Privacy Policy for audioforensicexpert.eu

Information on the processing of personal data under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR)
This Privacy Policy describes the processing of personal data connected with browsing audioforensicexpert.eu, contacting the service by email or WhatsApp, and the preliminary stage of a possible professional engagement. Processing carried out under an accepted engagement may also be governed by a case-specific privacy notice, the engagement letter and, where necessary, an agreement under Article 28 GDPR.
Last updated: 30 August 2026
1. Data Controller
Controller: Roberto Ruggeri — audioforensicexpert.eu
Professional domicile or contact address: Via Antonio Sogliano 84, 00164 Rome, Italy
Email: info@audioforensicexpert.eu
For the processing described on this page, the Controller determines the purposes and means of processing. For individual professional engagements, the privacy role applicable to materials entrusted for examination may vary according to the purpose of the processing and the instructions received, and is specified in the documentation applicable to the case.
2. Scope of This Privacy Policy
This Privacy Policy applies to:
- browsing the audioforensicexpert.eu domain;
- requests voluntarily sent by email;
- messages voluntarily sent through WhatsApp;
- materials shared for a preliminary assessment;
- administrative and contractual data relating to a possible professional engagement.
Third-party pages and services reached through external links apply their own privacy notices. This Privacy Policy does not govern processing carried out directly by those providers.
3. Categories of Personal Data Processed
Technical Browsing and Security Data
IT systems and hosting services may generate technical data necessary to deliver and secure the website, such as IP address, date and time of the request, URL visited, response status, browser type, operating system, user agent, referrer and diagnostic or security information.
These data are not used by the Controller for advertising or profiling, but may be processed for operation, security, abuse prevention, technical diagnosis and the establishment of responsibility in the event of cybersecurity incidents.
Data Communicated by Email
When you write to info@audioforensicexpert.eu, the data processed may include name, email address, organization or law firm, contact details, message content, communication metadata, attachments and other information voluntarily provided.
Data Communicated Through WhatsApp
If you choose WhatsApp, the data processed may include telephone number, profile name or image visible according to your settings, message content, files sent, date and time of communications and other information made available through the service.
Recordings, Documents and Engagement-Related Data
During the preliminary stage or performance of an engagement, the data processed may include audio or video files, voices, conversations, transcripts, metadata, legal documents, technical reports, information about acquisition methods and data relating to the client or third parties.
The material may contain special categories of personal data within the meaning of Article 9 GDPR, including health data and, where the relevant legal conditions are met, biometric data. It may also contain other sensitive information concerning private life, personal data relating to criminal convictions and offences governed by Article 10 GDPR, and information connected with legal proceedings. A voice recording is personal data where its content can be related to an individual; it constitutes special-category biometric data when processed using specific technical means for the purpose of uniquely identifying that person.
4. Purposes and Legal Bases
| Purpose | Legal basis |
|---|---|
| Website operation, maintenance and security; abuse prevention and management of technical anomalies | Controller’s legitimate interest in the security and proper delivery of the service — Article 6(1)(f) GDPR |
| Responding to requests, assessing feasibility and defining possible engagement terms | Pre-contractual measures taken at the request of the data subject — Article 6(1)(b) GDPR |
| Performing the professional engagement and managing communications, delivery and related activities | Performance of a contract — Article 6(1)(b) GDPR |
| Tax, accounting, administrative and professional obligations, and lawful requests from authorities | Legal obligation — Article 6(1)(c) GDPR |
| Preventing or managing disputes, protecting rights and documenting activities performed | Legitimate interest in the establishment, exercise or defense of rights — Article 6(1)(f) GDPR |
| Processing special categories of data where indispensable for an engagement or dispute | Establishment, exercise or defense of legal claims — Article 9(2)(f) GDPR, or another applicable condition specified in a case-specific privacy notice |
| Processing personal data relating to criminal convictions and offences where relevant to the engagement | Article 10 GDPR and applicable Union or national law, with appropriate safeguards |
| Optional activities based on consent, if introduced and clearly requested | Consent — Article 6(1)(a) GDPR and, where necessary, Article 9(2)(a) GDPR |
The website does not use personal data for newsletters or unsolicited promotional communications. If an additional purpose is introduced, the data subject will receive the required information before that new processing begins.
5. Contact by Email
Sending an email is voluntary. The data are used to read and respond to the request, ask for any necessary clarification, assess technical feasibility and, where requested, prepare engagement terms or a proposal for the requested work.
Avoid sending recordings, legal documents or particularly confidential information before the transfer method has been agreed. A simple communication does not automatically constitute acceptance of an engagement, a technical opinion or a confidentiality agreement.
6. Contact Through WhatsApp
WhatsApp is an optional channel for brief initial contact. For management of the communication, the Controller processes the data received under this Privacy Policy. WhatsApp Ireland Limited independently processes data relating to its own service, including telephone number, account data, technical information, metadata and other data described in its own privacy notice.
Personal messages are protected by the end-to-end encryption provided by the service, but this does not remove other processing carried out by the provider or risks connected with the device, backups and subsequent storage of the message by participants.
Do not send confidential recordings, case files, court documents or large archives through WhatsApp before an appropriate channel has been agreed. Use of WhatsApp is also subject to the WhatsApp Privacy Policy and Terms.
7. Professional Materials and Third-Party Data
Anyone who submits recordings or documents must be legally entitled to communicate them and should avoid including data that are not relevant to the request. Where required, the client must provide data subjects with the information required by law or identify the circumstances in which a different legal regime applies.
