Privacy Policy

Last updated: 22 January 2026

This document informs users, in accordance with Article 13 of Regulation (EU) 2016/679 (‘GDPR’), about the processing of personal data collected and/or provided by them through the website www.kitra-advisory.com (the ‘Website’).

Users’ personal data will be processed in compliance with applicable privacy and personal data protection legislation and provisions. Users are therefore invited to read this Privacy Policy carefully before providing their personal data and using Kitra’s Website.

  1. Data Controller and Data Protection Officers

The Data Controller is Kitra Advisory S.p.A., with registered office at Corso Europa 16, 20122 Milan, Italy. The company’s VAT number is 12868850962 (‘Kitra’). Users may contact Kitra at any time by sending an email to privacy@kitra-advisory.com.

The Data Controller has appointed a Data Protection Officer (DPO) who is responsible for supervising data processing practices and ensuring compliance with the GDPR. The DPO can be contacted by emailing dpokitra@kitra-advisory.com.

  1. Purpose and Legal Basis of Data Processing

Browsing the website is free of charge. Kitra may use and/or collect users’ personal data for the purposes and according to the legal bases set out below.

Processing Necessary for Providing Services Through The Website or Taking Pre-contractual Steps at User’s Request.

The Data Controller will process the data for the following purposes:

  •  to enable users to browse and use the services available on the website;
  • to enable users to send and respond to requests for information about Kitra’s services;
  • to manage applications for job positions at Kitra sent via the website based on additional information provided.

The legal basis for such processing is the implementation of per-contractual measures at data subject’s request (Art. 6(1)(b) of the General Data Protection Regulation, or ‘GDPR’).

N.B. During the recruitment and selection process, the Data Controller does not usually require special categories of personal data, also known as Sensitive Data. Therefore, please only include the data necessary for evaluating your profile in your CV, and refrain from including sensitive data unless you believe it is necessary for a better understanding of the position, particularly in relation to membership of protected categories. If you do include such data, you must give your consent by adding the following statement to the bottom of your CV: ‘Having read the privacy policy of Kitra Advisory S.p.A., I hereby consent to the processing of my special category data for the selection purposes indicated therein.’ This consent is necessary in order to recognise the resulting legal benefits for those belonging to protected categories, and without it, the application cannot be evaluated and the information will be deleted immediately.

  1. Compliance with Legal and Regulatory Obligations

Based on Kitra’s legal and/or regulatory obligations, the user’s personal data may be processed for the following purposes:

  • to comply with legal obligations or, upon request, any orders from the relevant authorities.
  • informing or responding to any requests from the relevant authorities to ascertain liability in the event of damage to the website, as well as preventing crimes;
  • to fulfill any accounting, tax and administrative obligations related to the sale of services offered through the website.

The legal basis for this processing is that it is necessary to fulfill a legal obligation to which the Data Controller is subject to (Article 6(1)(c) of the General Data Protection Regulation (GDPR)).

  1. Pursuit of the Legitimate Interests of the Data Controller

In line with Kitra’s legitimate interests and the need to improve and protect the website, user personal data may be processed for the following purposes:

  • prevent any kind of fraud from being committed through the website.
  • allow Kitra to ascertain, exercise or defend its rights in pre-litigation or litigation proceedings.
  • improve the services offered and/or provided through the Website.

The legal basis for the aforementioned processing is the Data Controller’s legitimate interest in administering and protecting the integrity of the website (Article 6(1)(f) of the General Data Protection Regulation (GDPR)).

  1. Categories of Data Subject to Processing

Kitra may request and/or access the following categories of personal data when users use the website.

  • Identification and contact details may include name, surname, address, place and date of birth, email address, certified email address, telephone number, etc. If users are acting on behalf of their company or for professional purposes, data relating to their work and company/professional contact details may also be processed. If users are interested in collaborating with Kitra, information relating to their professional experience may also be processed if they voluntarily provide it.
  • Technical and Navigation Data: During normal operation, the IT systems and software procedures used to operate the website may acquire some personal data whose transmission is implicit in the use of internet communication protocols. This category includes IP addresses, the domain names used by users when browsing the website, URI/URL addresses, the pages visited, the actions performed, the resources requested, the time of the request and the method used to submit the request to the server.
  • Personal Data Collected through Cookies or Similar Technologies: This website uses cookies, web beacons, unique identifiers and other similar technologies to collect personal data relating to the pages visited and other actions performed by users on this website. For more information, please refer to the Cookie Policy, which can be accessed by clicking here: www.kitra-advisory.com/cookie-policy/.
  1. Mandatory Provision of User’s Personal Data

Users are not required to provide their personal data. With the exception of strictly functional ones, data processed through cookies and/or similar tracking technologies are collected only with users’ consent. For more information, please refer to the following link: Cookie Policy of www.kitra-advisory.com.

