Ultimo aggiornamento: Gennaio 2025
Il GDPR (General Data Protection Regulation) è il Regolamento Europeo 2016/679 che tutela i diritti e le libertà fondamentali delle persone fisiche, in particolare il diritto alla protezione dei dati personali.
1. Titolare del Trattamento e Contatti
Ai sensi dell'art. 13 del Regolamento UE 2016/679, il Titolare del trattamento dei dati personali è:
- Denominazione: Medlinker
- Sede: Padova, Italia
- Email: info@medlinker.it
- Telefono: +39 327 881 1776
2. Cosa Prevede il GDPR
Il Regolamento UE 2016/679 (GDPR) stabilisce norme rigorose per la protezione dei dati personali. In particolare:
- Definisce regole chiare su raccolta e trattamento dei dati
- Richiede il consenso esplicito per determinati trattamenti
- Garantisce maggiori diritti agli interessati
- Impone obblighi di sicurezza ai titolari del trattamento
- Prevede sanzioni in caso di violazioni
3. I Tuoi Diritti
Il GDPR garantisce agli interessati i seguenti diritti (artt. 15-22):
3.1 Diritto di Accesso (Art. 15)
Hai il diritto di ottenere conferma che sia o meno in corso un trattamento di dati personali che ti riguardano e, in tal caso, di ottenere l'accesso ai dati e alle seguenti informazioni:
- Finalità del trattamento
- Categorie di dati trattati
- Destinatari dei dati
- Periodo di conservazione
- Origine dei dati
3.2 Diritto di Rettifica (Art. 16)
Hai il diritto di ottenere la rettifica dei dati personali inesatti che ti riguardano e l'integrazione dei dati incompleti.
3.3 Diritto alla Cancellazione - Diritto all'Oblio (Art. 17)
Hai il diritto di ottenere la cancellazione dei tuoi dati personali quando:
- I dati non sono più necessari per le finalità per cui sono stati raccolti
- Revochi il consenso su cui si basa il trattamento
- Ti opponi al trattamento
- I dati sono stati trattati illecitamente
3.4 Diritto di Limitazione (Art. 18)
Hai il diritto di ottenere la limitazione del trattamento quando:
- Contesti l'esattezza dei dati
- Il trattamento è illecito ma ti opponi alla cancellazione
- I dati ti servono per l'esercizio di un diritto in sede giudiziaria
- Ti sei opposto al trattamento in attesa di verifica
3.5 Diritto alla Portabilità (Art. 20)
Hai il diritto di ricevere i dati personali che ti riguardano in un formato strutturato, di uso comune e leggibile da dispositivo automatico, e di trasmetterli a un altro titolare.
3.6 Diritto di Opposizione (Art. 21)
Hai il diritto di opporti in qualsiasi momento al trattamento dei dati personali che ti riguardano, compresa la profilazione.
3.7 Diritto alla Revoca del Consenso
Quando il trattamento si basa sul consenso, hai il diritto di revocare il consenso in qualsiasi momento, senza pregiudicare la liceità del trattamento basata sul consenso prestato prima della revoca.
4. Come Esercitare i Tuoi Diritti
Per esercitare i diritti sopra elencati, puoi:
- Inviare un'email a info@medlinker.it specificando la richiesta
- Utilizzare le funzionalità disponibili nell'area riservata del tuo account
- Contattarci telefonicamente al +39 327 881 1776
Risponderemo alla tua richiesta entro 30 giorni dalla ricezione, come previsto dal GDPR.
