Privacy
Privacy policy
What DaVinci Capitals S.r.l. does with personal data in connection with this website and with messages sent to the address published on it. This is not a template. It describes a site with no forms, no accounts, no analytics and no cookies, and it says what the server actually records, which is close to nothing.
1. Who is responsible
DaVinci Capitals S.r.l., a company incorporated under Italian law with registered office in Via Giuseppe Lagrange 6, 20136 Milan, Italy, tax code and VAT number 13622850967, registered with the Milan Chamber of Commerce under REA MI-2734222, is the controller of the personal data described below, within the meaning of Article 4(7) of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR").
The company is wholly owned by a single shareholder, WPI LTD, a company registered in Malta, and its sole director is Paolo Pettinato.
No Data Protection Officer has been appointed, and none is required. The company is not a public authority, its core activities do not consist of large scale regular and systematic monitoring of individuals, and it does not process special categories of data on a large scale, so none of the cases in Article 37(1) GDPR applies.
Contact for anything in this policy
Or by post to the registered office above, marked for the attention of the sole director.
2. What this website is, and what it is not
This website is a set of static pages. There is no contact form, no login, no newsletter sign-up, no comment section, no chat widget, no analytics package, no advertising or conversion tag and no social plugin. Nothing here asks you for data, and no third party is told that you visited.
Everything the pages load, the stylesheets, the scripts, the images and the typefaces, is served from davincicapitals.com. Your browser makes requests to this domain and to no other. The email address is published as an image rather than as text, so that it is not harvested automatically.
One change worth declaring. Until 1 September 2026 these pages loaded their typefaces from Google's servers (fonts.googleapis.com and fonts.gstatic.com), which is how the site had been built. That sent the IP address of every visitor to Google, for no purpose of ours. Since that date the typefaces are stored on our own server and are served from this domain, and those requests no longer happen.
The pages contain a few ordinary links out to other websites. A link loads nothing until you click it. Once you do, you are on someone else's site, under their rules and their privacy policy, not ours.
The only way you can give DaVinci Capitals your data through this site is by deciding, yourself, to write to the address published on it.
3. What is actually processed
a. Technical connection data
To send you a page, the web server necessarily receives your IP address, the address you asked for and the technical details your browser announces (browser and operating system string, accepted languages, protocol version). That is true of every website in existence: it is how a page finds its way back to you. The question that matters is what is kept.
We checked before writing this. The web server is Caddy 2.6.2 and the configuration block that serves davincicapitals.com contains no logging directive, which in Caddy 2 means that no access log is produced at all. On 1 September 2026 we issued requests to the site, successful ones and a deliberately failing one carrying a recognisable marker, and then searched the whole machine for that marker and for the calling IP address. Neither appeared anywhere.
So: individual page requests to this website are not recorded. There is no visitor log, no IP address list, no statistics file, nothing to hand over and nothing to lose in a breach.
The machine's system journal holds only operational messages, such as service start-ups, configuration reloads and TLS certificate renewals, plus the administrative connections made by the people who maintain the server. It contains no record of visits to this website. The journal is capped by size and rotates automatically: when we looked, on 1 September 2026, it held about 189 MB covering the previous nine days.
If an access log ever has to be switched on, for instance while dealing with an attack on the server, it will be limited to what that purpose requires, kept for no longer than 30 days, and this page will be updated to say so.
b. What you send by email
If you write to the address published above, DaVinci Capitals receives your email address, your name if you give it, and whatever you choose to put in the message and its attachments.
We checked the DNS records of this domain on 1 September 2026: mail for davincicapitals.com is delivered to Google's mail servers, so the mailbox behind the published address is a Google Workspace mailbox. What you write to us is therefore stored on Google's infrastructure, under the terms described in section 6 and section 7 below.
Please do not send sensitive personal data (health, political or religious views, and the rest of Article 9 GDPR) by email. It is not needed for any purpose here, and ordinary email is not the right channel for it.
