Enterprise Privacy Notice – Website, Stakeholders, Professional Accounts and Digital Services
Extended notice under Regulation (EU) 2016/679 distinguishing UESE’s processing as an independent controller from processing performed on behalf of customer organisations.
Regulatory and governance references
- Regulation (EU) 2016/679 (GDPR), including Articles 5, 6, 9, 13-14, 25, 28, 30, 32-36, 37-39 and 44-49
- Italian Legislative Decree 196/2003, as amended
- Applicable measures and guidance of the Italian Data Protection Authority
- Regulation (EU) 2025/327 (EHDS), where relevant to the processing
References indicate the design framework and must be verified against the current legislation, implementing measures, national law and the parties’ actual roles at implementation time.
1. Controller and Scope of this Notice
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
The responsible legal entity must be unambiguously identifiable. Corporate details, contact channels and the relevant privacy role are kept separate from the commercial product name; a division or internal business unit does not change legal ownership unless expressly stated.
UESE maintains records and configurations suitable to evidence its own processing and, where acting as processor, provides the controller with information reasonably needed for governance. Customer documentation should state purposes, legal bases, data categories, recipients, retention and measures actually applied.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
2. Data Protection Officer (DPO)
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
UESE’s Data Protection Officer is Dr Prof Giuseppe Izzo, contactable at dpo@uese.it. The DPO performs the tasks under GDPR Articles 37–39 independently; where a request concerns data processed on behalf of a customer, UESE will cooperate but may need to direct the data subject to the competent controller.
UESE maintains records and configurations suitable to evidence its own processing and, where acting as processor, provides the controller with information reasonably needed for governance. Customer documentation should state purposes, legal bases, data categories, recipients, retention and measures actually applied.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
3. General Processing Principles
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
Each processing operation must respect purpose limitation, minimisation, accuracy, storage limitation, integrity and confidentiality. Configuration should avoid unnecessary free-text fields, uncontrolled copies and excessive transfers; synthetic or properly anonymised data should be preferred for testing and training where feasible.
UESE maintains records and configurations suitable to evidence its own processing and, where acting as processor, provides the controller with information reasonably needed for governance. Customer documentation should state purposes, legal bases, data categories, recipients, retention and measures actually applied.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
4. Categories of Data Subjects
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
Actual categories must be documented in records of processing and project annexes. They may include professional users, commercial contacts, research personnel and, in customer projects, research subjects; UESE does not assume that data are necessary or lawful merely because the platform technically supports them.
UESE maintains records and configurations suitable to evidence its own processing and, where acting as processor, provides the controller with information reasonably needed for governance. Customer documentation should state purposes, legal bases, data categories, recipients, retention and measures actually applied.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
5. Categories of Personal Data
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
Actual categories must be documented in records of processing and project annexes. They may include professional users, commercial contacts, research personnel and, in customer projects, research subjects; UESE does not assume that data are necessary or lawful merely because the platform technically supports them.
UESE maintains records and configurations suitable to evidence its own processing and, where acting as processor, provides the controller with information reasonably needed for governance. Customer documentation should state purposes, legal bases, data categories, recipients, retention and measures actually applied.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
6. Health, Genetic and Other Special-Category Data
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
Health and genetic data are special categories under GDPR Article 9. The controller must identify an Article 6 legal basis and an Article 9 condition, assess applicable health and research law and implement appropriate safeguards; pseudonymisation reduces risk but does not automatically make data anonymous.
UESE maintains records and configurations suitable to evidence its own processing and, where acting as processor, provides the controller with information reasonably needed for governance. Customer documentation should state purposes, legal bases, data categories, recipients, retention and measures actually applied.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
7. Browsing and Security Data
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
Technical access data may be processed for security, troubleshooting, abuse prevention and accountability. Logging must remain proportionate: application and security logs should not contain genomic sequences, medical reports or sensitive payloads unless strictly necessary and authorised.
