Privacy Policy

Data Controller

CRGS SCARL Genome Research Center for Health

Via S. Allende, snc Baronissi University Campus,

University of Salerno — Department of Medicine, Surgery and Dentistry

"Medical School of Salerno" - 84081, Baronissi (SA)

City Chamber of Commerce

Fiscal Code/P. VAT: 05859580655 - REA: SA-479367

Legal representative: Roberto Parente

Owner's email address: direzione.centrogenomica@gmail.com

Types of Data collected

Among the Personal Data collected by this Website, independently or through third parties, there are: email; password; Tracking Tool; Usage Data; Data communicated while using the service; first name; surname; various types of Data; Billing information; Universally Unique Identifier (UUID); purchase history; device information; telephone number; physical address.

Complete details on each type of data collected are provided in the dedicated sections of this privacy policy or through specific information texts displayed before the data is collected.

Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically when using this Website.

Unless otherwise specified, all Data requested by this Website are mandatory. If the User refuses to communicate them, it may be impossible for this Website to provide the Service. In cases where this Website indicates some Data as optional, Users are free to refrain from communicating such Data, without this having any consequence on the availability of the Service or on its operation.

Users who have doubts about which Data are mandatory are encouraged to contact the Owner.

Any use of Cookies - or other tracking tools - by this Website or by the owners of third-party services used by this Website, unless otherwise specified, has the purpose of providing the Service requested by the User, in addition to the additional purposes described in this document and in the Cookie Policy, if available.

The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this Website and guarantees that he has the right to communicate or disseminate them, freeing the Owner from any liability towards third parties.

Method and place of processing of the collected Data

Methods of treatment

The Data Controller adopts the appropriate security measures to prevent unauthorized access, disclosure, modification or destruction of Personal Data.

The processing is carried out using IT and/or telematic tools, with organizational methods and with logic strictly related to the purposes indicated. In addition to the Owner, in some cases, other subjects involved in the organization of this Website (administrative, commercial, marketing, legal, system administrators) or external subjects (such as third party technical service providers, postal couriers) may have access to the Data. , hosting providers, IT companies, communication agencies) also appointed, if necessary, as Data Processors by the Data Controller. The updated list of Managers can always be requested from the Data Controller.

Legal basis of the treatment

The Data Controller processes Personal Data relating to the User in the event that one of the following conditions exists:

  • the User has given consent for one or more specific purposes; Note: in some jurisdictions, the Data Controller may be authorized to process Personal Data without the User's consent or another of the legal bases specified below, as long as the User does not object ("opt-out") to such treatment. However, this is not applicable if the processing of Personal Data is governed by European legislation on the protection of Personal Data;
  • the processing is necessary for the execution of a contract with the User and/or for the execution of pre-contractual measures;
  • the processing is necessary for the execution of a contract with the User and/or for the execution of pre-contractual measures;
  • the treatment is necessary for the execution of a task of public interest or for the exercise of public powers with which the Data Controller is invested;
  • the processing is necessary for the pursuit of the legitimate interest of the Data Controller or of third parties.

However, it is always possible to ask the Data Controller to clarify the concrete legal basis of each treatment and in particular to specify whether the treatment is based on the law, provided for by a contract or necessary to conclude a contract.

Place

The Data is processed at the Data Controller's operating offices and in any other place where the parties involved in the processing are located. For more information, contact the Owner.

The User's Personal Data may be transferred to a country other than the one in which the User is located. To obtain further information on the place of processing, the User can refer to the section relating to the details on the processing of Personal Data.

The User has the right to obtain information regarding the legal basis for the transfer of Data outside the European Union or to an international organization governed by public international law or constituted by two or more countries, such as for example the UN, as well as regarding the security measures adopted by the Data Controller to protect the Data.

The User can verify whether one of the transfers described above takes place by examining the section of this document relating to the details on the processing of Personal Data or request information from the Data Controller by contacting him at the details indicated at the beginning.

Storage period

The Data are processed and stored for the time required by the purposes for which they were collected.

Therefore:

  • Personal Data collected for purposes related to the execution of a contract between the Owner and the User will be retained until the execution of this contract is completed.
  • Personal Data collected for purposes attributable to the legitimate interest of the Data Controller will be retained until such interest is satisfied. The User can obtain further information regarding the legitimate interest pursued by the Data Controller in the relevant sections of this document or by contacting the Data Controller.

When the treatment is based on the User's consent, the Owner can keep the Personal Data for longer until said consent is revoked. Furthermore, the Data Controller may be obliged to keep Personal Data for a longer period in compliance with a legal obligation or by order of an authority.

At the end of the retention period, the Personal Data will be deleted. Therefore, upon expiry of this term, the right of access, cancellation, rectification and the right to data portability can no longer be exercised.

