Privacy policy

This page describes the data processing methods used in the management of the Puglia Prevention Portal of the Puglia Region.

This Privacy Policy, provided pursuant to Article 13 of European Regulation No. 2016/679 (GDPR – General Data Protection Regulation), is addressed to users interacting with the website www.prevenzione.regione.puglia.it. It applies exclusively to the Puglia Prevention Portal and not to other external applications or services that may be accessible or used by users while browsing the portal.

The portal is designed to provide users with information and services related to health prevention and is structured into a public area and a private area.

 

1. Data Controller and Data Protection Officer

The Data Controller is the Regione Puglia, with registered office at Lungomare N. Sauro, 33, 70100 Bari.

Pursuant to Article 37(7) of the GDPR, the contact details of the Data Protection Officer (DPO/RPD) are:

You may contact the DPO to exercise your rights in accordance with Article 12 of the GDPR and/or to request any clarification regarding the protection of personal data.

 

2. Purpose of Processing and Legal Basis

The processing of personal data is carried out in compliance with personal data protection legislation and, in particular, with the principles of fairness, lawfulness, transparency, storage limitation, and data minimisation set out in Articles 5 and 25 of the GDPR.

In accordance with Articles 13 and 14 of the GDPR, the purposes and legal bases for data processing are as follows:

  • Personal data are processed in the performance of tasks carried out in the public interest or relating to the exercise of official authority and institutional activities entrusted to the Puglia Region.
     
  • Some processing activities are based on the user’s explicit consent. In such cases, users are free to provide their data and give consent through a clear and affirmative action.

Except as described for browsing data, users are free to provide personal data when requesting services, information, or support. Failure to provide such data may make it impossible to provide the requested service.

Users may refuse or withdraw consent at any time. However, refusal to provide consent will prevent the provision of the relevant services.

 

3. Types of Data Processed

I. Usage Data

  1. Common Personal Data and Special Categories of Data (Registered Users): Including name, surname, date of birth, gender, tax code (codice fiscale), and email address of registered users. These data are primarily obtained through SPID authentication.
    • Note: Additional data—such as residence, domicile, and the reference Local Health Authority (ASL)—required for service delivery are not stored in our database but retrieved dynamically from the external Edotto system.
       
  2. Voluntarily Provided Data: Images.
     
  3. Browsing Data: During normal operation, the IT systems and software procedures used to operate this website collect certain personal data, the transmission of which is implicit in the use of Internet communication protocols. This category includes IP addresses, domain names, URI (Uniform Resource Identifier) addresses, time of requests, method used to send requests to the server, size of files received, response status codes, and other parameters related to the user’s operating system and IT environment. These data are used exclusively for anonymous statistical analysis and to verify the website’s correct functionality.

 

4. Communication and Disclosure

No data deriving from the web service is communicated or disseminated, except where required by law.

Personal data collected via the web service are not transferred outside the European Union (EU) or the European Economic Area (EEA). All processing takes place within the EU/EEA, ensuring the protections and guarantees provided by the GDPR.

 

5. Retention Period

Common personal data, special categories of data, and voluntarily provided data are stored for the duration necessary to deliver the service, without prejudice to legal retention obligations, and will be deleted upon explicit request from the user.

 

6. Cookies

This website uses only necessary/technical, analytical, and third-party cookies.

  • Necessary/Technical Cookies: Used solely for the transmission of communications over the network and to ensure the provision of requested services (Art. 122(1) of Legislative Decree 196/2003). These are temporary “session” cookies essential for safe and efficient browsing.
     
  • Analytical Cookies (First-party): Used exclusively by this website to collect aggregated and anonymous information on the number of users and how the site is used, with the sole purpose of optimising its structure and content.
     
  • Third-party Cookies: Set by external services used within the site, such as geographical maps (OpenStreetMap).
    • Note: These services do not store cookies on our system, but the browser may send requests to their servers. For more information, refer to the privacy policies of the respective providers. Third-party services used by this site include OpenStreetMap, YouTube, and Office Online.

 

7. Rights of the Data Subject

At any time, the user (data subject) may request and obtain from the Data Controller confirmation and the exercise of the following rights:

  • Right to withdraw consent (Art. 7(3) GDPR)
  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (“right to be forgotten,” Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)

 

8. Right to Lodge a Complaint

Data subjects who believe that their personal data have been processed in violation of the GDPR have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or place of the alleged infringement.