Privacy Policy
This notice is provided pursuant to arts. 13 and 14 of Regulation (EU) 2016/679 (GDPR) and of the Italian Legislative Decree 196/2003 as updated by Legislative Decree 101/2018, to users who interact with the www.riccardorocchi.eu website (hereinafter, the “Site”).
1. Data Controller
The Controller of the personal data collected through the Site is:
Riccardo Rocchi, sole proprietor
Via San Francesco d’Assisi 100 — 00035 Olevano Romano (RM)
VAT: IT18343201002
Email: riccardo.rocchi@rayergroup.com
Data Protection Officer (DPO)
The Controller has not appointed a DPO as the processing does not fall within the cases provided for by art. 37(1) GDPR (core activities not consisting of large-scale systematic processing nor large-scale processing of special categories of data).
2. Types of personal data processed
2.1 Browsing data
The IT systems and software procedures responsible for the operation of the Site acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols: IP addresses, domain names, URIs of requested resources, time of the request, method used, size of the file received in response, status code, parameters relating to the user's operating system and IT environment. This data is used solely to ensure the correct operation of the Site and to obtain anonymous statistical information about its use.
2.2 Cookie consent data
When interacting with the cookie banner, the choices expressed (acceptance, refusal, granular preferences) are recorded together with a timestamp and a technical identifier. This allows the Controller to demonstrate that consent was given pursuant to art. 7(1) GDPR.
2.3 Voluntarily provided data
a) Direct communications. Should the user contact the Controller directly via the email address indicated in point 1, the relevant data (name, email address, content of the communication) are processed to follow up on the request.
b) Call request form (“Parliamoci”). By filling in the form on the /parliamoci page, the user provides: first name, last name, email address, role, topic of the request, a short description of their case and, optionally, phone number and name of the company or project. The date and time of submission, the referring page and the choice made on the optional box concerning promotional communications are also recorded, together with the exact wording of the box, as proof of consent. After submission, the user is taken to the Controller’s booking calendar to choose the day and time of the appointment.
Users are asked not to include in the free-text field any data belonging to special categories (for example, health data) or data about third parties.
2.4 Minors' data
The Site is intended exclusively for adult users. The Controller does not knowingly collect personal data of persons under 18. Should it become aware that minors' data has been collected without the consent of a parent or legal guardian, the Controller will delete it immediately.
2.5 Data processed by the anti-spam system
To protect the request form from automated submissions, the Site uses the Cloudflare Turnstile service, which checks that the submission comes from a person rather than an automated program. To do so, the service processes the IP address, some characteristics of the browser and device, and signals of interaction with the page. The Controller only receives the outcome of the check and does not use these data for profiling or advertising purposes.
3. Purposes and legal bases of processing
3.1 Operation of the Site and security
Browsing data is processed to ensure the correct operation of the Site, prevent abuse and protect the infrastructure from cyber threats.
Legal basis: legitimate interest of the Controller (art. 6.1.f GDPR) in the security and correct operation of its systems.
3.2 Cookie consent management
Consent data is processed to fulfil the obligation to demonstrate the user's consent for non-technical cookies.
Legal basis: legal obligation (art. 6.1.c GDPR), in accordance with the Italian DPA Guidelines of 10 June 2021.
3.3 Handling of call requests and direct communications
Data provided through the request form or by email are processed to respond to the user’s request, schedule and prepare the appointment, hold the call and follow up on what was agreed.
Legal basis: performance of pre-contractual measures taken at the data subject’s request (art. 6.1.b GDPR). Providing the data marked as mandatory is necessary to handle the request: without them the call cannot be scheduled.
To prepare the call, the Controller may use a generative artificial intelligence assistant (Claude, provided by Anthropic), to which the data submitted through the form are given in order to organise them and identify the topics to explore. The assistant makes no decisions about the user: the outcome of the request and the content of the call remain decided by the Controller.
3.4 Legal obligations
The Controller may process users' data to comply with legal, regulatory or tax obligations, or in execution of orders from competent public authorities.
Legal basis: legal obligation (art. 6.1.c GDPR).
3.5 No automated decision-making
The Controller declares that it does not carry out, through the data collected on the Site, solely automated decision-making producing legal effects or similarly significantly affecting the data subject, nor profiling activities pursuant to art. 22 GDPR. Should such processing be introduced in the future, the user will be informed by updating this notice.
3.6 Content produced with AI assistance
The texts of this Site are drafted with generative artificial intelligence systems and reviewed by the Controller before publication. No personal data of users are processed to draft the texts of the Site. Data submitted through the call request form, on the other hand, may be processed by an AI assistant to prepare the call, as described in point 3.3. Details on where and how I use artificial intelligence are on the page AI Transparency.
3.7 Sending of proposals, content and promotions (only with consent)
Only if the user has ticked the dedicated optional box in the form may the Controller send them, by email, proposals, content and promotions relating to the Controller’s services and projects.
Legal basis: consent of the data subject (art. 6.1.a GDPR and art. 130 of Italian Legislative Decree 196/2003). Consent is optional and in no way affects the possibility of booking the call. It may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal, as indicated in point 8. Without consent, the user will receive no promotional communications.
3.8 Protection of forms against spam and abuse
The data described in point 2.5 are processed to prevent automated submissions, spam and abuse of the request form.
