GFG & Partners
Privacy Policy
Last updated: August 2026
This notice describes how the website gfglex.it is managed with regard to the processing of the personal data of users who consult and interact with it. The notice is provided pursuant to Article 13 of Regulation (EU) 2016/679 (GDPR).
1. Data Controller
The controller of personal data is GFG & Partners Law Firm. Registered office: Viale Parioli, 87 – Rome. E-mail: .
2. Types of Data Processed
While browsing and using the Site, the Controller may collect the following categories of data:
- Browsing data: the IT systems responsible for operating the Site acquire certain personal data whose transmission is implicit in the use of the Internet communication protocols (e.g. IP addresses, domain names, request times).
- Data provided voluntarily by the user: identification and contact data (name, surname, e-mail address, telephone number) sent optionally and explicitly to the addresses shown on the Site.
3. Purposes and Legal Basis of Processing
Personal data are processed for the following purposes:
- Handling requests (performance of pre-contractual measures – Art. 6(1)(b) GDPR): to respond to requests for information, advice or quotations sent by the user.
- Operation of the Site (legitimate interest – Art. 6(1)(f) GDPR): to ensure the correct technical functioning and security of the website, and to derive anonymous statistical information on its use.
- Compliance with legal obligations (legal obligation – Art. 6(1)(c) GDPR): to comply with specific obligations laid down by applicable national or European law, or by orders of the Authorities.
4. Processing Methods and Retention
Processing is carried out using IT and electronic tools, with logic strictly related to the stated purposes and in compliance with the security measures under Article 32 of the GDPR, designed to prevent data loss, unlawful use or unauthorised access. Data will be retained for the time strictly necessary to achieve the purposes for which they were collected:
- Contact requests will be retained for a maximum of 12 months from their handling, unless a professional relationship is established.
- Where a legal engagement is conferred, data will be retained for 10 years from the conclusion of the mandate, to comply with civil and tax obligations.
5. Recipients of the Data
Personal data are not subject to dissemination. They may be made accessible exclusively to:
- Professionals and collaborators of the Firm, duly authorised and instructed in the processing.
- Third parties performing outsourced activities on behalf of the Controller (e.g. providers of hosting, website management and IT support services), specifically appointed as Data Processors (Art. 28 GDPR).
6. Transfer of Data Outside the EU
The management and storage of personal data take place on servers located within the European Union. No direct transfer of data to non-EU third countries is envisaged.
7. Rights of the Data Subject
Pursuant to Articles 15-22 of the GDPR, the user (Data Subject) has the right to ask the Controller, at any time, for:
- access to their personal data;
- the rectification or erasure (right to be forgotten) of such data;
- the restriction of, or objection to, processing;
- data portability (to receive the data in a structured, commonly used and machine-readable format).
Requests to exercise these rights may be sent by e-mail to . The Data Subject also has the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) should they consider that the processing of their data infringes applicable law.
