Privacy policy
Last updated: 27 September 2026
This policy explains what personal data IronSpend collects through ironspend.com and by email, why we collect it, how long we keep it and what rights you have. It is provided under Articles 13 and 14 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Italian Personal Data Protection Code (Legislative Decree 196/2003, as amended).
1. Who is responsible for your data
The data controller is:
Gianpaolo Maggio, trading as IronSpend
Contrada Santa Venera 162, 91025 Marsala, Italy
VAT number IT02951580816
Email: info@ironspend.com
We have not appointed a Data Protection Officer, as this is not required for our activities. For any privacy question or request, write to the email address above.
2. What data we collect
Data you give us
When you use the contact form or write to us, we collect the information you choose to provide: your role (brand, account provider or other), name, work email, company name, website, monthly ad spend range, who referred you and the content of your message. If a business relationship follows, we also process the contact and business details needed to manage it, including company registration and verification documents that you or your organisation provide.
Data collected automatically
When you visit the website, our hosting provider automatically records technical data needed to deliver and secure the site, such as IP address, date and time of the request, pages requested, browser type and referring URL. We do not use this data to identify you.
We do not use analytics tools, advertising pixels or social media plugins on this website.
3. Why we use your data and on what legal basis
| Purpose | Legal basis |
|---|---|
| Replying to your enquiry and evaluating a possible collaboration | Steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR) and our legitimate interest in answering business contacts (Art. 6(1)(f)) |
| Managing an agreed business relationship with clients and partners | Performance of a contract (Art. 6(1)(b)) |
| Business verification (KYC) required by us or by advertising platforms and partners | Legal obligations (Art. 6(1)(c)) and our legitimate interest in preventing fraud and policy violations (Art. 6(1)(f)) |
| Accounting, tax and invoicing | Legal obligations under Italian law (Art. 6(1)(c)) |
| Operating and securing the website | Legitimate interest in a secure, working website (Art. 6(1)(f)) |
| Establishing, exercising or defending legal claims | Legitimate interest (Art. 6(1)(f)) |
Providing your details through the form is voluntary, but without them we cannot reply to your enquiry. We do not use your data for automated decision-making or profiling, and we do not send marketing emails unless you ask us to.
4. How long we keep your data
- Enquiries that do not lead to a collaboration: up to 24 months from our last contact, then deleted.
- Client and partner data: for the duration of the relationship, and afterwards for up to 10 years where required for accounting, tax or legal purposes (Article 2220 of the Italian Civil Code).
- Website server logs: kept by our hosting provider for a short period, as set out in its own policies, and only longer if needed to investigate a security incident.
5. Who we share your data with
We do not sell your data. We share it only where needed, with:
- Service providers acting on our behalf as data processors, such as our website hosting and form provider (Netlify, Inc.), our email provider, and accounting and IT service providers. They may only use the data to provide their services to us.
- Advertising platforms and account partners, such as Meta, TikTok and agency account providers, when business verification data is needed to set up or maintain advertising accounts for you. They act as independent controllers under their own privacy policies.
- Professional advisers and public authorities, such as accountants, lawyers, tax authorities or courts, where required by law or to protect our rights.
6. Transfers outside the European Economic Area
Some of our providers and partners are located outside the EEA, including in the United States and Asia. When we transfer personal data outside the EEA, we do so only to countries covered by an adequacy decision of the European Commission (including, for certified US companies, the EU–US Data Privacy Framework) or on the basis of the Standard Contractual Clauses approved by the European Commission, together with any additional safeguards required. You can ask us for more information about these safeguards.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy of it;
- have inaccurate data corrected and incomplete data completed;
- have your data deleted, where there is no longer a valid reason to keep it;
- restrict how we use your data in certain circumstances;
- receive your data in a structured, machine-readable format and have it transferred to another controller (data portability);
- object at any time to processing based on our legitimate interests, on grounds relating to your particular situation.
To exercise any of these rights, email info@ironspend.com. We will reply within one month. We may ask you to confirm your identity before acting on a request.
You also have the right to lodge a complaint with a supervisory authority. In Italy this is the Garante per la protezione dei dati personali (garanteprivacy.it). You may also contact the authority in the EU country where you live or work.
8. Cookies
This website does not use cookies for analytics, advertising or profiling, and does not load third-party tracking scripts. Fonts and all other assets are served from our own domain.
Our hosting provider may use strictly necessary technical mechanisms to deliver the site securely and to protect the contact form from spam. These do not require your consent under Article 122 of the Italian Personal Data Protection Code and the ePrivacy Directive. If we introduce any non-essential cookies in future, we will ask for your consent first and update this section.
9. Security
The website is served exclusively over encrypted connections (HTTPS). We limit access to personal data to people who need it for the purposes above and use providers that apply appropriate technical and organisational security measures.
10. Changes to this policy
We may update this policy when our services or the law change. The date at the top of the page shows when it was last revised. Significant changes will be highlighted on this page.