MELIOR LAWASSOCIATED LAW FIRM · ROME

1. Data controller

The data controller is MELIOR LAW — Associated Law Firm, based in Rome. Data-protection requests may be sent through the contact details published on the website. The notice will be updated with a dedicated privacy contact once activated.

2. Data processed

The website may process technical browsing and security data, data voluntarily provided through communications or forms, and preferences relating to cookies and tracking tools.

3. Purposes and legal bases

Data may be processed to deliver, secure and maintain the website and prevent abuse; to respond to requests and take pre-contractual steps requested by the data subject; to comply with legal, professional, tax and ethical obligations; and, where applicable, for promotional communications or non-essential tools on an appropriate legal basis, including consent where required.

4. Artificial intelligence, confidentiality and personal data

MELIOR LAW may use AI systems to support research, knowledge organisation, analysis, drafting, review and content processing. Their use is organised so as to respect confidentiality, professional secrecy, data-protection and security obligations. Any use of personal data or client/matter information in AI systems must be assessed in light of necessity, proportionality, minimisation, legal basis, supplier terms, location of processing and security safeguards.

5. Pseudonymisation, images and public identity

For privacy and communication purposes, some public representations of non-professional staff, editorial figures or demonstrative content may use pseudonyms, synthetic images or AI-altered images. These elements concern public presentation and do not alter the personal data actually processed in professional relationships.

6. Recipients and service providers

Data may be processed by technical suppliers supporting hosting, DNS/CDN, email, security, maintenance, productivity, storage and other necessary services, acting as processors where required. Data may also be disclosed to public or private bodies where required by law or necessary to protect rights.

7. Transfers outside the EEA

Where a supplier involves transfers outside the European Economic Area, processing is carried out in accordance with the GDPR through adequacy decisions or other applicable safeguards.

8. Retention

Data are retained for the time necessary for the relevant purposes and thereafter for periods required by law, security needs, the establishment, exercise or defence of legal claims and professional obligations.

9. Data-subject rights

Where applicable under the GDPR, data subjects may exercise rights of access, rectification, erasure, restriction, objection and portability and may withdraw consent without affecting prior lawful processing. Complaints may be lodged with the Italian Data Protection Authority.

10. Security and updates

Technical and organisational measures proportionate to risk are adopted. No Internet-connected system can be regarded as completely immune from incidents. This notice may be updated as services, suppliers and law evolve.

Last updated: 10 September 2026.