5. Protezione dei Dati Sensibili
Medlinker tratta dati particolari (dati sensibili) relativi a:
- Dati relativi alla salute (contenuti nei documenti professionali)
- Dati biometrici (contenuti nei documenti di identità)
Questi dati sono trattati con misure di sicurezza rafforzate:
- Crittografia dei dati
- Visualizzazione dei documenti solo nel browser (no download)
- Accesso limitato ai soli utenti autorizzati
- Log di accesso tracciati
6. Misure di Sicurezza
Medlinker adotta misure tecniche e organizzative adeguate per garantire un livello di sicurezza appropriato al rischio:
- Pseudonimizzazione e cifratura dei dati personali
- Capacità di assicurare riservatezza, integrità, disponibilità e resilienza dei sistemi
- Procedure per ripristinare tempestivamente la disponibilità dei dati in caso di incidente
- Procedure di test regolari per valutare l'efficacia delle misure di sicurezza
7. Violazione dei Dati (Data Breach)
In caso di violazione dei dati personali che presenti un rischio per i diritti e le libertà delle persone, Medlinker:
- Notificherà la violazione all'Autorità Garante entro 72 ore
- Comunicherà la violazione agli interessati se il rischio è elevato
- Documenterà l'incidente e le misure adottate
8. Reclamo all'Autorità di Controllo
Se ritieni che il trattamento dei tuoi dati personali violi il GDPR, hai il diritto di proporre reclamo all'Autorità Garante per la Protezione dei Dati Personali:
- Sito web: www.garanteprivacy.it
- Email: protocollo@gpdp.it
- PEC: protocollo@pec.gpdp.it
- Telefono: +39 06 696771
9. Conservazione dei Dati
I dati personali sono conservati per il tempo strettamente necessario alle finalità del trattamento, nel rispetto dei seguenti criteri:
- Dati di registrazione: per tutta la durata del rapporto e per i successivi 10 anni
- Documenti caricati: fino a cancellazione dell'account o richiesta dell'interessato
- Dati di fatturazione: 10 anni (obbligo fiscale)
- Log di accesso: 6 mesi
10. Trasferimento Dati Extra-UE
I dati personali sono conservati su server situati nell'Unione Europea. In caso di trasferimento verso paesi terzi, ciò avverrà:
- Verso paesi con decisione di adeguatezza della Commissione UE
- Con garanzie adeguate (clausole contrattuali standard)
- Con il consenso esplicito dell'interessato
11. Aggiornamenti
Questa informativa può essere aggiornata periodicamente. Gli aggiornamenti saranno pubblicati su questa pagina con indicazione della data di ultimo aggiornamento.
12. Documenti Correlati
13. Contatti per la Privacy
Per qualsiasi domanda relativa al trattamento dei dati personali e all'esercizio dei tuoi diritti:
Última actualización: Enero 2025
El RGPD (Reglamento General de Protección de Datos) es el Reglamento Europeo 2016/679 que protege los derechos y las libertades fundamentales de las personas físicas, en particular el derecho a la protección de los datos personales.
1. Responsable del Tratamiento y Contacto
Conforme al art. 13 del Reglamento UE 2016/679, el Responsable del tratamiento de los datos personales es:
- Denominación: Medlinker
- Sede: Padua, Italia
- Correo electrónico: info@medlinker.it
- Teléfono: +39 327 881 1776
2. Qué Establece el RGPD
El Reglamento UE 2016/679 (RGPD) establece normas rigurosas para la protección de los datos personales. En particular:
- Define reglas claras sobre la recopilación y el tratamiento de los datos
- Exige el consentimiento expreso para determinados tratamientos
- Garantiza más derechos a los interesados
- Impone obligaciones de seguridad a los responsables del tratamiento
- Prevé sanciones en caso de infracciones
3. Tus Derechos
El RGPD garantiza a los interesados los siguientes derechos (arts. 15-22):
3.1 Derecho de Acceso (Art. 15)
Tienes derecho a obtener confirmación de si se está realizando o no un tratamiento de datos personales que te conciernen y, en tal caso, a obtener el acceso a los datos y a la siguiente información:
- Finalidad del tratamiento
- Categorías de datos tratados
- Destinatarios de los datos
- Periodo de conservación
- Origen de los datos
3.2 Derecho de Rectificación (Art. 16)
Tienes derecho a obtener la rectificación de los datos personales inexactos que te conciernen y la integración de los datos incompletos.
