by the ticketing platform as part of the application and ticketing service.


10. Future communications to purchasers

Future communications are reserved exclusively for those who have purchased a ticket and concern Empress Reverie, its events and initiatives directly connected to Empress Reverie.

They may be sent by email or through other contact channels the Controller may use.

People whose application was not approved, or who did not complete the purchase, do not receive these communications.

It is possible at any time to ask not to receive them by writing to giulia.luzzi2207@outlook.it.

Promotional communications by email will be sent exclusively where an appropriate lawful ground provided for by applicable law exists. Purchasing a ticket does not in itself constitute consent to promotional communications.

The communications referred to in this section are sent only where a lawful ground exists under the applicable rules on electronic communications, and after the data subject has been informed at the time the address is collected. Each communication states how to stop receiving them; it is in any case possible to ask at any time by writing to giulia.luzzi2207@outlook.it.


11. Photographs and recordings

Photographs and video recordings are planned during the event. A professional photographer is engaged to document the event.

The photographer may not use the images independently for their own purposes, including their own social media channels and portfolio, without separate authorisation.

11.1 Prior notice

Guests are informed before the event of the presence of photography and filming, through this notice and through the service communications preceding the event.

11.2 Ambient and group images

Ambient and group images may be taken for:

  • documentation of the event;
  • the historical archive;
  • communication of Empress Reverie;
  • promotion of Empress Reverie.

The legal ground envisaged for this processing is the legitimate interest of the Controller, subject to the internal documentation of the relevant balancing test (internal document LIA โ€” Photographs and recordings, Empress Reverie), retained by the Controller and available to the data subject on request.

The documentation of the balancing test is the outcome of the assessment carried out by the Controller and does not in itself constitute a definitive certification of the lawfulness of the processing, which remains subject to the verification referred to in point 11.7.

11.3 Minimisation

In taking and selecting the material, ambient and group images are favoured over individual close-ups that are not necessary for the stated purposes.

11.4 Names

Guests’ first and last names are not associated with published images, save where separately authorised.

11.5 Objection

Guests may object to being photographed or filmed:

  • by writing to giulia.luzzi2207@outlook.it;
  • or by informing the organisation at the entrance to the event.

Ambient and group images are not used to deliberately focus on a person who has objected.

11.6 Individual portraits and individualised promotional material

For individual portraits clearly referring to a person and used specifically as individualised promotional material, a separate and more cautious procedure is envisaged, with the collection of specific consent where required by the final legal characterisation.

11.7 Publication channels and retention

Images and videos may be published through:

  • the official Empress Reverie website;
  • the official Empress Reverie social media channels;
  • the social media channels of those who promote or communicate the event.

Those who promote the event may use the material exclusively to communicate and promote Empress Reverie.

Images may be retained for an indefinite period as a historical archive and as communication material for Empress Reverie.

Objections raised before or during the event are communicated to those taking the photographs and recordings. Before publication the material is selected by the Controller, who excludes images in which a person who has objected is identifiable and favours wide shots. Only the material so selected is provided to those who promote or communicate the event. Requests for the removal of an image already published are sent to giulia.luzzi2207@outlook.it.

For ambient and group images the ground indicated is the legitimate interest of the Controller (Art. 6(1)(f) GDPR), documented in the internal balancing test referred to in point 11.2, retained by the Controller and available to the data subject on request; the right to object under Art. 21 GDPR is unaffected. For individual portraits used as individualised promotional material, the separate procedure referred to in point 11.6 applies, which includes the collection of specific consent. The rules on the right to one’s image under Arts. 96 and 97 of Law 633/1941 and Art. 10 of the Italian Civil Code remain applicable in any event. The relationship with the appointed photographer is governed by the engagement conferred by the Controller, which excludes any independent use of the images.

11.8 Ticket purchase and the rules on images

Purchasing a ticket entails acceptance of the rules on photographs and recordings described in this section.

This is an organisational provision: it does not constitute consent within the meaning of the GDPR and does not replace the legal ground stated in point 11.2 nor the specific consent that may be required under point 11.6.

11.9 Recordings made by guests

The Terms and Conditions place limits on the use of professional photographic equipment by guests. This is an organisational rule of the event and not a processing activity carried out by the Controller: images taken by guests for personal purposes fall outside this notice.


12. Disclosure of data to the venue and suppliers

12.1 Access to the event

To manage entry, only the necessary names are disclosed, namely first name and last name.

These names may be disclosed to:

  • Aman Venice โ€” Palazzo Papadopoli and the venue staff;
  • staff appointed by the Controller to manage entry.

For this specific purpose the following are not disclosed: the answers to the application questions, the telephone number and any other data that is not necessary.

To organise the evening, the necessary data relating to table seating and to the organisation of the dinner may also be disclosed.

12.2 Dietary requirements

Information on allergies, intolerances or dietary requirements may be communicated voluntarily by the attendee, by email to the Controller or through the Weezevent form or channel where provided.

Where necessary to organise the dinner, such information may be disclosed to Aman Venice and the venue staff, to the catering and food service providers and to other suppliers directly involved in organising the evening.

Each party receives only the information necessary for its own service, in accordance with the minimisation principle. The legal basis and the condition applicable to this information are stated in section 7(e).

12.3 Competent authorities

Data may be disclosed to the competent authorities, where required by law.

12.4 Principle applied to suppliers

Each supplier receives only the data necessary for the specific service entrusted to it and does not automatically receive the full list of attendees. The data are used exclusively for that service and for organising the event.

The Controller discloses to each party only the data necessary for the service entrusted to it. The characterisation of the relationship with Aman Venice โ€” Palazzo Papadopoli and with each supplier follows from the agreements in place with each of them and is not asserted here in general terms. No party is authorised to use the data for its own purposes.

