Skip to content

Privacy Notice

Last updated: 11 August 2026

This notice explains how Studio Legale Lione processes personal data collected through this website, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”). It covers only the processing activities actually carried out through the website and not the professional relationship with clients, for which a dedicated notice is provided when the engagement is accepted.

1. Data controller

Studio Legale LioneViale Giustiniano 10, 20129 Milano MI, ItalyP.IVA 03571210834segreteria@studiolione.com+39 02 3061 8115

For any request concerning personal data, or to exercise your rights, please write to segreteria@studiolione.com.

2. Data processed, purposes and legal bases

We process only the data you voluntarily provide or that is technically necessary to operate the website.

a) Contact and consultation request forms

We collect your name and, where applicable, surname, email address, telephone number, company name, area of interest, preferred contact method and the text of your request. This data is stored in the website database (Supabase) and may be forwarded by email to the firm's secretariat to handle the request. Legal basis: steps taken at your request prior to entering into a contract and, where relevant, performance of the contract (Art. 6(1)(b) GDPR).

b) Appointment booking

If you use the booking feature, we process your name, surname, email, telephone, area of interest, description of the request and the chosen date and time. Availability and the calendar entry are managed through Google Calendar. Legal basis: pre-contractual measures and performance of the contract (Art. 6(1)(b) GDPR).

c) Newsletter

Upon voluntary subscription we process your name, surname, email address and any area of interest in order to send the firm's newsletter. Distribution is handled through Brevo. Legal basis: specific and optional consent (Art. 6(1)(a) GDPR), which may be withdrawn at any time through the unsubscribe link in every message or by writing to the controller.

d) Digital legal assistant

The assistant available on the website records the messages exchanged, a technical session identifier and certain technical metadata collected for security and abuse-prevention purposes (for example the browser user agent). Questions are processed through the Lovable AI gateway and the models of the relevant providers. The assistant provides general information only and does not constitute legal advice: please do not enter confidential information, third-party data or special categories of data (such as health or criminal data). Legal basis: the controller's legitimate interest in providing the informational service, ensuring its security and preventing abuse (Art. 6(1)(f) GDPR); for any data you enter voluntarily, responding to your request (Art. 6(1)(b) GDPR).

e) Administrative area

Access to the restricted area of the website is limited to authorised personnel through the Supabase authentication system, which processes credentials and technical session data. Legal basis: legitimate interest in system security (Art. 6(1)(f) GDPR) and compliance with legal obligations (Art. 6(1)(c) GDPR).

We also process data as necessary to comply with legal obligations and, where required, to establish, exercise or defend legal claims (Art. 6(1)(c) and 6(1)(f) GDPR).

3. Provision of data

Providing the data marked as mandatory in the forms is necessary in order to handle your request: without it we cannot reply or arrange an appointment. Subscribing to the newsletter is entirely optional and does not affect your ability to contact the firm.

4. Recipients and processors

Data is processed by the firm's professionals and authorised staff. It may also be processed on our behalf and on our instructions by the technical providers that operate the website:

  • Lovable, for application hosting and for the AI gateway through which requests to the digital assistant are routed;
  • Supabase, for the database, file storage and authentication of the administrative area;
  • Brevo, for newsletter subscriber management, message delivery and email notifications to the secretariat;
  • Google, for calendar and appointment management through Google Calendar;
  • the artificial intelligence model providers reached through the AI gateway, solely to process the requests sent to the assistant.

Data is not sold or transferred to third parties for commercial purposes. It may be disclosed to public authorities where required by law or necessary to protect a legal right.

5. Transfers outside the EEA

Some providers may process data outside the European Economic Area. In that case the transfer takes place on the basis of an adequacy decision of the European Commission or of appropriate safeguards under Art. 46 GDPR, such as standard contractual clauses, together with any supplementary measures required. Information on the safeguards adopted is available on request from the controller.

6. Retention

Data is retained for as long as necessary for the purposes for which it was collected and thereafter for the period required by legal obligations or by the need to establish, exercise or defend a legal claim. Newsletter subscriber data is retained until consent is withdrawn or the subscription is cancelled, without prejudice to retention of the record of consent and withdrawal. Once no longer necessary, data is deleted or rendered no longer attributable to the data subject using the technical means available.

7. Your rights

Within the limits set by the applicable law you may exercise the rights of access, rectification, erasure, restriction, portability and objection, and you may withdraw your consent at any time without affecting the lawfulness of processing carried out before the withdrawal. Requests can be sent to segreteria@studiolione.com.

You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — garanteprivacy.it) or with the supervisory authority of your country of residence.

8. Security, cookies and updates

We adopt appropriate technical and organisational measures to protect data against unauthorised access, loss or disclosure. For cookies and local storage, please see the cookie policy. This notice may be updated: the version published on this page is the one in force and always shows the date of the latest update.