Document drafted pursuant to Art. 13 of Regulation (EU) 2016/679 (GDPR)
Last updated: 18 Gennaio 2026
In ossequio al principio di trasparenza sancito dall'art. 12 del Regolamento (UE) 2016/679 (di seguito 'GDPR'), si rende noto che il Titolare del Trattamento è McFrancis, persona giuridica di diritto italiano con sede legale in Via Sandro Botticelli 58, Torino, C.F./P.IVA 12272120010. Ogni istanza inerente la protezione dei dati potrà essere indirizzata con formalità certa all'indirizzo PEC steven.di.francesca@pec.net o alla casella dedicata steven@mcfrancis.com.
The processing of personal data is guided by the principles of lawfulness, fairness, and transparency (Art. 5 GDPR) and is based on the following legal grounds (Art. 6 GDPR):
The Data Controller collects and processes, within the limits of the data minimization principle (Art. 5.1.c GDPR):
Processing is carried out using IT and electronic tools suitable for ensuring security (Art. 32 GDPR) and confidentiality. Data will be stored for the period strictly necessary to achieve the purposes (storage limitation principle), and specifically:
| Category | Purpose | Legal basis | Duration |
|---|---|---|---|
| Contact data | Request management/pre-contractual | Art. 6.1.b GDPR | Up to 24 months from the last interaction |
| Contractual data | Performance of the contract and legal obligations | Art. 6.1.b/6.1.c GDPR | 10 years (statute of limitations/tax) |
| Access logs | Security, anti-fraud | Art. 6.1.f GDPR | 12 months (unless otherwise required by law) |
| Marketing | Commercial communications | Art. 6.1.a GDPR | 24 months (consent renewal) |
Data will not be disseminated. It may be shared with third parties, appointed where necessary as Data Processors pursuant to Art. 28 of the GDPR (e.g., IT service providers, legal and tax consultants) or with Public Authorities in the exercise of their legitimate functions.
The Data Subject may exercise the rights set forth in Articles 15-22 of the GDPR (Access, Rectification, Erasure/Right to be Forgotten, Restriction, Portability, Objection) at any time by submitting a formal request to the Controller. This is without prejudice to the right to lodge a complaint with the Data Protection Authority (Art. 77 GDPR) if the processing is deemed to violate current legislation.
Providing data for contractual purposes is mandatory; failure to provide such data will make it impossible to proceed with the mediation relationship. Providing data for marketing purposes is optional, and withholding consent does not affect the use of the core services.
Personal data is stored on servers located within the European Union. Should it become necessary, for technical and operational reasons, to use entities located outside the European Economic Area (EEA), the transfer will take place in accordance with Chapter V of the GDPR, following the signing of Standard Contractual Clauses (SCC) or verification of Adequacy Decisions by the European Commission.
The Owner reserves the right to modify this privacy policy at any time by notifying Users on this page. Please check this page regularly, referring to the date of the last modification indicated at the bottom.
Data processing follows a 'Zero-Knowledge' security model (Zero-Knowledge Architecture). Personal data collected via the public interface (SAMI) is transmitted and stored in the secure management system (Janus II) exclusively in encrypted format. The process involves:
If personal data is not obtained directly from the data subject, the Controller shall inform the data subject, within a reasonable period and in any case no later than one month (or at the first useful contact), regarding: the sources from which the data originate, the categories of data being processed, the purposes and legal bases, the recipients, as well as the rights recognized by the GDPR.
The Data Controller adopts incident management procedures compliant with Articles 33–34 of the GDPR. In the event of a personal data breach, where the breach poses a risk to the rights and freedoms of natural persons, notification will be made to the Supervisory Authority within 72 hours and, if there is a high risk, communication to the data subjects. The process includes: containment, forensic analysis, impact assessment, corrective measures, and recording the event in the incident log.
Per questioni inerenti la protezione dei dati personali, l'interessato può contattare il Titolare all'indirizzo steven@mcfrancis.com o la casella PEC steven.di.francesca@pec.net. Qualora sia nominato un Data Protection Officer (DPO), la relativa casella di contatto è pubblicata su questa pagina. È disponibile un canale dedicato per la segnalazione di vulnerabilità o incidenti di sicurezza.