Skip to content

Legal

Privacy Policy

Data Controller
Nicoletta De Vincenzi
VAT Number: IT 17077981003
Address: Via Ricasoli 19, 00185 Rome (RM) — Italy
Email: info@emktglab.com

Last updated: July 26, 2026

1. Introduction

This Privacy Policy describes how Nicoletta De Vincenzi (hereinafter "we", "the Controller") collects, uses, and protects the personal data of users who visit the website nicolettadevincenzi.com (hereinafter "Site") or use the services offered.

Data processing is carried out in compliance with Regulation (EU) 2016/679 (GDPR), Legislative Decree 196/2003 (Privacy Code) as amended by Legislative Decree 101/2018, and Italian legislation on cookies.

2. Data collected and purposes of processing

2.1 Navigation data
During a visit to the Site, computer systems automatically acquire certain technical data: IP addresses, browser type, operating system, pages visited, access times. These data are processed to ensure the security, integrity, and proper functioning of the Site and to obtain aggregated technical statistics. They are deleted within 90 days.

  • Legal basis: Legitimate interest of the Controller (Art. 6, par. 1, lit. f GDPR).

2.2 Contact form
When you fill out the contact form, we collect the data you provide (name, email address, organization, and message). The data is used to respond to your request for information, speaking, advisory, or media.

  • Legal basis: Pre-contractual measures taken at the request of the data subject (Art. 6, par. 1, lit. b GDPR).

2.3 Newsletter subscription and resource unlock
When you subscribe to the newsletter or request to unlock resources via the reserved page (e.g., `/book-qr`), we collect your name and email address. The data is used to send editorial communications and downloadable materials (e.g., AIDIF™ canvas, book chapter). We may use technologies that allow us to measure engagement (open and click rates).

  • Legal basis: Consent of the data subject (Art. 6, par. 1, lit. a GDPR). Consent can be withdrawn at any time by clicking on the unsubscribe link present in every email.

3. Data recipients

Personal data may be communicated to:

  • Brevo SAS (Sendinblue) — email marketing and contact database provider, based in France.
  • Substack Inc. — editorial newsletter provider.
  • Google LLC — provider of Google Analytics 4 and Google Tag Manager.
  • Microsoft Corporation — provider of Microsoft Clarity for user behavior analysis.
  • Calendly LLC — appointment booking provider.

Personal data may also be processed by authorized personnel and IT service providers acting as data processors pursuant to Art. 28 GDPR. Data is not sold to third parties or transferred for third-party marketing purposes.

4. Extra-EU data transfer

Some providers (Google LLC, Microsoft Corporation, Substack Inc., Calendly LLC) are based in the United States. The transfer takes place in compliance with the safeguards provided by the GDPR, in particular through the Standard Contractual Clauses (SCCs) approved by the European Commission and, where applicable, the EU-US Data Privacy Framework.

5. Retention period

Type of dataRetention period
Navigation data90 days
Newsletter subscribersUntil consent is withdrawn, subject to periodic review
Contact requests24 months from receipt

6. Rights of the data subject

Pursuant to Articles 15-22 of the GDPR, you have the right to:

  • Access — obtain confirmation of processing and a copy of the data
  • Rectification — correct inaccurate or incomplete data
  • Erasure — request the deletion of data ("right to be forgotten")
  • Restriction — request the limitation of processing
  • Portability — receive data in a structured and readable format
  • Objection — object to processing based on legitimate interest
  • Objection to direct marketing — object at any time, without having to provide reasons
  • Withdrawal of consent — withdraw the consent given at any time

To exercise your rights, write to: info@emktglab.com.
You also have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or the supervisory authority of your country of residence.

7. Security

The Controller adopts adequate technical and organizational measures to protect personal data from unauthorized access, loss, destruction, or disclosure. The Site uses the HTTPS protocol for the secure transmission of data.

8. Changes to this Policy

The Controller reserves the right to modify this Privacy Policy at any time. Changes will be published on this page with an indication of the update date.