Privacy Notice
How the House of ESI handles your personal data
DRAFT. PENDING LEGAL REVIEW.
This Privacy Notice reflects the current practice of ESI Executive Search International and is provided in good faith to inform you of how we handle personal data. This version is a draft pending formal legal review under Italian and European law. For the most current version, or to report a concern, please contact privacy@esiglobal.com. Last updated 22 April 2026.
A quiet commitment
The House of ESI Executive Search International has been entrusted, since 1977, with one of the more sensitive responsibilities in luxury hospitality: the placement of senior leaders in properties that depend on discretion as much as on excellence. That trust is the foundation of our work. The careful handling of personal data is its natural extension.
This Privacy Notice explains what personal data the House collects, why we collect it, how long we keep it, with whom we share it, and what rights you have in relation to it. We have written it in the clearest language we could, because privacy is too important a matter to hide behind legal prose.
We comply with the European General Data Protection Regulation (EU) 2016/679 (GDPR), the Italian Data Protection Code (Legislative Decree 196/2003 as amended by Legislative Decree 101/2018), and applicable local data protection laws in the jurisdictions in which we operate.
Who we are
The data controller is ESI Executive Search International, Piazza del Popolo 18, 00187 Rome, Italy. Telephone: +39 393 237 4918. Email: info@esiglobal.com.
For any matter concerning your personal data, including requests to exercise your rights, please write to privacy@esiglobal.com. A senior member of the House will respond personally.
The personal data we process
The House processes different categories of personal data depending on the nature of your relationship with us. The sections below describe each category separately, because your rights and our obligations differ accordingly.
For senior hospitality professionals (candidates)
When you engage with the House as a potential candidate, by submitting a CV, by responding to our approach, or through confidential conversation, we may collect and process: identity and contact details (name, email, telephone, postal address, nationality, languages spoken); professional history (career record, employers, roles, responsibilities, achievements, dates of employment, education, certifications, professional memberships); current role and remuneration where you choose to share this; career aspirations, geographic preferences, and any constraints relevant to your next chapter; assessment data where a CADT assessment is conducted with your explicit written consent (including interview notes, observations, and the written report); references where provided and where the referee has consented to being contacted; other professional information you voluntarily share during our conversations.
We do not request, and we expressly discourage the sharing of, personal data not relevant to the professional purpose of our engagement with you.
For hotel owners, investors, and client organisations
When the House is engaged to conduct a search, or to provide advisory, we process personal data of individuals acting on behalf of client organisations, including: contact details of the principal, the hiring authority, and relevant members of the board or senior team; information shared in the course of the briefing and the engagement, including organisational context relevant to the search; records of communication, meeting notes, and documents exchanged during the engagement; financial details necessary for invoicing and fulfilment of the engagement.
For visitors to esiglobal.com
When you visit our website, we process limited technical data: anonymised analytics through Google Analytics 4, used to understand how visitors find and use the site in aggregate; IP address, browser type, and device information, as logged by our hosting provider Webflow for security and site performance; data you voluntarily submit through the contact form, the CV upload form, or the newsletter subscription form.
For newsletter subscribers
When you subscribe to our occasional newsletter, we process your email address, your first name where you provide it, and your subscription preferences. We use this data only to send the newsletter and to measure engagement in aggregate.
Why we process your personal data
The legal bases for our processing, under Article 6 GDPR, are the following.
Legitimate interests
Much of our work is carried out on the basis of legitimate interest, specifically the proper performance of our professional engagement on behalf of clients and the professional service to senior hospitality leaders who benefit from our network. When we rely on legitimate interest, we balance our interest against your rights and freedoms, and we document that assessment. You have the right to object to such processing, as explained in the Rights section below.
Contract performance
Where the House has a contractual relationship with a client organisation, processing of personal data necessary for the performance of that contract is carried out on that legal basis.
Consent
In specific circumstances we process data on the basis of your explicit consent. This applies to subscribing to the newsletter; the CADT assessment and its sharing with the client organisation, which is always carried out with your separate written consent; sharing your name and profile with a specific client in connection with a specific search; retention of your profile in our confidential network for future opportunities.
You may withdraw consent at any time, in which case we will cease the relevant processing, though this does not affect the lawfulness of processing carried out before the withdrawal.
Legal obligation
In limited cases we are required to process personal data to comply with a legal obligation, for example in relation to tax, accounting, or in response to lawful requests from authorities.
With whom we share personal data
The House shares personal data only where necessary and always with care.