However, failure to provide such data, or providing partial or inaccurate data, may prevent users from sending requests and/or submitting applications to us.

  1. Data Communication

Kitra may disclose users’ personal data to entities belonging to the following categories:

  • Providers of services accessible through the Site (e.g. external recruitment agencies).
    Providers who provide maintenance and support services for the Site on behalf of Kitra.
  • Freelancers, professional firms or associations appointed to defend and/or protect Kitra’s interests, including in pre-litigation or other proceedings.
  • Public security authorities, judicial authorities and other entities or bodies to which users’ personal data must be communicated pursuant to legal provisions or orders from the relevant authorities.

The communicated data will only concern information necessary for the purposes for which it was provided or collected. Users can request an updated list of these purposes by emailing privacy@kitra-advisory.com.

  1. Transfer of Data Abroad

Kitra may transfer data collected through the website within the European Union to comply with legal, regulatory or European Union requirements. Personal data processed by Kitra is stored by its hosting service provider, Aruba, whose servers are located in Italy.

Kitra does not normally transfer data processed through the website to countries outside the EU. However, if it shall be necessary to transfer your personal data to countries outside the EU/EEA, such transfers will only take place to countries with an Adequacy Decision approved by the European Commission. If there is no such decision, transfers will be made on the basis of Standard Contractual Clauses provided by the European Commission, along with additional security measures to ensure data security.

  1. Personal Data’s Retention Period

Personal data will be retained for as long as is necessary to fulfill the purposes for which it was collected, provided or subsequently processed, and in compliance with applicable legal and regulatory obligations. In particular:

  • if users exercise their right to erasure, data may be stored securely with limited access for a period not exceeding 12 months from the date of the request, where necessary for the purposes of investigating and prosecuting crimes. After this period, the data will be erased or anonymised unless there is another legal basis for processing it.

At the end of the retention period, personal data will be deleted and/or anonymised irreversibly within 30 days, subject to Kitra’s need to protect its rights in the court of jurisdiction  courts (which may require further retention of users’ personal data).

  1. Users’ Rights

Users may request clarification or exercise their rights under Articles 15 et seq. of GDPR at any time. In particular, users have the right to:

  1. Withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
  2. Object to the processing of their personal data.
  3. Access their personal data by asking Kitra to confirm the processing carried out and to provide a copy of the personal data held by Kitra via email.
  4. Verify and request the rectification of your personal data if the data held by Kitra is incorrect (for example, if it differs from the data provided when registering on the website) or incomplete.
  5. Obtain the restriction of processing in cases provided for by law.
  6. Obtain the erasure of their personal data, entirely or in part.
  7. Users can request the transfer of their personal data in a structured, commonly used and machine-readable format, or request that it be transferred to another data controller.
  8. Without prejudice to any other administrative or judicial remedy, users should lodge a complaint with the Data Protection Authority if they believe that Kitra’s processing of personal data is in conflict with or violates current legislation. Further information can be found on the website www.garanteprivacy.it.

To exercise their rights, users may address their requests to the contacts indicated in Article 1 above.

  1. Other Web Sites

The website may contain links to third-party services, websites, applications and/or platforms, either via specific links or other connection methods (e.g. APIs) made available through the website itself. Accessing and consulting such websites, services, applications or platforms falls outside the scope of Kitra’s activities, controls and/or security measures adopted to protect users’ personal data. In such cases, Kitra shall not held responsible for the processing of data carried out by the operators of these sites and/or applications. Users are therefore invited to carefully read the terms of use and privacy policies prepared by such parties, in order to understand how they process personal data.

  1. Updates

Kitra may amend this Privacy Policy if necessary, for example, in relation to any changes to the products and services provided on the Website, or to enable Kitra to comply with changes in legislation on personal data protection or instructions from the relevant authorities. Users are therefore invited to periodically consult this page to learn about the processing activities carried out by Kitra.

Each new version of the Privacy Policy will be published on the website and communicated to users by email or any other method Kitra will deem as appropriate.