3.3 Derecho de Supresión - Derecho al Olvido (Art. 17)
Tienes derecho a obtener la supresión de tus datos personales cuando:
- Los datos ya no sean necesarios para las finalidades para las que fueron recopilados
- Revoques el consentimiento en el que se basa el tratamiento
- Te opongas al tratamiento
- Los datos hayan sido tratados ilícitamente
3.4 Derecho de Limitación (Art. 18)
Tienes derecho a obtener la limitación del tratamiento cuando:
- Impugnes la exactitud de los datos
- El tratamiento sea ilícito pero te opongas a la supresión
- Necesites los datos para el ejercicio de un derecho ante los tribunales
- Te hayas opuesto al tratamiento a la espera de verificación
3.5 Derecho a la Portabilidad (Art. 20)
Tienes derecho a recibir los datos personales que te conciernen en un formato estructurado, de uso común y de lectura mecánica, y a transmitirlos a otro responsable.
3.6 Derecho de Oposición (Art. 21)
Tienes derecho a oponerte en cualquier momento al tratamiento de los datos personales que te conciernen, incluido el perfilado.
3.7 Derecho a Revocar el Consentimiento
Cuando el tratamiento se base en el consentimiento, tienes derecho a revocarlo en cualquier momento, sin que ello afecte a la licitud del tratamiento basado en el consentimiento otorgado antes de la revocación.
4. Cómo Ejercer tus Derechos
Para ejercer los derechos enumerados anteriormente, puedes:
- Enviar un correo electrónico a info@medlinker.it especificando la solicitud
- Utilizar las funcionalidades disponibles en el área privada de tu cuenta
- Contactarnos telefónicamente en el +39 327 881 1776
Responderemos a tu solicitud en un plazo de 30 días desde su recepción, según lo previsto por el RGPD.
5. Protección de los Datos Sensibles
Medlinker trata datos especiales (datos sensibles) relativos a:
- Datos relativos a la salud (contenidos en los documentos profesionales)
- Datos biométricos (contenidos en los documentos de identidad)
Estos datos se tratan con medidas de seguridad reforzadas:
- Cifrado de los datos
- Visualización de los documentos solo en el navegador (sin descarga)
- Acceso limitado únicamente a los usuarios autorizados
- Registros de acceso rastreados
6. Medidas de Seguridad
Medlinker adopta medidas técnicas y organizativas adecuadas para garantizar un nivel de seguridad apropiado al riesgo:
- Seudonimización y cifrado de los datos personales
- Capacidad de garantizar la confidencialidad, integridad, disponibilidad y resiliencia de los sistemas
- Procedimientos para restablecer rápidamente la disponibilidad de los datos en caso de incidente
- Procedimientos de prueba regulares para evaluar la eficacia de las medidas de seguridad
7. Violación de los Datos (Data Breach)
En caso de violación de los datos personales que suponga un riesgo para los derechos y las libertades de las personas, Medlinker:
- Notificará la violación a la Autoridad Garante en un plazo de 72 horas
- Comunicará la violación a los interesados si el riesgo es elevado
- Documentará el incidente y las medidas adoptadas
8. Reclamación ante la Autoridad de Control
Si consideras que el tratamiento de tus datos personales infringe el RGPD, tienes derecho a presentar una reclamación ante la Autoridad Garante para la Protección de los Datos Personales:
- Sitio web: www.garanteprivacy.it
- Email: protocollo@gpdp.it
- PEC: protocollo@pec.gpdp.it
- Teléfono: +39 06 696771
9. Conservación de los Datos
Los datos personales se conservan durante el tiempo estrictamente necesario para las finalidades del tratamiento, respetando los siguientes criterios:
- Datos de registro: durante toda la vigencia de la relación y los 10 años siguientes
- Documentos subidos: hasta la cancelación de la cuenta o la solicitud del interesado
- Datos de facturación: 10 años (obligación fiscal)
- Registros de acceso: 6 meses
10. Transferencia de Datos Fuera de la UE
Los datos personales se conservan en servidores ubicados en la Unión Europea. En caso de transferencia a países terceros, ello se realizará:
- Hacia países con decisión de adecuación de la Comisión UE
- Con garantías adecuadas (cláusulas contractuales estándar)
- Con el consentimiento expreso del interesado
11. Actualizaciones
Esta información puede actualizarse periódicamente. Las actualizaciones se publicarán en esta página indicando la fecha de la última actualización.
