Privacy Policy
Welcome to the privacy and data processing page of ClickCertificati. When you use our services, you entrust us with your information. This page describes our privacy practices so you can understand how we collect, use and share your data. Privacy legislation is very important to us, and we hope you will read this notice carefully.
1. Data Controller
The Data Controller for personal data collected through the platform www.clickcertificati.com is Claudio Arena (Italian VAT no. 03876350830), who can be contacted at:
Email: info@clickcertificati.com
Certified email (PEC): ufficiocertificati@legalmail.it
Registered office: Via Lombardia 12 – 98124 Messina, Italy
2. Personal data collected
The Data Controller collects the following categories of personal data:
2.1 Data provided directly by the user
When registering, requesting a Service or contacting the Data Controller, the user voluntarily provides data including: first and last name, tax identification number, residential address, email address and telephone number. For Services involving third parties (for example, a family member), the Client also provides the identifying details of the person to whom the requested document refers — first name, last name, date and place of birth.
Data may be collected through: the registration form, the Service request form, the contact form, the support chat, messaging services (such as WhatsApp), telephone or email.
2.2 Data collected automatically while browsing
While browsing the website, technical data is collected automatically, including: IP address, browser and device type, operating system, pages visited, duration of the visit and approximate geographic location. This data is collected through cookies, web beacons and similar tracking technologies, in accordance with the website’s Cookie Policy.
2.3 Data collected through social networks
If the user interacts with the Data Controller’s social media profiles (Facebook, Instagram, LinkedIn, YouTube) or uses the sharing buttons on the website, data may be collected in accordance with the respective privacy policies of those social platforms.
2.4 Special categories of data
The Data Controller does not intentionally collect or process special categories of personal data under Article 9 of the GDPR (health data, ethnic origin, political opinions, etc.). Should such data incidentally appear in the context of a requested document, it is processed exclusively for the purposes strictly necessary to perform the Service and on the basis of the conditions set out in Article 9(2) of the GDPR.
3. Purposes of processing and legal bases
Personal data collected is processed for the following purposes:
3.1 Provision of the Services — legal basis: performance of a contract (Art. 6.1.b GDPR)
Data is processed in order to manage Orders, perform the requested Services (obtaining certificates, apostille, sworn translations), communicate with the Client regarding the progress of their case, deliver the documents obtained and handle any refunds or complaints.
3.2 Tax and legal obligations — legal basis: legal obligation (Art. 6.1.c GDPR)
Billing data and accounting information are retained in order to comply with the tax and accounting obligations set out under Italian law (Presidential Decree 600/1973, Presidential Decree 633/1972 and subsequent amendments). Data is retained for the period required by law, including after the contractual relationship has ended.
3.3 Security and fraud prevention — legal basis: legitimate interest (Art. 6.1.f GDPR)
Browsing data and certain Order information are processed in order to prevent, detect and counter fraud, unlawful use of the Platform and security breaches. The Data Controller’s legitimate interest is to safeguard the integrity of the Platform and the security of all users.
3.4 Improving the Platform — legal basis: legitimate interest (Art. 6.1.f GDPR)
Browsing data collected through analytics tools (Google Analytics 4, configured with IP anonymisation, and Google Tag Manager) is used to analyse user behaviour on the Platform and improve the user experience.
3.5 Newsletter and marketing communications — legal basis: consent (Art. 6.1.a GDPR)
Subject to the user’s explicit consent, contact details are used to send newsletters, updates on new Services, articles and guides. Consent is entirely optional and may be withdrawn at any time by clicking the unsubscribe link included in every communication, or by contacting the Data Controller at info@clickcertificati.com.
3.6 Management of comments and reviews — legal basis: consent (Art. 6.1.a GDPR)
If the user posts a comment on the blog or a review of a Service, the data provided (name, email) is processed in order to publish and manage that contribution.
4. Data retention periods
Personal data is retained for as long as strictly necessary to achieve the purposes for which it was collected, in accordance with the principles of data minimisation and storage limitation set out in the GDPR:
- Contract and Order data: for the entire duration of the contractual relationship and for 10 years thereafter, in accordance with tax and civil law obligations.
- Billing data: 10 years from the date the tax document was issued, pursuant to Italian tax legislation (Presidential Decree 600/1973, Art. 22 and Presidential Decree 633/1972, Art. 39).
- Browsing data and technical logs: a maximum of 12 months, except where required for the investigation of criminal offences or unlawful conduct.
