PRIVACY POLICY

Version of 28 August 2026

Notice given under arts. 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and art. 122 of Legislative Decree 196/2003 (“Italian Privacy Code”), as amended by Legislative Decree 101/2018.

1. Data controller

Data controller: Avv. Alessio D'AscenzoTax code: DSCLSS94H05A345U
Registered office: Rome (RM), ItalyPEC: legaless@pec.it
Email: a.dascenzo@legaless.it

No Data Protection Officer (DPO) has been appointed, as the conditions of art. 37 GDPR do not apply.

2. Roles and structure of the processing
The Legaless® Platform connects the User with independent lawyers. It's important for the User to understand who processes their data and for what purposes:

PartyRoleScope of processing
Legaless® ControllerIndependent controllerOperation of the Platform, Account management, hosting, security, invoicing, its own legal obligations; receiving, storing and transmitting Case data (requests, documents, chats) to prepare Quotes, assign engagements and enable communication between User and Lawyer
Assigned lawyerIndependent controllerPerformance of the Professional Engagement, drafting of documents, legal defence, ethical and anti-money-laundering (AML) obligations under Legislative Decree 231/2007
Third-party Providers (Stripe, OpenAPI, Hostinger, etc.)Processors or independent controllers (see § 9)Technical operation of the related features

The Controller accesses Case data only to the extent needed to prepare Quotes, assign engagements, provide support and keep the Platform secure, through authorised staff bound by confidentiality. The Lawyer is an independent controller and handles their own privacy notice directly with the User for professional, ethical and anti-money-laundering purposes.
Requests to exercise your rights must be sent to the controller responsible for the relevant purpose of processing (see § 7 and § 10).

3. Categories of data processed
Depending on how the User interacts with the Platform, the Controller processes:
a) Personal and contact details: first name, last name, email, phone, residence, tax code, VAT number;
b) Identification data: a copy of the ID document, where needed to perform the Service or for the Lawyer's anti-money-laundering obligations (in that case the data is passed to the Lawyer, who processes it as an independent controller under Legislative Decree 231/2007);
c) Account data: login credentials (encrypted), settings, preferences;
d) Case data: description of the case, uploaded documents, chat messages, quotes, engagement letters. These may include special categories of data (art. 9 GDPR) – e.g. data about health, sex life, racial or ethnic origin, political opinions or religious beliefs – where relevant to the legal case; and data relating to criminal convictions and offences (art. 10 GDPR);
e) Payment data: handled entirely by Stripe; the Controller receives only transaction data (amount, outcome, identifier);
f) Electronic signature data: handled by OpenAPI (phone number for the OTP, signature logs);
g) Usage data: IP address, access logs, browser type, operating system, pages visited, timestamps;
h) Communication data: messages sent through the internal chat and by email.
The User is responsible for the accuracy, completeness and currency of the data provided, and for the lawfulness of disclosing third-party data.

4. Purposes and legal bases of processing

#PurposeLegal basis (art. 6 GDPR)Legal basis for special categories (art. 9)
4.1Creating and managing the AccountPerformance of the contract (art. 6(1)(b))—
4.2Providing the Platform's features (requests, quotes, chat, signature, payments)Performance of the contract (art. 6(1)(b))Explicit consent where special categories of data are involved (art. 9(2)(a)); or the establishment, exercise or defence of legal claims (art. 9(2)(f))
4.3Compliance with the Controller's legal obligations (tax, accounting, orders from authorities, DSA)Legal obligation (art. 6(1)(c))Art. 9(2)(g) (reasons of substantial public interest) where applicable
4.4Platform security, fraud prevention, access logsLegitimate interest (art. 6(1)(f))—
4.5Customer support and complaint handlingPerformance of the contract / legitimate interest—
4.6Sending service communications (notifications, Case updates)Performance of the contract (art. 6(1)(b))—
4.7Sending the Controller's newsletters / promotional communicationsConsent (art. 6(1)(a)), which can be withdrawn at any time—
4.8Soft spam about similar Services already requested (art. 130(4), Legislative Decree 196/2003)Legitimate interest, with the right to object—
4.9Defence of a right in court or out of courtLegitimate interest (art. 6(1)(f))Art. 9(2)(f)
4.10Aggregate statistics and service improvementLegitimate interest (art. 6(1)(f))—

Mandatory or optional provision. Providing the data under points 4.1–4.6 is necessary to perform the Service: failure to provide it prevents use of the Platform. Providing data for purpose 4.7 is optional and does not affect use of the Platform.

