Privacy Policy

How we process personal data.

Information provided under Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”).

Controller: HODL Capital SRL

Registered office: Via Empedocle 28A, 95030 Pedara (CT), Italy

VAT: IT05839430872 · REA CT–438763

Privacy contact: contact form

Last updated: 2 September 2026

1. Scope

This policy applies to visitors, people sending an enquiry through the form and contacts involved in the evaluation or management of a B2B professional relationship with HODL Capital.

2. Data processed

  • Navigation data: IP address, date and time, requested page, user agent, technical outcomes and security data generated by the server.
  • Contact data: name, role, company, email address and information contained in messages.
  • B2B relationship data: information required for proposals, contracts, project delivery, administration and compliance.
  • Cookie preferences: choices stored through the consent-management tool.

3. Purposes and legal bases

  • Responding to requests and taking requested pre-contractual steps: steps prior to entering into a contract.
  • Delivering a contract and managing customer or supplier relationships: performance of a contract.
  • Meeting administrative, tax and legal requirements: legal obligation.
  • Protecting the website, systems and company rights and preventing abuse: legitimate interests in security and protection.
  • Using optional non-essential technologies, if introduced: consent, which can be withdrawn at any time.

4. Providing data

Necessary technical data are processed to operate and secure the website. Providing information in the form is optional, but fields marked as required are needed to send and handle the enquiry.

5. Processing and recipients

Data are processed using appropriate organisational and technical measures by authorised people and providers supporting hosting, message delivery, email, security, consent management and professional services. The website configuration uses Vercel for hosting and the contact function, Resend for message delivery, DreamHost for the destination mailbox and CookieScript for cookie preferences.

Data may also be disclosed to professional advisers, authorities or other parties where required by law or necessary to protect rights. We do not sell personal data, and submitting the form does not subscribe the sender to marketing communications.

6. Transfers outside the EEA

Some providers may process data outside the European Economic Area. Where this occurs, transfers follow the GDPR mechanisms applicable to the provider and processing, such as adequacy decisions or Standard Contractual Clauses where required.

7. Retention

  • Enquiries not resulting in a relationship are normally retained for up to 24 months after the last contact, unless needed to protect rights.
  • Contractual, administrative and tax data are retained for statutory periods and the protection of rights.
  • Technical logs are retained for the period necessary for security, diagnosis and abuse prevention, according to provider settings.
  • Cookie preferences remain stored for the period stated in the Cookie Policy or until changed.

8. Rights

Where provided by the GDPR, individuals may request access, rectification, erasure, restriction, portability, objection and withdrawal of consent. Withdrawal does not affect processing carried out beforehand.

Requests may be submitted through the contact form using the privacy topic. Individuals may also complain to the Italian Data Protection Authority or their competent EEA supervisory authority.

9. Automated decisions

The website does not make solely automated decisions producing legal or similarly significant effects on visitors.

10. Updates

This policy may change when services, providers or processing activities change. The applicable version is the one published here with its update date.

Publication note: this text describes the planned website configuration and must be checked against the effective provider contracts and settings before the production-domain launch.