Privacy Policy
1. Introduction
This Privacy Policy describes how Nerion Advisory S.r.l. ("Nerion Advisory" or "Controller") processes the personal data of users who interact with the institutional website, contact forms, e-mail and any other channel made available.
This policy is issued under:
- Regulation (EU) 2016/679 ("GDPR") on the protection of natural persons with regard to the processing of personal data;
- Italian Legislative Decree no. 196/2003 ("Italian Privacy Code") as amended by Legislative Decree 101/2018;
- Directive 2002/58/EC ("ePrivacy") and applicable Italian Data Protection Authority ("Garante") guidelines on cookies and online identifiers;
- the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), for users residing in California (USA);
- the Lei Geral de Proteção de Dados (Federal Law no. 13,709/2018, "LGPD") for users residing in Brazil.
2. Data Controller
Nerion Advisory S.r.l.
Viale Umberto Tupini 103 — 00144 Rome (RM), Italy
VAT & Tax ID: 18552181002
REA: RM-1791890
Certified mail (PEC): nerionadvisorysrl@legalmail.it
The Controller may be contacted for any request relating to personal data processing at the addresses above.
3. Categories of personal data processed
The Controller processes the following categories of personal data:
| Category | Data collected | Source |
|---|---|---|
| Contact data | Name, surname, e-mail, phone, organization, role | Contact form, direct e-mail, certified mail |
| Communication content | Subject and body of messages, any attachments transmitted | Contact form, e-mail |
| Navigation data | IP address (aggregated and anonymised where possible), browser type, operating system, pages visited, date and time, session duration | Cookies and server logs |
| Professional data | Information voluntarily provided in connection with a mandate (corporate name, VAT, roles, operational context) | Direct communications and contractual documents |
The Controller does not deliberately collect special categories of personal data (Art. 9 GDPR — health, biometric, political opinions, religious beliefs, etc.) nor data relating to criminal convictions (Art. 10 GDPR), save to the extent strictly required for the execution of a specific mandate and subject to express consent or another suitable legal basis.
4. Purposes and legal bases of processing
| Purpose | Legal basis (GDPR) | Required |
|---|---|---|
| Responding to information and contact requests | Art. 6(1)(b) — pre-contractual measures at the request of the data subject | Required |
| Execution of professional mandates and contracts | Art. 6(1)(b) — performance of a contract | Required |
| Compliance with legal obligations (tax, AML, document retention) | Art. 6(1)(c) — legal obligation | Required |
| Defence of rights in legal proceedings | Art. 6(1)(f) — legitimate interest | No consent required |
| Strictly necessary and functional cookies | Art. 122 D.Lgs. 196/2003 — no consent required | Required |
| Analytics and third-party cookies | Art. 6(1)(a) — data subject's consent | Optional |
5. Processing methods
Data are processed by electronic and, where necessary, paper means, in compliance with the principles of lawfulness, fairness, data minimisation and transparency. The Controller adopts appropriate technical and organisational measures to ensure a level of security proportionate to the risk (Art. 32 GDPR), including access controls, encrypted communications, regular backups, environment segregation and training of authorised personnel.
6. Retention periods
Personal data are retained for the time strictly necessary to achieve the purposes for which they are collected, and in any case according to the following criteria:
- Contact requests without a contractual outcome: 24 months from the last interaction, unless erasure is requested earlier;
- Data related to active mandates: for the duration of the contractual relationship;
- Contractual, tax and accounting data: 10 years from the end of the relationship, under Italian Civil Code Art. 2220 and Presidential Decree 600/1973 Art. 22;
- Navigation data: technical logs up to 12 months, except where necessary to investigate security incidents;
- Consent records: for the duration of processing, plus the time necessary to document acquisition.
7. Communication and sharing of data
Personal data may be communicated to third parties acting on behalf of the Controller as Data Processors (Art. 28 GDPR), including:
- IT, hosting, e-mail and backup service providers;
- legal, tax, accounting advisors and auditors;
- cybersecurity and anti-spam providers;
- professional partners involved in the execution of specific mandates, subject to prior notice.
Data may also be communicated to judicial, administrative and supervisory Authorities when required by law, regulation or order.
The Controller does not sell personal data to third parties and does not transfer them for autonomous marketing purposes.
