Home Privacy policy

Privacy policy

Information pursuant to Article 13 of EU Regulation 2016/679 (GDPR)

Dear Sir/Madam,

in accordance with the provisions of Regulation (EU) 2016/679 (hereinafter the “GDPR”), the relevant Italian implementing legislation, as well as the Guidelines on cookies and other tracking tools of 10 June 2021 adopted by the Italian Data Protection Authority, Istituto Romagnolo per lo Studio dei Tumori (I.R.S.T.) “Dino Amadori” S.r.l., represented by its legal representative pro tempore, hereby provides you with the following information.

1. Contact details of the Data Controller

The Data Controller is:

Istituto Scientifico Romagnolo per lo Studio e la Cura dei Tumori (I.R.S.T.) S.r.l.
Via Piero Maroncelli 40
47014 Meldola (FC), Italy
Tel. +39 0543 739100
Email: direzione.generale@irst.emr.it

2. Contact details of the Data Protection Officer (DPO)

The Data Protection Officer (DPO) of IRST can be contacted at:

3. Personal data processed

The Data Controller may process personal data consisting of an identifier such as a name, an identification number, an online identifier, or one or more elements relating to the physical, physiological, psychological, economic, cultural or social identity of a person, making the data subject identified or identifiable (hereinafter, “Personal Data”).

The Personal Data processed through the Website include the following.

a) Browsing data

The IT systems and software procedures used to operate the Website acquire, during their normal operation, certain Personal Data whose transmission is implicit in the use of Internet communication protocols.

This information is not collected for the purpose of being associated with identified data subjects. However, by its very nature, it may allow users to be identified through processing and association with data held by third parties.

This category includes, by way of example:

  • IP addresses;
  • domain names of the computers used by users connecting to the Website;
  • URI (Uniform Resource Identifier) addresses of requested resources;
  • the time of the request;
  • the method used to submit the request to the server;
  • the size of the file received in response;
  • the numerical code indicating the status of the server response, such as success or error;
  • other parameters relating to the user’s operating system and IT environment.

b) Data voluntarily provided by the data subject

When using certain Website services, Personal Data relating to third parties and submitted by you to the Data Controller may be processed.

In such circumstances, you act as an independent data controller and assume all obligations and responsibilities required by law.

Accordingly, you shall indemnify the Data Controller to the fullest extent permitted by law against any complaint, claim or request for compensation arising from the processing of Personal Data belonging to third parties where such data have been processed through your use of the Website in breach of applicable data protection legislation.

c) Cookies

No users’ Personal Data are collected by the Website in this respect.

Cookies are not used to transmit information of a personal nature, nor are persistent cookies or other user-tracking systems used.

The use of session cookies, which are not permanently stored on the user’s device and disappear when the browser is closed, is strictly limited to transmitting session identifiers consisting of random numbers generated by the server and required to ensure safe and efficient browsing of the Website.

The session cookies used by the Website avoid the need to resort to other IT techniques that could potentially compromise the confidentiality of users’ browsing activities and do not allow the collection of personally identifiable information about users.

Users are also invited to read the Cookie Policy, which forms an integral part of this Privacy Policy.

d) Optional provision of data

With the exception of browsing data, users are free to provide the Personal Data requested in order to access the web services available in the interactive areas of the Website.

Failure to provide such data may make it impossible to provide the requested service or information.

4. Purposes and legal basis of processing

The Data Controller will process Personal Data within the scope of its activities for the following purposes:

  • to allow users to browse the Website and use the services offered by the Data Controller pursuant to Article 6(1)(b) GDPR. Where users request specific services, a dedicated privacy notice will be provided and, where required, consent to processing will be requested;
  • to carry out any defensive activity necessary for the establishment, exercise or defence of the Data Controller’s legal claims, whether in judicial proceedings or during stages preceding such proceedings, pursuant to Articles 6(1)(f) and 9(2)(f) GDPR;
  • to comply with legal obligations to which the Data Controller is subject pursuant to Article 6(1)(c) GDPR.

Further information concerning the processing of Personal Data may be provided in dedicated sections of the Website.

5. Processing methods and data retention

For the purposes described in Section 4 above, Personal Data are processed by the Data Controller in accordance with applicable data protection legislation.

In particular, processing:

  • may be carried out manually and with the assistance of electronic or automated systems that are suitable for ensuring the security and confidentiality of Personal Data and preventing unauthorised access by third parties;
  • is carried out directly by the Data Controller’s organisation and/or by processors appointed by the Data Controller under a contract entered into pursuant to Article 28 GDPR.

Personal Data will be retained only for the period necessary to fulfil the purposes for which they were collected, in accordance with the data minimisation principle set out in Article 5(1)(c) GDPR and with the legal obligations to which the Data Controller is subject.

