Questa pagina è anche disponibile in Italiano
Last updated: 29 August 2026
This policy describes how the personal data of those who visit the website
www.giovanniscornavacca.com or contact the practice is processed.
It is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative
Decree 196/2003 (Privacy Code).
As regards cookies and other tracking tools, please refer to the
Cookie Policy, which forms an integral part of this document.
1. Data Controller
Dr Giovanni Scornavacca — Physician and Surgeon
Via Giacomo Leopardi 23 — 95127 Catania (CT), Italy
Registered with the Medical Association (Ordine dei Medici Chirurghi e degli Odontoiatri) of the Province of
Catania, no. [TO BE COMPLETED: medical register number]
VAT no. [TO BE COMPLETED: VAT number]
E-mail: info@giovanniscornavacca.com
The Controller has not appointed a Data Protection Officer (DPO), as the conditions set out in Article 37
GDPR do not apply.
2. What data we process
2.1 Contact requests
Through the form on the website we collect your name, your e-mail address
and the content of your message. The form also includes a checkbox acknowledging that you have
read this policy and is protected by Google reCAPTCHA, which analyses browsing behaviour to distinguish human submissions from automated ones.
The same applies if you write directly to the e-mail address indicated in section 1, including any
attachments.
2.2 Important notice regarding health data
The contact form is not a medical consultation tool and does not replace an examination. We
invite you not to include in your message any information concerning your state of health,
diagnoses, ongoing treatments, medical reports, or other data falling within the special categories referred to
in Article 9 GDPR.
Should you nonetheless choose to communicate such information, processing takes place on the basis of your
explicit consent (Article 9(2)(a) GDPR), understood as given by voluntarily sending the
message, and only to the extent necessary to answer your request. This information is treated with particular
confidentiality, is accessible to the Controller alone, and is not disclosed to third parties.
For clinical matters, please use the telephone or arrange an appointment.
2.3 Data relating to professional services
Data collected in the course of an examination or medical service — medical history, reports, clinical
records — does not pass through the website and is not covered by this policy: it is processed
within the professional relationship, under a separate notice provided directly at the practice pursuant to
Articles 13 and 9 GDPR.
2.4 Browsing data
The IT systems underlying the operation of this website acquire, in the course of their normal operation,
certain data whose transmission is implicit in the use of Internet communication protocols: IP addresses,
browser and operating system type, date and time of the request, pages requested, and response status codes.
This data is recorded in the server log files and used solely to ensure the correct functioning and security of
the website; it is not used to identify users.
2.5 Statistical data
The website collects aggregate statistics on visits through a tool hosted on its own infrastructure,
without cookies and without identifying users. Full details are set out in the
Cookie Policy.
3. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Responding to contact requests and arranging appointments | Name, e-mail, message content | Pre-contractual measures taken at the data subject’s request and legitimate interest in providing a reply (Article 6(1)(b) and (f) GDPR) |
| Processing any health information you choose to include in your message | Message content | Explicit consent of the data subject (Article 9(2)(a) GDPR) |
| Ensuring the functioning and security of the website and protecting the contact form from automated submissions | Browsing data, system logs, data collected by reCAPTCHA | Legitimate interest in the security of the systems (Article 6(1)(f) GDPR) |
| Aggregate statistical measurement of visits | Browsing data in aggregate form | Legitimate interest in understanding how the website is used, by means of a cookieless and non-identifying tool (Article 6(1)(f) GDPR) |
| Displaying the map of the practice | Data transmitted to Google when the map is activated | Your consent (Article 6(1)(a) GDPR) |
Providing your name and e-mail address is necessary in order for us to reply to you: without them the
request cannot be acted upon.
We do not send promotional communications or newsletters and we do not use data for
marketing purposes. No profiling is carried out.
4. How data is processed
Data is processed using IT and telematic tools, applying technical and organisational measures appropriate to
ensure its security, integrity, and confidentiality, and to prevent unauthorised access, loss, or disclosure.
The website is served entirely over an encrypted connection (HTTPS) and the contact form is protected by an
anti-abuse verification system.
The Controller is bound by professional secrecy pursuant to Article 622 of the Italian
Criminal Code and the Italian Code of Medical Ethics.
5. No profiling or automated decision-making
The Controller does not carry out any profiling of users and does not employ
automated decision-making processes producing legal effects concerning you or similarly significantly
affecting you, within the meaning of Article 22 GDPR.
6. Recipients of the data
For the purposes set out above, your data may be made accessible to the following parties:
- the hosting and e-mail service provider, with servers located within the European Union,
appointed as Data Processor pursuant to Article 28 GDPR; - IT service providers responsible for the technical management of the website
(Processors); - Google Ireland Limited, for the protection of the contact form through reCAPTCHA and, if you choose to
activate the map, for the related connection data; - the Controller’s tax and accounting advisers, for statutory obligations;
- public and judicial authorities, only in the cases provided for by law.
Data is neither disseminated nor transferred to third parties for commercial purposes. An
up-to-date list of Data Processors is available on request.
7. Transfer of data outside the European Union
Data collected through the contact form, correspondence, and system logs is stored on servers located
within the European Union.
The exceptions are the Google services — reCAPTCHA, which connects when the pages hosting the form are loaded, and the Google Maps feature, which remains disabled until you give
your consent: if you choose to activate it, Google may process connection data in the United States as well, on
the basis of the European Commission’s adequacy decision of 10 July 2023 concerning the EU-U.S. Data Privacy
Framework and of the Standard Contractual Clauses.
8. Retention period
| Data | Retention |
|---|---|
| Contact requests with no follow-up | 24 months from the last exchange of correspondence |
| Requests leading to a professional relationship | Incorporated into the medical records, retained in accordance with sector legislation and the guidance of the Italian Data Protection Authority on health data |
| Any health information provided through the form and not followed by a medical service | Erased within 12 months, unless necessary to establish, exercise, or defend a legal claim |
| System logs | According to the technical retention periods of the hosting provider, ordinarily no longer than 12 months |
| Proof of cookie consent | 1 year |
At the end of the periods indicated, data is erased or irreversibly anonymised, except where retention is
required by law.
9. Your rights
You may exercise at any time the rights provided for by Articles 15-22 GDPR, and in particular you may:
- obtain confirmation as to whether or not your data is being processed and
access that data; - obtain the rectification of inaccurate data or the completion of
incomplete data; - obtain the erasure of your data in the cases provided for by Article 17;
- obtain the restriction of processing in the cases provided for by Article 18;
- receive the data concerning you in a structured, commonly used format and transmit it to another
controller (data portability, Article 20); - object at any time, on grounds relating to your particular situation, to processing based
on legitimate interest (Article 21); - withdraw the consent you have given, without affecting the lawfulness of processing
carried out before the withdrawal.
Requests should be addressed to
info@giovanniscornavacca.com. The Controller will respond
without undue delay and in any event within one month of receiving the request, a period that may be extended
by two further months in particularly complex cases.
If you believe that the processing of your data infringes applicable law, you have the right to lodge a
complaint with the Italian Data Protection Authority, the Garante per la protezione dei dati
personali (Piazza Venezia 11, 00187 Rome —
www.garanteprivacy.it),
or to bring proceedings before the courts.
10. Minors
The website is not directed at children under the age of 14. Requests concerning a minor must be submitted by
the holder of parental responsibility.
11. Changes to this policy
The Controller reserves the right to update this policy to reflect changes in legislation or organisation.
Each version shows the date of its most recent update at the top of the page.