Privacy Notice Regarding the Processing of Personal Data

Pursuant to Articles 13 and 14 of EU Regulation 2016/679 – GDPR

1. Data Controller

The data controller for the personal data collected through this website is:

PhoenITx S.r.l.
Via Pietro Calvi, 2
20129 Milan – Italy
Tax ID and VAT Number: IT06466860969

Email: amministrazione@phoenitx.it
Work email: segreteria@dri-italy.it
Phone: +39 02 82396499
WhatsApp: +39 351 3181130

PhoenITx S.r.l. manages DRI Italy’s operations and represents DRI International in Italy and France in the organization and delivery of official courses. The website confirms that registration and billing for Italian courses are handled by PhoenITx S.r.l. (DRI Italy)

2. Scope of This Privacy Policy

This privacy policy describes the processing of personal data by PhoenITx S.r.l. in connection with:

  • when visiting the website;
  • in response to requests for information;
  • enrollment in and participation in courses;
  • the administrative and organizational management of the courses;
  • when you subscribe to the newsletter;
  • the use of statistical, technical, and security tools;
  • communications sent via email, phone, or WhatsApp.

This privacy notice applies exclusively to data processing carried out by PhoenITx S.r.l.

Third-party websites, platforms, and services accessible via links on these pages are operated by independent data controllers and are governed by their respective privacy policies.

3. Source of the data

Personal data may be collected:

  • directly from the individual concerned, via the website, by email, phone, WhatsApp, or through the registration form;
  • by the company, agency, or organization that enrolls one of its employees or contractors in the course;
  • automatically, while you browse, through technical systems, server logs, security tools, and cookies;
  • from suppliers and platforms used to provide the services, to the extent necessary for managing the relationship.

When data is provided by the company or the individual purchasing the course, PhoenITx S.r.l. uses it exclusively for purposes related to enrollment, organization, and delivery of the training program.

4. Types of Data Processed

4.1 Browsing Data and Technical Data

When you visit the website, computer systems may automatically process information such as:

  • IP address;
  • date and time of the connection;
  • pages requested;
  • browser type and version;
  • operating system and device used;
  • URL of the referring page;
  • technical data related to the session;
  • system errors;
  • access attempts and other security-related events;
  • preferences expressed through the cookie management system.

This data is processed to ensure the proper functioning and security of the website, to prevent malicious activity, and—subject to consent where required—to obtain aggregate statistics on page usage.

4.2 Data Provided Through the Contact Form

When a user fills out the contact form, the following information may be collected:

  • name;
  • email address;
  • phone number;
  • city;
  • company or organization to which you belong;
  • message content;
  • other information voluntarily provided.

The website currently asks for your name, email address, and message, and also allows you to provide your phone number, city, and company. (DRI Italy)

Users are asked not to include in their messages data belonging to special categories, health information, or other data not necessary for the request.

4.3 Information Regarding Course Registration and Attendance

To manage course enrollment, PhoenITx S.r.l. may process:

  • the participant’s first and last name;
  • email address and phone numbers;
  • company or organization to which you belong;
  • professional role or function;
  • course selected;
  • information provided on the registration form;
  • organizational communications;
  • information required for billing;
  • information regarding the order and payment;
  • attendance and participation in training activities;
  • organizational or educational needs communicated by the participant;
  • six-digit DRI identification code.

If registration is performed by a company or organization, certain data may be provided to PhoenITx S.r.l. by the employer, the client, or the administrative contact.

PhoenITx S.r.l. does not create the participant’s personal account with DRI International, nor does it enter the participant’s personal or contact information on their behalf into the U.S.-based platform.

4.4 Information for newsletter subscription

The following information may be collected when you subscribe to the newsletter:

  • email address;
  • name;
  • last name;
  • registration date and procedures;
  • information necessary to document consent;
  • subscription or unsubscription status;
  • technical data related to message delivery;
  • Where enabled, statistical information regarding the opening of messages and the clicking of links contained in emails.

