Last updated: 3 July 2026
This policy describes how the personal data of users visiting tradingblog.it is processed, pursuant to Regulation (EU) 2016/679 (the “GDPR”) and applicable data protection law.
1. Data Controller
The Data Controller is Tiziano Brunno (natural person), NIF Y3735028A, resident in Spain.
Contact email: tiziano@tradingblog.it
2. Types of data collected
- Data provided voluntarily: name and email you submit through the newsletter, contact or free-resource download forms.
- Browsing data: IP address, browser, device and operating system, pages visited, referrer, date and time, collected mainly in aggregated form for statistical and security purposes.
- Cookies and identifiers: see the Cookie Policy for the detailed list and durations.
3. Purposes and legal bases
- Responding to requests sent through contact forms — legal basis: pre-contractual measures / legitimate interest (art. 6.1.b/f).
- Sending the newsletter and informational material — legal basis: consent (art. 6.1.a), revocable at any time.
- Statistical analysis of site usage — legal basis: consent to analytics cookies (art. 6.1.a).
- Protection against spam, abuse and site security — legal basis: legitimate interest (art. 6.1.f).
- Compliance with legal obligations — legal basis: legal obligation (art. 6.1.c).
Providing data for the newsletter and forms is optional; failure to provide it only prevents use of the related service.
4. Third-party services and data processors
To provide its services the site uses third-party providers, acting as data processors or independent controllers under their respective policies:
| Provider | Purpose | Location | Non-EU safeguard |
|---|---|---|---|
| Brevo SA (formerly Sendinblue) | Newsletter & contact management | France (EU) | — |
| Google Ireland Ltd – Google Analytics | Browsing statistics | Ireland (EU) | EU-US DPF (for any US transfers) |
| Google LLC – reCAPTCHA / YouTube | Form protection / embedded videos | USA | EU-US DPF / SCC |
| Automattic Inc. – Akismet | Anti-spam filter | USA | SCC / DPF |
| Defiant Inc. – Wordfence | Security and attack protection | USA | SCC |
| Hostinger International Ltd | Website hosting | EU (data center) | — |
An up-to-date list of processors is available on request by writing to the Controller.
5. Transfers of data outside the EU
Some providers are based in the United States. Any transfer of data outside the European Economic Area takes place only with adequate safeguards under Chapter V of the GDPR, such as the Standard Contractual Clauses (SCC) adopted by the European Commission and/or membership of the EU-US Data Privacy Framework. You may request a copy of the safeguards by writing to the Controller.
6. Retention period
- Newsletter: until consent is withdrawn (unsubscribe); subsequent deletion within technical timeframes.
- Contact requests: for the time needed to handle the request and any defence needs.
- Statistical data / Google Analytics: maximum retention 14 months.
- Security logs: for the time needed to protect the site.
7. Rights of the data subject
At any time you may exercise the following rights under articles 15-22 of the GDPR:
- access to your data (art. 15);
- rectification (art. 16) and erasure / right to be forgotten (art. 17);
- restriction of processing (art. 18) and portability (art. 20);
- objection to processing (art. 21), including direct marketing;
- withdrawal of consent at any time (art. 7.3), without affecting processing already carried out.
To exercise them, write to tiziano@tradingblog.it. You also have the right to lodge a complaint with the competent supervisory authority: in Italy the Garante per la protezione dei dati personali (garanteprivacy.it), in Spain the AEPD (aepd.es).
8. Security measures
The Controller adopts appropriate technical and organisational measures under article 32 of the GDPR, including: encrypted HTTPS/TLS connection, access control, perimeter protection and monitoring via Wordfence, software updates and periodic backups.
9. Data breaches
In the event of a personal data breach that poses a risk to the rights and freedoms of data subjects, the Controller will notify the supervisory authority within 72 hours and, where required, inform the data subjects without undue delay.
10. Minors
The site is not intended for minors under 16 and does not knowingly collect their data. Should a minor have provided data without the consent of the holder of parental responsibility, the parent/guardian may contact the Controller for deletion.
11. Important notice
The content of tradingblog.it is for informational and educational purposes only and does not constitute financial, investment, tax or legal advice, nor solicitation of public savings. Trading involves a high risk of capital loss.
12. Changes
The Controller reserves the right to update this policy. The version published on this page, with its date, is the one in force.

