Privacy Policy for Viridis
Last updated: 7 June 2026This Privacy Policy explains how Viridis processes personal data when users visit the public website, submit contact or consultation requests, subscribe to the newsletter, book meetings or interact with Viridis public digital services.
The Viridis website is a public informational website. It does not require users to create an account in order to browse the website.
Viridis is committed to processing personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Italian data protection laws.
1. Who we are
For the purposes of this Privacy Policy, the data controller is:
Viridis by Dr. Serap Çevirgen
22100 Como, Italy
VAT: 04191120130
Email:
info@viridisconsultancy.com
2. Scope of this Privacy Policy
This Privacy Policy applies to the public Viridis website available at www.viridisconsultancy.com and to related public website services, including contact forms, newsletter subscription forms, consultation requests, booking flows, downloadable resources and public webinar or video pages.
This Privacy Policy does not provide the full privacy information for the EcoTrack ESG assessment application. EcoTrack has its own dedicated Privacy Policy, which explains how EcoTrack account data, assessment data, subscription data and application-related technical data are processed.
Users should review the dedicated EcoTrack Privacy Policy before creating an EcoTrack account or using the EcoTrack application.
3. Personal data we process
3.1 Website browsing and technical data
When users visit the public Viridis website, technical systems may process IP address, browser type, device information, operating system, pages visited, date and time of access, referring source, technical logs and cookie consent preferences.
3.2 Contact form data
When users contact Viridis through a contact form, Viridis may process name, email address, company name where provided, message content, source page, date and time of submission and technical anti-abuse metadata.
3.3 Newsletter data
When users subscribe to the Viridis newsletter, Viridis may process email address, first name where provided, marketing consent status, subscription date, double opt-in status, unsubscribe status, source page and technical metadata necessary to prove consent and prevent abuse.
Newsletter communications may be managed through Brevo.
3.4 Consultation request and booking data
When users request or book a consultation, Viridis may process name, email address, company name, consultation topic, selected date and time, timezone, meeting status, calendar or meeting link information and technical metadata connected with the booking process.
Booking and meeting management may involve Brevo Meetings/Appointments and, where used, calendar or video-meeting tools such as Google Calendar or Google Meet.
3.5 Downloadable resources and webinar pages
If users access downloadable resources, webinar pages or embedded video content, Viridis may process technical website data connected with the page visit. Some public pages may include third-party embedded content, such as YouTube videos.
3.6 Email and business communication data
If users communicate with Viridis by email or other business communication channels, Viridis may process sender name, contact details, email address, company or professional details, message content, attachments and communication history.
4. Purposes and legal bases
Viridis processes personal data only where there is an appropriate legal basis under the GDPR, including legitimate interest, pre-contractual steps, contract, legal obligation or consent, depending on the specific processing activity.
5. Google Analytics on the public website
The public Viridis website may use Google Analytics only where the user has given consent through the cookie banner. Users can refuse analytics cookies, accept them or later change their choice through the Cookie settings link in the website footer.
Google Analytics is not intentionally loaded on EcoTrack application pages under /esg-assessment.
6. Newsletter communications
Newsletter communications are sent only where the user has provided consent. Viridis may use a double opt-in process to verify newsletter subscriptions.
7. Contact and consultation communications
If users send a contact request, consultation request or booking request, Viridis uses the data provided to respond, manage the request and provide information about relevant services.
8. EcoTrack application
EcoTrack is the ESG self-assessment application made available through the Viridis website infrastructure. EcoTrack has its own dedicated Privacy Policy.
Users should review the dedicated EcoTrack Privacy Policy before creating an EcoTrack account or using the EcoTrack application.
9. Data processors and service providers
Viridis may use third-party providers to operate the public website and related services, including Netsons, Google/Firebase, Brevo, Google Analytics, Google Calendar/Google Meet, YouTube, email service providers and professional advisors.
10. International data transfers
Some providers used by Viridis may process personal data or make it accessible from countries outside the European Economic Area. Where required, Viridis relies on appropriate transfer mechanisms such as adequacy decisions, the EU-U.S. Data Privacy Framework, Standard Contractual Clauses, data processing agreements and additional safeguards.
11. Data retention
Viridis keeps personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
12. Data security
Viridis applies reasonable technical and organisational measures to protect personal data, including access controls, encrypted connections where available, provider-level security measures, restricted administrative access, data minimisation and use of professional hosting, email, analytics and communication providers.
13. Your GDPR rights
Subject to the conditions and limits provided by applicable law, users have the right to access, correction, deletion, restriction, objection, portability, withdrawal of consent and complaint to a supervisory authority.
In Italy, the competent authority is the Garante per la protezione dei dati personali.
To exercise privacy rights, users can contact: info@viridisconsultancy.com .
14. Children
The Viridis public website and services are intended for business and professional users. They are not directed at children.
15. External links
The public website may contain links to external websites or third-party services. Viridis is not responsible for the privacy practices, content or security of third-party websites or services that are not operated by Viridis.
16. Changes to this Privacy Policy
Viridis may update this Privacy Policy from time to time to reflect changes in services, technologies, legal requirements or processing activities.
17. Contact
For questions about this Privacy Policy or the processing of personal data through the public Viridis website, contact Viridis at: info@viridisconsultancy.com .