Privacy Policy
Last updated: August 2026
Data controller
Artemij Keidan
Sapienza University of Rome — Department "ISO – Italian Institute of Oriental Studies"
Circonvallazione Tiburtina 4, 00185 Roma, Italy
Email: #
Hosting and data processing
This website is hosted on servers located within the European Union. The hosting provider acts as data processor pursuant to Art. 28 GDPR. A Data Processing Agreement (DPA) is in place in accordance with the provider's standard contractual clauses.
Categories of personal data and purposes of processing
The web server automatically records technical log data for each request (IP address, user agent, timestamp, requested resource). These data are processed solely for the purpose of ensuring the security and correct functioning of the website. The legal basis for this processing is the legitimate interest of the data controller (Art. 6(1)(f) GDPR).
Browsing this website sets no cookies. The user's display preferences are retained exclusively in the browser's local storage (localStorage), under a single entry named keidan_ui_state_v1. Because localStorage is never transmitted with HTTP requests, the contents of that entry never reach the server. It holds only the following, and is retained persistently until deleted by the user:
- Appearance settings: the selected visual theme (Ivory, Etching, or Studio), the configuration of the decorative background letters used by Ivory, and the density, intensity, scale, and random seed of Etching's procedural texture;
- Reading position: which section of the page was last open, whether the sections are collapsed, and whether the portrait card is flipped;
- List preferences: for each section, the filters currently applied, the chosen sort order, the text typed into the search field, and whether the filter panel is open.
The entry is written only in response to the user's own actions in the interface, a fraction of a second after the last change, and when the page is closed or hidden. None of this data is used for profiling, analytics, or advertising, it is not linked to any identifier, and it is not transmitted to third parties. Pursuant to Art. 5(3) of Directive 2002/58/EC and the Italian Data Protection Authority's Guidelines on cookies and other tracking tools (10 June 2021, § 17), storage strictly necessary to provide a service explicitly requested by the user is exempt from the requirement of prior consent. Users may delete this data at any time through their browser settings.
Cookies are used only in the site's private administration area (/ADMIN), and only for the site owner: a session cookie and the technical cookies adm and owner_hint, strictly necessary to authenticate the administrator and to keep the session open. They are never set for ordinary visitors and contain no personal data about them.
Should a user choose to contact the data controller by email, the personal data contained in the message (name, email address, content) will be processed solely for the purpose of responding to the enquiry. The legal basis is Art. 6(1)(b) GDPR (steps taken at the request of the data subject) or, where applicable, Art. 6(1)(f) GDPR (legitimate interest in handling correspondence).
Third-party services
This website does not make use of analytics, profiling, or advertising services. All typographic resources (fonts) are hosted locally; no automatic requests to external services are initiated upon page load.
The Blog section displays content retrieved from Tumblr (Automattic Inc., USA) through the site's own server. Tumblr-hosted images are served through a server-side proxy, so retrieving those images does not establish a direct connection between the user's browser and Tumblr. A post may, however, contain images or other resources hosted by third parties: when such content is displayed, the browser may connect automatically to the external host and transmit technical data such as the IP address. Direct connections also occur when the user opens an external link.
Automattic Inc. is a US-based company. Any residual data transfer to the USA would be governed by the applicable adequacy decisions or standard contractual clauses pursuant to Art. 46 GDPR.
Recipients and transfers
Personal data contained in server logs may be accessible to the hosting provider in its capacity as data processor. No other recipients are foreseen. The site's own server acts as an intermediary for Tumblr posts and Tumblr-hosted images; externally hosted resources embedded in those posts remain outside that proxy. A transfer of technical data to third countries may therefore occur when such an external resource is displayed or when the user opens an external link.
Retention
Server log data are retained for a maximum of 90 days, unless a longer period is required for the investigation of security incidents. Local storage data are persistent and remain stored until the user modifies the corresponding preference or deletes them through the browser settings. Email correspondence is retained for as long as necessary to address the enquiry and any follow-up communication.
Personal data breach
In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, the data controller undertakes to notify the Italian Data Protection Authority (Garante per la protezione dei dati personali) within 72 hours of becoming aware of the breach, in accordance with Art. 33 GDPR. Where the breach is likely to result in a high risk to the rights and freedoms of the data subjects, the data controller will also communicate the breach to the affected individuals without undue delay, pursuant to Art. 34 GDPR.
Rights of the data subject
Pursuant to Articles 15–22 of the GDPR, the data subject has the right to access, rectify, erase, restrict, and port their personal data, as well as the right to object to processing. These rights may be exercised by contacting the data controller at the address indicated above.
The data subject also has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), Piazza Venezia 11, 00187 Roma, www.garanteprivacy.it.
Cookie and storage management
Users can manage or delete data stored by this website through their browser settings:
- Chrome: Settings → Privacy and security → Clear browsing data → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data → Clear Data
- Safari: Preferences → Privacy → Manage Website Data
- Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data
Clearing site data will reset the display preferences (theme, floating letters, section and filter states) to their default values.