PRIVACY NOTICE UNDER GDPR EU 2016/679
Welcome to our website. Please carefully read our Notice, which applies whether you access the website and simply decide to browse through it, or whether you use its advanced services. This notice is provided under the European Regulation on the Protection of Personal Data (General Data Protection Regulation, also GDPR) 2016/679, which provides for the protection of individuals with regard to the processing of personal data. According to the indicated regulations, this processing will be based on the principles of fairness, lawfulness, transparency, and protection of your privacy and rights.
Data Controller
SS 16 Adriatica
Lecce—Maglie km 978
Corigliano d’Otranto (LE)
Italy
+39 0836 583 339
info@casalucihealthcare.com
Types of Data Collected
Among the Personal Data collected, either independently or through third parties, are: Cookies, Usage Data, email, various types of Data, phone number, country, city, province. Complete details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific informative texts displayed before the data is collected.
Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically during the use of the portal.
Unless otherwise specified, all requested Data is mandatory. If the User refuses to provide them, it may be impossible to provide the Service. In cases where the portal indicates some Data as optional, Users are free to refrain from communicating such Data, without this having any consequence on the availability or operation of the Service.
Users who have doubts about which Data are mandatory are encouraged to contact the Data Controller.
The possible use of Cookies – or other tracking tools – by the portal or by the third-party service providers used by the portal, unless otherwise specified, is for the purpose of providing the Service requested by the User, in addition to any other purposes described in this document and in the Cookie Policy, if available. The User assumes responsibility for the Personal Data of third parties obtained, published or shared through the portal and guarantees that he/she has the right to communicate or disseminate them, freeing the Data Controller from any responsibility towards third parties.
Methods and Place of Processing of Collected Data
Processing methods
The Data Controller adopts appropriate security measures to prevent unauthorized access, disclosure, alteration, or destruction of Personal Data. Processing is carried out using computers and/or IT-enabled tools, with organizational methods and logics strictly related to the purposes indicated. In addition to the Data Controller, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of the site (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Data Controller. The updated list of these parties may be requested from the Data Controller at any time.
Legal basis of processing
The Data Controller processes Personal Data relating to the User if one of the following conditions exists:
the User has given consent for one or more specific purposes; Note: in some jurisdictions, the Data Controller may be entitled to process Personal Data without the User’s consent or another of the legal bases specified below, until the User objects (“opt-out”) to such processing. However, this is not applicable if the processing of Personal Data is regulated by European legislation on the protection of Personal Data;
- processing is necessary for the performance of a contract with the User and/or for the performance of pre-contractual measures;
- processing is necessary to comply with a legal obligation to which the Data Controller is subject;
- processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
- processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party.
However, it is always possible to request the Data Controller to clarify the concrete legal basis of each processing and in particular to specify whether the processing is based on the law, provided for by a contract, or necessary to conclude a contract.
Location
The Data is processed at the Data Controller’s operating offices and in any other place where the parties involved in the processing are located. For further information, please contact the Data Controller.
The User’s Personal Data may be transferred to a country other than the one in which the User is located. To obtain further information on the location of the processing, the User can refer to the section containing details on the processing of Personal Data. The User has the right to obtain information regarding the legal basis for the transfer of Data outside the European Union or to an international public law organization or consisting of two or more countries, such as the UN, as well as regarding the security measures adopted by the Data Controller to protect the Data. In the event that one of the transfers described above takes place, the User can refer to the respective sections of this document or request information from the Data Controller using the contact details provided at the beginning.
Storage period
The Data is processed and stored for the time required by the purposes for which it was collected. Therefore:
Personal Data collected for purposes related to the performance of a contract between the Data Controller and the User will be retained until the performance of such contract is completed.
Personal Data collected for purposes attributable to the legitimate interest of the Data Controller will be retained until such interest is satisfied. The User can obtain further information regarding the legitimate interest pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.
When processing is based on the User’s consent, the Data Controller may retain Personal Data for a longer period until such consent is revoked. Furthermore, the Data Controller may be obliged to retain Personal Data for a longer period in compliance with a legal obligation or by order of an authority. At the end of the retention period, Personal Data will be deleted.
Therefore, upon expiration of this period, the right to access, delete, correct, and the right to data portability cannot be exercised.
