Last updated: 3 July 2026

This policy describes how the personal data of users visiting tradingblog.it is processed, pursuant to Regulation (EU) 2016/679 (the “GDPR”) and applicable data protection law.

1. Data Controller

The Data Controller is Tiziano Brunno (natural person), NIF Y3735028A, resident in Spain.
Contact email: tiziano@tradingblog.it

2. Types of data collected

  • Data provided voluntarily: name and email you submit through the newsletter, contact or free-resource download forms.
  • Browsing data: IP address, browser, device and operating system, pages visited, referrer, date and time, collected mainly in aggregated form for statistical and security purposes.
  • Cookies and identifiers: see the Cookie Policy for the detailed list and durations.

3. Purposes and legal bases

  • Responding to requests sent through contact forms — legal basis: pre-contractual measures / legitimate interest (art. 6.1.b/f).
  • Sending the newsletter and informational material — legal basis: consent (art. 6.1.a), revocable at any time.
  • Statistical analysis of site usage — legal basis: consent to analytics cookies (art. 6.1.a).
  • Protection against spam, abuse and site security — legal basis: legitimate interest (art. 6.1.f).
  • Compliance with legal obligations — legal basis: legal obligation (art. 6.1.c).

Providing data for the newsletter and forms is optional; failure to provide it only prevents use of the related service.

4. Third-party services and data processors

To provide its services the site uses third-party providers, acting as data processors or independent controllers under their respective policies:

Provider Purpose Location Non-EU safeguard
Brevo SA (formerly Sendinblue) Newsletter & contact management France (EU)
Google Ireland Ltd – Google Analytics Browsing statistics Ireland (EU) EU-US DPF (for any US transfers)
Google LLC – reCAPTCHA / YouTube Form protection / embedded videos USA EU-US DPF / SCC
Automattic Inc. – Akismet Anti-spam filter USA SCC / DPF
Defiant Inc. – Wordfence Security and attack protection USA SCC
Hostinger International Ltd Website hosting EU (data center)

An up-to-date list of processors is available on request by writing to the Controller.

5. Transfers of data outside the EU

Some providers are based in the United States. Any transfer of data outside the European Economic Area takes place only with adequate safeguards under Chapter V of the GDPR, such as the Standard Contractual Clauses (SCC) adopted by the European Commission and/or membership of the EU-US Data Privacy Framework. You may request a copy of the safeguards by writing to the Controller.

6. Retention period

  • Newsletter: until consent is withdrawn (unsubscribe); subsequent deletion within technical timeframes.
  • Contact requests: for the time needed to handle the request and any defence needs.
  • Statistical data / Google Analytics: maximum retention 14 months.
  • Security logs: for the time needed to protect the site.

7. Rights of the data subject

At any time you may exercise the following rights under articles 15-22 of the GDPR:

  • access to your data (art. 15);
  • rectification (art. 16) and erasure / right to be forgotten (art. 17);
  • restriction of processing (art. 18) and portability (art. 20);
  • objection to processing (art. 21), including direct marketing;
  • withdrawal of consent at any time (art. 7.3), without affecting processing already carried out.

To exercise them, write to tiziano@tradingblog.it. You also have the right to lodge a complaint with the competent supervisory authority: in Italy the Garante per la protezione dei dati personali (garanteprivacy.it), in Spain the AEPD (aepd.es).

8. Security measures

The Controller adopts appropriate technical and organisational measures under article 32 of the GDPR, including: encrypted HTTPS/TLS connection, access control, perimeter protection and monitoring via Wordfence, software updates and periodic backups.

9. Data breaches

In the event of a personal data breach that poses a risk to the rights and freedoms of data subjects, the Controller will notify the supervisory authority within 72 hours and, where required, inform the data subjects without undue delay.

10. Minors

The site is not intended for minors under 16 and does not knowingly collect their data. Should a minor have provided data without the consent of the holder of parental responsibility, the parent/guardian may contact the Controller for deletion.

11. Important notice

The content of tradingblog.it is for informational and educational purposes only and does not constitute financial, investment, tax or legal advice, nor solicitation of public savings. Trading involves a high risk of capital loss.

12. Changes

The Controller reserves the right to update this policy. The version published on this page, with its date, is the one in force.