Massimiliano Iannozzi
Consulente Finanziario Autonomo iscritto all’Albo OCF

 

 

Privacy Policy

Last updated: 1 September 2026

1. Introduction

This Privacy Policy explains how the personal data of users who visit and use www.maxinadvisory.com are processed.

This notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”) and Italian Legislative Decree No. 196/2003, as amended by Legislative Decree No. 101/2018 (the “Italian Data Protection Code”).

This Privacy Policy applies exclusively to processing carried out through the website and its related contact channels.

Where personal data are processed in connection with any contractual investment advisory relationship, the Client will receive a separate privacy notice together with the pre-contractual and contractual documentation.

This Privacy Policy does not apply to third-party websites, platforms or services that may be accessed through links on this website. Users are encouraged to review the relevant privacy notices issued by those third-party controllers.

2. Data Controller

The data controller is:

Massimiliano Iannozzi is registered with the Italian Single Register of Financial Advisers, in the Independent Financial Advisers Section, pursuant to OCF Resolution No. 2976 of 26 May 2026, registration No. 641736, under Italian Legislative Decree No. 58/1998 (the “TUF”).

The name “MaxIn Wealth Advisory” and the related logo are used by the Data Controller during his professional practice and do not constitute a separate legal entity.

The Data Controller has not appointed a Data Protection Officer (“DPO”). Any enquiries concerning the processing of personal data may be sent using the contact details set out above.

3. Scope of this Privacy Policy

The website www.maxinadvisory.com is an institutional and informational website.

The website does not currently provide:

·       a restricted client area;

·       user account registration;

·       public comments;

·    e-commerce facilities;

·       online payments;

·       the purchase or subscription of products or services through the website;

·       the independent uploading of content by users.

The website allows users to contact the Data Controller through the contact form, by email, by telephone or through other published contact details.

Submitting an enquiry through the website does not automatically establish a contractual advisory relationship and does not constitute the provision of investment advisory services.

4. Categories of Personal Data Processed

4.1 Browsing data

The IT systems and software procedures used to operate the website may, during their normal operation, acquire certain personal data whose transmission is inherent in the use of Internet communication protocols.

Such data may include, by way of example:

· IP address;

· domain name of the device used;

· URI/URL addresses of the requested resources;

· date and time of the request;

· method used to submit the request to the server;

· numeric code indicating the status of the server response;

· size of the file returned in response;

· browser used;

· operating system;

· device type;

· other parameters relating to the user's IT environment.

These data are used to enable browsing, ensure the proper technical operation of the website, obtain statistical information on its use and establish liability in the event of possible misuse, fraud or cybercrime affecting the website.

4.2 Data provided through the contact form

The website provides a contact form through which users may submit a preliminary enquiry.

The data collected through the contact form may include:

· first name;

· last name;

· company or organization represented, if provided;

· email address;

· telephone number, if provided;

· the content of the enquiry or message submitted.

Under the form currently in use, first name, last name, email address and a description of the enquiry are required to submit a request. Company and telephone number are optional.

Users are asked not to include unnecessary personal data, third-party data or particularly confidential information that is not relevant to the enquiry in the contact form.

4.3 Data sent by email, telephone or other contact channels

The voluntary sending of communications to the addresses and contact details published on the website entails the acquisition of the personal data contained in the communication, together with the contact details required to respond.

Such data may include, by way of example, first and last name, email address, telephone number, message content and any professional, asset-related or financial information voluntarily provided by the user.

Users are asked to provide only information that is relevant and necessary to the enquiry submitted.

4.4 Data processed for any future newsletter

The website may, including in the future, offer users the option of receiving informational communications or newsletters.

Any newsletter, if introduced, will be informational in nature and will not constitute investment advice, a personalized recommendation, an offer or a solicitation to invest.

Where a user subscribes to the newsletter, the user's email address and any further data strictly necessary to manage its delivery may be processed.

Any newsletter will be sent only with the data subject's prior consent, which may be withdrawn at any time.

4.5 Cookies and tracking technologies

The website uses strictly necessary cookies and may use analytics cookies or other tracking technologies, including Google Analytics.

Further information on the types of cookies used, their purposes, retention periods and the management of preferences is provided in the Cookie Policy available in the relevant section of the website.

The use of non-essential cookies or tracking technologies will be subject to the user's consent where required by applicable law.

