Legal information

Legal notice,privacy and cookies.

Last updated: 09 · 08 · 2026

I

Legal notice

In compliance with Regulation (EU) 2016/679 (GDPR), Italian Legislative Decree No. 196/2003 as amended by Legislative Decree 101/2018 (Codice Privacy) and Legislative Decree No. 70/2003 on information society services, the user is informed of the identifying details of the owner of the site www.avvocato-canonico.com:

Company name
I.P.A.C. - S.R.L.S. — Avvocato Canonico (Canon Law Counsel)
Registered office province
ROMA
Fiscal code
15402041006
VAT number
15402041006
REA number
1588137
Registered office
Palazzo Valadier Piazza del Popolo 18 00187 Roma, Italia
Contact
contacto@avvocato-canonico.com
WhatsApp +39 380 658 0687
Activity
Counsel and consultancy in Canon Law and specialised training.

Access to and use of this website confers the status of user and implies full acceptance of these terms. The owner reserves the right to modify the content of the site without prior notice.

Intellectual and industrial property. All the content of the site (texts, images, logos, source code, graphic design) is owned by the provider or by third parties who have authorised its use, and is protected by Legge n. 633/1941 on copyright and by the applicable international regulations. Any reproduction, distribution or transformation without express authorisation is prohibited.

Applicable law and jurisdiction. These terms are governed by Italian law and European Union law. In the event of any dispute, the parties submit to the competent forum of the consumer user's domicile.

Hosting and place of provision. The site is hosted on servers located in Italy (European Union) and the entire online advisory service is provided from Italy, even though it is also addressed to users in North America, Central America, South America and various European countries.

Canonical professional secrecy. All communication maintained with the firm, as well as the documentation submitted, is covered by professional secrecy and by the confidentiality proper to ecclesiastical matters.

II

Privacy policy (GDPR)

In accordance with Regulation (EU) 2016/679 (GDPR) and the Italian implementing legislation (Legislative Decree 196/2003 and Legislative Decree 101/2018), we inform you of the processing of personal data carried out through this site.

  • Data controller: I.P.A.C. - S.R.L.S. (Avvocato Canonico), with the contact details indicated in the legal notice.
  • Purposes: (i) responding to enquiries and requests for information sent by form, email or WhatsApp; (ii) providing the canon law advisory services contracted, including the single consultation and the monthly subscription; (iii) managing the subscribers' area, enrolment in training courses and invoicing; (iv) complying with applicable legal obligations.
  • Legal basis: the consent of the data subject (Art. 6(1)(a) GDPR), the performance of a contract or pre-contractual measures (Art. 6(1)(b)) and compliance with legal, tax and accounting obligations (Art. 6(1)(c)).
  • Retention: the data will be retained for as long as the relationship is maintained and, subsequently, for the periods legally required to address any liabilities and tax obligations.
  • Recipients: no data is disclosed to third parties except where legally required. There are data processors (hosting providers, email, technical tools and the Stripe payment gateway) contractually bound by the GDPR.
  • International transfers: where applicable, these will only be carried out with providers offering adequate safeguards in accordance with Chapter V of the GDPR.
  • Payment data: card details are entered and processed directly in the secure environment of the payment gateway; the site owner never stores card numbers.

III

Cookie policy

This Cookie Policy governs the use of cookies and equivalent technologies (pixels, local storage, SDKs, tags, fingerprinting) on www.avvocato-canonico.com, in accordance with Regulation (EU) 2016/679 (GDPR), Directive 2002/58/EC (ePrivacy), Legislative Decree 196/2003 (Codice Privacy) and the current guidelines of the Garante per la protezione dei dati personali and the European Data Protection Board (EDPB).

3.1 — What is a cookie?

A cookie is a small data file that is downloaded onto the user's terminal equipment when accessing certain web pages and that allows information about browsing or the device to be stored and retrieved. Other technologies for storing or accessing information on the terminal fall under the same legal category.

3.2 — Types

According to the entity managing them: first-party (sent from a domain managed by the site owner) and third-party (sent from a domain managed by another entity that processes the data obtained).