AML processing. Processing related to anti-money-laundering due diligence, record-keeping and reporting obligations is carried out by the Lawyer as the obliged entity and independent controller under Legislative Decree 231/2007 (see § 7). The Controller does not act as an AML obliged entity.

5. Technology tools and artificial intelligence
The Controller may use automation tools and artificial intelligence models solely for internal editorial, organisational and management support (e.g. drafting internal documents, classifying requests, helping write standard quotes). These tools are not fed with Case data, nor used to take automated decisions producing legal effects for the User, nor to profile the User within the meaning of art. 22 GDPR. The Lawyer remains solely responsible for professional assessments and for the content delivered to the User.

6. Processing methods and security
Data is processed using electronic tools and organisational procedures designed to ensure its security, integrity and confidentiality, in accordance with art. 32 GDPR. The measures adopted include, among others:
– encryption of sensitive data in transit (TLS) and at rest;
– two-factor authentication for privileged access;
– segregation of roles and the principle of least privilege;
– web application firewall (WAF), intrusion detection systems, anti-malware;
– regular backups and disaster recovery procedures;
– incident management and data breach notification procedures under arts. 33-34 GDPR;
– regular security audits.
Despite these measures, no IT system is entirely risk-free. The Controller undertakes to notify the Italian Data Protection Authority and — where required — the User of any data breaches in accordance with applicable law.

7. Retention periods
The Controller and the Lawyer are independent controllers with separate retention obligations. This section covers retention by the Controller; for retention by the Lawyer, please refer to the Lawyer's own privacy notice, which the Lawyer provides directly to the User.
7.1 Retention by the Controller

CategoryRetention period
Data of Accounts in useFor the duration of the relationship
Data relating to completed Cases (Platform side)Documents and chats from completed Cases: 24 months from completion.
Quotes, engagement letters and transaction data: 10 years from completion of the Case (in line with the limitation periods under art. 2946 of the Italian Civil Code and the record-keeping obligations under art. 2220 of the Italian Civil Code)
The Controller's tax and accounting records10 years (art. 2220 of the Italian Civil Code and art. 22 of Presidential Decree 600/1973)
Technical and security logsUp to 12 months, unless retention is needed for investigations
Marketing data (consent)Until consent is withdrawn, and in any case no longer than 24 months after the last interaction
Inactive accountAfter 24 months of inactivity, the User is asked to confirm whether they wish to keep the Account; if there is no reply within 30 days of the message, the Account is closed and the data deleted or anonymised (subject to the retention obligations above)

7.2 Retention by the Lawyer. The Lawyer, as an independent controller, retains the User's data for the periods and within the limits required by their legal obligations, in particular:
– professional case file documents: for as long as needed to defend the rights of the client and of the Lawyer, in line with the applicable limitation periods (as a general rule, at least 10 years from the end of the engagement, under art. 2946 of the Italian Civil Code);
– AML documents (due diligence, record-keeping, reports): 10 years from the end of the ongoing relationship or from performance of the occasional service, under art. 31 of Legislative Decree 231/2007;
– tax and accounting documents: 10 years under art. 2220 of the Italian Civil Code and art. 22 of Presidential Decree 600/1973.
7.3 Effect of termination on the separate controllers. Ending the relationship with the Owner, or a deletion request addressed to the Owner, does not automatically affect the retention periods binding on the Lawyer, and vice versa. To obtain full deletion of their data, the User must exercise their rights separately with each controller. In any event, the limits laid down by law for mandatory retention (e.g. AML, tax, defence of a right) continue to apply.

