Last updated: 26/01/2026 (v1.0)
This Privacy Policy, drafted pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR"), describes how personal data of users accessing the EasyRefert platform and using its services is collected, processed, and protected.
Personal data processing is carried out in full compliance with applicable data protection regulations, including:
The Data Controller for personal data relating to the EasyRefert platform is:
ITLand S.r.l.
Registered Office: Via Pietro Castellino, 179 - 80131 Napoli (NA)
Operational Office: Via Antiniana, 2i - 80078 Pozzuoli (NA)
VAT Number: IT09130391213
Email: support@itland.it
Certified Email (PEC): info@pec.itland.it
You can contact the Data Protection Officer (DPO) for all matters related to personal data processing and exercising your rights under the GDPR:
DPO Email: privacy@itland.it
During use of the EasyRefert platform, the following categories of common personal data may be collected and processed:
The EasyRefert platform is designed for processing health-related data pursuant to Article 4(15) and Article 9 of the GDPR, which constitute "special categories of personal data" subject to enhanced protection.
Healthcare facilities may process the following through the platform:
Personal data is processed for the following purposes, each based on a specific legal basis:
| Purpose | Legal Basis | Nature of Provision |
|---|---|---|
| Provision of the EasyRefert service Delivery of platform functionalities (report management, DICOM image storage, PDF generation, internal messaging) |
Performance of a contract (Art. 6(1)(b) GDPR) | Mandatory - service cannot be provided without this data |
| Health data processing Management of medical reports, diagnostic images, and healthcare documentation on behalf of client healthcare facilities |
Explicit patient consent (Art. 9(2)(a) GDPR) or necessity for reasons of public interest in public health or preventive medicine (Art. 9(2)(h) and (i) GDPR) | Mandatory for the provision of healthcare services |
| Tax, accounting, and administrative obligations Invoice issuance, payment management, tax compliance |
Legal obligation (Art. 6(1)(c) GDPR) | Mandatory by law |
| Technical assistance and customer support Handling support requests, resolving technical issues |
Performance of a contract (Art. 6(1)(b) GDPR) | Optional - but necessary to receive assistance |
| IT security Fraud prevention, protection against unauthorized access, data backup, audit logs |
Legitimate interest and legal obligation (Art. 6(1)(f) and (c) GDPR) | Mandatory to ensure platform security |
| Statistical analysis and service improvement Aggregated anonymous statistics on platform usage |
Legitimate interest of the Controller (Art. 6(1)(f) GDPR) | Optional - data processed anonymously |
| Marketing and promotional communications Sending newsletters, commercial communications about similar products and services |
Optional consent (Art. 6(1)(a) GDPR) and Art. 130 Legislative Decree 196/2003 | Optional - can be withdrawn at any time |
| Analytics cookies Use of Google Analytics 4 for web traffic analysis |
Optional consent (Art. 6(1)(a) GDPR) according to Italian Data Protection Authority Cookie Guidelines | Optional - managed via cookie banner |
Personal data is processed using electronic and digital tools, with methods strictly related to the stated purposes, and in any case in a manner that ensures the security and confidentiality of the data.
Processing is carried out by specifically authorized and trained personnel of the Controller, who have received adequate operational instructions.
Personal data may be disclosed to the following parties, acting as data processors or independent controllers:
The complete and updated list of Data Processors is available at the Controller's premises and can be requested by writing to support@itland.it.
Personal data is not subject to public disclosure. Access to health data is reserved exclusively for authorized healthcare personnel of the healthcare facility that controls the data.
Personal data is stored on servers located within the European Union (EU) and the European Economic Area (EEA).
Some third-party services used by the platform (e.g., Google Analytics) may involve data transfers to non-EU/EEA countries. In such cases, transfers occur exclusively:
For more information on the safeguards adopted for non-EU data transfers, please contact the DPO at privacy@itland.it.
The Controller implements adequate technical and organizational security measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR, including:
Personal data is retained for the time strictly necessary to achieve the purposes for which it was collected, in compliance with the minimization principle under Article 5 GDPR.
Specifically, data is retained for the following periods:
| Data Category | Retention Period | Justification |
|---|---|---|
| Personal and contractual data | 10 years from termination of the contractual relationship | Tax and accounting obligations (Art. 2220 Italian Civil Code) |
| Health data (reports and DICOM images) | According to the provisions of the healthcare facility controller, in compliance with applicable healthcare regulations (generally not less than 10 years) | Healthcare regulations and medical ethics |
| Tax data and invoices | 10 years from the date of issue | Art. 2220 Italian Civil Code and tax regulations |
| Browsing data and logs | 12 months from the date of recording | Legislative Decree 196/2003 and Data Protection Authority provisions |
| Cookie and marketing consents | Until consent withdrawal + 5 additional years to demonstrate consent given | Accountability and burden of proof (Art. 7(1) GDPR) |
| Security audit logs | 24 months from recording | IT security and access traceability |
| Support requests | 3 years from ticket closure | Contractual documentation and service quality |
After the retention periods expire, personal data is securely and irreversibly deleted or permanently anonymized.
As a data subject, you have the right to exercise the rights provided under Articles 15 to 22 of the GDPR against the Controller:
Obtain confirmation of whether your data is being processed and access such data, obtaining a copy in a structured format.
Obtain correction of inaccurate or incomplete personal data without undue delay.
Obtain erasure of personal data ("right to be forgotten") when the legal requirements are met.
Obtain restriction of processing when the regulatory requirements are met.
Receive personal data in a structured, commonly used, and machine-readable format, and transmit it to another controller.
Object to processing of personal data based on legitimate interest or for direct marketing purposes.
Withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Lodge a complaint with the Data Protection Authority if you believe that processing violates the GDPR.
To exercise the above rights, the data subject may send a written request via:
The Controller will respond to the request without undue delay and, in any case, within one month of receiving the request. This period may be extended by two months in case of particularly complex requests.
Without prejudice to any other administrative or judicial remedy, the data subject who believes that the processing concerning them violates the GDPR has the right to lodge a complaint with the Italian Data Protection Authority:
Garante per la Protezione dei Dati Personali
Piazza Venezia, 11 - 00187 Rome (RM)
Tel: +39 06 696771
Fax: +39 06 69677785
Email: garante@gpdp.it
Website: www.garanteprivacy.it
The Controller does not carry out fully automated decision-making processes pursuant to Article 22 GDPR, nor profiling activities based on users' personal data.
Any statistical analyses are performed exclusively on aggregated and anonymous data that does not allow identification of the data subject.
The Controller reserves the right to modify, update, and supplement this Privacy Policy at any time to adapt it to any regulatory changes, modifications to the services offered, or other operational needs.
Changes will be communicated to users by publishing the updated version on the website, indicating the date of the last update. In case of substantial changes requiring new consent, users will be informed with adequate notice and a new consent will be requested.
Users are invited to periodically consult this page to stay updated on how personal data is processed.
For any questions, clarification requests, or to exercise the rights provided by the GDPR regarding this Privacy Policy, you may contact:
ITLand S.r.l.
Email: support@itland.it
PEC: info@pec.itland.it
Tel: +39 081 18096512
Data Protection Officer
Email: privacy@itland.it
Contact hours: Lunedì-Venerdì 09:00-13:00, 14:00-18:00
ITLand S.r.l.
VAT: IT09130391213
Registered Office: Via Pietro Castellino, 179 - 80131 Napoli (NA)
Email: support@itland.it
PEC: info@pec.itland.it
Tel: +39 081 18096512