Notice

Privacy

Essential information on personal data processing through bethlen.it.

Last updated: July 10, 2026.

Controller and contact details

The controller is Andrea Bethlen, operator of bethlen.it. The protected contact form can be used for privacy inquiries and to exercise data protection rights.

Data processed and source

Data is collected directly from the data subject. The following data is processed through the form: name, email address, optional company, request area, and message. The server also processes technical data strictly necessary for operation and security, including IP address, date and time, session identifiers, anti-spam tokens, and technical logs.

Purposes and legal bases

  • Replies and pre-contractual steps: processing is necessary to reply and take pre-contractual steps at the data subject’s request (Article 6(1)(b) GDPR).
  • Non-contractual information requests: processing is based on the controller’s legitimate interest in managing incoming communications and providing the response requested by the data subject (Article 6(1)(f) GDPR).
  • Security and abuse prevention: technical data is processed to protect the site, form and email service from automated submissions, fraud and unlawful use, based on the controller’s legitimate interest in system security (Article 6(1)(f) GDPR).
  • Legal obligations and data subject requests: data may be processed to comply with administrative, tax or other legal obligations and to handle requests under Articles 12-22 GDPR (Article 6(1)(c) GDPR).

Form data is not used for newsletters, profiling or promotional communications.

Required and optional data

Providing data is voluntary. If you choose to use the form, name, email, message, and acknowledgment of this notice are technically required to submit the request and receive a reply; company is optional. Without the required data, the form cannot be submitted. Selecting the checkbox confirms that the notice has been read and does not constitute consent to additional purposes; the acknowledgment is not recorded as consent.

Processing and retention

Data is processed electronically using measures proportionate to the risk. Contact requests are retained for the time needed to handle the communication and any follow-up, then periodically reviewed and deleted when no longer necessary. They may be retained longer if they become part of a contractual relationship, if required by law, or if needed to establish, exercise, or defend a legal claim.

Anti-abuse counter events are retained for no more than 24 hours. Inactive technical files become eligible for deletion after 48 hours and are removed at the first available cleanup cycle during later form activity; they are not reused for profiling. The cookie expires when the browser is closed, and the server session is configured with a maximum inactivity period of 30 minutes. Infrastructure logs are retained by the technical provider according to the criteria necessary for security and service delivery.

Recipients and processors

Data may be processed by authorized persons and by Register S.p.A., the hosting and email provider. For processing performed on the controller’s behalf, the provider acts in the role and under the terms set out in the contract and the data processing agreement required by Article 28 GDPR. Data may also be disclosed to advisors or authorities where necessary to meet legal obligations or to establish, exercise, or defend legal claims. Data is not sold, publicly disclosed, or transferred for commercial purposes.

International transfers

The site does not embed third-party services that directly transfer browsing data outside the European Economic Area. Processing locations, any sub-processors, and transfers connected with hosting and email depend on the provider’s current contractual documentation. Transfers to third countries must comply with Articles 44 et seq. of the GDPR through an adequacy decision or appropriate safeguards. Information on applicable safeguards can be requested from the controller through the contact form.

Technical cookie and no tracking

The site uses only the first-party technical cookie bethlen_contact. It lasts for the browser session and uses the Secure, HttpOnly, and SameSite=Strict attributes. It associates the single-use token with the browser and protects the form. No profiling or advertising cookies, third-party analytics, or fingerprinting technologies are used.

Data subject rights

Where applicable, Articles 15-22 GDPR provide rights of access, rectification, erasure, restriction of processing, data portability, and objection. Requests can be submitted through the contact form and will be answered within the time limits under Article 12 GDPR.

Right to object: where processing is based on legitimate interests (Article 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation. The controller will stop processing unless compelling legitimate grounds prevail or processing is necessary to establish, exercise or defend a legal claim.

You may also lodge a complaint with the Italian Data Protection Authority under Article 77 GDPR or seek a judicial remedy.

Automated processing and message security

No automated decision-making producing legal or similarly significant effects, or profiling, takes place. Automated form checks are used solely to prevent abuse and repeated submissions.

Do not send passwords, credentials, health data, financial information, or other highly confidential data. If sensitive information is involved, agree on a suitable channel first.