Purpose of the processing of the collected data

The User's Data is collected to allow the Owner to provide the Service, fulfill legal obligations, respond to requests or executive actions, protect its rights and interests (or those of Users or third parties), identify any malicious activity or fraudulent, as well as for the following purposes: Contacting the User, Registration and authentication provided directly by this Website, Access to accounts on third-party services, Displaying content from external platforms, Management of support and contact requests, Hosting and backend infrastructure , Remarketing and behavioral targeting, Statistics, Infrastructure monitoring, Payment management, Commercial affiliation, Tag management, Data transfer outside the EU, Collection of privacy preferences, Interaction with live chat platforms, Management of User database, Interaction with data collection platforms and other third parties, Registration and a authentication, Management of web conferences and online telephony, Management of contacts and sending of messages, Data Linking, Interaction with support and feedback platforms, Collection of information, Advertising, Optimization and distribution of traffic and Internal processing tools.

To obtain detailed information on the purposes of the processing and on the Personal Data processed for each purpose, the User can refer to the "Details on the processing of Personal Data" section.

Details on the processing of Personal Data

Personal Data is collected for the following purposes and using the following services:

Contact the user

Mailing list or newsletter (this Website)

By registering with the mailing list or newsletter, the User's email address is automatically added to a list of contacts to which email messages containing information, including commercial and promotional information, relating to this Website may be sent. User's email address could also be added to this list as a result of registering on this Website or after making a purchase.

  • Personal Data processed: email.
  • Legal basis for processing: Consent.
  • Category of personal information collected pursuant to the CCPA: Identifiers.
  • This type of processing constitutes: a sale under the VCDPA

Field for the telephone number

By adding their telephone number in the field available on the invoice page, the User will be contacted in the event of billing problems related to the purchase of the solutions offered by iubenda. The telephone number may also be used to provide support in setting up the purchased solution.

  • Personal Data processed: telephone number.
  • Legal basis for processing: Contract.

This type of treatment constitutes:

  • a sale under the VCDPA
  • a share under the CCPA
  • targeted advertising according to the VCDPA

Hosting ed infrastruttura backend

This type of service has the function of hosting Data and files that allow this Website to function, allow its distribution and provide a ready-to-use infrastructure to deliver specific functions of this Website.

Some of the services listed below, if any, may operate on geographically distributed servers, making it difficult to determine the actual location where Personal Data is stored.

Webflow (Webflow Inc.)

Webflow is a web design and hosting platform that offers users the ability to build and host websites without the need for coding knowledge. With Webflow, users can design their website using a drag-and-drop interface and later publish the site to their hosting platform. Webflow also offers CMS integration features, allowing you to manage site content quickly and easily. In summary, Webflow is an all-in-one solution for website design and hosting.

Transfer of Data outside the EU

The Data Controller may transfer the Personal Data collected within the EU to third countries (i.e. all countries not belonging to the EU) only in compliance with a specific legal basis. Therefore, such Data transfers are performed according to one of the legal bases described below.

The User can request information from the Owner regarding the applicable legal basis that is actually applicable to each individual service.

Data transfer to countries that guarantee European standards

When this is the legal basis, the transfer of Personal Data from the EU to third countries takes place on the basis of an adequacy decision adopted by the European Commission. The European Commission adopts adequacy decisions with reference to individual third countries that it deems to guarantee a level of protection of Personal Data comparable to that provided for by the European legislation on the protection of Personal Data. The User can view the updated list of adequacy decisions on the European Commission website.

  • Personal Data processed: various types of Data.
  • Category of personal information collected pursuant to the CCPA: Internet information.

Transfer to third countries on the basis of standard contractual clauses

When this is the legal basis, the transfer of Personal Data from the EU to third countries takes place on the basis of standard personal data protection clauses adopted by the European Commission.

In such cases, the recipients of the Data have agreed to process the Personal Data in accordance with the levels of protection provided for by EU legislation. Users can request further information by contacting the Owner at the contact details indicated in this document.

  • Personal Data processed: various types of Data.
  • Category of personal information collected pursuant to the CCPA: Internet information.

Learn how to opt out of interest-based advertising

In addition to any opt-out function provided by any of the services listed in this document, Users can read more about how to disable interest-based advertising in the appropriate section of the Cookie Policy.

User rights

Users can exercise certain rights with reference to the Data processed by the Owner.

