PRIVACY POLICY
Eptamed S.r.l. (“Eptamed”), with its registered office in Cesena (FC), Via Luciano Lama 101, VAT No. 04107210405, registered with the Forlì-Cesena Register of Companies under No. FO330060, which can be contacted by email at [email protected], will process the personal data provided by purchasers of the products it markets and/or users of its services (“Customers”) in connection with a sales and/or supply contract, as well as data provided in any other manner in the context of a contractual and/or pre-contractual relationship (“Agreement”), for the supply of dental balancing devices and/or other goods marketed by Eptamed (“Products”) and other related activities and services, unless a different privacy notice regarding the processing of personal data is provided in the context of such activities or services.
2. TO WHOM AND TO WHAT DOES THIS PRIVACY POLICY APPLY?
Eptamed is the data controller with respect to the personal data obtained from the Customer, which is processed in accordance with the terms of this Privacy Policy and applicable law. Consequently, this Privacy Policy applies to all Customers.
3. WHAT KIND OF CUSTOMER PERSONAL DATA DOES EPTAMED COLLECT?
Eptamed collects the following categories of personal data:
a) first name, last name, gender, contact details (email, phone number, home address, billing address);
b) place and date of birth;
c) tax identification number;
d) identification document (ID card, passport, or driver’s license); ;
e) banking information (credit card details or bank account details).
4. HOW IS CUSTOMERS’ PERSONAL INFORMATION USED?
Eptamed processes customers’ personal data for the following purposes:
(a) for the sale of the Products or the provision of other additional services arising from the Contract;
b) for the analysis and improvement of the Products;
c) for the provision of technical assistance and customer support to the Customer, and for the delivery, use, and maintenance of the Products covered by the Contract;
d) to comply with applicable national and European regulations, including anti-money laundering and anti-fraud laws;
e) to manage complaints and disputes;
f) to assert and defend its rights, including in the context of debt collection procedures and the assignment of receivables to authorized companies, including through third parties;
g) to complete a potential merger, sale of assets, sale of the business, or sale of a business unit by disclosing and transferring the Customer’s personal data to the third party or parties involved;
h) with the Customer’s prior consent, to send marketing communications regarding the products and services offered by Eptamed (for example, by sending promotional materials or conducting market research). Marketing communications may be sent via traditional communication channels such as regular mail or email, as well as via chat, SMS, MMS, and instant messaging;
The purposes listed in subparagraphs (a) through (e) are collectively referred to as “Contractual Purposes.”
The purposes listed in subparagraphs (f) and (g) are collectively referred to as “Legitimate Interest Purposes.”
The purpose listed in subparagraph (h) is also referred to as “Marketing Purposes.”
Under no circumstances will Customers’ personal data be subject to disclosure or to any fully automated decision-making process, including profiling.
5. WHAT IS THE LEGAL BASIS FOR EPTAMED’S PROCESSING OF PERSONAL DATA?
The processing of Users’ personal data is necessary for Contractual Purposes, given that it is essential for the following purposes:
a) to perform the Contract regarding the sale of Products and the provision of the requested Services;
b) comply with the provisions of applicable law as set forth in Section 4, subparagraphs (d) and (e).
If the Customer does not provide the personal data necessary for the Contractual Purposes, Eptamed will not be able to enter into the Contract with the Customer.
The processing of the User’s personal data for the Purposes of Legitimate Interest referred to in Section 3, subparagraphs (f) and (g), is carried out in accordance with Article 24, paragraph 1, subparagraph (d) of Legislative Decree 196/2003 (“Privacy Code”) and, effective May 25, 2018, in accordance with Article 6(f) of the European General Data Protection Regulation
2016/679 (the “Privacy Regulation”) for the purpose of pursuing Eptamed’s legitimate interest, which is fairly balanced against the Customer’s interest, since the processing of personal data is limited to what is strictly necessary for the execution of the requested financial transactions.
Processing for Legitimate Interest Purposes is not mandatory, and the Customer may object to such processing in accordance with the procedures set forth in Section 9 below; however, if the Customer objects to such processing, their data may not be used for Legitimate Interest Purposes.
Finally, the processing is optional for Marketing Purposes. If the Customer withholds consent, they will not receive the commercial communications referred to in Section 4, subparagraphs (h) and (i). At any time, the Customer may revoke any consent previously provided in accordance with the procedures set forth in Section 9 of this Privacy Policy.
6. HOW DOES EPTAMED PROCESS USERS’ PERSONAL DATA?
Customers’ personal data may be processed using manual or computerized methods, https://www.eptamed.com/wp-content/uploads/2022/01/ALL-PRODUCTS.jpgei to ensure the security and confidentiality of such data and to prevent unauthorized access, disclosure, alteration, or theft of the data through the implementation of appropriate technical, physical, and organizational security measures.
