Blockwyse.
Legal

Privacy Policy

How we handle personal data.

PRIVACY POLICY

Last updated: September 18, 2026

This Privacy Policy explains how Blockwyse SRL, Registered office: Piazzale Cadorna 13 20123, Milano, Italy, Company registration no.: REA MI - 2813933 · VAT no.: 14889130960 ("we", "us", "the Company") processes personal data in connection with this website at blockwyse.io (the "Website") and in connection with our business communications with you, in accordance with Regulation (EU) 2016/679 (the "GDPR") and Italian Legislative Decree 196/2003, as amended by Legislative Decree 101/2018 (the "Codice Privacy"). This document must be read with our Terms of Service and Cookie Policy.

This policy does not cover personal data we process on behalf of our clients when delivering Services under a signed engagement (statement of work, master services agreement, etc.). That processing is governed by the data processing terms agreed with the relevant client, under which we typically act as a processor, not a controller.

WHO IS RESPONSIBLE FOR YOUR DATA

Data Controller: Blockwyse SRL, Registered office: Piazzale Cadorna 13 20123, Milano, Italy, Company registration no.: [Registration No.] · VAT no.: [VAT No.] Contact for privacy matters: through the provided contact form.

WHAT PERSONAL DATA WE PROCESS, AND WHY

We only process personal data in connection with specific, limited purposes. We do not sell personal data, and we do not use it for advertising or profiling.

(a) Enquiries submitted through the contact form

Data processed: name, organisation, role, work email address, and the content of your message.

Purpose: to respond to your enquiry and, where relevant, to take the steps you request before entering into an agreement with your organisation.

Legal basis: Article 6(1)(b) GDPR (steps at your request prior to a contract) where your enquiry concerns a potential engagement, or Article 6(1)(f) GDPR (our legitimate interest in responding to business correspondence addressed to us) for general enquiries.

Retention: enquiries that do not lead to an engagement are retained for [12–24] months from the last contact, then deleted or anonymised. Enquiries that lead to a client relationship are retained in accordance with Section 5 below.

(b) Client and prospect relationship data

Data processed: business contact details, role, correspondence, meeting notes, and records of the engagement, for individuals at organisations we work with or are in discussion with.

Purpose: to manage the business relationship, deliver the Services, and comply with our own legal and contractual obligations.

Legal basis: Article 6(1)(b) GDPR (performance of a contract with your organisation, or steps prior to it) and Article 6(1)(f) GDPR (our legitimate interest in maintaining accurate business records).

Retention: for the duration of the relationship and for [10] years afterwards, in line with Italian civil and tax record-keeping requirements.

(c) Website usage data and cookies

Data processed: depends on the cookie categories you consent to. Details of what is collected, by whom, and for how long are set out in full in our Cookie Policy, which forms part of this Privacy Policy along with Terms of Service by reference.

Purpose: strictly necessary cookies operate the Website; analytics cookies (only set with your consent) help us understand aggregate Website usage.

Legal basis: Article 6(1)(a) GDPR (consent) for any non-essential cookie or tracking tool; our legitimate interest in the technical operation of the Website for strictly necessary cookies, which do not require consent under Article 122 of the Codice Privacy.

(d) Job applications

Data processed: the information you provide in your CV, covering letter, and any subsequent correspondence, including career history, qualifications, and references you choose to supply.

Purpose: to assess your application and, if applicable, to contact you about the role or other opportunities.

Legal basis: Article 6(1)(b) GDPR (steps at your request prior to a contract) and, where you provide references or referee details, Article 6(1)(f) GDPR (our legitimate interest in verifying candidate information).

Retention: unsuccessful applications are retained for [12] months from the closing date of the role, then deleted, unless you ask us to keep your details on file for future opportunities, in which case we retain them for [24] months or until you withdraw consent.

(e) Server and security logs

Data processed: IP address, browser type, pages requested, timestamps, generated automatically by our hosting infrastructure.

Purpose: to operate, secure, and troubleshoot the Website, and to detect and prevent abuse.