The form on the website asks for your email address, first name, and last name. (DRI Italy)

5. Purposes and Legal Bases for Data Processing

5.1 Website Operation and Security

Technical and browsing data are processed for the following purposes:

  • make the website’s pages and features available;
  • ensure the stability and security of the systems;
  • prevent unauthorized access, malware, fraud, and cyberattacks;
  • check for anomalies and malfunctions;
  • manage technical logs;
  • determine liability in the event of illegal activities.

The legal basis is the Data Controller’s legitimate interest in protecting the website, its IT systems, data, and users, pursuant to Article 6(1)(f) of the GDPR.

5.2 Responding to Requests for Information

Data provided via the contact form, email, phone, or WhatsApp is processed for the following purposes:

  • respond to requests;
  • provide information about courses and certifications;
  • prepare bids;
  • contact the person concerned again;
  • manage any pre-contractual relationships.

The legal basis is the implementation of precontractual measures taken at the request of the data subject, pursuant to Article 6(1)(b) of the GDPR.

For general inquiries that are not of a contractual nature, the processing may be based on the Data Controller’s legitimate interest in responding to the communications received.

5.3 Course Management

Participant data is processed for the following purposes:

  • manage registration;
  • organize and deliver the course;
  • send meeting notices, links, and operational communications;
  • set up access to the learning platforms;
  • provide the materials for which PhoenITx S.r.l. is responsible;
  • record attendance;
  • provide support before, during, and after the course;
  • verify and confirm the participant’s enrollment in the official DRI course;
  • manage orders, payments, and billing;
  • comply with administrative, tax, and accounting obligations;
  • to protect the rights arising from the contractual relationship.

The legal basis is the performance of the contract or precontractual measures requested by the data subject, pursuant to Article 6(1)(b) of the GDPR.

The processing required for billing and accounting purposes is based on compliance with legal obligations, pursuant to Article 6(1)(c) of the GDPR.

5.4 Newsletters and Informational Communications

Subject to consent, the data is processed to send communications regarding:

  • training courses and programs;
  • professional certifications;
  • events and initiatives;
  • articles and in-depth features;
  • Business Continuity;
  • Cyber Resilience;
  • Disaster Recovery;
  • Operational Resilience;
  • Risk Management;
  • other professional activities promoted by PhoenITx S.r.l. and its brands.

The legal basis is the data subject’s consent, pursuant to Article 6(1)(a) of the GDPR.

Consent is optional and may be withdrawn at any time by clicking the unsubscribe link included in each newsletter or by writing to the Data Controller.

Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.

5.5 Website Usage Statistics

Subject to your consent, this website uses statistical tools to understand:

  • the number of visits;
  • the pages visited;
  • the duration of visits;
  • the general terms of use for the website;
  • the technical performance of the pages;
  • the approximate origin of the traffic.

The legal basis is the user’s consent, which is given through the cookie banner.

Rejecting statistical cookies does not prevent you from browsing the site.

6. Newsletter Management Using MailerLite

We use MailerLite to collect subscriptions, manage mailing lists, and send out the newsletter.

For customers based in the European Economic Area, the service is contractually provided by:

MailerLite Limited
88 Harcourt Street
Dublin 2, D02 DK18
Ireland

MailerLite Limited processes data on behalf of PhoenITx S.r.l. as the data controller, based on the contractual terms and the data processing agreement applicable to the service. MailerLite confirms that, for customers in the EEA, the United Kingdom, and Switzerland, the contracting party is the Irish company and provides a Data Processing Addendum. (mailerlite.com)

The following data may be processed through MailerLite:

  • first and last name;
  • email address;
  • registration date and procedures;
  • evidence of consent;
  • enrollment status;
  • unsubscribe request;
  • information on the delivery of communications;
  • When enabled, clicks on and interactions with links in newsletters.

The data subject may revoke consent at any time without affecting the ability to use the site’s other services.

7. Registration with DRI International

The courses offered through DRI Italy are part of the official programs of DRI International, an organization based in the United States.

To access the services managed directly by DRI International—including the personal account, materials made available on the DRI platform, exams, and any certification procedures—participants must register personally on the official DRI International website.

During the registration process, the participant provides the information requested by the platform directly to DRI International.

