Privacy notice on the processing of personal data
Adapted from the personalized documents and service decisions: Google Meet, optional recording with separate consent and no AI active today. Provider arrangements, transfers and implementation of retention criteria still need review; recording purposes, storage and retention must be defined and disclosed before recording. Final review with the practitioner and an adviser before use with patients.
1. Controller and practitioner
This notice is provided under Arts. 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003, as amended by Legislative Decree 101/2018. It concerns StefanoniFisioLab, booking management and remote physiotherapy; clinical and fiscal records are managed by the practitioner outside the website.
The controller of personal data is Valentina Stefanoni, physiotherapist registered with Ordine dei Fisioterapisti Interprovinciale Belluno, Treviso, Vicenza, Verona, no. 2216.
Italian tax code (codice fiscale): STFVNT97L57M089S. VAT number (Partita IVA): 05054600266.
Email: stefanonifisiolab@gmail.com.
Certified email (PEC): valentina.stefanoni01@pec.fnofi.it.
Privacy contact and requests to exercise your rights: vale.stefanoni17797@gmail.com.
The controller determines the purposes and means of processing personal data connected with professional activities, booking management and the provision of physiotherapy services, including remote services.
Service format: online telerehabilitation. Tax domicile: Viale Virgilio 16, Vittorio Veneto (TV), Italy.
2. Data processed and website scope
The form collects full name, email, appointment type, date/time, language, an existing-patient declaration and three separate acknowledgments. The website database retains the booking identifier, price, status, times, document version and acknowledgment date/time. Name and email are included in the private Google Calendar invitation, not duplicated in the website database.
The optional general reason/body-region menu stays in your browser and is not sent or saved. Do not put diagnoses, reports or other health information in this form or booking emails.
In the professional relationship, where necessary, data may include date of birth, tax code, telephone, address, health history, diagnoses, reports, functional assessments, goals, rehabilitation programme, clinical notes and progress. Parent, guardian or caregiver details are handled where necessary. The practitioner manages these activities outside the form: the website does not provide clinical records, patient accounts, questionnaires or document/video uploads.
Video calls use Google Meet and transmit your image and voice. A session may be recorded only after specific, explicit and separate patient consent, obtained and documented by the practitioner before recording starts. A recording may contain your image, voice and health information. The website does not start recordings or store audio/video files; booking acknowledgments do not authorize recording.
Bank-transfer payments and invoicing take place outside the website: the practitioner processes amounts, dates and details needed to verify payment and meet accounting duties. The website does not collect card or bank-account details. Infrastructure technical logs may contain IP, device and connection information needed for security.
3. Purposes, legal bases and future tools
Booking, invitations and appointment management: steps at your request or performance of the requested service, GDPR Art. 6(1)(b). Applicable tax/legal obligations: Art. 6(1)(c); payment and invoicing take place outside the website.
Security and abuse prevention: legitimate interests under Art. 6(1)(f), subject to checking its applicability. The practitioner must verify the legal basis for clinical health-data processing; care by professionals bound by professional secrecy may fall under Art. 9(2)(h) and 9(3). This notice does not certify that those requirements have been verified.
Optional recordings require specific, explicit, separate and withdrawable consent under GDPR Arts. 6(1)(a) and 9(2)(a), where applicable. The specific purpose, recorded data, recipients, retention and withdrawal process must be explained before consent and recording. Refusal does not prevent receiving an unrecorded session. Acknowledging this notice or choosing telerehabilitation is not consent to recording or marketing.
AI is not currently used to optimize assessment or treatment. Future tools may be considered to support care and help improve outcomes, without guaranteeing results or replacing the clinical judgment of the practitioner or physician. Suitability, risks and applicable requirements will be assessed and the information updated before activation; additional consent will be requested where necessary. Current acknowledgments, including any recording consent, do not automatically authorize future use of data or videos for AI or model training.
Newsletters, profiling and automated decisions with legal effects are not active.
4. Processing and security
Booking information is processed through the website, database and connected calendar. Public availability does not show patient details; events are created as private. The management link allows its holder to move or cancel the appointment: keep it confidential.
Use a private setting and protect your device and email account. The controller must check provider agreements, access permissions, encryption, backups and breach procedures for healthcare use; this notice does not certify those measures or compliance.
5. Recipients and providers
Relevant booking data are accessible to the practitioner and necessary providers: Replit for the application/database and Google for Calendar, invitations and Meet. Your email provider may process the invitation. The domain stefanonifisiolab.com identifies the website, not its hosting provider.
Google Meet is the only planned video-call service. Authorized recordings are managed by the practitioner outside the website, using only features available and verified for their account. Recording storage, access and recipients must be defined and disclosed before recording; the files are not stored in the booking database.
Bank transfers and tax duties may involve the bank, tax adviser, Agenzia delle Entrate and Sistema Tessera Sanitaria, within applicable purposes and obligations. The practitioner manages these relationships outside the website. No online payment platform is active.
Each provider requires verification of the service and account, processing role, applicable agreement, processing and access countries, subprocessors, any transfer safeguards, security and deletion. These details still need verification and documentation and are not represented as complete. Where required, processor arrangements are governed by GDPR Art. 28.
Data are not sold or publicly disclosed. This form does not authorize sharing clinical updates with a doctor or caregiver: any such sharing requires separate arrangements and a specific request or authorization where necessary.
6. Transfers outside the EEA
Technical providers may process data outside the European Economic Area. Applicable countries, roles and safeguards under GDPR Arts. 44–49: [TBD — verify before use with patients]. No claim is made that data remain exclusively in the EU or that particular agreements or certifications have already been verified.
7. Retention
Under the criteria supplied by the practitioner, clinical and rehabilitation records are retained for 10 years after the last service; fiscal records for 10 years after the last accounting entry, unless longer periods are required by law. These criteria must be confirmed during final review. The practitioner manages the records outside the website, which does not create a clinical record.
Booking data and acknowledgment evidence: as long as needed to manage the appointment, provide support and meet related documentation duties. Payment data: as long as needed to manage the relationship and meet accounting and tax obligations. The clinical 10-year period is not automatically applied to all website data or recordings.
Optional recordings: purposes, storage, specific retention period or criterion and deletion process [TBD]. The practitioner must define and disclose these in the separate consent before recording. No recording should start until these details are defined and consent is documented.
Google Calendar events also follow calendar settings. Technical-log periods, operational responsibility, review frequency, handling of copies and deletion procedures: [to verify with the practitioner and providers].
Patient accounts, video uploads and newsletters/marketing are not active on the website. Cancelling an appointment does not automatically erase acknowledgment evidence. The website does not automatically delete data when these criteria expire: the controller must verify and manage their implementation.
8. Rights and complaints
Request access, correction, deletion, restriction and, where applicable, portability or objection at stefanonifisiolab@gmail.com or vale.stefanoni17797@gmail.com. Where processing relies on consent, you can withdraw it without affecting earlier lawful processing. Requests must be handled within GDPR time limits, normally one month, subject to permitted extensions.
You may complain to Italy’s Garante per la protezione dei dati personali, www.garanteprivacy.it, or your competent authority. Any objections relating to healthcare/tax reporting should be discussed directly with the practitioner.
9. Required data, minors and updates
Name, email and time are necessary to confirm a booking. This form is for adults booking for themselves; contact the practitioner first for minors, guardians or third-party bookings.
This form does not activate advertising cookies or additional analytics. New tools require updated disclosure before activation. Material document changes require a new version; previous acknowledgments are not rewritten.
Shared privacy/consent version: booking-legal-2026-10-06-fiscal-address. Updated: 6 October 2026.