Privacy Policy

Welcome to the privacy and data processing page of ClickCertificati. When you use our services, you entrust us with your information. This page describes our privacy practices so you can understand how we collect, use and share your data. Privacy legislation is very important to us, and we hope you will read this notice carefully.

1. Data Controller

The Data Controller for personal data collected through the platform www.clickcertificati.com is Claudio Arena (Italian VAT no. 03876350830), who can be contacted at:

Email: info@clickcertificati.com
Certified email (PEC): ufficiocertificati@legalmail.it
Registered office: Via Lombardia 12 – 98124 Messina, Italy

2. Personal data collected

The Data Controller collects the following categories of personal data:

2.1 Data provided directly by the user

When registering, requesting a Service or contacting the Data Controller, the user voluntarily provides data including: first and last name, tax identification number, residential address, email address and telephone number. For Services involving third parties (for example, a family member), the Client also provides the identifying details of the person to whom the requested document refers — first name, last name, date and place of birth.

Data may be collected through: the registration form, the Service request form, the contact form, the support chat, messaging services (such as WhatsApp), telephone or email.

2.2 Data collected automatically while browsing

While browsing the website, technical data is collected automatically, including: IP address, browser and device type, operating system, pages visited, duration of the visit and approximate geographic location. This data is collected through cookies, web beacons and similar tracking technologies, in accordance with the website’s Cookie Policy.

2.3 Data collected through social networks

If the user interacts with the Data Controller’s social media profiles (Facebook, Instagram, LinkedIn, YouTube) or uses the sharing buttons on the website, data may be collected in accordance with the respective privacy policies of those social platforms.

2.4 Special categories of data

The Data Controller does not intentionally collect or process special categories of personal data under Article 9 of the GDPR (health data, ethnic origin, political opinions, etc.). Should such data incidentally appear in the context of a requested document, it is processed exclusively for the purposes strictly necessary to perform the Service and on the basis of the conditions set out in Article 9(2) of the GDPR.

3. Purposes of processing and legal bases

Personal data collected is processed for the following purposes:

3.1 Provision of the Services — legal basis: performance of a contract (Art. 6.1.b GDPR)

Data is processed in order to manage Orders, perform the requested Services (obtaining certificates, apostille, sworn translations), communicate with the Client regarding the progress of their case, deliver the documents obtained and handle any refunds or complaints.

3.2 Tax and legal obligations — legal basis: legal obligation (Art. 6.1.c GDPR)

Billing data and accounting information are retained in order to comply with the tax and accounting obligations set out under Italian law (Presidential Decree 600/1973, Presidential Decree 633/1972 and subsequent amendments). Data is retained for the period required by law, including after the contractual relationship has ended.

3.3 Security and fraud prevention — legal basis: legitimate interest (Art. 6.1.f GDPR)

Browsing data and certain Order information are processed in order to prevent, detect and counter fraud, unlawful use of the Platform and security breaches. The Data Controller’s legitimate interest is to safeguard the integrity of the Platform and the security of all users.

3.4 Improving the Platform — legal basis: legitimate interest (Art. 6.1.f GDPR)

Browsing data collected through analytics tools (Google Analytics 4, configured with IP anonymisation, and Google Tag Manager) is used to analyse user behaviour on the Platform and improve the user experience.

3.5 Newsletter and marketing communications — legal basis: consent (Art. 6.1.a GDPR)

Subject to the user’s explicit consent, contact details are used to send newsletters, updates on new Services, articles and guides. Consent is entirely optional and may be withdrawn at any time by clicking the unsubscribe link included in every communication, or by contacting the Data Controller at info@clickcertificati.com.

3.6 Management of comments and reviews — legal basis: consent (Art. 6.1.a GDPR)

If the user posts a comment on the blog or a review of a Service, the data provided (name, email) is processed in order to publish and manage that contribution.

4. Data retention periods

Personal data is retained for as long as strictly necessary to achieve the purposes for which it was collected, in accordance with the principles of data minimisation and storage limitation set out in the GDPR:

  • Contract and Order data: for the entire duration of the contractual relationship and for 10 years thereafter, in accordance with tax and civil law obligations.
  • Billing data: 10 years from the date the tax document was issued, pursuant to Italian tax legislation (Presidential Decree 600/1973, Art. 22 and Presidential Decree 633/1972, Art. 39).
  • Browsing data and technical logs: a maximum of 12 months, except where required for the investigation of criminal offences or unlawful conduct.
  • Newsletter data: until the user withdraws consent.
  • Account data: until the user deletes their account, with the exception of data whose retention is required by law.

