PRIVACY NOTICE FOR THE WEBSITE WWW.ESAOTE.COM
1. Introduction
Welcome to the privacy notice for the website www.esaote.com (hereinafter “Website”). This document, prepared in compliance with Art. 13 of the General Data Protection Regulation (Regulation (EU) 2016/679, hereafter “GDPR”), outlines how your personal data is processed within this Website. This notice applies exclusively to data processing activities within the Website and does not cover other external website accessible from links within this Website.
The Website is intended for users who are at least 18 years old. By navigating the Website, users confirm that they meet this age requirement.
2. Who is the controller of your personal data?
The data controller is Esaote S.p.A. (hereinafter, “Controller”, “Company” or “Esaote”), headquartered in Genova (GE), Via E. Melen n. 77, VAT No. 05131180969. Please contact us at [email protected].
3. Who is the Data Protection Officer?
A Data Protection Officer (“DPO”) has been appointed and can be reached for further information about personal data processing at [email protected].
4. What data we do collect and process?
4.1. Navigation data
This category of data includes the IP addresses or the domain names of the computers used by the users who connect to the Website, the addresses in URI (Uniform Resource Identifier) format of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in reply, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters related to the operating system and the computer environment of the user. This data is only used to collect statistical information, as well as to verify that the Website is functioning properly. The data, in addition, could be used to determine liability in the event of cybercrimes committed against the Website. Except in the latter case, the navigation data is erased after 12 months.
4.2. Data related to registration to the private area
Through the registration form for the private area, users are required to provide personal data such as first name, last name, country, email address, access password, main field of activity, clinical sector, area of interest.
4.3. Cookie
The Website collects and processes data using cookies or similar technologies. For further information on the use of cookies, please refer to the “Cookie Policy” of the Website.
4.4. Data voluntarily provided by the user
Through the forms present within the Website (e.g. “Contact us” or “Technical support”), the data subject can provide personal data such as name, surname, zip code, country, email address, phone number, company or institution, type of request, type of service, area of interest or product category, serial number, installation number, clinical sector, and job function.
5. What do we do with the personal data we collect about you?
5.1. Registration and access to the private area
Purpose: to allow users to register and manage their own account in the private area and access dedicated content. Providing personal data for this purpose is entirely optional; however, failure to do so will prevent registration access.
Legal basis: performance of a contract to which the user is a party (Art. 6(1)(b) GDPR).
Retention period: personal data is retained until the account is deleted, which users can do by emailing [email protected]. Upon account closure, data is retained for an additional period necessary to fulfil legal obligations and for the time frame allowed to assert legal claims, as determined by the statutory limitation periods.
5.2. Management of information requests
Purpose: to respond to information requests sent by the user through: (i) the “Personalized Consultancy” section available on the Website; and/or (ii) via email addresses reachable through links available on the Website, as well as for following up on subsequent interactions in order to assess the development of the relationship with the data subject and the potential commercial interest in Esaote’s products or solutions.
For the purposes set out above, the Controller may share the data subject's personal data with its subsidiaries and/or authorized distributors, to the extent necessary for the effective handling of the request submitted.
Providing personal data for this purpose is optional, but without it, it will not be possible to manage and respond to information requests submitted by the data subject.
Legal basis: performance of pre-contractual measures adopted at their request (Art. 6(1)(b) GDPR).
Retention period: personal data are retained for the time strictly necessary to manage and respond to information and support requests, and in any case no longer than 24 months from the date of collection, for the purpose of following up on subsequent interactions and assessing the development of the relationship with the data subject.
5.3. Management service and support requests
Purpose: to manage and fulfil requests for technical assistance, remote support, and scheduled or corrective maintenance of Esaote’s products sent by the user through: (i) the “Technical Support” section available on the Website; and/or (ii) via email addresses reachable through links available on the Website.
To ensure the most effective and timely handling of service and support requests, Esaote may share the personal data provided by the user with its subsidiaries and/or authorized distributors. Providing personal data for this purpose is optional, but without it, it will not be possible to manage and respond to information and support requests submitted by the data subject.
Legal basis: performance of a contract to which the data subject is a party (Art. 6(1)(b) GDPR).
