Privacy Policy & Data Protection
Pursuant to EU General Data Protection Regulation (GDPR 2016/679) & Italian Garante Cookie Guidelines
1. Data Controller & Contact Information
The Data Controller is Gabriele Ilardi, practicing as an independent cybersecurity specialist and cloud systems consultant, based in Milan, Italy. In compliance with the GDPR, given the professional nature of the consultancy, no Data Protection Officer (DPO) is legally required. For any inquiries regarding personal data processing, please contact:
TODO(gabriele): insert company PEC and VAT/P.IVA details if registered
2. Categories of Data Processed & Legal Bases
Personal data processed through this website is strictly minimized to what is necessary for initiating B2B advisory engagements:
- Voluntarily submitted contact details: full name, business name, professional email address, and phone number provided via WhatsApp messaging, direct email, or quote inquiry requests.
- Pre-contractual & contractual performance: drafting advisory proposals, cloud security audits, mutual Non-Disclosure Agreements (NDAs), and statutory accounting compliance (Art. 6.1.b and 6.1.c GDPR).
- Technical telemetry & edge security: anonymized IP addresses processed at network edge by Cloudflare for DDOS defense and perimeter reliability (Legitimate Interest, Art. 6.1.f GDPR).
3. Data Retention Periods
Personal information collected from exploratory inquiries or quote requests that do not proceed into formal engagements is securely erased after a maximum of 24 months from the latest interaction. Data associated with formal consulting contracts and statutory invoicing is retained for 10 years in compliance with Italian tax and civil law obligations.
4. Third-Party Data Processors & International Transfers
Personal data is strictly confidential and never sold or traded for marketing purposes. It is processed exclusively by verified technical providers:
5. Cookie Policy & Zero Commercial Profiling
This website operates under strict data minimization standards. It does not deploy third-party advertising cookies or behavioral trackers. Aggregated privacy-first analytics with IP anonymization operate strictly upon affirmative user consent, which can be modified or revoked at any time via the footer preference link.
6. Data Subject Rights (Articles 15-22 GDPR)
Under Articles 15 to 22 of EU Regulation 2016/679, you are entitled to exercise the following rights at any time:
- Right of access (Art. 15) and rectification of inaccurate records (Art. 16);
- Right to erasure ("right to be forgotten", Art. 17);
- Right to restriction of processing (Art. 18) and right to object on legitimate grounds (Art. 21);
- Right to data portability in machine-readable format (Art. 20);
- Right to lodge a complaint with the supervisory authority (in Italy: Garante per la Protezione dei Dati Personali, Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it, or your local EU authority).