Alessandro Del Ninno
Privacy Notice

Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679

Last updated: 29 July 2026

Download the privacy notice pursuant to Art. 13 of the GDPR (with a navigable table of contents).

1. Purpose and scope of this Privacy Notice

This Privacy Notice describes how Alessandro del Ninno, acting as data controller, processes the personal data of:

  • users who visit the website www.alessandrodelninno.it;
  • individuals who submit enquiries or requests to be contacted;
  • prospective clients and existing clients;
  • representatives, employees, contractors and contact persons of companies, public bodies and other organisations;
  • individuals involved, in any capacity, in legal advisory, assistance and representation activities;
  • participants in conferences, seminars, workshops and specialist training programmes;
  • professionals, consultants, service providers and other individuals with whom professional or organisational relationships are maintained.

This Privacy Notice applies to processing activities carried out directly by Alessandro del Ninno in his capacity as the controller of the website and in connection with professional activities directly attributable to him.
Where an engagement or a specific professional activity is entrusted to a different professional organisation, professional partnership or other legal entity, the related processing activities will also be governed by the privacy notice issued by the entity accepting the engagement in its capacity as data controller.


2. Identity and contact details of the data controller
The data controller is:
Alessandro del Ninno – Lawyer
Professional address: Via del Governo Vecchio 121 – 00186 Rome, Italy
VAT number: 06074801009
Member of the Rome Bar: Registration No A26640
Certified email address (PEC): alessandrodelninno@ordineavvocatiroma.org
Enquiries concerning the processing of personal data and requests to exercise data protection rights may be submitted to the certified email address indicated above or through the additional contact details published in the “Contacts” section of the website.


3. Applicable legislation and principles governing the processing
Personal data are processed in accordance with:

  • Regulation (EU) 2016/679, hereinafter the “GDPR”;
  • Italian Legislative Decree No 196 of 30 June 2003, as subsequently amended and supplemented, hereinafter the “Italian Data Protection Code”;
  • the laws and professional rules applicable to the legal profession;
  • the professional conduct rules governing processing activities carried out for the purposes of defence investigations or the establishment, exercise or defence of legal claims;
  • the applicable legislation on the prevention of money laundering and terrorist financing;
  • any other national and European Union provisions applicable to the relevant processing activities.

Personal data are processed in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability.


4. Categories of personal data processed
Depending on the purposes described in this Privacy Notice, the following categories of personal data may be processed.
Identification and personal details, including first name, surname, place and date of birth, tax identification number, identification document details, nationality, residential address, domicile and signature.
Contact details, including postal address, email address, certified email address, telephone number and other professional or personal contact details.
Professional and organisational information, including job title, role, company or organisation, employment or professional position, representative powers, powers of attorney, delegations and information relating to professional or business activities.
Financial, asset-related, banking, accounting and tax information, where required for issuing fee proposals, managing professional engagements, invoicing, processing payments, complying with tax requirements, carrying out anti-money laundering checks and managing disputes.
Data relating to professional engagements, including communications, documents, correspondence, agreements, legal instruments, legal opinions, corporate information, data concerning judicial, arbitration, administrative, disciplinary, mediation or negotiation proceedings and any other information necessary to provide legal advice, assistance or representation.
Special categories of personal data within the meaning of Article 9 GDPR, including, where strictly necessary in connection with an engagement, data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, as well as genetic data, biometric data, data concerning health or data concerning a person’s sex life or sexual orientation.
Personal data relating to criminal convictions and offences, proceedings and related security measures, within the meaning of Article 10 GDPR and Article 2-octies of the Italian Data Protection Code, where their processing is authorised by applicable law and necessary for the performance of professional activities.
Personal data relating to third parties, including counterparties, employees, directors, contractors, witnesses, consultants, professionals, family members, injured parties, persons under investigation, defendants or other individuals involved in the matters in respect of which legal assistance is provided.
Browsing and technical data, including IP addresses, device identifiers, browser and operating system information, request times, pages visited, technical logs and other information required for the operation, security and protection of the website.
Data contained in unsolicited applications, including curricula vitae, professional experience, educational qualifications and any additional information voluntarily provided by the applicant.
Users are requested not to submit through the website forms or by email any personal data that are unnecessary for the purposes of their enquiry, particularly special categories of personal data or personal data relating to criminal convictions and offences. Such data may nevertheless be processed where they are indispensable for assessing or carrying out the requested professional activity.