7. WHO HAS ACCESS TO CUSTOMERS’ PERSONAL DATA?
For the Contractual Purposes described above, Users’ personal data may be transferred to the following categories of recipients, located within the European Union and, subject to the limitations set forth in Section 8 below, outside the European Union:
a) third-party providers of support and consulting services to Eptamed in connection with activities in the following sectors (by way of example only): technology, accounting, administration, legal, insurance, and IT;
b) banks and credit card issuers;
c) companies within the Eptamed Group;
d) Eptamed’s sales network (e.g., agents, distributors);
e) entities and authorities whose right to access Customers’ personal data is expressly recognized by law, regulations, or orders issued by the competent authorities. Depending on the circumstances, these recipients will process personal data in their capacity as data controllers, data processors, or persons in charge of processing.
For the purposes of legitimate interests described above, Customers’ personal data may be transferred to the following categories of recipients, located within the European Union and, subject to the limitations set forth in Section 8 below, outside the European Union:
a) third-party providers of support and consulting services to Eptamed in connection with debt collection and assignment activities;
b) companies within the Eptamed Group;
c) potential acquirers of Eptamed and entities resulting from a merger, demerger, or any other form of reorganization involving Eptamed;
d) competent authorities.
For the Marketing Purposes described above, Users’ personal data may be transferred to the following categories of recipients, located within the European Union and, subject to the limitations set forth in Section 8 below, outside the European Union:
a) third-party providers of support and consulting services to Eptamed in connection with the sending of commercial communications;
b) companies within the Eptamed Group.
The external data processors appointed by Eptamed can be contacted, upon request, using the methods described in Section 9 below.
8. ARE CUSTOMERS’ PERSONAL DATA TRANSFERRED ABROAD?
Users’ personal data may be freely transferred outside Italy to countries within the European Union. With regard to transfers outside the European Union to countries not deemed adequate by the European Commission, Eptamed implements suitable and appropriate security measures to protect Customers’ personal data. Consequently, any transfer of customers’ data to countries outside the European Union will, in any case, take place in compliance with the appropriate and necessary safeguards for the purposes of the transfer, such as standard contractual clauses for data protection, in accordance with applicable law and, in particular, Articles 45 and 46 of the General Data Protection Regulation (GDPR).
9. WHAT ARE CUSTOMERS’ RIGHTS REGARDING THEIR PERSONAL DATA?
The Customer may, at any time and free of charge, exercise the following rights by sending an email to [email protected]:
a) obtain confirmation from Eptamed as to whether or not data concerning him or her exists, and be informed of the content and source of the data, verify its accuracy, and request that it be supplemented, updated, or corrected;
b) to have any data processed in violation of applicable law erased, anonymized, or blocked;
c) object, in whole or in part, to the processing on legitimate grounds;
d) withdraw consent to the processing of data at any time (with respect to processing for which such consent may be required), without this in any way affecting the lawfulness of the processing based on the consent given prior to the withdrawal;
e) request that Eptamed restrict the processing of their personal data if: the Customer disputes the accuracy of their personal data, for the period necessary for Eptamed to verify the accuracy of such data; the processing is unlawful and the Customer objects to the erasure of their personal data and requests instead that its use be restricted; although Eptamed no longer needs the data for processing purposes, the data is necessary for the Customer to establish, exercise, or defend a legal claim; the Customer has objected to the processing pursuant to Article 21(1) of the General Data Protection Regulation (GDPR), pending verification of whether compelling legitimate grounds for continuing the processing prevail.
f) object to the processing of their personal data;
g) request the erasure of their personal data without undue delay;
h) receive a copy of their personal data in electronic format, where the Customer wishes to transfer their personal data to themselves or to a different service provider, in cases where Eptamed processes personal data based on the Customer’s consent or on the grounds that the processing is necessary for the provision of the Services, and the personal data is processed using automated means;
i) file a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).
Eptamed has not appointed a Data Protection Officer, as such an appointment is not mandatory in the circumstances described in this privacy notice. In fact, pursuant to Article 37 of the GDPR, data controllers and data processors must appoint a Data Protection Officer whenever: a) the processing is carried out by a public authority, body, or agency; b) the core activities of the data controller and the data processor require regular and systematic monitoring of data subjects on a large scale; c) the core activities of the data controller or data processor consist of the large-scale processing of special categories of personal data referred to in Article 9 (Processing of special categories of personal data) or of data relating to criminal convictions and offenses referred to in Article 10 (Processing of personal data relating to criminal convictions and offenses).