Where processing is based on consent, the Data Subject retains the right to withdraw such consent at any time.

Further information is available from the Data Controller.

6. Disclosure of Personal Data

For the purposes described in Section 4, Personal Data may be disclosed and/or shared with third parties and public administrations where permitted or required by law.

Some of these parties will process Personal Data as data processors, following their appointment by the Data Controller pursuant to Article 28 GDPR.

A list of the appointed data processors is available to Data Subjects.

Other parties, including authorities authorised by law, healthcare supervisory bodies, other regulatory and supervisory authorities or public administration bodies, may process Personal Data received from the Data Controller in their capacity as independent data controllers.

Natural persons, employees and collaborators of the Data Controller, processors or third parties who are authorised to process Personal Data provided by Data Subjects act under the instructions of the relevant controller or processor and are subject to confidentiality obligations.

7. Transfer of data outside the European Union

Personal Data are not disseminated or transferred to countries outside the European Union or to international organisations.

Should such a transfer become necessary and/or unavoidable due to the Data Controller’s organisational requirements, it will take place exclusively:

  • to countries considered adequate or safe by the European Commission; or
  • in accordance with one of the transfer mechanisms permitted by applicable legislation.

In particular, transfers may be carried out subject to the appropriate safeguards referred to in Article 46 GDPR, for example through the use of Standard Contractual Clauses approved by the European Commission, or on the basis of one of the derogations provided for by Article 49 GDPR, such as the Data Subject’s consent.

8. Data Subjects’ rights

Pursuant to Regulation (EU) 2016/679, users may exercise the rights provided for under Articles 15-22 GDPR.

The exercise of such rights may be subject to the limitations provided for by applicable legislation, for example where essential considerations relating to private interests prevail over the right to obtain certain information.

Right of access

Users have the right to request access to the Personal Data processed by the Data Controller.

The Data Controller is also required to provide a copy of the Personal Data being processed free of charge, including by electronic means.

Right to rectification

Users have the right to obtain the rectification of inaccurate Personal Data concerning them and to have incomplete Personal Data completed.

Right to erasure

Under certain circumstances, users have the right to obtain the erasure of Personal Data concerning them.

Right to restriction of processing

Under certain circumstances, users have the right to obtain restriction of the processing of Personal Data concerning them.

Right to data portability

Where processing is based on consent or on a contract and is carried out by automated means, users have the right to receive Personal Data concerning them in a structured, commonly used and machine-readable format.

Users also have the right to transmit those Personal Data to another data controller without hindrance from the Data Controller, where technically feasible.

Right to object

Under certain circumstances, users have the right to object at any time to the processing of Personal Data concerning them.

For example, where users have requested information from the Data Controller and no longer wish to receive such information, they may withdraw their consent in order to prevent further communications.

Automated decision-making, including profiling

As a general rule, users have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly or negatively affects them.

This principle does not apply, among other cases provided for by applicable legislation, where automated decision-making or profiling is necessary for entering into or performing a contract between the user and the Data Controller.

Where the processing of Personal Data is based on consent, users may withdraw their consent at any time.

Withdrawal of consent does not affect the lawfulness of processing carried out by the Data Controller before consent was withdrawn.

Users also have the right to obtain confirmation as to whether or not Personal Data concerning them exist, even if such data have not yet been recorded, and to receive such data in an intelligible form.

Users also have the right to know:

  • the source of the data;
  • the purposes of the processing;
  • the identity and contact details of the Data Controller;
  • the persons or categories of persons to whom Personal Data may be disclosed or who may become aware of them.

Data Subjects may also obtain the updating, rectification or completion of their Personal Data, their erasure or, where possible, their anonymisation, and may exercise any other rights provided for under Regulation (EU) 2016/679 of 27 April 2016.

Complaints and information

Requests concerning the exercise of the rights provided for under the EU General Data Protection Regulation 2016/679 may be addressed to IRST’s Data Protection Officer:

Data Subjects may, for example:

  • obtain information regarding the Personal Data processed about them;
  • obtain information regarding the origin, logic, purposes and methods of processing;
  • request the erasure of their Personal Data;
  • request, where possible, the anonymisation of their Personal Data;
  • request the blocking of data processed unlawfully;
  • request the updating, rectification or completion of their Personal Data.

If a Data Subject considers that the processing of Personal Data relating to them infringes the GDPR, they have the right to lodge a complaint with the competent Data Protection Authority pursuant to Article 77 GDPR or to seek a judicial remedy pursuant to Article 79 GDPR.

9. Changes to this Privacy Policy

This Privacy Policy may be updated and/or amended in order to comply with national, European Union or international legislation or to reflect technological developments.

Any updates or changes to this Privacy Policy will be published on this web page and kept continuously available so that Data Subjects can remain fully informed about how Personal Data provided through the Website are used.