Legal

Privacy Policy

How Mebius srl processes personal data under the EU General Data Protection Regulation (GDPR, Reg. EU 2016/679).

Information on the processing of personal data pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR). Last updated: 13 July 2026.

1. Data Controller

Mebius srl — Via L'Aquila 23/m, Rome, Italy · VAT IT08694131007 · Email info@mebius.it · Phone +39 02.45.07.11.08.

To exercise your rights, or for any question about this policy, write to info@mebius.it.

No Data Protection Officer (DPO) has been appointed, as the conditions of Art. 37 GDPR do not apply.

2. What data we collect

a) Data you give us through the contact forms. First and last name, company, email address, phone number, and the content of your message. We also record the fact that you gave your consent, with the date and the exact wording you accepted: this is our proof that consent was collected properly, and your guarantee.

b) Data collected automatically while you browse. IP address, browser type (user agent), pages visited, date and time. This data is recorded in the server logs for security and service operation purposes.

c) Attribution data. When you reach the site from an advertisement, a search engine or another website, we keep the information on where you came from: advertising click identifiers (Google's gclid, gbraid, wbraid), campaign parameters (utm_*), the first page you landed on and the referring site. We use it to understand which of our initiatives actually work. The cookies involved are detailed in the Cookie Policy.

We do not collect special categories of data (Art. 9 GDPR: health, political opinions, religious beliefs, biometric data, sexual orientation). Please do not enter any in the message field.

3. Why we process your data, and on what legal basis

  • Answering your request for information, a quote or a commercial contact — pre-contractual measures at your request (Art. 6.1.b GDPR). The consent we ask for in the form is an additional transparency safeguard, not the legal basis of the processing.
  • Measuring the effectiveness of our advertising campaigns and understanding which channels bring useful enquiries — legitimate interest (Art. 6.1.f GDPR), balanced by the use of first-party, non-identifying data.
  • Keeping the site secure and preventing abuse (logs, anti-spam, rate limiting) — legitimate interest (Art. 6.1.f GDPR).
  • Sending commercial communications and newsletters (where active) — consent, freely given, specific and revocable (Art. 6.1.a GDPR).
  • Complying with legal obligations (tax, accounting, requests from authorities) — legal obligation (Art. 6.1.c GDPR).

Providing the data marked as mandatory in the form is necessary for us to get back to you: without it, the request cannot be handled. Everything else is optional.

4. How long we keep the data

  • Client data and contractual relationships: 10 years — civil and tax obligations (Art. 2220 of the Italian Civil Code).
  • Contacts subscribed to our communications (the Mystery Marketing News magazine, newsletters): until consent is withdrawn. The legal basis is consent: as long as you do not withdraw it, the editorial relationship continues. Every mailing contains an unsubscribe link.
  • Form enquiries without consent to communications: 36 months from the last contact. The B2B sales cycle can reach 12 months: three years cover the review of the enquiry.
  • Server logs: 12 months — security and investigation of abuse.
  • Attribution data (first-party cookies): 90 days, the lifetime of the cookie.

Once these periods expire, data is deleted or irreversibly anonymised.

5. Where your data is processed

Data submitted through the forms is processed on Mebius srl's own infrastructure (internal CRM), hosted by OVH on servers located in France, therefore within the European Union. OVH acts as a data processor under Art. 28 GDPR and its data centres are ISO/IEC 27001 certified.

Form data does not leave the European Union. We do not transfer form data to third-party marketing automation platforms. Until 12 July 2026 the forms were served by ActiveCampaign: this is no longer the case.

6. Who we share data with

Data may be processed by authorised Mebius srl staff and by the suppliers providing us with technical services, appointed as data processors (Art. 28 GDPR):

  • OVH (France, European Union) — hosting of the websites and of the CRM. ISO/IEC 27001 certified data centres.
  • Twilio SendGrid (Twilio Inc., United States) and Amazon Web Services — Amazon SES (Amazon Web Services EMEA SARL) — delivery of transactional emails and editorial communications: SendGrid for the CRM's transactional notifications, Amazon SES as the transport for editorial communications.
  • Google Ireland Ltd / Google LLC — Google Analytics 4 and Google Tag Manager, for the statistical measurement of site visits.

Data is not disclosed publicly and is never sold or transferred to third parties for marketing purposes.

Transfers outside the European Union. Some suppliers are based in the United States (Twilio SendGrid and the Google services). In those cases the transfer takes place on the basis of the Standard Contractual Clauses approved by the European Commission and/or of the EU-US Data Privacy Framework certification. You can ask us for a copy of the safeguards in place by writing to info@mebius.it.

7. Your rights

You have the right to: access your data and obtain a copy of it (Art. 15); ask for its rectification if inaccurate or incomplete (Art. 16); ask for its erasure (Art. 17); ask for the restriction of processing (Art. 18); receive your data in a machine-readable format and transmit it to another controller (portability, Art. 20); object to processing based on legitimate interest, including direct marketing (Art. 21); withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.

To exercise these rights, write to info@mebius.it. We reply within one month, extendable by two further months in complex cases (Art. 12.3 GDPR).

If you believe the processing infringes the GDPR, you may lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it) or bring the matter before the courts.

8. Automated decision-making

We do not carry out automated decision-making or profiling producing legal effects concerning you (Art. 22 GDPR).

9. Security

We adopt technical and organisational measures appropriate to protect the data: encrypted connections (HTTPS), access restricted to authorised staff, protection of public endpoints against automated abuse.

Mebius srl is ISO 9001 certified. The data centres hosting our systems are ISO/IEC 27001 certified.

10. Cookies

The cookies used by this site are detailed in the Cookie Policy. You can review your choices at any time from the cookie preferences.