12. Documentos Relacionados
13. Contacto para la Privacidad
Para cualquier consulta relativa al tratamiento de los datos personales y al ejercicio de tus derechos:
Last updated: January 2025
The GDPR (General Data Protection Regulation) is European Regulation 2016/679, which protects the fundamental rights and freedoms of natural persons, in particular the right to the protection of personal data.
1. Data Controller and Contact Details
Pursuant to art. 13 of EU Regulation 2016/679, the Data Controller for the processing of personal data is:
- Name: Medlinker
- Office: Padua, Italy
- Email: info@medlinker.it
- Phone: +39 327 881 1776
2. What the GDPR Provides
EU Regulation 2016/679 (GDPR) establishes strict rules for the protection of personal data. In particular, it:
- Defines clear rules on the collection and processing of data
- Requires explicit consent for certain processing
- Guarantees greater rights to data subjects
- Imposes security obligations on data controllers
- Provides for penalties in the event of breaches
3. Your Rights
The GDPR guarantees data subjects the following rights (art. 15-22):
3.1 Right of Access (Art. 15)
You have the right to obtain confirmation as to whether or not personal data concerning you is being processed and, where that is the case, to obtain access to the data and the following information:
- Purposes of the processing
- Categories of data processed
- Recipients of the data
- Retention period
- Source of the data
3.2 Right to Rectification (Art. 16)
You have the right to obtain the rectification of inaccurate personal data concerning you and the completion of incomplete data.
3.3 Right to Erasure - Right to be Forgotten (Art. 17)
You have the right to obtain the erasure of your personal data when:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw the consent on which the processing is based
- You object to the processing
- The data has been unlawfully processed
3.4 Right to Restriction (Art. 18)
You have the right to obtain the restriction of processing when:
- You contest the accuracy of the data
- The processing is unlawful but you object to erasure
- You need the data to establish, exercise or defend a legal claim
- You have objected to the processing pending verification
3.5 Right to Data Portability (Art. 20)
You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format, and to transmit it to another controller.
3.6 Right to Object (Art. 21)
You have the right to object at any time to the processing of personal data concerning you, including profiling.
3.7 Right to Withdraw Consent
Where the processing is based on consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of processing based on consent given before its withdrawal.
4. How to Exercise Your Rights
To exercise the rights listed above, you can:
- Send an email to info@medlinker.it specifying your request
- Use the features available in the account area of your profile
- Contact us by phone at +39 327 881 1776
We will respond to your request within 30 days of receipt, as required by the GDPR.
5. Protection of Sensitive Data
Medlinker processes special categories of data (sensitive data) relating to:
- Health-related data (contained in professional documents)
- Biometric data (contained in identity documents)
This data is processed with enhanced security measures:
- Data encryption
- Document viewing only in the browser (no download)
- Access limited to authorised users only
- Tracked access logs
6. Security Measures
Medlinker adopts appropriate technical and organisational measures to ensure a level of security appropriate to the risk:
- Pseudonymisation and encryption of personal data
- The ability to ensure the confidentiality, integrity, availability and resilience of systems
- Procedures to restore the availability of data promptly in the event of an incident
- Regular testing procedures to assess the effectiveness of security measures
7. Data Breach
In the event of a personal data breach that poses a risk to the rights and freedoms of individuals, Medlinker will:
- Notify the breach to the supervisory authority within 72 hours
- Communicate the breach to the data subjects if the risk is high
- Document the incident and the measures taken
8. Complaint to the Supervisory Authority
If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the competent data protection supervisory authority (in Italy, the Garante per la Protezione dei Dati Personali):
- Website: www.garanteprivacy.it
- Email: protocollo@gpdp.it
- Certified Email (PEC): protocollo@pec.gpdp.it
- Phone: +39 06 696771
9. Data Retention
Personal data is retained for the time strictly necessary for the purposes of the processing, in accordance with the following criteria:
- Registration data: for the entire duration of the relationship and for the subsequent 10 years
- Uploaded documents: until the account is deleted or at the data subject's request
- Billing data: 10 years (tax obligation)
- Access logs: 6 months
10. Transfer of Data Outside the EU
Personal data is stored on servers located within the European Union. In the event of a transfer to third countries, this will take place:
- To countries with an adequacy decision by the EU Commission
- With appropriate safeguards (standard contractual clauses)
- With the explicit consent of the data subject
11. Updates
This information notice may be updated periodically. Updates will be published on this page with an indication of the date of the last update.
