In accordance with the Italian Law Legislative Decree 196/2003 ("Code") and articles 13 and 14 of the General Data Protection Regulation 2016/679 ("GDPR"), anyone who processes personal data ("Data") must provide the data subject with adequate information and, in certain cases, obtain consent for the processing of their Data. As the data subject, we hereby inform you of the following:
This application directly collects the following types of personal data from the data subject: surname, first name, mobile number, email address, type of pathology/disorder, and photographs of the same person. Common personal data and those related to the data subject's health and lifestyle are collected/entered directly (art. 13 of the GDPR) by the data subject. The processing of the Data is carried out at the request of the data subject in order to enable the Data Controller to fulfill the following purposes: Sending diagnoses through the specific application.
The processing of the Data for these purposes may be carried out using both automated and non-automated methods, with strict adherence to the purposes and in compliance with the rules of confidentiality and security provided by law. The storage period for all types of personal data is 122 months, always in compliance with the terms of the law and privacy regulations.
The Data may also be processed on behalf of Medchange SRL by employees, professionals, and appointed companies that provide specific processing services or complementary activities to ours, necessary for the execution of our operations or services, under the control and responsibility of the Data Controller in accordance with the instructions provided or authorized by the Data Controller.
The Data is collected lawfully and necessary directly from the data subject, who provides or authorizes the collection.
The confidentiality of the collected personal data is protected by professional secrecy. Medchange SRL may communicate the personal data to external entities or professionals who will process them as autonomous data controllers or on behalf of the Healthcare Facility itself, to provide strictly necessary services connected and instrumental to its activities. The Data will not be disclosed to third parties.
Considering the existence of telematic, electronic, or correspondence connections, the Data may be made available abroad, even outside the countries belonging to the European Union.
Articles 15, 16, 17, 18, 19, 20, and 21 of the GDPR recognize numerous rights to the data subject, which we invite you to carefully consider. We briefly remind you that the data subject has the right to obtain information about:
The data subject has the right to:
The data subject has the right to object, in whole or in part, for legitimate reasons to the processing of personal data concerning them, even if pertinent to the purpose of collection.
In order to exercise their rights (Art. 7 of the Code and Art. 12 of the GDPR), the data subject may contact Medchange SRL. The data subject may also file a complaint with the competent supervisory authority in accordance with Article 77 of the GDPR, if deemed necessary.
The Data Controller can be contacted at Medchange, using the contact details provided at the beginning of this information notice.