
Privacy and Cookie Policy
FinGreenTech SRL – Benefit Company | www.fingreentech.com
Updated – September 2026
This policy covers www.fingreentech.com and the www.fingreentech.it domain, which is redirected automatically to the former through network services provided by Cloudflare.
1. Data Controller
The controller of personal data collected through this website is:
FinGreenTech SRL – Benefit Company
Registered office: Via Rovereto 7 – 00198 Rome (RM), Italy
VAT and tax code: 16172421006
Share capital: EUR 50,000.00 fully paid up
Email: info@fingreentech.com
Certified email (PEC): info@pec.fingreentech.it
Web: www.fingreentech.com
FinGreenTech SRL SB holds ISO 9001, ISO 14001, ISO/IEC 20000-1, ISO 22301, ISO/IEC 27001, ISO/IEC 27017 and ISO/IEC 27018 certification, together with the ACN QC2 qualification as a certified cloud provider for the Italian Public Administration. Data processing is carried out in line with those standards and with Regulation (EU) 2016/679 (GDPR).
2. Data Protection Officer (DPO)
Under Article 37 GDPR, the controller has appointed a Data Protection Officer:
Francesco Gandolfi
DPO email: dpo@fingreentech.com
Any question about how we handle your data, or any request to exercise your rights, can be sent directly to that address.
3. What Data We Collect
3.1 Browsing the website
The website has no restricted areas and runs no active profiling. It does offer a contact form through which you may choose to send us personal data.
As you browse, our systems automatically record certain technical data inherent in the use of Internet protocols:
- IP address (used for security only, never cross-referenced with other data);
- browser type and operating system;
- date and time of the request;
- referring page and exit page.
This data is handled in aggregate, anonymous form for statistical and security purposes.
3.2 Data you provide voluntarily
The website offers contact forms and a live chat through which you may enter personal data such as your name, email address and the content of your message. Providing it is your choice, but we cannot answer your enquiry without it.
We use what you send us solely to handle your enquiry and any pre-contractual steps that follow. We will not use it for marketing without your explicit consent.
Nothing we do through this website involves automated decision-making or profiling within the meaning of Article 22 GDPR. We do not process special categories of data under Article 9 GDPR through this site.
4. Purposes, Legal Bases and Retention
| Purpose | Legal basis (Art. 6 GDPR) | Retention |
|---|---|---|
| Handling enquiries received via form, chat or email, including requests for commercial and pre-contractual information | (b) – pre-contractual measures taken at your request | up to 24 months after the relationship ends |
| Pre-sales and professional consulting activity, where you ask for it | (b) – performance of a contract or pre-contractual measures | duration of the engagement plus statutory periods |
| Legal, accounting and tax obligations | (c) – legal obligation | 10 years |
| Website security: protection against attacks, spam and unauthorised access | (f) – our legitimate interest | 30 days for security logs (IP), then deleted or anonymised |
| Aggregate statistics on how the website performs | (a) – consent, for non-technical cookies | 24 months in aggregate form |
| Commercial communications | (a) – consent | until consent is withdrawn |
| Legal defence and protection of our rights | (f) – our legitimate interest | duration of proceedings and applicable appeal periods |
5. Third-Party Tools and Services
The third-party providers we use for this website (hosting and network, analytics, consent management, live chat) process personal data on our behalf as data processors under Article 28 GDPR. Each relationship is governed by a Data Processing Agreement setting out our instructions and the technical and organisational measures in place. You can request the current, complete list of processors at any time by writing to dpo@fingreentech.com.
5.1 Cloudflare – CDN, security and redirection
We use Cloudflare, Inc. for content delivery, DNS, edge security and redirection of the fingreentech.it domain. It handles technical connection data (IP address, HTTP headers, routing data) on the basis of our legitimate interest in protecting our systems.
5.2 iubenda – Privacy and consent management
We use iubenda S.r.l. (Milan, Italy) to run the cookie policy and the banner that collects and records consent. More information: iubenda.com
5.3 Tidio – Chat service
The website includes the Tidio Ltd. live chat service, which may collect personal data such as your name, email address and message content. We use it to answer enquiries. More information: tidio.com
5.4 Google Analytics
We use Google Analytics (Google Ireland Ltd) for aggregate traffic statistics, only after you have given consent through the banner. You can also opt out by installing the browser add-on Google provides: opt-out tool
The service may transfer data to the United States, on the basis of the European Commission’s adequacy decision of 10 July 2023 on the EU-U.S. Data Privacy Framework, supplemented where applicable by the Standard Contractual Clauses (Decision (EU) 2021/914) under Articles 44 et seq. GDPR.