4.6 Data processed through Google Analytics

The website uses Google Analytics to collect statistical information on website use, pages visited, browsing duration, the device used and how users interact with the pages.

This information is used to understand how the website is used, improve its content, verify its operation and optimize the browsing experience.

Google Analytics is used in accordance with applicable data protection and cookie legislation. Where the service involves cookies or tracking technologies that are not strictly necessary, the related processing will be subject to the user's consent through the cookie banner.

4.7 Data processed through Google Fonts

The website uses Google Fonts to ensure the correct display of its typefaces.

Where fonts are loaded from Google servers, the user's browser may transmit certain technical information to Google, including the IP address, browser data, device data and information relating to the page visited.

These data are processed to ensure that the website's content is displayed correctly and consistently.

4.8 Special categories of personal data

The website and contact form do not require users to provide special categories of personal data within the meaning of Article 9 GDPR, such as data concerning health, political opinions, religious or philosophical beliefs, trade union membership, biometric data, or data concerning a person's sex life or sexual orientation.

Users are asked not to include such data in communications submitted through the website.

If a user voluntarily provides special-category data that were not requested, the Data Controller will process them only to the extent strictly necessary to handle the enquiry or, if they are not relevant, may delete them.

5. Purposes and Legal Bases of Processing

5.1 Website access and technical operation

Browsing data are processed to provide access to the website and ensure its technical operation, security, maintenance and correct display.

Legal basis: the Data Controller's legitimate interest in the proper operation, security and protection of the website.

5.2 Statistical analysis of website use

Data collected through Google Analytics are processed to analyze website use statistically, improve content and functionality, verify the proper operation of the pages and understand how users interact with the website.

Legal basis: the user's consent, where required by applicable law; or the Data Controller's legitimate interest in analyzing website use in aggregate form, where the processing is carried out by technical means that comply with applicable law.

5.3 Display of fonts and graphic content

Technical data associated with the use of Google Fonts are processed to ensure the correct display of typefaces and visual consistency across the website.

Legal basis: the Data Controller's legitimate interest in the proper presentation, functionality and usability of the website, except where applicable law requires the user's consent.

5.4 Responding to user enquiries

Data provided through the contact form, by email, by telephone or through other channels are processed to respond to user enquiries, provide preliminary information, assess the nature of the request and manage any subsequent communications.

Legal basis: taking steps at the data subject's request prior to entering into a contract and, where applicable, the Data Controller's legitimate interest in managing communications received.

5.5 Possible commencement of a professional relationship

Where, following preliminary contact, a user wishes to consider entering into a professional relationship, the data may be processed for the preliminary activities required to assess the engagement and prepare the pre-contractual documentation.

Legal basis: taking steps at the data subject's request prior to entering into a contract.

Any subsequent contractual relationship, if established, will be governed by a separate privacy notice provided to the Client as part of the contractual documentation.

5.6 Any future newsletter or informational communications

The user's data may be processed for the purpose of sending newsletters or informational communications only if this feature is introduced and the user has given the relevant consent.

Legal basis: the data subject's consent. The data subject may withdraw consent at any time by using the contact details provided in Section 2.

5.7 Compliance with legal obligations

Personal data may be processed to comply with obligations imposed by laws, regulations or measures issued by competent authorities.

Legal basis: compliance with a legal obligation to which the Data Controller is subject.

5.8 Security, prevention of misuse and protection of rights

Data may be processed to prevent, identify or address misuse, unlawful use of the website, attempted fraud, cyberattacks or other harmful events, and to establish, exercise or defend the Data Controller's rights in judicial or out-of-court proceedings.

Legal basis: the Data Controller's legitimate interest in the security of the website and the protection of his rights.

6. Nature of the Provision of Data

The provision of browsing data is necessary to enable technical access to the website.

The provision of the data required in the contact form is necessary to allow the Data Controller to receive and handle the user's enquiry. Failure to provide the required data may prevent the enquiry from being submitted or answered.

The provision of optional data is voluntary. Failure to provide such data does not prevent an enquiry from being submitted, but may limit the completeness of the response.

The provision of data for newsletter purposes is optional. Withholding consent does not prevent the user from browsing the website or submitting a contact request.

7. Methods of Processing

Personal data are processed using IT, electronic and, where necessary, paper-based tools, in accordance with the principles of lawfulness, fairness, transparency, data minimization, accuracy, integrity and confidentiality.