In particular, the User has the right to:

  • withdraw consent at any time. The User can revoke the previously expressed consent to the processing of his Personal Data.
  • oppose the processing of their Data. The User can object to the processing of their Data when it occurs on a legal basis other than consent. Further details on the right to object are set out in the section below.
  • access their Data. The User has the right to obtain information on the Data processed by the Data Controller, on certain aspects of the processing and to receive a copy of the Data processed.
  • check and ask for rectification. The User can verify the correctness of his Data and request its updating or correction.
  • obtain the limitation of the treatment. When certain conditions are met, the User can request the limitation of the processing of their Data. In this case, the Data Controller will not process the Data for any other purpose than their conservation.
  • obtain the cancellation or removal of their Personal Data. When certain conditions are met, the User can request the cancellation of their Data by the Owner.
  • receive their data or have them transferred to another owner. The User has the right to receive their Data in a structured format, commonly used and readable by an automatic device and, where technically feasible, to obtain its transfer without obstacles to another holder. This provision is applicable when the Data are processed with automated tools and the processing is based on the User's consent, on a contract of which the User is a party or on contractual measures connected to it.
  • propose a complaint. The User can lodge a complaint with the competent personal data protection supervisory authority or take legal action.

Details on the right to object

When Personal Data is processed in the public interest, in the exercise of public powers vested in the Data Controller or to pursue a legitimate interest of the Data Controller, Users have the right to object to the processing for reasons connected with their particular situation.

Users are reminded that, should their Data be processed for direct marketing purposes, they may object to the processing without providing any reason. To find out if the Data Controller processes data for direct marketing purposes, Users can refer to the respective sections of this document.

How to exercise your rights

To exercise the User's rights, Users can direct a request to the contact details of the Owner indicated in this document. Requests are filed free of charge and processed by the Data Controller as soon as possible, in any case within a month.

Learn more about treatment

Defense in court

The User's Personal Data may be used by the Owner in court or in the preparatory stages for its eventual establishment for the defense against abuse in the use of this Website or related Services by the User.

The User declares to be aware that the Owner may be obliged to disclose the Data by order of the public authorities.

Specific information

At the request of the User, in addition to the information contained in this privacy policy, this Website may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.

System and maintenance logs

For needs related to operation and maintenance, this Website and any third party services used by it may collect system logs, i.e. files that record the interactions and which may also contain Personal Data, such as the User's IP address.

Information not contained in this policy

Further information in relation to the processing of Personal Data may be requested at any time from the Data Controller using the contact details.

Response to “Do Not Track” requests

This Website does not support “Do Not Track” requests.

To find out if any third-party services used support them, the User is invited to consult the respective privacy policies.

Changes to this privacy policy

The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Website as well as, if technically and legally feasible, by sending a notification to Users via one of the contact information you have. Therefore, please consult this page frequently, referring to the date of the last modification indicated at the bottom.

If the changes concern treatments whose legal basis is consent, the Data Controller will collect the User's consent again, if necessary.

Definitions and legal references

Personal Data (or Data)

Personal data is any information which, directly or indirectly, also in connection with any other information, including a personal identification number, makes a natural person identified or identifiable.

Usage Data

This is information collected automatically through this Website (also by third-party applications integrated into this Website), including: the IP addresses or domain names of the computers used by the User who connects with this Website, the addresses in URI (Uniform Resource Identifier) ​​notation, the time of the request, the method used to forward the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response from the server (successful, error, etc. .) the country of origin, the characteristics of the browser and operating system used by the visitor, the various temporal connotations of the visit (for example the time spent on each page) and the details relating to the itinerary followed within the Application, with particular reference to the sequence of the pages consulted, to the parameters relating to the operating system and the IT environment of the User.

User

The individual who uses this Website who, unless otherwise specified, coincides with the interested party.

Interested party

The natural person to whom the Personal Data refer.

Data Processor (or Manager)

The natural person, legal person, public administration and any other body that processes personal data on behalf of the Data Controller, according to what is set out in this privacy policy.

Data Controller (or Owner)

The natural or legal person, public authority, service or other body which, individually or together with others, determines the purposes and means of processing personal data and the tools adopted, including the security measures relating to the functioning and use of this Website. The Data Controller, unless otherwise specified, is the owner of this Website.

This Website (or this Application)

The hardware or software tool through which the Personal Data of Users are collected and processed.

Service

The Service provided by this Website as described in the relative terms (if available) and on this site/application.

European Union (or EU)

Unless otherwise specified, any reference to the European Union contained in this document is intended to extend to all current member states of the European Union and the European Economic Area.

Cookie

Cookies are Tracking Tools that consist of small portions of data stored in the User's browser.

Tracking Tool

Tracker means any technology - e.g. Cookies, unique identifiers, web beacons, embedded scripts, e-tags and fingerprinting - which allows tracking Users, for example by collecting or saving information on the User's device.

Legal references

This privacy statement has been prepared on the basis of multiple legislative systems, including articles 13 and 14 of Regulation (EU) 2016/679.

Unless otherwise specified, this privacy statement applies exclusively to this Website.

Translated with Linguana