Last updated: September 2026

Privacy Policy & Data Protection

Pursuant to EU General Data Protection Regulation (GDPR 2016/679) & Italian Garante Cookie Guidelines

1. Data Controller & Contact Information

The Data Controller is Gabriele Ilardi, practicing as an independent cybersecurity specialist and cloud systems consultant, based in Milan, Italy. In compliance with the GDPR, given the professional nature of the consultancy, no Data Protection Officer (DPO) is legally required. For any inquiries regarding personal data processing, please contact:

Privacy Contact:[email protected]
Phone / WhatsApp:+39 389 9296600

TODO(gabriele): insert company PEC and VAT/P.IVA details if registered

2. Categories of Data Processed & Legal Bases

Personal data processed through this website is strictly minimized to what is necessary for initiating B2B advisory engagements:

  • Voluntarily submitted contact details: full name, business name, professional email address, and phone number provided via WhatsApp messaging, direct email, or quote inquiry requests.
  • Pre-contractual & contractual performance: drafting advisory proposals, cloud security audits, mutual Non-Disclosure Agreements (NDAs), and statutory accounting compliance (Art. 6.1.b and 6.1.c GDPR).
  • Technical telemetry & edge security: anonymized IP addresses processed at network edge by Cloudflare for DDOS defense and perimeter reliability (Legitimate Interest, Art. 6.1.f GDPR).

3. Data Retention Periods

Personal information collected from exploratory inquiries or quote requests that do not proceed into formal engagements is securely erased after a maximum of 24 months from the latest interaction. Data associated with formal consulting contracts and statutory invoicing is retained for 10 years in compliance with Italian tax and civil law obligations.

4. Third-Party Data Processors & International Transfers

Personal data is strictly confidential and never sold or traded for marketing purposes. It is processed exclusively by verified technical providers:

Cloudflare, Inc.
Edge DNS routing, DDoS mitigation, and global CDN hosting. Governed by the EU-US Data Privacy Framework and Standard Contractual Clauses (SCCs).
Google Workspace (Google Ireland Ltd)
Professional email infrastructure and calendar booking for discovery sessions.
Meta Platforms Ireland Ltd (WhatsApp Business)
End-to-end encrypted direct messaging initiated at the sole discretion of the visitor.

5. Cookie Policy & Zero Commercial Profiling

This website operates under strict data minimization standards. It does not deploy third-party advertising cookies or behavioral trackers. Aggregated privacy-first analytics with IP anonymization operate strictly upon affirmative user consent, which can be modified or revoked at any time via the footer preference link.

6. Data Subject Rights (Articles 15-22 GDPR)

Under Articles 15 to 22 of EU Regulation 2016/679, you are entitled to exercise the following rights at any time:

  • Right of access (Art. 15) and rectification of inaccurate records (Art. 16);
  • Right to erasure ("right to be forgotten", Art. 17);
  • Right to restriction of processing (Art. 18) and right to object on legitimate grounds (Art. 21);
  • Right to data portability in machine-readable format (Art. 20);
  • Right to lodge a complaint with the supervisory authority (in Italy: Garante per la Protezione dei Dati Personali, Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it, or your local EU authority).
© 2026 Gabriele Ilardi · Milano, Italia