More details

Privacy Utenti EN

INFORMATIVA AGLI UTENTI SUL
TRATTAMENTO DEI DATI PERSONALI
INFORMATION FOR USERS ON THE PROCESSING OF PERSONAL DATA
P08-DOC_01
Rev. 00
Revision date 25/07/2025
Page 1 of 2

  1. General information
    Dear Madam / Dear Sir,
    Pursuant to Art. 13 of EU Regulation no. 2016/679 (hereinafter referred to as the “Regulation”), and in relation to the personal data
    processing activities carried out in carrying out the healthcare services requested by you, the company Fisiostandard Srl
    communicates the following.
    1.1. Data controller
    The Data Controller is Fisiostandard Srl , with registered office in Florence, Viale S. Lavagnini n. 18, CAP 50129, Fiscal Code/VAT
    number 06534870487 , email address info@fisiostandard.it .
    1.2. Data Protection Officer
    The Data Controller has appointed a Data Protection Officer pursuant to Art. 37 of the Regulation, who can be contacted at the email
    address dpo@fisiostandard.it .
    parties may contact the Data Protection Officer for further information on the processing of personal data by the companies listed above.
    1.3. Purpose of the processing
    Your personal data processed by our facility, following your request for healthcare services, are:
  • common data , such as personal data, residence, domicile, telephone contact, e-mail, data relating to electronic payment methods;
  • special data pursuant to Article 9 of the Regulation , Such data may be used to identify the patient’s health and/or the presence of
    any pathologies, biometric signatures for electronic documents, and genetic data relating to any genetic tests you request. In some
    cases, data revealing ethnic origin, biometric data, or data relating to a patient’s sexual life related to the services you request may
    also be processed.
    The treatment is aimed at:
  • carrying out all activities necessary for the provision of requested outpatient and/or home healthcare services , such as rehabilitation
    and physiotherapy sessions, specialist physiatric and orthopedic visits , including related administrative and accounting activities (this
    falls fully within the “treatment purposes” referred to in Article 9, paragraph 2, letter h of the Regulation, as these healthcare services
    are performed by, or under the responsibility of, healthcare professionals subject to professional secrecy or by other persons also
    subject to the obligation of confidentiality);
  • Monitoring and supervising the progress of physiotherapy and the correct, independent execution of the proposed exercises and
    treatments through video recordings shared via instant messaging platforms, only with your explicit consent;
  • scientific studies or research only with your explicit consent (in this case the data will be processed anonymously);
  • Sending informational material on initiatives relating to the services offered only with your explicit consent.
    In carrying out the assignment, the Data Controller also avails itself of its own collaborators and employees, who are bound by
    confidentiality obligations.
    Furthermore, in carrying out and providing the healthcare services described above, the Data Controller may also avail itself of
    healthcare facilities, professionals, and external parties (such as physiotherapists, physiatrists, orthopedists, clinics, and physiotherapy
    practices that adopt the same Fisiostandard procedures, etc.), duly appointed as external data processors.
    The data subject’s common data are processed and communicated to third parties, chosen by the Data Controller as data controllers,
    for the purpose of:
  • fulfill tax and accounting obligations;
  • comply with the obligations incumbent on the Data Controller and set forth by current legislation.
    The interested party’s special data are communicated to third parties, chosen by the Data Controller as data controllers, for the sole
    purpose of carrying out, in whole or in part, the healthcare services requested by the interested party for treatment purposes .
    1.4. Legal basis for processing
    The processing will be based on the principles of fairness, lawfulness, transparency and protection of your privacy and your rights.
    Therefore, the Data Controller will process your personal data lawfully where the processing:
  • is necessary for the performance of the healthcare services requested by you for treatment purposes and for all activities compatible
    with this purpose;
  • is necessary to fulfill a legal obligation incumbent on the Data Controller;
  • is based on express consent;
  • is necessary for the pursuit of the legitimate interests pursued by the Data Controller or by third parties, provided that such interests
    are not overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal
    data.
    1.5. Consequences of failure to communicate personal data
    With regard to personal data required to provide the healthcare services you request for treatment purposes or to comply with a
    regulatory obligation, failure to provide such personal data will prevent the provision of the requested healthcare services. Failure to
    consent to the processing of data for purposes other than treatment and described in paragraph 1.3 above will not prevent the provision
    of the requested healthcare service or service.
    1.6. Data processing and storage methods
    Your personal data will be processed using both paper and electronic archives and in a manner strictly necessary to fulfill the purposes
    indicated above. Electronic data will be stored on a server owned by the Data Controller, equipped with appropriate anti-intrusion and
    data recovery security measures. Specific security measures are implemented to prevent data loss, illicit or improper use, and
    unauthorized access. Your personal data collected and shared via instant messaging platforms will be stored on the mobile devices of
    the healthcare professionals who support you throughout your treatment and on cloud servers (e.g., Google Drive, iCloud, etc.) that rely
    on physical servers offering adequate guarantees and security measures.
    Your personal data, subject to processing, will be retained for an unlimited period.