The Data Controller implements reasonable technical and organizational measures appropriate to the level of risk to prevent data loss, unlawful or improper use, unauthorized access, improper disclosure or alteration of personal data.

Data are processed directly by the Data Controller and, where necessary, by third parties providing technical, IT, professional or organizational services, within the limits of the purposes set out in this Privacy Policy.

8. Recipients of Personal Data

Personal data may be disclosed, to the extent strictly necessary to the following categories of recipients:

· providers of technical services relating to the website, domain registration, DNS management, hosting, maintenance, cybersecurity and systems management;

· providers of email, calendar, storage and electronic communications services;

· providers of analytics, cookie-management and contact-form services, or other tools embedded on the website;

· the Data Controller's professional advisers, including legal, tax, administrative and IT advisers;

· public authorities, supervisory authorities, judicial authorities or other parties to whom disclosure is required by law;

· parties responsible for the technical or organizational management of the website, where applicable.

At present, the following providers are particularly relevant:

· Aruba S.p.A., for domain registration and management, DNS, website hosting, related technical services and, where applicable, services associated with the domain's email system;

· Microsoft 365 / Outlook, for email management, electronic communications, message storage and the possible manual sending of newsletters or informational communications;

· Google Ireland Limited / Google LLC, for Google Analytics, Google Fonts and, where enabled, other technical tools used to measure traffic, analyze website use or display website content.

Personal data are not disseminated and are not sold to third parties.

9. Transfers of Data Outside the European Economic Area

Where possible, the Data Controller gives preference to providers and services that process data within the European Economic Area.

As a result of the use of technology providers or digital services, such as Microsoft 365 / Outlook, Google Analytics or Google Fonts, certain personal or technical data may be transferred to countries outside the European Economic Area.

Any such transfer will be made in accordance with Articles 44 et seq. GDPR, on the basis of European Commission adequacy decisions, standard contractual clauses or other safeguards provided for by applicable law.

Further details may be requested by writing to contact details provided in Section 2.

10. Retention Periods

Personal data are retained only for as long as is strictly necessary for the purposes for which they were collected, subject to legal obligations or the need to protect the Data Controller's rights.

In particular:

· browsing data and technical logs are retained for the period required for the technical operation, security and maintenance of the website, in accordance with the providers' technical retention periods and in any event only for as long as necessary for the purposes pursued, except where they are required to establish liability in the event of misuse or cybercrime;

· data submitted through the contact form or by email are retained for the period required to handle the enquiry and any subsequent communications, normally for no longer than 24 months after the last contact, unless a professional relationship is established or retention is required by law or to protect legal rights;

· data processed through Google Analytics are retained for the periods specified in the Cookie Policy and in the settings of the relevant service;

· data processed for any newsletter are retained until consent is withdrawn or deletion is requested, except for information strictly necessary to demonstrate the lawfulness of the processing carried out;

· where a professional relationship is subsequently established, data processed for pre-contractual or contractual purposes will be retained as provided in the separate privacy notice supplied to the Client;

· data required to comply with legal obligations or protect the Data Controller's rights may be retained for the periods prescribed by applicable law or for the relevant limitation periods.

At the end of the applicable retention period, the data will be deleted, anonymized or otherwise rendered non-identifiable, unless further retention is required by law.

11. Newsletter and Informational Communications

Any MaxIn Wealth Advisory newsletter, if introduced, will be sent exclusively to persons who have given their consent or requested to receive informational communications.

The newsletter may be managed using ordinary email tools, including Microsoft 365 / Outlook, without the use of marketing automation platforms, unless this Privacy Policy is updated to state otherwise.

Users may withdraw their consent or ask not to receive further communications at any time by writing to the contact details provided in Section 2.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

12. Cookies

The website may use strictly necessary cookies required for its operation and analytics cookies associated with traffic-measurement services, including Google Analytics.

Strictly necessary cookies are used to enable browsing and ensure the proper operation of the website.

Analytics cookies are used to collect statistical information on website use and improve its structure, content and functionality.

The use of non-anonymized analytics cookies, profiling cookies or other tracking technologies that are not strictly necessary will be subject to the user’s consent where required by applicable law.

Certain external services, such as Google Fonts, may involve the processing of the user’s technical data even where no advertising-profiling purpose is pursued.

Detailed information on the cookies actually used, their purposes, retention periods and the management of preferences is provided in the Cookie Policy available on the website.

