Contents
1. Who is responsible for your data
The data controller for the processing described in this policy is Cristian Mora, operating as an independent consultant under the professional name CMI — Customer & Marketing Intelligence.
- E-mail: cristianmorahtc@gmail.com
No Data Protection Officer (DPO) has been appointed, as the activity does not meet the conditions set out in Article 37 of the GDPR. All privacy matters are handled directly at the address above.
2. Scope of this policy
This policy explains how personal data is processed in relation to this website and to the professional relationship that may follow from it, in accordance with Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended.
It does not apply to third-party websites you may reach from here, such as the scheduling page or LinkedIn. Those services publish their own privacy notices, which govern what they do with your data once you land on them.
3. Data processed and why
The website itself does not ask you for any personal data. Data is processed in the four situations described below.
3.1 Browsing data
As with any website, the hosting infrastructure records technical information needed to deliver pages and keep the service secure: IP address, browser type and version, operating system, date and time of the request, pages requested and referring page. These records are not used to identify individual visitors and are not combined with other data.
| Purpose | Legal basis | Retention |
|---|---|---|
| Delivering the website, diagnosing faults, preventing abuse and protecting the infrastructure | Legitimate interest in operating a secure and functioning website (Art. 6(1)(f) GDPR) | Logs are generated and retained by the hosting provider under its own standard retention periods. They are not accessible to, nor stored by, CMI |
3.2 Contacting me by e-mail
If you write to the address published on this site, I process your e-mail address, your name and any other information you decide to include in your message, including details about your company and its data situation. Please avoid sending sensitive information or confidential client data in a first e-mail: it is not needed at that stage.
| Purpose | Legal basis | Retention |
|---|---|---|
| Replying to your enquiry and assessing whether and how I can help | Steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR) | 24 months from the last exchange, unless a professional relationship begins |
3.3 Booking an introductory call
The scheduling page is provided by Microsoft Bookings, part of Microsoft 365. When you book a slot you provide your name, e-mail address and any notes you add, and the booking system records the date and time chosen. Microsoft processes this data on my behalf as a data processor under Article 28 of the GDPR. The call itself is not recorded.
| Purpose | Legal basis | Retention |
|---|---|---|
| Scheduling, confirming and holding the introductory call | Steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR) | 24 months from the appointment, unless a professional relationship begins |
3.4 Managing a professional engagement
If we start working together, I process the contact and administrative data needed to run the engagement and to meet accounting and tax obligations: names and roles of the people I deal with, business contact details, billing information and correspondence.
| Purpose | Legal basis | Retention |
|---|---|---|
| Performing the agreed services and managing the relationship | Performance of a contract (Art. 6(1)(b) GDPR) | Duration of the engagement |
| Invoicing, accounting and tax records | Compliance with a legal obligation (Art. 6(1)(c) GDPR) | 10 years, as required by Italian law |
| Establishing, exercising or defending legal claims | Legitimate interest (Art. 6(1)(f) GDPR) | Until the applicable limitation period expires |
Providing this data is necessary to enter into and perform the contract. Without it the engagement cannot proceed.
No automated decision-making or profiling within the meaning of Article 22 of the GDPR is carried out in relation to visitors of this website.
4. Client data in analytical engagements
Analytical work is carried out on data exported from your own systems. Where those exports contain personal data relating to your customers, you remain the data controller and I act as a data processor on your instructions, under a data processing agreement signed before any data is transferred.
- Data is used solely to produce the agreed analysis and for no other purpose.
- Direct identifiers are not required for most analytical work: pseudonymised customer identifiers are sufficient and are preferred wherever possible.
- Data is transferred through a secure channel agreed in advance and is not published, resold or shared with third parties.
- At the end of the engagement, data is returned or deleted according to the retention or deletion process defined in the agreement.
- A non-disclosure agreement can be signed before any information is shared, and a security annex can be added where your internal policies require one.
Sample deliverables published on this website are built on illustrative mock-up data and contain no client information.
5. Who may receive your data
Your data is never sold, rented or used for advertising purposes. It may be accessed by the following categories of recipient, each of which acts as a data processor or as an independent controller within its own remit:
- Cloudflare, Inc., acting in the European Union through Cloudflare Ireland Ltd — hosting of this website on Cloudflare Pages, delivery through its content delivery network, and the related server logs.
- Microsoft Ireland Operations Ltd — for e-mail, scheduling through Microsoft Bookings, video calls and file storage within Microsoft 365.
- Google Ireland Ltd — where the published contact address is a Gmail address, for the transmission and storage of e-mail correspondence.
- Accountant and tax advisers — for invoicing and statutory accounting obligations.
- Public authorities — where disclosure is required by law.
An up-to-date list of processors can be requested at any time using the contact details in section 12.
6. Transfers outside the EEA
The providers listed above are established in the European Union, but some of them may process data on infrastructure located in, or accessible from, countries outside the European Economic Area, in particular the United States.
Where this happens, transfers are covered by the safeguards provided under Chapter V of the GDPR: an adequacy decision of the European Commission, including the EU–US Data Privacy Framework where the provider is certified under it, or Standard Contractual Clauses adopted by the Commission together with supplementary measures where necessary.
This website also loads a web font from Google’s content delivery network. As a result, your IP address is disclosed to Google when a page is displayed. See the Cookie Policy for details and for how this can be avoided.
7. How long data is kept
Retention periods are set out in the tables in section 3. As a general principle, data is kept only for as long as it is needed for the purpose it was collected for, and then deleted or anonymised. Where a legal obligation prescribes a longer period, such as the ten-year period for accounting records, that period prevails.
8. Your rights
Under Articles 15 to 22 of the GDPR you have the right to:
- obtain confirmation of whether your data is being processed and receive a copy of it;
- have inaccurate or incomplete data corrected;
- have your data erased, where one of the grounds set out in Article 17 applies;
- obtain restriction of processing in the cases set out in Article 18;
- receive the data you provided in a structured, commonly used and machine-readable format, and have it transmitted to another controller;
- object at any time, on grounds relating to your particular situation, to processing based on legitimate interest;
- withdraw your consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out beforehand.
Requests can be sent to the e-mail address in section 12 and are answered without undue delay and in any case within one month, extendable by two further months for complex requests. No fee is charged unless a request is manifestly unfounded or excessive.
If you believe your data is being processed unlawfully, you have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the supervisory authority of the EU country where you live or work.
9. Security measures
Appropriate technical and organisational measures are in place, taking into account the state of the art and the nature of the data processed:
- encrypted connections (HTTPS) for the website and for file transfers;
- access to devices and accounts protected by strong credentials and multi-factor authentication;
- client data segregated by engagement and accessed only for the defined analytical purpose;
- the principle of data minimisation applied when defining the data required for each project;
- deletion or return of client data at the end of the engagement, as agreed.
10. Minors
This website and the services described on it are directed at businesses and professionals. They are not intended for people under the age of 18, and no data is knowingly collected from them.
11. Changes to this policy
This policy may be updated to reflect changes in the services offered, in the tools used or in applicable legislation. The version in force is always the one published on this page, with its date shown at the bottom. Where changes are substantial and affect an ongoing relationship, they are communicated directly.
12. Contact
For any question about this policy or to exercise your rights, write to cristianmorahtc@gmail.com.
Last updated: 28 July 2026 · Version 1.0. This page is kept under review and may be updated to reflect changes in the services offered, the tools used or applicable legislation.