Privacy Policy di www.gandiniassociati.com

Data Controller

Gandini & Associti S.T.P. S.A.S. di Matteo Gandini
Viale Cirene 7 – 20135 Milano (MI)
P.IVA/C.F. IT08018240963
REA: MI-2790630

Indirizzo email del Titolare: pec@pec.studiogandini.com

Types of Data Collected

Among the Personal Data collected by this Website, either independently or through third parties, are: Usage Data; Trackers; first name; last name; email address; responses to questions; clicks; keypress events; motion sensor events; mouse movements; scroll position; touch events; and Data communicated while using the service.

Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or through specific information notices displayed prior to the collection of such Data.

Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically when using this Website.

Unless otherwise specified, all Data requested by this Website are mandatory. Failure to provide such Data may make it impossible for this Website to provide its Services. Where this Website specifically states that certain Data are optional, Users are free not to communicate such Data without any consequences to the availability or operation of the Service.

Users who are uncertain about which Personal Data are mandatory are encouraged to contact the Data Controller.

Any use of Cookies or other tracking tools by this Website or by the owners of third-party services used by this Website serves the purpose of providing the Service requested by the User, in addition to any other purposes described in this document and in the Cookie Policy.

Users are responsible for any third-party Personal Data obtained, published, or shared through this Website.

Methods and Place of Processing of the Collected Data

Methods of Processing

The Data Controller adopts appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of Personal Data.

Data processing is carried out using IT and/or telematic tools, following organizational procedures and methods strictly related to the purposes indicated.

In addition to the Data Controller, in certain cases the Data may be accessible to other persons involved in the operation of this Website (administrative, commercial, marketing, legal staff, and system administrators) or to external parties (such as third-party technical service providers, postal couriers, hosting providers, IT companies, and communication agencies), who may also be appointed, where necessary, as Data Processors by the Data Controller.

An updated list of Data Processors may be requested from the Data Controller at any time.

Place of Processing

The Data are processed at the Data Controller’s operating offices and in any other location where the parties involved in the processing are located. For further information, please contact the Data Controller.

The User’s Personal Data may be transferred to a country other than the one in which the User is located. To obtain further information regarding the place of processing, Users may refer to the section detailing the processing of Personal Data.

Retention Period

Unless otherwise specified in this document, Personal Data shall be processed and stored for as long as required by the purpose for which they were collected and may be retained for a longer period where required by legal obligations or based on the User’s consent.

Purposes of Processing the Collected Data

User Data are collected to enable the Data Controller to provide the Service, comply with legal obligations, respond to requests or enforcement actions, protect its rights and interests (or those of Users or third parties), detect any malicious or fraudulent activities, as well as for the following purposes: Displaying content from external platforms, Contacting the User, Hosting and backend infrastructure, Spam and bot protection, and Collection of privacy preferences.

For detailed information on the purposes of processing and the Personal Data processed for each purpose, Users may refer to the section entitled “Details on the Processing of Personal Data”.

Details on the Processing of Personal Data

Personal Data are collected for the following purposes and using the following services:

Contact Form

By completing the contact form with their Data, Users consent to the use of such Data for the purpose of responding to requests for information, quotations, or any other inquiries specified in the form header.

Personal Data processed: Full Name, Company Name, Email Address, Phone Number.


Hosting

This type of service is intended to host Data and files that enable this Website to function and be distributed, or to provide a ready-to-use infrastructure for running specific features or parts of this Website.

Some of the services listed below, if applicable, may operate through geographically distributed servers, making it difficult to determine the actual location where Personal Data are stored.

TUCOWS.COM, CO. Tucows Domains Inc.

ArubaCloud is a hosting service provided by Aruba S.p.A.

Personal Data processed: various types of Data as specified in the service’s privacy policy.

Place of processing: Italy – Privacy Policy.

Spam and Bot Protection

This type of service analyzes the traffic of this Website, which may contain Users’ Personal Data, in order to filter unwanted traffic, messages, and content identified as spam, as well as to protect the Website from malicious bot activity.

Google reCAPTCHA (Google Ireland Limited)

Google reCAPTCHA is a spam protection service provided by Google Ireland Limited.

The use of reCAPTCHA is subject to Google’s Privacy Policy and Terms of Service.

For a better understanding of how Google uses data, please refer to Google’s Partner Policies.

