Skip to content
M3BSHOLDING
ExpertiseOur approachAbout us
IT/EN
Back to the site

M3BS / Privacy notice under Article 13 of the GDPR

Privacy and cookies

What the server records when you open this page, why, for how long, and how you can act on it. No banner to dismiss: this site sets no cookies.

Last updated: 8 September 2026

On this page

  1. In brief
  2. Who processes your data
  3. What the server records
  4. Visit statistics
  5. If you write to us
  6. Cookies and other tracking tools
  7. Links to external sites
  8. Who else processes this data
  9. Transfers outside the European Union
  10. How long we keep the data
  11. Security measures
  12. Your rights
  13. Right to object
  14. No consent, no profiling
  15. Updates to this page

In brief

This is a brochure site. It sells nothing, it registers no users, and it collects no data through forms.

  • It uses no cookies, neither first-party nor third-party.
  • It uses no Google Analytics and no other client-side analytics tool.
  • It has no contact form, no newsletter, no login, no shopping cart and no payments.
  • It loads nothing from external domains: images and icons come from this server, and typefaces are taken only from those already present on your device.

Some processing happens all the same, and it is only right to say so. The server records the technical data of every visit, including your IP address. Below you will find what it records, why, for how long, and who sees it.

This notice concerns the website m3bs-holding.com only. It does not concern the processing M3BS carries out on behalf of its clients in development, integration, assessment and training projects. In those engagements the client is the controller and M3BS acts as processor, on the client’s instructions and under the terms of the contract.

Who processes your data

The data controller is M3BS S.r.l.

Registered office
Via Mantovana 115, 37137 Verona (VR), Italy
VAT number and tax code
02518810201
Business register (REA) number
VR-450067
Email
marco.orso@m3bs-holding.com
Certified email (PEC) of the controller
heta-lab@legalmail.it

M3BS has not appointed a Data Protection Officer: the conditions set out in Article 37 of the GDPR (Regulation (EU) 2016/679) are not met. There is therefore no dedicated DPO address. For any question about personal data, write to the addresses above. Requests reach the controller directly.

What the server records

Every time you open a page, the web server writes a line to its log. That is how a server works, not a collection decision: without that line the page would not be delivered to you.

The line contains:

  • your IP address;
  • the date and time of the request;
  • the address of the page or resource requested;
  • the HTTP method and protocol version;
  • the server response code and the number of bytes transferred;
  • the referring page, where one exists;
  • the user agent string, which indicates your browser and operating system.

An IP address is personal data, including when it is dynamic. In principle it can lead to your identity, but only through your connectivity provider and at the request of a competent authority. We do not do this. We do not link logs to a name and we do not profile anyone.

Purpose
Operating the site, detecting anomalous access and intrusion attempts, diagnosing errors and malfunctions, and establishing liability in the event of abuse.
Legal basis
Legitimate interests, Article 6(1)(f) of the GDPR. The interest pursued is network and information security, recognised as a legitimate interest by Recital 49. On request we will explain how we weighed this interest against your rights.
Data you have to provide
None: the logging is technically necessary for the connection and takes place at the same moment the page is delivered to you.
Retention
The access logs are processed each night and archived. The archives are rotated when they reach 10 MB, and at most ten of them are kept for each type of log, in compressed form. No fixed term in days is set: given the low traffic of this site, the logs may therefore remain available for a long time, even beyond a year. They are deleted as rotation proceeds and are put to no other use.
Recipients
The hosting provider, which processes this data as a processor under Article 28 of the GDPR. Technical management of the server is carried out by the controller directly.

Consent is not required here, and it could not be sought in any event: logs are created on the server and involve no storage of information on your device.

Visit statistics

AWStats runs on the server. It is a program that reads the logs and produces traffic reports. All processing takes place on our own server: no data is sent to any external service and no measurement code runs in your browser.

These reports are not anonymous. Alongside aggregate totals, the AWStats data files contain visitors’ IP addresses, together with the number of pages viewed and the date of the last visit. No reverse DNS lookup is performed and no address is linked to an identity.

