Home/Legal/Privacy policy
Privacy policy
How we handle personal data when you use this website or send us an enquiry.
1Who is responsible
The controller of personal data processed in connection with this website and with enquiries made through it is:
Shared workspace, not a registered establishment
The controller is established in the European Union. No representative under Article 27 of the General Data Protection Regulation is required or appointed.
2What this website does not do
This website has no enquiry database behind it. The triage tool and the enquiry form both run entirely in your browser: the triage produces its result locally, and the enquiry form composes a message that you send from your own email account. Nothing you type into either is transmitted to us by the website, and nothing is stored on it.
In consequence, we do not operate a customer relationship system fed by this site, we do not build behavioural profiles of visitors, we do not run a mailing list, and we do not sell or share data with advertisers or data brokers. There is no automated decision-making, including profiling, that produces legal or similarly significant effects.
What we do process is the content of emails, telephone calls and messages you choose to send us, and the technical data described in clause 3.
3What we collect, and why
| Category | What it includes | Purpose |
|---|---|---|
| Enquiry data | Your name, role, organisation, email address, telephone number if given, and the outline of the matter you describe | To run a conflicts check, respond to you, and quote scope and fee |
| Conflicts records | Party names and a short matter description, retained after an enquiry is closed | To identify conflicts of interest in future matters, which is a professional requirement |
| Engagement data | Correspondence, documents and information provided in the course of a matter we are engaged on | To perform the engagement and to comply with record-keeping obligations |
| Technical data | Server log information generated by our hosting platform, such as IP address, browser type and pages requested | To keep the site available and secure, and to detect abuse |
We ask you not to send confidential, privileged or price-sensitive material with an initial enquiry. The enquiry form says so explicitly, and no duty of confidentiality arises on our side before an engagement is agreed in writing.
4Legal bases
- Article 6(1)(b) — steps taken at your request before entering into a contract, and performance of the engagement once agreed. This covers responding to enquiries and carrying out the work.
- Article 6(1)(f) — our legitimate interests in maintaining conflicts records, keeping the website secure, and establishing or defending legal claims. We have assessed these against your interests and consider the processing proportionate and expected.
- Article 6(1)(c) — compliance with legal obligations, including accounting, tax and anti-money-laundering record-keeping.
- Article 6(1)(a) — consent, where you have given it for a specific purpose. You may withdraw consent at any time without affecting processing already carried out.
5Who else sees it
We disclose personal data only where it is necessary and only to the following:
- Italian qualified counsel who reviews and signs every legal position we issue on Italian law.
- Italian co-counsel instructed on notification filings. Where a filing is involved we tell you which firm before you engage, and the firm acts under its own professional obligations.
- Technical reviewers engaged on artificial intelligence assessments, under confidentiality undertakings.
- Service providers that host this website and provide our email and document systems, acting as processors on documented instructions.
- Public authorities where a filing is made on your instructions, or where disclosure is required by law.
We do not disclose personal data to any other recipient for any other purpose.
6Transfers outside the EEA
Our work is cross-border, and correspondence with a client or its advisers outside the European Economic Area necessarily involves a transfer to that country. Where that happens at your request or is necessary for the performance of a contract with you, it is made under Article 49(1)(b) or (c) of the Regulation.
Where a service provider processes data outside the EEA on our behalf, we rely on an adequacy decision where one applies, and otherwise on the European Commission's standard contractual clauses together with any supplementary measures the transfer requires. You may ask us which safeguard applies to a particular transfer.
7How long we keep it
| Data | Retention |
|---|---|
| Enquiries that do not become engagements | Deleted within twelve months, except the minimum needed for conflicts records |
| Conflicts records | Retained for as long as the practice operates, since their purpose is to identify future conflicts |
| Engagement files | Ten years from the conclusion of the matter, reflecting limitation periods and record-keeping obligations |
| Accounting records | As required by Spanish commercial and tax law |
| Server logs | As retained by our hosting platform for security and availability purposes |
8Your rights
Subject to the conditions in the Regulation, you have the right to request access to your personal data, rectification of inaccurate data, erasure, restriction of processing, portability, and to object to processing based on our legitimate interests. Where processing rests on consent, you may withdraw it at any time.
Exercise any of these by writing to info@bcaun.it. We respond within one month, extendable by two further months for complex requests, and we will tell you if an extension applies. We may need to verify your identity before acting.
Some rights are qualified. We may decline erasure or restriction where the data is needed for conflicts records, to comply with a legal obligation, or to establish, exercise or defend legal claims — and we will explain which ground applies.
9Complaints
If you consider that we have not handled your personal data properly, please raise it with us first at info@bcaun.it — most issues are resolved faster that way.
You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Spanish data protection authority, the Agencia Española de Protección de Datos. You may instead complain to the authority in the member state of your habitual residence or place of work — in Italy, the Garante per la protezione dei dati personali.
10Changes
We update this policy when our processing changes or when the law requires it. The version number and date at the top of this page always identify the text in force. Material changes affecting an active engagement are notified to the client directly rather than by publication alone.