Privacy

Privacy Statement
Personal Privacy Statement (Article 13 Reg. EU 2016/679)
For the purposes set out in EU Regulation no. 679/2016 on the protection of natural persons with regard to the processing of personal data, we inform you that this website (www.daysurgeryclinic.it)  collects certain items of Personal Data from its Users. This Personal Data will be processed in compliance with the aforementioned EU Regulation, in compliance with the resulting rights and obligations.
 
Data Controller
The Data Controller is Day Surgery Clinic Dott. Erri CIPPINI, Chirurgo Plastico ECFMG certified | Via Spalto San Marco n°1/A 25121 Brescia tel. e fax: +39 030 3758502 | tel.-cellulare studio: +39 339 5496222 | Partita IVA: 01735190173
Data Controller email address: cippinierri@pcert.it
 
Type of Data collected
The Personal Data collected by this website, either independently or through third parties, includes: Cookies, usage data, name, email and other types of data.
Full details on each type of data collected are provided in the dedicated sections of this privacy policy or on specific information notices displayed before the data is collected.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during use of the website.
Unless otherwise specified, all Data requested by this website is mandatory. If the User refuses to provide requested Data, the website may be unable to provide the requested service. Where this website indicates certain Data as optional, Users are free to withhold such Data, without this affecting the availability of the service or its operation.
Users who are unsure about the mandatory nature of personal Data are invited to contact the Data Controller.
Any use of cookies - or other tracking tools - by this website or by third party service providers used by this website, unless otherwise specified, is undertaken for the purpose of providing e the service requested by the User, as well as for the additional purposes described in this document and in the Cookie Policy.
The User shall be liable for the Personal Data of third parties obtained, published or shared through this website and guarantees his/her right to communicate or disseminate such Data, relieving the Data Controller of any liability towards third parties.
 
Method and place of processing of collected Data
Method of processing
The Data Controller shall adopt appropriate security measures to prevent the unauthorised access, disclosure, modification or destruction of Personal Data.
Data processing shall be undertaken using IT and/or telematic tools, with organisational methods and logic strictly related to the purposes indicated. In addition to the Data Controller, other parties involved in the website organisation (administrative, sales, marketing personnel; legal bodies; system administrators) or external parties (such as suppliers of third party technical services, couriers, hosting providers, IT companies, communications agencies) may in certain cases have access to Data, including nomination, where necessary, as Data Processors by the Data Controller. An updated list of Data Processors can always be requested from the Data Controller.
Legal basis of the processing
The Data Controller shall process the Personal Data of the User in case of one of the following:
• the User has given his/her consent for one or more specific purposes;
• the processing is necessary for the performance of a contract with the User and/or the performance of pre-contractual measures;
• the processing is necessary for the fulfilment of legal obligations of the Data Controller;
• the processing is necessary for the performance of a task carried out in the public interest or for the exercise of official authority vested in the Data Controller;
• the processing is necessary for the pursuit of legitimate interests of the Data Controller or third parties.
It is, in any case, always possible to ask the Data Controller to clarify the concrete legal basis of each type of data processing and, in particular, to specify whether the processing is based on law, required under contract or necessary to conclude a contract.
Place
The Data is processed at the operational headquarters of the Data Controller and in any other place where parties involved in processing are located. For more information, contact the Controller.
The User's Personal Data may be transferred to a country other than that in which the User is located. For further information on the place of processing, the User can refer to the section detailing the processing of Personal Data.
The User has the right to obtain information regarding the legal basis for the transfer of Data outside the European Union or to an international organisation of public international law or consisting of two or more countries, such as the UN, as well as regarding the security measures adopted by the Data Controller to protect the Data.
In the event of any of the Data transfers described above, the User can refer to the respective sections of this document or request information from the Data Controller using the methods outlined in the introduction.
Retention period
The Data is processed and retained for the time required according to the purposes for which it was collected.
Therefore:
• Personal Data collected for the purposes of performing a contract between the Controller and the User will be retained until the performance of the contract is completed.
• Personal Data collected for purposes pertaining to the legitimate interest of the Controller will be retained until such interest is satisfied. The User can obtain further information regarding the legitimate interests pursued by the Controller in the relevant sections of this document or by contacting the Data Controller.
When the processing is based on the consent of the User, the Data Controller may retain Personal Data for a longer period until such consent is withdrawn. Furthermore, the Data Controller may be obliged to retain Personal Data for a longer period, in compliance with a legal obligation or as ordered by an authority.
Personal Data will be retained for as long as strictly necessary and in any case, data will be stored for ten years, as required by the Italian Civil Code;
At the end of the retention period, Personal Data will be deleted. Therefore, at the end of this term, the right to access, cancellation, rectification and the right to Data portability can no longer be exercised.
 