5. Sharing and disclosure of data

Personal data is not sold to third parties. It may, however, be disclosed — strictly to the extent necessary — to the following categories of recipients:

5.1 Third-party professionals appointed to carry out the Services

In order to carry out Additional Services (sworn translations), the Client’s data and the document to be translated are shared with the appointed sworn translator.

5.2 Public bodies and archives

In order to carry out the Basic Service, the identifying details of the person to whom the document refers are disclosed to the relevant comune, State Archive or parish archive, to the extent necessary to process the request.

5.3 Technology service providers

The Data Controller relies on third-party providers for the supply of technology services (hosting, email, payments, analytics). An up-to-date list of these providers is set out in Section 7.

5.4 Professional advisers

Data may be shared with accountants, lawyers or other professionals providing advice to the Data Controller, strictly to the extent necessary and subject to a duty of confidentiality.

5.5 Judicial and supervisory authorities

Data may be disclosed to the judicial authorities, law enforcement agencies, the Italian Data Protection Authority (Garante per la protezione dei dati personali) or other public authorities where required by law or by an order of the competent authority.

6. Transfer of data outside the European Union

The data collected is processed predominantly within the European Union. Some of the third-party providers used by the Data Controller (listed in Section 7) are based in, or process data in, the United States or other non-EU countries. For further information on these transfers and on the safeguards adopted by each provider, please refer to the respective privacy policies listed in Section 7.

7. Third-party providers

The main third-party providers used by the Data Controller are listed below, together with the service provided, their location and a link to their respective privacy policy.

7.1 Hosting and web platform

Rocket.net (onRocket.com LLC)
Service: Hosting and web infrastructure
Location: United States
Privacy Policy: https://rocket.net/privacy-policy/

WordPress (Automattic Inc.)
Service: CMS used to manage the website
Location: United States
Privacy Policy: https://automattic.com/privacy/

Google Fonts (Google LLC)
Service: Web font delivery service
Location: United States
Privacy Policy: https://policies.google.com/privacy

CookieYes Limited
Service: Cookie consent management and Cookie Policy
Location: Ireland / United Kingdom
Privacy Policy: https://www.cookieyes.com/privacy-policy/

7.2 Payments

Stripe Inc.
Service: Card payment processing
Location: United States
Privacy Policy: https://stripe.com/privacy

The Data Controller does not acquire or store payment card details. Such data is processed exclusively by Stripe Inc. in a secure, PCI-DSS certified environment.

7.3 Communications and messaging

Gmail (Google LLC)
Service: Email service
Location: United States
Privacy Policy: https://policies.google.com/privacy

Aruba S.p.A.
Service: Email hosting and cloud services
Location: Italy
Privacy Policy: https://www.aruba.it/documenti/italiano/pdf/informativa-privacy-aruba.aspx

Microsoft Corporation
Service: Document and database management (Microsoft 365)
Location: United States
Privacy Policy: https://privacy.microsoft.com/en-us/privacystatement

WhatsApp LLC (Meta Platforms)
Service: Messaging for customer support
Location: United States
Privacy Policy: https://www.whatsapp.com/legal/privacy-policy-eea

7.4 Newsletter and communications

Mailchimp (The Rocket Science Group LLC)
Service: Sending newsletters and communications by email
Location: United States
Privacy Policy: https://mailchimp.com/legal/privacy/

MailerLite (UAB MailerLite)
Service: Sending newsletters and communications by email
Location: Lithuania / EU
Privacy Policy: https://www.mailerlite.com/legal/privacy-policy

Newsletter subscription is optional. To unsubscribe, simply click the ‘Unsubscribe’ link at the bottom of any email received, or contact the Data Controller at info@clickcertificati.com.

7.5 Analytics and digital marketing

Google Analytics 4 (Google LLC)
Service: Analysis of website traffic and user behaviour (configured with IP anonymisation)
Location: United States
Privacy Policy: https://policies.google.com/privacy

Users may opt out of Google Analytics tracking by installing the browser add-on available at: https://tools.google.com/dlpage/gaoptout

Google Tag Manager (Google LLC)
Service: Centralised management of tracking tags
Location: United States
Privacy Policy: https://policies.google.com/privacy

Google Ads — Conversions (Google LLC)
Service: Measurement and optimisation of advertising campaigns
Location: United States
Privacy Policy: https://policies.google.com/privacy

Users may opt out of Google ad personalisation through their ad settings: https://adssettings.google.com/

7.6 Social networks

The website includes buttons linking to the Data Controller’s social media profiles as well as sharing buttons. The social networks concerned are: Facebook, Instagram, LinkedIn and YouTube (Meta Platforms / Google LLC).

