Last updated: 31 July 2026
This policy describes how personal data of visitors to the website www.meditehbeyond.com (the “Website”) is processed, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and to Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.
The Website is the institutional information channel of the MEDITeH BEYOND international summit on Digital Health and Telemedicine, promoted by Diplomatia – Health Policy Commission. This policy applies to the Website only; it does not apply to third-party websites that may be reached through links published here.
1. Data Controller
Academy Srl
Registered office: Via Aosta 4/A, 20155 Milan, Italy
E-mail: info@meditehbeyond.com
Data protection requests may be addressed to info@meditehbeyond.com.
2. Categories of data processed
2.1 Browsing data
The information systems and software procedures used to operate the Website acquire, in the course of their normal operation, certain data whose transmission is implicit in the use of Internet communication protocols: IP address, browser type and parameters, operating system, device type, date and time of the request, requested URL, HTTP response status and similar parameters relating to the operating system and the user’s IT environment. These data are used solely to obtain anonymous statistical information on the use of the Website, to verify its correct functioning and to ensure its security, and are deleted immediately after processing. They may be used to ascertain liability in the event of computer crimes against the Website or third parties.
2.2 Data provided voluntarily through forms
The Website makes available contact and expression-of-interest forms. Sending a form entails the acquisition of the data entered by the user, typically: first name, surname, e-mail address, organisation/institution, role, country, telephone number (optional) and the content of the message. Users are asked not to include in free-text fields any special categories of data pursuant to Art. 9 GDPR (in particular health data), which are not required for the purposes described below.
2.3 Data collected for statistical purposes
See section 6 (Cookies and analytics tools).
3. Purposes of the processing and legal bases
| Purpose | Legal basis |
|---|---|
| Making the Website available and ensuring its technical operation and security | Legitimate interest of the Controller in operating a secure website (Art. 6(1)(f) GDPR) |
| Replying to requests for information sent through the forms or by e-mail, and managing the resulting correspondence | Steps taken at the request of the data subject prior to entering into a contract, or performance of a contract (Art. 6(1)(b) GDPR) |
| Managing participation in the Summit and in related preparatory activities (webinars, working groups), where requested by the user | Performance of a contract or of pre-contractual measures (Art. 6(1)(b) GDPR) |
| Sending institutional communications and updates on the Summit and on the MEDITeH Network | Consent of the data subject (Art. 6(1)(a) GDPR), freely revocable at any time |
| Aggregated, non-identifying measurement of Website traffic (Umami) | Legitimate interest of the Controller in understanding, in aggregate form, the use of its own website (Art. 6(1)(f) GDPR) |
| Third-party analytics and audience measurement (Google Analytics 4) | Consent of the data subject expressed through the cookie banner (Art. 6(1)(a) GDPR and Art. 122 of the Italian Privacy Code) |
| Fulfilment of legal obligations and defence of the Controller’s rights before judicial authorities | Legal obligation (Art. 6(1)(c) GDPR) and legitimate interest (Art. 6(1)(f) GDPR) |
Providing the data marked as mandatory in the forms is necessary in order to receive a reply; failure to provide it makes it impossible to process the request. Providing any other data is optional.
4. Retention periods
- Browsing data / server logs: no longer than 12 months, save for security incidents.
- Data sent through the forms: for the time necessary to handle the request and, subsequently, for a maximum of 24 months from the last contact, unless the data are needed for the management of the Summit or for the fulfilment of legal obligations.
- Data relating to participation in the Summit: for the duration of the event and, thereafter, for the periods prescribed by tax and accounting legislation (10 years).
- Data processed on the basis of consent (communications/updates): until consent is withdrawn or an objection is raised.
- Analytics data: for the periods indicated in section 6.
5. Recipients of the data and data processors
Data may be processed by staff of the Controller authorised pursuant to Art. 29 GDPR, and by third parties acting as data processors pursuant to Art. 28 GDPR, in particular:
- the hosting and IT infrastructure provider of the Website;
- the provider of e-mail and productivity services;
- the organising secretariat and the technical suppliers of the Summit;
- Google Ireland Limited, in respect of the Google Analytics service (see section 6);
- professionals and consultants engaged for administrative, accounting and legal purposes.