Purposes of processing collected Data
The User Data is collected to allow the Controller to provide its Services, as well as for the following purposes: Statistics, Displaying content from external platforms, Contacting the User and Backend hosting and infrastructure.
For further detailed information on processing purposes and Personal Data actually relevant to each purpose, the User can refer to the relevant sections of this document.
Details on the processing of Personal Data
Personal Data is collected for the following purposes and using the following services:
• Contacting the User
Contact form (this website)
By filling out the contact form with their Data, the User consents to its use to respond to requests for information, quotes, or any other kind indicated by the form header.
Personal Data collected: email address, first name, last name, town or city, postal code, district, phone number and subject of the request.
• Reserved Area
We use your personal data in order to offer dedicated info through the private area accessible with userid and password.
Personal Data collected: first name, last name, email address
• Backend hosting and infrastructure
These services are designed to host and operate key components of this Application, making it possible to deliver this Application from a single platform. These platforms provide the Controller with a wide range of tools, such as analytical tools, for managing user registration, managing comments and databases, for e-commerce, processing payments, etc. The use of such tools involves the collection and processing of Personal Data.
This type of service also hosts Data and files that enable the operation of this website, allowing its distribution and providing a ready-to-use infrastructure for providing specific features of this website.
Some of these services work through geographically dislocated servers in different locations, making it difficult to determine the exact location in which the Personal Data is stored.
SMARTWEBSITE is a web platform with a hosting service provided by Stefana Web & Innovation by Stefana Stefano
Personal Data collected: Usage Data and various types of Data, as specified in the service privacy policy.
Place of processing: Italy, France -Privacy Policy
• Statistics
The services included in this section allow the Data Controller to monitor and analyse traffic data and are used to track User behaviour.
Google Analytics (Google Inc.)
Google Analytics is a web analysis service provided by Google Inc. ("Google"). Google uses the Personal Data collected for the purpose of tracking and analysing use of this website, compiling reports and sharing them with other services developed by Google.
Google may use the Personal Data to contextualise and customise the advertisements on its advertising network.
Personal Data collected: Cookies and usage Data.
Place of processing: United States -Privacy Policy-Opt Out. Privacy Shield participant.
• Displaying content from external platforms
This type of service allows you to view an interact with content hosted on external platforms directly from the website pages.
In the event that a service of this type is installed, it is possible that, even if the Users do not use the service, it collects traffic data relating to the pages on which it is installed.
Google Maps Widget (Google Inc.)
Google Maps is a map visualisation service managed by Google Inc. that allows this website to integrate such content within its pages.
Personal Data collected: Cookies and usage Data.
Place of processing: United States -Privacy Policy. Privacy Shield participant.
YouTube Video Widget (Google Inc.)
YouTube is a video content visualisation service managed by Google Inc. that allows this application to integrate such content within its pages.
Personal Data collected: Cookies and usage Data.
Place of processing: United States -Privacy Policy. Privacy Shield participant.
 