5. Sources of personal data
Personal data may be collected directly from the data subject, for example when the data subject:
•    visits the website;
•    completes a contact form;
•    sends a communication by email or certified email;
•    requests an appointment, information, a fee proposal or a legal opinion;
•    instructs the data controller to provide professional services;
•    participates in a conference, workshop or training programme;
•    submits an application or a proposal for professional collaboration.
In the course of professional activities, personal data may also be obtained from sources other than the data subject, including:
•    clients and prospective clients;
•    companies, public bodies or other organisations to which the data subject belongs;
•    counterparties and their professional advisers;
•    judicial, administrative, independent or supervisory authorities;
•    mediation, arbitration and alternative dispute resolution bodies;
•    consultants, experts, investigators, notaries and other professionals;
•    witnesses and persons with knowledge of relevant facts;
•    public registers, professional registers, databases and archives;
•    publicly accessible sources;
•    providers of professional information and verification services, within the limits permitted by law.
Where personal data have not been obtained directly from the data subject, the information required under Article 14 GDPR will be provided within the time limits and in accordance with the procedures laid down by applicable law, unless one of the relevant exemptions applies.
In particular, the information may not be provided, or its provision may be deferred, where providing it proves impossible, would involve a disproportionate effort, is likely to render impossible or seriously impair the achievement of the purposes of the processing, or where the personal data must remain confidential pursuant to an obligation of professional secrecy or another statutory obligation of confidentiality.


