Personal Privacy Statement (Article 13 Reg. EU 2016/679)
For the purposes set out in EU Regulation no. 679/2016 on the protection of natural persons with regard to the processing of personal data, we inform you that this website (www.daysurgeryclinic.it) collects certain items of Personal Data from its Users. This Personal Data will be processed in compliance with the aforementioned EU Regulation, in compliance with the resulting rights and obligations.
The Data Controller is Day Surgery Clinic Dott. Erri CIPPINI, Chirurgo Plastico ECFMG certified | Via Spalto San Marco n°1/A 25121 Brescia tel. e fax: +39 030 3758502 | tel.-cellulare studio: +39 339 5496222 | Partita IVA: 01735190173
Data Controller email address: firstname.lastname@example.org
Type of Data collected
The Personal Data collected by this website, either independently or through third parties, includes: Cookies, usage data, name, email and other types of data.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during use of the website.
Unless otherwise specified, all Data requested by this website is mandatory. If the User refuses to provide requested Data, the website may be unable to provide the requested service. Where this website indicates certain Data as optional, Users are free to withhold such Data, without this affecting the availability of the service or its operation.
Users who are unsure about the mandatory nature of personal Data are invited to contact the Data Controller.
The User shall be liable for the Personal Data of third parties obtained, published or shared through this website and guarantees his/her right to communicate or disseminate such Data, relieving the Data Controller of any liability towards third parties.
Method and place of processing of collected Data
Method of processing
The Data Controller shall adopt appropriate security measures to prevent the unauthorised access, disclosure, modification or destruction of Personal Data.
Data processing shall be undertaken using IT and/or telematic tools, with organisational methods and logic strictly related to the purposes indicated. In addition to the Data Controller, other parties involved in the website organisation (administrative, sales, marketing personnel; legal bodies; system administrators) or external parties (such as suppliers of third party technical services, couriers, hosting providers, IT companies, communications agencies) may in certain cases have access to Data, including nomination, where necessary, as Data Processors by the Data Controller. An updated list of Data Processors can always be requested from the Data Controller.
Legal basis of the processing
The Data Controller shall process the Personal Data of the User in case of one of the following:
• the User has given his/her consent for one or more specific purposes;
• the processing is necessary for the performance of a contract with the User and/or the performance of pre-contractual measures;
• the processing is necessary for the fulfilment of legal obligations of the Data Controller;
• the processing is necessary for the performance of a task carried out in the public interest or for the exercise of official authority vested in the Data Controller;
• the processing is necessary for the pursuit of legitimate interests of the Data Controller or third parties.
It is, in any case, always possible to ask the Data Controller to clarify the concrete legal basis of each type of data processing and, in particular, to specify whether the processing is based on law, required under contract or necessary to conclude a contract.
The Data is processed at the operational headquarters of the Data Controller and in any other place where parties involved in processing are located. For more information, contact the Controller.
The User's Personal Data may be transferred to a country other than that in which the User is located. For further information on the place of processing, the User can refer to the section detailing the processing of Personal Data.
The User has the right to obtain information regarding the legal basis for the transfer of Data outside the European Union or to an international organisation of public international law or consisting of two or more countries, such as the UN, as well as regarding the security measures adopted by the Data Controller to protect the Data.
In the event of any of the Data transfers described above, the User can refer to the respective sections of this document or request information from the Data Controller using the methods outlined in the introduction.
The Data is processed and retained for the time required according to the purposes for which it was collected.
• Personal Data collected for the purposes of performing a contract between the Controller and the User will be retained until the performance of the contract is completed.
• Personal Data collected for purposes pertaining to the legitimate interest of the Controller will be retained until such interest is satisfied. The User can obtain further information regarding the legitimate interests pursued by the Controller in the relevant sections of this document or by contacting the Data Controller.
When the processing is based on the consent of the User, the Data Controller may retain Personal Data for a longer period until such consent is withdrawn. Furthermore, the Data Controller may be obliged to retain Personal Data for a longer period, in compliance with a legal obligation or as ordered by an authority.
