Back to the site

Privacy Policy

Information on the processing of personal data under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.

Last updated: · Version 1.0

This is a courtesy translation. The controller is established in Italy: in case of any discrepancy, the Italian version of this policy prevails.

1. Who processes your data

The data controller is Giuseppe Buomprisco, a sole trader established in Italy, operating the VisioScreening service (the “Service”, available at visioscreening.com).

The controller can be reached at assistenza@medcompetente.it for anything concerning this policy, including requests to exercise the rights described in section 10. If you need the controller's full registration details — VAT number and registered office included — ask at that address and you will receive them at no cost.

ControllerGiuseppe Buomprisco
Trading asVisioScreening
Legal formSole trader (impresa individuale) under Italian law
Country of establishmentItaly
Emailassistenza@medcompetente.it

No Data Protection Officer has been appointed: the processing does not fall within the cases listed in Article 37 GDPR, as it involves neither regular and systematic monitoring on a large scale nor large-scale processing of special categories of data. For any data protection matter you can write directly to the addresses above.

2. Two kinds of data, two different roles

VisioScreening is a professional tool: the person using it is a physician, optician, occupational health technician or other healthcare professional administering vision tests to a display-screen worker. That produces two entirely separate categories of data, and it is essential not to conflate them.

DataWho is the controllerWhere it lives
Data about the professional using the Service (account, practice details, payment)Giuseppe Buomprisco is the controllerOn the Service's servers
Data about the worker being tested (identity, answers, results, report)The professional or healthcare organisation is an independent controllerSolely on the professional's own device

Clinical data about the worker is never sent to our servers. It stays in the browser's memory for the duration of the screening, and the PDF report is generated locally on the professional's device. We are neither controller nor processor of that data, because we never receive it. Section 4 explains exactly how this works.

3. What we process and why

We process only what is needed to give you an account, let you generate reports and collect payment. We do not profile users, we do not send unsolicited newsletters, we do not sell or share data for marketing purposes, and we run no behavioural analytics.

Category of dataPurposeLegal basisRetention
Account data: email address, name (optional), password stored only as a bcrypt hash; if you sign in with Google, the name, email and profile picture Google passes onCreating and managing your account, authenticating you, allowing password recoveryArt. 6(1)(b) GDPR — performance of the contractFor the life of the account and up to 30 days after a deletion request (backups up to 90 days)
Practice data: name and address of your practice, physician's name, logo and signature image you uploadBranding the header of the PDF report with your practice's detailsArt. 6(1)(b) GDPR — performance of the contractUntil the account is deleted or the configuration is changed
Report ledger: a random report identifier, timestamp, language, whether the report was free or paid, and a salted SHA-256 hash of the IP addressEnforcing the licence you purchased, counting free reports already used, detecting abuse of the free report (serial account creation)Art. 6(1)(b) and Art. 6(1)(f) GDPR — performance of the contract and legitimate interest in preventing abuseThe row stays for the life of the account, because it is the record of the licence you hold; the IP hash is removed once the few-day window in which it serves to detect abuse has passed
Payment data: checkout session identifier, amount, currency, status, and the billing and tax details you enter on StripeCollecting the one-off fee and issuing and retaining accounting recordsArt. 6(1)(b) GDPR — performance of the contract; Art. 6(1)(c) GDPR — tax and accounting obligationsAccounting documents 10 years from the entry (Art. 2220 of the Italian Civil Code and tax law); the technical transaction data until the account is deleted
Technical and security data: IP address, browser type, request timestamps, failed login attempts, session and password-reset tokensKeeping the Service running, protecting it against unauthorised access, rate-limiting password guessingArt. 6(1)(f) GDPR — legitimate interest in network and information securityLogin attempts: minutes. Tokens: until expiry. Hosting provider logs: typically 30 days
Correspondence: the content of emails or messages you send us for supportAnswering your requests and handling disputesArt. 6(1)(b) and Art. 6(1)(f) GDPR — performance of the contract and legitimate interest in defending legal claimsUp to 24 months from the last contact, unless a dispute is pending

Providing the data marked as required in our forms is necessary to activate the account and use the Service: without it we cannot technically provide the Service. Providing any other data is optional and withholding it does not affect your use of the Service.

4. Data about the worker being tested

The intake questionnaire, the worker's identifying details, the answers to the seven tests and the final report are health data — special categories of personal data under Article 9 GDPR. The Service is built so that we never receive them.

  • Data entered during a screening stays in the browser's memory, on the professional's device, and is never transmitted to our servers at any point.
  • The PDF report is assembled entirely in the browser: it never passes through us, we do not store it and we keep no copy.
  • If you interrupt a screening to complete payment, the data entered is saved temporarily in the browser's sessionStorage for at most two hours so you can pick up where you left off. sessionStorage is cleared when the browser closes, and the logo and signature are never written to it.
  • The only thing that reaches our servers when you download a report is a random report identifier carrying no reference whatsoever to the worker: it exists solely to decrement your report counter.

Because we never come into possession of the worker's health data, we consider that the conditions for appointing us as a processor under Article 28 GDPR are not met. That said, on request we will still sign a data processing agreement, or issue a written statement describing the architecture set out here: write to the address in section 14.

All obligations concerning the worker's data remain with the professional using the Service: identifying the legal basis for the processing (typically Art. 9(2)(h) GDPR for occupational medicine, read together with Art. 41 of Italian Legislative Decree 81/2008), providing their own privacy notice to the data subject, storing the report securely and observing professional secrecy. Giuseppe Buomprisco is not responsible for what the professional does with the report once it has been generated.

5. Who we share data with

We do not sell or trade your data. We share it only with the providers that make the Service technically possible, each appointed as a processor under Article 28 GDPR and bound to process it only on our instructions.

