Privacy Notice on the processing of personal data
Version 2026-10-v1 — Courtesy translation: in case of discrepancy, the Italian version prevails.
Introduction
This notice describes how Blackstone Advisor processes the personal data of users who visit blackstoneadvisor.it, use the Client Area, request professional services, book meetings, use Blackstone Tax AI, subscribe to informational communications or interact with the other digital services available on the site.
The notice is provided pursuant to Articles 13 and, where applicable, 14 of Regulation (EU) 2016/679 ("GDPR") and the applicable national legislation.
1. Data Controller
The Data Controller is: Dott. Daniele Alberto Zanella, operante professionalmente con il brand Blackstone Advisor (Dr. Daniele Alberto Zanella, practising professionally under the Blackstone Advisor brand). Registered office: Piazza Castello n. 21 — 20121 Milano (MI), Italia. Tax code / VAT no.: IT06367370969. Privacy e-mail: segreteria@blackstoneadvisor.it. Certified e-mail (PEC): d.zanella@legalmail.it.
For any matter concerning the protection of personal data or to exercise the rights provided for by the GDPR, you may contact the Controller at the above details.
2. Categories of data processed
Browsing and technical data: technical data required for the operation, security and management of the site and digital services, such as IP address, browser and device information, technical identifiers, access logs and session data.
Identification and contact data: first name, surname, e-mail address, telephone number and other data voluntarily provided by the user.
Account data: account credentials and identifiers, language preferences, information relating to registration, authentication, suspension or archiving of the account. Passwords are never stored in clear text.
Professional, corporate, tax and financial data: in the context of the services requested, information relating to professional or business activity, companies, transactions, economic, tax, financial and asset position and any further information necessary for the requested service may be processed.
Documents: Client Area users may upload or receive documents connected to professional, administrative and tax services. Such documents may contain personal, corporate, economic, tax or financial data.
Requests and appointments data: the information entered in contact requests, service requests, meeting bookings and subsequent communications with the Firm.
Payment data: Blackstone Advisor may retain information such as amount, description, payment status, transaction identifier and references needed for reconciliation. Full payment card data is not acquired or stored directly by Blackstone Advisor when payment is made through the external payment system used by the site.
Blackstone Tax AI data: the content of questions, information provided during the interaction, conversation history, generated assessments and the technical identifiers needed to manage the session. Users are invited not to enter unnecessary personal data, third-party data, credentials, special-category data or other confidential information unless strictly necessary for the request.
Informational communications data: in case of voluntary subscription to newsletters or informational communications, the e-mail address, consent status and information needed to manage subscription and unsubscription may be processed.
3. Purposes and legal bases
Handling of requests and contacts — to respond to requests made by the user, organise meetings and provide information on the requested services. Legal basis: performance of pre-contractual measures taken at the data subject's request and, where applicable, the Controller's legitimate interest in handling the requests received.
Registration and management of the Client Area — to create and administer the account, authenticate the user, allow access to reserved services and manage documents, requests, appointments and services associated with the account. Legal basis: performance of the contract or of pre-contractual measures requested by the data subject.
Provision of professional services — to manage engagements, professional requests, documentation and activities connected to advisory services. Legal basis: performance of the contract and pre-contractual measures, compliance with legal obligations and, where applicable, pursuit of legitimate interests connected to the protection of the rights of the Controller and the client. Professional activities may also be subject to specific regulatory and ethical obligations.
Payments — to enable payment for services, verify their outcome, manage administrative reconciliation and comply with accounting and tax obligations. Legal basis: performance of the contract and compliance with legal obligations.
Security and abuse prevention — to protect accounts, systems, documents and infrastructure, prevent unauthorised access, fraud and unlawful use, and reconstruct any security incidents. Legal basis: the Controller's legitimate interest in the security of its systems and services and, where applicable, compliance with legal obligations.
Blackstone Tax AI — to allow the user to obtain a preliminary analysis of the matters submitted to the system, maintain session continuity and, where provided, enable subsequent professional follow-up. Legal basis: performance of the service requested by the user and the related pre-contractual or contractual measures. Use of Blackstone Tax AI is also governed by the specific notice and terms dedicated to the service.