PhoenITx S.r.l.:

  • does not create a personal account on behalf of the participant;
  • does not enter the participant’s personal information into the DRI platform;
  • does not transmit to DRI International the data entered directly by the data subject during registration;
  • does not receive their personal login credentials for the DRI account.

DRI International collects, among other information, personal data, contact information, DRI ID numbers, and information regarding courses, exams, certifications, and payments directly. For these processing activities, DRI International acts independently and applies its own privacy policy. (drii.org)

Participants must therefore review the privacy policy provided by DRI International before completing their registration.

8. Six-digit DRI identification code

After registering, the participant receives a six-digit DRI identification code.

The participant must provide this code to PhoenITx S.r.l. so that enrollment in the official course can be verified and confirmed.

For confirmation purposes, PhoenITx S.r.l. provides DRI International solely with the identification code and does not transmit, as part of this procedure:

  • first and last name;
  • email address;
  • phone number;
  • mailing address;
  • company data;
  • login credentials;
  • other information provided by the participant when creating the account.

Although the code does not contain any directly readable personal information, it must be considered pseudonymized personal data, since DRI International can link it to the account and identify the participant.

PhoenITx S.r.l. uses and discloses the code exclusively for:

  • verify the participant’s DRI identity;
  • link it to the purchased course;
  • confirm your participation;
  • fulfill the obligations related to the organization of the official course.

The provision of the code is based on the performance of the contractual relationship with the participant or with the organization that purchased the course.

The code is retained for the period necessary to manage the course and fulfill the related administrative and contractual obligations.

When the data subject personally provides their data to a data controller located in a third country, the data is not transferred by a European data exporter. The subsequent disclosure of the code by PhoenITx S.r.l. to DRI International, however, constitutes a transfer between two separate entities and must be assessed in accordance with the rules applicable to international transfers.

9. Google Analytics

This site uses Google Analytics 4, installed via Google Site Kit, to generate statistics on site traffic.

For European customers, the service is provided by Google Ireland Limited. (Google Marketing Platform)

Google Analytics is enabled only after the user has given consent for the “Statistics” category.

The following can be processed through the service:

  • browser and device information;
  • pages viewed;
  • session duration;
  • navigation events;
  • approximate geographic area;
  • technical information regarding the connection;
  • online identifiers generated by the service.

Google states that Google Analytics does not record or store individual IP addresses and that, for users in the European Union, IP data used to derive approximate geographic information is deleted before it is recorded. (Google Support)

PhoenITx S.r.l. has configured the system so that Google Analytics data is not used for the website’s own advertising purposes without the necessary consent.

Users can refuse or withdraw their consent at any time by using the “Manage Cookie Preferences” option.

10. Cookies and Consent Management

This website uses:

  • necessary technical cookies;
  • cookies to store your language and other preferences;
  • cookies to record consent preferences;
  • statistical tools that are activated only after consent is given;
  • technologies necessary for site security.

Technical cookies are used based on the need to provide the requested service and the Data Controller’s legitimate interest in ensuring the proper functioning of the website.

Statistical cookies are used only with your consent.

The website does not currently use first-party cookies for the purpose of advertising profiling of users.

Detailed information about cookies, services, purposes, and durations is available in the Cookie Policy.

Users can change or revoke their choices using the “Manage Cookie Preferences” option on the website.

11. Google Fonts

This site may use Google Fonts to display fonts.

If fonts are loaded directly from Google’s servers, the user’s browser may establish a connection with those servers and transmit technical data, including the IP address.

The loading of external services is managed, where necessary, according to the preferences expressed through the consent system.

If the fonts are hosted locally on the website’s server, a connection to Google’s servers is not required to display them.

12. Website Security and Wordfence

This site uses Wordfence to protect itself against:

  • unauthorized access;
  • cyberattacks;
  • attempted intrusions;
  • malware;
  • vulnerability;
  • attempts to log in using compromised credentials;
  • potentially harmful traffic.

For this purpose, the following may be processed:

  • IP addresses;
  • date and time of the requests;
  • requested pages and resources;
  • user agent;
  • authentication attempts;
  • security incidents;
  • technical information needed to distinguish legitimate traffic from malicious traffic.

The legal basis is PhoenITx S.r.l.’s legitimate interest in protecting the website, its systems, and the data it processes.

Wordfence is provided by Defiant, Inc., a U.S. company. Defiant states that it may process identifiers and IP addresses in the provision of its services and that it may use, where applicable, standard contractual clauses approved by the European Commission for international data transfers. (Wordfence)

13. Platforms Used for Online Courses

When a course is delivered online, the data required for participation may be processed through videoconferencing platforms and educational tools used for:

  • send the access link;
  • identify the participants;
  • to allow participation in the class;
  • manage audio, video, and content sharing;
  • provide technical assistance;
  • record attendance.

Any audio or video recording of a class will be made only after the participants have been informed and provided there is an adequate legal basis.

External platforms also process data in accordance with their own terms and privacy policies.

14. WhatsApp and Other Communication Channels

Users may voluntarily contact PhoenITx S.r.l. via WhatsApp.

In that case, the following are processed:

  • phone number;
  • name or designation associated with the account;
  • message content;
  • documents or attachments voluntarily submitted;
  • date and time of the communications.

WhatsApp is a third-party service and processes data in accordance with its own privacy policy.

The use of WhatsApp is optional. Users may also contact the Data Controller via email or phone.

15. Links to Social Media and External Websites

The website may contain simple links to LinkedIn, X, institutional websites, educational platforms, and other external services.

When a user clicks a link, they leave this site and access a platform operated by a third party.

The third party processes the data in accordance with its own privacy policy and terms and conditions.

The mere presence of a link does not imply that PhoenITx S.r.l. receives data related to the user’s account on the social network.

16. Recipients of the Data

Personal data may be processed, to the extent necessary, by:

  • directors, employees, and authorized contractors of PhoenITx S.r.l.;
  • faculty and staff involved in organizing the courses;
  • hosting and IT infrastructure providers;
  • email service providers;
  • maintenance and technical support providers;
  • MailerLite Limited, for newsletter management;
  • Google Ireland Limited and its affiliates, for Google Analytics and other Google services used;
  • Defiant, Inc., for Wordfence services;
  • providers of videoconferencing and online training platforms;
  • administrative, tax, and legal consultants;
  • credit institutions and payment service providers;
  • public authorities and other entities to which disclosure is required by law;
  • DRI International, limited to the DRI identification code required to link the participant to the official course.

Entities that process data on behalf of PhoenITx S.r.l. are designated as data processors pursuant to Article 28 of the GDPR, where applicable.

Personal data is not sold to third parties.

17. Data Transfers Outside the European Economic Area

Some of the suppliers used by the website may have headquarters, infrastructure, affiliated companies, or subcontractors located outside the European Economic Area.

When PhoenITx S.r.l. transfers personal data to a third country, the transfer must comply with Articles 44 et seq. of the GDPR, using one of the mechanisms provided for by the regulation, such as:

  • an adequacy decision;
  • standard contractual clauses approved by the European Commission;
  • other appropriate safeguards;
  • one of the exceptions provided for by law, when actually applicable.

Relations with DRI International

DRI International is headquartered in the United States.

The data entered by the participant when creating an account is provided directly by the participant to DRI International and is not transferred by PhoenITx S.r.l.

PhoenITx S.r.l. provides DRI International solely with the six-digit DRI identification code required to verify and confirm enrollment in the course.

The code:

  • does not contain any personally identifiable information that is directly readable;
  • does not contain contact information;
  • does not contain credentials;
  • However, DRI International may link it to the participant’s account.

PhoenITx S.r.l. applies the principle of data minimization, refraining from sharing with DRI International the personal and contact information already provided directly by the participant.

Further information regarding how the code is communicated and the applicable guarantees may be requested from the Data Controller.

18. Processing Methods and Security Measures

The data is processed using computer systems, telecommunications systems, and, where necessary, on paper.

PhoenITx S.r.l. implements appropriate technical and organizational measures to protect data from:

  • unauthorized access;
  • loss;
  • destruction;
  • alteration;
  • unauthorized disclosure;
  • use that does not conform to the stated purposes;
  • unintended unavailability;
  • cyberattacks.

Access to the data is limited to those who need it to perform their duties.

However, no system can guarantee absolute security.

19. Retention Periods

Personal data is retained for as long as necessary to fulfill the purposes for which it was collected.

Technical and Safety Data

Technical and security logs are retained for a period of time commensurate with the need to protect the site, investigate any incidents, and identify unlawful conduct.

In the event of an accident or dispute, the data may be retained for a longer period to allow for the necessary investigations.

Contact Requests

Data related to requests for information are retained for as long as necessary to respond to such requests and manage any subsequent interactions.

If the request results in a contractual relationship, the data will be included in the relevant administrative and contractual documentation.

Courses and Contractual Relationships

Data regarding course enrollment and attendance are retained for the duration of the relationship and thereafter for as long as necessary:

  • compliance with administrative and tax obligations;
  • the handling of any disputes;
  • to protect the rights of the data subject;
  • the documentation of the training activities provided.

Tax and accounting records are retained for the periods specified by applicable law.

DRI Identification Code

The DRI identification code is retained for as long as necessary to verify and manage the course and to fulfill any related administrative and contractual obligations.

Newsletter

The data used for the newsletter is retained until:

  • upon withdrawal of consent;
  • to unsubscribe;
  • in response to the request for cancellation;
  • upon termination of employment.

The information needed to document consent and subsequent opt-out may be retained for as long as necessary to demonstrate compliance with regulatory requirements.

Google Analytics

Statistical data is retained in accordance with the settings configured in the Google Analytics account and for a period commensurate with the purposes of the analysis.

20. Whether the contribution is mandatory or optional

The provision of data is:

  • necessary to respond to requests that require the identification of the data subject;
  • required to register and participate in the courses;
  • necessary for billing and contractual obligations;
  • required, limited to the DRI code, to link the participant to the official course;
  • optional for newsletter subscription;
  • optional for statistical cookies;
  • Optional for using WhatsApp.

Failure to provide the necessary information may make it impossible to respond to your request, complete your registration, or provide the service.

Rejecting statistical cookies does not prevent you from browsing the site normally.

21. Rights of the Data Subject

In the cases provided for by the GDPR, the data subject may:

  • to obtain confirmation of the existence of personal data concerning him or her;
  • access the data;
  • request a correction;
  • obtain the cancellation;
  • request the restriction of processing;
  • object to processing based on legitimate interests;
  • to receive the data in a structured, commonly used, and machine-readable format, where applicable;
  • request that the data be transferred to another data controller, where applicable;
  • withdraw consent at any time;
  • file a complaint with the supervisory authority;
  • seek judicial relief.

The withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.

Requests may be sent to:

amministrazione@phoenitx.it

or:

segreteria@dri-italy.it

The Data Controller may request the information necessary to verify the applicant’s identity.

The applicable rights and disclosure obligations are governed by Articles 12–22 of the GDPR. (Eur-Lex)

22. Complaint to the supervisory authority

The data subject has the right to file a complaint with:

Data Protection Officer

or to the competent supervisory authority in the Member State where the individual resides, works, or believes the violation occurred.

Filing a complaint does not preclude the right to seek redress through the courts. (Data Protection Authority)

23. Automated Decisions and Profiling

PhoenITx S.r.l. does not use the data collected through the website to make decisions based solely on automated processing that produce legal effects or significantly affect the data subject.

The website does not engage in its own advertising profiling.

Google Analytics is used for statistical purposes only with prior consent.

24. Data on Minors

The courses and services promoted through this website are primarily intended for professionals and adults.

PhoenITx S.r.l. does not intend to knowingly collect personal data from minors through this website.

If data relating to a minor has been disclosed without proper authorization, you may contact the Data Controller to request verification and, where applicable, deletion of such data.

25. Changes to the Privacy Policy

This privacy policy may be amended to reflect:

  • regulatory changes;
  • new guidelines from the authorities;
  • organizational changes;
  • the introduction or discontinuation of services;
  • changes in processing methods.

The updated version will be posted on this page.

Last updated: July 16, 2026