Legal basis: legitimate interest of the Controller (art. 6.1.f GDPR) in the security of the Site and of its systems.
4. Processing methods
Personal data is processed with automated tools for the time strictly necessary to achieve the purposes for which it was collected. The Controller adopts adequate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with art. 32 GDPR, including: encryption of data in transit (HTTPS protocol), access control to administration systems, regular software updates, minimization of the data processed.
5. External Data Processors
For the operation of the Site, the Controller relies on third parties that process personal data on its behalf as Data Processors pursuant to art. 28 GDPR. The categories currently in use include:
- Webflow, Inc. (USA) — hosting and distribution (CDN) of the Site, with a data processing agreement (DPA) and Standard Contractual Clauses.
- Cloudflare, Inc. (USA) — CDN, DDoS protection, obfuscation of email addresses published on the Site and anti-spam verification of the request form (Turnstile).
- Google LLC (Google Fonts) — delivery of web fonts; it involves transmitting the user's IP address to Google's servers.
- Volentio JSD Limited (United Kingdom) — jsDelivr service: delivery (CDN) of the software libraries the Site uses for cookie consent management and for animations; it involves transmitting the user's IP address.
- Google (Google Workspace — Calendar) — management of appointment booking and of the call invitation.
- Hetzner Online GmbH (Germany) — provision of the server running the automation system that receives the requests submitted through the form.
- Notion Labs, Inc. (USA) — archive of call requests and related consents.
- Anthropic (USA) — artificial intelligence assistant (Claude) used to prepare calls, as described in point 3.3.
The updated list of data processors is available upon written request to the email address indicated in point 1.
6. Transfer of data to third countries
Some Data Processors (namely Webflow, Inc., Cloudflare, Inc., Google LLC, Notion Labs, Inc. and Anthropic) are established in the United States. In such cases, the transfer takes place on the basis of the Standard Contractual Clauses approved by the European Commission pursuant to art. 46 GDPR and, where applicable, of the EU-US Data Privacy Framework (adequacy decision of 10 July 2023 under art. 45 GDPR), with additional technical protection measures. The server of the automation system (Hetzner Online GmbH) is located in the European Union.
Volentio JSD Limited (jsDelivr service) is established in the United Kingdom, a country for which the European Commission has adopted an adequacy decision under art. 45 GDPR.
7. Data retention period
Data is kept for the time strictly necessary to achieve the stated purposes, according to the following criteria:
- Browsing data (server logs): 6 months, unless a longer period is required for documented security needs;
- Cookie consent data: 6 months, after which the banner is shown again to the user;
- Direct email communications: for the time needed to handle the request and for a further 24 months for professional follow-up purposes;
- Call requests submitted through the form: for the time needed to handle the request and for a further 24 months from the last contact for professional follow-up purposes; if the request leads to an engagement, the data are kept for the duration of the relationship and for the periods required by law;
- Data for promotional communications: until consent is withdrawn; failing withdrawal, until 12 months after the last interaction with the communications received;
- Proof of consent (date, time and wording of the ticked box): for the duration of the processing it refers to and for a further 12 months after withdrawal, to demonstrate the lawfulness of the processing carried out;
- Technical logs of the automation system: 7 days, then automatically deleted;
- Data processed by the anti-spam check: not kept by the Controller, which only receives the outcome of the check;
- Data subject to tax obligations (any invoices): 10 years, pursuant to art. 2220 of the Italian Civil Code and Presidential Decree 600/1973.
8. Data subjects' rights
Pursuant to arts. 15-22 GDPR, the data subject has the right to:
- obtain access to their personal data;
- obtain the rectification of inaccurate or incomplete data;
- obtain the erasure of the data (“right to be forgotten”) in the cases provided for by art. 17 GDPR;
- obtain the restriction of processing in the cases provided for by art. 18 GDPR;
- obtain the portability of the data in a structured, commonly used and machine-readable format (art. 20 GDPR);
- object to processing based on legitimate interest (art. 21 GDPR);
- withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise these rights, simply send a written request to riccardo.rocchi@rayergroup.com. The Controller will respond within 30 days of receiving the request, save for a justified extension pursuant to art. 12(3) GDPR.
Consent to promotional communications may be withdrawn at any time via the link at the bottom of each communication or by writing to riccardo.rocchi@rayergroup.com.
9. Personal Data Breach Notification
In the event of a personal data breach that poses a risk to the rights and freedoms of data subjects, the Controller will notify the breach to the Italian Data Protection Authority (Garante) within 72 hours of discovery, pursuant to art. 33 GDPR. Should the breach pose a high risk, the Controller will also communicate the breach to the data subjects without undue delay, pursuant to art. 34 GDPR.
10. Right to lodge a complaint
Without prejudice to any other administrative or judicial remedy, the data subject has the right to lodge a complaint with the Italian supervisory authority — Italian Data Protection Authority (Garante) (www.garanteprivacy.it) — if they believe that the processing of data concerning them infringes the GDPR or applicable national law.
11. Changes to this Privacy Policy
The Controller reserves the right to modify this Privacy Policy at any time, publicizing it on the Site. Users are invited to consult this page periodically, checking the last-updated date shown at the top. Substantial changes will be highlighted appropriately.