According to their duration: session cookies (deleted when the browser is closed) and persistent cookies (remain stored for a defined period).

According to their purpose: technical or strictly necessary cookies (exempt from consent), preference or personalisation cookies, analytics or measurement cookies and advertising or behavioural advertising cookies.

3.3 — Cookies used on this site

NameOwnerPurposeTypeDuration
lang_prefFirst-partyRemember the selected language.Technical / preference1 year
cookie_consentFirst-partyStore the user's decision on the cookie banner.Technical6 months
sb-*-auth-tokenFirst-partyKeep the session logged in within the subscribers' area.TechnicalSession / 1 year
__stripe_mid / __stripe_sidStripe (third-party)Fraud prevention for card payments.Technical1 year / 30 minutes
__cf_bmCloudflare (third-party)Security and bot mitigation.Technical30 minutes

Note. This site does not currently use analytics, advertising or profiling cookies. Should any be incorporated in the future, this policy will be updated and prior consent will be requested via the corresponding banner.

3.4 — Legal basis and consent

Strictly necessary technical cookies are installed on the basis of Art. 122 of Legislative Decree 196/2003 and Art. 5(3) of the ePrivacy Directive (consent exemption). Any other cookie requires the user's prior, free, specific, informed and unambiguous consent, given through a clear affirmative action. Consent may be withdrawn at any time as easily as it was given.

Where applicable, the banner offers, at the first level and with equal visual prominence, the options "Accept", "Reject" and "Settings", in accordance with the Garante's cookie guidelines (Linee guida cookie, 10 June 2021) and EDPB guidance; no dark patterns, pre-ticked boxes or cookie walls are used.

3.5 — International transfers

Where any third-party cookie involves a transfer of personal data outside the European Economic Area, this will only be carried out with providers offering adequate safeguards in accordance with Chapter V of the GDPR (adequacy decisions, standard contractual clauses or binding corporate rules).

3.6 — Management and withdrawal

The user may allow, block or delete the installed cookies through the settings options of their browser (Chrome, Firefox, Safari, Edge). Disabling technical cookies may prevent certain sections of the site from working properly, in particular the subscribers' area and the payment process.

3.7 — Retention and updates

Cookies are retained for the periods indicated in the table. Consent will be requested again at most every 6 months, in accordance with the Garante's guidelines, or earlier if new purposes are incorporated. This Policy may be updated to adapt to regulatory or technical changes.

IV

International scope and applicable data protection regulations

The service is provided entirely from Italy by an Italian company and the site is hosted on servers located in Italian territory (European Union). However, the service is also addressed to users in North America, Central America, South America and various European countries. For this reason, the owner uniformly applies the highest standard of protection —that of Regulation (EU) 2016/679 (GDPR)— to all users, regardless of their country of residence, while additionally respecting the rights recognised by local legislation where applicable.

In particular, and without limitation, the following regulations are taken into account where applicable to the user:

  • European Union and EEA: Regulation (EU) 2016/679 (GDPR), Directive 2002/58/EC (ePrivacy) and, in Italy, Legislative Decree 196/2003 as amended by Legislative Decree 101/2018. United Kingdom: UK GDPR and the Data Protection Act 2018. Switzerland: nLPD/FADP.
  • United States: the CCPA/CPRA of California and equivalent state laws (Virginia, Colorado, Connecticut, Utah, Texas and others), including the rights to know, access, correct, delete and limit the use of sensitive personal information, as well as the right to opt out of the sale or sharing of data. The owner does not sell or share personal data.
  • Canada: PIPEDA and equivalent provincial laws (including Quebec's Law 25).
  • Mexico and Central America: the Mexican LFPDPPP and its Regulations (ARCO rights), as well as the national data protection laws of Costa Rica, Panama, Nicaragua, Honduras, Guatemala, El Salvador and the Dominican Republic.
  • South America: Brazil (LGPD, Lei 13.709/2018), Argentina (Law 25,326), Chile (Law 19,628 and its reform), Colombia (Law 1581/2012 and Decree 1377/2013), Peru (Law 29733), Uruguay (Law 18,331), Ecuador (LOPDP), Paraguay and Bolivia.

