This website collects some personal data from its users. This notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the Regulation or GDPR) and to Italian Legislative Decree no. 196 of 30 June 2003, as amended by Legislative Decree no. 101 of 10 August 2018 (the Code). The document can be printed using the browser print command.
1. Data controller
The data controller is GD Tecnologie Interdisciplinari Farmaceutiche S.r.l., with registered office at Via Augusto Gaudenzi 29, 00163 Rome (RM), Italy, VAT no. 01356041002, tax code 05098680589, telephone +39 06.66418170, email address web@gditalia.biz.
The Controller has not appointed a data protection officer, as the conditions set out in Article 37(1) of the Regulation do not apply. For any matter relating to the processing of personal data and for the exercise of the rights referred to in section 13, users may contact the Controller directly at the contact details given above.
2. Subject matter and scope
This notice concerns the processing of personal data carried out by the Controller through the website www.gditalia.biz, in its Italian and English versions, including the product pages, the blog and the contact and newsletter subscription forms.
The notice does not cover third-party websites that may be reached through links on this site, for which the Controller is not responsible, nor the social platforms on which the Controller is present. Personal data that users communicate to the Controller through such platforms is processed by the Controller as an independent controller in order to respond to the communication received, while the operation of the platform is governed by the notice of its respective operator.
3. Categories of personal data processed
The Controller processes two categories of data, distinguished by how they are acquired.
Data provided voluntarily by the user. Through the forms on the site the following are collected: name, email address, the category of interest optionally selected and any free text entered by the user.
Data collected automatically during browsing. These are the IP address, usage data (URI addresses of the resources requested, time of the request, method used, size and status of the server response, path followed within the site), browser and device information, the approximate location inferred from the IP address at city level and the technical session identifiers described in the Cookie Policy.
The site does not offer online sales and neither requests nor collects payment data.
4. Data capable of revealing health status
The contact form allows users to indicate the area in which they wish to be assisted, choosing among those into which the Controller’s offering is organised, some of which relate to physiological or pathological conditions: these include, by way of example, dry and atopic skin, trichology, women’s wellbeing, gut microbiota and functional metabolism.
Selecting one of these areas, being associated with the user’s identifying data, may reveal information concerning health status and therefore constitutes a special category of personal data pursuant to Article 9(1) of the Regulation. The same applies to any information users choose to enter in the free text field.
Providing this data is optional and does not affect the ability to contact the Controller. Where provided, it is processed solely on the basis of the data subject’s explicit consent pursuant to Article 9(2)(a) of the Regulation, collected by means of a dedicated checkbox, separate from any other consent and withdrawable at any time without prejudice to the lawfulness of processing carried out before withdrawal.
The Controller does not request diagnoses, medical reports, prescriptions, ongoing treatments or other clinical data, and invites users not to enter any in the free text field. Should such information nevertheless be provided spontaneously, it is used solely to respond to the request and deleted once the request has been dealt with.
The data covered by this section is never used for marketing purposes, does not feed the newsletter contact list and is not used to build user profiles.
5. Purposes of processing, legal bases and retention periods
The Controller processes users’ personal data for the purposes set out in the table below, each with its own legal basis and retention period. At the end of the period indicated, the data is erased or irreversibly anonymised.
| Purpose | Data processed | Legal basis | Retention |
|---|---|---|---|
| Responding to requests for information, advice or of any other nature sent through the forms on the site | Name, email address, category of interest, free text | Art. 6(1)(b) of the Regulation: performance of pre-contractual measures taken at the data subject’s request | 36 months from closure of the request |
| Processing the category of interest and the free text where they reveal health status, within the limits of section 4 | Category of interest, free text | Art. 9(2)(a) of the Regulation: explicit consent of the data subject |
6. No automated decision-making
Through this site the Controller carries out no automated decision-making within the meaning of Article 22 of the Regulation, nor any profiling of users. Requests received through the forms are examined by the Controller’s staff.
7. Mandatory or optional nature of providing data
Providing a name and email address is necessary to enable the Controller to respond to the request: without them a reply is not possible. Providing the category of interest and the free text is optional. Consent to newsletter subscription is likewise optional, and refusing it in no way affects the ability to send a contact request or to receive a reply.
8. Data recipients and processors
Personal data may be accessed, within the limits of their respective duties and on the basis of specific instructions, by the Controller’s employees and collaborators authorised to process it. The Controller also uses the suppliers listed in the table below, appointed as data processors pursuant to Article 28 of the Regulation.
| Supplier | Service provided | Place of processing |
|---|---|---|
| Vercel Inc. | Website hosting and delivery; statistical and performance measurement services | European Union for website hosting; United States for measurement services and service administration |
| Supabase, Inc. | Database and storage of site content and of data collected through the forms | European Union (Frankfurt, Germany) |
| Sendinblue SAS (Brevo) | Contact list management and newsletter sending | European Union (France) |
| Functional Software, Inc. (Sentry) | Application error monitoring | United States |
Personal data may also be disclosed to public authorities, which process it as independent controllers, where this is required by a legal obligation or requested in the course of an investigation or proceedings. The Controller does not disclose users’ data to third parties for marketing purposes, and neither transfers nor sells it. An up-to-date list of data processors may be requested at any time at the contact details given in section 1.