6. Purposes and legal bases of the processing
6.1. Website browsing, operation and security
Technical and browsing data are processed in order to:
•    enable access to and the proper operation of the website;
•    manage the technical infrastructure and network communications;
•    ensure the security of the website, systems and information;
•    prevent, detect and address unauthorised access, cyberattacks, fraud, abuse and other security events;
•    perform technical maintenance and resolve malfunctions;
•    establish liability in the event of unlawful conduct affecting information systems.
The legal basis for the processing is the legitimate interest pursued by the controller in ensuring the operation, continuity and security of the website and related systems, pursuant to Article 6(1)(f) GDPR and, where applicable, compliance with a legal obligation to which the controller is subject pursuant to Article 6(1)(c) GDPR.
The legitimate interest is pursued by limiting the processing to the data and periods strictly necessary and by implementing measures designed to minimise the impact of the processing on data subjects.
6.2. Management of enquiries and requests for information
Personal data are processed in order to:
•    respond to enquiries submitted through the website, by email, certified email or telephone;
•    provide information concerning professional activities;
•    arrange appointments and preliminary discussions;
•    assess the nature of the matter submitted;
•    prepare proposals, fee quotations and terms of engagement;
•    take steps at the request of the data subject prior to entering into a contract.
Where the request is submitted directly by the data subject with a view to a possible professional engagement, the legal basis is the taking of steps at the request of the data subject prior to entering into a contract, pursuant to Article 6(1)(b) GDPR.
Where the request is submitted by a contact person, employee, director or contractor on behalf of a company, public body or other organisation, the legal basis is the legitimate interest in managing the request and the professional relationship with the organisation represented, pursuant to Article 6(1)(f) GDPR.
6.3. Identity checks, conflict checks and acceptance of professional engagements
Before accepting a professional engagement, personal data may be processed in order to:
•    identify the prospective client and the individuals involved;
•    verify representative powers;
•    establish whether any conflict of interests exists;
•    protect independence, confidentiality and the proper practice of the legal profession;
•    determine whether the engagement may legally and professionally be accepted;
•    carry out, where applicable, anti-money laundering, sanctions-screening and client due diligence checks.
The applicable legal bases are:
•    compliance with legal and professional obligations, pursuant to Article 6(1)(c) GDPR;
•    the legitimate interest in preventing conflicts of interest, protecting clients, ensuring the proper practice of the legal profession and safeguarding the rights of the controller and third parties, pursuant to Article 6(1)(f) GDPR;
•    the taking of steps prior to entering into a contract, where the checks are necessary to assess whether the engagement requested by the data subject may be accepted, pursuant to Article 6(1)(b) GDPR.
6.4. Performance of professional engagements
Personal data are processed for the purpose of carrying out the activities requested by the client, including, by way of example:
•    providing legal advice and assistance;
•    preparing legal opinions, advisory notes, memoranda and legal assessments;
•    drafting, reviewing and negotiating agreements, policies, procedures and other documents;
•    performing legal compliance reviews, due diligence exercises and legal audits;
•    managing complaints, challenges, formal notices and proceedings;
•    providing assistance in negotiations, mediation, arbitration and alternative dispute resolution procedures;
•    representing, assisting and defending clients before judicial, administrative, independent, regulatory or supervisory authorities;
•    conducting defence investigations and gathering evidence within the limits permitted by law;
•    coordinating with other lawyers, consultants, experts, technical advisers and professionals;
•    managing communications and activities necessary for the proper performance of the engagement;
•    providing assistance in the fields of technology law, data protection, the regulation of personal and non-personal data, artificial intelligence, cybersecurity, Information and Communication Technology, intellectual and industrial property, media and domain names;
•    carrying out any other contentious or non-contentious activity falling within the practice of law.
Where the client is a natural person, the legal basis is the performance of a contract for professional legal services, pursuant to Article 6(1)(b) GDPR.
As regards the personal data of representatives, employees, contractors and contact persons of the client or of other organisations involved, the legal basis is the legitimate interest in properly performing the professional engagement and managing professional relationships, pursuant to Article 6(1)(f) GDPR.
Where processing is necessary for compliance with statutory or professional obligations, Article 6(1)(c) GDPR also applies.
6.5. Establishment, exercise or defence of legal claims
Personal data may be processed in order to:
•    establish, exercise or defend the rights of the client, the controller or third parties;
•    develop legal and defence strategies;
•    retain and use documents, communications and evidence;
•    manage disputes, complaints, damages claims and proceedings;
•    recover professional fees;
•    manage complaints or challenges relating to professional engagements or services provided;
•    activate or manage professional indemnity insurance cover.
The legal basis is the legitimate interest in the establishment, exercise or defence of legal claims, pursuant to Article 6(1)(f) GDPR.
Where special categories of personal data are involved, the processing is also based, where applicable, on Article 9(2)(f) GDPR.
6.6. Administrative, accounting, tax and professional compliance
Personal data are processed in order to:
•    maintain client and engagement records;
•    issue fee proposals, fee notes and invoices;
•    record and verify payments;
•    comply with tax, accounting, social security and insurance obligations;
•    manage professional files, records and documentation;
•    comply with requests and inspections carried out by competent authorities;
•    comply with professional, anti-money laundering and counter-terrorist financing obligations.
The legal basis is compliance with legal obligations to which the controller is subject, pursuant to Article 6(1)(c) GDPR.
Administrative activities strictly necessary for the performance of a professional engagement may also be based on Article 6(1)(b) GDPR.
6.7. Conferences, seminars, workshops and specialist training
Personal data may be processed in order to:
•    respond to enquiries relating to conferences, seminars and workshops;
•    organise meetings and specialist training programmes;
•    manage registrations, attendance, organisational communications and training materials;
•    prepare training proposals and related fee quotations;
•    perform teaching, training or professional development engagements;
•    issue certificates of attendance, where applicable;
•    manage the related administrative and tax requirements.
Where the data subject acts in his or her own capacity, the legal basis is the taking of steps prior to entering into a contract or the performance of a contract, pursuant to Article 6(1)(b) GDPR.
As regards contact persons of companies, public bodies and other organisations, the legal basis is the legitimate interest in organising and delivering the activity requested by the organisation represented, pursuant to Article 6(1)(f) GDPR.
Related accounting and tax compliance is based on Article 6(1)(c) GDPR.
6.8. Requests concerning professional collaboration, interviews, publications and academic initiatives
Personal data may be processed in order to manage:
•    invitations to participate in conferences, round tables and academic initiatives;
•    requests for interviews or media appearances;
•    publishing proposals and editorial contributions;
•    professional, academic or training collaborations;
•    relationships with journalists, publishers, universities, training providers and event organisers.
The legal basis is the taking of steps at the request of the data subject prior to entering into a contract, pursuant to Article 6(1)(b) GDPR, or the legitimate interest in managing professional and institutional relationships, pursuant to Article 6(1)(f) GDPR.
6.9. Unsolicited applications
Personal data contained in curricula vitae or unsolicited applications are processed for the purpose of assessing possible professional collaborations, traineeships or other working arrangements.
The legal basis is the taking of steps at the request of the data subject prior to entering into a contract, pursuant to Article 6(1)(b) GDPR.
Applicants are requested not to include in their curricula vitae any special categories of personal data that are not relevant to the application.
6.10. Management of data protection requests
Personal data are also processed in order to:
•    receive and manage requests to exercise data protection rights;
•    verify the identity of the requesting individual;
•    provide a response;
•    demonstrate compliance with the obligations laid down by the GDPR;
•    manage complaints or communications with the Italian Data Protection Authority.
The legal basis is compliance with legal obligations pursuant to Article 6(1)(c) GDPR and, in the event of a dispute, the legitimate interest in defending legal rights pursuant to Article 6(1)(f) GDPR.