8. International data transfers (outside the EU)
Where it is necessary to transfer personal data outside the European Economic Area (EEA) — for example, when using IT service providers located in the United States — the Controller adopts one of the safeguards provided by Articles 44 et seq. of the GDPR:
- Adequacy decisions of the European Commission (e.g. EU–US Data Privacy Framework);
- Standard Contractual Clauses (SCC) approved by the European Commission;
- Supplementary safeguards documented on a case-by-case basis (transfer impact assessment);
- Explicit consent of the data subject, where applicable.
9. Rights of the data subject (GDPR)
At any time, the data subject may exercise the rights provided by Articles 15–22 of the GDPR, namely:
- Right of access (Art. 15): obtain confirmation of processing and a copy of the data;
- Right to rectification (Art. 16): obtain correction of inaccurate data or completion of incomplete data;
- Right to erasure (Art. 17, "right to be forgotten"): obtain the deletion of data in the cases provided;
- Right to restriction (Art. 18): obtain restriction of processing;
- Right to portability (Art. 20): receive own data in a structured and commonly used format;
- Right to object (Art. 21): object to processing based on legitimate interest;
- Right to withdraw consent (Art. 7(3)): at any time, without prejudice to the lawfulness of pre-withdrawal processing;
- Right not to be subject to automated decisions (Art. 22), including profiling.
Requests must be sent to the Controller's certified mail or e-mail. A response is provided within 30 days, extendable by a further 60 days in complex cases.
The data subject also has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it) or with the supervisory Authority of their country of residence.
10. Provisions for California residents (CCPA/CPRA)
If the user resides in California (USA), the California Consumer Privacy Act, as amended by the California Privacy Rights Act, grants additional rights, including:
- Right to Know — to know the categories and specific personal information collected, the sources, the purposes, the categories of third parties with whom it is shared;
- Right to Delete — to request deletion of personal information, subject to legal exceptions;
- Right to Correct — to request correction of inaccurate information;
- Right to Opt-Out of Sale or Sharing — to opt out of the sale or sharing of personal information, including for cross-context behavioural advertising;
- Right to Limit Use of Sensitive Personal Information — to limit the use of sensitive personal information to performance of requested services only;
- Right to Non-Discrimination — not to be discriminated against for exercising privacy rights;
- Designation of an Authorized Agent — the ability to appoint an authorised agent to exercise rights on behalf of the consumer.
Nerion Advisory does not sell personal information under the CCPA/CPRA and does not share personal information for cross-context behavioural advertising purposes. Requests may be sent by e-mail to the Controller. Identity verification is mandatory.
Complaints may be addressed to the California Privacy Protection Agency (cppa.ca.gov) or to the California Attorney General's Office (oag.ca.gov/privacy).
11. Provisions for Brazil residents (LGPD)
If the data subject (titular) resides in Brazil, the Lei Geral de Proteção de Dados (Law no. 13,709/2018) grants in particular the following rights (Art. 18 LGPD):
- Confirmation of the existence of processing;
- Access to data;
- Correction of incomplete, inaccurate or outdated data;
- Anonymisation, blocking or deletion of unnecessary, excessive or unlawfully processed data;
- Portability to another service or product provider;
- Deletion of personal data processed with consent;
- Information on public and private entities with which data have been shared;
- Information on the possibility not to provide consent and the consequences of refusal;
- Withdrawal of consent.
The competent supervisory authority is the Autoridade Nacional de Proteção de Dados (ANPD) — www.gov.br/anpd. The Brazil representative, where designated under Art. 23 LGPD, will be indicated in this section.
12. Data security
The Controller adopts technical and organisational measures to prevent unauthorised access, disclosure, alteration or destruction of personal data, in accordance with Art. 32 GDPR. In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, the Controller will notify the supervisory authority within 72 hours of becoming aware of the event, and will inform data subjects where required.
13. Minors
The Controller's services are not addressed to persons under the age of 16, pursuant to Art. 8 GDPR. For US residents, the Controller does not knowingly collect personal information from children under the age of 13 (COPPA — Children's Online Privacy Protection Act).
14. Changes to this policy
This Privacy Policy may be updated at any time. Previous versions are retained. The date of the last update is shown at the top of the document. Substantial updates are communicated through the website.
15. Contact
For any request regarding personal data protection, exercise of rights or clarifications:
- E-mail / Certified mail: nerionadvisorysrl@legalmail.it
- Address: Viale Umberto Tupini 103, 00144 Rome (RM), Italy