This notice explains how personal data is processed when you visit fpexec.com or contact FP Exec through the form, by email or through the other channels listed on the site. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and Italian Legislative Decree 196/2003.
1. Data controller
The data controller is shown in the box at the top of this page. For any request about your data, write to info@fpexec.com.
2. What data we process
Data you provide. When you fill in the contact form or send an email: your name, email address, company (optional), the content of your message and any other information you choose to include. Please do not include special categories of data (health, political opinions, etc.) or unnecessary data about other people.
Browsing data. Like any web server, the systems hosting this site record some technical information: IP address, date and time of the request, page requested, response code, and the browser and operating system reported. This data is not used to identify or profile visitors.
NIS2 checklist. Your answers to the online self-assessment are processed only in your browser and are neither transmitted nor stored.
The site does not use profiling cookies, analytics tools or tracking pixels. See the cookie policy for details.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Replying to your enquiry and, if you wish, discussing a possible engagement | Steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR); for enquiries unrelated to an engagement, your consent (Art. 6(1)(a)), which you can withdraw at any time |
| Keeping the site secure and preventing abuse (for example automated form submissions) | The controller’s legitimate interest in protecting its systems (Art. 6(1)(f)) |
| Complying with legal obligations and, where necessary, establishing or defending legal claims | Legal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f)) |
Your data is not used for promotional mailings or newsletters, and is not passed to third parties for marketing.
4. Whether you must provide data
Providing the data requested in the form is optional, but without a name, email address and message we cannot reply.
5. How data is processed and who receives it
Data is processed electronically with appropriate technical and organisational measures, including encrypted connections (HTTPS), access control and rate limiting on the form.
The following may process data on the controller’s behalf as processors (Art. 28 GDPR):
- the provider of the infrastructure hosting the site: TODO name the server provider;
- the provider of the email delivery service used by the form (SMTP relay): TODO name the provider (e.g. Brevo);
- the provider of the mailbox that receives messages: TODO name the provider.
Data is not published. It may be disclosed to the competent authorities where the law requires.
6. Transfers outside the European Economic Area
TODO: check where the providers listed in section 5 are based. If any of them processes data outside the EEA, state the safeguard used here (an adequacy decision such as the EU-U.S. Data Privacy Framework, or standard contractual clauses).
7. How long we keep data
- Messages and enquiries: for as long as needed to handle the enquiry, and no longer than 24 months after the last exchange. If a professional relationship follows, data is kept for the duration of the engagement and then for the periods required by civil and tax law (usually 10 years).
- Browsing data (technical logs): for up to 30 days, unless needed to investigate abuse or criminal activity.
8. Your rights
You can exercise your rights under Articles 15–22 GDPR at any time: access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interest, and withdrawal of consent (without affecting the lawfulness of earlier processing).
To exercise them, write to info@fpexec.com. We reply within one month, as required by Art. 12 GDPR.
If you believe the processing breaks the law, you can lodge a complaint with the Italian Data Protection Authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or with the supervisory authority where you live or work.
9. Automated decision-making
No decisions are made solely by automated means, including profiling.
10. Links to third-party sites
The site links to external services (for example LinkedIn and the call booking service). When you open them, their own privacy notices apply.
11. Changes
This notice may be updated. The date of the latest revision is shown at the bottom of the page.
This English version is provided for convenience. In case of discrepancy, the Italian version prevails.
Last updated: