Information on the processing of personal data
pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 – GDPR
Last updated: 13 July 2026
1. Data controller
Mebius srl
Via L'Aquila 23/m, Rome, Italy
VAT no.: 08694131007
Email: info@mebius.it – Phone: 02.45.07.11.08
To exercise your rights, or for any question about this notice, you can write to info@mebius.it.
No Data Protection Officer (DPO) has been appointed, as the conditions set out in Article 37 GDPR do not apply.
2. What data we collect
a) Data you provide through the contact forms
First and last name, company, email address, phone number, and the content of the message you write. We also record the fact that you gave your consent, together with the date and the exact wording you accepted: this allows us to prove that consent was collected properly, and it is a safeguard for you.
b) Data collected automatically while you browse
IP address, browser type (user agent), pages visited, date and time. This data is recorded in the server logs for security reasons and to keep the service running.
c) Source data (attribution)
When you reach the site from an advertisement, a search engine or another website, we store information about where you came from: advertising click identifiers (Google's gclid, gbraid, wbraid), campaign parameters (utm_*), the first page you saw and the referring website. This helps us understand which of our initiatives actually work. Details of the cookies used are in section 10.
We do not collect special categories of data (Article 9 GDPR: health, political opinions, religious beliefs, biometric data, sexual orientation). Please do not include any such data in the message field.
3. Why we process your data, and on what legal basis
- Responding to your request for information, a quote or a commercial contact – pre-contractual measures taken at your request (Article 6.1.b GDPR). The consent we ask for in the form is an additional transparency safeguard, not the legal basis of the processing.
- Measuring the effectiveness of our advertising campaigns and understanding which channels bring useful enquiries – legitimate interest (Article 6.1.f): our interest in assessing the effectiveness of our own communication, balanced by the use of non-identifying, first-party data.
- Keeping the website secure and preventing abuse (logs, anti-spam, rate limiting) – legitimate interest (Article 6.1.f).
- Sending commercial communications and newsletters (where active) – consent, freely given, specific and revocable (Article 6.1.a).
- Complying with legal obligations (tax, accounting, requests from the authorities) – legal obligation (Article 6.1.c).
Providing the data marked as mandatory in the form is necessary for us to get back to you: without it, the request cannot be handled. Everything else is optional.
4. How long we keep the data
- Customer data and contractual relationships – 10 years, due to civil-law and tax obligations (Article 2220 of the Italian Civil Code).
- Contacts subscribed to our communications (the Mystery Marketing News magazine, newsletters) – until consent is withdrawn. The legal basis is consent: until you withdraw it, the editorial relationship continues. Every message contains an unsubscribe link.
- Form enquiries without consent to communications – 36 months from the last contact.
- Server logs – 12 months, for security and to investigate abuse.
- Attribution data (first-party cookies) – 90 days, matching the lifetime of the cookie.
Once these periods expire, the data is deleted or irreversibly anonymised.
5. Where the data is processed
Data submitted through the forms is processed on Mebius srl's own infrastructure (internal CRM), hosted at OVH, on servers located in France, and therefore within the European Union. OVH acts as a data processor pursuant to Article 28 GDPR and its data centres are ISO/IEC 27001 certified.
Data submitted through the forms does not leave the European Union.
We do not transfer form data to third-party marketing automation platforms. Until 12 July 2026 the forms were provided by ActiveCampaign: this is no longer the case.
6. Who we share the data with
The data may be processed by authorised staff of Mebius srl and by the suppliers that provide us with technical services, appointed as data processors (Article 28 GDPR):
- OVH – hosting of the websites and of the CRM, servers in France (European Union). ISO/IEC 27001 certified data centres.
- Twilio SendGrid (Twilio Inc., United States) and Amazon Web Services – Amazon SES (Amazon Web Services EMEA SARL) – delivery of transactional emails and editorial communications.
- Google Ireland Ltd / Google LLC – Google Analytics 4 (with Consent Mode v2) and Google Maps, both present on this website.
The data is not disseminated and is not sold or transferred to third parties for marketing purposes.
Transfers outside the European Union. Some suppliers are based in the United States (Twilio SendGrid; the Google services). In these cases the transfer takes place on the basis of the Standard Contractual Clauses approved by the European Commission and/or of the EU-US Data Privacy Framework certification. You can ask us for a copy of the safeguards in place by writing to info@mebius.it.
7. Your rights
You have the right to:
- access your data and obtain a copy of it (Article 15);
- ask for its rectification if it is inaccurate or incomplete (Article 16);
- ask for its erasure (Article 17);
- ask for the restriction of processing (Article 18);
- receive your data in a machine-readable format and transmit it to another controller (portability, Article 20);
- object to processing based on legitimate interest, including direct marketing (Article 21);
- withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
To exercise them, write to info@mebius.it. We reply within one month, extendable by two further months in complex cases (Article 12.3).
If you believe the processing infringes the GDPR, you can lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or bring an action before the courts.
8. Automated decision-making
We do not carry out automated decision-making or profiling producing legal effects concerning you (Article 22 GDPR).
9. Security
We adopt appropriate technical and organisational measures to protect the data: encrypted connections (HTTPS), access restricted to authorised staff, protection of public endpoints against automated abuse.
Mebius srl is ISO 9001 certified. The data centres hosting our systems are certified ISO/IEC 27001.
10. Cookies
This website uses technical cookies, always active because they are necessary for the site to work and for first-party measurement, and analytics and advertising cookies, which are only set after consent has been given through the banner. Consent preferences are stored locally in the browser (localStorage) and can be changed at any time from the cookie icon on the site.
Technical and necessary cookies (always active)
Attribution cookies (first-party, technical/measurement) – mc_gclid, mc_gbraid, mc_wbraid, mc_utm_* (mc_utm_source, mc_utm_medium, mc_utm_campaign, mc_utm_term, mc_utm_content), mc_landing, mc_referrer. Duration: 90 days. They link a request submitted through our forms to the campaign, search engine or page the user came from, so that we can measure the effectiveness of our initiatives. They are first-party cookies, they do not profile the user and are not shared with third parties.
Analytics and advertising cookies (subject to consent)
Subject to consent, the website uses Google Analytics cookies (usage statistics) and Google advertising cookies. Without consent, these cookies are not set.