Privacy notice
Notice pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and Italian Legislative Decree 196/2003 as amended, for visitors to fvitali.com and users of its contact form.
Last updated: 2 October 2026.
In short: I only collect the data you send me through the contact form or by email, I use it solely to reply to you, I do not share it with anyone and I do not use it for marketing. This site uses no cookies and no analytics or tracking tools.
1. Data controller
The data controller is Federico Vitali, based in Rome (Italy), who can be contacted at federico.vitali@fvitali.com.
2. What data I process
- Data you provide voluntarily through the contact form or by email: full name, email address, area of interest and, if you choose to provide them, company, phone number and message content.
- Browsing data: the systems running the site automatically log certain technical data (e.g. IP address, date and time of the request, page visited, browser and operating system). This data is not used to identify you, but could allow identification if combined with other data.
Please do not include special categories of data (e.g. health data) or third-party data that is not needed for your request.
3. Why I process it and on what legal basis
- Replying to your request, arranging the exploratory call and, where relevant, sending you a proposal: processing is necessary to take steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR).
- Keeping the site running and secure, preventing abuse and unsolicited messages (spam): the controller's legitimate interest (Art. 6(1)(f) GDPR).
- Complying with legal obligations and, where necessary, establishing, exercising or defending legal claims: legal obligation and legitimate interest (Art. 6(1)(c) and (f) GDPR).
Your data is not used for newsletters or promotional communications, nor for profiling or automated decision-making.
4. Mandatory data
Name, email and area of interest are required in order to reply to you: without them I cannot handle your request. All other fields are optional.
5. How data is processed
Data is processed electronically, with appropriate technical and organisational measures to protect it against unauthorised access, loss or disclosure. The site uses an encrypted connection (HTTPS) and requests received are accessible only to the controller.
6. Who it may be shared with
Data is not published or sold. It may be processed, solely for the purposes described above, by providers acting as data processors under Art. 28 GDPR:
- Netlify, Inc.: website hosting, contact form handling and browsing data;
- the email service provider used by the controller, for receiving notifications and correspondence.
Data may also be disclosed to public authorities or to the controller's advisors where required to comply with legal obligations or protect a legal right.
7. Transfers outside the EU
Netlify, Inc. is based in the United States, so some data may be transferred outside the European Economic Area. Such transfers rely on the safeguards provided by the GDPR: the European Commission's adequacy decision on the EU-U.S. Data Privacy Framework (Art. 45 GDPR) for participating providers, and/or the Standard Contractual Clauses approved by the European Commission (Art. 46 GDPR).
8. How long I keep it
- Contact requests: up to 12 months from the last exchange, unless a professional relationship follows.
- If an engagement follows: for the duration of the relationship and thereafter for the period required by law for keeping contractual and tax records (normally 10 years).
- Browsing data: for as long as strictly necessary for the security and operation of the service, in line with the hosting provider's policies.
9. Cookies and tracking
This site does not use cookies, whether technical or profiling, and does not include analytics, social media pixels or any other tracking tools. Typefaces and images are hosted on the site itself, so browsing it does not involve connections to third-party servers. This is why no cookie banner is shown.
10. Links to external sites
The site contains a link to the controller's LinkedIn profile. When you visit LinkedIn, that platform's privacy policy applies; the controller has no control over it.
11. Your rights
You may exercise your rights under Articles 15–22 GDPR at any time:
- access your data and obtain a copy;
- request its rectification or completion;
- request its erasure;
- request restriction of processing;
- receive your data in a structured format and transfer it to another controller (portability);
- object to processing based on legitimate interest.
To exercise them, simply write to federico.vitali@fvitali.com. You will receive a reply within one month of your request.
12. Complaints
If you believe that the processing of your data infringes the GDPR, you may lodge a complaint with the Italian Data Protection Authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or with the supervisory authority of the EU country where you live or work.
13. Changes to this notice
This notice may be updated, for example when new features are added to the site or regulations change. The date of the latest update is shown at the top of this page.