Privacy Policy
Informativa ai sensi degli artt. 13 e 14 del Regolamento (UE) 2016/679 (GDPR) · Ultimo aggiornamento: 7 agosto 2026
1. Titolare del trattamento
Il titolare del trattamento dei dati è Unleaf Advisoring s.r.l.s.,
con sede legale in Via Sebino 11, 00199 Roma (RM), P.IVA 17905611004.
Email: info@unleaf.it ·
PEC: company@pec.unleaf.it
2. Dati personali trattati
a) Dati forniti volontariamente tramite il modulo di contatto
Compilando il modulo di contatto presente sul sito, l'utente fornisce: nome e cognome, indirizzo email, motivo del contatto e testo del messaggio. Il modulo è gestito direttamente dal sito, sull'infrastruttura di hosting del titolare (Aruba S.p.A., server in Italia): i dati inseriti sono recapitati via email al titolare e non sono comunicati a servizi terzi di gestione moduli.
b) Dati forniti tramite email o PEC
L'invio volontario di messaggi agli indirizzi email indicati sul sito comporta l'acquisizione dell'indirizzo del mittente e dei dati contenuti nel messaggio.
c) Dati di navigazione
I sistemi informatici che ospitano il sito (hosting Aruba S.p.A., con server in UE) acquisiscono, nel corso del loro normale funzionamento, alcuni dati tecnici la cui trasmissione è implicita nei protocolli internet: indirizzi IP, orario della richiesta, pagina richiesta, browser e sistema operativo. Si tratta di dati necessari alla fruizione del sito, utilizzati solo in forma aggregata e per accertare eventuali responsabilità in caso di reati informatici.
Il sito non utilizza strumenti di analytics, tracciamento o profilazione, né di prima né di terza parte. Tutte le risorse della pagina — fogli di stile, librerie, caratteri tipografici e immagini — sono servite dal dominio del sito stesso: la navigazione non comporta richieste a server di terze parti e quindi nessuna comunicazione dell'indirizzo IP a soggetti diversi dal fornitore di hosting.
Per l'uso di cookie e memorizzazione locale si rinvia alla Cookie Policy.
3. Finalità e base giuridica del trattamento
| Finalità | Base giuridica |
|---|---|
| Rispondere alle richieste inviate tramite modulo di contatto, email o PEC (informazioni, consulenza, formazione, partnership) | Esecuzione di misure precontrattuali adottate su richiesta dell'interessato (art. 6.1.b GDPR) |
| Iscrizione e invio della newsletter CyberWatch Italy, se richiesta dall'utente | Consenso dell'interessato (art. 6.1.a GDPR), revocabile in ogni momento |
| Adempimento di obblighi di legge (fiscali, contabili, di sicurezza) | Obbligo legale (art. 6.1.c GDPR) |
| Sicurezza del sito e prevenzione di abusi | Legittimo interesse del titolare (art. 6.1.f GDPR) |
Il conferimento dei dati tramite il modulo di contatto è facoltativo, ma il mancato conferimento dei campi obbligatori rende impossibile dare seguito alla richiesta. I dati non sono utilizzati per processi decisionali automatizzati né per profilazione.
4. Modalità del trattamento e conservazione
I dati sono trattati con strumenti informatici, da parte del titolare e di soggetti autorizzati, con misure di sicurezza adeguate a prevenire accessi non autorizzati, perdita o divulgazione. I dati sono conservati:
- Richieste di contatto — 12 mesi dalla chiusura della richiesta; in caso di successivo rapporto professionale, per la durata dello stesso e per i termini di legge conseguenti;
- Newsletter — fino alla revoca del consenso (cancellazione dall'iscrizione);
- Dati di navigazione — per i tempi tecnici previsti dal fornitore di hosting;
- Dati soggetti a obblighi di legge — per i termini previsti dalla normativa applicabile (di regola 10 anni per i documenti contabili).
5. Destinatari dei dati
I dati personali possono essere comunicati a:
- fornitori di servizi tecnici che agiscono per conto del titolare: Aruba S.p.A. (hosting del sito, gestione del modulo di contatto e caselle email, server in Italia), fornitori della piattaforma di invio newsletter;
- professionisti e consulenti del titolare (es. commercialista), limitatamente a quanto necessario;
- autorità competenti, ove richiesto dalla legge.
I dati non sono oggetto di diffusione né di vendita a terzi.
6. Trasferimenti di dati extra-UE
I dati inviati tramite il modulo di contatto, le caselle email e l'hosting del sito sono gestiti da Aruba S.p.A. su server situati in Italia: i dati personali sono quindi conservati all'interno dell'Unione Europea. Qualora un fornitore (ad esempio la futura piattaforma di invio della newsletter) tratti dati al di fuori dell'UE, il trasferimento avverrà sulla base delle garanzie previste dal Capo V del GDPR (Clausole Contrattuali Standard approvate dalla Commissione Europea e, ove applicabile, certificazione EU-U.S. Data Privacy Framework).
7. Link a siti esterni
Il sito può contenere collegamenti a siti di terzi (ad esempio LinkedIn o siti istituzionali). Il titolare non risponde del trattamento dei dati personali effettuato da tali siti, per il quale si rinvia alle rispettive informative privacy.
8. Diritti dell'interessato
Ai sensi degli artt. 15–22 GDPR, l'interessato ha diritto di ottenere dal titolare:
- l'accesso ai propri dati personali e alle informazioni sul trattamento;
- la rettifica dei dati inesatti o l'integrazione di quelli incompleti;
- la cancellazione dei dati («diritto all'oblio»), nei casi previsti;
- la limitazione del trattamento;
- la portabilità dei dati forniti;
- l'opposizione al trattamento fondato sul legittimo interesse;
- la revoca del consenso in qualsiasi momento, senza pregiudicare la liceità del trattamento precedente.
