Privacy

Privacy Policy

Last updated: June 9, 2026

This page explains what personal data I collect when you write to me through the contact form, why I process it, how long I keep it, and the rights you have under the GDPR. I keep it short and concrete, the same way I work.

Who is responsible for your data

The data controller is Mario Montanari, Operational AI Consultant and Incubator, based in Turin and Bologna, Italy. VAT number IT03012500535.

Contact for any privacy matter: ai@mariomontanari.it

What I collect, and why

I only collect what you choose to send through the contact form, plus the minimum technical data needed to keep the form safe from spam.

From the form
Your name, your email address, your company or website (optional), and the message you write. These are the details I need to read your case and reply to you.
Technical, for security only
A one-way hashed (irreversible) version of your IP address and a timestamp. I use these only to rate-limit and block automated abuse of the form. The hash cannot be turned back into your real IP address.

I do not use tracking, analytics, or profiling cookies on this site. I do not build a profile of you, and I do not run advertising trackers.

The legal basis

  • Your consent (Article 6(1)(a) GDPR), given with the checkbox on the form, lets me process your details to read and reply to your request. You can withdraw it at any time, with no effect on processing already carried out.
  • Legitimate interest (Article 6(1)(f) GDPR) covers the hashed IP and timestamp, used only to protect the form from spam and abuse.

How your message is sent, and who can access it

When you submit the form, your message is sent to me by email, to ai@mariomontanari.it, over an encrypted connection (SMTP over TLS). It is not posted to any third-party form service, marketing platform, or analytics tool.

The website and the mailbox are run by my hosting and email provider, which processes the data on my behalf as a data processor under Article 28 GDPR, bound by a data processing agreement. I do not sell your data, I do not share it with advertisers, and I never add you to a newsletter or any mailing list.

How long I keep it

  • Your message and contact details: kept for as long as needed to handle your request and any follow-up that comes from it, then deleted. If your case does not lead to further contact, I delete it once the exchange is closed.
  • Security data (hashed IP and timestamp): kept for 90 days, then deleted automatically.

Where your data is processed

Your data is processed within the European Union. If at any point a transfer outside the EU were to become necessary, it would happen only with the safeguards the GDPR requires, such as Standard Contractual Clauses.

Your rights

Under the GDPR you can ask me, at any time, to:

  • access the data I hold about you, and get a copy of it;
  • correct it if it is wrong or out of date;
  • delete it (right to erasure);
  • restrict or object to how I process it;
  • receive it in a portable, machine-readable format;
  • withdraw your consent, at any time.

To exercise any of these, write to ai@mariomontanari.it. I reply personally. You also have the right to lodge a complaint with your supervisory authority. In Italy this is the Garante per la protezione dei dati personali (garanteprivacy.it).

Changes to this policy

If I change how I handle your data, I update this page and the date at the top. The current version always lives at this address.