UESE maintains records and configurations suitable to evidence its own processing and, where acting as processor, provides the controller with information reasonably needed for governance. Customer documentation should state purposes, legal bases, data categories, recipients, retention and measures actually applied.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
8. Professional Account Data
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
Access is intended for organisations and professionals acting in the course of their activities. The customer must ensure that users, researchers and collaborators are authorised and appropriately trained; involvement of consumers, patients or non-professional users requires a separate contractual and regulatory assessment.
Accounts are personal and must not be shared. The customer must promptly manage onboarding, role changes and de-provisioning; privileged access requires enhanced controls and, where policy requires, multi-factor authentication. Traceability is undermined where multiple people use the same identity.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
9. Information Requests, Demos and Stakeholder Relations
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
Public-form data are used to qualify enquiries, organise contacts, demos or assessments and document the pre-contractual relationship. The public form must not receive patient data; where an assessment requires sensitive information, UESE first establishes a protected channel and clarifies privacy roles.
Access, rectification, erasure, restriction, objection and portability requests are handled according to the actual role. Where UESE is processor it does not replace the controller’s decision-making, but provides tools and information compatible with the nature of processing and security requirements.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
10. Newsletter and Professional Communications
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
Access is intended for organisations and professionals acting in the course of their activities. The customer must ensure that users, researchers and collaborators are authorised and appropriately trained; involvement of consumers, patients or non-professional users requires a separate contractual and regulatory assessment.
The newsletter is voluntary and separate from commercial or technical enquiries. UESE uses email double opt-in to document the data subject’s choice; unsubscribe is available at any time and withdrawal does not affect the lawfulness of earlier processing.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
11. Purposes and Legal Bases
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
Legal basis is determined per purpose, not per platform. Pre-contractual activities, contract performance, security, legal obligations and marketing may rely on different grounds; health or genetic data also require an Article 9 condition and, where applicable, research safeguards under Article 89.
RTO and RPO, if offered, must be expressly stated in the SLA and aligned with the architecture. Without executed values they cannot be inferred from public material; disaster recovery and application restoration should be tested periodically where required by the continuity plan.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
12. Privacy Roles in Customer Projects
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
Controller, joint controller and processor are functional qualifications rather than contractual labels. Parties must assess who determines purposes and essential means for each activity; joint-controller arrangements and DPAs must reflect the actual allocation and define responsibilities, rights channels and cooperation.
UESE maintains records and configurations suitable to evidence its own processing and, where acting as processor, provides the controller with information reasonably needed for governance. Customer documentation should state purposes, legal bases, data categories, recipients, retention and measures actually applied.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
13. Pseudonymisation, Minimisation and Key Separation
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
Each processing operation must respect purpose limitation, minimisation, accuracy, storage limitation, integrity and confidentiality. Configuration should avoid unnecessary free-text fields, uncontrolled copies and excessive transfers; synthetic or properly anonymised data should be preferred for testing and training where feasible.
Where technically feasible, direct identity remains with the healthcare or research institution and the platform uses pseudonymous identifiers. Re-identification keys should be segregated, protected and accessible to a restricted group; re-identification should occur only where permitted by protocol and legal basis.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
14. Recipients, Authorised Persons and Providers
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
Recipients are limited to authorised persons and necessary providers. Before entrusting processing to third parties, role, security, location, onward subcontracting and contractual terms are assessed; the sub-processor chain is governed under GDPR Article 28 and the agreed authorisation mechanism.
UESE maintains records and configurations suitable to evidence its own processing and, where acting as processor, provides the controller with information reasonably needed for governance. Customer documentation should state purposes, legal bases, data categories, recipients, retention and measures actually applied.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
15. Sub-processors and Digital Supply Chain
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
Recipients are limited to authorised persons and necessary providers. Before entrusting processing to third parties, role, security, location, onward subcontracting and contractual terms are assessed; the sub-processor chain is governed under GDPR Article 28 and the agreed authorisation mechanism.
