Privacy​

LAISA – Società tra avvocati per azioni, in its capacity as Data Controller (hereinafter “LAISA”), places the utmost importance on the confidentiality, protection, and security of the personal data of all individuals with whom it interacts.

 

Users are invited to read this document carefully, as it describes the procedures adopted in managing this website with regard to the processing of personal data of those who visit it. This notice is provided pursuant to Regulation (EU) 2016/679 (“GDPR”) to all individuals who interact with LAISA’s web services accessible online at laisalegal.com.

 

This privacy notice applies exclusively to LAISA’s website and not to any third-party websites that users may access through links contained herein. LAISA has no control over such external websites or over the data protection practices they apply. Users are therefore encouraged to review the privacy policies of any third parties before providing personal information.

 

DATA CONTROLLER

The Data Controller is LAISA – Società tra avvocati per azioni, with offices in Rome, Via Barberini 86, 00187, and Milan, Via San Gregorio 29, 20142. Email: info@laisalegal.com.

 

PURPOSES OF PROCESSING AND LEGAL BASIS

The personal data processed by LAISA is exclusively that voluntarily provided by users while browsing the Website, through the optional, explicit, and voluntary submission of forms on the site or through emails sent to the addresses indicated. Failure to provide such data may prevent LAISA from delivering the requested service.

 

The processing of your personal data is based on:

 

(i) your consent, and

 

(ii) LAISA’s compliance with legal obligations.

 

Within the scope of the purposes described above, personal data is processed using manual, electronic, and telematic tools.

 

LAISA adopts appropriate organisational and technical measures to ensure the security and confidentiality of personal data.

 

CATEGORIES OF DATA PROCESSED

LAISA processes personal data collected directly from users or from third parties, including, by way of example, identification data and information relating to the device used (e.g., operating system).

 

METHODS OF PROCESSING

Personal data is processed using manual and electronic tools solely for the purposes for which it was collected. Specific security measures are implemented to prevent data loss, unlawful or improper use, and unauthorised access.

 

CATEGORIES OF RECIPIENTS

LAISA does not disclose personal data to Third Parties except where required to comply with legal obligations.

 

Processing activities carried out for the purposes described above are performed exclusively by LAISA or by entities appointed by LAISA as external Data Processors.

 

TRANSFER OF DATA TO THIRD COUNTRIES

LAISA prioritises the processing of personal data within the European Union. Should data be transferred to any country outside the EU or the European Economic Area, LAISA ensures compliance with the standard contractual clauses adopted by the European Commission and with any other relevant guidance issued by relevant Authorities.

 

DATA RETENTION

Personal data is retained in a form that permits identification of data subjects for no longer than is strictly necessary to achieve the specific purposes indicated above.

 

DATA SUBJECTS’ RIGHTS

Pursuant to Articles 15-21 of the GDPR, data subjects may exercise the following rights:

 
  1. a) Right of access: the right to obtain confirmation from the Data Controller as to whether or not personal data is being processed and, if so, to access such data and receive detailed information regarding the origin, purposes, categories, recipients, and other relevant elements;
  2. b) Right to rectification: the right to obtain from the Data Controller, the rectification of inaccurate personal data and the completion of incomplete data without undue delay, including by providing a supplementary statement;
  3. c) Right to deletion (“right to be forgotten”): the right to obtain the deletion of personal data without undue delay where:
  4. the data is no longer necessary for the purposes for which it was collected;
  5. consent has been withdrawn and no other legal basis exists;

iii. the data has been processed unlawfully;
  1. deletion is required to comply with a legal obligation;
  2. d) Right to object to processing: the right to object at any time to the processing of personal data based on the Data Controller’s legitimate interests and/or to processing for marketing purposes, including profiling. If the user objects to processing for marketing purposes, their personal data will no longer be processed for such purposes;
  3. e) Right to restriction of processing: the right to obtain restriction of processing where the accuracy of the data is contested (for the time necessary for verification by the Data Controller), where processing is unlawful, and/or where the data subject has objected to processing;
  4. f) Right to data portability: the right to receive personal data in a structured, commonly used, machine-readable format and to transmit such data to another Data Controller, where technically feasible, when processing is based on consent or on a contract and carried out by automated means;
  5. g) Right to lodge a complaint with a supervisory authority: without prejudice to any other administrative or judicial remedy, data subjects who believe that the processing of their personal data infringes the GDPR may lodge a complaint with the supervisory authority of the Member State in which they have their habitual residence, place of work, or where the alleged infringement occurred;
  6. h) Rights relating to fully automated profiling: in relation to fully automated profiling, the right to obtain human intervention from the Data Controller to express their point of view and contest the decision.

