Legal

Privacy Policy

This notice, provided pursuant to Arts. 13 and 14 of Regulation (EU) 2016/679 (GDPR) and to the Italian Privacy Code (Legislative Decree 196/2003 as amended by Legislative Decree 101/2018), explains what personal data the Controller processes through the site and its forms, for which purposes and legal bases, which providers it relies on and the rights available to the Data Subject.

Last updated: August 2026 GDPR compliant Version 1.0 Applies to intarmour.com

This notice, provided pursuant to Arts. 13 and 14 of Regulation (EU) 2016/679 (GDPR) and to the Italian Privacy Code (Legislative Decree 196/2003 as amended by Legislative Decree 101/2018), explains what personal data the Controller processes through the site and its forms, for which purposes and legal bases, which providers it relies on and the rights available to the Data Subject.

01

Data controller

The controller of personal data (hereinafter the “Controller”) is Intarmour® di Simone Nogara, a sole proprietorship with registered office at Via Morazzone 4, 22100 Como (CO), Italy — VAT no. IT03817020138, tax code NGRSMN91P14C933V.

The Controller may be contacted regarding any matter concerning the processing of personal data and the exercise of the data subject’s rights at the following addresses: email advisory@intarmour.com; certified email (PEC) info@pec.intarmour.com / simone@pec.intarmour.com; landline +39 031 5478618 and mobile +39 349 478 6520.

This notice is provided pursuant to Arts. 13 and 14 of Regulation (EU) 2016/679 (hereinafter the “GDPR”) and to Legislative Decree No. 196 of 30 June 2003, as amended by Legislative Decree No. 101 of 10 August 2018 (hereinafter the “Italian Privacy Code”), for anyone who interacts with the Controller’s website and services (hereinafter the “Data Subject” or the “User”).

02

Data protection officer (DPO)

The Controller has not appointed a Data Protection Officer (DPO), as the conditions requiring such appointment under Art. 37 of the GDPR do not apply. Data-protection requests are handled directly by the Controller at the contact details set out above.

03

Categories of data processed

The Controller processes the data the Data Subject chooses to provide through the site’s forms and correspondence, together with the minimal technical data required to deliver and secure the pages. The categories of data processed are as follows.

  • Browsing and technical data — data whose transmission is implicit in the use of the Internet communication protocols (for example IP address, browser type and version, system logs), processed by the hosting infrastructure for the purposes of delivering and securing the site.
  • Data provided through the forms — name, email address, company, role, message and, for the booking form, telephone number and preferred date and time for the meeting.
  • Consents — the choices expressed by the Data Subject regarding cookies and any subscription to marketing communications, together with the related record data (for example date and time of consent).
  • Correspondence — the data contained in communications addressed to the Controller by email or certified email (PEC) and the information needed to respond to them.

04

Purposes and legal bases of processing

Personal data is processed solely for the purposes set out below, each associated with a specific legal basis under Art. 6 of the GDPR.

  • Handling contact and booking requests — responding to the Data Subject’s enquiries and arranging any meeting. Legal basis: Art. 6(1)(b) GDPR, performance of pre-contractual measures taken at the Data Subject’s request, and/or Art. 6(1)(f), the Controller’s legitimate interest in replying.
  • Sending the newsletter and marketing communications — sending updates and informational materials, only to those who have consented. Legal basis: Art. 6(1)(a) GDPR, consent, which may be withdrawn at any time.
  • Statistics and measurement via Google Analytics 4, the LinkedIn Insight Tag and the Apollo.io website tracker — analysis of site usage and analytics activities, including for advertising and B2B marketing purposes. Legal basis: Art. 6(1)(a) GDPR, consent, given through the dedicated banner and always revocable.
  • Compliance with legal obligations — fulfilment of the tax, accounting and other obligations laid down by applicable law in connection with any relationships established. Legal basis: Art. 6(1)(c) GDPR, legal obligation.
  • Site security and anti-bot verification — prevention of abuse, fraud, spam and automated submissions, and safeguarding of system integrity. To this end the forms use a hidden honeypot field (which collects no personal data) and the Cloudflare Turnstile service, which processes technical data (for example IP address and browser signals) solely to distinguish human users from bots, with no advertising purpose and no profiling. Legal basis: Art. 6(1)(f) GDPR, the Controller’s legitimate interest in protecting the site, the forms and its Users.

05

Nature of the provision of data

The provision of the data requested by the forms is optional; however, failure to provide the data marked as required prevents the Controller from responding to the contact or booking request. The provision of data for marketing purposes is likewise optional, and any refusal does not affect the ability to use the other services. The provision of data necessary to comply with legal obligations is, on the other hand, mandatory within the limits set by applicable law.

06

Recipients and data processors

Personal data is processed by the Controller and may be disclosed to a limited number of providers that process it on the Controller’s behalf as data processors, appointed pursuant to Art. 28 of the GDPR and bound by appropriate agreements. Data may also be disclosed to third parties (for example advisers or authorities) where necessary to comply with legal obligations. A copy of the Data Processing Agreement (DPA) is available on request. The main providers are as follows.

