Privacy policy
Last updated: 24 September 2026
Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”), T-ONE Therapeutics S.r.l. informs users of the website www.tonetx.eu about how their personal data are processed. This notice applies only to this website and not to third-party websites reachable through links.
1. Data controller
T-ONE Therapeutics S.r.l.
Registered office: Via Pietro Giannone, 9, 20154 Milano (MI), Italy
VAT and tax code 12445320968 – REA MI-2662611
Email: segreteria@tonetx.eu · PEC (certified email): t_one_srl@legalmail.it · Phone +39 02 0066 0221
2. Data processed
Browsing data
During normal operation, the IT systems running the website collect some data whose transmission is implicit in the use of Internet protocols: IP address, browser and device type, date and time of the request, pages visited and outcome of the request. These data are used only to ensure the proper functioning and security of the website and are not used to identify or profile users.
Data voluntarily provided by users
When users write to the addresses shown on the website or use the form on the Contact page, the Controller receives by email the data entered: first name, last name, email address, phone number if provided, subject and content of the message, and any other data the user chooses to share. Please avoid sending special categories of data (such as health data) unless strictly necessary.
Cookies
The website only uses technical cookies. For full details please see the cookie policy.
3. Purposes and legal bases
- Answering user requests sent by email or through the contact form: steps taken at the request of the data subject (Art. 6(1)(b) GDPR).
- Ensuring the functioning and security of the website, including preventing abuse and cyber attacks: legitimate interest of the Controller (Art. 6(1)(f) GDPR).
- Complying with legal obligations or requests from authorities: legal obligation (Art. 6(1)(c) GDPR).
- Establishing, exercising or defending legal claims: legitimate interest of the Controller (Art. 6(1)(f) GDPR).
Providing data is optional, but without contact details it is not possible to answer requests. No automated decision-making or profiling takes place.
4. How data are processed
Data are processed electronically by authorised and trained staff, using appropriate technical and organisational measures to protect them against unauthorised access, loss or disclosure. Communications with the website use an encrypted connection (HTTPS).
5. Recipients
Data may be shared with providers of services to the Controller, such as website hosting, email and IT support, acting as data processors under Art. 28 GDPR, and with the competent authorities where required by law. Data are not disclosed to the public or transferred to third parties for commercial purposes.
6. Transfers outside the European Union
Data are processed within the European Economic Area. Should a provider process them outside the EEA, the transfer will only take place in compliance with Articles 44–49 GDPR, for example on the basis of an adequacy decision of the European Commission or standard contractual clauses.
7. Retention period
- Browsing data: for the time strictly necessary to ensure the security of the website and in any case no longer than 12 months, unless needed to investigate offences.
- Contact requests: for the time needed to handle the request and any follow-up, and in any case no longer than 24 months, unless a contractual relationship is established or legal obligations require longer retention.
8. Your rights
Users may at any time exercise the rights set out in Articles 15–22 GDPR: access to their data, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interest. Where processing is based on consent, it may be withdrawn at any time without affecting the lawfulness of prior processing.
To exercise these rights, simply write to segreteria@tonetx.eu or to the PEC address t_one_srl@legalmail.it. Users also have the right to lodge a complaint with the Italian Data Protection Authority, Garante per la protezione dei dati personali (www.garanteprivacy.it).
9. Minors
The website is not intended for children under 14 and the Controller does not knowingly collect data about them.
10. Links to third-party websites
The website contains links to external websites (for example LinkedIn, Google Maps, scientific journals and news outlets). The Controller is not responsible for the processing of data carried out by those websites; please refer to their own privacy notices.
11. Changes to this notice
This notice may be updated, including following changes in the law. The date of the latest update is shown at the top of the page.