- Newsletter data: until the user withdraws consent.
- Account data: until the user deletes their account, with the exception of data whose retention is required by law.
5. Sharing and disclosure of data
Personal data is not sold to third parties. It may, however, be disclosed — strictly to the extent necessary — to the following categories of recipients:
5.1 Third-party professionals appointed to carry out the Services
In order to carry out Additional Services (sworn translations), the Client’s data and the document to be translated are shared with the appointed sworn translator.
5.2 Public bodies and archives
In order to carry out the Basic Service, the identifying details of the person to whom the document refers are disclosed to the relevant comune, State Archive or parish archive, to the extent necessary to process the request.
5.3 Technology service providers
The Data Controller relies on third-party providers for the supply of technology services (hosting, email, payments, analytics). An up-to-date list of these providers is set out in Section 7.
5.4 Professional advisers
Data may be shared with accountants, lawyers or other professionals providing advice to the Data Controller, strictly to the extent necessary and subject to a duty of confidentiality.
5.5 Judicial and supervisory authorities
Data may be disclosed to the judicial authorities, law enforcement agencies, the Italian Data Protection Authority (Garante per la protezione dei dati personali) or other public authorities where required by law or by an order of the competent authority.
6. Transfer of data outside the European Union
The data collected is processed predominantly within the European Union. Some of the third-party providers used by the Data Controller (listed in Section 7) are based in, or process data in, the United States or other non-EU countries. For further information on these transfers and on the safeguards adopted by each provider, please refer to the respective privacy policies listed in Section 7.
7. Third-party providers
The main third-party providers used by the Data Controller are listed below, together with the service provided, their location and a link to their respective privacy policy.
7.1 Hosting and web platform
Rocket.net (onRocket.com LLC)
Service: Hosting and web infrastructure
Location: United States
Privacy Policy: https://rocket.net/privacy-policy/
WordPress (Automattic Inc.)
Service: CMS used to manage the website
Location: United States
Privacy Policy: https://automattic.com/privacy/
Google Fonts (Google LLC)
Service: Web font delivery service
Location: United States
Privacy Policy: https://policies.google.com/privacy
CookieYes Limited
Service: Cookie consent management and Cookie Policy
Location: Ireland / United Kingdom
Privacy Policy: https://www.cookieyes.com/privacy-policy/
7.2 Payments
Stripe Inc.
Service: Card payment processing
Location: United States
Privacy Policy: https://stripe.com/privacy
The Data Controller does not acquire or store payment card details. Such data is processed exclusively by Stripe Inc. in a secure, PCI-DSS certified environment.
7.3 Communications and messaging
Gmail (Google LLC)
Service: Email service
Location: United States
Privacy Policy: https://policies.google.com/privacy
Aruba S.p.A.
Service: Email hosting and cloud services
Location: Italy
Privacy Policy: https://www.aruba.it/documenti/italiano/pdf/informativa-privacy-aruba.aspx
Microsoft Corporation
Service: Document and database management (Microsoft 365)
Location: United States
Privacy Policy: https://privacy.microsoft.com/en-us/privacystatement
WhatsApp LLC (Meta Platforms)
Service: Messaging for customer support
Location: United States
Privacy Policy: https://www.whatsapp.com/legal/privacy-policy-eea
7.4 Newsletter and communications
Mailchimp (The Rocket Science Group LLC)
Service: Sending newsletters and communications by email
Location: United States
Privacy Policy: https://mailchimp.com/legal/privacy/
MailerLite (UAB MailerLite)
Service: Sending newsletters and communications by email
Location: Lithuania / EU
Privacy Policy: https://www.mailerlite.com/legal/privacy-policy
Newsletter subscription is optional. To unsubscribe, simply click the ‘Unsubscribe’ link at the bottom of any email received, or contact the Data Controller at info@clickcertificati.com.
7.5 Analytics and digital marketing
Google Analytics 4 (Google LLC)
Service: Analysis of website traffic and user behaviour (configured with IP anonymisation)
Location: United States
Privacy Policy: https://policies.google.com/privacy
Users may opt out of Google Analytics tracking by installing the browser add-on available at: https://tools.google.com/dlpage/gaoptout
Google Tag Manager (Google LLC)
Service: Centralised management of tracking tags
Location: United States
Privacy Policy: https://policies.google.com/privacy
Google Ads — Conversions (Google LLC)
Service: Measurement and optimisation of advertising campaigns
Location: United States
Privacy Policy: https://policies.google.com/privacy
Users may opt out of Google ad personalisation through their ad settings: https://adssettings.google.com/
7.6 Social networks
The website includes buttons linking to the Data Controller’s social media profiles as well as sharing buttons. The social networks concerned are: Facebook, Instagram, LinkedIn and YouTube (Meta Platforms / Google LLC).