12. Related Documents
13. Privacy Contact
For any questions regarding the processing of personal data and the exercise of your rights:
Zuletzt aktualisiert: Januar 2025
Die DSGVO (Datenschutz-Grundverordnung) ist die europäische Verordnung 2016/679, die die Grundrechte und Grundfreiheiten natürlicher Personen schützt, insbesondere das Recht auf den Schutz personenbezogener Daten.
1. Verantwortlicher und Kontaktdaten
Gemäß Art. 13 der EU-Verordnung 2016/679 ist der Verantwortliche für die Verarbeitung personenbezogener Daten:
- Name: Medlinker
- Büro: Padua, Italien
- E-Mail: info@medlinker.it
- Telefon: +39 327 881 1776
2. Was die DSGVO vorsieht
Die EU-Verordnung 2016/679 (DSGVO) legt strenge Regeln zum Schutz personenbezogener Daten fest. Insbesondere:
- Definiert klare Regeln für die Erhebung und Verarbeitung von Daten
- Verlangt eine ausdrückliche Einwilligung für bestimmte Verarbeitungen
- Gewährleistet den betroffenen Personen umfassendere Rechte
- Auferlegt den Verantwortlichen Sicherheitspflichten
- Sieht Sanktionen im Falle von Verstößen vor
3. Ihre Rechte
Die DSGVO gewährleistet den betroffenen Personen die folgenden Rechte (Art. 15-22):
3.1 Auskunftsrecht (Art. 15)
Sie haben das Recht, eine Bestätigung darüber zu erhalten, ob Sie betreffende personenbezogene Daten verarbeitet werden, und in diesem Fall Zugang zu den Daten und den folgenden Informationen zu erhalten:
- Zwecke der Verarbeitung
- Kategorien der verarbeiteten Daten
- Empfänger der Daten
- Speicherdauer
- Herkunft der Daten
3.2 Recht auf Berichtigung (Art. 16)
Sie haben das Recht, die Berichtigung Sie betreffender unrichtiger personenbezogener Daten und die Vervollständigung unvollständiger Daten zu erwirken.
3.3 Recht auf Löschung – Recht auf Vergessenwerden (Art. 17)
Sie haben das Recht, die Löschung Ihrer personenbezogenen Daten zu erwirken, wenn:
- Die Daten für die Zwecke, für die sie erhoben wurden, nicht mehr notwendig sind
- Sie die Einwilligung, auf der die Verarbeitung beruht, widerrufen
- Sie der Verarbeitung widersprechen
- Die Daten unrechtmäßig verarbeitet wurden
3.4 Recht auf Einschränkung (Art. 18)
Sie haben das Recht, die Einschränkung der Verarbeitung zu erwirken, wenn:
- Sie die Richtigkeit der Daten bestreiten
- Die Verarbeitung unrechtmäßig ist, Sie aber die Löschung ablehnen
- Sie die Daten zur Geltendmachung, Ausübung oder Verteidigung von Rechtsansprüchen benötigen
- Sie der Verarbeitung bis zur Überprüfung widersprochen haben
3.5 Recht auf Datenübertragbarkeit (Art. 20)
Sie haben das Recht, die Sie betreffenden personenbezogenen Daten in einem strukturierten, gängigen und maschinenlesbaren Format zu erhalten und sie an einen anderen Verantwortlichen zu übermitteln.
3.6 Widerspruchsrecht (Art. 21)
Sie haben das Recht, jederzeit der Verarbeitung Sie betreffender personenbezogener Daten, einschließlich des Profilings, zu widersprechen.
3.7 Recht auf Widerruf der Einwilligung
Beruht die Verarbeitung auf einer Einwilligung, haben Sie das Recht, Ihre Einwilligung jederzeit zu widerrufen, ohne dass die Rechtmäßigkeit der aufgrund der Einwilligung bis zum Widerruf erfolgten Verarbeitung berührt wird.