  • Cloudflare, Inc. — hosting, content delivery network (CDN), infrastructure-security services, operation of the serverless endpoint (Cloudflare Worker) that relays form submissions, and anti-bot verification of the forms via Cloudflare Turnstile, in the context of which browsing and technical data is processed. Data transfers are governed by the Standard Contractual Clauses (SCC).
  • HubSpot, Inc. (United States) — receives the fields submitted through the contact, booking, download and subscription forms (name, email, company, role, telephone, message, chosen date and time), manages the contact in its CRM, notifies the Controller and, where marketing consent is given or the newsletter is subscribed to, manages the sending of newsletters and marketing communications. Data transfers are governed by the Standard Contractual Clauses (SCC) and, where applicable, by the EU-US Data Privacy Framework.
  • Google Ireland Ltd — provides Google Analytics 4 for the production of aggregated statistics on site usage, activated only subject to the Data Subject’s consent.
  • LinkedIn Ireland Unlimited Company (Microsoft group) — provides the LinkedIn Insight Tag for cross-site analytics and advertising purposes, activated only subject to the Data Subject’s consent.
  • Apollo.io (United States) — provides the website tracker used, subject to consent, to recognise visitors and the companies they come from for B2B sales analysis and marketing, activated only subject to the Data Subject’s consent.
  • LiveIntent, Inc. (United States) — identity-resolution service that may be activated by the Apollo.io tracker for cross-site recognition of visitors for marketing purposes, activated only subject to the Data Subject’s consent.

07

Transfers of data to third countries

Some providers (in particular Google, LinkedIn, Cloudflare, HubSpot, Apollo.io and LiveIntent) may involve the transfer of personal data to the United States of America. Such transfers take place on the basis of the Standard Contractual Clauses (SCC) approved by the European Commission and, where applicable, of the EU-US Data Privacy Framework, as adequate safeguards under Chapter V of the GDPR. The Data Subject may ask the Controller for information on the safeguards adopted and how to consult them.

08

Retention periods

Personal data is retained for the time strictly necessary to achieve the purposes for which it was collected and, thereafter, for any period required by law, according to the criteria set out below.

  • Data from contact and booking requests — for the time necessary to handle the request and, in any event, no longer than 24 months, save where a dispute arises, in which case the data is retained until the dispute is resolved.
  • Contractual and accounting data — for 10 years, in compliance with the retention obligations laid down by Arts. 2214 and 2220 of the Italian Civil Code and by tax legislation.
  • Data processed for marketing purposes — until the Data Subject withdraws consent, subject to the technical time needed to give effect to the withdrawal.
  • Analytics data collected through the providers — according to the retention periods laid down in the respective providers’ terms.

09

Rights of the data subject

In relation to the processing described in this notice, the Data Subject may exercise at any time the rights provided under Arts. 15–22 of the GDPR, summarised below.

  • Right of access — to obtain confirmation as to whether processing is taking place and to access one’s personal data and the related information (Art. 15).
  • Right to rectification — to obtain the correction of inaccurate data and the completion of incomplete data (Art. 16).
  • Right to erasure — to obtain the erasure of data in the cases provided for by law (Art. 17).
  • Right to restriction — to obtain the restriction of processing in the cases provided for (Art. 18).
  • Right to portability — to receive, in a structured, commonly used and machine-readable format, the data provided and to transmit it to another controller (Art. 20).
  • Right to object — to object to processing based on legitimate interest on grounds relating to one’s particular situation (Art. 21).
  • Right to withdraw consent — to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

10

How to exercise rights and lodge a complaint

The Data Subject may exercise these rights by writing to the Controller at advisory@intarmour.com or at the certified email (PEC) info@pec.intarmour.com / simone@pec.intarmour.com. The Controller responds to requests without undue delay and, in any event, within the time limits laid down by the GDPR.

The Data Subject also has the right to lodge a complaint with the supervisory authority, the Italian Data Protection Authority — Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome — garanteprivacy.it) — and to bring proceedings before the competent court.

11

Minors

The Controller’s services are not directed to minors under 18 years of age, and the Controller does not knowingly collect personal data of minors of that age. Should data of a minor be found to have been collected inadvertently, it will be deleted without undue delay.

12

No automated decision-making

The Controller does not carry out automated decision-making, including profiling, that produces legal effects concerning the Data Subject or similarly significantly affects the Data Subject within the meaning of Art. 22 of the GDPR.

13

Cookies and tracking technologies

The site uses storage technologies necessary for its operation and, only subject to consent, Google Analytics 4, the LinkedIn Insight Tag and the Apollo.io website tracker. Full details of the technologies used, the cookies set, the purposes and how to manage and withdraw consent are set out in the Cookie Policy, to which reference is made in full.

14

Changes to this notice

The Controller reserves the right to amend or update this notice to reflect any changes in legislation or in its company or services. Updated versions are published on this page, stating the date of last update; the Data Subject is invited to consult it periodically.

15

Contact

For any question about this notice or the processing of personal data: email advisory@intarmour.com, certified email (PEC) info@pec.intarmour.com / simone@pec.intarmour.com, tel. +39 031 5478618 (landline) / +39 349 478 6520 (mobile).

This document is provided for information purposes and does not constitute legal advice.

Questions about this document?

If you need clarification on my policies, data processing or legal documentation, I’m happy to help.

Contact Intarmour