9. Transfers of data to third countries
The services indicated in the table in section 8 as processed in the United States involve a transfer of personal data outside the European Economic Area. Such transfers are carried out on the basis of the standard contractual clauses adopted by the European Commission by implementing decision (EU) 2021/914 of 4 June 2021, which constitute an appropriate safeguard pursuant to Article 46(2)(c) of the Regulation, supplemented where necessary by the additional technical, organisational and contractual measures identified by the Controller following its transfer impact assessment.
A copy of the clauses applied and information on the supplementary measures adopted may be requested at the contact details given in section 1.
10. Processing methods and security measures
Processing is carried out using computer and telematic tools, with organisational methods and logic strictly related to the stated purposes. The Controller adopts technical and organisational measures appropriate under Article 32 of the Regulation, including encryption of communications between the user’s browser and the site, restriction of database access to authorised personnel only by means of individual credentials, logging of administrative access, periodic backups and periodic review of the adequacy of the measures adopted.
11. Minors
The site is not intended for children under fourteen and the forms on it must not be completed by children under that age without the consent of the holder of parental responsibility. Article 2-quinquies of the Code, implementing Article 8(1) of the Regulation, sets fourteen as the age from which a minor may validly consent to the processing of their personal data in relation to the direct offer of information society services, while for younger children processing based on consent is lawful only if given by the holder of parental responsibility.
The Controller erases without delay any personal data it establishes to have been provided by children under fourteen in the absence of such consent.
12. System logs
For operational and maintenance purposes, the site and the third-party services it uses record system logs, that is files documenting interactions which may also contain personal data such as the IP address. These records are used solely for technical and security purposes and are retained for the period indicated in the table in section 5.
13. Rights of the data subject
Users have the right to obtain from the Controller access to their personal data and a copy of it (Article 15 of the Regulation), the rectification of inaccurate data and the completion of incomplete data (Article 16), the erasure of data in the cases provided for (Article 17), the restriction of processing (Article 18) and receipt of the data in a structured, commonly used and machine-readable format, with its transmission to another controller where technically feasible (Article 20).
Users also have the right to object to processing based on the Controller’s legitimate interest, on grounds relating to their particular situation (Article 21(1)). Where data is processed for direct marketing purposes, the objection may be exercised at any time, free of charge and without any need to give reasons (Article 21(2)); the unsubscribe link included in every message received is sufficient for this purpose.
Any consent given may be withdrawn at any time pursuant to Article 7(3) of the Regulation, without prejudice to the lawfulness of processing carried out before withdrawal.
Requests may be addressed to the Controller at web@gditalia.biz or at the contact details given in section 1. Exercising these rights is free of charge and the Controller replies without undue delay and in any case within one month of receiving the request, a period that may be extended by a further two months in particularly complex cases, informing the data subject within the first month, pursuant to Article 12(3) of the Regulation.
Users who consider that the processing of their data infringes the applicable rules have the right to lodge a complaint with the competent supervisory authority, in Italy the Garante per la protezione dei dati personali (Article 77 of the Regulation), and to bring proceedings before the courts (Article 79).
14. Cookies and other trackers
Information on the cookies and other trackers used by the site, their purposes, their duration and how users may give, change or withdraw their consent is set out in the Cookie Policy, available at www.gditalia.biz/cookie-policy and always reachable from the footer of every page of the site.
15. Changes to this notice
The Controller reserves the right to amend this notice at any time, giving notice on this page. Each version is identified by the revision number and the last update date shown at the top of the document. Where the changes concern processing whose legal basis is consent, the Controller collects the data subject’s consent again before the changes take effect.
16. Definitions
Personal data. Any information that, directly or indirectly, including in connection with other information, makes a natural person identified or identifiable.
Special categories of personal data. The data referred to in Article 9(1) of the Regulation, including data concerning health.
Data subject. The natural person to whom the personal data relates.
Data controller. The party that determines the purposes and means of processing, including the security measures.
Data processor. The party that processes personal data on behalf of the Controller, on the basis of an appointment compliant with Article 28 of the Regulation.
Tracker. Any technology that allows information to be stored on the user’s device or already stored information to be accessed, or that otherwise allows the user to be tracked, including cookies, unique identifiers, embedded scripts, pixels, browser local storage technologies and device fingerprinting techniques.