10. DATA RETENTION PERIODS APPLICABLE TO CUSTOMERS
Customers’ personal data will be retained for the period of time necessary to fulfill the purposes for which such data was collected, as stated in this Privacy Policy. In any case, the following retention periods will apply with respect to the processing of Customers’ personal data for the purposes listed below:
a) For the Contractual and Legitimate Interest Purposes referred to in Section 4, subparagraphs (a) through (g), Customers’ personal data are retained for a period equal to the term of the Contract (including any renewals) and for ten years following the expiration, termination, or withdrawal from the Contract, except in cases where retention for a longer period is required for potential disputes, requests from competent authorities, or pursuant to applicable law;
b) For Marketing Purposes, Users’ personal data is retained for the duration of the Contract and for a period of twenty-four months following its termination.
11. CHANGES AND UPDATES
This Privacy Policy is current as of May 25, 2018, and may be subject to changes and additions, including as a result of the applicability of the General Data Protection Regulation and any subsequent regulatory changes and/or additions, which will be promptly made available on the website www.eptamed.com.
Customers can view the text of the Privacy Policy, which is constantly updated, on the website www.eptamed.com.
COOKIE POLICY
WHAT ARE COOKIES?
A cookie is a small text file that is stored on your device (computer, tablet, or smartphone) when you visit a particular website. The file stores information that the website can read when you visit it again from the same device. Essentially, cookies are useful because they allow a website to recognize your device.
Cookies serve various purposes: they help you navigate the site’s pages more efficiently, remember your preferences, and generally improve your browsing experience. In some cases, cookies allow us to show you promotions that might interest you the most. Some of these cookies are necessary for the website to function properly, while others are useful because they securely store information such as your username or language settings. The advantage of having cookies installed on your computer is that you no longer need to enter the same information every time you want to access a site you’ve visited before.
Some cookies are automatically disabled at the end of the session (from the time the user opens the browser until the user closes it); others are stored on the user’s device for a longer period of time (typically, these cookies are used to store the preferences and choices of users visiting the site or to tailor commercial promotions).
The website may contain both first-party cookies and third-party cookies—that is, cookies that are set by a domain other than the website’s own.
Visit AboutCookies.org for more information about cookies and how they affect your browsing experience.
TYPES OF COOKIES
The website uses the following types of cookies:
1. Technical (or session) cookies: These are technical cookies that are essential for navigating the website and using its various features. Without these cookies, the shopping cart section for requesting a quote cannot function.
2. Analytical cookies that improve the website’s performance (Google Analytics): These cookies collect information about how the website is used, such as which pages are viewed most frequently. These cookies do not collect information that identifies individual users, but only aggregated and anonymous data. They are used exclusively to improve the services offered by the website.
By using our website, you agree that these cookies may be stored on your device.
WHAT COOKIES DO WE USE
You can configure your browser to disable cookies using a very simple procedure (please note: disabling cookies in your browser may cause the website to malfunction, and you will not be able to save your username and password for the restricted areas).
Firefox:
1. Open Firefox
2. Press the “
” key on your keyboard 3. In the toolbar at the top of the browser, select “Tools” and then “Options”
4. Then select the “Privacy” tab
5. Go to “History Settings:” and then select “Use custom settings.” Uncheck “Accept cookies from sites” and save your preferences.
Internet Explorer:
1. Open Internet Explorer
2. Click the Tools button, then click Internet Options
3. Select the Privacy tab and move the slider to the privacy level you want to set (up to block all cookies or down to allow all of them)
4. Then click OK
Google Chrome:
1. Open Google Chrome
2. Click the Tools icon
3. Select Settings, then Advanced Settings
4. Select Content Settings under Privacy
5. On the Cookies tab, you can uncheck cookies and save your preferences
Safari:
1. Open Safari
2. Choose Preferences from the toolbar, then select the Security pane in the dialog box that appears
3. In the “Accept Cookies” section, you can specify whether and when Safari should save cookies from websites. For more information, click the Help button (marked with a question mark)
4. For more information about the cookies stored on your computer, click Show Cookies.
GOOGLE ANALYTICS
This website uses Google Analytics (analytical cookies), a web analytics service provided by Google, Inc. (“Google”). Google Analytics uses “cookies,” which are text files stored on your computer to enable the website to analyze how users use the site. The information generated by the cookie regarding your use of the website (including your anonymized IP address) will be transmitted to and stored on Google’s servers in the United States. Google will use this information to evaluate your use of the website, compile reports on website activity for website operators, and provide other services related to website activity and internet usage. Google may also transfer this information to third parties where required by law or where such third parties process the information on Google’s behalf. Google will not associate your IP address with any other data held by Google. You may refuse the use of cookies by selecting the appropriate settings on your browser, but please note that if you do so, you may not be able to use all the features of this website. By using this website, you consent to the processing of your data by Google in the manner and for the purposes described above.
You can prevent Google from collecting a cookie that is generated as a result of and in connection with your use of this website (including your IP address) and from processing this data by downloading and installing this browser plugin: http://tools.google.com/dlpage/gaoptout?hl=en
