Datenschutz

HomeDatenschutz

Privacy Policy in accordance with EU Regulation 2016/679 (GDPR)

1. DATA PROCESSING

a) MyLav S.R.L. informs you that this privacy policy is provided in accordance with EU Regulation 2016/679 (hereinafter, the „Regulation“ or „GDPR“).

b) This policy, which applies exclusively to the personal and sensitive data processed, is updated as of the date indicated at the bottom. MyLav S.R.L. reserves the right, at any time, to modify and update it.


2. CATEGORIES OF SUBJECTS WHO PROCESS THE DATA

The data controller is MyLav S.R.L., C.F. and P. IVA 04197610753, with registered office in Alessano (LE) at via Vecchia Montesardo 21.

The data processor is Dr. Guglielmo Giordano, residing in Alessano, via Piani, 43.

The system administrator is Dr. Guglielmo Giordano, residing in Alessano, via Piani, 43.

The persons in charge of processing are employees and collaborators on the staff of MyLav S.R.L. who have been correctly informed about the methods of data processing, as required by the Community Regulation.

The processing of sensitive data by MyLav S.R.L. and its appointees may occur regardless of the consent of the data subject and upon authorization from the guarantor in the following cases:

  • where the processing is necessary for the purposes of carrying out defensive investigations as per law no. 397 of 7 December 2000 or, in any case, to assert or defend a right in court, of equal rank to that of the data subject, when the data are suitable for revealing health status and sexual life, provided that the data are processed exclusively for these purposes and for the period strictly necessary for their pursuit.
  • where the processing is necessary for the safeguarding of the life or physical safety of the data subject or a third party, in the event that the data subject cannot give consent due to physical impossibility, inability to act, or incapacity to understand or to will.

3. CATEGORIES AND TYPES OF DATA SUBJECT TO PROCESSING

The personal data processed by the Controller may include: a) common data, such as personal information (e.g., name, surname, date of birth, address, image, gender, marital status, tax code, etc.), contact information (e.g., landline and/or mobile phone number, email address, etc.), professional and work-related data. b) Data relating to animals owned by the Client may be collected, for which the use of the MyLav for Pets app (available only on official Apple/Google Play stores) or the MyLav Vet Portal website (https://vetportal.mylav.net) is required. The data may include consultation and/or the exchange of information on the health diary/clinical record relating to the state of health, pathologies, diagnostic and therapeutic treatments, and the course of the disease, including with reference to suggested instrumental and pharmacological therapies. c) Data may be collected remotely by completing a form on our website www.laboratoriolavallonea.net on the page dedicated to the first contact procedure. d) During navigation on our portals mylav.net, vetportal.mylav.net, evrps.mylav.net, www.ilfattoveterinario.it, expertsonline.mylav.net, mylavforpets.app, www.laboratoriolavallonea.net, www.mylavblog.net, and with reference to work choices and requests for services from our company and for marketing purposes. e) Via email, classic mail, social media (Facebook, LinkedIn, etc.) in communication exchanges with our staff. f) By phone with the people in charge of the Customer Care service. g) Through API interfaces for bidirectional communication between our information systems and third-party software.


4. PURPOSE OF PROCESSING

The data you provide will be processed by the controller and by duly authorized processors and appointees for the following purposes: a) to guarantee access to the services offered; b) aggregated profiling for scientific and/or market research purposes, statistical surveys, analysis, and for the creation of reports, carried out directly or also through specialized third-party companies; c) communication with the User regarding changes or updates to the terms of use of the MyLav for Pets app and MyLav portals. Should you provide personal data of third parties, you will be considered, with respect to the processing of such data, an autonomous controller, assuming all legal obligations and responsibilities and expressly indemnifying MyLav S.R.L. from any consequences in the event of a dispute, claim, or request for damages from processing that may be received from the interested third parties.


5. LOCATION OF PERSONAL DATA PROCESSING AND COLLECTION METHODS

a) The processing of your data takes place at the registered office of MyLav S.R.L., as indicated above, and at the operational office located in Passirana di Rho (MI) at via G. Sirtori no. 9. Personal data may also be processed by the controller, the processor, or persons appointed by the company at fairs, conferences, seminars, congresses, medical and scientific journals for study, statistical, and scientific research purposes. b) Personal data may be collected through the use of the MyLav app and websites, and, therefore, following the completion of forms, or on the occasion of information exchanges and interactions between the client and the veterinarian.


6. RETENTION

MyLav S.R.L. retains the personal data collected for as long as such information is considered relevant for study and research purposes, unless the data subject requests its deletion. The data is stored in a Data Center located at the operational headquarters and online at the Data Centers of the hosting provider Amazon AWS (https://aws.amazon.com) located in Dublin (Ireland) and Milan (Italy).


