Privacy Notice on the Processing of Personal Data (Privacy Code – Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 – EU Regulation 679/2016 – Art. 13)
Medici in Famiglia S.r.l. Impresa Sociale, with registered office at Corso Lodi, 13 – 20135 Milano (MI), VAT No.: 08372680960 (hereinafter, “Controller”), acting as Data Controller, hereby informs you pursuant to Legislative Decree 196/2003, as amended by Legislative Decree 101/2018 (hereinafter, “Privacy Code”) and Art. 13 of EU Regulation No. 2016/679 (hereinafter, “GDPR”) that your data will be processed in accordance with principles of fairness, lawfulness, and transparency, in compliance with the purposes and methods set out below, collecting them to the extent strictly necessary and accurate for the processing.
0. Preamble
This privacy notice is provided as a supplement to what is already set out in the Privacy Policy of the application called Mindy Map, to which reference is made for further information on the processing of users’ personal data.
1. Categories of Data Processed and Data Subjects
We collect and process the personal data of users who use Mindy Map, as data subjects. The App is designed for users such as, by way of example and not exhaustively:
- parents and caregivers;
- educators and teachers;
- social workers;
- healthcare personnel.
The categories of personal data processed are:
- identifying, personal, and contact data: first name, last name, tax identification code, gender, residential address, date and place of birth, email address, telephone number;
- number of children;
- possible data of minors: date of birth.
2. Purposes of Processing and Legal Bases
Your personal data are processed for the following purposes:
a) to fulfil pre-contractual and contractual obligations arising from the relationship with you, pursuant to Art. 6(1)(b) GDPR:
- to enable access to and use of the Mindy Map application;
- to allow you to register an account;
- to perform the requested service or activity;
- to manage any disputes that may arise between us;
- to assist you and respond to your requests.
b) to fulfil legal or regulatory obligations pursuant to Art. 6(1)(c) GDPR:
- obligations imposed by law, regulation, or EU legislation;
- to respond to an official request from a public or judicial authority;
- to fulfil tax and accounting obligations.
c) to pursue our legitimate interest, pursuant to Art. 6(1)(f) GDPR:
- to implement and develop our products and services;
- to defend our legal rights and interests in legal proceedings;
- IT management, including infrastructure management and IT security.
d) subject to your express and prior consent, pursuant to Art. 6(1)(a) GDPR:
- to send you – including via email, SMS, and MMS – advertising material, newsletters, and communications with informational and/or promotional content relating to the Controller’s activities or topics of interest to app users, unless you object via the unsubscribe links found at the bottom of our communications. Consent is free and optional and may be withdrawn at any time [Direct Marketing];
- to carry out profiling activities, using information relating to the number of children and their dates of birth, aimed at analysing your potential interests or preferences for participation (e.g. types of workshops or courses selected) in order to send you communications, invitations to events, and activities that are genuinely relevant and useful for your family. This activity allows us to avoid sending proposals that are not aligned with children’s developmental stages or your needs as a parent [Profiling];
- to process personal data of minors over whom you exercise parental authority, solely for the purpose of personalising our communications, as described in point 2.d.2) above [Processing of Data of Minors].
3. Nature of Data Provision and Consequences of Refusal
The provision of data for the purposes referred to in points 2.a), 2.b), and 2.c) is mandatory for everything required by legal obligations and obligations arising from the membership relationship; therefore, any refusal to provide them, in whole or in part, may result in the Controller’s inability to carry out such activities.
The provision of data for the purposes referred to in points 2.d.1), 2.d.2), and 2.d.3) is optional and will have no consequence on the performance of the services offered by the Controller.
4. Processing Methods
The processing of your personal data is carried out through the operations referred to in Art. 4(2) GDPR, namely: collection, recording, organisation, storage, consultation, processing, modification, selection, extraction, comparison, use, interconnection, blocking, communication, erasure, and destruction of data. Your personal data are subject to both paper-based and electronic and/or automated processing.
5. Access to and Disclosure of Data
Your data may be made accessible for the purposes referred to in points 2.a), 2.b), 2.c) and, subject to your express consent, 2.d.1), 2.d.2), and 2.d.3), to various categories of recipients, such as:
- employees and collaborators of the Controller, where applicable, in their capacity as authorised persons or processors and/or system administrators;
- third-party companies (by way of example, consultants, business partners, companies/individuals engaged by the Controller for data archiving activities, IT consultancy firms, and, more generally, companies performing outsourced activities on behalf of the Controller). Such parties may perform these activities as independent data controllers or external data processors.
The Controller may also disclose your data for the above purposes to:
- Supervisory bodies, judicial authorities, law enforcement agencies, public bodies, and all those parties to whom disclosure is required by law for the performance of the above purposes. Such parties will process the data in their capacity as independent data controllers.
Your data will not be disseminated.
6. Retention Period
For the purposes referred to in points 2.a), 2.b), and 2.c), personal data will be processed and retained for the period strictly necessary to pursue the purposes for which they were collected, and in any case at least until your account is deactivated and deleted; after such period, the data will be erased or anonymised, unless further retention is necessary for the purposes of legal defence. Data collected and processed in relation to the Direct Marketing purposes referred to in point 2.d.1) above will be processed and retained for 2 years from the date of your last registration with the service. Data collected and processed in relation to the Profiling purposes referred to in point 2.d.2) above will be processed and retained for a maximum of 12 months. Finally, for the purposes referred to in point 2.d.3), information relating to minors will be processed until they reach the age of fourteen, at which point, as the purpose of child-oriented services ceases and by virtue of the current rules on digital consent capacity in Italy, such data will be erased or anonymised.
7. International Data Transfers
Personal data are not transferred outside the European Union. However, it is understood that, where necessary, we may transfer personal data to non-EEA countries, guaranteeing that such transfer will comply with applicable legal provisions:
- in the case of international transfers of personal data originating from the European Economic Area (EEA) to a non-EEA country, the transfer may take place if the European Commission has recognised that the non-EEA country provides an adequate level of data protection: in such case, your personal data may be transferred on this basis;
- for transfers to non-EEA countries where the level of protection has not been recognised as adequate by the European Commission, we may rely on a derogation applicable to the specific situation and/or otherwise adopt the standard contractual clauses provided by the European Commission for the transfer of personal data outside the EU.
8. Data Subject Rights and How to Exercise Them
We hereby inform you that, at any time and where the relevant conditions are met, you may exercise your rights under Arts. 15 et seq. GDPR:
- to obtain confirmation of the existence or otherwise of personal data concerning you, and a copy thereof in an intelligible form;
- to obtain the updating, rectification, or supplementation of your data;
- to request the erasure of your data, within the limits permitted by law;
- to object, in whole or in part, to the processing of personal data concerning you;
- to restrict processing, in the event of a violation, rectification request, or objection;
- to request the portability of data processed electronically, provided on the basis of consent or contract;
- to withdraw consent to the processing of your data, where applicable;
- in relation to fully automated profiling, to obtain human intervention by the Controller in order to express your opinion and contest the decision.
If you deem it appropriate, you may lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali).
To exercise your rights, you may contact the Controller at the following email address: dpo@centrowelcomed.it.