Skip to main content
GDPR

Privacy Policy

Last updated: July 21, 2026

This Privacy Policy explains how Riccardo Bozzato (“I”, “me”, “my”) collects, uses, and protects your personal data when you visit my website, download resources, engage my consulting services, or purchase ShipKit. I take your privacy seriously — I follow the GDPR (Reg. EU 2016/679) and the Italian Data Protection Code (D.Lgs. 196/2003, as amended by D.Lgs. 101/2018), and keep data collection to the minimum necessary for the requested services.

1. Data Controller

Riccardo Bozzato

Legnaro, PD, Italy

Email: [email protected]

Phone: +39 389 213 9542

2. Data Collected — Per Service

<strong>General contact form:</strong> name, email, and message. Used for role inquiries, projects, or consultations.

<strong>Operations Audit (€490):</strong> name, email, company, operational problem description. Collected to deliver the 2-day audit and prepare the report.

<strong>Delivery & Process Design (from €1,500):</strong> name, email, company, current team and process details. Required to design and implement the agreed operational framework.

<strong>eCommerce & PIM-DAM Operations (from €2,000):</strong> name, email, company, platform technical details (Magento, Shopware, Pimcore), temporary access credentials (if needed for implementation). Credentials are destroyed at engagement completion.

<strong>AI-Assisted Operations (from €2,500):</strong> name, email, company, process data and operational documentation. Used to design automations and dashboards.

<strong>Fractional Head of Ops (from €2,500/mo):</strong> name, email, company, organizational structure, financial and operational data required for the interim role.

<strong>CV download:</strong> no data collected — the download is anonymous.

<strong>ShipKit purchase (€49):</strong> name, email, billing address (via Stripe). I do not receive or store your credit card details — Stripe handles them on my behalf.

<strong>Freebie downloads (playbook):</strong> name and email address — used to deliver the PDF and send the email sequence (max 6 emails over 30 days).

<strong>Technical data:</strong> IP address, browser user-agent, and referral headers are automatically collected by the server for security and operational purposes. Not used for tracking or profiling.

<strong>Analytics:</strong> anonymous, aggregated page views using Plausible Analytics (privacy-friendly, no cookies). No personal tracking, no fingerprinting.

3. How I Use Your Data

Each data point is used exclusively for its stated purpose:

• Contact inquiries: to respond and prepare proposals.

• Consulting services (Audit, Delivery, eCommerce, AI Ops, Fractional): to deliver the agreed service, communicate during the engagement, and handle billing.

• ShipKit purchase: to process payment (via Stripe) and deliver the product.

• Playbook download: to send the PDF and associated educational email sequence.

• Technical data and analytics: to improve the site and detect technical issues.

I do <strong>not</strong> sell, rent, trade, or share your personal data with any third party for their marketing purposes. Your data is never used to train AI models.

4. Email Marketing (Consent, Double Opt-In & Unsubscribe)

When you download the free playbook, you may opt in (via a dedicated checkbox) to receive a 6-email educational sequence over approximately 30 days. After submitting the form, you will receive a confirmation email asking you to verify your address (double opt-in). You will start receiving the sequence only after confirming.

Each email includes an unsubscribe link. You can withdraw consent at any time — your request is processed immediately and you will receive no further emails. Unsubscribing does not affect communications related to active consulting engagements.

5. Legal Basis (GDPR) & Your Right to Object

I process your data based on:

<strong>Consent (Art. 6.1.a GDPR):</strong> when you check the consent box on a form (contact, playbook download, service request). You may withdraw at any time.

<strong>Contractual necessity (Art. 6.1.b GDPR):</strong> when you engage my consulting services or purchase ShipKit — processing is required to deliver the agreed work or product, including billing.

<strong>Legal obligation (Art. 6.1.c GDPR):</strong> retention of fiscal and accounting data for 10 years as required by Italian law (D.P.R. 600/73).

<strong>Legitimate interest (Art. 6.1.f GDPR):</strong> responding to pre-sales inquiries and improving my services.

<strong>Right to object (Art. 21 GDPR):</strong> where I process your data based on legitimate interest, you have the right to object at any time by contacting me. I will cease processing unless I have compelling legitimate grounds that override your interests.

6. Data Retention

Your data is retained only as long as necessary for the purpose collected:

• Contact form: deleted after 12 months from last contact.

• Operations Audit and single services: 24 months from engagement completion.