Retention period: personal data are retained for the entire duration of any maintenance and support agreement between the user and Esaote and, in any event, for the full statutory warranty period required by law following the product’s sale. Upon the expiry of the support agreement, personal data shall be retained for a further period of 10 years to comply with legal, fiscal, and accounting obligations, as well as to enable Esaote to assert or defend its rights in accordance with the applicable statutory limitation periods.
5.4 Compliance
Purpose: to meet legal obligations and regulatory requirement, including allowing data subject to exercise his privacy rights.
Legal basis: compliance with legal obligations to which the Controller is subject (Art. 6(1)(c) GDPR).
Retention period: personal data is retained for the duration required by applicable legal obligations.
5.5 Exercise and defence of rights in judicial proceedings
Purpose: to establish, exercise or defend a claim in a legal proceeding or whenever the judicial authorities exercise their judicial functions.
Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR).
Retention period: personal data is retained for a period strictly limited to the duration of the litigation, until the expiry of the terms for enforcement or appeal.
5.6 Direct marketing
Purpose: to send commercial and promotional communications via email related to the products and services offered by the Company. Providing personal data for this purpose is entirely optional and does not affect the use of the Website or related services.
Legal basis: data subject’s consent (Art. 6(1)(a) GDPR).
Retention period: personal data is retained until consent is withdrawn, which can be exercised by contacting the Company at [email protected].
5.7 Profiled marketing
Purpose: to send personalized commercial and promotional communications based on data subject’s interests. Providing personal data for this purpose is entirely optional and does not affect the use of the Website or related services.
Legal basis: data subject’s consent (Art. 6(1)(a) GDPR).
Retention period: personal data is retained until consent is withdrawn, which can be exercised by contacting the data Controller at [email protected].
5.8 Soft spam
Purpose: to send commercial communications via email regarding products and services similar to those already purchased by the data subject, unless he refuses to receive such communications expressed at the time of the first communication or subsequent communications.
Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR).
Retention period: personal data are retained until an objection to processing, exercised by the data subject through the appropriate link at the bottom of each communication or by contacting the Controller at the email address [email protected].
5.9. Disclosure to Third Parties for direct marketing purposes
Purpose: to disclose user’s data (e.g., name, surname, email address) to third-party companies belonging to the Esaote Group for their own direct marketing purposes.
Legal basis: data subject’s consent (Art. 6(1)(a) GDPR).
Retention period: personal data is retained until consent is withdrawn, which can be exercised by contacting the Company at [email protected].
6. To whom do we disclose or share your personal data?
Personal data can be shared with the following recipients:
- Third parties acting as data processors, such as: (i) service providers for Website development; (ii) entities delegated to perform technical maintenance activities on the Website; (iii) individuals, companies, or professional firms providing assistance and consulting services.
- Third parties acting as independent data controllers, such as: (i) Authorities or third parties where disclosure is required by law, including law enforcement agencies, regulatory bodies, or other governmental entities for compliance with legal obligations; (ii) Esaote Group Companies for: (a) technical assistance, maintenance, and after-sales service activities on Esaote’s products; (b) handling and follow-up of customer information requests submitted via the Website or other contact channels; (c) their own direct marketing purposes.
7. Who are the subjects authorized to process your personal data?
Personal data can be processed by Esaote’s personnel and operators in charge of pursuing the purposes mentioned above, who have been expressly authorized for processing, have received appropriate operational instructions, and are bound by professional secrecy.
8. How is personal data transferred internationally?
Some personal data may be shared with recipients who may be located outside the European Economic Area. The Controller ensures that the data processing by these recipients is carried out in compliance with the GDPR. Transfers may be based on an adequacy decision, on Standard Contractual Clauses approved by the European Commission, or another suitable legal basis. More information is available from the Controller by writing to [email protected].
9. What are your rights?
Data subject can exercise his rights by contacting [email protected], including access to the personal data, deletion or rectification, erasure, restriction, objection on legitimate interest grounds, and data portability, if technically feasible.
Consent can be withdrawn at any time, contacting [email protected]. However, it should be noted that the withdrawal of consent does not affect the lawfulness of the processing based on consent before its withdrawal.
Data subject also has the right to file a complaint with the competent Supervisory Authority, pursuant to Art. 77 of the GDPR, if he believes that the processing of their personal data infringes applicable data-protection law.