Personal Data will be retained for as long as strictly necessary and in any case, data will be stored for ten years, as required by the Italian Civil Code;
At the end of the retention period, Personal Data will be deleted. Therefore, at the end of this term, the right to access, cancellation, rectification and the right to Data portability can no longer be exercised.
Purposes of processing collected Data
The User Data is collected to allow the Controller to provide its Services, as well as for the following purposes: Statistics, Displaying content from external platforms, Contacting the User and Backend hosting and infrastructure.
For further detailed information on processing purposes and Personal Data actually relevant to each purpose, the User can refer to the relevant sections of this document.
Details on the processing of Personal Data
Personal Data is collected for the following purposes and using the following services:
• Contacting the User
Contact form (this website)
By filling out the contact form with their Data, the User consents to its use to respond to requests for information, quotes, or any other kind indicated by the form header.
Personal Data collected: email address, first name, last name, town or city, postal code, district, phone number and subject of the request.
• Reserved Area
We use your personal data in order to offer dedicated info through the private area accessible with userid and password.
Personal Data collected: first name, last name, email address
• Backend hosting and infrastructure
These services are designed to host and operate key components of this Application, making it possible to deliver this Application from a single platform. These platforms provide the Controller with a wide range of tools, such as analytical tools, for managing user registration, managing comments and databases, for e-commerce, processing payments, etc. The use of such tools involves the collection and processing of Personal Data.
This type of service also hosts Data and files that enable the operation of this website, allowing its distribution and providing a ready-to-use infrastructure for providing specific features of this website.
Some of these services work through geographically dislocated servers in different locations, making it difficult to determine the exact location in which the Personal Data is stored.
SMARTWEBSITE is a web platform with a hosting service provided by Stefana Web & Innovation by Stefana Stefano
The services included in this section allow the Data Controller to monitor and analyse traffic data and are used to track User behaviour.
Google Analytics (Google Inc.)
Google Analytics is a web analysis service provided by Google Inc. ("Google"). Google uses the Personal Data collected for the purpose of tracking and analysing use of this website, compiling reports and sharing them with other services developed by Google.
Google may use the Personal Data to contextualise and customise the advertisements on its advertising network.
Personal Data collected: Cookies and usage Data.
• Displaying content from external platforms
This type of service allows you to view an interact with content hosted on external platforms directly from the website pages.
In the event that a service of this type is installed, it is possible that, even if the Users do not use the service, it collects traffic data relating to the pages on which it is installed.
Google Maps Widget (Google Inc.)
Google Maps is a map visualisation service managed by Google Inc. that allows this website to integrate such content within its pages.
Personal Data collected: Cookies and usage Data.
. Privacy Shield participant.
YouTube Video Widget (Google Inc.)
YouTube is a video content visualisation service managed by Google Inc. that allows this application to integrate such content within its pages.
Personal Data collected: Cookies and usage Data.
. Privacy Shield participant.
Users may exercise certain rights with reference to the Data processed by the Data Controller.
In particular, Users have the right to:
• withdraw consent at any time. Users may withdraw consent given previously for the processing of their Personal Data. (art. 7 par.3 EU Regulation no. 2016/679)
• oppose the processing of their Personal Data. Users can oppose the processing of their Personal Data when it occurs on a legal basis other than consent. Further details on the right to opposition are indicated in the section below. (art. 21 of EU Regulation no. 2016/679)
• access their Data. Users have the right to obtain information on the Data being processed by the Data Controller, on certain aspects of the processing and to receive a copy of the Data processed. (art. 15 of EU Regulation no. 2016/679)
• verify and request rectification. Users can verify the correctness of their Personal Data and request that it be updated or corrected.
(art. 16 of EU Regulation no. 2016/679)
• obtain the restriction of processing. When certain conditions are met, Users can request the restriction of the processing of their Personal Data. In this case, the Data Controller shall not process the Data for any purpose other than its retention. (art. 18 of EU Regulation no. 2016/679)
• obtain the cancellation or deletion of their Personal Data. When certain conditions are met, Users can request the cancellation of their Personal Data by the Data Controller .
