Skip to main content

Privacy Policy

Last Updated: March 14, 2026

1 — Introduction & Controller Identity

This Privacy Policy explains how Nelo Italia S.r.l. ("Nelo Italia", "we", "our", "us") collects, uses, and protects your personal data when you visit our website and engage with our educational services in Italy. It also tells you about your rights and how the law protects you under the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Italian data protection laws.

Data Controller: Nelo Italia S.r.l., Via Giuseppe Mazzini 9, Centro Storico, 20123 Milano, Italy. Contact email for privacy matters: [email protected]. We currently have not appointed a Data Protection Officer because our processing activities do not require a DPO under GDPR. If this changes, we will update this Policy.

This Policy applies to personal data collected via our site, forms, and communications in connection with our management and financial skills education services. It does not cover third-party websites you may access through links on our site.

2 — Personal Data We Collect

We collect only the information necessary to provide our services, respond to inquiries, and improve site performance. Categories include:

  • Identity and contact data: name, email address, telephone number.
  • Inquiry and enrollment data: course interests, messages, preferences, availability notes, and communication history.
  • Technical data: IP address (truncated/anonymized where applicable), browser type and version, device type and operating system, language settings, and basic diagnostic data.
  • Usage data: pages viewed, time on page, navigation paths, referring URLs, and interactions with on‑site elements (e.g., clicks on buttons and forms).
  • Cookie and identifier data: first‑party cookies for session continuity and consent preferences; optional analytics and marketing cookies/tags if you consent (see Section 4).
  • Conversion and communication events: form submissions and subsequent contact events related to your request.

We do not intentionally collect special categories of data (e.g., health, political opinions, religious beliefs), financial account information, or government identification numbers. Please avoid including such data in free‑text fields.

3 — Why We Process Personal Data & Legal Basis (GDPR Art. 6)

  • Responding to inquiries and providing pre‑contract information: to supply course outlines, schedules, and guidance. Legal basis: Art. 6(1)(b) performance of a contract or pre‑contractual steps, and Art. 6(1)(a) consent where applicable.
  • Managing enrollment and course administration: arranging sessions, communicating essential updates, and maintaining records. Legal basis: Art. 6(1)(b) contract.
  • Analytics to improve content and site performance: understanding aggregate usage, measuring interest in topics. Legal basis: Art. 6(1)(a) consent (analytics cookies disabled by default until you opt in).
  • Marketing/remarketing: showing or measuring advertising where permitted. Legal basis: Art. 6(1)(a) consent (marketing cookies disabled by default until you opt in).
  • Security and fraud prevention: maintaining service integrity, detecting abuse. Legal basis: Art. 6(1)(f) legitimate interests.
  • Legal compliance: keeping records required by applicable laws and responding to lawful requests. Legal basis: Art. 6(1)(c) legal obligation.

Automated Decision‑Making and Profiling (Art. 22): We do not perform automated decision‑making or profiling that produces legal or similarly significant effects on individuals.

4 — Cookies & Tracking Technologies

We use cookies and similar technologies such as pixel tags to operate the site, understand usage, and—if you allow—support advertising and remarketing. Cookies may be session (expire when you close your browser) or persistent (remain for a defined period). They may be first‑party (set by us) or third‑party (set by service providers on our behalf).

  • Essential cookies (no consent required): enable core functionality such as navigation, form submission protection, session continuity, and your cookie preferences. Examples: _site_session, cookie_consent. Typical retention: session to 12 months.
  • Analytics cookies (consent): help us measure visits and improve content. We may use Google Analytics 4 with IP anonymization. Examples: _ga (2 years), _ga_XXXXXXXXXX (2 years). Data retention in analytics systems is generally 14 months.
  • Marketing cookies (consent): used for advertising, remarketing, and conversion measurement (e.g., Google Ads, Meta Pixel). Examples: _gcl_au (90 days), _fbp (90 days), _fbc (90 days).

You can manage your choices at any time using the "Manage cookie preferences" link in our footer or the preferences panel on the site. For more details, see our Cookie Policy.

5 — Consent Management (EEA/UK)

Visitors in the European Economic Area and the United Kingdom receive a consent prompt. Analytics and marketing technologies are off until you provide informed, freely given consent. Your selection is stored in the cookie_consent cookie (12 months). You may withdraw consent at any time via the preferences panel or by clearing cookies. Withdrawing consent does not affect processing carried out before withdrawal.

6 — Sharing With Service and Advertising Partners

We do not sell personal data. We share limited data with trusted providers to operate the site, deliver analytics, security, and—if you consent—advertising. Categories of recipients include:

  • Google LLC (Analytics, Ads): cookie identifiers, approximate location derived from IP (anonymized where configured), usage metrics, and conversion events.
  • Meta Platforms (Pixel/remarketing): page views and conversion events, hashed contact identifiers where configured.
  • Cloudflare or similar CDN/security providers: IP and technical diagnostics to protect and accelerate the site.
  • Operational tools (email and hosting): contact details and communications necessary to respond to your inquiries.

