Privacy policy
How we process the personal data of those who visit this website, pursuant to Regulation (EU) 2016/679.
Last updated: 17 July 2026
This notice explains how the personal data of those who visit www.rominaorsetti.it is processed, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”). It concerns the website only: the processing of patients’ data in the context of healthcare services is covered by a separate notice, provided at the clinic.
1. Data controller
Dott.ssa Romina Orsetti – Studio Podologico
Via Fonte Magna 25, 60027 Osimo (AN) · Via Giosuè Carducci 3/A, 60025 Villa Musone di Loreto (AN)
P.IVA 01259580429
E-mail: info@rominaorsetti.it · Telephone: +39 329 888 5486
For any matter concerning your personal data you can write to info@rominaorsetti.it. No Data Protection Officer (DPO) has been appointed, as the legal requirements for doing so do not apply.
2. What data we process
This website is deliberately minimal: it contains no contact forms, requires no registration, has no comment area and uses no analytics or profiling systems (no Google Analytics, no advertising pixels). The data processed is therefore limited to:
- Browsing data. The computer systems and software procedures used to run the website acquire, in the course of their normal operation, certain data whose transmission is implicit in the use of Internet protocols: IP address, browser type and operating system, date and time of the request, pages visited. This data is recorded in the server logs for security and diagnostic purposes and is not used to identify you.
- Data you provide voluntarily. If you contact us by telephone, WhatsApp or e-mail, we will process the data you choose to share with us (name, contact details and the content of your message), for the sole purpose of replying to you.
- Cookies. The site uses only technical cookies; third-party content is blocked until you give your consent. Details are in the Cookie policy.
3. Why we process the data and on what legal basis
- To provide the website and ensure its security – the legitimate interest of the Controller in offering a functioning site protected from abuse (Art. 6.1.f GDPR).
- To respond to your contact requests and arrange an appointment – performance of pre-contractual measures taken at your request (Art. 6.1.b GDPR).
- To display third-party maps and reviews – your consent, freely given and revocable at any time (Art. 6.1.a GDPR).
- To comply with legal obligations, for example tax or healthcare obligations, where applicable (Art. 6.1.c GDPR).
4. Health data: an important note
Health data belongs to the “special categories of data” (Art. 9 GDPR) and deserves reinforced protection. This website does not collect it: there are no forms, and no page asks you for clinical information.
If, however, you spontaneously send us information about your health — for example by describing a condition or attaching a photograph via WhatsApp or e-mail — we will process that data for the purposes of care and to respond to your request, on the basis of Art. 9.2.h GDPR (preventive medicine, diagnosis and healthcare, by a professional bound by professional secrecy) and, where necessary, of your explicit consent (Art. 9.2.a GDPR).
We advise you not to send health data, medical reports or clinical photographs through messaging channels. WhatsApp is a service run by a third-party provider and is not the right channel for clinical information: use it to arrange or reschedule an appointment. The assessment of your case takes place at the clinic, where you will also receive the notice dedicated to the processing of health data.
5. Who processes the data besides us
The data is neither disclosed nor sold to third parties for commercial purposes. It may be processed, on our behalf and on our instructions, by parties appointed as data processors (Art. 28 GDPR), or by independent third-party controllers when you activate the relevant consent:
- Infomaniak Network SA (Switzerland) – provider of the hosting on which the website resides, data processor.
- Google Ireland Ltd. – the Google Maps service, for displaying the maps of the locations. Active only with your consent.
- Trustindex – a widget that displays the public reviews from the clinic’s Google profile. Active only with your consent.
- WhatsApp Ireland Ltd. (Meta group) – if you choose to contact us via WhatsApp. In that case the processing of your data by Meta is governed by the privacy policy of that service, over which we have no control.
- Consultants, technicians and IT service providers who assist us, bound by confidentiality.
6. Transfers outside the European Union
The data is stored on servers located in Switzerland, a country for which the European Commission has adopted an adequacy decision: the transfer therefore takes place without the need for further safeguards.
Activating Google Maps or the reviews widget may involve a transfer of data (in particular the IP address) to companies based in the United States. Such transfers are based on the adequacy decision of the EU-U.S. Data Privacy Framework and, additionally, on the Standard Contractual Clauses adopted by the European Commission. If you do not give your consent, no data is sent to these parties.
7. How long we keep the data
- System logs: for the time technically necessary for security and diagnostics, as a rule no longer than 12 months.
- Contact requests: for the time needed to handle them and, in the event of an appointment, in accordance with the terms laid down for healthcare records and for the protection of rights in legal proceedings.
- Cookies: according to the durations indicated in the Cookie policy.
8. Your rights
At any time you can exercise the rights provided for by Articles 15-22 of the GDPR: access your data and obtain a copy of it, request its rectification or erasure, obtain the restriction of processing, object to processing based on legitimate interest, request the portability of the data and withdraw your consent at any time, without affecting the lawfulness of the processing carried out before the withdrawal.
Simply write to info@rominaorsetti.it. We will reply without undue delay and in any case within one month.
9. Complaint to the supervisory authority
If you believe that the processing of your data infringes the law, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) (Piazza Venezia 11, 00187 Roma – garanteprivacy.it) or to bring the matter before the courts.
10. Changes to this notice
This notice may be updated to bring it into line with legislative developments or changes to the website. The version published on this page, with the date shown at the top, is always the one in force.