Personal data protection – Privacy policy
Dear User, we wish to inform you that the “European Regulation 2016/679 on the protection of natural persons with regard to the Processing of Personal Data, as well as on the free movement of such data” (hereinafter “GDPR”) provides for the protection of natural persons with regard to the processing of personal data as a fundamental right. Pursuant to Article 13 of the GDPR, we hereby inform you that Princivalle Apruzzi Danielli Law Firm will process certain of your personal data as specified below.
CATEGORIES OF PERSONAL DATA:
SOURCE OF PERSONAL DATA: The personal data held by our law firm are collected directly from the data subject.
DATA CONTROLLER: The data controller is the professional association named Princivalle Apruzzi Danielli Law Firm, with registered office in Via Santo Stefano 50, 40125 Bologna, TAX Code and VAT no. 03082431200, reachable by phone at +39 0510930400 or by email at info@padlex.com.
PURPOSES OF PROCESSING AND LEGAL BASIS: Your personal data are processed for the following purposes:
DATA RECIPIENTS: Within the limits relevant to the purposes indicated, your data may be disclosed to third parties acting as independent data controllers, such as agencies and public authorities, judicial bodies, credit institutions, insurance companies, carriers and shippers. They may also be disclosed or made accessible to service providers, consulting firms, accounting and marketing companies, hosting providers and digital service providers acting as data processors. Your data will not be disseminated in any way. Information regarding processors and persons authorized by the Controller is available in an updated list held by the Controller.
TRANSFER OF DATA ABROAD: As part of the processing activities, collected data may be transferred outside the European Economic Area (EEA). Our firm uses a cloud-based storage service with data centers located within the European Union. Where transfers to the USA occur, they are subject to the Data Privacy Framework; otherwise, in the absence of an adequacy decision, transfers are carried out by adopting standard contractual clauses pursuant to Article 46 of the GDPR.
DATA RETENTION PERIOD: The collected data will be retained for a period not exceeding that necessary to achieve the purposes for which they were collected or in accordance with legal deadlines. For more information on retention, you may contact the firm. Periodic checks are carried out to verify the obsolescence of stored data in relation to the purposes for which they were collected.
PROVISION OF DATA: The provision of your data is optional with respect to the purposes described above; however, it is necessary, as failure to provide such data will prevent the submission of applications, subscription to the newsletter, or receipt of commercial and marketing information from the Firm.
METHODS OF PROCESSING: The personal data you provide will be processed in compliance with the above-mentioned regulations and confidentiality obligations inherent in the Controller’s activity, as well as professional ethical obligations applicable to the legal profession. Data will be processed using both IT tools and paper-based means, as well as any other suitable media, in compliance with appropriate security measures pursuant to Article 5(1)(f) of the GDPR.
ARTIFICIAL INTELLIGENCE: Furthermore, we inform you that the professionals of the firm may use, for instrumental and support activities related to the services provided, and without prejudice to the predominance of intellectual work, online generative artificial intelligence (AI) systems. The use of such AI systems may entail potential risks or margins of error; therefore, results are always verified and validated by the professional. Where necessary for drafting documents or acts in the performance of the assignment, the use of AI does not in any way replace the judgment, expertise, and responsibility of the professional, who remains responsible for all final evaluations and decisions related to the mandate.
DATA SUBJECT’S RIGHTS: The data subject always has the right to request from the Controller access to their data, rectification or erasure, restriction of processing, or to object to processing, as well as the right to data portability and to withdraw consent. These and other rights provided by the GDPR may be exercised by simple communication to the Controller. The data subject may also lodge a complaint with a supervisory authority.
March 2026, Princivalle Apruzzi Danielli