Draft under review. The highlighted items must be confirmed by the practice before final publication. The Italian version is the reference text.
Notice under Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR").
1. Data controller
The controller of personal data is:
Studio Odontoiatrico Conti Cortesi [full legal name to be confirmed]
Viale di Trastevere, 108 — Building B, Unit 2 — 00153 Rome, Italy
VAT no. 11144031009
Email: info@emotionaldentistry.it — Certified email (PEC): [to be provided]
Phone: +39 06 5800729
For any request about the processing of personal data, contact the controller at the details above.
2. What this notice covers
This notice covers data processed through the website emotionaldentistry.it and the contact channels it lists (phone, email, WhatsApp). It does not cover patients' health data collected during visits and treatment: for those the practice provides a specific notice on site, at registration.
3. Types of data processed
a) Data you provide voluntarily. The website has no contact forms and no visitor accounts. If you choose to write to or call the practice, you provide the data needed to receive a reply: name, phone number or email address and the content of your message. Providing them is optional; without a contact detail we cannot reply.
Please do not send reports, X-rays or detailed descriptions of your health by email or WhatsApp: a name and a contact detail are enough to book a first visit. Any health information sent spontaneously is processed only to answer your request.
b) Browsing data. The systems that run the website acquire, in normal operation, some data whose transmission is implicit in the use of Internet protocols (IP address, date and time of the request, page requested, browser type). They are not collected to identify visitors and are used only to keep the website working and secure.
c) Access to the administration area. The website's administration area is reserved for the practice's staff. For security reasons the system records the date, time, outcome, username and network address (for IPv6 addresses, the /64 prefix only) of sign-in attempts. These data are used only to prevent unauthorised access (legal basis: legitimate interest, Art. 6(1)(f)) and are deleted automatically after 180 days.
4. Purposes and legal basis
a) Answering contact requests (information, appointments, first visit). Legal basis: steps taken at the request of the data subject prior to entering into a contract (Art. 6(1)(b) GDPR). For any health information provided spontaneously: the data subject's consent, expressed by sending it (Art. 9(2)(a)).
b) Complying with legal obligations, where applicable. Legal basis: Art. 6(1)(c) GDPR.
c) Security and proper functioning of the website. Legal basis: the controller's legitimate interest (Art. 6(1)(f) GDPR).
Data collected through the website and the contact channels are not used for marketing or profiling and are not passed to third parties for commercial purposes. The website uses no analytics or tracking tools.
5. How data are processed and secured
Processing is carried out with electronic tools, with technical and organisational measures appropriate to ensure security and confidentiality (Art. 32 GDPR). The website is served only over an encrypted connection (HTTPS). Messages are read only by authorised staff of the practice.
6. Contact via WhatsApp
Among its contact channels the practice offers WhatsApp on +39 392 430 7792. The channel is used only on the user's initiative. The service is provided by WhatsApp Ireland Limited / Meta Platforms, Inc., which processes data related to the use of the app (phone number, message metadata, device information) as an independent controller, under its own privacy policy: whatsapp.com/legal/privacy-policy-eea. Using WhatsApp may involve transfers of data outside the EU, based on the safeguards adopted by the provider under Chapter V GDPR. If you prefer not to use WhatsApp, you can reach the practice by phone or email.
7. Recipients
Data are not disseminated. They may be accessed, within their respective remit, by: authorised staff of the practice; providers of the technical services needed to run the website and email, appointed as processors where required (Art. 28 GDPR); parties to whom disclosure is required by law.
The website is hosted by Netsons s.r.l., on servers located in Italy [to be confirmed]. The email service is provided by [provider to be indicated].
8. Transfers outside the EU
Except as described in section 6 and for the Google map described in the Cookie Policy (loaded only at the user's request), data are processed within the European Union. Any transfer outside the EU will comply with the safeguards of Chapter V GDPR.
9. Retention
Messages received by email or WhatsApp are kept for the time needed to handle the request and, afterwards, for a maximum of 24 months [to be confirmed], unless the person becomes a patient of the practice (in which case the terms of the notice provided on site apply) or retention is needed to establish, exercise or defend a legal claim. Browsing data are kept for the technically necessary time, normally no longer than 30 days.
10. Your rights
Under Articles 15–22 GDPR you may: obtain access to your data (Art. 15); have them rectified (Art. 16) or erased, where applicable (Art. 17); obtain restriction of processing (Art. 18); receive your data in a structured format — portability (Art. 20); object to processing based on legitimate interest (Art. 21); withdraw any consent given at any time, without affecting the lawfulness of earlier processing.
Requests should be sent to the controller at the details in section 1; a reply is given within one month. If you believe the processing infringes the GDPR you may lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or bring legal proceedings.
11. Cookies
The website uses technical cookies only, needed for it to work and stay secure. It uses no profiling cookies and no third-party tracking tools, which is why it shows no consent banner. Details are in the Cookie Policy.
12. Automated decision-making
The controller carries out no processing involving automated decision-making, including profiling (Art. 22 GDPR).
13. Changes
The controller may update this notice, also following changes in the law or in the website. Changes take effect when published on this page.
Last updated: 1 October 2026