McFrancis
Company Technologies Security Resources Sami Software Overview Janus Real Estate Janus Logistics Janus Construction Plans Contact
Request a demo Client area
Italiano English Español Deutsch Français Nederlands Русский العربية 中文 日本語 한국어
Company Technologies Security Resources Sami Software Overview Janus Real Estate Janus Logistics Janus Construction Plans Contact Request a demo → Client area →
Legal notes

Privacy Policy

Document drafted pursuant to Art. 13 of Regulation (EU) 2016/679 (GDPR)

Last updated: 18 January 2026

Index

  • 1. Identity and Contact Details of the Data Controller
  • 2. Purposes and Legal Bases of Processing
  • 3. Categories of Data Subject to Processing
  • 4. Processing Methods and Data Retention Period
  • 4-bis. Data Retention Table
  • 5. Scope of Communication and Dissemination
  • 6. Exercise of Data Subject Rights
  • 7. Nature of Data Provision
  • 8. Data Transfer Outside the EU
  • 9. Revision Clause
  • 10. Security Architecture and Data Segregation (Janus II)
  • 11. Data Not Obtained from the Data Subject (Art. 14 GDPR)
  • 12. Personal Data Breaches (Data Breach)
  • 13. DPO and Security Reporting Channel

1. Identity and Contact Details of the Data Controller

In compliance with the principle of transparency established by Art. 12 of Regulation (EU) 2016/679 (hereinafter 'GDPR'), please be advised that the Data Controller is McFrancis, a legal entity under Italian law with its registered office at Via Sandro Botticelli 58, Torino, Tax Code/VAT No. 12272120010. Any request regarding data protection may be formally addressed to the certified email address steven.di.francesca@pec.it or to the dedicated mailbox steven@mcfrancis.com.

2. Purposes and Legal Bases of Processing

The processing of personal data is guided by the principles of lawfulness, fairness, and transparency (Art. 5 GDPR) and is based on the following legal grounds (Art. 6 GDPR):

  • Contractual Performance (Art. 6.1.b): Processing is a conditio sine qua non for the establishment and execution of the real estate brokerage relationship, the management of appointments, and the fulfillment of pre-contractual obligations.
  • Compliance with Legal Obligations (Art. 6.1.c): Processing is mandated by mandatory regulations, including anti-money laundering legislation (Legislative Decree 231/2007) and tax and accounting obligations.
  • Legitimate Interest (Art. 6.1.f): For the protection of corporate assets, fraud prevention, and the exercise of the right of defense in legal proceedings.
  • Consent (Art. 6.1.a): Exclusively for direct marketing activities and non-essential profiling, subject to free, specific, informed, and unambiguous consent, which can be revoked at any time.

3. Categories of Data Subject to Processing

The Data Controller acquires and processes, within the limits of the data minimization principle (Art. 5.1.c GDPR):

  • Common Data: Personal details, telephone and electronic contact information, necessary for the identification of the contracting party.
  • Economic and Financial Data: Information strictly necessary for the assessment of real estate capacity or requirements.
  • Browsing Data: IP addresses, URIs, and technical parameters automatically acquired by internet communication protocols (see Cookie Policy).

4. Processing Methods and Data Retention Period

Processing is carried out using IT and electronic tools suitable for ensuring security (Art. 32 GDPR) and confidentiality. Data will be stored for the period strictly necessary to achieve the purposes (storage limitation principle), and specifically:

  • For the duration of the contractual relationship and, subsequently, for the ten-year ordinary statute of limitations (Art. 2946 of the Italian Civil Code) for civil and tax purposes.
  • For 24 months for marketing purposes, unless consent is renewed.