The reports are not public: the statistics directory is accessible only after authentication, and a request from outside without credentials receives a 401 error.

Purpose
Understanding how many visits the site receives and which pages are read.
Legal basis
Legitimate interests, Article 6(1)(f) of the GDPR. The interest pursued is understanding the site’s traffic, seeing which content is read and sizing the server correctly, through processing that stays on our own systems and does not track visitors.
Consent
Not required. Not because the processing produces statistics, but because it involves neither the storing of information on your device nor access to information already stored there. It therefore falls outside Article 122(1) of the Italian Data Protection Code (Codice in materia di protezione dei dati personali, Legislative Decree 196 of 30 June 2003), which transposes Article 5(3) of Directive 2002/58/EC.
Retention
The server control panel is set to three months and deletes older monthly reports. The monthly data files that contain IP addresses are not, however, covered by any automatic deletion that we have been able to verify: they may remain on the server beyond that term, until they are removed. You may ask us at any time which period is in fact available.

If you write to us

There is no form on this site and no field to fill in. The addresses you see are mailto links: they open the mail application on your own device. Some links on the home page also fill in the subject line. The site sends nothing on your behalf, does not read your message and keeps no copy of it.

Processing begins afterwards, when the message reaches the mailbox marco.orso@m3bs-holding.com or the certified mailbox heta-lab@legalmail.it.

At that point we process your email address, your name, your company and role where given, your telephone details, and any other data you choose to write in the message or its attachments. For certified email (posta elettronica certificata, PEC) we also process transmission data and the acceptance and delivery receipts.

Purpose
Replying to you and assessing a possible engagement: enquiries about digital development and integration, cybersecurity assessments, artificial intelligence assessments and training courses. Thereafter, managing and archiving the correspondence.
Legal bases
Article 6(1)(b) of the GDPR for replying to your enquiry, which is a pre-contractual step taken at your request; Article 6(1)(f) for the ordinary management and archiving of correspondence, the legitimate interest being our ability to trace the enquiries we receive, to maintain professional relationships and, where necessary, to defend legal claims; Article 6(1)(c) for retaining documents of legal, accounting or tax relevance, as required by Article 2220 of the Italian Civil Code and by Italian tax legislation.
Data you have to provide
Nothing is compulsory: it is your choice. But without your address and the content of your enquiry we cannot respond. There are no other consequences.
Retention
24 months from the last contact for enquiries that lead to no relationship; 10 years where the contact gives rise to a contract.

The mailboxes on the m3bs-holding.com domain are not hosted on a server of ours: the mail is handled through Google Workspace, a paid subscription service. On our instructions the provider processes the content of messages and attachments and the metadata the messages carry — sender and recipient addresses, date and time, subject line, headers and technical identifiers. Under the terms of the service agreement, that content is not used by the provider for advertising purposes. The service is also subject to the provider’s automated anti-spam, anti-phishing and anti-malware filters, which have to analyse messages and attachments in order to work: they are provided for by the service terms and they also serve our legitimate interest in the security of the mail service (Article 6(1)(f) of the GDPR).

The technical transmission data recorded in the provider’s systems — SMTP logs, delivery outcomes, anti-spam checks — and the service access logs are processed by the provider under its own terms and retention periods, which we do not determine and are not able to alter. The periods given above therefore concern how long correspondence stays in the mailbox, which is the only part that depends on us. The provider’s role under Article 28 of the GDPR is set out in the section “Who else processes this data”; the service runs on a global infrastructure, and transfers outside the European Union are dealt with in the section devoted to them.

No marketing

The address you write from is used to reply to you. We do not use it for newsletters, commercial mailings or promotional communications, and we do not pass it to anyone.

If you mention other people

Your message may name colleagues, technical contacts or employees. Please keep their data to what is strictly necessary and make sure you have informed them: in respect of third-party data you send us, you are the controller. Avoid writing data that serves no purpose, in particular data concerning health or any other special category under Article 9 of the GDPR.

Cookies and other tracking tools

This site sets no cookies. No technical cookies, no analytics cookies, no profiling cookies, no third-party cookies. None. Last technical check on the code: 8 September 2026.