7. Processing of special categories of personal data and personal data relating to criminal convictions and offences
The performance of professional activities may require the processing of special categories of personal data or personal data relating to criminal convictions, offences, proceedings and related security measures.
Special categories of personal data are processed only where one of the conditions set out in Article 9(2) GDPR applies and, in particular:
•    where processing is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in their judicial capacity, pursuant to Article 9(2)(f);
•    where processing is necessary for reasons of substantial public interest, on the basis of Union or Member State law, pursuant to Article 9(2)(g);
•    where processing relates to personal data which are manifestly made public by the data subject, pursuant to Article 9(2)(e);
•    in residual circumstances, where processing is based on the data subject’s explicit consent and consent constitutes an appropriate legal basis.
Personal data relating to criminal convictions and offences are processed in accordance with Article 10 GDPR, Article 2-octies of the Italian Data Protection Code and any other provisions authorising such processing in connection with contentious, non-contentious and defence-related legal activities.
Such data are processed only where relevant and necessary to the matter entrusted to the lawyer and subject to appropriate safeguards for the rights and freedoms of data subjects.


8. Nature of the provision of personal data and consequences of failure to provide them
The provision of personal data required to respond to an enquiry, assess or accept a professional engagement, comply with identification requirements, perform professional activities or comply with legal obligations is necessary.
Failure to provide the required personal data may make it impossible to:
•    provide a complete response;
•    prepare a fee proposal;
•    assess or accept the engagement;
•    provide the requested professional services;
•    enable participation in a training activity or event;
•    establish or continue the requested relationship.
The provision of personal data that are not necessary for the specific request is optional.
Users may continue to access the publicly available pages of the website, without prejudice to the technical data automatically generated by information systems and necessary for the operation and security of the website.


9. Methods of processing and security measures
Personal data are processed using paper-based, electronic and telematic means, in a manner consistent with the purposes described in this Privacy Notice.
Technical and organisational measures appropriate to the level of risk are implemented to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data and against any other processing that is unlawful or inconsistent with the stated purposes.
Access to personal data is restricted to individuals who require such access for the performance of their respective duties and is governed by authorisation, confidentiality and data minimisation principles.
Personal data processed in connection with the practice of law are also protected by legal professional privilege, professional secrecy and any additional confidentiality obligations imposed by law and applicable professional rules.


10. Recipients of personal data
To the extent necessary for the purposes pursued, personal data may be disclosed to the following categories of recipients:
•    employees, trainees, contractors and other persons authorised to process personal data;
•    local counsel, correspondent lawyers, consultants, experts, notaries, translators, investigators and other professionals involved in an engagement;
•    judicial, administrative, independent, regulatory, tax, law-enforcement or supervisory authorities;
•    court registries, administrative offices, enforcement officers, mediation bodies, arbitration institutions and other competent bodies;
•    counterparties, their legal advisers and other individuals involved in negotiations, legal assistance or defence activities, where disclosure is necessary;
•    providers of information technology, hosting, email, certified email, cloud, storage, security, maintenance and technical support services;
•    providers of administrative, accounting, tax, banking, insurance and payment services;
•    service providers and organisers involved in conferences, seminars or training activities;
•    persons or entities to whom disclosure is required by law, regulation or an order issued by a competent authority, or is otherwise necessary for compliance with statutory or professional obligations.
Where the applicable requirements are met, entities processing personal data on behalf of the controller are appointed as processors pursuant to Article 28 GDPR.
Other recipients process personal data as independent controllers on the basis of their respective powers and responsibilities.
Personal data are not made available to the general public, unless publication is required by law, strictly necessary for a specific purpose or expressly authorised by the data subject on the basis of an appropriate legal ground.