8. Recipients of the data
Data may be disclosed to:
a) Assigned Lawyers, as independent controllers, to perform the Professional Engagement and for their AML, ethical and tax obligations;
b) The Controller's associates and authorised staff, designated as persons authorised to process data and bound by confidentiality;
c) Technical service providers designated as processors under art. 28 GDPR (hosting, maintenance, security, support, automation tools);
d) Third-party Providers for payments (Stripe), electronic signature (OpenAPI) and hosting (Hostinger), as specified in § 9;
e) Advisers (the Controller's accountant and lawyer) for professional compliance and defence;
f) Judicial and administrative authorities in the event of lawful requests (including the Financial Intelligence Unit (UIF) and the Guardia di Finanza for AML purposes, on lawful request). Data is not disseminated and is not transferred to third parties for their direct marketing purposes.

9. Third-party providers and transfers outside the EU

ProviderFunctionLocation and transfers
Stripe Payments Europe Ltd.Online paymentsBased in the EU (Ireland). Any transfers to Stripe Inc. (USA) take place on the basis of the European Commission's Standard Contractual Clauses (Decision 2021/914) and, where applicable, the EU-US Data Privacy Framework.
Openapi S.p.A.eIDAS electronic signatureRegistered office in the EU (Italy).
Hostinger International Ltd.Hosting and infrastructureBased in the EU/EEA (European data centres).

Any other providers can be named on request by writing to supporto@legaless.it. For transfers outside the EU/EEA, where needed, the Controller adopts the safeguards provided for by arts. 44-49 GDPR (adequacy decisions, Standard Contractual Clauses, supplementary measures).

10. User rights
The User may exercise the following rights at any time, within the limits of the law:
– Access (art. 15 GDPR) – find out what data is processed and obtain a copy;
– Rectification (art. 16) – correct inaccurate data or complete it;
– Erasure / right to be forgotten (art. 17) – ask for the data to be removed, within the limits provided;
– Restriction (art. 18) – temporarily restrict processing;
– Portability (art. 20) – receive the data in a structured, commonly used, machine-readable format and transmit it to another controller;
– Objection (art. 21) – object to processing based on legitimate interest or for direct marketing;
– Withdrawal of consent (art. 7(3)) – at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
– Complaint to the supervisory authority – Garante per la protezione dei dati personali (Italian Data Protection Authority), Piazza Venezia 11, 00187 Rome, garante@gpdp.it, www.garanteprivacy.it;
– Not to be subject to automated decisions (art. 22) – the Controller does not take automated decisions producing significant legal effects.
– Exercising rights with independent controllers. For data processed by the Legaless® Controller, requests should be sent to supporto@legaless.it. For data processed by the Lawyer (performance of the Engagement, AML, professional conduct), requests should be sent directly to the Lawyer, who provides their own privacy notice.
Legal limits (e.g. AML, tax and legal-defence retention obligations) may lead to some requests being refused or deferred, with reasons given.
The Controller responds within 30 days of receipt, extendable by a further 60 days in complex cases (art. 12 GDPR).

11. Cookies
The use of cookies and similar technologies is governed by the separate Cookie Policy available on legaless.it, drawn up in accordance with the Italian Data Protection Authority's Decision of 10 June 2021.

12. Legal defence
The User's data may be used by the Controller, even after the relationship has ended, to establish, exercise or defend a legal claim, within the limits of art. 9(2)(f) GDPR and the law.

13. Changes to this notice
The Controller may update this notice. Changes will be communicated to the User through their Account and/or by email. The current version is always available at legaless.it/privacy-policy/.

14. Minors
The Platform is intended only for adults. The Controller does not knowingly collect data from minors. If processing of a minor's data is detected, the Controller will delete it, unless otherwise authorised by the holder of parental responsibility under art. 8 GDPR.