Skip to content

Data protection

Privacy
Policy.

Courtesy translation. Only the Italian version is legally binding.

This page describes how personal data are processed for visitors of massimilianosilla.com, for those who use the forms and for those who access the client area, pursuant to Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.

Data controller

The data controller is Massimiliano Silla, Viale dell’Arte 25, 00144 Rome, Italy, registered with the Italian Register of Financial Advisers (OCF) by resolution no. 2425 of 19/03/2024, VAT IT10577390585. For any request concerning personal data: info@massimilianosilla.com or massimiliano.silla@pec.it.

No Data Protection Officer has been appointed: the cases set out in Article 37 GDPR do not apply.

Data collected and purposes

Contact form. Name, email address, phone number if provided, and the message. Used to reply to the enquiry. Nothing is stored by the website: the message is forwarded by email to the firm’s mailbox and nothing remains on our systems.

Monthly newsletter sign-up. The email address only. Until the subscription is confirmed the address is not recorded anywhere: it travels inside a signed link and expires with it. Only the confirmation click records it.

Weekly newsletter. Reserved for clients of the firm and activated with the advisory relationship. No sign-up from the site.

Client area. Email address for access, plus the documents and portfolio positions the firm uploads for the client. See the dedicated section below.

Technical data. As on any website, servers log the IP address and connection data, to run the service and protect it from abuse. No analytics or profiling tool is in use: no Google Analytics, no advertising pixel, no identifier that follows the user.

Legal basis

  • Consent (Art. 6.1.a): monthly newsletter subscription. It can be withdrawn at any time, with one click from the link at the bottom of every issue.
  • Performance of pre-contractual measures and of the contract (Art. 6.1.b): replies to contact enquiries, advisory service, weekly newsletter to clients, client area.
  • Legal obligation (Art. 6.1.c): tax obligations and those laid down by financial advice regulations.
  • Legitimate interest (Art. 6.1.f): site security and protection against automated submissions and unauthorised access.

Data recipients

Data are neither disclosed nor sold to third parties for their own purposes. The following providers process data on our behalf, as processors and on our instructions — each one verified against the site’s code:

  • Cloudflare, Inc. — hosts and delivers the site, runs the code behind the forms and the client area, and holds its database, sessions and documents. Every visit goes through its servers.
  • Brevo (Sendinblue SAS, France) — sends the emails: contact form messages, subscription confirmations, access codes and the newsletters. It stores subscribers’ addresses.
  • Friendly Captcha GmbH (Germany) — the “not a robot” check on the forms. The browser contacts it when pages containing a form are opened.
  • jsDelivr — the network delivering the script for that check. Contacted at the same moments.
  • Hostinger — provides the firm’s mailbox, where contact form messages arrive.

Friendly Captcha and jsDelivr are contacted when the page loads on pages containing a form — Contacts, Insights, Resources and Sign in — and not on the others. The sign-in dialog present on every page contacts them only if it is opened.

Some providers may process data outside the European Union: transfers take place on the basis of the Standard Contractual Clauses approved by the European Commission.

Client area

The client area is built not to hold the identity of those who access it.

  • The database contains no names, surnames, addresses or tax codes: each client is a six-digit number.
  • The email address is not stored in clear text, only as a cryptographic fingerprint, which serves to recognise it and not to read it.
  • Access uses a one-time code sent by email, valid for five minutes; after five wrong attempts a new code is required. The session lasts twenty-four hours.
  • Documents are encrypted (AES-GCM, with a different key for each document).
  • Positions and transactions are stored in clear text so they can be aggregated, but tied to the six-digit number and not to an identified person.
  • A log records when a code was requested and used, and when the client opens their investments page. It serves to notice unusual access and, should data ever reach the wrong area, to know whether it was opened. The log is tied to the six-digit number, not to an identified person.

Data retention

  • Contact form messages: not stored by the site; they remain in the firm’s mailbox for as long as needed to reply and to document the contact.
  • Newsletter subscribers: until unsubscription.
  • Access codes: five minutes, then they expire.
  • Sessions: twenty-four hours.
  • Client area documents and positions: ten years from the signing of the contract and five years from the end of the relationship, whichever of the two falls later. Once the period has elapsed, the data is deleted.

Rights of the data subject

The rights set out in Articles 15-22 GDPR may be exercised at any time — access, rectification, erasure, restriction, portability and objection — as well as withdrawal of consent, without affecting the lawfulness of processing carried out beforehand. Requests should be sent to the controller’s contact details.

A complaint may also be lodged with the Italian Data Protection Authority (garanteprivacy.it).

Cookies and similar technologies

This site uses no profiling, analytics or marketing cookies, and for that reason there is no banner to accept.

There are two cookies, both technical, both needed to make something you asked for work.

__Host-sessione is created only for those who access the client area, lasts twenty-four hours and keeps the session open. Without it, staying signed in from one page to the next would not be possible.

__Host-iscritto is created when you confirm your subscription to the monthly newsletter, or when you prove you are already subscribed. It holds your email address and an expiry date, both signed, and serves one purpose: letting you repeat the calculation in the estate-division simulator, which without it can be run only once. It lasts six months. You can delete it from your browser at any time — you will lose only that recognition, not the subscription.

Neither follows what you do on this site or anywhere else, and neither can be read by third parties: both carry the __Host- prefix, which binds them to this domain and to a secure connection.

Last updated: 16 September 2026. Every provider named on this page is verified against the site’s code, and an automated test checks that the list does not fall behind.

Let’s talk about
your wealth.

A first confidential meeting, with no obligation, to understand where to start.

Request a meeting