Privacy Policy of dermatologiaprati.com
To obtain information regarding your personal data collected, the purposes for which it is used, and the parties with whom the data is shared, please contact the Data Controller.
Data Controller Piera Fileccia, Studio Dermatologia Prati, Via Cola Di Rienzo 212 – 00192 Rome. VAT No. 10254800583
Email address of the Data Controller: info@dermatologiaprati.com
Types of Data Collected The Data Controller does not provide a list of the types of personal data collected.
Complete details on each type of personal data collected are provided in the dedicated sections of this privacy policy or through specific information texts displayed prior to the collection of the data itself.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the use of this Application.
Unless otherwise specified, all data requested by this Application is mandatory. If the User refuses to provide it, it may be impossible for this Application to provide the Service. In cases where this Application indicates some data as optional, Users are free to refrain from communicating such data without affecting the availability or operation of the Service.
Users who are uncertain about which data is mandatory are encouraged to contact the Data Controller.
The use of Cookies – or other tracking tools – by this Application or by the owners of third-party services used by this Application is for the purpose of providing the Service requested by the User, as well as for other purposes described in this document and in the Cookie Policy.
The User assumes responsibility for the personal data of third parties obtained, published, or shared through this Application.
Methods and Location of Data Processing
Methods of Processing
The Data Controller takes appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of personal data.
Processing is carried out using IT and/or telematic tools, with organizational methods and logic strictly related to the indicated purposes. In addition to the Data Controller, in some cases, the data may be accessed by other parties involved in the operation of this Application (administrative, commercial, marketing, legal staff, system administrators) or external entities (such as third-party technical service providers, postal couriers, hosting providers, IT companies, communication agencies) appointed, if necessary, as Data Processors by the Data Controller. An updated list of these Data Processors can be requested from the Data Controller at any time.
Location
Data is processed at the operational offices of the Data Controller and any other locations where the parties involved in the processing are located. For further information, contact the Data Controller.
The User’s personal data may be transferred to a country different from where the User is located. For more information on the place of processing, the User may refer to the section detailing the processing of personal data.
Data Retention Period
Unless otherwise specified in this document, personal data is processed and retained for the time required by the purpose for which it was collected and may be stored for a longer period due to legal obligations or based on the consent of the Users.
Cookie Policy
This Application uses tracking tools. For more information, Users can consult the Cookie Policy.
Additional Information for Users
Legal Basis of Processing
The Data Controller processes personal data relating to the User if one of the following conditions applies:
- The User has given consent for one or more specific purposes.
- Processing is necessary for the performance of a contract with the User and/or to take pre-contractual measures.
- Processing is necessary for compliance with a legal obligation to which the Data Controller is subject.
- Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller.
- Processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by third parties.
It is always possible to request clarification from the Data Controller regarding the specific legal basis of each processing operation and, in particular, to specify whether the processing is based on law, a contract, or necessary to conclude a contract.
Further Information on Data Retention
Unless otherwise stated in this document, personal data is processed and retained for the time necessary to fulfill the purposes for which it was collected and may be stored for a longer period due to legal obligations or based on the consent of the Users.
Therefore:
- Personal data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until such contract has been fully executed.
- Personal data collected for purposes related to the legitimate interest of the Data Controller will be retained until such interest is fulfilled. Users can obtain further information regarding the legitimate interest pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.
- When processing is based on the User’s consent, the Data Controller may retain personal data for a longer period until such consent is revoked. Additionally, the Data Controller may be required to retain personal data for a longer period to comply with a legal obligation or by order of an authority.
At the end of the retention period, personal data will be deleted. Therefore, after this period expires, the right to access, erase, rectify, and the right to data portability can no longer be exercised.
User Rights Based on the General Data Protection Regulation (GDPR)
Users can exercise certain rights concerning the data processed by the Data Controller.
In particular, within the limits provided by law, the User has the right to:
- Revoke consent at any time. The User can revoke previously given consent for the processing of their personal data.
- Object to the processing of their data. The User can object to the processing of their data when it is carried out on a legal basis other than consent.
- Access their data. The User has the right to obtain information about the data processed by the Data Controller, certain aspects of the processing, and to receive a copy of the data being processed.