Legal basis: Article 6(1)(f) GDPR (our legitimate interest in the security and proper functioning of the Website).

Retention: [6–12] months, unless a longer period is required to investigate a specific security incident.

We do not process any special categories of data (Article 9 GDPR) through the Website, and we do not ask you to submit any. Please do not include special category data (health, political opinions, religious beliefs, trade union membership, sexual orientation, biometric or genetic data) in the contact form or your job application unless specifically requested and relevant to the role.

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects on you.

WHO WE SHARE DATA WITH

We share personal data only with recipients who need it to deliver the purposes above, and only under a data processing agreement where the recipient is a processor. Categories of recipient include:

Hosting and infrastructure providers, to host and operate the Website ([provider name(s)]).

Email and business communication providers, to send and receive correspondence ([provider name(s)]).

Analytics providers, only where you have consented to analytics cookies (see our Cookie Policy for details).

Professional advisers (lawyers, accountants, auditors), where necessary for our own compliance and governance.

Public authorities, where we are required by law to disclose information (e.g. tax, AML, or judicial requests).

We do not sell, rent, or otherwise trade personal data to third parties, and we do not share it for third-party marketing purposes.

INTERNATIONAL DATA TRANSFERS

Some of the service providers listed in Section 3 may process data outside the European Economic Area, in particular in the United States. Where this occurs, we rely on one or more of the following safeguards:

an adequacy decision of the European Commission (for example, the EU–U.S. Data Privacy Framework, where the recipient is a certified participant); or

the European Commission's Standard Contractual Clauses, together with a transfer risk assessment where required.

You can request a copy of the relevant safeguard by writing to us through the contact form.

HOW LONG WE KEEP YOUR DATA

Retention periods are set out activity-by-activity in Section 2. As a general principle, we keep personal data only for as long as necessary for the purpose it was collected for, plus any period required by Italian civil, tax, or corporate law (generally up to 10 years for contractual and accounting records), after which it is deleted or irreversibly anonymised.

YOUR RIGHTS

Under Articles 15–22 GDPR, you have the right to:

Access the personal data we hold about you;

Rectification of inaccurate or incomplete data;

Erasure of your data, where one of the grounds in Article 17 GDPR applies;

Restriction of processing, in the circumstances set out in Article 18 GDPR;

Data portability, for data you provided to us and that we process on the basis of consent or contract, in a structured, commonly used, machine-readable format;

Object to processing based on our legitimate interest, on grounds relating to your particular situation;

Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal, where processing is based on consent (this applies in particular to non-essential cookies — see our Cookie Policy for how to change your preferences);

Lodge a complaint with the Garante per la Protezione dei Dati Personali (www.garanteprivacy.it), or with the supervisory authority of your habitual residence or place of work, if you consider that our processing infringes the GDPR.

To exercise any of these rights, write to us through the provided contact form. We will respond within one month of a verified request, extendable by a further two months for complex requests, as permitted under Article 12(3) GDPR.

Providing the data described in Section 2(a), (b) and (d) is generally necessary for us to respond to you, assess your application, or take steps toward a contract; if you do not provide it, we may not be able to do so. Providing data for cookies described in Section 2(c) is always optional, and declining it does not affect your ability to use the core functionality of the Website.

HOW WE PROTECT YOUR DATA

We apply technical and organisational measures appropriate to the risk, including access controls, encryption in transit, and limiting access to personal data to personnel and processors who need it for the purposes described above. No system is completely secure, and if you have reason to believe your interaction with the Website is no longer secure, please contact us immediately through the provided contact form.

CHILDREN

The Website and our Services are directed exclusively at adults, businesses and professionals. We do not knowingly collect personal data from individuals under 18. If you believe a minor has provided us with personal data, please contact us and we will delete it.

CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time, for example to reflect changes in our processing activities or in applicable law. The "Last updated" date at the top of this page indicates when it was last revised. Material changes will be indicated on this page; we encourage you to review it periodically.

CONTACT

Use the provided contact form.