4-bis. Data Retention Table

CategoryPurposeLegal basisDuration
Contact detailsRequest management/pre-contractualArt. 6.1.b GDPRUp to 24 months from the last interaction
Contractual dataExecution of relationship and legal complianceArt. 6.1.b/6.1.c GDPR10 years (statute of limitations/tax)
Access logsSecurity, anti-fraudArt. 6.1.f GDPR12 months (unless otherwise required)
MarketingCommercial communicationsArt. 6.1.a GDPR24 months (consent renewal)

5. Scope of Communication and Dissemination

Data will not be disseminated. It may be communicated to third parties, appointed where necessary as Data Processors pursuant to Art. 28 of the GDPR (e.g., IT service providers, legal and tax consultants), or to Public Authorities in the exercise of their legitimate functions.

6. Exercise of Data Subject Rights

The Data Subject may exercise the rights established by articles 15-22 of the GDPR (Access, Rectification, Erasure/Right to be Forgotten, Restriction, Portability, Objection) at any time by submitting a formal request to the Data Controller. This is without prejudice to the right to lodge a complaint with the Data Protection Authority (Art. 77 GDPR) if the Data Subject considers that the processing violates current legislation.

7. Nature of Data Provision

Providing data for contractual purposes is mandatory; failure to do so will make it impossible to proceed with the brokerage relationship. Providing data for marketing purposes is optional, and withholding consent will not affect the use of the main services.

8. Data Transfer Outside the EU

Personal data is stored on servers located within the European Union. Should it become necessary for technical and operational reasons to use entities located outside the European Economic Area (EEA), the transfer will take place in accordance with Chapter V of the GDPR, following the signing of Standard Contractual Clauses (SCC) or the verification of European Commission Adequacy Decisions.

9. Revision Clause

The Data Controller reserves the right to modify this privacy policy at any time by notifying Users on this page. Please check this page regularly, referring to the date of the last modification indicated at the bottom.

10. Security Architecture and Data Segregation (Janus II)

Data processing follows a multi-level security model. Personal data collected via the public interface (SAMI) is transmitted to the management system (Janus II) exclusively through an encrypted channel. The process includes:

  • Ingestion: Acquisition via secure HTTPS (TLS) channel.
  • Access Control: Every read and modification is subject to strong cryptographic authentication, with private keys residing locally on company devices, and role-based permissions verified by the server.
  • Selective Encryption: Documents and credentials stored in the Vault area are end-to-end encrypted (AES-256) with keys not held by the server; remaining operational data resides on restricted-access infrastructure and is protected by access controls and server-side attestation logs.

11. Data Not Obtained from the Data Subject (Art. 14 GDPR)

If personal data is not obtained directly from the data subject, the Controller shall inform the data subject, within a reasonable period and in any case no later than one month (or at the first point of contact), regarding: the sources from which the data originates, the categories of data being processed, the purposes and legal bases, the recipients, as well as the rights recognized by the GDPR.

12. Personal Data Breaches (Data Breach)

The Data Controller adopts incident management procedures in compliance with Articles 33–34 of the GDPR. In the event of a personal data breach, where the breach poses a risk to the rights and freedoms of individuals, the Supervisory Authority will be notified within 72 hours and, if the risk is high, communication will be sent to the data subjects. The process includes: containment, forensic analysis, impact assessment, corrective measures, and recording the event in the incident log.

13. DPO and Security Reporting Channel

For matters relating to the protection of personal data, the data subject may contact the Data Controller at the address steven@mcfrancis.com or the certified email (PEC) address steven.di.francesca@pec.it. If a Data Protection Officer (DPO) is appointed, their contact details will be published on this page. A dedicated channel is available for reporting vulnerabilities or security incidents.

McFrancis
The Signature that Rewrites the Web
LinkedIn Instagram Facebook X TikTok YouTube
Company Technologies Security Resources Sami Software Plans Contact
Privacy Policy Cookie Policy Cookie Management Terms and Conditions Sitemap

McFrancis™ is a registered Made in Italy trademark in Europe, all rights reserved. © 2026 McFrancis™ · Brand No. 018718267 · Netspace Agency · Via Sandro Botticelli 58, Torino · P.IVA 12272120010

Sami Avatar