11. Transfers of personal data outside the European Economic Area
The controller gives preference to service providers that process personal data within the European Economic Area.
Where the use of a specific service involves the transfer of personal data to a country outside the European Economic Area or to an international organisation, the transfer will be carried out in accordance with Articles 44 et seq. GDPR.
In particular, the transfer may be based on:
•    an adequacy decision adopted by the European Commission;
•    standard contractual clauses adopted by the European Commission;
•    another transfer mechanism provided for under the GDPR;
•    exceptionally, one of the derogations laid down in Article 49 GDPR.
Where necessary, supplementary measures will be assessed and implemented in order to ensure a level of protection essentially equivalent to that guaranteed within the European Union.
Further information concerning the safeguards applied may be requested from the controller using the contact details set out in this Privacy Notice.


12. Strictly necessary cookies
The website uses exclusively technical or strictly necessary cookies and other tools that are essential for enabling browsing, ensuring the proper operation of its pages, maintaining website security, managing the functions requested by the user and transmitting communications over an electronic communications network.
Strictly necessary cookies are used solely for functional and security purposes. They are not used to analyse or profile users, determine their preferences, monitor their browsing behaviour for commercial purposes or deliver personalised advertising.
The website does not use first-party or third-party profiling cookies.
Since the cookies used are strictly necessary for the operation of the website and the provision of functions expressly requested by the user, their storage does not require the user’s prior consent.
Users may nevertheless configure their browser to receive notifications concerning cookies, inspect their characteristics or prevent their storage. Disabling strictly necessary cookies may, however, impair the proper operation of the website or prevent certain functions from being used.
Detailed information on the strictly necessary cookies actually used, their purposes and their duration may be provided in a separate Cookie Policy available through the website.


13. Retention periods
Personal data are retained for periods proportionate to the purposes for which they were collected, taking into account statutory and professional obligations, applicable limitation periods and the need to safeguard the rights of the controller, clients and third parties.
In particular:
Personal data relating to enquiries or contact requests that do not result in a professional engagement: such data are ordinarily retained for no longer than 90 days from the last substantive communication, unless a longer retention period is necessary to document the communications, perform conflict-of-interest checks, manage a dispute or comply with legal obligations.
Personal data used for conflict-of-interest checks: limited information may be retained for as long as may reasonably be necessary to prevent conflicts of interest, protect client confidentiality and comply with professional obligations, subject to periodic review of the need for continued retention.
Personal data relating to professional engagements: such data are retained for the duration of the engagement and, following its completion, ordinarily for ten years, unless a longer period is necessary due to ongoing proceedings, statutory obligations, limitation periods, disputes, professional liability considerations or the need to establish, exercise or defend legal claims.
Administrative, accounting and tax documentation: such documentation is retained for the period required by applicable law, ordinarily ten years, without prejudice to any longer period resulting from pending audits, investigations or proceedings.
Personal data processed for anti-money laundering compliance: such data are retained for the period prescribed by applicable legislation, ordinarily ten years following termination of the ongoing relationship, completion of the professional service or performance of the occasional transaction.
Personal data relating to conferences, workshops and training activities: such data are retained for the period necessary to organise and deliver the relevant activity. Administrative, accounting and tax data are retained for the statutory periods, while enquiries that do not result in an engagement or participation are ordinarily retained for no longer than 90 days.
Unsolicited applications: such data are ordinarily retained for no longer than twelve months from receipt, unless a professional relationship is established or the applicant requests that the information be updated.
Personal data relating to the exercise of data protection rights: such data are retained for the period necessary to manage the request and, subsequently, for as long as is necessary to demonstrate compliance with applicable data protection obligations.
Browsing data and security logs: such data are retained for the period strictly necessary to ensure the operation, security and protection of the website and are ordinarily deleted within 30 days of collection, unless a longer period is necessary to investigate a security incident, establish liability, protect a legal right or comply with a request from a competent authority.
Strictly necessary cookies: session cookies are deleted when the browser is closed, while any persistent technical cookies are retained solely for the period strictly necessary to perform the technical or security function for which they are stored, as may be further specified in the Cookie Policy.
Upon expiry of the applicable retention periods, personal data are erased, anonymised or retained solely where this is necessary to comply with a statutory obligation or protect a legal right.