8 Cookie Policy

 

What are cookies?

 

How do we use cookies?

 

Types of cookies we use

 

Manage cookie preferences

Consent Preferences

You can modify your cookie settings anytime by clicking the ‘Consent Preferences’ button above. This will allow you to revisit the cookie consent banner and update your preferences or withdraw your consent immediately.

Additionally, different browsers offer various methods to block and delete cookies used by websites. You can adjust your browser settings to block or delete cookies. Below are links to support documents on how to manage and delete cookies in major web browsers.

Chrome: https://support.google.com/accounts/answer/32050

Safari: https://support.apple.com/en-in/guide/safari/sfri11471/mac

Firefox: https://support.mozilla.org/en-US/kb/clear-cookies-and-site-data-firefox?redirectslug=delete-cookies-remove-info-websites-stored&redirectlocale=en-US

Internet Explorer: https://support.microsoft.com/en-us/topic/how-to-delete-cookie-files-in-internet-explorer-bca9446f-d873-78de-77ba-d42645fa52fc

If you are using a different web browser, please refer to its official support documentation.

9. Data security

The Data Controller implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction or accidental disclosure, in accordance with Article 32 of the GDPR. In particular:

  • The website uses the HTTPS protocol with an SSL/TLS certificate for the secure transmission of data
  • Access to internal systems is protected by credentials and secure authentication
  • Data is stored on servers with appropriate physical and logical security measures
  • Third-party providers are selected partly on the basis of the security guarantees they offer and are contractually bound to comply with high protection standards
  • The effectiveness of the security measures in place is reviewed periodically

10. Rights of data subjects

EU Regulation 2016/679 (GDPR) grants data subjects the following rights, which may be exercised at any time by contacting the Data Controller using the details set out in Section 1:

Right of access (Art. 15 GDPR): to obtain confirmation as to whether or not personal data concerning them is being processed and, if so, to access that data and the information relating to the processing (purposes, categories of data, recipients, retention period, etc.).

Right to rectification (Art. 16 GDPR): to obtain the rectification of inaccurate personal data or the completion of incomplete data.

Right to erasure / right to be forgotten (Art. 17 GDPR): to obtain the erasure of their personal data in the cases provided for by law (for example, data no longer necessary, withdrawal of consent, unlawful processing, legal obligation to erase), unless there are legitimate grounds requiring its retention (for example, legal obligations or the investigation of criminal offences).

Right to restriction of processing (Art. 18 GDPR): to obtain the restriction of processing in certain cases provided for by law (for example, where the accuracy of the data is contested, where processing is unlawful but the data subject opposes erasure, or where the data must be retained for the establishment or defence of legal claims).

Right to data portability (Art. 20 GDPR): to receive their personal data in a structured, commonly used and machine-readable format, and to transmit it to another controller where technically feasible, when processing is based on consent or on a contract and is carried out by automated means.

Right to object (Art. 21 GDPR): to object at any time to the processing of their personal data for direct marketing purposes (including profiling), or on grounds relating to their particular situation where processing is based on the Data Controller’s legitimate interest.

Right to withdraw consent: to withdraw at any time any consent given for purposes that require consent (newsletter, marketing cookies), without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal.

Right to lodge a complaint (Art. 77 GDPR): data subjects also have the right to lodge a complaint with a supervisory authority, in particular with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) or with the supervisory authority of the EU Member State in which they habitually reside or work.

How to exercise your rights

Requests may be submitted:
– By email to: info@clickcertificati.com
– By certified email (PEC) to: ufficiocertificati@legalmail.it
– By ordinary post to the address of the registered office

The Data Controller provides an initial acknowledgement of the request within 48 working hours. A final response is provided within one month of receipt of the request, in accordance with Article 12(3) of the GDPR. This deadline may be extended by a further two months where the request is particularly complex or where a high number of requests has been received; in such cases, the Data Controller will inform the data subject of the extension and the reasons for the delay within one month of the request.

11. Further information

Please note that this policy may be subject to change, and we therefore invite you to check this page regularly. For further information, you can contact us at the following email address: info@clickcertificati.com.

We also invite you to read our terms and conditions of service, as well as our frequently asked questions.