Purposes of Processing of Collected Data
The User’s Data is collected to allow the Data Controller to provide its Services, as well as for the following purposes: Statistics, Remarketing and behavioral targeting, Management of support and contact requests, Performance testing of content and features (A/B testing), Contacting the User, Social features, User database management, Tag management, Heat mapping and session recording, Hosting and backend infrastructure, Interaction with online survey platforms, Interaction with data collection platforms and other third parties, Monitoring of infrastructure, and Contact management and message sending. For further detailed information on the purposes of processing and the Personal Data specifically relevant to each purpose, the User can refer to the relevant sections of this document.
Details on the processing of Personal Data
Personal Data is collected for the following purposes and using the following services:
- Contacting the User
- Social features
- Contact management and message sending
This type of service allows the management of a database of email contacts, phone contacts, or contacts of any other kind, used to communicate with the User. These services may also allow the collection of data concerning the date and time when the messages are viewed by the User, as well as the User’s interaction with them, such as information about clicks on links included in the messages.
Management of support and contact requests
This type of service allows the portal to manage support and contact requests received via email or through other tools, such as the contact form. The Personal Data processed depends on the information provided by the User within the messages and the tool used for communication (e.g., email address).
Hosting and backend infrastructure
This type of service has the function of hosting Data and files that enable the portal to function, allow for its distribution, and provide a ready-to-use infrastructure to deliver specific features of the portal. Some of these services operate through servers located geographically in different places, making it difficult to determine the exact location where the Personal Data is stored.
Interaction with data collection platforms and other third parties
This type of service allows Users to interact with data collection platforms or other services directly from the pages of the portal for the purpose of saving and reusing data. In the event that one of these services is installed, it may still collect Usage Data related to the pages on which it is installed, even if Users do not use the service.
Monitoring of infrastructure
This type of service allows the portal to monitor the use and behavior of its components, for the purpose of improving performance and functionality, maintenance, or problem resolution.
The Personal Data processed depends on the characteristics and manner of implementation of these services, which by their nature filter the activity of the portal.
Statistics
The services contained in this section allow the Data Controller to monitor and analyze traffic data and are used to keep track of User behavior.
Google Analytics (Google Ireland Limited)
Google Analytics is a web analytics service provided by Google Ireland Limited. Google uses Personal Data collected for the purpose of tracking and examining the use of the portal, compiling reports, and sharing them with other services developed by Google. Google may use Personal Data to contextualize and personalize the ads of its advertising network.
Facebook Analytics for Apps (Facebook, Inc.)
Facebook Analytics for Apps is a statistics service provided by Facebook, Inc. Personal Data collected: Usage Data and various types of Data as specified in the privacy policy of the service.
Unique device identification
The portal may track Users by storing a unique identification code of their device, for statistical purposes or to retain User preferences.
User’s Rights
Users can exercise certain rights with reference to the Data processed by the Data Controller. In particular, the User has the right to:
- withdraw consent at any time. The User can withdraw consent to the processing of their Personal Data previously expressed.
- object to the processing of their Data. The User can object to the processing of their Data when it occurs on a legal basis other than consent. Further details on the right to object are set out in the section below.
- access their Data. The User has the right to obtain information about the Data processed by the Data Controller, on certain aspects of the processing, and to receive a copy of the Data processed.
- check and ask for rectification. The User can verify the correctness of their Data and request its updating or correction.
- obtain the limitation of the processing. When certain conditions are met, the User may request the limitation of the processing of their Data. In this case, the Data Controller will not process the Data for any purpose other than their retention.
- obtain the erasure or removal of their Personal Data. When certain conditions are met, the User may request the erasure of their Data by the Data Controller.
- receive their Data or have it transferred to another controller. The User has the right to receive their Data in a structured, commonly used, and machine-readable format and, where technically feasible, to have it transferred without hindrance to another controller. This provision is applicable when the Data is processed by automated means and the processing is based on the User’s consent, on a contract to which the User is a party, or on contractual measures related thereto.
- lodge a complaint. The User may lodge a complaint with the competent data protection supervisory authority or take action in court.
Details on the right to object
When Personal Data is processed in the public interest, in the exercise of official authority vested in the Data Controller, or to pursue a legitimate interest of the Data Controller, Users have the right to object to the processing for reasons related to their particular situation. Users are reminded that, if their Data is processed for direct marketing purposes, they can object to the processing without providing any justification. To find out whether the Data Controller processes data for direct marketing purposes, Users can refer to the relevant sections of this document.
How to exercise rights
To exercise the rights of the User, Users may address a request to the contact details of the Data Controller indicated in this document. Requests are filed free of charge and processed by the Data Controller as soon as possible, in any case within one month.