5.5 YouTube and social plugins
YouTube videos are embedded in enhanced privacy (no-cookie) mode, which holds back cookies until you interact with the video. Social buttons (LinkedIn, Facebook, Instagram) set cookies only once you click them. Where these services transfer data to the United States, the same EU-U.S. Data Privacy Framework and Standard Contractual Clauses apply.
6. Cookie Policy
6.1 Categories of cookies used
- Technical cookies (strictly necessary): needed for the website to work, for security, and to remember your cookie choice. Some expire when you close the browser; others last up to 12 months. No consent required (Art. 122, Italian Legislative Decree 196/2003).
- Functional cookies: improve the browsing experience (language, preferences). Consent required.
- Analytical cookies: measure visitor numbers and how the site is used, in aggregate. Consent required.
- Profiling and marketing cookies: we do not set any of our own. Any such cookies set by third parties are activated only after explicit consent and are managed entirely by those third parties.
6.2 Giving, changing or withdrawing consent
On your first visit a banner lets you accept, reject or customise the non-essential cookie categories. Until you make an explicit choice, only technical cookies are set: simply continuing to browse, scrolling the page or closing the banner does not count as consent.
You can change or withdraw your choices at any time, without detriment, using the cookie preferences button available on every page of the website, or through your browser settings:
Disabling technical cookies may stop parts of the website working; disabling third-party cookies may prevent videos, maps and social buttons from loading. A full, always-current list of individual cookies, with names, purposes, duration and owners, is available in the Cookie Policy maintained through iubenda and reachable from the preferences button.
This website does not support “Do Not Track” requests.
7. Where Data Is Processed and Transfers Outside the EU
Data is processed at our operating premises and at the certified data centres we use (Pisa – Vianova and Rome – Retelit/CONSIS), all located within the European Economic Area.
Some data may be transferred outside the EU, in particular to the United States for the third-party services listed in section 5, with appropriate safeguards under Articles 44-49 GDPR. You may ask us for details of the legal basis for any transfer and a copy of the safeguards in place.
8. Your Rights
Under Articles 15-22 GDPR you have the right to:
- access your data and obtain a copy of it (Art. 15);
- have inaccurate or incomplete data corrected (Art. 16);
- have your data erased (the “right to be forgotten”) where applicable (Art. 17);
- restrict processing in certain circumstances (Art. 18);
- receive your data in a structured, machine-readable format and have it ported elsewhere (Art. 20);
- object to processing based on legitimate interest on grounds relating to your particular situation and, with no need to give reasons, to processing for direct marketing (Art. 21);
- withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand;
- lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) or bring proceedings before the courts.
To exercise your rights, contact: info@fingreentech.com | dpo@fingreentech.com | PEC info@pec.fingreentech.it. Requests are handled free of charge within one month of receipt, extendable by a further two months for particularly complex requests, in which case we will tell you.
9. Security Measures
FinGreenTech SRL SB applies technical and organisational measures appropriate to the risk, consistent with the standards we are certified against (ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018):
- site-to-browser traffic encrypted with HTTPS (TLS);
- infrastructure protected by firewalls, intrusion detection systems and encryption;
- data access limited to authorised, trained personnel bound by confidentiality, on a least-privilege basis;
- encrypted backups and access logging;
- documented incident management, data breach handling and business continuity procedures under ISO 22301 and the NIS2 framework.
We maintain a Record of Processing Activities under Article 30 GDPR, kept current and compliant with applicable law.
10. Further Information
System logs and maintenance. For operational and maintenance reasons, this website and any third-party services it uses may collect system logs, which can contain personal data such as your IP address.
Service-specific notices. Where a specific service or a particular collection of data calls for it – in particular if you send us data to request consulting work or engage us professionally – we provide a separate notice at that point.
Third-party data. If you send us personal data relating to someone else, you confirm that you are entitled to do so and hold us harmless against any claim by that person.
11. Changes to This Policy
We may update this policy at any time, publishing changes on this page and updating the date shown below. Please check back periodically. Where changes affect processing based on consent, we will ask for your consent again if required.
12. Regulatory References
We are committed to the principles and good practice set out in the codes of conduct and industry standards that apply to personal data protection, information security and digital services.
- Regulation (EU) 2016/679 – GDPR, in particular Articles 13 and 14
- Italian Legislative Decree No. 196 of 30 June 2003 – Privacy Code (as amended by Legislative Decree 101/2018)
- Italian Data Protection Authority guidelines on cookies – No. 231 of 10 June 2021
- NIS2 Directive (EU) 2022/2555, transposed in Italy by Legislative Decree 138/2024
- Implementing Decision (EU) 2023/1795 – EU-U.S. Data Privacy Framework
Last updated: September 2026 – this policy replaces the March and April 2026 versions in full.