User Rights
Users may exercise certain rights with reference to the Data processed by the Data Controller.
In particular, Users have the right to:
• withdraw consent at any time. Users may withdraw consent given previously for the processing of their Personal Data. (art. 7 par.3 EU Regulation no. 2016/679)
• oppose the processing of their Personal Data. Users can oppose the processing of their Personal Data when it occurs on a legal basis other than consent. Further details on the right to opposition are indicated in the section below. (art. 21 of EU Regulation no. 2016/679)
• access their Data. Users have the right to obtain information on the Data being processed by the Data Controller, on certain aspects of the processing and to receive a copy of the Data processed. (art. 15 of EU Regulation no. 2016/679)
• verify and request rectification. Users can verify the correctness of their Personal Data and request that it be updated or corrected. 
(art. 16 of EU Regulation no. 2016/679)
• obtain the restriction of processing. When certain conditions are met, Users can request the restriction of the processing of their Personal Data. In this case, the Data Controller shall not process the Data for any purpose other than its retention. (art. 18 of EU Regulation no. 2016/679)
• obtain the cancellation or deletion of their Personal Data. When certain conditions are met, Users can request the cancellation of their Personal Data by the Data Controller .
 (art. 17 of EU Regulation no. 2016/679)
• receive their Personal Data or transfer it to another data controller (portability). Users have the right to receive their Data in a structured, commonly used and machine-readable format and, where technically feasible, have the right to transmit it without hindrance to another controller. This provision is applicable when the Data is  processed with automated tools and the processing is based on User consent, on a contract of which the User is a party or on related contractual measures. (art. 20 of EU Regulation no. 2016/679)
• lodge a complaint. Users can lodge a complaint with the relevant personal data protection authority or engage in legal proceedings. (art. 51 of EU Regulation no. 2016/679)
Details on the right to opposition
When Personal Data is processed in the public interest, in the exercise of public authority vested in the Controller or to pursue a legitimate interest of the Controller, Users have the right to oppose the processing for reasons related to their particular situation.
Users are reminded that, if their Data is processed for direct marketing purposes, they can oppose the processing without providing any reasons. To find out whether the Controller processes data for direct marketing purposes, Users can refer to the relevant sections of this document.
How to exercise User Rights
The aforementioned rights may be exercised by means of a written communication sent by email to the address of the Data Controller. Requests are made free of charge and processed by the Controller as soon as possible, in any case within one month.
Additional information on data processing
Legal defence
The Personal Data of Users may be used by the Controller in court or during the preliminary stages of the possible establishment of defence against abuse in the use of this website or related Services by the User.
Users declare themselves to be aware that the Data Controller may need to disclose their Personal Data by order of public authorities.
Specific information
At the request of the User, in addition to the information included in this privacy policy, this website may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.
System logs and maintenance
For needs relating to operation and maintenance, this website and any third party services used by it may collect System Logs, which are files that record interactions and may also contain Personal Data, such as the User IP address.
Information not included in this policy
Further information on the processing of Personal Data may be requested, at any time, from the Data Controller using the contact details.
Response to "Do Not Track" requests
This website does not support "Do Not Track" requests.
To find out if any used third-party services used support these requests, the User is invited to consult their respective privacy policies.
Links to third-party sites
This website includes links to other websites whose privacy regulations may differ from its own. If you send Personal Data to one of these sites, your User Data will be processed according to the privacy policy in force for these websites. We recommend that you read the privacy information carefully for each website visited.
Under 18s
We do not ask for or collect Personal Data from persons under the age of 18. Persons under the age of 18 must not enter information on this website or use our services. If you believe that your child, under the age of 18, has entered his or her Personal Data on this website, you may contact the Data Controller to request that this Personal Data be deleted.
Amendments to this privacy policy
The Data Controller reserves the right to make changes to this privacy policy at any time, notifying Users on this page and, if possible, on this website, as well as, where technically and legally feasible, sending notification to Users via the contact details held by the Controller. Therefore, please consult this page regularly, referring to the date of the last amendment indicated at the bottom of the page.
If the amendments concern processing whose legal basis is consent, the Controller will request the User's consent again, where necessary.
 
Definitions and legal references
Personal Data (or Data)
Personal data is any information that, directly or indirectly, also in connection with any other information, including a personal identification number, makes a natural person identified or identifiable.
Usage Data
This is information collected automatically via this website (including from third-party applications integrated into this website), including: IP addresses or domain names of the computers used by the User to connect to the website, the URI addresses (Uniform Resource Identifier), the time of request, the method used to forward the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server response (success, error, etc.) the country of origin, the characteristics of the browser and the operating system used by the visitor, the various temporal connotations of the visit (for example the time spent on each page) and the details of the route followed within the Application, with particular reference to the sequence of pages consulted, operating system parameters and the User’s IT environment.
User
The individual who uses this website and who, unless otherwise specified, is the Interested Party.
Interested Party
The natural person to whom the Personal Data refers.
Data Processor (or Processor)
The natural person, legal person, public administration and any other entity that processes personal data on behalf of the Controller, according to the provisions of this privacy policy.
Data Controller (or Controller)
The natural or legal person, public authority, service or other body that individually or together with others, determines the purposes and means of the personal data processing and the tools adopted, including the security measures relating to the operation and use of this website. The Data Controller, unless otherwise specified, is the owner of this website.
This website
The hardware or software tool through which Users’ Personal Data is collected and processed.
Service
The Service provided by this website as defined in the relative terms (where existing) on this website/application.
European Union (or EU)
Unless otherwise specified, any reference to the European Union made in this document is understood to include all current member states of the European Union and European Economic Area.
Cookies
Small portion of data stored on the User's device.
________________________________________
Legal references
This privacy statement is drawn up on the basis of multiple legislative systems, including articles 13 and 14 of Regulation (EU) 2016/679.
Unless otherwise specified, this privacy statement applies exclusively to this website.