• Fractional Head of Ops (ongoing contracts): 24 months from contract end.

• ShipKit purchase: 10 years (Italian fiscal obligation).

• Playbook subscribers: until unsubscribe + 30 days grace period.

• Technical data (server logs): 30 days, then anonymized.

You may request early deletion of your data at any time by emailing [email protected]. Unless legally required (e.g., invoices), I will delete everything within 30 days.

7. Your Rights (GDPR)

You have the right to:

<strong>Access (Art. 15):</strong> request a copy of all data I hold about you.

<strong>Rectification (Art. 16):</strong> correct inaccurate or incomplete data.

<strong>Erasure (Art. 17):</strong> obtain deletion of your data (subject to legal retention requirements).

<strong>Restriction (Art. 18):</strong> restrict processing in certain cases.

<strong>Portability (Art. 20):</strong> receive your data in a structured, machine-readable format.

<strong>Object (Art. 21):</strong> object to processing based on legitimate interest.

<strong>Withdraw consent:</strong> at any time, without affecting the lawfulness of prior processing.

To exercise any right, email [email protected]. I will respond within 30 days (Art. 12 GDPR). If the request is complex, I will inform you within 30 days and may extend the deadline by up to 60 additional days.

8. Third-Party Processors

I use the following third-party services to operate this site and deliver services. Each has been verified for GDPR compliance. Data is processed within the EU and US (under Standard Contractual Clauses):

<strong>Resend</strong> (resend.com) — transactional email delivery, automated email sequences, and notifications. Privacy: resend.com/privacy — DPO: [email protected]

<strong>Netlify</strong> (netlify.com) — website hosting, CDN, and deployment. Privacy: netlify.com/privacy — DPO: [email protected]

<strong>GitHub</strong> (github.com) — source code hosting and authentication. Privacy: github.com/privacy

<strong>Stripe</strong> (stripe.com) — payment processing for ShipKit purchases. Stripe is PCI DSS Level 1 certified. Privacy: stripe.com/privacy — DPO: [email protected]

<strong>Vercel</strong> (vercel.com) — deployment preview and serverless functions. Privacy: vercel.com/privacy

<strong>Plausible Analytics</strong> (plausible.io) — privacy-friendly analytics without cookies. Data is anonymized server-side. Privacy: plausible.io/privacy

9. International Transfers

Some of my service providers (Stripe, GitHub, Resend) may transfer data to the United States. These transfers rely on Standard Contractual Clauses (SCC) approved by the European Commission (Implementing Decision 2021/914), which ensure a level of protection equivalent to the GDPR. You may request a copy of the applicable SCC by emailing [email protected].

10. Data Security

I implement appropriate technical and organizational measures: encrypted connections (HTTPS/TLS 1.3), access controls on databases, data minimization principle, and periodic security reviews. Temporary access credentials for client platform interventions are destroyed upon engagement completion. No data transmission over the internet is 100% secure, but I follow industry best practices to minimize risk.

11. Cookies

This website uses only:

• Technical cookies: required for site functionality (no consent required).

• Analytics cookies: Plausible Analytics does not use cookies — data is anonymized server-side.

No profiling, advertising, or cross-site tracking cookies are used. You can manage preferences via the cookie banner displayed on your first visit.

12. Job Application Data

If you contact me regarding a job position (Head of Operations, Delivery Manager, Senior PM, etc.), the data you share (CV, portfolio, references) is used exclusively to evaluate your application and, if applicable, for the selection process. Data of non-selected candidates is deleted after 12 months.

13. Limitation of Liability

Consulting services are provided with the professional diligence required by the PMP® Code of Ethics. However, results (e.g., time-to-market reduction, productivity gains) depend on external factors beyond my control (team cooperation, market conditions, technological constraints). Audit reports and recommendations provided are professional opinions based on facts at the time of analysis, not contractual guarantees of outcome.

14. Changes to This Policy

I may update this privacy policy periodically to reflect regulatory changes, new services, or process modifications. Material changes will be communicated via email if I have your active contact, or via a notice on this website. The &ldquo;Last updated&rdquo; date at the top of this page reflects the most recent revision.

15. Complaints

For any questions, requests, or complaints:

Riccardo Bozzato

Legnaro, PD, Italy

Email: [email protected]

Phone: +39 389 213 9542

If you believe the processing violates the GDPR, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) at garanteprivacy.it — Piazza Venezia 11, 00187 Rome.

Questions?

Email: [email protected]