4. Wie Sie Ihre Rechte ausüben
Um die oben aufgeführten Rechte auszuüben, können Sie:
- Eine E-Mail an info@medlinker.it senden und Ihre Anfrage angeben
- Die im Kontobereich Ihres Profils verfügbaren Funktionen nutzen
- Uns telefonisch unter +39 327 881 1776 kontaktieren
Wir beantworten Ihre Anfrage innerhalb von 30 Tagen nach Eingang, wie es die DSGVO vorschreibt.
5. Schutz sensibler Daten
Medlinker verarbeitet besondere Kategorien von Daten (sensible Daten) in Bezug auf:
- Gesundheitsdaten (in beruflichen Dokumenten enthalten)
- Biometrische Daten (in Ausweisdokumenten enthalten)
Diese Daten werden mit verstärkten Sicherheitsmaßnahmen verarbeitet:
- Datenverschlüsselung
- Dokumenteneinsicht nur im Browser (kein Download)
- Zugriff nur für autorisierte Nutzer
- Nachverfolgte Zugriffsprotokolle
6. Sicherheitsmaßnahmen
Medlinker ergreift geeignete technische und organisatorische Maßnahmen, um ein dem Risiko angemessenes Sicherheitsniveau zu gewährleisten:
- Pseudonymisierung und Verschlüsselung personenbezogener Daten
- Die Fähigkeit, die Vertraulichkeit, Integrität, Verfügbarkeit und Belastbarkeit der Systeme zu gewährleisten
- Verfahren zur raschen Wiederherstellung der Verfügbarkeit der Daten bei einem Zwischenfall
- Regelmäßige Testverfahren zur Bewertung der Wirksamkeit der Sicherheitsmaßnahmen
7. Datenschutzverletzung (Data Breach)
Im Falle einer Verletzung des Schutzes personenbezogener Daten, die ein Risiko für die Rechte und Freiheiten von Personen darstellt, wird Medlinker:
- Die Verletzung innerhalb von 72 Stunden der Aufsichtsbehörde melden
- Die Verletzung den betroffenen Personen mitteilen, wenn das Risiko hoch ist
- Den Vorfall und die ergriffenen Maßnahmen dokumentieren
8. Beschwerde bei der Aufsichtsbehörde
Wenn Sie der Ansicht sind, dass die Verarbeitung Ihrer personenbezogenen Daten gegen die DSGVO verstößt, haben Sie das Recht, bei der zuständigen Datenschutzaufsichtsbehörde (in Italien der Garante per la Protezione dei Dati Personali) Beschwerde einzulegen:
- Website: www.garanteprivacy.it
- E-Mail: protocollo@gpdp.it
- Zertifizierte E-Mail (PEC): protocollo@pec.gpdp.it
- Telefon: +39 06 696771
9. Speicherdauer der Daten
Personenbezogene Daten werden für die zur Erreichung der Verarbeitungszwecke unbedingt erforderliche Zeit gespeichert, nach folgenden Kriterien:
- Registrierungsdaten: für die gesamte Dauer der Beziehung und die darauffolgenden 10 Jahre
- Hochgeladene Dokumente: bis zur Löschung des Kontos oder auf Wunsch der betroffenen Person
- Abrechnungsdaten: 10 Jahre (steuerliche Pflicht)
- Zugriffsprotokolle: 6 Monate
10. Übermittlung von Daten außerhalb der EU
Personenbezogene Daten werden auf Servern innerhalb der Europäischen Union gespeichert. Im Falle einer Übermittlung in Drittländer erfolgt diese:
- In Länder mit einem Angemessenheitsbeschluss der EU-Kommission
- Mit geeigneten Garantien (Standardvertragsklauseln)
- Mit der ausdrücklichen Einwilligung der betroffenen Person
11. Aktualisierungen
Diese Informationen können regelmäßig aktualisiert werden. Aktualisierungen werden auf dieser Seite mit Angabe des Datums der letzten Aktualisierung veröffentlicht.
12. Zugehörige Dokumente
13. Datenschutz-Kontakt
Bei Fragen zur Verarbeitung personenbezogener Daten und zur Ausübung Ihrer Rechte: