PRIVACY POLICY

Effective Date: 10/06/2026

Introduction and Definitions

This notice (“Privacy Notice”) is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and applicable Italian law, including Legislative Decree No. 196/2003, as amended (“Privacy Code”).

For the purposes of this Privacy Policy, the terms listed below, when capitalized, shall have the meanings specified below.

Account: the profile created by the Visitor or Customer to access restricted areas and features of the Site, the Software, or the Services.

App: a mobile, web, or desktop application owned by Eptamed or made available by Eptamed, including its versions, components, updates, and documentation.

Customer: the party—whether a natural person or a legal entity—that enters into a contract with Eptamed through the Website, a restricted area, an Order, or another authorized channel.

Professional Customer: any entity acting in the course of its business, commercial, craft, or professional activities, including professionals, firms, companies, businesses, healthcare facilities, and private entities.

Public Client: the public administration, the contracting authority, the Local Health Authority (ASL), the hospital system, the National Health Service agency, or any other entity subject to public procurement regulations.

Consumer: a natural person acting for purposes unrelated to their business, commercial, craft, or professional activities, as defined by applicable consumer protection laws.

Digital content: data produced and provided in digital format, not provided on a physical medium.

Contract: the agreement entered into between Eptamed and the Customer, consisting—depending on the specific circumstances—of these Legal Notices, the Order, the Data Sheet, the supplementary terms and conditions, the manufacturer’s documentation, the DPA where applicable, and any other documents expressly referenced or accepted.

Customer Data: data, documents, information, content, images, files, and materials uploaded, transmitted, processed, stored, or handled by the Customer through the Software or Services.

Medical Device: A product classified as a medical device by the manufacturer and under applicable regulations, including any variants, configurations, accessories, or components classified as such.

Eptamed: Eptamed S.r.l., as identified in Art. 1.

Order: the contract proposal submitted by the Customer via the Website, a restricted-access area, a form, a platform, or another authorized channel, containing the requested Products or Services and the related specific terms and conditions.

Product: any tangible personal property, medical device, accessory, non-medical product, software, app, digital content, or other item offered or provided by Eptamed.

Product Sheet: The product sheet applicable to the specific Product or Service, in the version in effect at the time of the Order, including, where applicable, specifications, intended use, prices, warnings, instructions, requirements, limitations, and delivery times and methods.

Services: assistance, maintenance, hosting, configuration, integration, training, courses, events, digital content, cloud services, technical support, and any other ancillary or standalone services specified in the Order or in the Data Sheet.

Website: the website www.eptamed.com, including its pages, restricted areas, online store, interfaces, features, and any links to Apps and Services.

Software: programs, modules, portals, cloud components, object code, source code, interfaces, apps, updates, developments, customizations, migrations, and related documentation, within the limits specified in the Order and the Software Specification Sheet.

Durable medium: any medium that enables the recipient to store information addressed personally to them for a period of time appropriate to the purposes for which it is intended and to reproduce it identically.

Registered User: a Visitor who has created an Account through the Site’s registration process.

Visitor: any natural or legal person who accesses or interacts with the Site, regardless of whether they have registered or entered into a Contract.

1. Data Controller

The data controller is Eptamed S.r.l., with its registered office in Cesena (FC), Via Lama 101, ZIP Code 47521, tax ID and VAT number 04107210405, registered with the Romagna – Forlì-Cesena and Rimini Business Register, REA FO-330060, certified email address (PEC) [email protected].

For inquiries regarding the protection of personal data, please contact Eptamed at the email address [email protected] or via certified email (PEC) [email protected].

2. Who it applies to

This privacy notice pertains to personal data processed through the Website www.eptamed.com, restricted areas, the online store, apps, software, cloud services, courses, events, customer support, complaints, and other channels authorized by Eptamed.

According to the specific report, it applies to:

  1. individuals who make purchases for purposes unrelated to their professional or business activities;
  2. individuals acting on behalf of Professional Clients, companies, firms, healthcare facilities, and private entities;
  3. Professional clients who are individuals;
  4. registered users, course and event participants, contacts, employees, contractors, and business contacts;
  5. individuals whose data is disclosed by a Customer or another party for the purpose of performing the Contract.

For Public Sector Clients, this privacy notice applies to the personal data of individuals acting on behalf of the entity, unless otherwise specified in additional privacy notices or agreements required by the public sector relationship.

3. Categories of Data Processed

Eptamed can treat:

  1. identification and personal information;
  2. contact information, including email address, phone number, mailing address, and certified email address (PEC);
  3. billing and payment information, tax information, tax identification number, VAT number, SDI code, and order details;
  4. information regarding the shipment, the recipient, the carrier, and the destination country;
  5. information regarding professional qualifications, professional association or registry, registration number, affiliated organization, and stated authority;
  6. credentials, account information, login logs, IP address, device identifiers, technical and security data;
  7. data related to service requests, complaints, returns, warranties, monitoring, and recalls;
  8. data regarding participation in courses and events, including attendance, certificates, and any continuing medical education (CME) credits;
  9. Customer data uploaded or processed using Software and Services;
  10. images, recordings, or testimonies only when collected on an appropriate legal basis and, where necessary, with separate consent;
  11. data contained in communications addressed to Eptamed and in documents submitted in connection with orders, audits, customer service, complaints, or oversight.

Eptamed asks that you not upload health-related data, patient images, or other data that goes beyond the purpose of the Service. The Customer is responsible for ensuring that it has the necessary legal basis and authorizations for the data it transmits to Eptamed.

4. Consumer Section

When an individual makes a purchase for purposes unrelated to their professional or business activities, Eptamed processes the data primarily to manage registration, orders, payments, deliveries, customer support, returns, legal warranties, complaints, and tax obligations.

Providing the data marked as required on the registration form or in the Order is necessary to create the Account, conclude or perform the Contract, make the delivery, issue the invoice, or process the payment. Failure to provide this information may prevent registration, purchase, or the performance of the service.

Marketing is not required to purchase or use the Site. It is carried out only if the data subject provides separate, freely given, specific, informed, and revocable consent, except for any communications strictly necessary for the management of the existing relationship.

5. Section for Professional Clients and Business Contacts

When an individual acts on behalf of a Professional Client, Eptamed may process data to verify identity, role, authority, professional qualifications, affiliated organization, tax information, intended use, distribution chain, compliance, payments, delivery, support, software, services, training courses, oversight, and security.

Providing the requested data is necessary for the management of the professional relationship, the professional association, the license, the service, or the supply. Eptamed may verify professional and tax information through registries, professional rolls, VIES, or equivalent systems, within the limits of the law.

In B2B relationships, marketing may be conducted on the basis of consent when requested. Eptamed may also use the email addresses of paying customers for communications regarding similar products or services, within the limits and under the conditions set forth in Article 130, paragraph 4, of the Privacy Code, ensuring that customers have the option to opt out at the time of data collection and in every communication.

6. Purposes and Legal Bases

Purpose

Data

Legal Basis

Account Registration and Management

identification data, contact information, credentials, logs

Performance of precontractual measures or the Contract; legitimate interest in security and technical management

Order, Sales, and Supply Management

Personal Information, Contact Information, Tax Information, Order, Delivery

performance of the Contract; compliance with legal obligations

Payments, Billing, and Accounting

identification, tax, payment, and billing information

Performance of the Contract; Legal Obligations

Delivery, Transportation, Customs, and Export Controls

contacts, addresses, destination, end user, documents

performance of the Contract; legal obligations; legitimate interest in fraud prevention and compliance with applicable restrictions

Professional and Supply Chain Audits

qualification, professional registry, organization, VAT number, intended use

performance of the Contract; legal and regulatory obligations; legitimate interest in security and compliance

Software, Apps, Hosting, and Cloud Services

Account, Customer Data, Technical Data, Logs

performance of the Contract; security obligations; legitimate interest in protecting systems

Customer Service, Complaints, Returns, Warranties, and Cancellations

Identifying information, Order, communications, documents

Performance of the Contract; Legal Obligations

Medical Devices, Complaints, Incidents, Withdrawals, and Recalls

Order data, Product, Lot, UDI, Communications

legal and regulatory obligations; performance of the Contract; legitimate interest in security

Courses, Events, Certificates, and Continuing Medical Education (CME)

Identification Information, Enrollment, Attendance, and Certificate

performance of the Contract; legal or regulatory obligations

Security, Fraud Prevention, and Protection of Rights

logs, technical data, communications, data related to disputes

legitimate interest; legal obligations; establishing, exercising, or defending rights

Tax, Administrative, and Accounting Requirements

identification information, tax information, invoices, and payments

legal obligations

Sales and Marketing Communications

contact information, preferences, purchase history

consent, when required; in the case of direct marketing to paying customers, Article 130, paragraph 4, of the Privacy Code, within the applicable limits

Profiling and Personalized Offers

usage data, preferences, and history

separate consent, if given

The processing necessary for registration, the performance of the Contract, and compliance with legal obligations is not based on consent. Merely reviewing this privacy notice does not constitute consent to the processing.

7. Optional Marketing

Consent to marketing is optional, and opting out does not prevent you from registering, placing orders, making purchases, receiving support, or using other Services.

When the data subject provides consent, Eptamed may send marketing communications regarding Products, Medical Devices, Software, Apps, Services, courses, events, and initiatives via email, text message, phone, notifications, or other permitted means. Consent is documented and may be revoked at any time by using the link provided in the communications, through the Account settings, or by writing to Eptamed.

Withdrawal does not affect the lawfulness of processing based on consent given prior to withdrawal.

8. Health-related data and patient images

Eptamed does not normally require health-related data, images, X-rays, fingerprints, or patient identification documents for registration or purchase. Such data must not be uploaded unless it is essential for the Service and has been authorized in advance.

When Eptamed processes health-related data on behalf of the Client, the Client determines the purposes and instructions, and the Parties govern the relationship through a data processing agreement pursuant to Article 28 of the GDPR, where Eptamed acts as a processor. Eptamed processes such data only within the documented limits, applying data minimization, access controls, segregation, pseudonymization, or encryption as appropriate, and any other measures required by the DPA.

Separate and specific consent is required, where necessary, for images, testimonials, recordings, and promotional materials.

9. Processing Methods and Security

Data is processed using paper-based, computerized, and electronic means, in accordance with the principles of lawfulness, fairness, transparency, data minimization, accuracy, storage limitation, integrity, and confidentiality.

Eptamed implements technical and organizational measures appropriate to the risks, including access controls, authorizations, multi-factor authentication where appropriate, encryption or pseudonymization where necessary, TLS, backups, recovery, updates, log monitoring, testing, incident management, training, and business continuity.

No system can guarantee absolute security. The data subject and the Customer must protect their credentials, devices, systems, and data extracted from the Eptamed environment and promptly report any unauthorized access or incidents.

In the event of a personal data breach, Eptamed takes the measures required by law and notifies the Customer without undue delay after ascertaining the incident, when acting as the data controller, in accordance with the DPA.

10. Recipients of the Data

The data may be processed by individuals authorized by Eptamed and disclosed, as necessary, to:

  1. IT providers, hosting, cloud, security, maintenance, and support;
  2. payment service providers, banks, and intermediaries;
  3. couriers, carriers, freight forwarders, and customs brokers;
  4. legal, tax, accounting, technical, and insurance consultants;
  5. manufacturers, importers, and other economic operators in the medical device supply chain;
  6. organizers, instructors, accrediting bodies, and other parties involved in courses and events;
  7. data controllers and data processors;
  8. companies belonging to the Eptamed Group or affiliated with it;
  9. public authorities, regulatory bodies, and health authorities;
  10. entities responsible for debt collection, dispute resolution, or the defense of rights;
  11. potential buyers, investors, or advisors in connection with corporate transactions, subject to confidentiality agreements.

Recipients process the data in accordance with their respective roles: independent data controllers, joint data controllers, data processors, or sub-processors. The updated list of data processors and sub-processors may be requested from Eptamed at the privacy contact address provided in this notice.

11. Data Within the European Union and Intra-Group Transfers

Personal data is stored and processed in facilities located in the European Union or the European Economic Area, unless otherwise specified in the Order, the DPA, or the provider’s documentation.

Eptamed may grant access to data to group companies and suppliers located in the European Union for the purposes of administration, security, customer service, technical management, compliance, billing, support, and business continuity. Such intra-group data access is carried out on an as-needed basis, subject to appropriate authorizations, instructions, confidentiality obligations, and security measures.

If a supplier or a group company needs to access data from a country outside the European Economic Area, Eptamed will apply an adequacy decision, appropriate safeguards under the GDPR, standard contractual clauses, or another permissible legal basis. The data subject may request information about the safeguards applied and a copy of the relevant clauses, to the extent permitted.

12. Storage

Data is retained for as long as necessary to fulfill the purposes for which it was collected and, thereafter, for the periods required by tax, accounting, regulatory, and supervisory obligations, as well as by statutes of limitations and the need to defend rights.

As a general guide:

  1. Registration and Account data: for the duration of the Account and for the period necessary for security, dispute resolution, and compliance with legal obligations;
  2. Order, payment, and invoice data: for the periods required by tax, accounting, and civil law regulations;
  3. Data related to complaints, warranties, oversight, and recalls: for as long as necessary to manage these matters and to comply with legal obligations and for defense purposes;
  4. Customer data processed in the cloud services: for the duration of the Service and for the retention period specified in the Order or the DPA, except as required by law, in the event of litigation, for regulatory compliance, or for backup purposes;
  5. marketing data: until consent is withdrawn or the interest ceases, with periodic verification of relevance;
  6. Log and security data: for the period necessary to prevent and manage incidents and to protect rights.

13. Automated Decision-Making and Profiling

Eptamed does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect the data subject, unless otherwise specifically stated and the safeguards provided for by the GDPR are applied.

Any automated checks related to fraud, security, availability, licensing, export controls, or compliance may result in requests for information, a precautionary suspension, or human review. Such checks do not necessarily constitute an automated decision within the meaning of Article 22 of the GDPR.

Profiling for personalized marketing is conducted only when permitted and based on separate consent, where required.

14. Rights of the Data Subject

The data subject may request from Eptamed access to their data, rectification, erasure, restriction of processing, and data portability, and may object to processing based on legitimate interests or, for reasons related to their particular situation, to other forms of processing in the cases provided for by the GDPR. The data subject may object to direct marketing at any time.

When processing is based on consent, the data subject may withdraw that consent at any time, without affecting the lawfulness of the processing carried out prior to such withdrawal.

Requests may be sent to [email protected] or to the certified email address (PEC) [email protected]. Eptamed will respond within the timeframes set forth in the GDPR and may request reasonable information to verify the requester’s identity.

The data subject has the right to file a complaint with the Italian Data Protection Authority, Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it, or to the supervisory authority of the Member State in which the data subject resides, works, or where the alleged violation occurred.

15. Updates to the Privacy Policy

Eptamed may update this privacy policy in response to regulatory, organizational, technological, or service-related changes. The updated version will be posted on the Website, along with the date of the update.

×
×

Cart