Privacy Policy
Last updated: 1 September 2026
1. Introduction
This Privacy Policy explains how the personal data of users who visit and use www.maxinadvisory.com are processed.
This notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”) and Italian Legislative Decree No. 196/2003, as amended by Legislative Decree No. 101/2018 (the “Italian Data Protection Code”).
This Privacy Policy applies exclusively to processing carried out through the website and its related contact channels.
Where personal data are processed in connection with any contractual investment advisory relationship, the Client will receive a separate privacy notice together with the pre-contractual and contractual documentation.
This Privacy Policy does not apply to third-party websites, platforms or services that may be accessed through links on this website. Users are encouraged to review the relevant privacy notices issued by those third-party controllers.
2. Data Controller
The data controller is:

Massimiliano Iannozzi is registered with the Italian Single Register of Financial Advisers, in the Independent Financial Advisers Section, pursuant to OCF Resolution No. 2976 of 26 May 2026, registration No. 641736, under Italian Legislative Decree No. 58/1998 (the “TUF”).
The name “MaxIn Wealth Advisory” and the related logo are used by the Data Controller during his professional practice and do not constitute a separate legal entity.
The Data Controller has not appointed a Data Protection Officer (“DPO”). Any enquiries concerning the processing of personal data may be sent using the contact details set out above.
3. Scope of this Privacy Policy
The website www.maxinadvisory.com is an institutional and informational website.
The website does not currently provide:
· a restricted client area;
· user account registration;
· public comments;
· e-commerce facilities;
· online payments;
· the purchase or subscription of products or services through the website;
· the independent uploading of content by users.
The website allows users to contact the Data Controller through the contact form, by email, by telephone or through other published contact details.
Submitting an enquiry through the website does not automatically establish a contractual advisory relationship and does not constitute the provision of investment advisory services.
4. Categories of Personal Data Processed
4.1 Browsing data
The IT systems and software procedures used to operate the website may, during their normal operation, acquire certain personal data whose transmission is inherent in the use of Internet communication protocols.
Such data may include, by way of example:
· IP address;
· domain name of the device used;
· URI/URL addresses of the requested resources;
· date and time of the request;
· method used to submit the request to the server;
· numeric code indicating the status of the server response;
· size of the file returned in response;
· browser used;
· operating system;
· device type;
· other parameters relating to the user's IT environment.
These data are used to enable browsing, ensure the proper technical operation of the website, obtain statistical information on its use and establish liability in the event of possible misuse, fraud or cybercrime affecting the website.
4.2 Data provided through the contact form
The website provides a contact form through which users may submit a preliminary enquiry.
The data collected through the contact form may include:
· first name;
· last name;
· company or organization represented, if provided;
· email address;
· telephone number, if provided;
· the content of the enquiry or message submitted.
Under the form currently in use, first name, last name, email address and a description of the enquiry are required to submit a request. Company and telephone number are optional.
Users are asked not to include unnecessary personal data, third-party data or particularly confidential information that is not relevant to the enquiry in the contact form.
4.3 Data sent by email, telephone or other contact channels
The voluntary sending of communications to the addresses and contact details published on the website entails the acquisition of the personal data contained in the communication, together with the contact details required to respond.
Such data may include, by way of example, first and last name, email address, telephone number, message content and any professional, asset-related or financial information voluntarily provided by the user.
Users are asked to provide only information that is relevant and necessary to the enquiry submitted.
4.4 Data processed for any future newsletter
The website may, including in the future, offer users the option of receiving informational communications or newsletters.
Any newsletter, if introduced, will be informational in nature and will not constitute investment advice, a personalized recommendation, an offer or a solicitation to invest.
Where a user subscribes to the newsletter, the user's email address and any further data strictly necessary to manage its delivery may be processed.
Any newsletter will be sent only with the data subject's prior consent, which may be withdrawn at any time.
4.5 Cookies and tracking technologies
The website uses strictly necessary cookies and may use analytics cookies or other tracking technologies, including Google Analytics.
