PRIVACY POLICY

(Art. 13 Regulation (EU) 2016/679 – GDPR)

1. Data Controller

The Data Controller is Attorney Davide Bertolini, Corso Giacomo Matteotti 46, 25122 Brescia – Italy.

For any requests or communications please contact: info@bertolinilegal.it

The Data Controller processes users’ personal data in compliance with Regulation (EU) 2016/679 (“GDPR”) and the applicable Italian data protection laws.

2. Types of Data Collected

While browsing the website, the following personal data may be processed.

Browsing Data

The IT systems and software procedures used to operate this website automatically collect certain personal data whose transmission is implicit in the use of Internet communication protocols.

This information may include:

  • IP address
  • browser type
  • operating system
  • date and time of the visit
  • pages visited

Such information is used exclusively to ensure the proper functioning of the website, to obtain aggregated statistical information on website usage, and to ascertain responsibility in the event of potential cybercrime against the website.

For more information about the use of cookies and any tracking technologies used by the website, please refer to the Cookie Policy.

Data Provided Voluntarily by the User

Users may contact the firm through:

  • email
  • telephone
  • contact form available on the website

In such cases the firm may process personal data such as:

  • name and surname
  • email address
  • telephone number
  • any information contained in the message

Providing personal data is optional but necessary in order for the firm to respond to the user’s request.

Data entered in the contact form will be processed exclusively for the purpose of responding to the user’s request and will not be used for marketing or profiling purposes.

Sending communications through the website does not automatically create a professional relationship between the user and the law firm.

Users are invited not to send special categories of personal data pursuant to Article 9 GDPR (such as health data, judicial data, or other sensitive information) through the website, unless strictly necessary in the context of a potential professional relationship.

Any personal data voluntarily provided by users will be processed only to the extent necessary to respond to the request received.

3. Purpose of Processing

Personal data are processed for the following purposes:

  • enabling the proper functioning and navigation of the website
  • responding to user inquiries
  • providing information about the firm’s professional activities
  • complying with legal obligations

4. Legal Basis for Processing

The processing of personal data is based on the following legal grounds:

  • performance of pre-contractual measures requested by the data subject (Art. 6(1)(b) GDPR)
  • compliance with legal obligations (Art. 6(1)(c) GDPR)
  • the legitimate interest of the Data Controller in responding to user requests and ensuring website security (Art. 6(1)(f) GDPR).

5. Methods of Processing

Personal data are processed using electronic tools and, where necessary, paper-based systems, in accordance with the principles of lawfulness, fairness and transparency established by the GDPR.

Appropriate technical and organizational measures are implemented to ensure the security and confidentiality of personal data.

6. Disclosure of Data

Personal data will not be publicly disclosed.

They may be communicated to parties providing services necessary for the operation of the website and the professional activity of the firm, such as:

  • IT and hosting service providers
  • website technical maintenance providers
  • consultants for legal or tax obligations

Where necessary, such parties act as Data Processors pursuant to Article 28 GDPR.

7. Data Transfers

Personal data are processed within the European Economic Area (EEA).

If technical services used by the website involve transfers of data to countries outside the EEA, such transfers will take place in compliance with the safeguards provided for by Articles 44–49 GDPR.

8. Data Retention Period

Personal data are retained only for the time necessary to achieve the purposes for which they were collected.

In particular:

  • data relating to information requests: retained for a maximum period of 24 months from the last communication
  • data relating to any professional relationship: retained for the period required by applicable legal obligations.

9. Data Subject Rights

Data subjects may exercise the rights provided for in Articles 15–22 GDPR, including:

  • right of access to personal data
  • right to rectification
  • right to erasure
  • right to restriction of processing
  • right to data portability
  • right to object to processing.

Data subjects may also lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali)
 https://www.garanteprivacy.it

Requests may be sent to the Data Controller using the contact details provided in this Privacy Policy.

Policy Updates

This Privacy Policy may be updated in order to comply with regulatory or technical changes.

Last updated: 13.3.2026

Avv. Davide Bertolini
Privacy overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.