Cookie & Privacy Policy

Cookie

Privacy Policy

Pursuant to Article 13 of the GDPR (EU Regulation 2016/679), the following information is provided, in accordance with the principle of transparency, to inform users about the characteristics and methods of data processing.

  1. Controller Identity and Contact Details

The Data Controller is: 
Healtion S.r.l. – Benefit Company 
(Tax Code and VAT No.: 01975760495) 
Registered office: Via degli Olmi 13–15, 50041 Calenzano (FI), Italy 
Email:privacy@Healtion.it.

Contact details: 
Phone: +39 055 88931
Email: privacy@Healtion.it
Certified email (PEC): Healtion@open.legalmail.it

  1. Purposes, Legal Basis and Data Retention
Product purchase management

Legal basis

Retention

Processing

Product purchase management
Personal data processed: identification, contact, personal and payment data

Performance of a contract (Art. 6(1)(b) GDPR)

Until completion of the contract

Authorised internal personnel

Product delivery management
Data: identification and contact details

Contractual necessity

Until completion

Internal staff and authorised external processors

Newsletter management
Data: identification and contact details

Consent (Art. 6(1)(a) GDPR)

Until consent is withdrawn, max 12 months

Authorised internal personnel

Website management
Data: identification and contact data

Contractual necessity

Until completion

Internal staff and appointed processors

Aggregated data analysis
Data: anonymised personal data

legitimate interest (Art. 6(1)(f) GDPR)

Up to 12 months

Internal staff and processors

Personalisation of products/services
Data: browsing and purchase data

Consent

Up to 12 months

Internal staff and processors

Remarketing activities
Data: identification, contact and browsing/purchase data

Consent

Up to 24 months
 

Authorised internal personnel

Legal dispute management
Data: identification and payment data

Legitimate interest

Up to 10 years

Internal staff and legal advisors

  1. Categories of Data Processed

Healtion processes common personal data (identification, personal and contact data).

  1. Data Transfer Outside the EU

For certain purposes, personal data may be transferred outside the EU. Transfers will take place in compliance with GDPR provisions (Articles 44 et seq.), either to countries deemed adequate or through Standard Contractual Clauses ensuring an adequate level of protection.

  1. Data Subject Rights

You have the right to:

  • access your data 
  • request correction or deletion 
  • restrict processing 
  • receive notification of changes 
  • data portability 
  • object to processing 
  • not be subject to automated decision-making 
  • be informed of data breaches 

The Controller will respond within one month (extendable to three months in complex cases).
You may withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise your rights, contact: cs@Healtion.it.

  1. Right to Object

Where processing is based on legitimate interest, you may object by contacting: cs@Healtion.it.

  1. Complaints

You have the right to lodge a complaint with the Italian Data Protection Authority www.garanteprivacy.it

  1. Data Provision

Providing personal data is mandatory for certain purposes (e.g. purchase, delivery, website functionality, legal obligations). Failure to provide data may prevent contract execution.

  1. Further Processing 

If data is processed for purposes other than those originally stated, additional information will be provided beforehand.

  1. Automated Processing

The Controller uses automated processes for profiling, remarketing and aggregated data analysis.