- Verify and request rectification. The User can verify the accuracy of their data and request its update or correction.
- Obtain restriction of processing. The User has the right to request the restriction of the processing of their data. In this case, the Data Controller will not process the data for any purpose other than its storage.
- Obtain the erasure or removal of their personal data. The User can request the deletion of their data from the Data Controller.
- Receive their data or have it transferred to another controller. The User has the right to receive their data in a structured, commonly used, and machine-readable format and, where technically feasible, to have it transferred to another controller without hindrance.
- Lodge a complaint. The User can lodge a complaint with the competent data protection authority or take legal action.
Users have the right to obtain information regarding the legal basis for the transfer of data abroad, including to any international organization governed by international law or formed by two or more countries, such as the United Nations, and regarding the security measures adopted by the Data Controller to protect their data.
Details on the Right to Object
When personal data is processed in the public interest, in the exercise of official authority vested in the Data Controller, or for legitimate interests pursued by the Data Controller, Users have the right to object to such processing for reasons related to their particular situation.
Users are informed that, where their data is processed for direct marketing purposes, they can object to the processing at any time without providing any justification. If Users object to processing for direct marketing purposes, personal data will no longer be processed for such purposes. To find out whether the Data Controller processes data for direct marketing purposes, Users can refer to the relevant sections of this document.
How to Exercise Rights
Any requests to exercise User rights can be addressed to the Data Controller using the contact details provided in this document. Requests are free of charge, and the Data Controller will respond as quickly as possible, in any case within one month, providing Users with all legally required information. Any rectifications, deletions, or restrictions of processing will be communicated by the Data Controller to each recipient, if any, to whom personal data has been transmitted unless this proves impossible or involves disproportionate effort. The Data Controller will inform the User of these recipients upon request.
Additional Information on Data Processing
Legal Defense
The User’s personal data may be used by the Data Controller in legal proceedings or in the preparatory stages for its potential establishment to defend against abuse in the use of this Application or the connected services by the User.
The User declares to be aware that the Data Controller may be required to disclose personal data by order of public authorities.
Specific Notices
Upon the User’s request, in addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information regarding specific services or the collection and processing of personal data.
System Logs and Maintenance
For operational and maintenance purposes, this Application and any third-party services used may collect system logs, which are files that record interactions and may contain personal data, such as the User’s IP address.
Information Not Contained in this Policy
Further information regarding the processing of personal data may be requested from the Data Controller at any time using the contact details provided.
Modifications to this Privacy Policy
The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Application, as well as, where technically and legally feasible, sending a notification to Users through any contact information available to the Data Controller. Please consult this page frequently, referring to the date of the last modification indicated at the bottom.
If the modifications involve processing activities based on the User’s consent, the Data Controller will collect new consent from the User, if necessary.
Definitions and Legal References
- Personal Data (or Data): Any information that directly or indirectly, even in connection with other information, including a personal identification number, allows the identification or identifiability of a natural person.
- Usage Data: Information collected automatically through this Application (or third-party services employed by this Application), including: the IP addresses or domain names of the computers used by the Users who connect with this Application, the URI (Uniform Resource Identifier) addresses, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server’s response (success, error, etc.), the country of origin, the features of the browser and the operating system used by the visitor, the various time details per visit (e.g., the time spent on each page) and the details of the path followed within the Application, with special reference to the sequence of pages visited, and other parameters about the User’s operating system and computer environment.
- User: The individual using this Application, who, unless otherwise specified, coincides with the Data Subject.
- Data Subject: The natural person to whom the personal data refers.
- Data Processor (or Processor): The natural or legal person, public authority, agency, or other body that processes personal data on behalf of the Data Controller, as described in this privacy policy.
- Data Controller (or Controller): The natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data, including the security measures concerning the operation and use of this Application. The Data Controller, unless otherwise specified, is the owner of this Application.
- This Application: The means by which the personal data of the User is collected and processed.
- Service: The service provided by this Application as described in the relative terms (if available) on this website/application.
- European Union (or EU): Unless otherwise specified, any reference made within this document to the European Union includes all current member states to the European Union and the European Economic Area.
- Legal References: This privacy policy is based on provisions of multiple legislations, including Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR). Unless otherwise stated, this privacy policy only concerns this Application.