Privacy Policy
Last updated: July 19, 2026
1. Data Controller
The controller for the processing of personal data is Alessandro Marrarosa, with registered office in Lugano (Canton Ticino, Switzerland). For any request regarding this notice, you can use the form available on the page Contact.
2. Collected Data
The website collects the following categories of personal data:
- Data provided voluntarily via the contact or booking form: first name, last name, e-mail address, company, telephone (if indicated) and message content.
- Browsing data: IP address, browser type, operating system, pages visited, date and time of visit, referrer.
- Technical data collected via cookies and similar technologies (see the Cookie Policy).
3. Purposes of Processing
Personal data are processed for the following purposes:
- respond to requests sent via the contact form;
- manage the booking of meetings and appointments;
- provide the requested consulting services;
- comply with legal, tax and contractual obligations;
- ensure technical security and the correct functioning of the website.
4. Legal Basis
Processing is based on the data subject's consent (Art. 6 Swiss FADP; Art. 6.1.a GDPR), on the performance of pre-contractual or contractual measures (Art. 6.1.b GDPR), on the legitimate interest of the controller to manage and protect the website (Art. 6.1.f GDPR) and on legal obligations (Art. 6.1.c GDPR).
5. Recipients and External Processors
Data may be processed by service providers acting as data processors, including:
- HubSpot Inc. — CRM and contact management (EU servers);
- Supabase / Lovable Cloud — database hosting and server functions;
- Cloudflare — hosting, CDN and protection against attacks;
- Resend — sending transactional notifications via e-mail.
Data are not sold or transferred to third parties for independent marketing purposes.
6. Transfers outside the EU/Switzerland
Some providers may process data outside the European Union or Switzerland. In such cases, the transfer is guaranteed by standard contractual clauses or equivalent mechanisms provided for by the Swiss FADP and the GDPR.
7. Retention Period
Data collected via the contact form are kept for the time necessary to manage the request and, subsequently, for a maximum of 24 months for commercial follow-up purposes. Contractual data are kept for the time required by applicable tax and civil law obligations (up to 10 years).
8. Data Subject Rights
At any time, you can exercise your rights of access, rectification, erasure, restriction, portability and objection to processing, as well as withdraw any consent given. Requests can be sent via the page Contact. It is also possible to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) or the competent supervisory authority in your country of residence.
9. Security
Appropriate technical and organizational measures are adopted to protect data from unauthorized access, loss, destruction or disclosure: encryption in transit (HTTPS/TLS), access controls, backups and access monitoring.
10. Amendments
This notice may be updated at any time. The version in force is always published on this page, indicating the date of the last update.
