This Privacy Policy is provided pursuant to Article 13 of Regulation (EU) 2016/679 (also referred to below as the “Regulation” or the “GDPR”) to inform those who interact with the website “Himetop — The History of Medicine Topographical Database” of Università Campus Bio-Medico di Roma (the “Website”) about how personal data will be processed, both through the mere browsing of the Website and through the use of the functionalities made available through it, including the search and consultation of contents, any access to the reserved area by authorised users, and the sending of communications to the contact details indicated on the Website.
This Privacy Policy is provided exclusively for the Website indicated above and does not apply to any other websites, sections, pages or online spaces owned by third parties that users may access through specific links, for which reference should be made to the respective privacy policies.
1. Controller and Data Protection Officer
The Controller is Università Campus Bio-Medico di Roma (“UCBM”, the “University” or the “Controller”), Tax Code 97087620585, with registered office in Rome, Via Álvaro del Portillo no. 21.
The Data Protection Officer (“DPO”) may be contacted at the following addresses:
- by e-mail at: [email protected];
- by ordinary mail at the address of Università Campus Bio-Medico di Roma, Via Álvaro del Portillo no. 21, 00128 Rome (RM), Italy, for the attention of the Data Protection Officer.
2. Personal data processed
Please note that, when you use the Website, the Controller may collect and process information and personal data relating to you which, depending on the functionalities used and/or the services requested, may include identifiers such as your name, an identification number, location data, an online identifier, or one or more factors specific to your physical, physiological, mental, economic, cultural or social identity, which may identify you or make you identifiable (“Personal Data”).
In particular, the Controller will process the following categories of Personal Data:
a. Browsing Data
The Controller will process the Personal Data collected in the context of your browsing of the Website. Such Personal Data includes, for example, the IP address, location (country), the domain names of the computer or device used by you, the URI (Uniform Resource Identifier) addresses of the resources requested on the Website, the time of the requests, the method used to submit the requests to the server, the size of the file obtained in response to a request, the numerical code indicating the status of the response given by the server (successful, error, etc.), and so on.
Indeed, the operation of the Website involves the use of IT systems and software procedures that collect information about users of the Website as part of their normal operation. Although the Controller does not collect such information for the purpose of linking it to specific users, it is nevertheless possible to identify such users either directly through such information or by using other information collected. As such, this information is also considered Personal Data.
b. Common data voluntarily provided
The Controller will process the Personal Data that you may provide in the context of requests sent to the e-mail address indicated on the Website, including through the “Contact” section available in the footer of the Website, as well as in connection with any communications sent for the purpose of requesting information, proposing collaborations, reporting issues, errors, corrections or additions to the contents published on the Website, or sending further communications relating to the Himetop project.
The Controller may also process the Personal Data that may be provided by authorised users in connection with access to the reserved area of the Website through the “Login” section and the use of the relevant functionalities, including, where available, the creation, editing or management of contents, entries, updates or further materials relating to the Himetop project, including with reference to the “Community Live Feed” section.
When sending requests or communications to the Controller, as well as when using any reserved functionalities of the Website, you are invited to provide only the Personal Data that are strictly necessary, excluding any Personal Data that are excessive or not relevant.
c. Cookie
The Controller will process the Personal Data collected through cookies and other tracking technologies. For further information on the Personal Data processed through cookies and other tracking technologies, please refer to the relevant Cookie Policy.
3. Purposes and legal basis of the processing
Your Personal Data will be processed for the following purposes:
a. To enable browsing of the Website, including the management of the Website’s security
The Controller will process, pursuant to Article 6(1)(b) of the Regulation (legal basis: performance of a contract to which the data subject is party or performance of pre-contractual measures taken at the request of the data subject), the Personal Data referred to in paragraph 2, letter a), in order to enable access to and browsing of the Website, as well as to ensure its proper functioning.
b. Managing and responding to requests for information, collaboration, correction or integration submitted through the contact details available on the Website
The Controller will process, pursuant to Article 6(1)(b) of the Regulation (legal basis: performance of a contract to which the data subject is party or performance of pre-contractual measures taken at the request of the data subject), the Personal Data referred to in paragraph 2, letter b), in order to manage and respond to requests submitted to the e-mail address indicated on the Website, including through the “Contact” section, such as requests for information, collaboration proposals, reports of issues, errors, corrections or additions to the contents published on the Website, as well as further communications relating to the Himetop project.
The provision of Personal Data for these purposes is optional; however, failure to provide such data would make it impossible for the Controller to manage and respond to the request submitted.
Once provided, your Personal Data may also be processed for the following purposes:
c. Complying with obligations provided for by laws, regulations or EU legislation, or satisfying requests from competent authorities
The Controller will process, pursuant to Article 6(1)(c) of the Regulation (legal basis: legal obligation), the Personal Data referred to in paragraph 2 in order to comply with applicable legal obligations.
d. Meeting any defensive needs, including the identification, prevention, mitigation and detection of fraudulent or unlawful activities in relation to the services offered through the Website
The Controller will process, pursuant to Articles 6(1)(f) and 9(2)(a) of the Regulation (legal basis: legitimate interest), the Personal Data referred to in paragraph 2 in order to protect its rights and/or legitimate interests in judicial and extrajudicial proceedings.
