Privacy Policy
Information notice pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) for users of the Palazzo Manzoni SRL website.
1. Data Controller
Palazzo Manzoni SRL, registered office at Via dei Mille 14, 25122 Brescia, Italy, VAT/Tax code 03439460985, is the Controller of the personal data collected through this website.
Contacts: certified email (PEC) palazzomanzonisrl@legalmail.it · tel. +39 030 294 2437.
2. Types of data processed
- Browsing data: IP addresses, access times, pages visited and other technical parameters implicitly acquired by the website systems.
- Data provided voluntarily: name, surname, contact details and the content of messages sent through the contact, booking or newsletter forms.
- Special categories of data (health data): any health information spontaneously provided in booking or contact requests. Health data processed for diagnosis and care purposes is handled at the clinic, on the basis of a specific notice provided on site.
- Cookies and similar technologies: please refer to the Cookie Policy.
3. Purposes and legal bases
- Responding to contact requests and managing bookings — legal basis: pre-contractual measures taken at the data subject’s request (Art. 6.1.b GDPR); for any health data provided, the data subject’s explicit consent (Art. 9.2.a GDPR).
- Compliance with legal, accounting and tax obligations — Art. 6.1.c GDPR.
- Security and proper operation of the website — legitimate interest of the Controller (Art. 6.1.f GDPR).
- Sending the newsletter — the data subject’s consent (Art. 6.1.a GDPR), which may be withdrawn at any time.
4. Processing methods and security
Data is processed by authorised and trained personnel using IT tools, with technical and organisational measures adequate to ensure confidentiality, integrity and availability. No automated decision-making or profiling is carried out.
5. Recipients
Data may be processed by the hosting provider Aruba S.p.A., by administrative consultants and by other processors appointed under Art. 28 GDPR, as well as by authorised internal personnel. Data is not disseminated.
6. Transfers outside the EU
Data is processed within the European Union. Should any provider involve transfers to third countries, these take place on the basis of adequacy decisions or the standard contractual clauses approved by the European Commission.
7. Retention
Contact data is kept for the time needed to respond to the request and in any case no longer than 24 months; data connected to legal obligations for the terms required by law; newsletter data until consent is withdrawn. Health records are kept for the terms required by the law applicable to healthcare facilities.
8. Data subject rights
Under Articles 15-22 GDPR, data subjects may exercise their rights of access, rectification, erasure, restriction, portability and objection, and may withdraw consent, by writing to the Controller at the contacts in section 1. A complaint may also be lodged with the Italian Data Protection Authority (www.garanteprivacy.it).
9. Minors
The website is not intended for children under 14 and the Controller does not knowingly collect their data. Requests concerning minors must be submitted by the holder of parental responsibility.
10. Changes to this notice
This notice may be updated; the version published on this page is the one in force. Last updated: 19 July 2026.