Privacy Policy

Last updated: 6 January 2026

1. Introduction

AAI Consulting S.r.l.s. (hereinafter the "Data Controller", "we" or "AAI Consulting") respects the privacy of the users of its website and is committed to protecting personal data in compliance with the General Data Protection Regulation (GDPR - EU Regulation 2016/679) and Italian Legislative Decree 196/2003 (the Italian Privacy Code) as amended by Legislative Decree 101/2018.

This policy describes how we collect, use, share and protect your personal data when you visit our website www.aaiconsulting-srls.com.

2. Data Controller

The controller of your personal data is:

  • Company name: AAI Consulting S.r.l.s.
  • Registered office: Via Circumvallazione 108, 83100 Avellino (AV), Italy
  • VAT number: IT03161050640
  • Email: info@aaiconsulting-srls.com
  • Legal representative: Antonio Aiello (Sole Director)

3. Categories of Data Collected

AAI Consulting may collect the following categories of personal data:

3.1 Data you provide voluntarily

When you contact us through the contact forms or by email, we may collect:

  • First name and surname
  • Email address
  • Telephone number (if provided)
  • Company name (if provided)
  • The content of your message and related information

3.2 Browsing data

While you browse the website, the following may be collected automatically:

  • IP address
  • Browser type and version
  • Operating system
  • Pages visited and time spent on them
  • Date and time of access
  • Referring URL (referrer)

3.3 Cookies and similar technologies

The website may use technical cookies that are necessary for it to function. For further information, please see our Cookie Policy.

4. Purposes of Processing

The personal data collected is used for the following purposes:

4.1 Necessary purposes (legal basis: performance of a contract)

  • Responding to contact and information requests
  • Providing the consulting services requested
  • Managing the commercial relationship with clients
  • Fulfilling contractual obligations

4.2 Legitimate purposes (legal basis: legitimate interest)

  • Improving the user experience of the website
  • Analysing website usage statistics
  • Preventing fraud and ensuring the security of the website
  • Protecting the rights of the Data Controller

4.3 Consent-based purposes (legal basis: explicit consent)

  • Sending commercial and promotional communications
  • Newsletters and service updates
  • Direct marketing

Note: for these purposes, consent may be withdrawn at any time.

4.4 Mandatory purposes (legal basis: legal obligations)

  • Fulfilling tax and accounting obligations
  • Complying with applicable regulatory requirements

5. Legal Basis for Processing

The processing of personal data is based on:

  • Consent of the data subject: for sending commercial and marketing communications
  • Performance of a contract: to provide the services requested
  • Legitimate interest: to improve our services and ensure security
  • Legal obligations: to comply with regulatory requirements

6. Retention Period

Personal data is retained for as long as is necessary to fulfil the purposes for which it was collected:

  • Contact data: for the duration of the commercial relationship and for up to 2 years after the last interaction
  • Contractual data: for the duration of the contract and for 10 years thereafter, in compliance with tax obligations
  • Browsing data: for a maximum of 12 months
  • Marketing data: until consent is withdrawn or for a maximum of 2 years from the last interaction

Once these periods have elapsed, the data is permanently erased or anonymised.

7. Disclosure and Sharing of Data

Your personal data will never be sold or transferred to third parties for commercial purposes.

7.1 Recipients of the data

Data may be disclosed to:

  • Service providers: hosting, email services, communication platforms (acting as data processors)
  • Consultants and professionals: accountants, lawyers, IT consultants (bound by confidentiality obligations)
  • Public authorities: where required by law or by a court order

7.2 Transfers outside the EU

Personal data is stored on servers located within the European Union. Should it become necessary to transfer data outside the EU, appropriate safeguards will be applied in compliance with the GDPR.

8. Your Rights as a Data Subject

As a data subject, you have the right to:

  • Access (art. 15 GDPR): obtain confirmation as to whether or not personal data concerning you is being processed and, if so, obtain access to that data and to information about the processing
  • Rectification (art. 16 GDPR): obtain the rectification of inaccurate data or the completion of incomplete data
  • Erasure (art. 17 GDPR - the "right to be forgotten"): obtain the erasure of your personal data where the conditions set out in the regulation are met
  • Restriction (art. 18 GDPR): obtain the restriction of processing where one of the cases set out in the regulation applies
  • Portability (art. 20 GDPR): receive the personal data you provided to the Data Controller in a structured, commonly used and machine-readable format, and transmit it to another controller without hindrance
  • Objection (art. 21 GDPR): object at any time to the processing of your personal data on grounds relating to your particular situation
  • Withdrawal of consent: withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal
  • Complaint (art. 77 GDPR): lodge a complaint with the competent supervisory authority (the Italian Data Protection Authority - www.garanteprivacy.it)

To exercise your rights, you can contact us by email at: info@aaiconsulting-srls.com

9. Security Measures

AAI Consulting adopts appropriate technical and organisational measures to protect personal data against:

  • Unauthorised access
  • Accidental or unlawful disclosure
  • Accidental loss or destruction
  • Unauthorised alteration

The security measures in place include:

  • Encryption of data in transit (HTTPS protocol)
  • Access controls on IT systems
  • Regular data backups
  • Incident response procedures
  • Staff training on data protection

10. Children’s Data

The services offered by AAI Consulting are intended exclusively for adults and businesses. We do not knowingly collect personal data from anyone under the age of 18.

Should we become aware that we have collected data from a minor without the consent of a parent or legal guardian, we will erase that information immediately.

11. Links to Third-Party Websites

Our website may contain links to third-party websites. AAI Consulting is not responsible for the privacy practices or the content of such external websites.

We encourage you to read the privacy policies of any third-party websites you visit.

12. Changes to this Policy

AAI Consulting reserves the right to amend or update this privacy policy at any time to reflect changes in our practices or to comply with regulatory requirements.

Material changes will be communicated through the website by updating the "Last updated" date at the top of the page.

We encourage you to review this page periodically so that you are always informed about how we protect your personal data.

13. Contact Details

For any question, concern or request regarding this privacy policy or the processing of your personal data, you can contact us:

  • Email: info@aaiconsulting-srls.com
  • Address: Via Circumvallazione 108, 83100 Avellino (AV), Italy
  • Certified email (PEC): aiiconsulting@pec-legal.it

14. Supervisory Authority

If you have concerns that have not been resolved by the Data Controller, you have the right to lodge a complaint with the competent supervisory authority:

  • Name: Garante per la Protezione dei Dati Personali (Italian Data Protection Authority)
  • Address: Piazza Venezia 11, 00187 Rome, Italy
  • Website: www.garanteprivacy.it
  • Email: garante@gpdp.it
  • Certified email (PEC): protocollo@pec.gpdp.it

By using this website and providing your personal data, you confirm that you have read and understood this privacy policy and consent to the processing of your personal data for the purposes described.