Users may withdraw their consent to specific optional processing activities at any time, without prejudice to the lawfulness of the processing carried out prior to withdrawal.

 

To exercise these rights, users may contact:

 

By post: LAISA – Società tra avvocati per azioni, Roma, Via Barberini 86, 00187 and Milan, Via San Gregorio 29, 20142

 

By Email: info@laisalegal.com

 

The content on this website, including script codes, graphics, text, tables, images, audio, and any other information available in any form, is protected under applicable intellectual property laws. All companies and products mentioned on this wedsite are identified by their respective trademarks, which may be protected by patents and/or copyrights granted or registered by the relevant authorities. Unless otherwise specified, software products and informational content may be downloaded or used solely for personal or otherwise non-commercial purposes, provided the source is acknowledged.

 

Creation and Management of this Application

The main components of this Application are created and managed directly by the Data Controller using the software tools listed below.

 

This Application

WordPress (self-hosted)

Provider: this Application

 

Personal Data processed: date of birth +1

 

Tag Management

These services allow the Data Controller to manage, in a centralised manner, the tags or scripts required by this Application. As a result, User Data may be processed by such services and may also be stored.

 

Google LLC

Google Tag Manager

Provider: Google LLC

 

Location of processing: United States

 

Personal Data processed: Usage Data +1

 

Traffic Optimisation and Distribution

These services enable this Application to distribute its content through servers located across different regions and to optimise its performance.

The Personal Data processed depends on the characteristics and implementation methods of these services, which by their nature filter communications between this Application and the User’s browser.

Given the distributed nature of this system, it is difficult to determine the exact locations to which content -potentially containing the User’s Personal Data – is transferred.

 

Imperva, Inc.

Imperva CDN

Provider: Imperva, Inc.

 

Location of processing: United States

 

Personal Data processed: Usage Data

 

Imperva, Inc.

Imperva Application Security

Provider: Imperva, Inc.

 

Location of processing: United States

 

Personal Data processed: Tracking Tools +1

 

Statistics

The services contained in this section enable the Data Controller to monitor and analyse traffic data and are used to track User behaviour.

 

Google LLC

Google Analytics 4

Provider: Google LLC

 

Location of processing: United States

 

Personal Data processed: Usage Data +3

 

Displaying Content from External Platforms

These services allow content hosted on external platforms to be displayed directly on the pages of this Application and to interact with such content. These services are often referred to as “widgets”, meaning small elements embedded in a website or application that provide specific information or perform a particular function, often enabling user interaction.

Such services may still collect web traffic data relating to the pages where they are installed, even when Users do not actively use them.

 

Google LLC

Google Fonts

Provider: Google LLC

 

Location of processing: United States

 

Personal Data processed: Usage Data +1

 

Adobe Systems Incorporated

Adobe Fonts

Provider: Adobe Systems Incorporated

 

Location of processing: United States

 

Personal Data processed: Usage Data +1

 

Fonticons, Inc.

Font Awesome

Provider: Fonticons, Inc.

 

Location of processing: United States

 

Personal Data processed: Usage Data +1

 

Font Awesome is a font-style display service provided by Fonticons, Inc., which enables this Application to incorporate such content into its pages.

 

Personal Data processed:

Usage Data

Tracking Tools

Service provided by:

Fonticons, Inc. (United States) – Privacy Policy
Privacy Policy

Get in touch

If you need legal advice, contact us immediately.

Privacy policy       Legal       Governance

Privacy policy       Legal       Governance