7. RIGHTS OF DATA SUBJECTS

The data subject may, at any time, exercise the following rights:

  • Right of access: obtain confirmation of whether or not personal data concerning them exists, even if not yet registered, and their communication in an intelligible form in accordance with the provisions of Art. 15 of EU Regulation 2016/679.
  • Right to rectification: rectify and/or complete the data in the company database, where possible, directly through the app, or by sending a request via email to the official company email address: info@mylav.net in accordance with the provisions of Art. 16 of EU Regulation 2016/679.
  • Right to erasure (right to be forgotten): request the erasure of personal data concerning them in accordance with the provisions of Art. 17 of EU Regulation 2016/679.
  • Right to restriction of processing: request the restriction of processing in accordance with the provisions of Art. 18 of EU Regulation 2016/679.
  • Right to data portability: receive personal data concerning them, which they have provided to a data controller, in a structured, commonly used and machine-readable format and transmit it to another data controller in accordance with the provisions of Art. 20 of EU Regulation 2016/679.
  • Right to object: object, in certain cases, to the processing of personal data concerning them in accordance with the provisions of Art. 21 of EU Regulation 2016/679.
  • Portability and Switching: The switching/portability rights of the Data Act primarily concern non-personal data and the client’s digital assets in SaaS services. For personal data of data subjects, the right to portability under Art. 20 GDPR remains applicable; requests will be handled in a structured, commonly used and machine-readable format, respecting the security and rights of third parties.

8. INFORMATION SECURITY

a) Personal data is sent and stored on servers equipped with firewalls and physically located in protected data centers. b) MyLav S.R.L. is not responsible for any unauthorized access, data loss (e.g., passwords), unlawful/incorrect use, or alterations of personal information that occur outside its control, nor can it guarantee the correct and secure use of personal data by third parties. In the event of a Data Breach, i.e., a security violation – accidental or unlawful – that causes the destruction, loss, alteration, unauthorized disclosure of, or access to personal data stored or otherwise processed, the controller will notify the Guarantor of any violations within 72 hours of becoming aware of them. The analysis of the breach must allow for an assessment of the actual risk of data dissemination, also based on the security measures adopted, the type of data processed, and the degree of identifiability of any individuals involved, in order to establish the priority actions to be taken. The System Administrator will monitor the security status of all processing operations, keeping hardware and software supports updated and informing the Controller about the activities to be implemented to ensure an adequate level of security (in proportion to the type and quantity of personal data processed).


9. RELATIONSHIP BETWEEN THE DATA ACT AND THE GDPR

Reg. (EU) 2023/2854 (“Data Act”) governs the switching/interoperability of digital services and access to data in cases of exceptional need by Public Administrations. For personal data, the Data Act does not create a new legal basis: processing remains governed by the GDPR (Reg. (EU) 2016/679) and its relevant legal bases (Art. 6 and, if applicable, Art. 9). In case of conflict, the GDPR prevails.


10. PUBLIC ADMINISTRATION REQUESTS FOR „EXCEPTIONAL NEED“ (DATA ACT Cpt5)

In the presence of a reasoned request from a Public Administration:

  • MyLav prioritizes the provision of non-personal/aggregated data and limits access to only the data necessary for the stated purpose.
  • If personal data are indispensable, the processing will occur exclusively if a GDPR legal basis exists (e.g., legal obligation or protection from legal claims), applying pseudonymization/anonymization and adequate security measures.
  • MyLav keeps logs of requests and verifies the terms and guarantees declared by the Authority (purpose, duration, deletion at the end of the need, channel security).

11. TRANSPARENCY ON INTERNATIONAL GOVERNMENT ACCESS (DATA ACT, ART. 28)

We will publish and keep an updated transparency page with: (i) the jurisdictions of the data centers/ICT providers used; (ii) a general description of the technical, organizational, and contractual measures adopted to prevent government access that is not compliant with EU law to non-personal data processed in the EU. The relevant URL is an integral part of this policy.


12. CONTACTS

The data subject can exercise the rights recognized by EU Regulation 2016/679 and submit any request, question, comment, or dispute regarding this Policy, or the way their personal data is processed on the Site, to:

MyLav S.R.L. – Registered office via Vecchia Montesardo, 21 – 73031 Alessano (LE) – Operational headquarters: Via G. Sirtori, 9 – 20017 Passirana di Rho (MI) – tel 029311172
– email  info@mylav.net / laboratoriolavallonea@pec.it
– website : www.mylav.net

Last update: 09/12/2025

MyLav
Datenschutz-Übersicht

Diese Website verwendet Cookies, damit wir dir die bestmögliche Benutzererfahrung bieten können. Cookie-Informationen werden in deinem Browser gespeichert und führen Funktionen aus, wie das Wiedererkennen von dir, wenn du auf unsere Website zurückkehrst, und hilft unserem Team zu verstehen, welche Abschnitte der Website für dich am interessantesten und nützlichsten sind.