International transfers. Data is processed and stored principally in the European Union. Where the provision of the service requires a transfer outside the EEA (for example, to serve a user in the Americas), this is carried out under Chapter V of the GDPR: European Commission adequacy decisions, standard contractual clauses (SCCs) with supplementary measures, or the explicit and informed consent of the data subject. Users from countries whose regulations require specific authorisation or consent for the international transfer expressly give it when contracting the service.

Minors. The services are addressed exclusively to adults. Data of minors under 16 (or the minimum age set by local law) is not knowingly collected; if detected, it will be deleted without delay.

Security. Appropriate technical and organisational measures are applied in accordance with Art. 32 GDPR: encryption in transit (TLS), access control by authenticated user, data minimisation, access logging, backups and staff confidentiality undertakings. In the event of a personal data breach, the competent authority and, where appropriate, the data subjects, will be notified within the legally established time limits.

V

Electronic contracting and consumer rights

The single consultation, monthly subscription and training services are contracted remotely by electronic means. The contract is concluded in Italy and is governed by Legislative Decree 206/2005 (Codice del Consumo), Legislative Decree 70/2003 and Directive 2011/83/EU on consumer rights.

  • Prices and taxes: prices are shown in the selected currency including applicable taxes. Transactions subject to Italian VAT are invoiced at 22%; supplies to customers outside the European Union and those subject to the reverse charge mechanism are invoiced without Italian VAT, with the corresponding legal notation.
  • Right of withdrawal: the consumer has 14 calendar days to withdraw without giving any reason, by notifying contacto@avvocato-canonico.com. If the consumer expressly requests that provision of the service begin before that period elapses, they acknowledge that they will lose the right of withdrawal once the service has been fully performed, and that they must pay the proportional part already provided if they withdraw during its performance.
  • Subscriptions: the subscription renews automatically each month by charging the card provided, until the subscriber cancels it. Cancellation may be requested at any time from the subscribers' area or by email, and takes effect at the end of the period already invoiced. Annual commitments and the terms of the trial month are expressly disclosed before contracting.
  • Payments: payments are processed through a PCI-DSS certified gateway. The owner does not access or store complete card data.
  • Complaints and dispute resolution: complaints may be addressed to contacto@avvocato-canonico.com. Consumers resident in the European Union may resort to the alternative dispute resolution mechanisms provided for by their national legislation. Consumers resident outside the EU retain the mandatory rights recognised by the legislation of their habitual country of residence, which are not affected by the choice of Italian law.
  • Nature of the service: the advice is provided exclusively in matters of Canon Law and does not constitute advice on the civil, criminal or administrative law of States. No particular outcome is guaranteed in proceedings before the ecclesiastical authority.

VI

User rights and complaints

The data subject may exercise at any time the rights of access, rectification, erasure, objection, restriction of processing and portability, as well as withdraw any consent given, by writing to dpi@avvocato-canonico.com and proving their identity. The request is dealt with free of charge within a maximum period of one month (or the shorter period imposed by local law), without any discrimination for having exercised these rights.

Regardless of country of residence, the owner recognises for all users the equivalent rights provided for by their local legislation: ARCO rights (Mexico and Latin America), the rights of confirmation, access, correction, anonymisation, portability and withdrawal of consent (Brazilian LGPD), and the rights to know, delete, correct, limit the use of sensitive data and opt out of the sale or sharing of data (CCPA/CPRA and US state laws). The owner does not sell or share personal data nor carry out profiling with legal effects.

The data subject also has the right to lodge a complaint with the competent supervisory authority: in Italy, the Garante per la protezione dei dati personali, headquartered at Piazza Venezia 11, 00187 Rome, whenever they consider that the processing does not comply with the applicable regulations.

Users resident outside Italy may equally address their national supervisory authority —among others, the ANPD (Brazil), the AAIP (Argentina), the INAI (Mexico), the SIC (Colombia), the relevant Data Protection Agency in Chile, Peru, Uruguay or Ecuador, the Privacy Commissioner of Canada, or the relevant state Attorney General in the United States— without prejudice to the competence of the Italian Garante as the controller's lead authority.