An up-to-date list of the data processors is available on request at info@meditehbeyond.com. Personal data is not disseminated and is not subject to automated decision-making or profiling producing legal effects.
6. Cookies and analytics tools
A cookie is a small text file stored on the user’s device by the website being visited. The Website also uses similar technologies (e.g. browser local storage). This section constitutes the Website’s cookie policy pursuant to the Guidelines of the Italian Data Protection Authority of 10 June 2021.
6.1 Technical cookies (no consent required)
These are strictly necessary for the operation of the Website and for storing the user’s privacy preferences. They are installed on the basis of Art. 122 of the Italian Privacy Code and do not require consent. They include a cookie that stores the cookie preferences expressed by the user and a session cookie used for session management and for protecting the forms against abuse (CSRF).
6.2 Umami — first-party, cookieless analytics
The Website uses Umami, an open-source web analytics platform hosted on a server located within the European Union. Umami does not install cookies and does not track users across websites. It collects aggregated information on page views, referring source, country, device type and browser. The IP address is used transiently and is not stored in identifiable form. The data produced is aggregated and, in the Controller’s assessment, does not allow the identification of individual users.
6.3 Google Analytics 4 — third-party analytics (consent required)
The Website uses Google Analytics 4, a service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Google Analytics uses cookies and similar identifiers in order to analyse how users interact with the Website. The scripts are activated only after the user has given consent through the cookie banner, and IP-address anonymisation is enabled.
| Name | Purpose | Duration |
|---|---|---|
| _ga | Distinguishes users | 2 years |
| _ga_<container-id> | Maintains the session state | 2 years |
Event and user data are retained in the Google Analytics account for 14 months. Further information is available in Google’s privacy policy and in the Google Business Data Responsibility pages.
6.4 Third-party content
Pages of the Website may include content hosted by third parties (for example video players or maps). Such third parties may install their own cookies; where they are not strictly necessary, they are loaded only after consent has been given.
6.5 Managing preferences
Consent may be given, refused or withdrawn at any time through the cookie preferences panel. Cookies may also be managed or deleted through the browser settings; disabling technical cookies may impair the functioning of the Website. Instructions are available for Chrome, Firefox, Safari and Edge.
7. Transfers of data outside the European Economic Area
Data is processed as a rule within the European Economic Area. Where the use of Google Analytics entails a transfer of data to Google LLC in the United States, such transfer takes place on the basis of the adequacy decision of the European Commission of 10 July 2023 relating to the EU–US Data Privacy Framework and, as an additional safeguard, of the Standard Contractual Clauses adopted by the European Commission. A copy of the safeguards adopted may be requested at info@meditehbeyond.com.
8. Rights of the data subject
Data subjects have the right to obtain from the Controller access to their personal data (Art. 15 GDPR), their rectification (Art. 16), their erasure (Art. 17), the restriction of the processing (Art. 18), data portability (Art. 20), as well as the right to object to processing based on legitimate interest (Art. 21) and to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3)).
Requests may be sent to info@meditehbeyond.com. A reply will be provided without undue delay and in any case within one month of receipt.
Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it) or with the supervisory authority of their country of residence, or to bring proceedings before the competent judicial authority.
9. Security
The Controller adopts appropriate technical and organisational measures pursuant to Art. 32 GDPR, including encryption of communications (HTTPS/TLS), access control, segregation of environments and periodic backups, in order to protect personal data against unauthorised access, loss, alteration or disclosure.
10. Minors
The Website is addressed to healthcare professionals, institutional representatives, researchers and companies. It is not directed at minors under the age of 16, and no data is knowingly collected from them.
11. Amendments to this policy
The Controller reserves the right to amend this policy at any time, in particular where required by changes in the applicable legislation or in the services used. The version in force is the one published at this address, together with the date of the latest update.