ProviderRoleData involved
Stripe Payments Europe, Ltd. (Ireland)Card payment processingBilling details, amount, outcome. Card details are handled by Stripe directly and are never disclosed to us
MongoDB, Inc. / MongoDB AtlasManaged databaseAll account and licence data
Render Services, Inc.Server-side application hostingData sent to the API and technical logs
Netlify, Inc.Website and web app hosting and CDNConnection data (IP address, user agent)
Transactional email provider (Resend / configured SMTP provider)Sending system emails such as password resetsEmail address and message content
Google Ireland LimitedSign in with Google, only if you choose to use itGoogle account identifier, name, email and profile picture
Accountants and tax advisersAdministrative and tax complianceBilling data

Data may also be disclosed to public authorities where required by law or necessary to establish, exercise or defend legal claims. An up-to-date list of processors is available on request at assistenza@medcompetente.it.

6. Transfers outside the European Economic Area

Some of the providers listed above are established in the United States or may process data outside the European Economic Area. Where that happens, the transfer relies on one of the safeguards set out in Chapter V GDPR: an adequacy decision of the European Commission — in particular the EU-U.S. Data Privacy Framework for providers certified under it — or the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, supplemented where necessary by additional measures.

Some of the services we use operate in regions outside the European Union, in particular in the United States. At any time, and at no cost, you can ask for an up-to-date statement of where the data sits and a copy of the safeguards in place for each provider by writing to assistenza@medcompetente.it.

7. How long we keep data

Retention periods are stated per category in the table in section 3. In short:

  • Account data is kept for as long as the account exists. The application exposes no self-service deletion: erasure is carried out manually by the controller on a request sent to the address in section 14, without undue delay and in any case within 30 days, and covers the account, licence, practice configuration, sessions and report records.
  • The IP address hash exists to detect abuse of the free report over a window of a few days. Past that window it serves no purpose and is removed during the controller's periodic housekeeping; the report row it belonged to remains, without the hash, because it is the record of your licence.
  • Accounting and tax records relating to your payment are kept for 10 years, as Italian law requires: that obligation overrides a deletion request, and it covers the accounting documents only, not the whole technical history of the payment.
  • Technical and security data is short-lived: login attempt counters last minutes, session and reset tokens expire on their own, and hosting provider logs follow the rotation those providers set.
  • Backups managed by the database provider follow the rotation of the plan in use: removal from live systems is immediate, removal from backups happens at the next rotation cycle.

Erasure being a manual operation narrows neither its scope nor its deadline: Article 17 GDPR is exercised by writing to the controller, and the request is handled within the time limits in section 10. If you would rather verify that it happened, ask in the same email and you will get written confirmation.

9. Security

We apply technical and organisational measures appropriate to the risk, in accordance with Article 32 GDPR, including:

  • all data transmitted over encrypted connections (HTTPS/TLS);
  • passwords stored only as bcrypt hashes, never in plaintext and never reversible;
  • session tokens in httpOnly, Secure cookies, with an expiry;
  • per-account data isolation: no user can reach another user's configuration or reports;
  • automatic rate limiting of repeated login attempts;
  • IP addresses retained only as SHA-256 hashes with a secret salt, not traceable to the original address without that salt;
  • data minimisation at source: health data never leaves the professional's device.

No security measure can be considered absolute. In the event of a personal data breach posing a risk to the rights and freedoms of data subjects, we will notify the Italian Data Protection Authority within 72 hours and, where the risk is high, inform the data subjects, in accordance with Articles 33 and 34 GDPR.

10. Your rights

You may exercise the rights granted by Articles 15 to 22 GDPR at any time:

  • access: obtain confirmation that processing is taking place and receive a copy of the data (Art. 15);
  • rectification: correct inaccurate data or complete incomplete data (Art. 16);
  • erasure: have data removed where we are not required by law to keep it (Art. 17);
  • restriction: ask that processing be suspended in the cases provided for (Art. 18);
  • portability: receive the data you provided in a structured, machine-readable format, or have it transmitted to another controller (Art. 20);
  • objection: object at any time, on grounds relating to your particular situation, to processing based on legitimate interest (Art. 21).

To exercise these rights, write to assistenza@medcompetente.it. We reply within one month of receiving the request, extendable by two further months for particularly complex requests, in which case we will tell you. Exercising your rights is free of charge, unless requests are manifestly unfounded or excessive.

If you believe the processing of your data infringes the GDPR, you have the right to lodge a complaint with the Italian Data Protection Authority — Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, Italy; phone +39 06 696771; email garante@gpdp.it; certified email protocollo@pec.gpdp.it; www.garanteprivacy.it — or with the supervisory authority of the Member State where you reside. Your right to seek a judicial remedy is unaffected.

11. Automated decision-making and profiling

We carry out no automated decision-making or profiling within the meaning of Article 22 GDPR. Test results are computed locally on the device, serve as screening support only, and in no way replace the assessment and diagnosis of a healthcare professional.

12. Minors

The Service is addressed to professionals acting in the course of their work and is not intended for minors. We do not knowingly collect data about minors through account registration. If you believe a minor has created an account, tell us and we will delete it.

13. Changes to this policy

This policy may be updated to reflect changes to the Service, to the providers we use or to applicable law. The version in force is always published on this page, with its last-updated date and version number. Where changes are substantial, we will notify registered users by email or inside the application before they take effect.

14. Contact

For any question about this policy or about the processing of your personal data, write to assistenza@medcompetente.it. It is the same address as support, watched daily and by design: requests concerning personal data are recognised and handled as such. If you need a postal address for the controller — for registered post or a formal complaint — ask there and it will be provided at no cost.