Skip to content

Privacy notice

Privacy Policy

This notice explains which personal data is collected through this website, why it is processed and which rights you can exercise, under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

Last updated: 2 August 2026

1. Data controller

The data controller is PSW SAS — VAT 12366081003, which operates this website and the professional activities of Fabio De Leonardis.

For any request concerning personal data you can write to fabio.deleonardis@bigup.marketing.

No Data Protection Officer has been appointed, as the conditions set out in Article 37 GDPR do not apply.

2. What data I collect

The website requires no registration and builds no user profiles. Personal data is collected only in the following cases.

  • Data you enter in the contact form: name, email address and message are required; company, website, sector, type of collaboration, budget range, organisation size and timing are optional.
  • Direct contact data: if you write by email, call or use WhatsApp, I process the data you choose to share in that message.
  • Technical context of the request: landing page, page language, referring website and any campaign parameters in the address (UTM and advertising click identifier), submitted with the form to understand where the request came from.
  • Navigation data logged by the server: IP address, date and time of the request, browser type and technical information needed for the operation and security of the site.
  • Data collected through cookies and measurement tools, described in the Cookie Policy and activated only according to your choices.

Please do not include special categories of data in your message (health, political opinions, religious beliefs and similar): they are not needed to answer a professional enquiry.

3. Purposes and legal bases

PurposeLegal basis
Responding to requests received through the form, email, phone or WhatsAppPre-contractual measures taken at the data subject’s request, Art. 6.1.b GDPR
Managing the professional relationship and the consulting work that followsPerformance of a contract, Art. 6.1.b GDPR
Keeping the website secure, preventing abuse and limiting automated submissionsLegitimate interest of the controller in system security, Art. 6.1.f GDPR
Measuring website usage through analytics toolsConsent given through the cookie banner, Art. 6.1.a GDPR
Sending occasional communications about digital marketing topics, if you ticked the optional boxConsent, withdrawable at any time, Art. 6.1.a GDPR
Meeting accounting, tax and legal obligationsLegal obligation, Art. 6.1.c GDPR

4. Whether providing data is mandatory

Providing the data marked as required in the form is necessary to handle the request: without a name, an email address and a message there is no way to reply.

All other fields are optional and only help me understand the context before the first conversation. Consent to optional communications is free and refusing it has no effect on the reply to your request.

5. Cookies and measurement tools

The website uses technical cookies necessary for its operation and, subject to consent, measurement and advertising tools. Categories, purposes and how to change your choices are described in the Cookie Policy.

6. Who receives the data

Data is never disseminated and is not sold to third parties for their own commercial purposes. It may be processed on behalf of the controller, as data processors, by the suppliers that make the service possible.

  • Hosting and infrastructure provider that hosts the website and records its technical logs.
  • Email service provider used for correspondence.
  • Contact management system used to record and follow up on received requests.
  • Providers of measurement and advertising tools, activated only after consent.
  • Accounting and tax advisors, within the limits of legal obligations.

Data may also be disclosed to public authorities where disclosure is required by law or necessary to establish, exercise or defend a legal claim.

7. Transfers outside the European Economic Area

Some technology providers, particularly those related to online measurement and advertising, may process data outside the European Economic Area. In those cases the transfer relies on an adequacy decision of the European Commission or on the standard contractual clauses provided for by Article 46 GDPR, together with the supplementary safeguards applied by each provider.

8. How long data is kept

  • Requests that do not lead to a professional relationship: kept for as long as needed to handle the conversation and to answer any follow-up, then deleted.
  • Data related to active professional relationships: kept for the duration of the relationship and afterwards for the periods required by accounting, tax and limitation rules.
  • Data processed on the basis of consent: kept until consent is withdrawn.
  • Server technical logs: kept for the period needed for system security and diagnostics.
  • Data collected through cookies: kept for the durations indicated in the Cookie Policy.

9. Your rights

At any time you can exercise the rights set out in Articles 15 to 22 GDPR.

  • Access to the personal data concerning you and to information about its processing.
  • Rectification of inaccurate data and completion of incomplete data.
  • Erasure of data, in the cases provided for by law.
  • Restriction of processing.
  • Portability of the data you provided, in a structured, machine-readable format.
  • Objection to processing based on legitimate interest.
  • Withdrawal of consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.

To exercise these rights, simply write to fabio.deleonardis@bigup.marketing describing your request. You will receive a reply within the deadlines set by law.

10. Complaint to a supervisory authority

If you believe that the processing of your data infringes data protection law, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome) or with the supervisory authority of the Member State where you habitually reside.

11. Security and minors

The website is served over an encrypted connection and applies technical and organisational measures appropriate to the risk, including limits on automated form submissions and access controls on the systems holding the data.

The services described here are addressed to organisations and professionals: they are not intended for children under sixteen and I do not knowingly collect data concerning them.

12. Changes to this notice

This notice may be updated to reflect changes to the services, to the tools in use or to the legal framework. The date of the last update is shown at the top of the page: significant changes will be signalled on the website.

Questions about this notice?

If you want to exercise your rights or need a clarification about how data is handled, write to me: I reply personally.

Send an email