The site contains none of the following: client-side analytics tools, tag managers, advertising pixels, social widgets or buttons, embedded maps, embedded video, iframes, captchas, content delivery networks, service workers, offline caches, IndexedDB or localStorage. Nor are any passive identification techniques used: no device or browser fingerprinting, no unique identifier generated on the client.

The site uses only the fonts already installed on your device: no request is sent to Google Fonts or to any other font service, and no font file is hosted on this server. The photographs are hosted on this server and the icons are drawn inside the page itself.

Opening the site does not disclose your IP address to any third party: every request that makes up the page goes to this server. The one exception is the resolution of the domain name, which happens before and outside the site: the DNS resolver you use may pass a truncated portion of your address to the authoritative servers (the EDNS Client Subnet mechanism). It is covered in the section on recipients.

What stays in your browser

The site’s navigation runtime may write two entries, and only two, to your browser’s sessionStorage: __vinext_rsc_initial_reload__ and __vinext_hard_navigation_target__. They are not there to recognise you: each holds the address of the page of this site that is being loaded, and each acts as a guard against an endless reload loop. They are written only where a page load fails or requires a full reload, and removed as soon as the load succeeds; in ordinary browsing the sessionStorage stays empty.

Your position on the page and the order of the pages you have visited are not held in sessionStorage: they are fields of the browser’s history state (history.state, namely __vinext_scrollX, __vinext_scrollY, __vinext_historyIndex, __vinext_previousNextUrl, __vinext_bfcacheIds and __vinext_bfcacheVersion), which the browser keeps for the individual tab and discards when you close it. The site uses no localStorage. There is also the ordinary HTTP cache of pages and images, because the server sends ETag and Last-Modified headers: that is how the web works, it avoids downloading again what you have already downloaded, and it is emptied when you clear your cache. None of this contains an identifier capable of recognising you on a later visit, and none of it allows profiling.

sessionStorage and the browser history state also fall within Article 122(1) of the Italian Data Protection Code (Legislative Decree 196 of 30 June 2003), which transposes Article 5(3) of Directive 2002/58/EC: the rule covers any storing of information on the user’s device and any gaining of access to information already stored there, not cookies alone, as the European Data Protection Board confirmed in Guidelines 2/2023. Here, however, the exemption in Article 122(1) itself applies: the storing is strictly necessary in order for the provider of an information society service explicitly requested by you — showing you this site when you open its address — to provide that service. Consent is therefore not required; information is, and this is it.

Why there is no banner

Because there is nothing to consent to. A banner asking permission for cookies that do not exist would be a pointless obstacle and, given how this site is built, a false statement as well. The exemption from consent for strictly technical tools is laid down in Article 122(1) of the Italian Data Protection Code: for such tools information under Article 13 of the GDPR remains due, but consent does not. This is confirmed by the Italian Data Protection Authority’s Guidelines on cookies and other tracking tools — Linee guida cookie e altri strumenti di tracciamento, decision no. 231 of 10 June 2021, doc. web no. 9677876, published in the Italian Official Gazette (Gazzetta Ufficiale) no. 163 of 9 July 2021.

How to check it yourself, in a minute

Open your developer tools: F12, or Ctrl+Shift+I. On a Mac the shortcut is Cmd+Alt+I in Chrome, Edge and Firefox; in Safari you first have to enable the Develop menu in the settings. Look for the panel Chrome and Edge call Application and Firefox calls Storage. Under Cookies you will find no entry for m3bs-holding.com, and Local Storage is empty. Check Session Storage as well: in ordinary browsing that is empty too, and if anything appears it is only the two entries described above, whose value is the address of a page of this site and not an identifying code. Finally open the Network tab and reload: every request points to m3bs-holding.com and none to an external domain.

Links to external sites

The pages of this site contain no links to third-party websites. The only exception is on this page: the link to the website of the Italian Data Protection Authority (Garante per la protezione dei dati personali), in the section on your rights. It opens only if you click it, and from that moment the privacy notice of the destination site applies, over which M3BS has no control.

No resource is loaded from external domains while you browse. The photographs are hosted on this server: opening a page triggers no request to the websites of their authors.