Further information on the types of cookies used, their purposes, retention periods and the management of preferences is provided in the Cookie Policy available in the relevant section of the website.
The use of non-essential cookies or tracking technologies will be subject to the user's consent where required by applicable law.
4.6 Data processed through Google Analytics
The website uses Google Analytics to collect statistical information on website use, pages visited, browsing duration, the device used and how users interact with the pages.
This information is used to understand how the website is used, improve its content, verify its operation and optimize the browsing experience.
Google Analytics is used in accordance with applicable data protection and cookie legislation. Where the service involves cookies or tracking technologies that are not strictly necessary, the related processing will be subject to the user's consent through the cookie banner.
4.7 Data processed through Google Fonts
The website uses Google Fonts to ensure the correct display of its typefaces.
Where fonts are loaded from Google servers, the user's browser may transmit certain technical information to Google, including the IP address, browser data, device data and information relating to the page visited.
These data are processed to ensure that the website's content is displayed correctly and consistently.
4.8 Special categories of personal data
The website and contact form do not require users to provide special categories of personal data within the meaning of Article 9 GDPR, such as data concerning health, political opinions, religious or philosophical beliefs, trade union membership, biometric data, or data concerning a person's sex life or sexual orientation.
Users are asked not to include such data in communications submitted through the website.
If a user voluntarily provides special-category data that were not requested, the Data Controller will process them only to the extent strictly necessary to handle the enquiry or, if they are not relevant, may delete them.
5. Purposes and Legal Bases of Processing
5.1 Website access and technical operation
Browsing data are processed to provide access to the website and ensure its technical operation, security, maintenance and correct display.
Legal basis: the Data Controller's legitimate interest in the proper operation, security and protection of the website.
5.2 Statistical analysis of website use
Data collected through Google Analytics are processed to analyze website use statistically, improve content and functionality, verify the proper operation of the pages and understand how users interact with the website.
Legal basis: the user's consent, where required by applicable law; or the Data Controller's legitimate interest in analyzing website use in aggregate form, where the processing is carried out by technical means that comply with applicable law.
5.3 Display of fonts and graphic content
Technical data associated with the use of Google Fonts are processed to ensure the correct display of typefaces and visual consistency across the website.
Legal basis: the Data Controller's legitimate interest in the proper presentation, functionality and usability of the website, except where applicable law requires the user's consent.
5.4 Responding to user enquiries
Data provided through the contact form, by email, by telephone or through other channels are processed to respond to user enquiries, provide preliminary information, assess the nature of the request and manage any subsequent communications.
Legal basis: taking steps at the data subject's request prior to entering into a contract and, where applicable, the Data Controller's legitimate interest in managing communications received.
5.5 Possible commencement of a professional relationship
Where, following preliminary contact, a user wishes to consider entering into a professional relationship, the data may be processed for the preliminary activities required to assess the engagement and prepare the pre-contractual documentation.
Legal basis: taking steps at the data subject's request prior to entering into a contract.
Any subsequent contractual relationship, if established, will be governed by a separate privacy notice provided to the Client as part of the contractual documentation.
5.6 Any future newsletter or informational communications
The user's data may be processed for the purpose of sending newsletters or informational communications only if this feature is introduced and the user has given the relevant consent.
Legal basis: the data subject's consent. The data subject may withdraw consent at any time by using the contact details provided in Section 2.
5.7 Compliance with legal obligations
Personal data may be processed to comply with obligations imposed by laws, regulations or measures issued by competent authorities.
Legal basis: compliance with a legal obligation to which the Data Controller is subject.
5.8 Security, prevention of misuse and protection of rights
Data may be processed to prevent, identify or address misuse, unlawful use of the website, attempted fraud, cyberattacks or other harmful events, and to establish, exercise or defend the Data Controller's rights in judicial or out-of-court proceedings.
Legal basis: the Data Controller's legitimate interest in the security of the website and the protection of his rights.