4. Recipients of Personal Data
Your Personal Data may be shared, for the purposes indicated in paragraph 3 of this Privacy Policy, with the following subjects, collectively referred to as “Recipients”:
- persons authorised by the Controller, pursuant to Articles 29 and 32 of the Regulation and Article 2-quaterdecies of Legislative Decree no. 196/2003 (Italian “Privacy Code” or “Codice Privacy”), to process the personal data necessary to carry out activities strictly connected with the provision of the services, who have undertaken to maintain confidentiality or are subject to an appropriate statutory obligation of confidentiality;
- entities that typically act as processors pursuant to Article 28 of the Regulation, on behalf of the Controller, in particular entities entrusted with the provision of services necessary for the use of the Website, such as hosting providers, technical maintenance service providers, training service providers, etc. The complete list of processors is available by sending a written request to the DPO using the contact details indicated in paragraph 1 of this Privacy Policy;
- furthermore, the Controller may disclose your Personal Data to persons, entities or authorities where such disclosure is mandatory under legal provisions or pursuant to orders issued by the competent authorities. These subjects will process the Personal Data as independent controllers.
5. Transfers of Personal Data
As a rule, the Controller does not transfer your data outside the European Union. In certain specific circumstances, such as for purposes connected with the electronic storage and management of data, some of your data may be provided to Recipients who transfer them to third countries. In such cases, the Controller ensures that any processing of personal data by Recipients located in third countries outside the European Economic Area (EEA) or by international organisations will take place in compliance with the applicable legislation, or in accordance with one of the mechanisms permitted by law pursuant to Articles 44–49 of the GDPR, such as, for example, the data subject’s consent, the adoption of Standard Contractual Clauses approved by the European Commission, or the selection of entities participating in international programmes for the free flow of data, in compliance with Recommendations 01/2020 adopted on 10 November 2020 by the European Data Protection Board.
Further information on the data transfers carried out and on the safeguards adopted for this purpose may be requested by writing to the DPO at the addresses indicated in paragraph 1 of this Privacy Policy.
6. Retention of Personal Data
The Personal Data processed for the purposes indicated in paragraph 3, letters a) and b), of this Privacy Policy will be processed for the time strictly necessary to achieve those purposes, in compliance with the principles of data minimisation and storage limitation pursuant to Article 5(1)(c) and (e) of the Regulation.
The Personal Data processed for the purposes indicated in paragraph 3, letter c), of this Privacy Policy will be retained for the period provided for by the relevant specific obligation or by the applicable legislation.
The Controller also reserves the right to retain Personal Data for the time necessary to establish and exercise its rights and/or to meet any defensive needs in judicial and extrajudicial proceedings, including pre-litigation phases.
Further information on the data retention period and on the criteria used to determine such period may be requested by writing to the DPO using the contact details indicated in paragraph 1.
7. Data subject’s rights
As a data subject, you have the right to exercise the following rights at any time:
- Right of access (Article 15 of the Regulation) — you have the right to obtain confirmation as to whether or not your personal data are being processed, as well as the right to receive any information relating to such processing.
- Right to rectification (Article 16 of the Regulation) — you have the right to obtain the rectification of your personal data where they are incomplete or inaccurate.
- Right to erasure (Article 17 of the Regulation) — in certain circumstances, you have the right to obtain the erasure of your personal data from our records.
- Right to restriction of processing (Article 18 of the Regulation) — under certain conditions, you have the right to obtain the restriction of the processing of your personal data.
- Right to data portability (Article 20 of the Regulation) — you have the right to obtain the transfer of your personal data to another controller, as well as the right to receive the data concerning you in a structured, commonly used and machine-readable format.
- Right to object (Article 21 of the Regulation) — you have the right to submit a request to object to the processing of your personal data, providing the reasons justifying such objection; the Controller reserves the right to assess the request, which may not be granted where there are compelling legitimate grounds that override your interests, rights and freedoms.
Furthermore, if you believe that the processing of your Personal Data infringes data protection legislation, you have the right, pursuant to Article 77 of the Regulation, to lodge a complaint with the supervisory authority of the Member State where you habitually reside or work, or of the place where the alleged infringement occurred.
To exercise the rights indicated above, you may write to the DPO at the registered office in Rome, Via Álvaro del Portillo no. 21, for the attention of the DPO, or at the e-mail address [email protected].
8. Updates to this Privacy Policy
The Controller reserves the right to amend or simply update, in whole or in part, the content of this Privacy Policy, including in light of any changes to the applicable legislation. Therefore, the Controller invites you to regularly visit this section in order to review the most recent and updated version of the Privacy Policy, so that you may always be informed about the data collected and how they are processed.
9. How to contact the Controller and exercise the data subject’s rights
In case of any questions or doubts concerning the processing of Personal Data, or in order to exercise any of the rights mentioned above, the data subject may send a written communication by registered letter with return receipt to Università Campus Bio-Medico di Roma, with registered office in Rome, Via Álvaro del Portillo no. 21, for the attention of the DPO — Data Protection Officer, or by e-mail to [email protected].