Who else processes this data

Few parties, all of them necessary to run the site and the mailboxes.

  • Aruba S.p.A., which provides the dedicated server on which the site runs and which processes the browsing data as a processor under Article 28 of the GDPR. It does not host the domain mailboxes and does not process the correspondence.
  • The email service provider. The mailboxes on the m3bs-holding.com domain are handled through Google Workspace, a paid subscription service of the Google group. The name of the company with which the service agreement is concluded, identified by the billing address under the table published by the provider, is given on request. The provider acts as a processor under Article 28 of the GDPR in respect of mailbox content, on the basis of the Cloud Data Processing Addendum, which forms an integral part of the service agreement; in respect of account, billing and technical service-operation data it acts instead as an independent controller, under its own privacy notice. Additional services not included in the core service fall outside that addendum. The provider may engage sub-processors: the controller is notified of any change and may object within the limits set by the contract, but does not select them.
  • The certified email provider (Legalmail, InfoCert). It acts as a processor for the safekeeping of the mailbox. It acts as an independent controller for the obligations that Italian legislation on certified electronic delivery places directly on it, including retention of the message log.
  • The controller’s legal and tax advisers, where the correspondence concerns a contractual relationship or a document of accounting or tax relevance.
  • Judicial and law enforcement authorities, upon lawful request.

No one else, save for the sub-processors engaged by the email service provider as set out above. Technical management of the server and the site is carried out by the controller directly, with no external supplier. The data is neither disclosed nor sold to third parties for purposes of their own. An up-to-date list of processors is available on request.

Name resolution for m3bs-holding.com is handled by a third-party managed DNS service (Google Cloud DNS). Authoritative DNS servers translate the domain name into a network address: they receive only the name-resolution query, which reaches them from your provider’s resolver. They do not receive your HTTP requests, they do not see the pages you visit, and they do not receive the site logs. For that reason they are not listed among the recipients of your browsing data.

Transfers outside the European Union

Your browsing data stays in Italy. The site is hosted on a dedicated Aruba server in an Italian data centre. There is no content delivery network, no third-party proxy and no external statistics service: for this data no transfer to third countries or international organisations takes place, save for the domain name resolution described below.

Email is a different matter, and it is only right to say so. The domain mailboxes are handled through Google Workspace, which runs on a global infrastructure: processing the correspondence may therefore involve the transfer of personal data to third countries, including the United States of America. Such transfers take place on the basis of the safeguards under Chapter V of the GDPR applicable to the provider from time to time: at present, the adequacy decision adopted by the European Commission in respect of the EU-US data protection framework and, in addition, the standard contractual clauses adopted by the European Commission, as incorporated into the service documentation. Should any of those safeguards cease to apply, transfers will continue solely on the basis of the other Chapter V safeguards of the Regulation applicable at that time.

The managed DNS service mentioned above may also operate outside the European Economic Area. It concerns the translation of the domain name only and involves no transfer of your browsing data. To the extent that a transfer of personal data nonetheless occurs, it relies on the Chapter V safeguards of the GDPR set out in the provider’s terms of service.

You may ask for information about the safeguards in place and for a copy of the contractual documentation, to the extent that it is available to us, or for details of where it is published, by writing to marco.orso@m3bs-holding.com.

How long we keep the data

Every processing operation has the term set out in the table below. Where no fixed term exists, we say so; where the period is not set by us but by the service provider, the table says so expressly.

DataRetention
Web server logsSize-based rotation: 10 MB per file, at most ten compressed archives for each type of log. No fixed term in days
Monthly AWStats statistics reports3 months
Monthly AWStats data files, which contain IP addressesNo verified automatic deletion: they remain until they are removed
Technical message-transmission data recorded in the provider’s systems and access logs of the email serviceSet by the terms of the email service provider: we do not determine it, do not verify it and cannot alter it
Enquiry emails with no follow-up24 months from the last contact
Correspondence and documents relating to contractual relationships10 years (Article 2220 of the Italian Civil Code and Italian tax legislation)
Certified email (PEC) messages of legal relevance10 years

Where a log relates to a security incident under investigation or to a request from a competent authority, the data concerned may be kept beyond the ordinary term, for as long as is needed for the investigation and for the establishment or defence of legal claims.

