Privacy Policy
1. Purpose of this Privacy Policy
The purpose of this Privacy Policy is to inform users of the website (http://www.carolinecorbin.com) about how their personal data is collected, used, stored, and protected in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (“GDPR”), as well as with applicable Italian data protection legislation.
The protection of privacy and respect for professional confidentiality are fundamental principles of medical practice. Personal data is processed with the utmost care, in compliance with the principles of lawfulness, fairness, transparency, data minimisation, accuracy, storage limitation, and security.
This Privacy Policy applies to the processing of personal data carried out in connection with the use of this website, as well as to the collection of personal data necessary for the management of appointments, the provision of healthcare services, and the preparation of professional documentation.
Administrative data provided in the context of healthcare services, including through electronic forms, are processed in accordance with applicable data protection laws and regulations.
2. Data Controller
The data controller responsible for the processing of personal data is:
Dott.ssa Caroline Corbin
Medical Doctor – Psychotherapist
Corso Magenta 56
20123 Milano – Italy
Email: info@carolinecorbin.com
The data controller determines the purposes and means of the processing of personal data carried out through this website.
3. What Data Is Collected?
Depending on how you use the website, the following categories of data may be collected.
a) Data provided through the contact form
When you use the contact form, you may be asked to provide:
-
surname;
-
first name;
-
email address;
-
telephone number;
-
preferred consultation format (in-office or online);
-
type of consultation (individual consultation, couples consultation, or parental consultation);
-
preferred availability;
-
free-text message (optional).
You remain free not to provide information that is not necessary for your request.
You are advised not to submit detailed medical information or sensitive personal data through the contact form unless such information is strictly necessary for processing your request.
b) Technical data
During your browsing session, certain technical information may be automatically collected, including:
-
IP address;
-
browser type;
-
operating system;
-
browser language;
-
pages visited;
-
date and time of connection;
-
information relating to the device used.
This information is primarily required for the technical operation and security of the website.
c) Cookies
The website uses cookies and similar technologies. Their use is described in detail in the Cookie Policy.
4. Purposes of Processing
Personal data is processed only for specific, explicit, and legitimate purposes.
It may be used in particular to:
-
respond to requests submitted through the contact form;
-
arrange an initial contact prior to a consultation;
-
communicate with individuals who have requested information;
-
ensure the proper technical functioning and security of the website;
-
comply with legal and regulatory obligations applicable to healthcare professionals;
-
manage requests relating to the exercise of rights provided under the GDPR.
Personal data is not used for automated commercial marketing purposes or profiling.
5. Legal Basis for Processing
In accordance with Article 6 of the GDPR, processing activities are based, depending on the circumstances, on:
-
the implementation of pre-contractual measures taken at the request of the data subject when they request an initial contact;
-
compliance with legal obligations applicable to the data controller;
-
the legitimate interest of ensuring the security, operation, and administration of the website;
-
where applicable, the user’s consent, particularly for cookies that are not strictly necessary for the operation of the website.
​Where health data is subsequently processed as part of the therapeutic relationship, such processing is based on the specific legal grounds provided for by the GDPR and applicable regulations governing healthcare professionals.
6. Recipients of Personal Data
Personal data is accessible only to persons who require access in order to perform their duties and who are bound by confidentiality obligations.
Depending on the circumstances, recipients may include:
-
the data controller, Dott.ssa Caroline Corbin;
-
technical service providers involved in website hosting, maintenance, and operation, including the Wix platform;
-
the email service provider used to receive requests submitted through the contact form;
-
Microsoft, when consultations are organised through Microsoft Teams;
-
administrative or judicial authorities where required by law.
Personal data is neither sold, rented, nor transferred to third parties for commercial purposes.
7. Website Hosting and Processors
The website is created and hosted using the Wix platform.
As such, certain technical or personal data may be processed by Wix as a data processor or, in certain cases described in its own documentation, as an independent data controller for specific services.
Email exchanges are processed by the email provider used by the data controller.
When remote consultations are organised, the data required for their provision may be processed by Microsoft Teams in accordance with Microsoft’s terms and privacy policy.
Each service provider is required to implement appropriate technical and organisational measures to ensure a level of security consistent with GDPR requirements.
8. International Transfers of Data
Certain technical service providers used for the operation of the website or for online consultations may be located outside the European Economic Area (EEA) or may process certain data outside the EEA.
In such cases, transfers are carried out only where they are based on one of the mechanisms provided for by the GDPR, including:
-
an adequacy decision adopted by the European Commission;
-
Standard Contractual Clauses adopted by the European Commission;
-
or any other appropriate safeguard provided for by applicable legislation.
9. Data Retention Period
Personal data is retained only for the period necessary to fulfil the purposes for which it was collected.
In particular:
Requests submitted through the contact form
Requests that do not result in patient care or a therapeutic relationship are retained for a maximum period of **six (6) months** and are then deleted, unless a legal obligation requires otherwise.
Correspondence
Email exchanges are retained for the period necessary to process the request.
Technical data
Technical data and security logs are retained for the period necessary for the proper operation, maintenance, and security of the website, in accordance with the hosting provider’s practices.
Patient data
Data processed as part of medical care is not exclusively governed by this Privacy Policy. Such data is retained in accordance with the legal obligations applicable to healthcare professionals in Italy.
10. Data Security
The data controller implements appropriate technical and organisational measures to ensure a level of security appropriate to the risks associated with the processing activities.
These measures are intended in particular to protect data against:
-
accidental or unlawful destruction;
-
loss;
-
alteration;
-
unauthorised disclosure;
-
unauthorised access.
Despite all precautions taken, no electronic transmission or storage system can guarantee absolute security.
11. Your Rights
Under the GDPR, you have the following rights:
-
the right to obtain information about the processing of your data;
-
the right of access to your personal data;
-
the right to request correction of inaccurate or incomplete data;
-
the right to erasure where the legal requirements are met;
-
the right to restriction of processing;
-
the right to object to processing in cases provided for by applicable regulations;
-
the right to data portability where applicable;
-
the right to withdraw your consent at any time where processing is based on consent.
The exercise of certain rights may be limited where processing is necessary to comply with legal obligations applicable to healthcare professionals.
12. Exercising Your Rights
To exercise your rights or ask any questions concerning the processing of your personal data, you may contact:
Dott.ssa Caroline Corbin
Corso Magenta 56
20123 Milano – Italy
Email: info@carolinecorbin.com
A response will be provided within the time limits required by applicable regulations.
13. Right to Lodge a Complaint with the Supervisory Authority
If you believe that the processing of your personal data does not comply with applicable regulations, you have the right to lodge a complaint with the competent supervisory authority.
As the data controller is established in Italy, the competent supervisory authority is the **Garante per la Protezione dei Dati Personali**, without prejudice to your right to contact the supervisory authority of your place of residence where permitted under the GDPR.
14. Protection of Minors
This website is primarily intended for adults.
Where consultations concern children or adolescents, personal data processing is carried out in accordance with applicable rules regarding parental responsibility, consent, and professional confidentiality.
15. Links to Third-Party Websites
The website may contain links to external websites, including mapping services or other useful resources.
The data controller cannot be held responsible for the privacy practices of these websites. Users are encouraged to consult the privacy policies of these websites before using them.
16. Changes to this Privacy Policy
This Privacy Policy may be amended at any time in order to reflect changes in legislation, regulations, technology, or the services offered.
The applicable version is the version published on the website at the time it is consulted.
Changes become effective as soon as they are published online.