Via Sardegna 50 — 00187 Roma
TofaniLEGAL
Privacy notice · GDPR arts. 13-14

Privacy notice.

How Studio Legale Tofani processes personal data of visitors to tofani.legal, newsletter subscribers, and those who contact us for consultation. Current version last updated 19 April 2026.

1. Data Controller

The data controller is Studio Legale Tofani, with offices at Via Sardegna, 50, 00187 Roma (IT), VAT 10514750586, registered with the Ordine degli Avvocati di Roma.

For any matter relating to this notice, write to info@tofani.legal or call +39 06 42016048.

2. Data Protection Officer

The Firm has not appointed a DPO under GDPR art. 37 because the processing does not fall within the mandatory scenarios (public authority; large-scale processing of special categories; large-scale systematic monitoring).

Privacy requests can be addressed directly to the Controller at info@tofani.legal.

3. Data collected and purposes

3.1 Website navigation

DataPurposeLegal basisRetention
Pages visited, timestampsTechnical operation, securityLegitimate interest (art. 6.1.f)90 days
Country code (x-vercel-ip-country header)Aggregated geographic statisticsLegitimate interest90 days
User-agent (browser/device)Debugging, rendering optimizationLegitimate interest90 days
Pseudonymized session ID (tfn_sid, 30 min)Unique visitor countingLegitimate interest (technical analytic cookie)30 min sliding

No IP addresses are stored (the system explicitly discards the x-forwarded-for header before database write).

3.2 Contact form

If you contact us via /contacts or email we collect: name, surname, email, message content.

PurposeLegal basisRetention
Handling consultation requestsPre-contractual measures (art. 6.1.b)Up to 24 months from last contact, unless a professional mandate is engaged

3.3 Insights Newsletter subscription

DataPurposeLegal basisRetention
Email addressDelivery of editorial contributions by the Firm's lawyersExplicit consent (art. 6.1.a)Until consent withdrawn
IP at subscription + confirmationBurden of proof of consent (art. 7.1 GDPR)Legal obligation10 years (statute of limitations)
User-agentProof of consentLegal obligation10 years
Accepted notice versionProof of consentLegal obligation10 years

Double opt-in: enrollment finalizes only after clicking the confirmation link received by email. Withdrawal: click «unsubscribe» in any email (GDPR art. 7 + Italian Legislative Decree 70/2003 art. 13) or write to info@tofani.legal.

3.4 Client engagements

Personal data of clients and of counterparties involved in professional mandates are processed in compliance with art. 3 of the Italian Forensic Code of Ethics (professional secrecy) and anti-money-laundering law (Legislative Decree 231/2007). This website does not collect data within active engagements; any engagement-related processing uses separate secure channels (certified email, secure portals, in-office meetings).

4. Recipients and processors

ProcessorRoleLocationData transfer safeguard
Vercel Inc.Application hosting + CDNUSA (with EU edge)EU-US Data Privacy Framework (DPF)
Supabase Inc.Database + storage + authEU-West regionWithin EEA — no transfer
MailerSendTransactional email deliveryUSAStandard Contractual Clauses (SCC) + EU-US DPF
Google LLC (Fonts)Typography fonts served via CDNGoogle Fonts CDN if configured in Theme editor, otherwise bundledRuntime request to fonts.googleapis.com only if font CDN is enabled
Google LLC (Search Console)Indexing monitoringUSAEU-US DPF · Controller access to aggregated technical data

Data is not sold or transferred to third-party marketers.

5. Extra-EU transfers

Certain providers (Vercel, MailerSend) are U.S. entities. Transfer is grounded on:

  • EU-US Data Privacy Framework (EU Commission adequacy decision 10/07/2023) for certified providers (verifiable on dataprivacyframework.gov)
  • Standard Contractual Clauses (module C2P — controller to processor) under EU 2021/914 decision
  • Supplementary measures: TLS 1.2+ in transit, AES-256 at rest, tenant segregation, SOC 2 audit compliance

6. Your rights

As a data subject, you have the right to:

  • Access (art. 15)
  • Rectification (art. 16)
  • Erasure / right to be forgotten (art. 17)
  • Restriction (art. 18)
  • Portability (art. 20)
  • Objection (art. 21)
  • Withdraw consent (art. 7.3) — for consent-based processing (newsletter)
  • Lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome · www.garanteprivacy.it)

How to exercise: write to info@tofani.legal with subject line «GDPR rights request». Response within 30 days (extendable by 60 days in complex cases under art. 12 GDPR, with prior notice).

7. Data retention

In addition to the retention periods in Section 3, data is kept for statutory periods (tax, accounting, anti-money-laundering). At the end of retention, data is securely deleted or irreversibly anonymized.

8. Security

The Firm applies technical and organizational measures appropriate to the risk (art. 32 GDPR): TLS 1.2+, AES-256 at rest, MFA on privileged access, daily encrypted backups (30-day retention), access logging, 72-hour data breach notification procedure (art. 33 GDPR).

9. No automated decision-making

Data is not subject to profiling or automated decision-making as defined in GDPR art. 22.

10. Changes to this notice

The Controller reserves the right to amend this notice as applicable law requires. The current version is always at tofani.legal/en/privacy-notice. Newsletter subscribers are notified of substantial changes by email.


Last updated: 19 April 2026 · version: v1-2026-04