The certified email message log is kept by the provider for the period that Italian legislation on certified electronic delivery imposes on it, as stated in its terms of service: it is an obligation the controller cannot shorten.

For email, the periods in the table concern the correspondence that stays in the mailbox, which is the only part we govern. Deleting a message does not remove it at once from every system of the provider: deleted data remains in backup systems for the period stated by the provider itself, which we are not in a position to verify.

Security measures

The attack surface is small: a static site, with no database, no member area and no incoming data. These are the measures in place.

  • The site is served over an encrypted HTTPS connection.
  • The statistics reports are accessible only after authentication: a request from outside without credentials receives a 401 error.
  • Access to the web server logs and to the machine is restricted to authorised technical staff.

Your rights

Within the limits set by the GDPR, you may request:

  • access to the data concerning you (Article 15);
  • rectification of inaccurate data (Article 16);
  • erasure (Article 17);
  • restriction of processing (Article 18);
  • data portability (Article 20): it covers only data processed by automated means on the basis of a contract or of consent. It may therefore cover correspondence connected to an enquiry of yours, but not the server logs or the statistics, which rest on legitimate interests;
  • objection (Article 21), which is dealt with in the next section.

To exercise these rights, write to marco.orso@m3bs-holding.com or to the certified mailbox heta-lab@legalmail.it. We reply within one month; where a request is complex the period may be extended by two further months, and we will tell you within the first month (Article 12(3)). Exercising your rights is free of charge.

The logs are not linked to a name. To find the data concerning you we need the IP address and the period. If you cannot supply them, we may be unable to identify you, and in that case certain rights cannot be exercised over that data (Article 11(2) of the GDPR).

If you consider that the processing infringes the GDPR, you may lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali): Piazza Venezia 11, 00187 Rome, Italy; switchboard (+39) 06 696771; email protocollo@gpdp.it; certified email protocollo@pec.gpdp.it, which accepts messages only from other certified email accounts; www.garanteprivacy.it. If you live or work in another EU Member State, or if you believe the infringement took place in another Member State, you may lodge your complaint with the supervisory authority of that country instead (Article 77(1) of the GDPR). You may also apply to the courts: under Italian law an administrative complaint and judicial proceedings on the same facts cannot be pursued together.

Right to object

The server logs, the access statistics and the management and archiving of correspondence rest on our legitimate interests. You therefore have the right to object at any time to that processing, on grounds relating to your particular situation. It is enough to write to marco.orso@m3bs-holding.com.

If you object, we will stop processing that data. We may continue only if we demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or if that data is needed for the establishment, exercise or defence of legal claims.

The log line cannot be suppressed in advance, because it is written at the very moment the server delivers the page to you. An objection therefore concerns the retention and the subsequent use of that data.

No consent, no profiling

No processing connected with this site rests on consent. You are not asked for it, none is recorded, and there is nothing to withdraw: the right of withdrawal under Article 13(2)(c) of the GDPR does not apply. If we ever introduce tools that require consent, this page will be updated before they go live.

There is no automated decision-making, including profiling, within the meaning of Article 22 of the GDPR. No decision concerning you is taken automatically: the site collects nothing that would make it possible.

Updates to this page

We update this text whenever something substantive changes: a new processing operation, a new recipient, a different retention period. If the site introduces a contact form, an analytics tool, a font loaded from an external domain or an embedded map, this notice will be updated together with the change, not afterwards.

Language

This notice is published in Italian and in English, with matching content and the same date. In the event of any discrepancy between the two versions, the Italian version prevails. Italian version: Privacy e cookie.

Last updated: 8 September 2026

Back to homeWrite to us
M3BSHOLDING

Digital expertise. Human vision.

Back to top
M3BS S.r.l.Via Mantovana 115
37137 Verona (VR), Italy
VAT / Tax code: 02518810201REA VR-450067
PECheta-lab@legalmail.it
© 2026 M3BS S.r.l.Privacy