Privacy Policy

Last updated: July 15, 2026

1. Data Controller

The data controller for the personal data collected through the website www.continuitaly.it is:

PhoenITx S.r.l.
Via Pietro Calvi 2 – 20129 Milan, Italy
Tax ID and VAT No.: IT06466860969
Email: amministrazione@phoenitx.it
Phone: +39 02 82396499

Continuitaly™ is a registered trademark of PhoenITx S.r.l.

2. Types of Data Processed

The website may process the following categories of personal data:

  • browsing data and technical information regarding the device, browser, IP address, and website usage;
  • first name, last name, email address, phone number, city, and information voluntarily provided in contact forms;
  • first name, last name, and email address provided when signing up for the newsletter;
  • identification, professional, administrative, and contact information provided to request information or register for courses, events, and training activities;
  • information voluntarily provided via email, phone, WhatsApp, or other communication channels;
  • data necessary for the management of contractual, administrative, accounting, and tax matters.

Users are asked not to submit, via the forms on this website, any sensitive data or information that is not necessary for the request being made.

3. Purposes and Legal Bases

Personal data may be processed for the following purposes.

Managing Contact Requests

Data submitted via the contact form, email, phone, or WhatsApp is used to respond to the data subject’s requests, provide information about our services, and prepare any offers.

The legal basis is the implementation of pre-contractual measures taken at the request of the data subject or, where applicable, the Data Controller’s legitimate interest in managing the communications received.

Registration and Participation in Courses and Events

The data is processed to manage enrollment requests, registrations, organizational communications, the delivery of training, certificates, billing, and related obligations.

The legal basis is the performance of the contract or precontractual measures, and compliance with legal, administrative, accounting, and tax obligations.

Newsletters and informational or promotional communications

The information provided when subscribing to the newsletter—specifically, first name, last name, and email address—is used to send updates regarding articles, courses, certifications, events, services, and initiatives from Continuitaly and PhoenITx S.r.l.

Mailing lists, subscriptions, unsubscriptions, and the sending of communications are managed through MailerLite, an email marketing service provided—for customers located in the European Economic Area—by MailerLite Limited, 88 Harcourt Street, Dublin 2, D02 DK18, Ireland.

MailerLite processes personal data on behalf of PhoenITx S.r.l., acting as the data controller, solely for the purpose of providing the newsletter management and distribution service, in accordance with the relevant data processing agreement.

The legal basis for the processing is the data subject’s consent. Consent may be withdrawn at any time by using the unsubscribe link included in every communication or by contacting the Data Controller.

Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.

MailerLite contractually states that it acts as the data controller with respect to subscribers’ data and processes it in accordance with the customer’s instructions.

Website Usage Statistics and Analysis

With your consent, this site uses Google Analytics to obtain aggregate information about page usage, improve content, monitor performance, and understand user interest.

The legal basis is the consent provided via the cookie banner. Additional information is available in the Cookie Policy.

Website Security and Operation

Technical data may be processed to ensure the security of the website, prevent misuse, identify malfunctions, protect IT systems, and exercise or defend any rights.

The legal basis is the Data Controller’s legitimate interest in the security and proper management of its systems.

4. Nature of the contribution

Providing the data marked as required on the forms is necessary to allow the Data Controller to respond to your request or process your registration for a service.

Failure to provide this information may make it impossible to provide the requested response or service.

Providing your information for the newsletter is optional, and failure to give consent does not prevent you from using the other services on the site.

5. Processing Methods and Security

Personal data is processed using electronic means and, when necessary, on paper, in accordance with the principles of lawfulness, fairness, transparency, data minimization, accuracy, and storage limitation.

The Data Controller implements appropriate technical and organizational measures to reduce the risks of loss, unauthorized access, disclosure, alteration, or misuse of the data.

6. Recipients of the Data

The data may be processed by personnel and contractors authorized by PhoenITx S.r.l. and disclosed, to the extent necessary, to the following categories of recipients:

  • providers of hosting, maintenance, security, and IT support;
  • email and newsletter service providers, including MailerLite Limited;
  • providers of statistical and technological services;
  • instructors, partners, and organizations involved in the organization or certification of courses, as necessary;
  • administrative, tax, legal, and insurance consultants;
  • banks, payment institutions, and payment service providers;
  • public authorities or other entities in the cases provided for by law.

Vendors that process data on behalf of the Data Controller are designated as data processors when required by law.

The data is not disclosed or transferred to third parties for independent commercial purposes.

7. International Transfers

Some technology providers may process personal data in countries outside the European Economic Area.

In such cases, the transfer is carried out in accordance with Articles 44 and following of the GDPR, based on adequacy decisions, standard contractual clauses, or other safeguards provided for by applicable law.

The data processed through MailerLite is managed in accordance with the relevant Data Processing Addendum. According to the currently available contractual documentation, the infrastructure of the new MailerLite service uses a data center located in the Netherlands, while the Legacy version uses a data center located in Germany.

MailerLite may use subprocessors, and if data processing involves a transfer to a country outside the European Economic Area for which there is no adequacy decision, it states that it applies the Standard Contractual Clauses approved by the European Commission or other safeguards provided for by applicable law.

Any other international transfers carried out by the technology providers used by the Data Controller are conducted in accordance with Articles 44 et seq. of the GDPR.

MailerLite’s DPA expressly provides for the use of Standard Contractual Clauses for any transfers to countries not recognized as adequate; the updated list of sub-processors currently includes Google Cloud infrastructure in the Netherlands for the new MailerLite and in Germany for the Legacy version

8. Retention periods

Data is retained only for as long as necessary to fulfill the purposes for which it was collected:

  • contact requests: for as long as necessary to process the request and any subsequent interactions, normally no longer than 24 months from the last communication, unless there are disputes or further contractual relationships;
  • newsletter: until consent is withdrawn or you unsubscribe from the service;
  • registrations, contracts, invoices, and administrative documentation: for the periods specified by civil and tax law;
  • Statistical data: according to the time periods configured in the relevant services and described in the Cookie Policy;
  • Data necessary to protect rights: for the duration of any disputes and the applicable statutes of limitations.

When data is no longer needed, it is deleted, anonymized, or retained only when required by law.

9. Cookies and Tracking Tools

This website uses necessary technical cookies and, with your consent, statistical tools.

Users can accept, reject, or customize their preferences via the banner and can change them later using the consent management tool.

To learn about the cookies we use, their purposes, and their durations, please see our Cookie Policy.

10. Rights of the Data Subject

The data subject may exercise, where applicable, the rights set forth in Articles 15–22 of the GDPR, including:

  • to obtain confirmation of whether their data is being processed and to access their data;
  • request the correction or supplementation of the data;
  • request deletion;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • receive data in a structured format and request its portability;
  • withdraw consent at any time;
  • not to be subject to decisions based solely on automated processing in the cases provided for by law.

Requests may be sent to:

amministrazione@phoenitx.it

The data subject also has the right to file a complaint with the Data Protection Authority or the competent supervisory authority.

11. Links to External Sites

The website may contain links to websites, social media platforms, and services operated by third parties.

When a user leaves the Continuitaly website, data processing is governed by the privacy policies of the respective website operators, over which PhoenITx S.r.l. has no control.

12. Privacy Policy Updates

The Data Controller may modify or update this Privacy Policy in response to regulatory, technical, or organizational changes.

 

This post is also available in: Italian French