Data are not transferred or sold to third parties for those third parties’ own commercial purposes.


13. Retention and erasure

13.1 Applications

Applications are retained until the event has concluded. Once the event has concluded, the following are erased:

  • the application data;
  • the answers to the application questions;
  • the email correspondence relating to the application;

save for any data that must be retained to comply with legal obligations.

13.2 Early erasure

Erasure may be requested even before the event has concluded, by writing to giulia.luzzi2207@outlook.it. The request is handled subject to any legal obligations.

13.3 Purchasers

The answers to the application questions are not retained after the event has concluded, even where the applicant was approved and purchased a ticket.

The data necessary to manage the purchase are retained in accordance with applicable obligations. Tax and invoicing data are retained for the period provided for by applicable law.

The data contained in tax documents and in the related records are retained for the period provided for by the applicable civil, accounting and tax rules, and are erased or rendered no longer attributable to the data subject once that period has elapsed. The applicable period follows from the obligations to which the Controller is subject in relation to the transaction and is not determined by the Controller.

13.4 Photographs and recordings

See point 11.2: retention for an indefinite period as a historical archive and communication material.

13.5 Defence of a legal claim

Data necessary to establish, exercise or defend a legal claim are retained for as long as necessary for that purpose.


14. Cookies and third-party services

The detailed management of cookies and third-party tools is dealt with in the Cookie Policy, to which reference is made for the full list, categories, purposes and durations.

The website is equipped with a consent management platform, currently operational. On first access a banner is presented allowing the user to accept, refuse or manage preferences by category. The categories provided for by the current configuration are: functional, preferences, statistics, marketing.

Consent may be withdrawn at any time through the consent management link available on the website.

Limited to what has been technically verified in the current configuration:

  • Weezevent widget. The widget used for applications and ticketing is declared to the consent management platform as a third-party content item belonging to the marketing category, and is blocked before consent: a placeholder is displayed in place of the content. The widget is loaded only after the user has consented to the corresponding category.
  • Cookies and tools loaded by the widget after consent. Once consent has been given and the widget loaded, the widget’s infrastructure may set cookies on the weezevent.com domain. Among those observed: _ga, _ga_K89VXH3JTP, _ga_NY2EEVVEMR, with an observed duration of 400 days. These cookies are not set by the Controller. The list given is what was observed and does not constitute an exhaustive inventory.
  • Site images. The images are served through the i0.wp.com domain, the content delivery network of the WordPress.com environment. This call occurs on every page and is not subject to consent.
  • Emoji images. The language menu contains two emoji characters, replaced by two SVG images called from the s.w.org domain. This call occurs on every page and is not subject to consent.
  • Performance telemetry. On every page the script bilmur.min.js of the WordPress.com environment is loaded from the s0.wp.com domain; it collects technical performance metrics of the page and transmits them to the pixel.wp.com address declared in its own code. Inspection of the code shows that the script neither reads nor sets cookies, does not use browser storage and does not generate identifiers. The call occurs before consent. The behaviour of the server receiving the transmission cannot be determined from the client-side code alone.
  • Typefaces. Public pages of the site use typefaces served from the site’s own domain. The typefaces used are hosted on empressreverie.com and are not requested from third-party domains.
  • WordPress.com / Automattic. The hosting platform forms part of the website’s technical environment and may use its own statistical measurement tools.

This document does not certify that all observed cookies are attributable to the Controller: the ownership and characterisation of each tool are dealt with in the Cookie Policy and remain in part to be determined.

The complete list of the tools used or called by the website, the ownership of each, their purposes and their durations are set out in the Cookie Policy, which is the reference document on this matter and is updated following any technical change to the website or to the tools used.


15. International transfers

15.1 Processing carried out through the Weezevent platform

For any transfers of data connected with the processing carried out through the platform, and for the related safeguards, reference is made to Weezevent’s official documentation and privacy notice (section 8.2).

Any such transfers are not carried out by the Controller and are not automatically attributable to the Controller.

15.2 Processing carried out by the Controller

Some of the tools used for the operation of the website and for communications โ€” in particular the hosting platform on which the site is hosted and the email service used by the Controller โ€” are provided by parties that may process data outside the European Economic Area as well. For the location of the processing and for the safeguards applied, reference is made to the documentation made available by each provider.

No transfer is asserted here in the absence of documentation.


16. Security of data

Processing is carried out using IT and electronic tools, with technical and organisational measures appropriate to protect personal data against unauthorised access, loss, disclosure or unlawful processing.

No profiling and no automated decision-making are carried out.

In the event of a personal data breach, the Controller takes the measures provided for by applicable law, including, where the relevant conditions are met, notification to the supervisory authority and communication to the data subjects.


17. Rights of data subjects

Data subjects may exercise, where applicable, the rights provided for by Articles 15โ€“22 GDPR, and in particular:

  • access to their personal data (Art. 15);
  • rectification of inaccurate or incomplete data (Art. 16);
  • erasure of data (Art. 17);
  • restriction of processing (Art. 18);
  • portability of data, where applicable (Art. 20);
  • objection to processing (Art. 21);
  • withdrawal of consent, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.

No profiling is carried out and no automated decision-making exists: the decision on applications is taken personally by Giulia Luzzi.

Requests should be sent to giulia.luzzi2207@outlook.it.


18. Complaint to the supervisory authority

Data subjects have the right to lodge a complaint with the competent supervisory authority. In Italy the supervisory authority is the Garante per la protezione dei dati personali (www.garanteprivacy.it), or to bring the matter before the courts.


19. Contacts and updates

Giulia Luzzi
Email: giulia.luzzi2207@outlook.it

The Controller reserves the right to update this notice. The applicable version is the one published on this page, with the date of last update indicated.