Privacy Policy
Last updated: 26 August 2026
This Privacy Policy explains how personal data is collected, used, stored and protected when you visit leonardofiori.com or contact Leonardo Fiori through the website.
This Policy is intended to comply with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the Data Protection Act (Chapter 586 of the Laws of Malta), and applicable Maltese data protection and electronic communications rules.
1. Data Controller
The data controller responsible for the processing of personal data through this website is:
Leonardo Fiori
Website: leonardofiori.com
Email: fiorileonardo20@gmail.com
Business location: Malta
A “data controller” means the person or organisation that decides why and how personal data is processed.
2. Personal Data We Collect
The personal data collected through this website depends on how you use it.
2.1 Data you provide voluntarily
If you contact us through the website, request a consultation, or send an enquiry by email, we may collect:
your name;
your email address;
your phone number, if you choose to provide it;
your organisation or company name, if relevant;
your job title, if relevant;
the content of your message;
any information you choose to include in your enquiry.
Please do not submit sensitive personal data unless it is strictly necessary for your enquiry. Sensitive data may include information about health, political opinions, religious beliefs, trade union membership, biometric data, or similar special categories of personal data.
2.2 Technical and website usage data
When you visit the website, certain technical information may be collected automatically, such as:
IP address;
browser type and version;
device type;
operating system;
approximate location based on technical data;
date and time of visit;
pages visited;
referral source;
website interaction data;
basic server logs.
This information is generally used to operate, secure and improve the website.
2.3 Cookies and similar technologies
The website may use cookies or similar technologies.
Some cookies may be strictly necessary for the website to function properly. These cookies do not usually require consent.
If the website uses non-essential cookies, such as analytics, marketing, embedded media, or tracking cookies, these will only be used where required with your prior consent. You will be given clear information and a real choice before such cookies are placed on your device.
You can manage or withdraw cookie consent through the cookie banner or cookie settings available on the website, where applicable. You can also disable cookies through your browser settings.
3. Why We Process Personal Data and Legal Bases
We process personal data only where we have a valid legal basis under the GDPR.
We may process your personal data to respond to enquiries, manage consultation requests, communicate with you, provide requested services, manage client or prospective client relationships, maintain website security, comply with legal or accounting obligations, and protect our legal rights.
Depending on the context, we rely on one or more of the following legal bases:
Contract or pre-contractual steps, where processing is necessary to respond to your request, discuss a possible engagement, or provide services you have requested.
Legitimate interests, where processing is necessary to operate the website, respond to business enquiries, maintain professional communications, prevent abuse or security threats, and manage business relationships.
Legal obligation, where processing is necessary to comply with applicable tax, accounting, regulatory, or legal requirements.
Consent, where required, for example for non-essential cookies, analytics, or any future newsletter or marketing communications.
Where we rely on consent, you may withdraw it at any time. This does not affect the lawfulness of processing carried out before consent was withdrawn.
4. Newsletter and Marketing Communications
At present, this website does not automatically subscribe visitors to a newsletter or marketing mailing list.
If a newsletter or mailing list is introduced in the future, your email address will only be used for that purpose if you actively subscribe or otherwise give valid consent. You will be able to unsubscribe at any time.
5. Who We Share Personal Data With
We do not sell personal data.
Personal data may be shared only where necessary with trusted service providers or professional advisers, such as:
website hosting providers;
email service providers;
website maintenance or security providers;
analytics providers, if used;
booking or calendar tools, if used;
accountants, legal advisers or professional consultants, where necessary;
public authorities, regulators or courts, where required by law.
These recipients may act as processors or independent controllers depending on the circumstances. Where service providers process personal data on our behalf, we seek to use providers that offer appropriate data protection safeguards.
Current or likely service providers may include:
Website hosting: Hostinger
Email service: Gmail
Analytics: not currently used
Booking tool: not currently used
Cookie consent tool: not currently used
This section is updated if new providers are added.
6. International Data Transfers
Some service providers may process or store personal data outside Malta or outside the European Economic Area (“EEA”).
Where personal data is transferred outside the EEA, appropriate safeguards will be used where required by the GDPR. These may include:
an adequacy decision by the European Commission;
Standard Contractual Clauses approved by the European Commission;
participation in an approved transfer framework, where applicable;
other safeguards or derogations permitted by the GDPR.
If you would like more information about international transfers relevant to your personal data, you may contact us using the details provided in this Policy.
7. How Long We Keep Personal Data
We keep personal data only for as long as necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law.
Enquiries and consultation requests are kept for as long as needed to respond, follow up, manage potential client relationships, or keep reasonable business records. Client, project, accounting, invoicing, and tax-related records are kept for the periods required under applicable Maltese legal, tax, and accounting obligations.
Technical data, such as server logs and security-related information, is kept only for a limited period necessary to operate, protect, troubleshoot, and maintain the website.
Where processing is based on consent, such as non-essential cookies or any future newsletter, the relevant data is kept until consent is withdrawn or until it is no longer needed for that purpose.
When personal data is no longer required, it will be deleted, anonymised, or securely archived where appropriate.
8. Your Data Protection Rights
Subject to applicable law and any relevant limitations, you may have the following rights:
the right to be informed about how your personal data is processed;
the right to access your personal data;
the right to request correction of inaccurate or incomplete personal data;
the right to request deletion of your personal data;
the right to request restriction of processing;
the right to object to processing based on legitimate interests;
the right to data portability, where applicable;
the right to withdraw consent at any time, where processing is based on consent;
rights in relation to automated decision-making and profiling, where applicable.
We do not use your personal data for automated decision-making that produces legal or similarly significant effects.
To exercise your rights, contact:
We may need to verify your identity before responding to a request. We will normally respond within one month, unless the request is complex or multiple requests have been made, in which case the GDPR may allow an extension.
9. Right to Lodge a Complaint
If you believe that your personal data has been processed in breach of applicable data protection law, you have the right to lodge a complaint with the Maltese supervisory authority:
Office of the Information and Data Protection Commissioner (IDPC)
Floor 2, Airways House
Triq Il-Kbira
Tas-Sliema SLM 1549
Malta
Telephone: +356 2328 7100
Website: idpc.org.mt
You are encouraged to contact us first so that we can try to resolve the issue directly, but you are not required to do so before contacting the IDPC.
10. Website Security
We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.
These measures may include access controls, secure account practices, reputable hosting providers, website security tools, and limiting access to personal data where appropriate.
However, no website, email system or internet transmission can be guaranteed to be completely secure.
11. Links to Third-Party Websites
This website may contain links to third-party websites or services.
We are not responsible for the privacy practices, content or security of third-party websites. You should review the privacy policies of any external websites you visit.
12. Children’s Data
This website is intended for business and professional audiences. It is not directed at children, and we do not knowingly collect personal data from children.
If you believe that a child has provided personal data through this website, please contact us so that appropriate action can be taken.
13. Changes to This Policy
This Privacy Policy may be updated from time to time to reflect changes in the website, services, legal requirements or data processing practices.
The updated version will be published on this page with a revised “Last updated” date.
14. Contact
For questions about this Privacy Policy or the processing of your personal data, contact:
Leonardo Fiori
Email: fiorileonardo20@gmail.com
Website: leonardofiori.com