With client organisations
Candidate information is shared with a client organisation only with the explicit consent of the candidate for the specific search in question. The House does not share candidate names or profiles with clients without that consent. Once consent is given, the client organisation becomes a separate data controller in relation to that data and processes it according to its own data protection practices.
With trusted service providers
We work with a small number of service providers who process data on our behalf under contracts that impose confidentiality and data protection obligations at least equivalent to those we impose on ourselves. These include Webflow, Inc. for website hosting (United States, with EU Standard Contractual Clauses); Google LLC for analytics and Google Workspace services (United States, with EU Standard Contractual Clauses and supplementary technical measures); Mailchimp for newsletter distribution where applicable (United States, with EU Standard Contractual Clauses); accountancy and legal advisors bound by professional secrecy.
With our international trusted network
The House works with a trusted international network of senior consultants across Europe and Middle East. Where a search or advisory assignment requires input from a member of this network, personal data may be shared with them under confidentiality terms. This sharing is always subject to the same standards of discretion that apply to the House itself.
With competent authorities
We may be required to share personal data with regulatory or judicial authorities in response to lawful requests. We comply with such requests only where a valid legal basis exists.
We do not sell personal data
The House does not sell, rent, or lease personal data to any third party, under any circumstances.
Transfers of personal data outside the European Economic Area
Our trusted network and some of our service providers are established outside the European Economic Area. When personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses, on adequacy decisions where applicable, and on supplementary safeguards where a particular jurisdiction requires them. You may request further information about these transfers by writing to privacy@esiglobal.com.
How long we keep personal data
We keep personal data only for as long as necessary for the purposes for which it was collected, with the following general retention periods: active candidate profiles for the duration of our engagement, plus 5 years, unless you request earlier deletion; inactive candidate profiles (no contact for 3 years) reviewed and deleted unless you confirm you wish to remain in the network; client engagement files for the duration of the engagement, plus 10 years, as required by Italian civil law for the retention of professional records; financial and tax records for 10 years, as required by Italian tax law; newsletter subscriber data until you unsubscribe; website analytics for 26 months (Google Analytics default) in aggregated form.
At the end of the applicable retention period, data is either deleted or fully anonymised.
Your rights
Under the GDPR and Italian data protection law, you have the following rights in relation to your personal data.
Right of access: to obtain confirmation that we process your personal data and receive a copy of that data.
Right of rectification: to request correction of inaccurate or incomplete data.
Right of erasure: to request deletion of your personal data, subject to applicable legal retention obligations.
Right to restrict processing: to limit how we process your data in specific circumstances.
Right to object: to object to processing based on legitimate interest.
Right to data portability: to receive your data in a structured, machine-readable format and transmit it to another controller.
Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
Right to lodge a complaint: with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, www.garanteprivacy.it) or with the data protection authority of your country of residence.
To exercise any of these rights, please write to privacy@esiglobal.com. We will respond within one month of receiving your request, as required by the GDPR. There is no fee for exercising these rights, unless the request is manifestly unfounded or excessive.
How we protect personal data
The House treats discretion as architecture, not policy. In practical terms, this means: sensitive briefings happen by voice, not email; written records are kept to the minimum necessary; our team is small and senior by design, so that fewer people handle each engagement; digital systems are protected by access controls, encryption in transit and at rest where technically feasible, and multi-factor authentication for administrative access; we review our service providers and their data protection practices regularly.
In the event of a personal data breach, we will notify affected individuals and the Garante within 72 hours, as required by the GDPR, where the breach is likely to result in a risk to their rights and freedoms.
Cookies and similar technologies
The website esiglobal.com uses a limited number of cookies and similar technologies: strictly necessary cookies required for the site to function; analytics cookies through Google Analytics 4, used only with your consent to understand website use in aggregate.
When you first visit the site, a cookie consent banner allows you to accept, reject, or adjust your preferences. You can change your preferences at any time by clicking the cookie settings link in the footer. The site does not use advertising cookies, social media tracking pixels, or profiling technologies.
Changes to this notice
The House may update this Privacy Notice from time to time to reflect changes in our practices, in our service providers, or in the applicable law. The date of the most recent update is shown at the top of this page. Material changes will be communicated to active candidates and clients by email where appropriate.
Contact
For any question about this Privacy Notice or about how the House handles your personal data, please contact:
ESI Executive Search International
Attn. Privacy Officer
Piazza del Popolo 18, 00187 Rome, Italy
Email: privacy@esiglobal.com
Telephone: +39 393 237 4918
Echte gastvrijheid, van oudsher. True hospitality, from times past. Ospitalità autentica, da sempre.