6. Nature of the Provision of Data
The provision of browsing data is necessary to enable technical access to the website.
The provision of the data required in the contact form is necessary to allow the Data Controller to receive and handle the user's enquiry. Failure to provide the required data may prevent the enquiry from being submitted or answered.
The provision of optional data is voluntary. Failure to provide such data does not prevent an enquiry from being submitted, but may limit the completeness of the response.
The provision of data for newsletter purposes is optional. Withholding consent does not prevent the user from browsing the website or submitting a contact request.
7. Methods of Processing
Personal data are processed using IT, electronic and, where necessary, paper-based tools, in accordance with the principles of lawfulness, fairness, transparency, data minimization, accuracy, integrity and confidentiality.
The Data Controller implements reasonable technical and organizational measures appropriate to the level of risk to prevent data loss, unlawful or improper use, unauthorized access, improper disclosure or alteration of personal data.
Data are processed directly by the Data Controller and, where necessary, by third parties providing technical, IT, professional or organizational services, within the limits of the purposes set out in this Privacy Policy.
8. Recipients of Personal Data
Personal data may be disclosed, to the extent strictly necessary to the following categories of recipients:
· providers of technical services relating to the website, domain registration, DNS management, hosting, maintenance, cybersecurity and systems management;
· providers of email, calendar, storage and electronic communications services;
· providers of analytics, cookie-management and contact-form services, or other tools embedded on the website;
· the Data Controller's professional advisers, including legal, tax, administrative and IT advisers;
· public authorities, supervisory authorities, judicial authorities or other parties to whom disclosure is required by law;
· parties responsible for the technical or organizational management of the website, where applicable.
At present, the following providers are particularly relevant:
· Aruba S.p.A., for domain registration and management, DNS, website hosting, related technical services and, where applicable, services associated with the domain's email system;
· Microsoft 365 / Outlook, for email management, electronic communications, message storage and the possible manual sending of newsletters or informational communications;
· Google Ireland Limited / Google LLC, for Google Analytics, Google Fonts and, where enabled, other technical tools used to measure traffic, analyze website use or display website content.
Personal data are not disseminated and are not sold to third parties.
9. Transfers of Data Outside the European Economic Area
Where possible, the Data Controller gives preference to providers and services that process data within the European Economic Area.
As a result of the use of technology providers or digital services, such as Microsoft 365 / Outlook, Google Analytics or Google Fonts, certain personal or technical data may be transferred to countries outside the European Economic Area.
Any such transfer will be made in accordance with Articles 44 et seq. GDPR, on the basis of European Commission adequacy decisions, standard contractual clauses or other safeguards provided for by applicable law.
Further details may be requested by writing to contact details provided in Section 2.
10. Retention Periods
Personal data are retained only for as long as is strictly necessary for the purposes for which they were collected, subject to legal obligations or the need to protect the Data Controller's rights.
In particular:
· browsing data and technical logs are retained for the period required for the technical operation, security and maintenance of the website, in accordance with the providers' technical retention periods and in any event only for as long as necessary for the purposes pursued, except where they are required to establish liability in the event of misuse or cybercrime;
· data submitted through the contact form or by email are retained for the period required to handle the enquiry and any subsequent communications, normally for no longer than 24 months after the last contact, unless a professional relationship is established or retention is required by law or to protect legal rights;
· data processed through Google Analytics are retained for the periods specified in the Cookie Policy and in the settings of the relevant service;
· data processed for any newsletter are retained until consent is withdrawn or deletion is requested, except for information strictly necessary to demonstrate the lawfulness of the processing carried out;
· where a professional relationship is subsequently established, data processed for pre-contractual or contractual purposes will be retained as provided in the separate privacy notice supplied to the Client;
· data required to comply with legal obligations or protect the Data Controller's rights may be retained for the periods prescribed by applicable law or for the relevant limitation periods.
At the end of the applicable retention period, the data will be deleted, anonymized or otherwise rendered non-identifiable, unless further retention is required by law.