UESE maintains records and configurations suitable to evidence its own processing and, where acting as processor, provides the controller with information reasonably needed for governance. Customer documentation should state purposes, legal bases, data categories, recipients, retention and measures actually applied.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
16. International Transfers
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
Any third-country transfer is subject to GDPR Chapter V and must be mapped before activation. In the absence of an adequacy decision, Standard Contractual Clauses, a transfer impact assessment and supplementary measures may be required; remote access from a third country is assessed as part of the same risk.
UESE maintains records and configurations suitable to evidence its own processing and, where acting as processor, provides the controller with information reasonably needed for governance. Customer documentation should state purposes, legal bases, data categories, recipients, retention and measures actually applied.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
17. Retention and Deletion
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
Retention periods are defined by data category and purpose. Exit must distinguish export, return, logical deletion, storage deletion and backup cycles; legal duties, disputes or legal hold may justify limited segregated retention that is documented and not reused for other purposes.
UESE maintains records and configurations suitable to evidence its own processing and, where acting as processor, provides the controller with information reasonably needed for governance. Customer documentation should state purposes, legal bases, data categories, recipients, retention and measures actually applied.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
18. Data Subject Rights
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
Access, rectification, erasure, restriction, objection and portability requests are handled according to the actual role. Where UESE is processor it does not replace the controller’s decision-making, but provides tools and information compatible with the nature of processing and security requirements.
UESE maintains records and configurations suitable to evidence its own processing and, where acting as processor, provides the controller with information reasonably needed for governance. Customer documentation should state purposes, legal bases, data categories, recipients, retention and measures actually applied.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
19. Request Handling and Cooperation with Customer Controllers
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
The responsible legal entity must be unambiguously identifiable. Corporate details, contact channels and the relevant privacy role are kept separate from the commercial product name; a division or internal business unit does not change legal ownership unless expressly stated.
Professional enquiries are registered and notified to the Superadmin or configured address for allocation and qualification. Internal notes should contain only information relevant to the professional relationship and must not be used to record unnecessary health or special-category data.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
20. Personal Data Breaches and Incident Response
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
Events are classified by severity and impact, contained and documented. Where UESE acts as processor it notifies the controller without undue delay after becoming aware of a personal data breach and provides available information for GDPR Articles 33 and 34 assessments; regulatory notifications remain with the competent party.
Requests are prioritised by impact and urgency. Response time measures acknowledgement and engagement, not necessarily resolution; critical priorities require defined escalation channels, contacts and minimum diagnostic information.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
21. Automated Decision-Making, Profiling and AI
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
The public configuration does not provide automated decisions producing legal or similarly significant effects on data subjects. Any future use case must be separately assessed under the GDPR and AI Act, including human oversight and rules governing clinical decisions.
UESE maintains records and configurations suitable to evidence its own processing and, where acting as processor, provides the controller with information reasonably needed for governance. Customer documentation should state purposes, legal bases, data categories, recipients, retention and measures actually applied.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
22. Notice Updates, Complaints and Contacts
UESE ITALIA S.p.A. processes personal data under Regulation (EU) 2016/679 and applicable Italian law, using an accountability, minimisation and role-separation model. The platform may operate in contexts where UESE is an independent controller for its own activities and, separately, a processor for healthcare, research or biotech organisations; these roles must not be conflated and depend on who actually determines purposes and essential means.
Public information is descriptive and may be updated where it does not alter existing contractual commitments. Guaranteed specifications, service levels and features must be found in executed documents; healthcare or regulatory decisions must not rely on promotional material.
UESE maintains records and configurations suitable to evidence its own processing and, where acting as processor, provides the controller with information reasonably needed for governance. Customer documentation should state purposes, legal bases, data categories, recipients, retention and measures actually applied.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
For requests concerning data processed within a customer project, UESE may need to direct the data subject to the competent controller. For commercial or technical enquiries, use the dedicated stakeholder form and do not submit patient data.
Request informationWebsite owner and corporate contacts
UESE ITALIA S.p.A. · Piazza Trivulziana 4/A · 20126 Milano (MI) · Italy · P. IVA / C.F. IT04398760274 · REA MI 2679515 · sales@uese.it · +39 02 5656 8416.