Personal Data processed: clicks, Usage Data, keypress events, motion sensor events, touch events, mouse movements, scroll position, responses to questions, and Trackers.

Luogo del trattamento: Irlanda – Privacy Policy.

Displaying Content from External Platforms

This type of service allows content hosted on external platforms to be displayed directly on the pages of this Website and enables Users to interact with such content.

These services are often referred to as widgets, which are small elements embedded within a website or application. They provide specific information or perform particular functions and often allow interaction with Users.

This type of service may still collect web traffic data related to the pages on which the service is installed, even when Users do not actively interact with it.

Google Fonts (Google Ireland Limited)

Google Fonts is a font visualization service provided by Google Ireland Limited that allows this Website to incorporate such content into its pages.

Personal Data processed: Usage Data; Trackers.

Luogo del trattamento: Irlanda – Privacy Policy.

LinkedIn Button and Social Widgets (LinkedIn Corporation)

The LinkedIn button and social widgets are services that enable interaction with the LinkedIn social network, provided by LinkedIn Corporation.

Personal Data processed: Usage Data; Trackers.

Luogo del trattamento: Stati Uniti – Privacy Policy.

Facebook Like Button and Social Widgets (Meta Platforms Ireland Limited)

The Facebook “Like” button and social widgets are services that enable interaction with the Facebook social network, provided by Meta Platforms Ireland Limited.

Personal Data processed: Usage Data; Trackers.

Luogo del trattamento: Irlanda – Privacy Policy.

Additional Information About the Processing of Personal Data

Cookie Policy

This Website uses Trackers. For further information, Users may consult the Cookie Policy.

Additional Information for Users

Legal Basis for Processing

The Data Controller processes Personal Data relating to the User if one of the following conditions applies:

  • The User has given consent for one or more specific purposes;
  • Processing is necessary for the performance of a contract with the User and/or for the implementation of pre-contractual measures;
  • Processing is necessary for compliance with a legal obligation to which the Data Controller is subject;
  • Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
  • Processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party.

In any case, the User may always request that the Data Controller clarify the specific legal basis applicable to each processing activity and, in particular, whether the processing is based on a legal requirement, a contractual obligation, or is necessary to enter into a contract.

Additional Information About Data Retention

Unless otherwise specified in this document, Personal Data shall be processed and stored for as long as required by the purpose for which they were collected and may be retained for a longer period where required by legal obligations or based on the User’s consent.

Accordingly:

  • Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User shall be retained until such contract has been fully performed.
  • Personal Data collected for purposes related to the legitimate interests of the Data Controller shall be retained for as long as necessary to fulfil such interests. Users may obtain further information regarding the legitimate interests pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.

Where processing is based on the User’s consent, the Data Controller may retain Personal Data for a longer period until such consent is withdrawn. Furthermore, the Data Controller may be required to retain Personal Data for a longer period in order to comply with a legal obligation or upon the order of an authority.

Upon expiration of the retention period, Personal Data shall be deleted. Therefore, once the retention period has expired, the rights of access, erasure, rectification, and data portability can no longer be exercised.

User Rights Under the General Data Protection Regulation (GDPR)

Users may exercise certain rights regarding their Personal Data processed by the Data Controller.

In particular, and within the limits provided by law, Users have the right to:

  • Withdraw their consent at any time. Users may withdraw their previously given consent to the processing of their Personal Data.
  • Object to the processing of their Data. Users may object to the processing of their Data when such processing is carried out on a legal basis other than consent.
  • Access their Data. Users have the right to obtain information regarding the Data processed by the Data Controller, certain aspects of the processing, and to receive a copy of the Data being processed.
  • Verify and request rectification. Users may verify the accuracy of their Data and request that it be updated or corrected.
  • Obtain restriction of processing. Users may request that the processing of their Data be restricted. In such cases, the Data Controller will not process the Data for any purpose other than storage.
  • Obtain the erasure of their Personal Data. Users may request the deletion or removal of their Data by the Data Controller.
  • Receive their Data and have it transferred to another controller. Users have the right to receive their Data in a structured, commonly used, and machine-readable format and, where technically feasible, to have it transferred to another data controller without hindrance.
  • Lodge a complaint. Users have the right to lodge a complaint with the competent data protection supervisory authority or seek judicial remedy.

