Privacy Policy
Information on the processing of personal data under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.
Last updated: · Version 1.0
This is a courtesy translation. The controller is established in Italy: in case of any discrepancy, the Italian version of this policy prevails.
1. Who processes your data
The data controller is Giuseppe Buomprisco, a sole trader established in Italy, operating the VisioScreening service (the “Service”, available at visioscreening.com).
The controller can be reached at assistenza@medcompetente.it for anything concerning this policy, including requests to exercise the rights described in section 10. If you need the controller's full registration details — VAT number and registered office included — ask at that address and you will receive them at no cost.
| Controller | Giuseppe Buomprisco |
| Trading as | VisioScreening |
| Legal form | Sole trader (impresa individuale) under Italian law |
| Country of establishment | Italy |
| assistenza@medcompetente.it |
No Data Protection Officer has been appointed: the processing does not fall within the cases listed in Article 37 GDPR, as it involves neither regular and systematic monitoring on a large scale nor large-scale processing of special categories of data. For any data protection matter you can write directly to the addresses above.
2. Two kinds of data, two different roles
VisioScreening is a professional tool: the person using it is a physician, optician, occupational health technician or other healthcare professional administering vision tests to a display-screen worker. That produces two entirely separate categories of data, and it is essential not to conflate them.
| Data | Who is the controller | Where it lives |
|---|---|---|
| Data about the professional using the Service (account, practice details, payment) | Giuseppe Buomprisco is the controller | On the Service's servers |
| Data about the worker being tested (identity, answers, results, report) | The professional or healthcare organisation is an independent controller | Solely on the professional's own device |
Clinical data about the worker is never sent to our servers. It stays in the browser's memory for the duration of the screening, and the PDF report is generated locally on the professional's device. We are neither controller nor processor of that data, because we never receive it. Section 4 explains exactly how this works.
3. What we process and why
We process only what is needed to give you an account, let you generate reports and collect payment. We do not profile users, we do not send unsolicited newsletters, we do not sell or share data for marketing purposes, and we run no behavioural analytics.
| Category of data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Account data: email address, name (optional), password stored only as a bcrypt hash; if you sign in with Google, the name, email and profile picture Google passes on | Creating and managing your account, authenticating you, allowing password recovery | Art. 6(1)(b) GDPR — performance of the contract | For the life of the account and up to 30 days after a deletion request (backups up to 90 days) |
| Practice data: name and address of your practice, physician's name, logo and signature image you upload | Branding the header of the PDF report with your practice's details | Art. 6(1)(b) GDPR — performance of the contract | Until the account is deleted or the configuration is changed |
| Report ledger: a random report identifier, timestamp, language, whether the report was free or paid, and a salted SHA-256 hash of the IP address | Enforcing the licence you purchased, counting free reports already used, detecting abuse of the free report (serial account creation) | Art. 6(1)(b) and Art. 6(1)(f) GDPR — performance of the contract and legitimate interest in preventing abuse | The row stays for the life of the account, because it is the record of the licence you hold; the IP hash is removed once the few-day window in which it serves to detect abuse has passed |
| Payment data: checkout session identifier, amount, currency, status, and the billing and tax details you enter on Stripe | Collecting the one-off fee and issuing and retaining accounting records | Art. 6(1)(b) GDPR — performance of the contract; Art. 6(1)(c) GDPR — tax and accounting obligations | Accounting documents 10 years from the entry (Art. 2220 of the Italian Civil Code and tax law); the technical transaction data until the account is deleted |
| Technical and security data: IP address, browser type, request timestamps, failed login attempts, session and password-reset tokens | Keeping the Service running, protecting it against unauthorised access, rate-limiting password guessing | Art. 6(1)(f) GDPR — legitimate interest in network and information security | Login attempts: minutes. Tokens: until expiry. Hosting provider logs: typically 30 days |
| Correspondence: the content of emails or messages you send us for support | Answering your requests and handling disputes | Art. 6(1)(b) and Art. 6(1)(f) GDPR — performance of the contract and legitimate interest in defending legal claims | Up to 24 months from the last contact, unless a dispute is pending |
Providing the data marked as required in our forms is necessary to activate the account and use the Service: without it we cannot technically provide the Service. Providing any other data is optional and withholding it does not affect your use of the Service.
4. Data about the worker being tested
The intake questionnaire, the worker's identifying details, the answers to the seven tests and the final report are health data — special categories of personal data under Article 9 GDPR. The Service is built so that we never receive them.
- Data entered during a screening stays in the browser's memory, on the professional's device, and is never transmitted to our servers at any point.
- The PDF report is assembled entirely in the browser: it never passes through us, we do not store it and we keep no copy.
- If you interrupt a screening to complete payment, the data entered is saved temporarily in the browser's sessionStorage for at most two hours so you can pick up where you left off. sessionStorage is cleared when the browser closes, and the logo and signature are never written to it.
- The only thing that reaches our servers when you download a report is a random report identifier carrying no reference whatsoever to the worker: it exists solely to decrement your report counter.
Because we never come into possession of the worker's health data, we consider that the conditions for appointing us as a processor under Article 28 GDPR are not met. That said, on request we will still sign a data processing agreement, or issue a written statement describing the architecture set out here: write to the address in section 14.
All obligations concerning the worker's data remain with the professional using the Service: identifying the legal basis for the processing (typically Art. 9(2)(h) GDPR for occupational medicine, read together with Art. 41 of Italian Legislative Decree 81/2008), providing their own privacy notice to the data subject, storing the report securely and observing professional secrecy. Giuseppe Buomprisco is not responsible for what the professional does with the report once it has been generated.