4. Purposes and legal bases
| Data | Purpose | Legal basis |
|---|---|---|
| Technical connection data, for the moment a request is being served, and any access log switched on temporarily | Delivering the page, keeping the server up and defending it from abuse | Legitimate interest, Article 6(1)(f) GDPR: running and protecting one's own website |
| Content of messages sent to the published address | Reading, replying, and keeping a record of the exchange | Article 6(1)(b) GDPR where the exchange concerns steps taken at your request before a possible contract, otherwise legitimate interest, Article 6(1)(f), in handling correspondence addressed to the company |
| Correspondence relevant to a transaction or a dispute | Establishing, exercising or defending legal claims, and meeting company record keeping duties | Article 6(1)(f) GDPR and, where a statutory retention duty applies, Article 6(1)(c) |
Nothing here relies on consent, because nothing on this site does anything that would require it.
5. How long data is kept
- Page requests: not recorded at all, so there is nothing to keep and nothing to erase.
- Server operational messages: overwritten automatically as the size capped system journal rolls over.
- Correspondence: kept while the matter it concerns is open and, afterwards, for as long as it may be needed to establish, exercise or defend a legal claim, and in any case no longer than ten years from the last message, which is also the period Italian law requires for company accounting records. Unsolicited messages of no interest to the company are deleted, normally within twelve months.
6. Who else may see the data
- The hosting provider. The site runs on a virtual server rented from netcup GmbH (Daimlerstrasse 25, 76185 Karlsruhe, Germany) and physically located in its Austrian data centre. netcup acts as a processor under Article 28 GDPR for whatever passes through or sits on that server.
- The email provider. Mail for this domain is handled by Google Workspace, provided to the company by Google Ireland Limited, acting as a processor.
- Professional advisers (lawyers, accountants, auditors) and public authorities, where the company is legally required to involve them or legitimately needs to.
Personal data is never sold, rented or passed to advertisers or data brokers. There are no advertising or analytics recipients, because there is no advertising and no analytics.
7. Transfers outside the EEA
Serving this website involves no transfer outside the European Economic Area. The server sits in Austria, its provider is established in Germany, and the pages load nothing from anywhere else.
Email deserves a straight answer rather than a comfortable one. Google Workspace is supplied by an EU established company, Google Ireland Limited, but Google's infrastructure can involve access from outside the EEA. Where that happens the transfer relies on the European Commission's standard contractual clauses and, for the United States, on Google's certification under the EU-US Data Privacy Framework. If you would rather avoid that, write to the registered office by post instead.
8. Your rights
Under Articles 15 to 22 GDPR you can ask DaVinci Capitals for:
- access to the personal data it holds about you, and a copy of it;
- rectification of anything inaccurate or incomplete;
- erasure, where one of the grounds in Article 17 applies;
- restriction of processing, where Article 18 applies;
- portability of data you provided, in a machine readable format, where the processing is based on a contract and carried out by automated means;
- objection, at any time and on grounds relating to your situation, to processing based on legitimate interest.
Since no processing here is based on consent, there is no consent to withdraw. Since page requests are not recorded, an access request can only concern correspondence: on the browsing side there is genuinely nothing to produce.
Write to the address above to exercise any of these. You will get an answer within one month, as Article 12(3) GDPR requires. If it is not obvious who you are, the company may ask for the information needed to be reasonably sure, and will use it for that check only. Exercising these rights costs nothing.
9. Complaints
If you think your data has been mishandled, you can lodge a complaint with the Italian supervisory authority:
Garante per la protezione dei dati personali
Piazza Venezia 11, 00187 Rome, Italy
garanteprivacy.it
Under Article 77 GDPR you may instead complain to the supervisory authority of the EU or EEA country where you live, where you work, or where you believe the infringement took place. You can also go to court. Telling DaVinci Capitals first is welcome but is not a condition of any of this.
10. No profiling, no marketing, no automated decisions
DaVinci Capitals builds no profiles from this website, tracks nobody across sites, and sends no marketing from it. No decision about anyone is taken by automated means, including profiling, within the meaning of Article 22 GDPR. There is no mailing list to be added to, because there is nothing here that could add you to one.
11. Applicable law, and changes to this page
This policy is governed by the GDPR and, in Italy, by legislative decree 196 of 30 June 2003 (the Italian data protection code) as amended by legislative decree 101 of 10 August 2018. The cookie side is covered separately in the cookie policy, which follows the guidelines on cookies and other tracking tools adopted by the Garante on 10 June 2021.
If what the site does changes, this page changes with it, and the date below moves. Since the site keeps no record of who visits, nobody can be notified individually: that date is the only signal, so check it if it matters to you.
Last updated: 1 September 2026. Previous versions are not published; this page replaces anything said before it. See also the cookie policy.