Users are also entitled to obtain information regarding the legal basis for transfers of Data abroad, including to any international organization governed by public international law or established by two or more countries, such as the United Nations, as well as information regarding the security measures adopted by the Data Controller to safeguard their Data.

Details About the Right to Object

Where Personal Data are processed in the public interest, in the exercise of official authority vested in the Data Controller, or for the purposes of the legitimate interests pursued by the Data Controller, Users have the right to object to such processing on grounds relating to their particular situation.

Users are informed that, where their Personal Data are processed for direct marketing purposes, they may object to such processing at any time, free of charge and without providing any justification. If a User objects to processing for direct marketing purposes, the Personal Data will no longer be processed for such purposes. To determine whether the Data Controller processes Personal Data for direct marketing purposes, Users may refer to the relevant sections of this document.

How to Exercise These Rights

Any requests to exercise User rights may be directed to the Data Controller using the contact details provided in this document. Such requests are free of charge, and the Data Controller will respond as soon as possible and, in any event, within one month, providing all information required by law.

Any rectification, erasure, or restriction of processing shall be communicated by the Data Controller to each recipient, if any, to whom the Personal Data have been disclosed, unless this proves impossible or involves a disproportionate effort. The Data Controller shall inform the User of those recipients upon request.

Additional Information About Data Processing

Legal Action

The User’s Personal Data may be used by the Data Controller for legal purposes, including in court proceedings or in the stages leading to possible legal action, for the defence against misuse of this Website or the related Services by the User.

The User acknowledges that the Data Controller may be required to disclose Personal Data upon request by public authorities.

Specific Information Notices

Upon request, and in addition to the information contained in this Privacy Policy, this Website may provide Users with additional and contextual information notices regarding specific Services or the collection and processing of Personal Data.

System Logs and Maintenance

For operational and maintenance purposes, this Website and any third-party services used by it may collect system logs, i.e., files that record interactions and may contain Personal Data, such as the User’s IP address.

Information Not Contained in This Policy

Further information concerning the processing of Personal Data may be requested at any time from the Data Controller using the contact details provided in this document.

Changes to This Privacy Policy

The Data Controller reserves the right to make changes to this Privacy Policy at any time by notifying Users on this page and, where possible, on this Website and/or, where technically and legally feasible, by sending a notification to Users through any contact information available to the Data Controller.

Users are therefore encouraged to check this page regularly, referring to the date of the latest modification indicated at the bottom of the document.

Should the changes affect processing activities whose legal basis is the User’s consent, the Data Controller shall obtain the User’s consent again, where required.

Definitions and Legal References

Personal Data (or Data)

Personal Data means any information that, directly or indirectly, including in connection with any other information, such as a personal identification number, makes a natural person identified or identifiable.

Usage Data

Usage Data are information collected automatically through this Website (including from third-party applications integrated into this Website), which may include: the IP addresses or domain names of the computers used by Users connecting to this Website, URI (Uniform Resource Identifier) addresses, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s response (successful outcome, error, etc.), the country of origin, the characteristics of the browser and operating system used by the visitor, the various time details of each visit (for example, the time spent on each page), and details regarding the User’s navigation path within the Application, with particular reference to the sequence of pages visited and parameters relating to the User’s operating system and IT environment.

User

The individual using this Website who, unless otherwise specified, coincides with the Data Subject.

Data Subject

The natural person to whom the Personal Data relate.

Data Processor (or Processor)

The natural or legal person, public authority, agency, or other body that processes Personal Data on behalf of the Data Controller, as described in this Privacy Policy.

Data Controller (or Controller)

The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of this Website.

Unless otherwise specified, the Data Controller is the owner of this Website.

This Website (or This Application)

The hardware or software tool through which Users’ Personal Data are collected and processed.

Service

The Service provided by this Website as described in the relevant terms and conditions (if available) on this Website/Application.

European Union (or EU)

Unless otherwise specified, any reference made within this document to the European Union shall be deemed to include all current Member States of the European Union and the European Economic Area (EEA).

Cookies

Cookies are Trackers consisting of small pieces of data stored within the User’s browser.

Tracker

Tracker means any technology — such as Cookies, unique identifiers, web beacons, embedded scripts, e-tags, and fingerprinting techniques — that enables the tracking of Users, for example by collecting or storing information on the User’s device.

Legal References

Unless otherwise specified, this Privacy Policy relates solely to this Website.

 

Ultima modifica: 24/04/2026