POLICY PRIVACY

(pursuant to Regulation (EU) 2016/679 – GDPR)

This Privacy Policy is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and describes how personal data of users visiting the website of the law firm ELLECOSTA • MALL (hereinafter also the “Firm” or the “Controller”) are processed.


1. Data Controller

The Data Controller is:
Law Firm ELLECOSTA • MALL
Piazza Gilm 2
39031 Brunico / Bruneck (BZ) – Italy

Email: info@elma-lex.com


2. Types of Data Processed

a) Browsing Data

The IT systems and software procedures used to operate this website acquire certain personal data during their normal operation, the transmission of which is implicit in the use of Internet communication protocols.

Such data may include:

  • IP address

  • browser type

  • operating system

  • date and time of access

  • pages visited

  • technical information relating to the user’s device

These data are processed exclusively for:

  • ensuring the proper technical functioning of the website

  • IT security purposes

  • the production of aggregated and anonymous statistical data


b) Data Voluntarily Provided by the User

The voluntary, explicit and intentional sending of communications to the contact details published on this website entails the acquisition of the personal data provided by the sender, including:

  • first and last name

  • email address

  • telephone number

  • content of the communication

Given the professional activity carried out by the Firm, users may transmit data belonging to special categories pursuant to Article 9 GDPR (e.g., data relating to judicial proceedings or personal circumstances).

Such data will be processed exclusively for the purpose of responding to the request and in compliance with appropriate technical and organisational security measures.


3. Purposes of Processing

Personal data are processed for the following purposes:

  • responding to requests for information or contact

  • providing preliminary legal advice

  • complying with legal obligations

  • ensuring the security and protection of the website

  • preventing fraudulent or unauthorised access


4. Legal Basis for Processing

The processing of personal data is based on:

  • Article 6(1)(b) GDPR – performance of pre-contractual measures requested by the data subject

  • Article 6(1)(c) GDPR – compliance with legal obligations

  • Article 6(1)(f) GDPR – legitimate interest of the Controller (IT security and legal defence)

  • Article 6(1)(a) GDPR – consent, where required


5. Processing Methods and Security Measures

Data processing is carried out using electronic and IT tools in accordance with the principles of lawfulness, fairness and transparency.

The Controller adopts appropriate technical and organisational measures to ensure:

  • protection against unauthorised access

  • prevention of data loss or destruction

  • integrity and confidentiality of personal data


6. Data Retention

Personal data are retained:

  • for the time necessary to manage the user’s request

  • in accordance with legal and professional obligations

  • in any case, no longer than necessary in relation to the purposes for which they were collected

Communications not resulting in a professional mandate may be retained for a maximum period of 12 months, unless legal requirements dictate otherwise.


7. Disclosure of Data

Personal data are not disclosed to the public.

They may be communicated to:

  • collaborators and professionals of the Firm

  • IT service providers and hosting providers

  • technical consultants

  • competent authorities, where required by law

All third parties are bound by confidentiality obligations.


8. Transfers Outside the European Union

The website may integrate third-party services (e.g., Google Maps).

The use of such services may result in the transfer of personal data to countries outside the European Union.

Such transfers are carried out in compliance with the safeguards provided for under Articles 44 et seq. GDPR.


9. Cookies and Tracking Tools

The website uses exclusively:

  • technical cookies

  • functional cookies

  • statistical analysis tools configured in compliance with applicable data protection regulations

No profiling cookies are used for marketing purposes.

Further details are available in the Cookie Policy.


10. Rights of the Data Subject

Pursuant to Articles 15–22 GDPR, data subjects have the right to:

  • obtain confirmation of the existence of their personal data

  • access their personal data

  • request rectification or erasure

  • request restriction of processing

  • object to processing

  • withdraw consent at any time

  • lodge a complaint with the competent Data Protection Authority

Requests may be sent to the Controller at the email address indicated above.


11. Updates

This Privacy Policy may be updated from time to time.

Users are encouraged to review it periodically.