Skip to content
Di MarcoCapital

Legal

Privacy Policy

How Di Marco Capital handles personal data when you visit this website, send an enquiry, request a meeting or work with the practice. Written for an Italy / European Union context under Regulation (EU) 2016/679 (GDPR) and Legislative Decree 196/2003 as amended.

Effective / last updated
20 August 2026
Contact for this document
contact@dimarcocapital.co

01

Who is responsible for your data

“Di Marco Capital” is the trading and project name used by Gianluca Jesus Di Marco Nader, Founder & Managing Director, for an independent financial intelligence and consulting practice operating from Italy / the European Union. No legal entity has been constituted at the date of this document.

The data controller of record is controller legal identity to be confirmed, with registered address registered address pending and, where applicable, VAT / tax identification number pending. Until those details are confirmed, all data protection requests are handled by the founder at contact@dimarcocapital.co.

No Data Protection Officer has been appointed. Based on the current scale and nature of processing, appointment is not believed to be mandatory under Article 37 GDPR; this will be reassessed as the practice grows.

02

Scope of this policy

This policy applies to https://dimarcocapital.co/ and to business correspondence, contact forms, meeting requests and analytical intake forms operated through it. It is addressed primarily to business contacts (B2B) and to individuals who approach the practice on their own behalf. It does not apply to third-party websites reachable through links.

03

Categories of personal data we process

  • Identity and contact data — full name, work email address, company or organisation, role, telephone number (optional), country.
  • Enquiry content — the service you are interested in, company size, message text, meeting preferences, time zone and any information you choose to include.
  • Consent records — whether you accepted this policy, whether you gave separate optional marketing consent, the policy version and the timestamp.
  • Technical and source data — landing page, referring URL, UTM campaign parameters, browser-reported language, and a one-way hash derived from IP address and browser signature used solely for abuse prevention and rate limiting. Raw IP addresses are not stored in our application database.
  • Analytical intake data — where you voluntarily use the Financial Snapshot intake, the business context, ranges and priorities you submit.

Please do not submit special categories of data (Article 9 GDPR), sensitive financial documents, account credentials or third-party personal data through the public forms. The public contact form does not accept file uploads for this reason.

05

Contact forms and meeting requests

Submissions to the contact form are validated and written to our database through a server-side function. You are shown a success message only after the record has been confirmed as stored. If storage fails, you are told so honestly and given the direct email address contact@dimarcocapital.co.

Where a public scheduling link is used to book a meeting, that booking is processed by the scheduling provider under its own privacy policy, and the data you enter there (name, email, chosen slot, notes) is received by us in order to hold the meeting. Where scheduling is handled by correspondence instead, your proposed windows are stored with the enquiry and the meeting exists only once confirmed by reply.

06

Recipients and processors

  • Hosting and application platform — the provider that serves this website and runs its server functions.
  • Database and backend — Supabase, storing enquiry, meeting-request and relationship records.
  • Transactional email — Resend, used to deliver enquiry notifications and acknowledgements once the sending domain is verified.
  • Calendar and productivity — Google Workspace, for correspondence and meeting scheduling.
  • Professional advisers — accountants or lawyers, where necessary and bound by confidentiality.

Additional operational tools (for example a Notion-based internal CRM or secure document storage in Google Drive) may be introduced; this policy will be updated before any new category of recipient begins processing your data. Processors act on documented instructions under Article 28 GDPR data processing agreements. We do not sell personal data and do not use it for automated decision-making producing legal effects.

07

International transfers

Some providers listed above may process data outside the European Economic Area, in particular in the United States. Where this occurs, transfers rely on an adequacy decision of the European Commission where one applies, or otherwise on Standard Contractual Clauses adopted by the Commission together with supplementary technical measures such as encryption in transit and at rest. You may request information about the safeguards applied by writing to contact@dimarcocapital.co.

08

Retention periods

  • Enquiries that do not lead to an engagement — up to 24 months from the last contact, then deleted or anonymised.
  • Client relationship records — for the duration of the relationship and up to 10 years afterwards where Italian civil and tax law requires records to be kept.
  • Marketing consent records and mailing entries — until consent is withdrawn, plus the period needed to evidence the withdrawal.
  • Security and rate-limiting hashes and technical logs — a short operational period, normally not exceeding 12 months.

Final retention schedules are subject to confirmation on legal review once the controller identity and applicable statutory obligations are fixed.

09

Security

Data is transmitted over TLS, stored in a managed database with row-level security enabled, and reachable only through validated server-side functions using least-privilege access. Administrative access is limited to the founder. Public forms apply honeypot checks and rate limiting. No method of transmission or storage is completely secure, and we do not claim absolute security; we do commit to notifying the supervisory authority and affected individuals where a personal data breach requires it under Articles 33 and 34 GDPR.

10

Your rights

Subject to the conditions in the GDPR, you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), including objection to processing based on legitimate interest. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

To exercise any right, write to contact@dimarcocapital.co. We respond within one month, which may be extended by two further months for complex requests. We may ask for information needed to verify your identity.

You also have the right to lodge a complaint with a supervisory authority. In Italy this is the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it. You may alternatively complain to the authority of your EU country of residence or workplace.

11

Cookies and analytics

This website relies on strictly necessary browser storage for language preference, form handling and security. It does not intentionally set advertising or cross-site tracking cookies. Any usage measurement performed is aggregated and privacy-conscious, and no third-party analytics or advertising vendor is enabled at the date of this document.

Enabled analytics and cookie vendors, if any are introduced, will be listed here: analytics and cookie vendor list pending. Non-essential technologies will only be activated behind a compliant consent mechanism. See the Cookie Policy for detail.

12

Children

The site addresses business and professional audiences and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided data, contact contact@dimarcocapital.co and it will be deleted.

13

Changes to this policy

We may update this policy when practices, providers or legal obligations change. The effective date and version identifier at the top of this page always reflect the current version, and the version accepted at the time of your submission is stored with your record (current version: 2026-08-20-privacy-v1). Material changes will be signalled on this page.

Questions about this document: contact@dimarcocapital.co — or use the contact form.