Where personal data have not been obtained directly from the person to whom they relate, the obligations under Article 14 GDPR and any applicable conditions or exemptions are assessed in relation to the source, purpose, proceedings and privacy role applicable to the individual engagement.
For technical materials entrusted by the client, Roberto Ruggeri may act as an independent controller or, where personal data are processed exclusively on behalf of and under the documented instructions of the client, as a processor under Article 28 GDPR. The applicable role is defined in the engagement letter or a separate agreement.
8. Nature of Providing Personal Data
Providing data for an initial request is optional. Failure to provide essential information may make it impossible to respond meaningfully or assess feasibility.
For performance of an engagement, data required for the contract, legal obligations, identification of the materials or proper documentation of the work must be provided. Refusal may prevent acceptance or continuation of the engagement.
9. Recipients and Other Parties Who May Process Personal Data
Within the limits of their respective functions, personal data may be processed by:
- hosting, domain, email, security, maintenance and backup providers;
- messaging and communication providers, including WhatsApp Ireland Limited;
- cloud transfer or storage providers selected and communicated for the individual engagement;
- professionals, consultants, technicians or collaborators bound by confidentiality and involved where necessary;
- accountants, legal advisers, insurers and other parties necessary for administrative obligations or protection of rights;
- the client, appointed lawyer, judicial authority, law-enforcement bodies or other recipients required by the engagement or by law.
Personal data are not sold. They are not made public except where required by law or where publication is expressly authorized and appropriately anonymized when necessary. An up-to-date list of processors may be requested from the Controller.
10. Transfers Outside the European Economic Area
Some external providers may process personal data outside the European Economic Area. This may occur, for example, in connection with WhatsApp and Meta services or agreed cloud infrastructure.
Where a transfer is carried out under the Controller’s responsibility, it is based on an adequacy decision of the European Commission or appropriate safeguards such as Standard Contractual Clauses, together with supplementary measures where necessary. Information about the safeguards applied may be requested from the Controller.
Processing independently carried out by external providers is governed by their own privacy notices. Before a service is used for sensitive professional material, necessity, data location, available security measures and contractual conditions are assessed.
11. Retention Periods and Criteria
- Technical and security logs: for the period necessary to provide, diagnose and protect the website, with possible extension in the event of an incident, abuse or authority request.
- Requests that do not become an engagement: for the period needed to manage the communication and, as a rule, no longer than twelve months from the last contact, unless a dispute, legal obligation or justified reason requires further retention.
- WhatsApp communications: according to the same criteria as preliminary requests; data independently retained by WhatsApp follow the periods stated by the provider.
- Contractual, administrative and tax documents: for the period required by applicable law and any period necessary for the protection of rights.
- Recordings, working copies, reports and technical attachments: for the period defined in the engagement or case-specific privacy notice and in any event no longer than necessary for performance, delivery, legal obligations and defense of rights.
- Data-subject requests and complaints: for the period necessary to handle them and document the response, taking into account possible subsequent proceedings.
At the end of the applicable retention period, personal data are deleted, anonymized or kept under restricted access where continued retention is still legally required or justified.
12. Security Measures
The Controller adopts technical and organizational measures proportionate to the nature of the data and the risks, including access limitation, protected credentials, system updates, separation between received files and working copies, encryption or protected transfer where available, backups and traceability of relevant operations.
No system can guarantee absolute security. In the event of a personal data breach, the assessment, documentation, notification and communication obligations required by applicable law are followed.
13. Cookies, Tracking Technologies and External Links
The website does not provide user accounts, comments, newsletters or direct file-upload functions. The current configuration of cookies and similar technologies is described in the Cookie Policy.
Technical logs generated by the server or security systems do not necessarily constitute cookies. Links to WhatsApp, institutional websites, technical resources or other external services lead to independent platforms that may process personal data under their own terms.
Profiling or behavioral advertising tools are not intentionally enabled without the legal conditions and, where required, the consent provided for by applicable law.
14. Automated Tools and Artificial Intelligence
The website does not use solely automated decision-making or profiling that produces legal effects or similarly significantly affects the data subject.
In a professional engagement, automated or AI-based tools may be used only where technically relevant and compatible with confidentiality and data-protection obligations. Any use of external services, the processing arrangements and the limitations of the tool must be assessed and documented; automated output does not replace professional evaluation.
15. Data Subject Rights
Where provided for by the GDPR, a data subject may request:
- access to personal data and information about the processing;
- rectification of inaccurate data and completion of incomplete data;
- erasure, where the legal conditions are met;
- restriction of processing;
- data portability, where applicable;
- objection to processing based on legitimate interests;
- withdrawal of consent where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
A request may be sent to info@audioforensicexpert.eu. The Controller may request information necessary to verify the identity of the requester. A response is provided without undue delay and, as a rule, within one month, subject to any extension permitted by law.
Certain rights may be restricted by legal obligations, the protection of rights, professional confidentiality, third-party rights or other conditions provided for by law.
A data subject may lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) or apply to the competent judicial authority.
16. Children
The website and professional services are intended for adults or persons acting through an authorized representative. Do not submit data or recordings relating to children unless this is necessary, lawful and appropriately authorized in the context of the matter.
17. Updates to This Privacy Policy
This Privacy Policy may be updated when website functions, providers, operational methods or applicable law change. The current version is published on this page together with its update date.
For the conditions governing use of the website, see the Terms of Service. For cookies and similar technologies, see the Cookie Policy.
Privacy Contact
For information about personal-data processing or to exercise rights under the GDPR, write to info@audioforensicexpert.eu and use “Privacy request” in the subject line.