Skip to content

Privacy notice

On this page

Draft to be validated by the DPO before publication.

This notice explains how we process your personal data when you visit our website, write to us, apply for a job or book a service online, under articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.

Data controller

POLIAMBULATORIO FONDAZIONE ATM S.R.L., Via Carlo Farini 9/B, 20159 Milan, Italy — Tax code/VAT 12067550967.

Email: amministrazione@poliambulatoriofondazioneatm.it

Data protection officer (DPO)

[to be completed: DPO name and contact details]

What data we process

  • Contact form: full name, phone number, email, topic of your request and the text of your message.
  • Job applications (Work with us): full name, phone number, email, cover message and the attached CV, with whatever information you choose to include in it.
  • Online booking: first name, last name, Italian tax code (codice fiscale), date of birth, email, mobile number, the service, doctor, date and time you choose, the rate you declare (private patient, Fondazione ATM member, partner plan), any employee ID or membership card number, any partner plan and card or policy number, and optional notes for the reception desk.
  • Email verification: to confirm your booking we send a one-time code (OTP) to the email address you provide; we record the outcome of the check and the number of attempts.
  • Consents: we record that you accepted this notice and, if given, your consent to receive communications, with the date, time and version of the notice you accepted.
  • Technical browsing data: IP address, date and time of the request, pages visited and browser type, collected by the systems that run the website, also for security and abuse prevention.

Booking a healthcare service may reveal information about your health (article 9 GDPR), for example the specialty you choose. Please do not include detailed clinical information in notes or messages: you will discuss it directly with the doctor.

  • Replying to requests sent through the contact form — Pre-contractual steps at your request (art. 6.1.b)
  • Managing bookings, confirmations, reminders and cancellations — Pre-contractual steps and performance of the contract (art. 6.1.b); for health-related data, medical diagnosis, care and treatment (art. 9.2.h)
  • Checking the declared rate (membership or partner plan) at the clinic — Performance of the contract (art. 6.1.b)
  • Assessing job applications — Pre-contractual steps at your request (art. 6.1.b)
  • Sending you news about prevention campaigns — Optional consent, which you can withdraw at any time (art. 6.1.a)
  • Meeting legal obligations (e.g. tax and healthcare rules) — Legal obligation (art. 6.1.c)
  • Keeping the website secure and preventing abuse — Our legitimate interest (art. 6.1.f)

Fields marked as required are necessary: without them we cannot reply to you, assess your application or register your booking.

How long we keep your data

  • Contact form requests: [to be defined] months after the request is closed.
  • Applications and CVs: [to be defined] months from receipt, unless you agree to a longer period.
  • Bookings: for as long as needed to provide the service and then for the periods required by applicable tax and healthcare rules [to be defined].
  • Unconfirmed bookings (OTP code not entered): deleted within [to be defined].
  • Consent records: for as long as the processing lasts and for the period needed to prove the consent was valid.
  • Technical browsing data: [to be defined] days, unless needed to investigate unlawful activity.

Who may receive your data

Your data is processed by authorised clinic staff (reception, administration, and doctors for the bookings that concern them) and by suppliers acting as data processors under article 28 GDPR, in particular:

  • hosting and infrastructure providers for the website and booking system;
  • email delivery providers (confirmations, verification codes, reminders);
  • [to be completed: any other suppliers, e.g. software maintenance].

To check the partner plan rate we may need to share some data with the fund or company you indicate, only as far as necessary [to be completed]. Your data is never published.

Transfers outside the European Union

Your data is stored and processed within the European Union. Should a supplier ever process it outside the EU, the transfer will only take place with the safeguards set out in articles 44 and following of the GDPR, and this notice will be updated.

Your rights

You can exercise the rights set out in articles 15–22 GDPR at any time: access, rectification, erasure, restriction, portability, objection to processing based on legitimate interest, and withdrawal of consent, without affecting the lawfulness of processing carried out before withdrawal.

To exercise them, write to amministrazione@poliambulatoriofondazioneatm.it or to the DPO. You also have the right to lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it).

Cookies

For information about cookies, please read our cookie policy.

Updates

Version [to be defined] of [to be defined]. Any changes will be published on this page.

We only use technical cookies. The Google map is shown only if you accept external content. Read the cookie policy