Privacy policy
How we use and protect personal data.
This policy explains what Mobility in Change collects through this website, why it is used, where it is processed, how long it is kept and how you can exercise your rights under the GDPR.
The short version
You can browse without identifying yourself. We use inquiry details only to respond and manage a possible professional relationship. Optional analytics stay off unless you choose them. We do not sell personal data, run advertising profiles or make automated decisions about you.
1. Controller and contact
The data controller is the operator identified in the legal details on this page. The controller determines why and how personal data collected through this website is processed.
For privacy questions or a rights request, use the email address below. No data protection officer has been appointed because the activities described here do not require one under Article 37 GDPR.
2. Data we collect
When you send an inquiry, we collect your name, work email, company, and the service, market, timing and preferred next step you select. Your role, current situation and desired outcome are optional. Please do not send special-category or other unnecessary personal data.
When the site or its security controls are used, hosting systems necessarily process technical request data such as IP address, browser/device information, requested URL, timestamps and security events. The application stores only a salted hash derived from IP address and user agent for short-lived rate limiting; it does not store the raw IP in its database.
3. Purposes and legal bases
We process only what is necessary for the following purposes:
- Answer and assess an inquiry and take steps requested before a possible contract — Article 6(1)(b) GDPR.
- Manage follow-up, maintain a non-identifying daily count of submitted inquiries, and protect the website against spam, abuse and security incidents — our legitimate interests under Article 6(1)(f) GDPR.
- Meet accounting, tax, legal and regulatory duties where they arise — Article 6(1)(c) GDPR.
- Measure site use and content performance only after your optional consent — Articles 6(1)(a) and 7 GDPR and Article 122 of the Italian Privacy Code.
4. Optional analytics and device storage
Analytics are disabled by default. If you accept, our first-party system records page path, language, referrer origin/path and clicks to services or the inquiry flow. Form contents are never sent as analytics metadata. We use the results for aggregate site measurement, not advertising or cross-site tracking.
The browser stores one first-party local-storage value named mobility-analytics-consent until you change or clear the choice, or the consent version changes. The technical NEXT_LOCALE cookie remembers language for up to 12 months; Clerk authentication cookies are used only when an authorised person enters sign-in or administration. These records are strictly necessary for the requested preference or function. You can withdraw analytics consent as easily as you gave it using Privacy settings in the footer; processing stops for future visits without affecting earlier lawful processing.
5. Recipients and processors
Access is restricted to the controller and specifically authorised administrators. Necessary processors may include Vercel (hosting and Blob media), Neon (Postgres database), Microsoft (Microsoft 365/Graph email), and Clerk (authentication used only on administrator sign-in and administration routes). Their personnel may act only under contractual and confidentiality obligations.
Inquiry information is stored in Neon and copied to the Mobility in Change Microsoft 365 mailbox so it can be answered. Providers may process limited technical logs for reliability, security and abuse prevention under their own documented retention controls. We do not sell or rent personal data.
6. Processing outside the EEA
We choose European processing regions where the service and production configuration permit. Some providers or support operations may involve the United States or another country outside the EEA. Where no adequacy decision applies, transfers are protected by the European Commission's Standard Contractual Clauses and supplementary safeguards as required by Articles 44–49 GDPR. You may request information about the relevant safeguard.
7. Retention and deletion
We apply the following maximum periods, then delete or irreversibly aggregate data unless a longer period is required to establish, exercise or defend legal claims or comply with law:
- Inquiry records that do not become a client engagement: 24 months after the last interaction.
- Website analytics events: 13 months; non-identifying daily aggregate counts: 25 months.
- Pseudonymous rate-limit records: no more than 48 hours.
- Contract, invoice and transaction records created outside this inquiry system: for the statutory period that applies, normally 10 years for Italian accounting records.
8. Your GDPR rights
Subject to the conditions and exceptions in law, you may:
- ask whether we process your data and receive access and a copy;
- correct inaccurate or incomplete data;
- request deletion, including inquiry data that is no longer necessary;
- restrict processing in the cases set out by Article 18 GDPR;
- receive data you provided in a portable format where Article 20 applies;
- object to processing based on legitimate interests; and
- withdraw consent at any time. You also have the right not to be subject to qualifying solely automated decisions; we do not make such decisions.
9. How to exercise your rights
Email the address below with the subject “Data protection request” and enough information to locate your inquiry. State whether you want access, correction, restriction, portability, objection or deletion. We may request proportionate information to verify identity before disclosing or deleting data.
Requests are normally free. We will respond without undue delay and within one month. If a request is complex, we may extend by up to two further months and explain the extension within the first month. Deletion is not absolute where retention is legally required, but we will explain any refusal and available remedies.
10. Complaints
You may complain to the Garante per la protezione dei dati personali, the Italian supervisory authority, or to the supervisory authority where you live or work. You may also seek a judicial remedy. We invite you to contact us first so we can address the concern promptly.
11. Required information and automated decisions
The inquiry form marks the information needed for us to assess and answer you. Without required fields we cannot process the inquiry. Providing optional fields is voluntary. We do not use this website data for automated decision-making or profiling that produces legal or similarly significant effects.
12. Changes to this policy
We may update this policy when processing, providers or law changes. The effective date above identifies the current version. If a change materially affects consent-based processing, we will request a new choice before that processing continues.
