Privacy Policy

PRIVACY POLICY (ART. 13 GDPR)

We inform you that the website www.michelemonasta.it (“Website”) is managed by Michele Monasta, with operational headquarters at Michele Monasta – Via Vittorio Emanuele II, 44 – 50134 Florence – Italy – VAT IT05836300482.

This Privacy Policy, provided pursuant to Art. 13 of EU Regulation 2016/679 (“GDPR”) and Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 (“Privacy Code”), aims to inform you about the processing of your personal data provided through the “Contact” page form on this Website, as well as data automatically collected during navigation (cookies, IP addresses, etc.).

Your personal information will be collected, stored and used in compliance with applicable privacy regulations.

SCOPE OF APPLICATION

This Privacy Policy concerns the processing of personal data collected through the Website www.studiolegalebellini.eu and in the context of the related legal consultancy services.

The Website may contain links to third-party websites. This Privacy Policy will not apply when accessing a third-party website via a link on this Website. This Privacy Policy does not reflect the policies of third-party websites. The Data Controller is therefore not responsible for the privacy practices and data processing carried out by other websites, which will be governed by the terms and policies found on those sites, which you are encouraged to read carefully.

DATA CONTROLLER

Michele Monasta
Via Vittorio Emanuele II, 44
50134 Florence – Italy
VAT IT05836300482
Email: info@michelemonasta.it

CATEGORIES OF DATA PROCESSED

Your personal data may be collected in the following ways.

DATA VOLUNTARILY PROVIDED BY DATA SUBJECTS

You may provide your personal data (such as first name, last name, email address, phone number and any other information voluntarily entered) by filling in the forms on the Website or by sending communications to info@studiolegalebellini.eu. Such data is necessary to respond to requests and manage the professional relationship.

BROWSING DATA

The IT systems and software procedures used to operate the Website automatically acquire, during normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified individuals, but by its very nature could, through processing and association with data held by third parties, allow users to be identified.

This category includes: IP addresses, domain names of computers used, URI (Uniform Resource Identifier) addresses of requested resources, time of request, method used to submit the request to the server, size of the file received in response, numeric code indicating the server response status (success, error, etc.) and other parameters relating to the user’s operating system and IT environment.

COOKIES

The Website uses cookies to improve navigation. For more information on the use of cookies and consent management, please refer to the Cookie Policy available on the Website.

PURPOSES AND LEGAL BASIS FOR PROCESSING

The personal data collected will be processed for the following purposes:

a) Managing contact requests and providing professional services
– Legal basis: performance of pre-contractual measures taken at the request of the data subject (Art. 6(1)(b) GDPR) and performance of the professional services contract
– Purpose: responding to requests, providing quotes, managing and carrying out the requested professional services

b) Legal obligations
– Legal basis: legal obligation (Art. 6(1)(c) GDPR)
– Purpose: mandatory compliance in tax, accounting, administrative matters and any other obligation required by applicable law

c) Security and prevention of cybercrime
– Legal basis: legitimate interest of the Data Controller (Art. 6(1)(f) GDPR)
– Purpose: establishing liability in the event of cybercrime against the Website

MANDATORY OR OPTIONAL NATURE OF DATA PROVISION

The provision of data is optional; however, refusal to provide the data requested in the contact forms will make it impossible for the Data Controller to fulfil the request or provide professional services.

The provision of data for legal compliance purposes is mandatory. Failure to provide such data will prevent the proper management of the professional relationship.

PROCESSING METHODS

Personal data will be processed using electronic and/or paper-based tools, with logic strictly related to the stated purposes and, in any case, in a manner that ensures the security and confidentiality of the data.

RETENTION PERIOD

Personal data will be retained for the time strictly necessary to pursue the purposes for which it was collected, and in particular:

Contact data and requests: for the time necessary to fulfil the request and, in the event of a professional relationship being established, for the entire duration of the relationship and subsequently for the statutory limitation periods (10 years from the end of the relationship)
Data for tax/accounting obligations: 10 years from the end of the relationship, as required by tax regulations
Browsing data (logs): maximum 12 months, unless required for investigation of criminal offences

DATA RECIPIENTS

Your data may be disclosed to:

– entities, bodies or Authorities to whom disclosure is mandatory under provisions of law or orders of the Authority (e.g. Revenue Agency, Judicial Authority, Cassa Forense)
– individuals, companies or professional firms providing assistance and consultancy to the Data Controller in accounting, administrative, legal, tax and fiscal matters

Such parties act as Data Processors pursuant to Art. 28 GDPR, on the basis of a specific agreement, or as independent data controllers.

A complete and updated list of Data Processors is available upon request to the Data Controller at the addresses indicated in this Policy.

Personal data will not be subject to disclosure.

TRANSFERS OUTSIDE THE EU

Personal data is not transferred to third countries outside the EU or to international organisations.

SECURITY

The Data Controller applies and maintains appropriate technical and organisational security measures to protect personal data from accidental loss, unauthorised access, use or disclosure, in accordance with Arts. 32 et seq. of the GDPR.

Please note, however, that the transmission of information over the Internet may not be completely secure. Therefore, despite the Data Controller’s commitment to protecting your data, any information transmitted to the Website is sent at the data subject’s own risk.

RIGHTS OF THE DATA SUBJECT

At any time, you may exercise the following rights provided for under Arts. 15–22 of the GDPR:

Art. 15 – Right of access: obtain confirmation as to whether personal data concerning you is being processed and access such data, obtaining information on purposes, categories of data, recipients, retention period, and origin of data

Art. 16 – Right to rectification: obtain the rectification of inaccurate data or the completion of incomplete data

Art. 17 – Right to erasure (“right to be forgotten”): obtain the erasure of personal data in the cases provided for under Art. 17 GDPR

Art. 18 – Right to restriction of processing: obtain restriction of processing where one of the circumstances set out in Art. 18 GDPR applies

Art. 20 – Right to data portability: receive personal data provided to the Data Controller in a structured, commonly used and machine-readable format and transmit it to another controller

Art. 21 – Right to object: object at any time to the processing of personal data based on the legitimate interest of the Data Controller (Art. 6(1)(f) GDPR)

Art. 22 – Right not to be subject to automated decision-making: not be subject to decisions based solely on automated processing, including profiling

You also have the right to lodge a complaint with the supervisory authority (Italian Data Protection Authority – Garante per la Protezione dei Dati Personali – www.garanteprivacy.it) if you believe that the processing of personal data is in violation of the GDPR.

HOW TO EXERCISE YOUR RIGHTS

To exercise the rights listed above, you may send a request to the Data Controller at the following addresses:

Email: info@michelemonasta.it
Post: Michele Monasta – Via Vittorio Emanuele II, 44 – 50134 Florence – Italy

The Data Controller will provide a response without undue delay and, in any case, within one month of receiving the request.

UPDATES TO THIS POLICY

This Privacy Policy may be subject to changes. You are therefore advised to periodically check this page for any updates.

Last updated: April 2026