Privacy Policy
Protecting the privacy and security of the personal data of everyone who visits our website or contacts us is a serious responsibility for us. Below we explain transparently what data we collect, for what purpose and on what legal basis we process it, and the rights you hold. We act in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Italian Personal Data Protection Code (Legislative Decree 196/2003, as amended by Legislative Decree 101/2018). By using the site or submitting an enquiry, you confirm that you have read this Policy.
Effective date: 20 July 2026
Data controller
The controller that determines the purposes and means of processing personal data on this website is:
- Firm
- Carrara e Associati — Studio Legale
- Address
- Piazza Napoli, 36 — 20146 Milano (MI)
- Responsible person
- Tancredi Carrara
- Contact
- studio@carrara-associati.it
Definitions
- Personal data — any information that identifies, or can reasonably be used to identify, a natural person.
- Processing — any operation performed on personal data: collection, recording, storage, alteration, use, disclosure, restriction, erasure or destruction.
- Controller — Carrara e Associati, as the party determining the purposes and means of processing.
- Data subject — a natural person whose data is processed.
Data we collect
Provided directly by you: name and contact details (email, phone, country of residence); information about your case, voluntarily provided via forms or communication channels; copies of identity documents where required by law for customer due-diligence purposes; any other data you choose to provide.
Collected automatically: IP address (in anonymised form), browser type and version, operating system, time zone; information about how you use the site (pages viewed, time spent); cookies (see the “Cookies” section).
Obtained from third parties: data from publicly available sources; information from financial institutions, brokers or law-enforcement or judicial authorities in the course of the recovery process — where permitted by law.
Purposes of processing
- Providing our services — assessing, managing and carrying out the recovery of funds from fraudulent brokers or financial institutions.
- Communication — responding to your enquiries and keeping you updated on your case.
- Legal obligations — complying with regulatory requirements, Italian anti-money-laundering legislation (Legislative Decree No 231 of 21 November 2007) and requests for information from the authorities.
- Website operation — performance analysis, security and improving the user experience.
- Information — sending information about our services where you have given consent.
Legal bases for processing
We process personal data only where a legal basis exists and collect only as much as is necessary for the specific purpose. Legal bases under the GDPR:
- Consent (Art. 6(1)(a)) — where you voluntarily provide data and consent to its use.
- Performance of a contract (Art. 6(1)(b)) — where processing is necessary to provide the services or take pre-contractual steps.
- Legal obligation (Art. 6(1)(c)) — where required by law.
- Legitimate interests (Art. 6(1)(f)) — where processing is necessary for our operational, legal or security interests and does not override your rights.
Enquiries via the contact form
The data you submit via the contact form (name, contact details, the content of your enquiry) is used solely to handle your request and to communicate with you. It is not shared with third parties, except where necessary to provide the legal service (for example, involving a court or the opposing party within the mandate) or where required by law. It is retained for as long as needed to process the request and in line with statutory retention periods, after which it is deleted.
Cookies and data collected when you visit the site
When you access the site, the server temporarily processes technical data that your browser transmits automatically (browser type, date and time of the request, IP address in anonymised form). This is necessary for the stable and secure operation of the site and is not used to identify individual users.
In addition to the technically necessary cookies the site needs in order to work, we use analytics and audience-measurement tools (Google Tag Manager and Google Analytics), which are activated when the page loads: the cookie notice shown to you is informational and does not make their loading conditional on your action. You may disable cookies in your browser settings or use the opt-out add-ons made available by the provider; without them, some site features may not work correctly.
Sharing and disclosure of data
We share data only in limited circumstances: with authorised staff, lawyers and advisers solely to provide the service; with technical processors (hosting, analytics, payment processors) under strict data-processing agreements; with regulators, authorities, courts or banks where required by law. We do not sell, rent or transfer your personal data to third parties for commercial purposes.
Storage and retention of data
We store data in secure environments within the European Union. Personal data is retained only for as long as necessary for the purpose of processing, or in line with statutory retention periods (in particular professional and tax-law obligations). Once these periods expire, the data is securely deleted or anonymised.
Security measures
We implement technical and organisational measures to protect your data — encryption, secure servers, access controls, firewalls and ongoing monitoring. That said, no system or transmission of data over the internet can guarantee absolute (100%) security.
International data transfers
Should a transfer of data outside the European Economic Area (EEA) become necessary, it will take place only with appropriate safeguards — in particular the Standard Contractual Clauses (SCCs) approved by the European Commission, which ensure an adequate level of protection.
Your rights
Under the GDPR, you have the right to:
- access — to know, free of charge, what data we hold about you;
- rectification of inaccurate or incomplete data;
- erasure (the “right to be forgotten”);
- restriction of processing;
- portability — to receive your data in a structured format or have it transferred to another provider;
- objection to processing based on legitimate interest, and withdrawal of consent at any time (without affecting the lawfulness of prior processing);
- complaint to the Garante per la protezione dei dati personali, which is the single data-protection supervisory authority in Italy; as an alternative to a complaint, you may bring the matter before the courts.
To exercise your rights, please send a written request to the contact details set out below.
Contact information
For any questions, or to exercise your rights, please contact us:
- Firm
- Carrara e Associati — Studio Legale
- Address
- Piazza Napoli, 36 — 20146 Milano (MI)
- Website
- carrara-associati.it
- Office hours
- Mon–Fri, 09:00–18:00 CET
Changes to this policy
We may update this Privacy Policy to reflect changes in the law, industry practice or our internal processes. The current version is always available on this page, stating the effective date.