(art. 17 of EU Regulation no. 2016/679)
• receive their Personal Data or transfer it to another data controller (portability). Users have the right to receive their Data in a structured, commonly used and machine-readable format and, where technically feasible, have the right to transmit it without hindrance to another controller. This provision is applicable when the Data is processed with automated tools and the processing is based on User consent, on a contract of which the User is a party or on related contractual measures. (art. 20 of EU Regulation no. 2016/679)
• lodge a complaint. Users can lodge a complaint with the relevant personal data protection authority or engage in legal proceedings. (art. 51 of EU Regulation no. 2016/679)
Details on the right to opposition
When Personal Data is processed in the public interest, in the exercise of public authority vested in the Controller or to pursue a legitimate interest of the Controller, Users have the right to oppose the processing for reasons related to their particular situation.
Users are reminded that, if their Data is processed for direct marketing purposes, they can oppose the processing without providing any reasons. To find out whether the Controller processes data for direct marketing purposes, Users can refer to the relevant sections of this document.
How to exercise User Rights
The aforementioned rights may be exercised by means of a written communication sent by email to the address of the Data Controller. Requests are made free of charge and processed by the Controller as soon as possible, in any case within one month.
Additional information on data processing
The Personal Data of Users may be used by the Controller in court or during the preliminary stages of the possible establishment of defence against abuse in the use of this website or related Services by the User.
Users declare themselves to be aware that the Data Controller may need to disclose their Personal Data by order of public authorities.
System logs and maintenance
For needs relating to operation and maintenance, this website and any third party services used by it may collect System Logs, which are files that record interactions and may also contain Personal Data, such as the User IP address.
Information not included in this policy
Further information on the processing of Personal Data may be requested, at any time, from the Data Controller using the contact details.
Response to "Do Not Track" requests
This website does not support "Do Not Track" requests.
To find out if any used third-party services used support these requests, the User is invited to consult their respective privacy policies.
Links to third-party sites
We do not ask for or collect Personal Data from persons under the age of 18. Persons under the age of 18 must not enter information on this website or use our services. If you believe that your child, under the age of 18, has entered his or her Personal Data on this website, you may contact the Data Controller to request that this Personal Data be deleted.
If the amendments concern processing whose legal basis is consent, the Controller will request the User's consent again, where necessary.
Definitions and legal references
Personal Data (or Data)
Personal data is any information that, directly or indirectly, also in connection with any other information, including a personal identification number, makes a natural person identified or identifiable.
This is information collected automatically via this website (including from third-party applications integrated into this website), including: IP addresses or domain names of the computers used by the User to connect to the website, the URI addresses (Uniform Resource Identifier), the time of request, the method used to forward the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server response (success, error, etc.) the country of origin, the characteristics of the browser and the operating system used by the visitor, the various temporal connotations of the visit (for example the time spent on each page) and the details of the route followed within the Application, with particular reference to the sequence of pages consulted, operating system parameters and the User’s IT environment.
The individual who uses this website and who, unless otherwise specified, is the Interested Party.
The natural person to whom the Personal Data refers.
Data Processor (or Processor)
Data Controller (or Controller)
The natural or legal person, public authority, service or other body that individually or together with others, determines the purposes and means of the personal data processing and the tools adopted, including the security measures relating to the operation and use of this website. The Data Controller, unless otherwise specified, is the owner of this website.
The hardware or software tool through which Users’ Personal Data is collected and processed.
The Service provided by this website as defined in the relative terms (where existing) on this website/application.
European Union (or EU)
Unless otherwise specified, any reference to the European Union made in this document is understood to include all current member states of the European Union and European Economic Area.
Small portion of data stored on the User's device.
This privacy statement is drawn up on the basis of multiple legislative systems, including articles 13 and 14 of Regulation (EU) 2016/679.
Unless otherwise specified, this privacy statement applies exclusively to this website.