PRIVACY POLICY
Pursuant to Articles 13-14 of Regulation (EU) 2016/679 (GDPR)
Last updated: 18 April 2026
This website collects some Personal Data from its Users.
This document can be printed using the print command in the settings of any browser.
1. Data Controller
Microconsult S.r.l. Via R. Corsinovi, 37 – 50019 Sesto Fiorentino (FI) – Italy
Share capital: € 10,400.00 fully paid-in VAT number: IT04903720482 | REA: FI-499293 E-mail: info@microconsult.it PEC (certified email): microconsult@pec.it Tel: +39 055 4493196
For any questions regarding the processing of personal data, Users may contact the Data Controller at the above details.
2. Types of Personal Data collected
The Data Controller collects the following categories of personal data, provided directly by the User or collected automatically during browsing:
-
Identification data: first name and last name
-
Contact data: e-mail address, phone number
-
Browsing data: IP address, browser type, pages visited, access times (usage data)
-
Technical cookies and, subject to consent, analytical or profiling cookies (see Cookie Policy)
Data marked as mandatory in the site's forms are necessary to provide the requested service. Failure to provide them may make it impossible to deliver the service.
3. Purposes of processing and legal bases
3.1 Handling contact requests
Data provided through the contact form are processed to respond to User requests and provide the requested information.
Legal basis: Art. 6(1)(b) GDPR (performance of pre-contractual measures at the request of the data subject); where applicable, Art. 6(1)(a) GDPR (consent).
Retention period: 12 months from receipt of the request, unless a contractual relationship is established or legal obligations require otherwise.
3.2 Performance of contractual obligations
Where a contract is entered into, data will be processed for its execution and for related tax, accounting and administrative obligations.
Legal basis: Art. 6(1)(b) and (c) GDPR (performance of contract and compliance with legal obligations).
Retention period: for the duration of the contract and thereafter for the period required by applicable tax and civil law (generally 10 years).
3.3 Compliance with legal obligations
The Data Controller may process User data to comply with obligations imposed by law, regulations or EU legislation.
Legal basis: Art. 6(1)(c) GDPR.
3.4 Legitimate interest of the Data Controller
Data may be processed for purposes of IT security, fraud prevention, legal defence and protection of the Data Controller's rights.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest of the Data Controller). Users have the right to object to such processing on grounds relating to their particular situation.
3.5 Statistical analysis and site improvement (subject to consent)
Should traffic analysis tools (e.g. Google Analytics or equivalent) be activated, the relevant data will be processed exclusively with the User's prior consent, with an update to this Privacy Policy and the Cookie Policy.
Legal basis: Art. 6(1)(a) GDPR (consent).
4. Methods of processing
Personal data are processed using IT and electronic tools, with the adoption of technical and organisational measures appropriate to the level of risk, pursuant to Art. 32 GDPR, in order to prevent unauthorised access, loss, destruction or disclosure of data.
Data are not subject to automated decision-making processes or profiling pursuant to Art. 22 GDPR.
5. Place of processing
Data are processed at the operational premises of Microconsult S.r.l. and, where necessary, at the premises of Data Processors appointed pursuant to Art. 28 GDPR.
Personal data are not transferred to countries outside the European Economic Area (EEA), except as indicated in Section 7. In the event of any transfer outside the EEA (e.g. use of cloud services with servers in the USA), the Data Controller will adopt the safeguards provided for under the GDPR (e.g. Standard Contractual Clauses adopted by the European Commission or adequacy decisions).
6. Data Processors and authorised persons
Personal data may be disclosed, to the extent strictly necessary, to the following categories of parties, appointed as Data Processors pursuant to Art. 28 GDPR or authorised to process data:
-
Hosting and IT infrastructure service providers
-
E-mail and CRM service providers
-
Professional advisors (legal, tax, accounting)
-
Public authorities and supervisory bodies, where required by law
An up-to-date list of Data Processors is available at the Data Controller's registered office and may be requested by e-mail at the address indicated at the beginning of this document.
Data are not transferred to third parties for marketing purposes without the User's prior consent, nor are they sold to third parties.
7. Third-party services and international transfers
The website may integrate third-party services (e.g. Google Fonts, maps, social plugins) that involve the processing of data by third parties, including with servers located outside the EU. In such cases, the Data Controller ensures that such transfers comply with the safeguards provided for under Arts. 44-49 GDPR.
For a detailed list of currently active third-party services and the relevant safeguards adopted, please refer to the Cookie Policy.
8. Rights of data subjects
Pursuant to Arts. 15-22 GDPR, Users have the right to:
-
Access (Art. 15): obtain confirmation as to whether or not personal data concerning them are being processed and, if so, receive a copy
-
Rectification (Art. 16): obtain the rectification of inaccurate data or the completion of incomplete data
-
Erasure (Art. 17): obtain the erasure of their data ("right to be forgotten"), where the conditions set out in the regulation are met
-
Restriction (Art. 18): obtain restriction of processing in certain cases
-
Portability (Art. 20): receive their data in a structured, machine-readable format, or transfer them to another controller
-
Objection (Art. 21): object to processing based on legitimate interest or public interest, on grounds relating to their particular situation; object at any time to processing for direct marketing purposes
-
Withdrawal of consent (Art. 7): withdraw consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal
-
Complaint (Art. 77): lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali — www.garanteprivacy.it, Piazza Venezia 11 – 00187 Rome, tel. +39 06 696771)
Requests relating to the exercise of the above rights must be sent to the Data Controller by e-mail or post at the contact details indicated in Section 1. The Data Controller will respond within 30 days of receipt; this period may be extended by a further 60 days in cases of particular complexity. Requests are free of charge, unless manifestly unfounded or excessive.
9. Data Protection Officer (DPO)
In light of the size and activities of Microconsult S.r.l., the appointment of a Data Protection Officer (DPO) is not mandatory pursuant to Art. 37 GDPR. Should such an obligation arise in the future, or should the Data Controller decide to proceed voluntarily with the appointment, this Privacy Policy will be updated with the relevant contact details.
10. Cookie Policy
The website uses technical cookies necessary for the functioning of the site. For more information on the use of cookies, the types installed and how to manage consent, please refer to the Cookie Policy available on the website.
11. Modifications to this Privacy Policy
Microconsult S.r.l. reserves the right to modify this Privacy Policy at any time, giving adequate notice of changes on this website. Changes take effect from the date of publication. Where changes affect processing based on consent, the Data Controller will collect Users' consent again where required by law.
Users are advised to consult this page periodically.
10. Cookie Policy
This website uses technical cookies necessary for the proper functioning of the site. For more information on the use of cookies, the types installed, and how to manage or withdraw consent, please refer to the Cookie Policy available on this website.
11. Changes to this Privacy Policy
Microconsult S.r.l. reserves the right to modify this Privacy Policy at any time, giving adequate notice of the changes on this website. Changes take effect from the date of publication. Where changes concern processing based on consent, the Data Controller will collect Users' consent again where required by applicable law. Users are advised to check this page periodically.
Microconsult S.r.l. – Privacy Policy – Last updated: 18 April 2026