14. Personal data relating to children
The website and the professional services described on it are not specifically directed at children and do not provide for the independent registration of underage users.
Where personal data relating to children are processed in connection with a professional engagement, dispute or other legal matter, they will be processed only where necessary, in accordance with applicable law and with particular regard to the protection of the child’s rights and interests.


15. Automated decision-making and profiling
Personal data are not used to make decisions based solely on automated processing, including profiling, which produce legal effects concerning the data subject or similarly significantly affect him or her.
No decision-making profiling activities are carried out for the purposes described in this Privacy Notice.
Any use of automated support tools does not replace human professional judgement and takes place in accordance with the principles of necessity, proportionality, confidentiality and security.


16. Rights of the data subject
In the circumstances and subject to the conditions laid down by the GDPR, data subjects may exercise the following rights.
Right of access: the right to obtain confirmation as to whether or not personal data concerning the data subject are being processed and, where that is the case, access to the personal data and the information listed in Article 15 GDPR.
Right to rectification: the right to obtain the rectification of inaccurate personal data and the completion of incomplete personal data pursuant to Article 16 GDPR.
Right to erasure: the right to obtain the erasure of personal data in the circumstances laid down in Article 17 GDPR, unless processing remains necessary, among other reasons, for compliance with a legal obligation or for the establishment, exercise or defence of legal claims.
Right to restriction of processing: the right to obtain restriction of processing in the circumstances laid down in Article 18 GDPR.
Right to data portability: the right to receive personal data provided by the data subject in a structured, commonly used and machine-readable format and to transmit those data to another controller, where the processing is carried out by automated means and is based on consent or on a contract, subject to the conditions and limitations laid down in Article 20 GDPR.
Right to object: the right to object, on grounds relating to the data subject’s particular situation, to processing based on legitimate interests pursuant to Article 21 GDPR. In such circumstances, the controller will cease processing the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or the processing is required for the establishment, exercise or defence of legal claims.
Right to withdraw consent: the right to withdraw any consent given at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Right not to be subject to automated individual decision-making: the right, in the circumstances laid down in Article 22 GDPR, not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning the data subject or similarly significantly affects him or her.
The above rights may be exercised free of charge by submitting a request to the controller using the certified email address or any other contact details provided in this Privacy Notice.
The controller may request such information as is strictly necessary to verify the identity of the requesting individual and prevent unauthorised access to or disclosure of personal data.
The controller will provide information on action taken on the request without undue delay and, in any event, ordinarily within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of requests. In such cases, the data subject will be informed of the extension and the reasons for the delay within one month of receipt of the request.
Where requests are manifestly unfounded or excessive, in particular because of their repetitive character, the controller may charge a reasonable fee or refuse to act on the request, within the limits laid down in Article 12 GDPR.
The exercise of data protection rights may be restricted or deferred in the circumstances provided for by applicable law, particularly where this is necessary to protect legal professional privilege, professional secrecy, the rights and freedoms of others or the establishment, exercise or defence of legal claims.


17. Right to lodge a complaint and judicial remedies
A data subject who considers that the processing of personal data relating to him or her infringes applicable data protection law has the right to lodge a complaint with the:
Italian Data Protection Authority
(Garante per la protezione dei dati personali)
in accordance with the procedures described on the Authority’s institutional website.
Where the relevant requirements are met, the data subject may also lodge a complaint with the supervisory authority of the European Union Member State of his or her habitual residence, place of work or place of the alleged infringement.
The data subject’s right to an effective judicial remedy pursuant to Articles 78 and 79 GDPR remains unaffected.


18. Links to third-party websites and services
The website may contain links to websites, platforms or services managed by third parties.
The controller does not control processing activities independently carried out by such third parties. Before using the relevant services, users are advised to review the privacy notices issued by the respective providers.
Access to external websites and services takes place at the user’s discretion. This website does not install profiling cookies or use tracking tools to monitor the user’s subsequent browsing activity on third-party websites.


19. Amendments to this Privacy Notice
This Privacy Notice may be amended to reflect changes in applicable law, measures adopted by competent authorities, technological developments or changes to the activities and services offered.
The updated version will be published on the website together with the date on which it was last updated.
Where any amendment materially affects the purposes, legal bases or methods of the processing, appropriate notice will be provided to data subjects through the relevant communication channels.