Legal information
Privacy Policy
Policies and terms for the BeEasy Consulting website.
Last updated: 1 August 2025
This policy explains how BeEasy Consulting S.r.l.s. collects, uses and protects personal data in connection with the website and related services.
1. Data Controller
VAT/Tax Code: IT07244890484
Registered Office: Viale Filippo Strozzi 30, 50129 Firenze (FI), Italy
Phone: +39 328 058 8502
Email: info@beeasyconsulting.com
2. Data We Collect
- Browsing data: IP address, browser and operating-system information, requested pages, request time and method, server response codes, file size, navigation paths and referring sites. Data is generally used in aggregate, except where security or fraud investigations require otherwise.
- Data provided voluntarily: name, surname, email, telephone, billing or shipping details, payment preferences, purchase history and newsletter subscriptions.
- Cookies and tracking tools: technical, analytics and marketing cookies, where implemented and consented to. See the Cookie Policy.
3. Legal Basis and Purposes
- Legitimate interest for website functionality, security and performance.
- Contractual necessity for purchases, orders and customer service.
- Consent for newsletters, marketing communications and non-essential analytics.
- Legal obligation for compliance with applicable laws.
Consent may be withdrawn at any time without affecting processing already carried out lawfully.
4. Nature of Data Provision
5. How We Process Data
6. Data Storage and Sharing
7. Data Retention
- Purchase data: up to 10 years where required by law.
- Newsletter data: until subscription is withdrawn.
- Contact-form data: up to 12 months.
- Payment details: only where explicitly authorised and required.
8. Access to Data
9. User Rights
10. External Links
11. Policy Updates
12. Contact
13. Website message widget
The on-site message widget may collect the visitor’s name, email address, telephone number, message, originating page and consent confirmation. The data is used only to respond to the enquiry and may be transmitted to the company’s authorised messaging provider so that the notification can reach the designated business telephone. Messages should not contain health data, patient information or other special-category personal data.
Before activation, the provider, retention period, processor terms and any international transfers must be reflected in the final production privacy documentation.