8 Cookie Policy
What are cookies?
How do we use cookies?
Types of cookies we use
Manage cookie preferences
Consent PreferencesYou can modify your cookie settings anytime by clicking the ‘Consent Preferences’ button above. This will allow you to revisit the cookie consent banner and update your preferences or withdraw your consent immediately.
Additionally, different browsers offer various methods to block and delete cookies used by websites. You can adjust your browser settings to block or delete cookies. Below are links to support documents on how to manage and delete cookies in major web browsers.
Chrome: https://support.google.com/accounts/answer/32050
Safari: https://support.apple.com/en-in/guide/safari/sfri11471/mac
Internet Explorer: https://support.microsoft.com/en-us/topic/how-to-delete-cookie-files-in-internet-explorer-bca9446f-d873-78de-77ba-d42645fa52fc
If you are using a different web browser, please refer to its official support documentation.
9. Data security
The Data Controller implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction or accidental disclosure, in accordance with Article 32 of the GDPR. In particular:
- The website uses the HTTPS protocol with an SSL/TLS certificate for the secure transmission of data
- Access to internal systems is protected by credentials and secure authentication
- Data is stored on servers with appropriate physical and logical security measures
- Third-party providers are selected partly on the basis of the security guarantees they offer and are contractually bound to comply with high protection standards
- The effectiveness of the security measures in place is reviewed periodically
10. Rights of data subjects
EU Regulation 2016/679 (GDPR) grants data subjects the following rights, which may be exercised at any time by contacting the Data Controller using the details set out in Section 1:
Right of access (Art. 15 GDPR): to obtain confirmation as to whether or not personal data concerning them is being processed and, if so, to access that data and the information relating to the processing (purposes, categories of data, recipients, retention period, etc.).
Right to rectification (Art. 16 GDPR): to obtain the rectification of inaccurate personal data or the completion of incomplete data.
Right to erasure / right to be forgotten (Art. 17 GDPR): to obtain the erasure of their personal data in the cases provided for by law (for example, data no longer necessary, withdrawal of consent, unlawful processing, legal obligation to erase), unless there are legitimate grounds requiring its retention (for example, legal obligations or the investigation of criminal offences).
Right to restriction of processing (Art. 18 GDPR): to obtain the restriction of processing in certain cases provided for by law (for example, where the accuracy of the data is contested, where processing is unlawful but the data subject opposes erasure, or where the data must be retained for the establishment or defence of legal claims).
Right to data portability (Art. 20 GDPR): to receive their personal data in a structured, commonly used and machine-readable format, and to transmit it to another controller where technically feasible, when processing is based on consent or on a contract and is carried out by automated means.
Right to object (Art. 21 GDPR): to object at any time to the processing of their personal data for direct marketing purposes (including profiling), or on grounds relating to their particular situation where processing is based on the Data Controller’s legitimate interest.
Right to withdraw consent: to withdraw at any time any consent given for purposes that require consent (newsletter, marketing cookies), without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal.
Right to lodge a complaint (Art. 77 GDPR): data subjects also have the right to lodge a complaint with a supervisory authority, in particular with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) or with the supervisory authority of the EU Member State in which they habitually reside or work.
How to exercise your rights
Requests may be submitted:
– By email to: info@clickcertificati.com
– By certified email (PEC) to: ufficiocertificati@legalmail.it
– By ordinary post to the address of the registered office
The Data Controller provides an initial acknowledgement of the request within 48 working hours. A final response is provided within one month of receipt of the request, in accordance with Article 12(3) of the GDPR. This deadline may be extended by a further two months where the request is particularly complex or where a high number of requests has been received; in such cases, the Data Controller will inform the data subject of the extension and the reasons for the delay within one month of the request.
11. Further information
Please note that this policy may be subject to change, and we therefore invite you to check this page regularly. For further information, you can contact us at the following email address: info@clickcertificati.com.
We also invite you to read our terms and conditions of service, as well as our frequently asked questions.