These providers act as processors or independent controllers depending on the service. Contracts and safeguards are in place to protect personal data, and providers may not use our site data for their own independent commercial purposes unrelated to our instructions.

7 — International Transfers

Where partners process data outside the EEA/Italy (for example, in the United States), we rely on appropriate safeguards such as the EU‑US Data Privacy Framework (where applicable), Standard Contractual Clauses (EU 2021/914), and supplementary technical and organisational measures. If a transfer mechanism changes due to legal developments, we will adopt an alternative compliant mechanism.

8 — Data Retention

We keep personal data only for as long as necessary for the purposes set out in this Policy, or to comply with legal, accounting, or reporting requirements. Typical retention periods are:

  • Inquiry and contact records: 2 years from last interaction.
  • Enrollment and course administration data: for the duration of the course and as required by applicable law (generally up to 10 years for tax/accounting records in Italy).
  • Analytics event data: 14 months in analytics systems, subject to your consent status.
  • Marketing identifiers: for the lifetime of the cookie (typically 90 days) or until you withdraw consent.
  • Server and security logs: up to 90 days unless we investigate specific incidents.
  • Consent records: 3 years for audit purposes.

9 — Your Rights Under GDPR

Subject to conditions and exceptions under GDPR, you have the following rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection (Art. 21). You also have the right to withdraw consent at any time (Art. 7(3)). To exercise any right, email [email protected]. We will respond within 30 days, extendable by 60 days for complex requests, and we may need to verify your identity.

Supervisory Authority: In Italy, you may lodge a complaint with the Garante per la protezione dei dati personali. You also retain the right to complain to your local authority if you are located elsewhere in the EEA.

10 — Children’s Privacy

Our website and educational programs are intended for adult learners. We do not knowingly collect personal data from individuals under 16 years old. If we learn that we have collected data from a minor without appropriate consent, we will delete it promptly. Parents or guardians may contact us at [email protected] to request deletion.

11 — Do Not Track

Some browsers offer a "Do Not Track" (DNT) setting. As no industry standard for DNT is established, our site does not respond to DNT signals. Your cookie preferences panel provides a reliable way to control analytics and marketing technologies.

12 — Account & Data Deletion Requests

You may request deletion of your personal data by emailing us with the subject line "Data Deletion Request" at [email protected]. We will verify your identity and process the request within 30 days unless legal obligations require us to retain certain records (e.g., tax documentation). Where we have shared your data with processors, we will instruct them to delete it as appropriate.

13 — Business Transfers

If Nelo Italia S.r.l. undergoes a reorganisation, merger, acquisition, asset sale, financing, or insolvency event, personal data may be transferred to a successor entity as part of the transaction. We will ensure that the recipient respects this Policy and applicable laws, and we will notify users on the site if a material change occurs.

14 — California Privacy (CCPA/CPRA)

While we operate in Italy, some visitors may be California residents. For transparency, during the past 12 months we may have collected: identifiers (name, email, IP), internet activity (pages viewed, interactions), and inferences (course interests). We share this information with service providers and advertising partners to operate the site and, with consent, for cross‑context behavioural advertising. We do not sell personal information as defined by CCPA. California residents may request access, deletion, correction, and to opt out of sharing for cross‑context advertising by contacting [email protected]. We will verify requests as required by law and respond within statutory timeframes. We do not discriminate for exercising rights.

15 — Virginia (VCDPA)

For visitors from Virginia, you may have rights to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of targeted advertising. Submit requests to [email protected]. If we deny your request, you may appeal by emailing us with the subject "Appeal of Refusal — Privacy Request." We will respond within 60 days. We do not sell personal data or engage in profiling that produces legal or similarly significant effects.

16 — Nevada

Nevada law allows residents to opt out of the sale of covered information. We do not sell personal information as defined by Nevada law. You may still submit a verified opt‑out request by emailing [email protected] with the subject "Nevada Do Not Sell Request."

17 — Changes to This Policy

We may update this Policy from time to time to reflect changes in law or our processing activities. Material changes will be highlighted on our homepage or via an in‑site notice at least 14 days before they take effect where required. The "Last Updated" date at the top of this page will also change.

18 — Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, contact:

  • Nelo Italia S.r.l.
  • Via Giuseppe Mazzini 9, Centro Storico, 20123 Milano, Italy
  • Email: [email protected]

We aim to respond within one business day for general inquiries and within statutory deadlines for privacy rights requests.