Privacy notice

Privacy and cookies

Notice provided under Articles 12 and 13 of Regulation (EU) 2016/679 (“GDPR”) to users who visit alvaren.it or use its contact tools. Last updated: 30 July 2026.

1. Scope of this notice

This notice applies only to alvaren.it and to the internal pages directly managed by ALVAREN. It does not apply to external websites, platforms or services reached through hyperlinks, which operate under their own notices and terms.

2. Data controller

Elena De Riva – ALVARENVAT no. 08533030964Via Broletto 4, 20121 Milan, ItalyEmail: milano@alvaren.it

3. Personal data processed

Browsing data

The IT systems and services required to operate the website may acquire, in the ordinary course of their operation, the IP address, date and time of the request, requested resource, response status, browser and device type, operating system, referring page and other technical information contained in security and operational logs.

Data provided by the user

When a user submits the form, emails ALVAREN or schedules a meeting, ALVAREN may process the user’s first name, last name, email address, company, message content, appointment details and any other information voluntarily provided.

Data not requested

The form is not intended for special categories of data under Article 9 GDPR, criminal-offence data or unnecessary documents, including unsolicited CVs. Users are asked not to provide such information. If it is provided voluntarily, it will be processed only where strictly necessary and deleted when irrelevant.

4. Purposes and legal bases

  • Website operation and security: page delivery, abuse prevention, infrastructure protection, diagnostics and error management. Legal basis: the Controller’s legitimate interest in providing a secure and efficient service, Article 6(1)(f) GDPR, and any applicable legal obligations under Article 6(1)(c).
  • Handling contact requests: reading and replying to messages, arranging a conversation and carrying out any requested preliminary activities. Legal basis: steps taken at the data subject’s request prior to entering into a contract, Article 6(1)(b) GDPR; where the contact is made on behalf of a company, the legitimate interest in managing the professional relationship, Article 6(1)(f).
  • Scheduling meetings: availability management, organisational communications and holding the meeting. Legal basis: Article 6(1)(b) and (f) GDPR.
  • Compliance and protection of rights: compliance with legal, administrative or tax obligations and the establishment, exercise or defence of legal claims. Legal basis: Article 6(1)(c) and (f) GDPR.

ALVAREN does not use data collected through the website for profiling, behavioural advertising or newsletters. The checkbox in the form records that the user has read this notice; it is not consent used as the legal basis for processing.

5. Requirement to provide data

Browsing entails the processing of strictly necessary technical data. In the form, first name, last name, email address, message and acknowledgement of this notice are required to submit and handle the request; the “Company” field is optional. Without the required data, the form cannot be submitted, although users remain free not to use the service.

6. Processing methods and security

Data is processed mainly by electronic means in accordance with the principles of lawfulness, fairness, transparency, minimisation, accuracy, storage limitation and confidentiality. Technical and organisational measures proportionate to the risks are used, including access controls, communication safeguards, privilege limitation, anti-spam measures and security-event monitoring. No solely automated decision is made that produces legal or similarly significant effects on the user.

7. Authorised persons, recipients and providers

Data may be processed by the Controller and expressly authorised persons, as well as providers of hosting, CDN and security, IT maintenance, form management, email delivery and appointment scheduling. Depending on the circumstances, they act as processors under Article 28 GDPR or as independent controllers. Legal, tax or technical advisers and public authorities may also receive data where required by law or necessary to protect a right.

Once activated, the form uses the Resend email-delivery service. The meeting link takes users to the external Calendly platform. The website also loads typefaces through Google Fonts; the technical request may disclose the IP address and browser information to Google. The providers’ own notices govern processing carried out for their independent purposes.

8. Transfers outside the EEA

Some providers may process data outside the European Economic Area, particularly in the United States. In those cases, transfers rely on an applicable adequacy decision, including the recipient’s participation in the EU–US Data Privacy Framework where relevant, or on standard contractual clauses approved by the European Commission together with supplementary measures where necessary. Information on the applicable safeguards may be requested from the Controller.

9. Retention periods

  • Technical and security logs are retained for the time required to operate and protect the website, normally no longer than 30 days, except where anomalies, incidents or investigations require longer retention.
  • Contact requests and appointment data are retained for as long as needed to reply and, where no professional relationship follows, normally no longer than 24 months after the last meaningful contact.
  • If a professional relationship is established, relevant data is retained for its duration and subsequently for the period required by law or necessary to protect rights, normally up to 10 years, without prejudice to litigation or longer statutory periods.

Data stored in backups is deleted according to ordinary technical overwrite and recovery cycles.

10. Cookies and tracking technologies

The website does not use profiling, advertising, remarketing or analytics cookies and does not install non-essential tracking tools. Only cookies or technical identifiers strictly required to deliver and secure the service may be used; prior consent is not required for these tools. A consent banner is therefore not displayed.

External platforms reached through links, such as Calendly, may use their own cookies under their respective notices and the preferences selected by the user on those pages.

11. Data subject rights

Where the conditions in Articles 15–22 GDPR are met, data subjects may request access, rectification, erasure, restriction of processing and data portability, and may object to processing based on legitimate interests. If any future processing relies on consent, consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.

Requests may be sent to milano@alvaren.it. The Controller will respond without undue delay and normally within one month. Data subjects may also lodge a complaint with the Italian Data Protection Authority or with the competent supervisory authority in the country where they live, work or believe the infringement occurred.

12. Updates

The Controller may update this notice to reflect legal, organisational or technical changes. The current version is published on this page together with its update date.