Privacy and Cookie Policy
bergamolegal.com — Bergamo Legal Società tra Avvocati s.r.l. — VAT no. 04565220169
Privacy Policy
Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR), Bergamo Legal Società tra Avvocati s.r.l., as Data Controller, provides the following information on the processing of the personal data of users who visit and interact with the website bergamolegal.com. Data processed in the course of a professional engagement is covered by a separate notice, given when instructions are accepted.
1. Data Controller
Bergamo Legal Società tra Avvocati s.r.l., registered office at Via Fratelli Calvi 10E, 24122 Bergamo (BG), Italy. VAT no. 04565220169. Email: info@bergamo.legal — certified email (PEC): bergamo.legal@ultracert.it. No Data Protection Officer (DPO) has been appointed, none being required under Article 37 GDPR.
2. Data processed, purposes and legal bases
- Browsing data. While you browse, the website and the hosting provider collect technical data (IP address, browser type, date and time, pages requested) to ensure operation and security. Legal basis: the Controller's legitimate interest in the security of the site (Art. 6(1)(f)) and any legal obligations.
- Booking an appointment (TidyCal service). The booking calendar is not hosted on this website: the "Book" button leads to an external page provided by TidyCal. The data you enter there (name, email, telephone, any notes) is processed by the Controller in order to arrange and manage the appointment. Legal basis: steps taken at your request prior to entering into a contract (Art. 6(1)(b)) and/or consent.
- Direct contact (email, telephone, WhatsApp). We process the data you give us in order to reply. Email is run on Google Workspace. Legal basis: responding to your request and pre-contractual steps (Art. 6(1)(b)).
3. Data retention
Data collected through the website is kept for as long as is needed to deal with the request and in any event no longer than 36 months, unless the contact leads to a consultation or to a professional engagement: in that case the data is kept under the terms of the engagement notice and in compliance with legal obligations (professional conduct, tax and anti-money laundering).
4. Disclosure of data and processors
Data may be processed on the Controller's behalf, as Processors under Article 28 GDPR, by the providers of the technical services used, with whom data processing agreements (DPAs) are in place:
- TidyCal — appointment booking, on an external page (United States);
- Google — Google Workspace email (United States);
- IONOS — website hosting (European Union).
Data is neither disseminated nor transferred to third parties for marketing purposes.
5. Transfers outside the EU
Some providers (TidyCal, Google) are based in the United States: those transfers take place on the basis of the appropriate safeguards provided for by Articles 44-46 GDPR, in particular the European Commission's Standard Contractual Clauses (SCCs), supplemented where necessary by additional measures.
6. Special categories and criminal-offence data
The contact channels on this website are not intended for the collection of special categories of data (Art. 9) or of data relating to criminal convictions and offences (Art. 10). Please do not send sensitive information through these channels: such data, where needed, will be processed solely within the professional engagement, under a dedicated notice and with appropriate safeguards of confidentiality.
7. No profiling and no automated decision-making
The website carries out no profiling and no automated decision-making (Art. 22) in respect of visitors. Any artificial-intelligence tools used by the firm operate solely as internal support in the handling of its files and do not process website users' data automatically.
8. Provision of data
Providing data through the website is optional; failure to provide the data needed (for example to book an appointment or to receive a reply) means the request cannot be acted upon.
9. Your rights
You may exercise at any time the rights set out in Articles 15-22 GDPR: access, rectification, erasure, restriction, objection, portability and withdrawal of consent (without affecting processing already carried out). Requests may be sent to info@bergamo.legal or by certified email (PEC) to bergamo.legal@ultracert.it. You also have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).
Cookie Policy
What cookies are
A cookie is a small text file that websites save on the user's device while browsing. Cookies may be session cookies (deleted when the browser is closed) or persistent. Browser local storage is treated in the same way as cookies.
Cookies used by this website
The website is designed to keep cookies to a minimum: it uses no tracking, analytics or profiling cookies and collects no data for statistical or marketing purposes. Typefaces are served directly by the website, with no requests to external services. No maps, chats or calendars are embedded in the pages.
Links to external services
Third-party features are not embedded in this website: they are plain links that open in a new tab. Until you use them, no third-party cookie or resource is set by this website. If you follow them, the provider concerned may set its own cookies, under its own privacy policy:
- TidyCal — appointment booking page (meet.bertocchi.lawyer), subject to the provider's privacy policy;
- WhatsApp — direct link; the conversation takes place on WhatsApp, under its privacy policy.
Disabling cookies
You can disable cookies in your browser at any time, although this may limit some features of the website. For instructions, see the settings of the browser you use.
Last updated: September 2026