Le richieste possono essere rivolte a privacy@unleaf.it o via PEC a company@pec.unleaf.it. Il titolare risponde entro un mese dal ricevimento della richiesta.
Resta salvo il diritto di proporre reclamo al Garante per la protezione dei dati personali (www.garanteprivacy.it) o all'autorità di controllo dello Stato membro di residenza.
9. Minori
Il sito e i servizi offerti si rivolgono a professionisti e imprese e non sono destinati a minori di 18 anni. Il titolare non raccoglie consapevolmente dati personali di minori.
10. Aggiornamenti di questa informativa
La presente informativa può essere aggiornata in caso di modifiche normative o dei servizi offerti. La data di ultimo aggiornamento è indicata in testa alla pagina.
Privacy Policy
Notice pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) · Last updated: 7 August 2026
1. Data controller
The data controller is Unleaf Advisoring s.r.l.s.,
with registered office at Via Sebino 11, 00199 Rome (Italy), VAT no. IT17905611004.
Email: info@unleaf.it ·
Certified email (PEC): company@pec.unleaf.it
2. Personal data processed
a) Data voluntarily provided through the contact form
By filling in the contact form on this website, users provide: full name, email address, reason for contact and message text. The form is handled directly by the website, on the controller's hosting infrastructure (Aruba S.p.A., servers in Italy): the data entered is delivered to the controller by email and is not disclosed to third-party form services.
b) Data provided by email or certified email (PEC)
Voluntarily sending messages to the email addresses shown on this website entails the acquisition of the sender's address and of the data contained in the message.
c) Browsing data
The IT systems hosting this website (Aruba S.p.A., with servers in the EU) acquire, during their normal operation, certain technical data whose transmission is implicit in internet protocols: IP addresses, time of the request, page requested, browser and operating system. This data is necessary for the operation of the website, is used only in aggregate form, and may be used to ascertain liability in the event of cybercrimes.
This website does not use any analytics, tracking or profiling tools, whether first- or third-party. All page resources — stylesheets, libraries, fonts and images — are served from the website's own domain: browsing triggers no requests to third-party servers, and therefore no IP address is disclosed to anyone other than the hosting provider.
For the use of cookies and local storage, please refer to the Cookie Policy.
3. Purposes and legal basis of processing
| Purpose | Legal basis |
|---|---|
| Responding to requests submitted via the contact form, email or PEC (information, consulting, training, partnerships) | Pre-contractual measures taken at the data subject's request (Art. 6(1)(b) GDPR) |
| Subscription to and delivery of the CyberWatch Italy newsletter, where requested by the user | Consent of the data subject (Art. 6(1)(a) GDPR), which may be withdrawn at any time |
| Compliance with legal obligations (tax, accounting, security) | Legal obligation (Art. 6(1)(c) GDPR) |
| Website security and abuse prevention | Legitimate interest of the controller (Art. 6(1)(f) GDPR) |
Providing data through the contact form is optional; however, failure to fill in the mandatory fields makes it impossible to follow up on the request. Data is not used for automated decision-making or profiling.
4. Processing methods and retention
Data is processed using IT tools, by the controller and by authorised persons, with security measures appropriate to prevent unauthorised access, loss or disclosure. Data is retained as follows:
- Contact requests — 12 months from closure of the request; where a professional relationship follows, for its duration and for any subsequent statutory periods;
- Newsletter — until consent is withdrawn (unsubscription);
- Browsing data — for the technical periods set by the hosting provider;
- Data subject to legal obligations — for the periods required by applicable law (as a rule, 10 years for accounting records).
5. Recipients of the data
Personal data may be disclosed to:
- technical service providers acting on behalf of the controller: Aruba S.p.A. (website hosting, contact form handling and email, servers in Italy), newsletter delivery platform providers;
- the controller's professionals and advisors (e.g. accountant), to the extent necessary;
- competent authorities, where required by law.
Data is not disseminated or sold to third parties.
6. Data transfers outside the EU
Data submitted through the contact form, email accounts and website hosting are managed by Aruba S.p.A. on servers located in Italy: personal data is therefore stored within the European Union. Should a provider (for example the future newsletter delivery platform) process data outside the EU, the transfer will rely on the safeguards provided by Chapter V of the GDPR (Standard Contractual Clauses approved by the European Commission and, where applicable, certification under the EU-U.S. Data Privacy Framework).
7. Links to external websites
This website may contain links to third-party websites (for example LinkedIn or institutional websites). The controller is not responsible for the processing of personal data carried out by such websites; please refer to their respective privacy notices.
8. Your rights
Under Articles 15–22 GDPR, data subjects have the right to obtain from the controller:
- access to their personal data and information about the processing;
- rectification of inaccurate data or completion of incomplete data;
- erasure of data ("right to be forgotten"), in the cases provided for;
- restriction of processing;
- portability of the data provided;
- objection to processing based on legitimate interest;
- withdrawal of consent at any time, without affecting the lawfulness of prior processing.
Requests may be sent to privacy@unleaf.it or by certified email to company@pec.unleaf.it. The controller replies within one month of receiving the request.
Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or with the supervisory authority of their Member State of residence.
9. Minors
This website and the services offered are aimed at professionals and businesses and are not intended for persons under 18. The controller does not knowingly collect personal data from minors.
10. Updates to this notice
This notice may be updated in the event of regulatory changes or changes to the services offered. The date of the latest update is shown at the top of this page.