5. Who we share data with
We do not sell or trade your data. We share it only with the providers that make the Service technically possible, each appointed as a processor under Article 28 GDPR and bound to process it only on our instructions.
| Provider | Role | Data involved |
|---|---|---|
| Stripe Payments Europe, Ltd. (Ireland) | Card payment processing | Billing details, amount, outcome. Card details are handled by Stripe directly and are never disclosed to us |
| MongoDB, Inc. / MongoDB Atlas | Managed database | All account and licence data |
| Render Services, Inc. | Server-side application hosting | Data sent to the API and technical logs |
| Netlify, Inc. | Website and web app hosting and CDN | Connection data (IP address, user agent) |
| Transactional email provider (Resend / configured SMTP provider) | Sending system emails such as password resets | Email address and message content |
| Google Ireland Limited | Sign in with Google, only if you choose to use it | Google account identifier, name, email and profile picture |
| Accountants and tax advisers | Administrative and tax compliance | Billing data |
Data may also be disclosed to public authorities where required by law or necessary to establish, exercise or defend legal claims. An up-to-date list of processors is available on request at assistenza@medcompetente.it.
6. Transfers outside the European Economic Area
Some of the providers listed above are established in the United States or may process data outside the European Economic Area. Where that happens, the transfer relies on one of the safeguards set out in Chapter V GDPR: an adequacy decision of the European Commission — in particular the EU-U.S. Data Privacy Framework for providers certified under it — or the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, supplemented where necessary by additional measures.
Some of the services we use operate in regions outside the European Union, in particular in the United States. At any time, and at no cost, you can ask for an up-to-date statement of where the data sits and a copy of the safeguards in place for each provider by writing to assistenza@medcompetente.it.
7. How long we keep data
Retention periods are stated per category in the table in section 3. In short:
- Account data is kept for as long as the account exists. The application exposes no self-service deletion: erasure is carried out manually by the controller on a request sent to the address in section 14, without undue delay and in any case within 30 days, and covers the account, licence, practice configuration, sessions and report records.
- The IP address hash exists to detect abuse of the free report over a window of a few days. Past that window it serves no purpose and is removed during the controller's periodic housekeeping; the report row it belonged to remains, without the hash, because it is the record of your licence.
- Accounting and tax records relating to your payment are kept for 10 years, as Italian law requires: that obligation overrides a deletion request, and it covers the accounting documents only, not the whole technical history of the payment.
- Technical and security data is short-lived: login attempt counters last minutes, session and reset tokens expire on their own, and hosting provider logs follow the rotation those providers set.
- Backups managed by the database provider follow the rotation of the plan in use: removal from live systems is immediate, removal from backups happens at the next rotation cycle.
Erasure being a manual operation narrows neither its scope nor its deadline: Article 17 GDPR is exercised by writing to the controller, and the request is handled within the time limits in section 10. If you would rather verify that it happened, ask in the same email and you will get written confirmation.
9. Security
We apply technical and organisational measures appropriate to the risk, in accordance with Article 32 GDPR, including:
- all data transmitted over encrypted connections (HTTPS/TLS);
- passwords stored only as bcrypt hashes, never in plaintext and never reversible;
- session tokens in httpOnly, Secure cookies, with an expiry;
- per-account data isolation: no user can reach another user's configuration or reports;
- automatic rate limiting of repeated login attempts;
- IP addresses retained only as SHA-256 hashes with a secret salt, not traceable to the original address without that salt;
- data minimisation at source: health data never leaves the professional's device.
No security measure can be considered absolute. In the event of a personal data breach posing a risk to the rights and freedoms of data subjects, we will notify the Italian Data Protection Authority within 72 hours and, where the risk is high, inform the data subjects, in accordance with Articles 33 and 34 GDPR.
10. Your rights
You may exercise the rights granted by Articles 15 to 22 GDPR at any time:
- access: obtain confirmation that processing is taking place and receive a copy of the data (Art. 15);
- rectification: correct inaccurate data or complete incomplete data (Art. 16);
- erasure: have data removed where we are not required by law to keep it (Art. 17);
- restriction: ask that processing be suspended in the cases provided for (Art. 18);
- portability: receive the data you provided in a structured, machine-readable format, or have it transmitted to another controller (Art. 20);
- objection: object at any time, on grounds relating to your particular situation, to processing based on legitimate interest (Art. 21).
To exercise these rights, write to assistenza@medcompetente.it. We reply within one month of receiving the request, extendable by two further months for particularly complex requests, in which case we will tell you. Exercising your rights is free of charge, unless requests are manifestly unfounded or excessive.
If you believe the processing of your data infringes the GDPR, you have the right to lodge a complaint with the Italian Data Protection Authority — Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, Italy; phone +39 06 696771; email garante@gpdp.it; certified email protocollo@pec.gpdp.it; www.garanteprivacy.it — or with the supervisory authority of the Member State where you reside. Your right to seek a judicial remedy is unaffected.
11. Automated decision-making and profiling
We carry out no automated decision-making or profiling within the meaning of Article 22 GDPR. Test results are computed locally on the device, serve as screening support only, and in no way replace the assessment and diagnosis of a healthcare professional.
12. Minors
The Service is addressed to professionals acting in the course of their work and is not intended for minors. We do not knowingly collect data about minors through account registration. If you believe a minor has created an account, tell us and we will delete it.
13. Changes to this policy
This policy may be updated to reflect changes to the Service, to the providers we use or to applicable law. The version in force is always published on this page, with its last-updated date and version number. Where changes are substantial, we will notify registered users by email or inside the application before they take effect.
14. Contact
For any question about this policy or about the processing of your personal data, write to assistenza@medcompetente.it. It is the same address as support, watched daily and by design: requests concerning personal data are recognised and handled as such. If you need a postal address for the controller — for registered post or a formal complaint — ask there and it will be provided at no cost.