Document drafted pursuant to Art. 13 of Regulation (EU) 2016/679 (GDPR)
Last updated: 18 January 2026
In compliance with the principle of transparency established by Art. 12 of Regulation (EU) 2016/679 (hereinafter 'GDPR'), please be advised that the Data Controller is McFrancis, a legal entity under Italian law with its registered office at Via Sandro Botticelli 58, Torino, Tax Code/VAT No. 12272120010. Any request regarding data protection may be formally addressed to the certified email address steven.di.francesca@pec.it or to the dedicated mailbox steven@mcfrancis.com.
The processing of personal data is guided by the principles of lawfulness, fairness, and transparency (Art. 5 GDPR) and is based on the following legal grounds (Art. 6 GDPR):
The Data Controller acquires and processes, within the limits of the data minimization principle (Art. 5.1.c GDPR):
Processing is carried out using IT and electronic tools suitable for ensuring security (Art. 32 GDPR) and confidentiality. Data will be stored for the period strictly necessary to achieve the purposes (storage limitation principle), and specifically:
| Category | Purpose | Legal basis | Duration |
|---|---|---|---|
| Contact details | Request management/pre-contractual | Art. 6.1.b GDPR | Up to 24 months from the last interaction |
| Contractual data | Execution of relationship and legal compliance | Art. 6.1.b/6.1.c GDPR | 10 years (statute of limitations/tax) |
| Access logs | Security, anti-fraud | Art. 6.1.f GDPR | 12 months (unless otherwise required) |
| Marketing | Commercial communications | Art. 6.1.a GDPR | 24 months (consent renewal) |
Data will not be disseminated. It may be communicated to third parties, appointed where necessary as Data Processors pursuant to Art. 28 of the GDPR (e.g., IT service providers, legal and tax consultants), or to Public Authorities in the exercise of their legitimate functions.
The Data Subject may exercise the rights established by articles 15-22 of the GDPR (Access, Rectification, Erasure/Right to be Forgotten, Restriction, Portability, Objection) at any time by submitting a formal request to the Data Controller. This is without prejudice to the right to lodge a complaint with the Data Protection Authority (Art. 77 GDPR) if the Data Subject considers that the processing violates current legislation.
Providing data for contractual purposes is mandatory; failure to do so will make it impossible to proceed with the brokerage relationship. Providing data for marketing purposes is optional, and withholding consent will not affect the use of the main services.
Personal data is stored on servers located within the European Union. Should it become necessary for technical and operational reasons to use entities located outside the European Economic Area (EEA), the transfer will take place in accordance with Chapter V of the GDPR, following the signing of Standard Contractual Clauses (SCC) or the verification of European Commission Adequacy Decisions.
The Data Controller reserves the right to modify this privacy policy at any time by notifying Users on this page. Please check this page regularly, referring to the date of the last modification indicated at the bottom.
Data processing follows a multi-level security model. Personal data collected via the public interface (SAMI) is transmitted to the management system (Janus II) exclusively through an encrypted channel. The process includes:
If personal data is not obtained directly from the data subject, the Controller shall inform the data subject, within a reasonable period and in any case no later than one month (or at the first point of contact), regarding: the sources from which the data originates, the categories of data being processed, the purposes and legal bases, the recipients, as well as the rights recognized by the GDPR.
The Data Controller adopts incident management procedures in compliance with Articles 33–34 of the GDPR. In the event of a personal data breach, where the breach poses a risk to the rights and freedoms of individuals, the Supervisory Authority will be notified within 72 hours and, if the risk is high, communication will be sent to the data subjects. The process includes: containment, forensic analysis, impact assessment, corrective measures, and recording the event in the incident log.
For matters relating to the protection of personal data, the data subject may contact the Data Controller at the address steven@mcfrancis.com or the certified email (PEC) address steven.di.francesca@pec.it. If a Data Protection Officer (DPO) is appointed, their contact details will be published on this page. A dedicated channel is available for reporting vulnerabilities or security incidents.