Newsletter and informational communications — to send newsletters, insights, updates and other promotional or informational communications when the user has chosen to receive them. Legal basis: the data subject's consent, where required. Consent is optional and may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
4. Nature of data provision
Provision of data marked as required is essential to deliver the requested service. Failure to provide it may make it impossible to create an account, respond to a request, perform an engagement or deliver a specific service.
Provision of data for marketing or newsletter purposes is optional and refusal does not prevent use of the other services.
5. Processing methods and security
Data is processed mainly by electronic means, adopting technical and organisational measures designed to protect it from unauthorised access, loss, alteration, disclosure or unlawful use. Access to information is limited to authorised persons in relation to their respective functions.
Documents in the Client Area are managed through private storage systems and made available to authorised users through the application backend.
6. Providers and recipients
To deliver its digital services Blackstone Advisor uses technology providers that may process personal data to the extent necessary to provide their respective services. Categories of providers may include: hosting, database, authentication and object storage providers; artificial intelligence infrastructure and service providers; e-mail service providers; payment service providers; providers of research and public source acquisition services; consultants and technical providers in charge of system maintenance and security.
As of the last update, depending on the service used, the digital infrastructure may rely on Emergent (hosting, database, object storage, authentication and application infrastructure for access to AI models), OpenAI through the application infrastructure used, Perplexity, Resend and Stripe.
Perplexity is used in the current architecture for editorial research activities and is not intended to receive client file data or Blackstone Tax AI conversations.
Depending on the processing, providers may act as processors or as independent controllers for specific activities determined by them.
7. International transfers
Some technology providers may process data outside the European Economic Area. Where processing involves an international transfer subject to Chapter V of the GDPR, the transfer is carried out using one of the mechanisms provided for by applicable law, such as adequacy decisions, Standard Contractual Clauses approved by the European Commission or other legally recognised instruments.
The actual location of processing may depend on the provider and the configuration of the service used. Blackstone Advisor does not assume that the mere selection of a European endpoint or technical region necessarily entails exclusive storage of data within the European Economic Area.
8. Retention period
Data is retained for the period necessary for the purposes for which it was collected and, thereafter, for the time required or permitted by applicable law and necessary to protect the Controller's rights. Retention criteria take into account the nature of the professional relationship, civil, tax, accounting, professional and legal obligations, limitation periods and security needs.
Data relating to users who only make guest use of Blackstone Tax AI, not linked to an account, is retained for 90 days from the last activity and then deleted.
Data relating to consent to newsletters and communications is retained to document consent and any subsequent changes or withdrawals within the limits permitted by law. Technical logs are retained for the period reasonably necessary for security, error diagnosis and abuse prevention. The operational periods applicable to the different categories of data are defined and reviewed according to the above criteria.
9. Artificial intelligence
Some Blackstone Advisor services use artificial intelligence systems to support analysis, processing and content preparation activities. Such systems are support tools and do not replace, where necessary, the assessment of a professional.
Blackstone Advisor applies data minimisation criteria and invites users not to provide the system with personal information beyond what is necessary. The specific operation of Blackstone Tax AI is described in the dedicated notice and the related terms of use.
10. Automated decision-making
Unless otherwise specified in a notice relating to a particular service, Blackstone Advisor does not use users' data to make solely automated decisions that produce legal effects on the data subject or similarly significantly affect them within the meaning of Article 22 GDPR.
11. Data subject rights
In the cases provided for by the GDPR, the data subject may exercise the rights of: access to their data; rectification of inaccurate data; erasure; restriction of processing; objection to processing; data portability; withdrawal of consent, where processing is based on consent. The exercise of these rights is subject to the conditions and exceptions provided for by law, including those connected to legal and professional retention obligations.
Requests may be sent to segreteria@blackstoneadvisor.it. The data subject also has the right to lodge a complaint with the competent supervisory authority. For data subjects in Italy, the competent authority is the Garante per la protezione dei dati personali.
12. Third-party data
When the user communicates personal data relating to third parties, they must ensure that they are entitled to do so and communicate only the information necessary for the purpose pursued.
13. Minors
Blackstone Advisor's professional and digital services are not specifically intended for minors.
14. Changes to this notice
This notice may be updated to reflect regulatory, organisational or technological changes. The current version is published on the site with an indication of the version and the date of the last update.