    1.7. Data communication
    Your personal data may be communicated to:
  1. healthcare providers for the treatment purposes indicated above;
  2. consultants, accountants or other professionals who provide services functional to the purposes indicated above;
  3. banking and insurance institutions that provide services functional to the purposes indicated above;
  4. entities that process data in compliance with specific legal obligations;
  5. Judicial or administrative authorities, for the fulfillment of contractual and legal obligations.
    As part of the processing carried out by each Data Controller, your personal data will not be transferred to third countries or international
    organizations.
    1.8. Profiling and dissemination of data
    Your personal data will not be disclosed or subjected to any fully automated decision-making process, including profiling, unless you
    provide specific and express consent to such processing methods.
    “Profiling” means “any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal
    aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work,
    economic situation, health, personal preferences, interests, reliability, behaviour, location or movements” (Article 4, point 4 of the
    Regulation) .
    In the event that data storage or processing services are used via remote servers or, more generally, through web services, such as
    cloud storage services, service providers will be selected from among those who provide adequate guarantees, as required by Article 46
    of the Regulation.
    1.9. Rights of the interested party
    The interested party has the following rights:
  • ask the Data Controller for access to your personal data and information relating to them, including the purposes of the processing,
    the categories of personal data in question, the recipients to whom the personal data have been, will be, or may be disclosed, and the
    data retention period (Article 15 of the Regulation);
  • request the rectification or integration of incomplete personal data (Article 16 of the Regulation);
  • obtain the erasure of personal data when one of the conditions set out in Article 17, paragraph 1 of the Regulation applies and in
    compliance with the exceptions set out in Article 17, paragraph 3 of the Regulation;
  • obtain the limitation of data processing when one of the hypotheses indicated in Art. 18, paragraph 1 of the Regulation occurs
  • request and obtain from the Data Controller – in cases where the processing is carried out by automated means – your personal data
    in a structured and machine-readable format, also for the purpose of communicating such data to another data controller (so-called
    right to data portability pursuant to Art. 20 of the Regulation);
  • object at any time to the processing of your personal data;
  • withdraw your consent at any time, limited to cases in which the processing is based on your consent for one or more specific
    purposes – processing based on consent, and carried out prior to its withdrawal, remains lawful;
  • lodge a complaint with the Italian Data Protection Authority ( www.garanteprivacy.it ).
  1. Electronic Health Record
    The Data Controller processes and stores digital healthcare data and documents generated by current and past clinical events involving
    users. Processing and storage are carried out as described in section 1.6 above, using specific software applications.
    The digital health data and documents managed by the Data Controller through its applications constitute an Electronic Health Record
    (hereinafter referred to as “DSE”).
    You may always express your opposition to the processing of your personal data through the DSE and may always revoke any consent
    you may have provided.
    The processing of data through the DSE must be understood as:
  • optional , only if you, after understanding this information, have voluntarily authorised it by giving your specific consent;
  • non-binding for the execution of the requested healthcare service or provision, which will be provided in any case.
    For information on the methods of processing personal data carried out by the healthcare facility, please refer to the previous paragraph
    1.
    With regard to the processing of personal data, including sensitive data, which occurs through the DSE , in addition to the information
    indicated above, we inform you of the following:
  • the processing is exclusively for treatment purposes (prevention, diagnosis, treatment and rehabilitation) and governance purposes
    (healthcare planning, verification of the quality of care and evaluation of healthcare);
  • the documents in your DSE consist mainly of bookings and reports;
  • the legal basis for the processing is the consent of the interested party, to be expressed at the bottom of this information ;
  • with the interested party’s consent, all healthcare personnel working on behalf of the Data Controller and involved in the user’s care
    process can access the DSE;
  • You may be made aware of the accesses made to your DSE at any time upon explicit request.
    Administrative staff may only consult the information necessary to perform their assigned administrative functions and strictly related to
    the provision of healthcare services (e.g., staff responsible for booking specialist appointments may only consult the data essential for
    the booking itself).
    Administrative staff are authorized to consult your health data only with your explicit consent, given after understanding this information.

Form Candidatura Terapista

Nome
Disponibilità Giornaliera
Disponibilità Oraria
Zona di lavoro preferita
Cerca...
Privacy Preferences

When you visit our website, it may store information through your browser from specific services, usually in the form of cookies. Here you can change your Privacy preferences. It is worth noting that blocking some types of cookies may impact your experience on our website and the services we are able to offer.

For performance and security reasons we use Cloudflare
required
Our website uses cookies, mainly from 3rd party services. Define your Privacy Preferences and/or agree to our use of cookies.