2027-2028 IntakeApplications for the new academic year are open
Legal & Security

Privacy Notice (GDPR)

Last updated: 9 October 2026

1. Data Controller

The data controller under the EU General Data Protection Regulation ("GDPR") and, for residents of Turkey, the Turkish Personal Data Protection Law No. 6698 ("KVKK"), is Rome Consultancy.

Rome office: Via Regina Margherita 232, 00198 Rome, Italy
Bursa office: Üçevler Mah. Bayraktepe Sok. No:14 Emir Arslan Plaza Kat:3 Daire:6 Nilüfer / Bursa, Turkey
Email: info@romeconsultancy.com · Phone: +39 351 685 5882

2. Personal Data We Process

  • Identity and contact details: name, phone number (including WhatsApp), email address, country of residence.
  • Education details: school year or graduation status, entrance exam status, language level, programme of interest and any notes you write in the form.
  • Scholarship pre-assessment: an estimated family income range, if you choose to share it.
  • Security data: the IP address and time of your form submission.

We collect this data directly from you through the forms on our website.

3. Purposes

  • Responding to your request and contacting you by phone, WhatsApp or email,
  • Assessing your eligibility for Italian universities, entrance exams, the student visa and the DSU scholarship,
  • Providing our consultancy services if you ask us to,
  • Preventing misuse of the form (spam, bots) and keeping our systems secure.

4. Legal Bases

  • Steps taken at your request before entering into a contract: GDPR art. 6(1)(b) (KVKK art. 5/2-c),
  • Our legitimate interest in keeping the form secure (IP address): GDPR art. 6(1)(f) (KVKK art. 5/2-f).

5. Recipients and Service Providers

We never sell your data or share it with advertising or marketing companies. We only use the following infrastructure providers to deliver our service:

  • Google Ireland Ltd. / Google LLC (Firebase Firestore): the database where requests are stored. Servers are located in the European Union (eur3: Belgium/Netherlands).
  • Vercel Inc.: website hosting. The server functions that process the form run in Germany (Frankfurt); the company is based in the United States.

Where a provider is based outside the EU, the transfer is protected by appropriate safeguards such as the EU Standard Contractual Clauses. At your request, and only as needed, information may be shared with the universities and public authorities you apply to.

6. Retention

We keep requests for a maximum of 2 years after our last contact with you, after which they are deleted. If you sign a consultancy agreement, the retention periods required by law apply. If you ask us to delete your data, we do so without delay.

7. Cookies

The public pages of our website do not use cookies, advertising or tracking tools (analytics, pixels, etc.) and do not store information in your browser. Only the admin panel used by authorised staff uses a strictly necessary technical cookie to keep the session secure.

8. Security

Connections are encrypted (HTTPS). Requests are stored in a database protected by access rules and encrypted at rest; they cannot be read or changed from outside. Only authorised Rome Consultancy staff can access them with their personal accounts.

9. Your Rights

Under GDPR arts. 15-22 (and KVKK art. 11 for residents of Turkey) you have the right to:

  • Access your personal data and receive information about how it is processed,
  • Have inaccurate data corrected and have your data erased,
  • Restrict or object to processing,
  • Receive a copy of your data in a portable format,
  • Withdraw any consent at any time, without affecting earlier processing.

10. Requests and Complaints

Send your requests to info@romeconsultancy.com; we reply within 30 days. You can also lodge a complaint with the Italian data protection authority (Garante per la protezione dei dati personali), the supervisory authority of your country of residence, or, in Turkey, the Personal Data Protection Authority (KVKK).