13. Links to Third-Party Websites and Services

The website may contain links to third-party websites, pages or services, including institutional websites, supervisory authorities, dispute-resolution bodies, professional profiles or external platforms.

The website may contain a link to the Data Controller’s LinkedIn profile, allowing users to view professional information, his curriculum vitae and other publicly available content. Merely accessing this website does not cause the Data Controller to transfer personal data to LinkedIn. If the user selects the link and accesses the LinkedIn platform, the related processing of personal data will be governed by LinkedIn’s privacy policy, with LinkedIn acting as an independent data controller.

The Data Controller does not control those websites and is not responsible for personal data processing carried out by independent third-party controllers. Users are encouraged to review the privacy and cookie policies of any third-party websites they visit.

14. No Automated Decision-Making

In connection with ordinary browsing of the website and use of the contact form, the Data Controller does not carry out automated decision-making that produces legal effects concerning the data subject or similarly significantly affects the data subject.

The website does not perform financial profiling of users through browsing activity or the contact form.

Any MiFID suitability assessment, if the user becomes a Client, is carried out within the professional advisory relationship and in accordance with the applicable pre-contractual and contractual documentation.

15. Data Subject Rights

Subject to the conditions and limitations laid down by applicable law, the data subject may exercise the rights granted under Articles 15–22 GDPR.

In particular, the data subject has the right to:

• obtain confirmation as to whether personal data concerning him or her are being processed;

• obtain access to his or her personal data;

• obtain the rectification of inaccurate data or completion of incomplete data;

• obtain erasure of the data, where provided by law;

• obtain restriction of processing;

• receive the data in a structured, commonly used and machine-readable format, where applicable;

• object to processing, where applicable;

• withdraw consent without affecting the lawfulness of processing carried out before its withdrawal;

• not be subject to a decision based solely on automated processing, including profiling, where provided by law. 

To exercise these rights, the data subject may write to the contact details provided in Section 2.

The Data Controller will respond within the time limits prescribed by applicable law.

16. Complaint to the Supervisory Authority

A data subject who considers that personal data processed through the website are being handled in breach of applicable law has the right to lodge a complaint with the Italian Data Protection Authority.

Further information is available on the Authority’s official website: www.garanteprivacy.it

The right to seek a judicial remedy before the competent courts remains unaffected.

17. Security of Electronic Communications

Electronic communications, including emails and messages sent through the website, may involve risks relating to the security, integrity and confidentiality of the information transmitted.

The Data Controller adopts reasonable measures to protect communications and processed data, within the limits of the available technologies and services used.

Users are advised to exercise caution when sending confidential information through electronic channels and to verify that the contact details used are correct.

18. Change to this Privacy Policy

This Privacy Policy may be updated or amended from time to time to reflect changes in law, technology, organization or the services used by the website.

Any changes will be published on this page together with the date of the latest update.

Users are encouraged to review this Privacy Policy periodically.

19. Related Documents

For a fuller understanding of the informational and legal framework applicable to the website, users are also encouraged to review:

·       Terms And Conditions;

·       Cookie Policy;

·       Disclaimer;

·       Pre-Contractual Disclosure;

·       Information on the Financial Disputes Arbitrator;

·       Sustainability Factors Integration Disclosure.

20. Privacy contact details

For any enquiry concerning this Privacy Policy or the processing of personal data, please contact:

Massimiliano Iannozzi - Consulente Finanziario Autonomo, registered with the Single Register of Financial Advisers, CFA section, under OCF Resolution no. 2976 of 26 May 2026, registration no. 641736, pursuant to Legislative Decree no. 58/1998 — the Italian Consolidated Law on Finance (TUF). Advisory services are provided independently. VAT no. 18347001002.

The content presented on this page is provided for informational purposes only and does not constitute pre-contractual information under applicable regulations, nor a solicitation to the public to invest or an offer of financial instruments. Any investment recommendations regarding financial instruments are provided exclusively following an individualized suitability assessment, in accordance with the client’s MiFID profile and expressed preferences. The advisory service is provided on a non-discretionary basis, in compliance with the transparency, fairness, and suitability requirements set forth under the Italian Consolidated Financial Act (TUF) and the MiFID II Directive; it does not include portfolio management services or any delegation of trading authority. All investment decisions and their execution remain under the full and exclusive responsibility of the client. No guarantee is provided regarding results or future performance.