Cookie policy
This page explains which cookies this website uses, which connections your browser makes while you read it, and what happens to the few personal details you may send through the contact form. It is written to be read, not to be signed.
What cookies are
Cookies are small text files that a website asks your browser to store on your device. Some are needed for the pages to work at all; others exist to recognise you across visits or across other websites. The same rules apply to any equivalent technology, such as local storage or tracking pixels.
The cookies this website uses
This is a static website: the pages are published as plain files, there is no user account, no reserved area and no newsletter. It installs no analytics, advertising, profiling, social or retargeting cookies, and it builds no profile of you.
The only cookies that may be set are strictly technical ones, needed to deliver the pages and to protect the server. Under EU and Italian rules these do not require your consent, which is why you are not asked to accept anything to read this site.
- Strictly necessary technical cookies, set by the hosting infrastructure. Purpose: serving the pages correctly and basic server security. Duration: the browser session, or a short technical lifetime. Consent: not required.
- Nothing else. No statistics, no advertising, no social buttons that follow you around, no third-party profiling of any kind.
Server logs
Independently of cookies, the web server keeps standard technical logs: IP address, date and time of the request, page requested, browser and operating system. They serve only to keep the site up and secure, they are not used to identify individual visitors and they are not cross-referenced with anything else.
Connections to other services
The site embeds no maps, no videos, no comment system and no social plugins. Two connections are worth naming plainly:
- Web fonts. The typefaces are loaded from Google’s font service. No cookie is set, but your browser does contact Google servers, which therefore receive your IP address and the technical data needed to deliver the font files.
- The WhatsApp button. Nothing happens until you tap it. If you do, the conversation takes place inside WhatsApp, under Meta’s own terms and privacy policy, outside this website.
If visitor statistics are added later
No analytics tool is installed today. If one is ever added, it will stay switched off until you have given your consent: a banner will let you accept or refuse, refusing will be exactly as easy as accepting, and this page will be updated before the tool goes live. Statistics cookies are never installed on the basis of a legitimate interest alone.
Managing cookies from your browser
You can block or delete cookies at any time from your browser settings. Blocking the strictly necessary ones may stop some pages from displaying correctly. Official instructions:
Who is responsible for your data
The data controller is Dr. Giovanni De Flaviis, sole practitioner. VAT no. 02469650689 · tax code DFLGNN94P14A488Z. Registered at Via Giovanni Iannucci 32, 65013 Città Sant'Angelo (PE), Italy. Email nutrizionista@giovannideflaviis.it · phone +39 388 759 4145. No Data Protection Officer has been appointed: a practice of this size is not required to have one.
What the website collects
The contact form asks for a short list of details and nothing more: your name, your phone number, your email address, the type of appointment you are asking about (first consultation or check-up) and the time of day that would suit you. There is no free-text field. To these are added the technical server logs described above.
There is no online booking system, no upload of documents and no reserved area: the form is a request to be called back, and the appointment is agreed with you by phone.
Please do not send health information through the site
The form deliberately leaves no space for symptoms, diagnoses, therapies, test results or any other information about your health, and you are asked not to send that kind of information by email or WhatsApp either. Health information is collected in person, during the consultation, where it can be handled properly.
Two different levels, two different sets of rules
1. Through this website. Data: the contact details listed above. Purpose: replying to you and arranging an appointment. Legal basis: your consent (art. 6(1)(a) GDPR), given by ticking the box in the form, together with the steps taken at your request before entering into a contract (art. 6(1)(b) GDPR). Providing the data is optional, but without it there is no way to call you back.
2. At the practice. During the consultation, health data are collected — personal history, measurements, body composition — and kept as a record of the programme. These are special categories of personal data under art. 9 GDPR. Legal basis: art. 9(2)(h) GDPR, processing necessary for preventive medicine, health assessment and the provision of care, together with art. 6(1)(b) GDPR and the confidentiality duties that bind a registered health professional. A separate, specific notice is given to you in the practice before any of this begins.
Minors. Where the person followed is a minor, the data are provided by whoever holds parental responsibility, who is given the notice and signs the consent on the minor’s behalf.
How long the data are kept
- Contact requests. Kept for the time needed to reply and to arrange the appointment; if no relationship follows, they are deleted.retention period to confirm
- Records of people followed at the practice. Kept for the period required by the law and by the professional rules that apply to a registered health professional. retention period to confirm
- Technical server logs. Kept by the hosting provider for a short technical period, then overwritten.
Who else can see your data
- The hosting provider that keeps the website and the mailbox running (Hostinger, servers in the European Union), acting as a data processor.
- Hive Digital Studio (Studio Hive Digital Studio di Boris Mazza), the agency that builds and maintains the site, appointed as a data processor under art. 28 GDPR and strictly for technical maintenance.
- The accountant who handles invoicing and tax obligations, once an appointment has turned into a professional service.
Your data are never sold, never published and never used for marketing. There is no newsletter. The full and current list of data processors can be requested at the email address above.
No profiling, no automated decisions, no transfers outside the EU
No decision concerning you is taken by automated means and no profiling is carried out. The data described here are processed within the European Union. The one exception is the web-font connection described above, where your browser contacts Google’s servers: it transmits the IP address needed to deliver the font files and sets no cookies. If you choose to use the WhatsApp button, that conversation happens on Meta’s platform and under Meta’s own rules.
Your rights
Under arts. 15 to 22 GDPR you can ask for access to your data, their correction or erasure, the restriction of the processing, portability, and you can object to the processing. Where the processing is based on consent, you can withdraw it at any time, without affecting what was lawfully done before. For the health data collected at the practice some rights — erasure in particular — are limited by the record-keeping duties of a health professional.
To exercise them, write to nutrizionista@giovannideflaviis.it. You will receive an answer within one month. If you believe your data are being handled unlawfully, you can also lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome —garanteprivacy.it), or bring the matter before a court.
Changes to this page
This page is updated whenever something changes in how the site works — a new tool, a new form, statistics being switched on. The full privacy notice is available on theprivacy page.