Skip to content
MTF Srl — Making The Future

privacy

Privacy Policy

Version: 1.0 · Effective date: September 2, 2026

With this document MTF Srl, as Data Controller, informs users of the website www.mtf-srl.com about the purposes and methods of processing personal data and about the rights granted by Regulation (EU) 2016/679 (“GDPR”). This notice covers processing carried out through this website: processing related to contracts, service delivery and support activities is covered by separate notices provided when the data is collected.

1. Data Controller

MTF Srl

  • Registered office: Via Tempio del Cielo, 3 — 00144 Rome (RM), Italy
  • VAT / Tax code: 03042700124
  • Phone: +39 06 6385048 — Fax: +39 06 66410392
  • Email: info@mtf-srl.com

Operating offices: Rome (Via Tempio del Cielo, 3 — 00144), Milan (Via Tadino, 42 — 20124), Vasto (Via L. Cardone, 16 — 66054).

For any matter concerning the processing of personal data, including the exercise of the rights described in section 8, the contact channel is info@mtf-srl.com.

2. Personal data processed

2.1 Data provided voluntarily

Through the contact form available on the website, or by writing directly to the published email addresses, the user provides:

  • first and last name;
  • company (optional);
  • email address;
  • phone number (optional);
  • solution or service of interest (selection field, optional);
  • the free text of the message.

Providing data is optional, but failure to provide the data marked as required prevents MTF from responding to the request.

2.2 Data collected automatically when the form is submitted

Along with the form, some technical and provenance data is transmitted:

  • the URL of the page from which the form was submitted and the referring page;
  • any campaign parameters present in the page address (utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid, fbclid);
  • the IP address from which the submission originated.

The IP address is stored together with the request in the temporary queue described in section 4 and is used to limit repeated submissions from the same address, protecting the form from automated abuse.

2.3 Infrastructure operation data

The hosting provider processes, for security and service continuity purposes, the technical data inherent to every connection to a website (IP address, date and time of the request, requested resource, browser type). MTF does not use this data to identify users.

2.4 Resources loaded from third parties

For typography, the website loads the Inter typeface from the rsms.me service. When the browser requests that resource, the server hosting it receives the visitor’s IP address and the technical data inherent to the connection. The service does not install cookies and MTF receives no data from that request.

2.5 No profiling and no analytics tools

The website does not install cookies, does not use traffic analytics systems, does not employ profiling or remarketing cookies and does not embed social network plugins. No automated decision-making, including profiling, is carried out pursuant to Article 22 GDPR. See the Cookie Policy.

PurposeLegal basis
Responding to requests sent through the contact form or by email, and possibly issuing a quotationArt. 6.1.b GDPR — pre-contractual measures taken at the request of the data subject
Understanding which channel the request came from (referrer and campaign parameters)Art. 6.1.f GDPR — legitimate interest of the Controller in assessing the effectiveness of its communication channels
Protecting the contact form from automated submissions and abuse, through a per-IP submission limitArt. 6.1.f GDPR — legitimate interest of the Controller in the security of its systems
Compliance with legal obligations, where the contact leads to a contractual relationshipArt. 6.1.c GDPR — legal obligation

The website carries out no processing for direct marketing purposes: no newsletters are active, no promotional communications are sent to those who simply contact MTF through the website, and no consent is collected for that purpose.

4. Retention period

DataPeriod
Copy of the request in the intermediate technical queueMaximum 7 days, automatically deleted
Per-IP submission counter (anti-abuse)1 hour, automatically deleted
Request received by email and imported into MTF’s internal management systemFor the time needed to handle the request; if the contact leads to a contractual relationship, for the duration of the relationship and the terms required by law

5. Recipients of the data

Data is processed by authorised MTF personnel (sales, technical and administrative functions) and may be processed, as data processors pursuant to Article 28 GDPR, by the technical service providers MTF relies on to operate the website and the contact form:

  • Cloudflare, Inc. — website publishing, execution of the serverless function that receives the form, and temporary technical queue of requests;
  • Resend — delivery of the notification email to MTF addresses.

The request is then imported into MTF’s internal management system, hosted on MTF infrastructure and accessible only to authorised personnel.

Data is not disseminated or transferred to third parties for their own purposes. It may be disclosed to judicial or other competent authorities in the cases provided for by law.

6. Transfers to third countries

The providers listed in section 5 are companies based in the United States of America and may process data outside the European Economic Area. Transfers take place on the basis of the safeguards provided for in Chapter V of the GDPR (Articles 44 et seq.) adopted by the respective providers. Data subjects may request information about the safeguards applied by writing to info@mtf-srl.com.

7. Processing methods and security

Processing is carried out using electronic tools, with logic strictly related to the stated purposes. MTF adopts appropriate technical and organisational measures, including:

  • encrypted transmission (HTTPS/TLS) of all website pages and of the endpoint that receives the contact form;
  • access to data restricted to authorised personnel;
  • automatic deletion of the intermediate technical queue within 7 days;
  • protections against automated and repeated form submissions.

8. Rights of the data subject

Under the conditions set out in the GDPR, data subjects may exercise the rights granted by Articles 15 to 22, in particular:

  • right of access (Art. 15): to obtain confirmation as to whether personal data concerning them is being processed and to access that data;
  • right to rectification (Art. 16): to obtain correction of inaccurate data and completion of incomplete data;
  • right to erasure (Art. 17): to obtain the deletion of data, except where processing is necessary to comply with a legal obligation or for the establishment, exercise or defence of legal claims;
  • right to restriction (Art. 18): to obtain restriction of processing in the cases provided for by law;
  • right to data portability (Art. 20): to receive, in a structured, commonly used and machine-readable format, the data provided to the Controller, and to transmit it to another controller;
  • right to object (Art. 21): to object at any time to processing based on legitimate interest;
  • right not to be subject to automated decision-making (Art. 22);
  • right to withdraw consent, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.

Rights may be exercised by writing to info@mtf-srl.com, indicating “GDPR Request” in the subject line. Exercising these rights is free of charge pursuant to Article 12 GDPR; in the case of manifestly unfounded or excessive requests, including because of their repetitive character, the Controller may charge a reasonable fee or refuse to act on the request. The Controller may request further information necessary to confirm the identity of the requester.

Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority — Garante per la protezione dei dati personali (www.garanteprivacy.it).

9. Minors

The website is not directed at minors and MTF does not knowingly collect data from minors through the contact form.

10. Updates

This notice may be updated to reflect changes to the website, to the services used or to the regulatory framework. The version and effective date are shown at the top of this page.