Privacy & GDPR

Notice on the processing of personal data

Provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 as amended — Last updated: 11 May 2026.

Italian version is authoritative

This English translation is provided for convenience. In the event of any discrepancy, the Italian version prevails and is the only legally binding text. Italiano

1. Data controller

The data controller is Fondazione Banca degli Occhi del Veneto Onlus (hereinafter «FBOV» or the «Controller»), registered office at Via Paccagnella 11, 30174 Mestre (VE), Italy.

To exercise the rights granted by the GDPR, and for any request concerning the processing of personal data, the Controller can be reached at the contact details above.

2. Data Protection Officer (DPO)

The Controller has appointed a Data Protection Officer, who can be contacted at dpo@fbov.it regarding any matter relating to the processing of personal data and the exercise of the rights guaranteed by the GDPR.

3. Categories of personal data processed

Through this website FBOV processes the following categories of data:

3.1 Account and sign-in data

  • email address (used as the unique user identifier and to send the magic sign-in link);
  • technical authentication metadata handled by the Firebase Authentication provider (sign-in timestamps, unique user identifier UID, email verification status).

3.2 Data collected through the course registration form

Depending on the participant type selected, the following are processed:

  • identity and contact data (mandatory): first name, last name, email, telephone number, Italian tax code (codice fiscale);
  • for «resident» participants: university of residency, year of the programme and the name of the academic supervisor (optional);
  • for «professional» participants (billing data for the expense reimbursement): VAT number, company or practice name, SDI recipient code, certified email (PEC) address.

The tax code and tax identifiers are collected solely for the tax and administrative obligations connected with issuing the expense-reimbursement documentation and with registration for the course.

3.3 Payment data

For professional participants, payment of the expense reimbursement is handled by an external payment provider. FBOV does not collect or store payment card or bank account details: those data are processed directly by the payment service provider, acting as an independent controller.

3.4 Browsing data

To operate the website, automatically generated technical system logs are processed (IP address, user agent, request timestamps). These data are used solely to ensure the security and correct operation of the service and are not used to profile users. For details on the use of technical cookies, see the cookie policy.

The website does not use analytics tools, advertising tracking or third-party profiling.

4. Purposes and legal basis of processing

PurposeLegal basis (Art. 6 GDPR)
Creating and managing the user account; authentication via email link.Performance of pre-contractual measures and of the contract (Art. 6(1)(b)).
Handling the course registration request, assessing the application and related communications.Performance of pre-contractual measures and of the contract (Art. 6(1)(b)).
Tax, accounting and administrative obligations (issuing the electronic invoice for the expense reimbursement, document retention).Legal obligation (Art. 6(1)(c)).
Information security, abuse prevention and protection of the service.Legitimate interest of the Controller (Art. 6(1)(f)).
Responding to enquiries sent by email or telephone.Performance of pre-contractual measures (Art. 6(1)(b)) or legitimate interest (Art. 6(1)(f)).

Providing the data marked as mandatory in the forms is necessary in order to act on the request: without them FBOV cannot process the course registration or grant access to the personal area.

5. Means of processing and place of storage

Data are processed by electronic means, by authorised and appropriately instructed personnel, applying appropriate technical and organisational measures to ensure their security, confidentiality, integrity and availability (Art. 32 GDPR), including encryption in transit (TLS) and at rest, access control and operation logging.

Data are stored on cloud infrastructure located in the European Economic Area:

  • Application database — Google Cloud Firestore, region eur3 (europe-west);
  • Web application hosting — AWS Amplify, region eu-west-1 (Ireland);
  • Authentication service — Firebase Authentication (Google LLC).

6. Recipients and external processors

For the purposes set out above, data may be processed by the following parties, appointed as processors under Art. 28 GDPR or acting as independent recipients where provided for by law:

  • Google Ireland Limited / Google LLC — provider of Firebase Authentication and Cloud Firestore;
  • Amazon Web Services EMEA SARL — provider of AWS Amplify hosting services;
  • Payment service providers — for handling the expense reimbursement of professional participants (independent controllers);
  • Consultants, accountants and professional advisers — for tax, accounting and legal obligations;
  • Public authorities — where required by law, regulation or order of an authority.

Personal data are not disseminated nor transferred to third parties for marketing or profiling purposes.

7. Transfers outside the EU

Data are stored in data centres located within the European Union. However, some technical services (in particular Firebase Authentication, provided by Google LLC) may involve a transfer of, or access to, data by the parent company located in the United States of America. Any such transfer takes place exclusively on the basis of appropriate safeguards under Chapter V of the GDPR, including:

  • the provider's participation in the EU-US Data Privacy Framework, approved by the European Commission in its adequacy decision of 10 July 2023;
  • the adoption of the European Commission's Standard Contractual Clauses (Decision 2021/914).

A copy of the safeguards adopted is available on request by writing to dpo@fbov.it.

8. Retention period

  • User account data: for as long as the user is registered for the service. Users may request deletion at any time.
  • Data relating to registration requests and course attendance: for as long as needed to run the course and for the 24 months following its conclusion, for internal reporting purposes.
  • Billing data and tax documentation: 10 years from issue of the document, in accordance with Art. 2220 of the Italian Civil Code and applicable tax legislation.
  • System and security logs: for no longer than 12 months, save where longer retention is required to establish or defend legal claims.

At the end of the retention period, data are deleted or irreversibly anonymised.

9. Rights of the data subject

Data subjects may at any time exercise the following rights against the Controller under Arts. 15-22 GDPR:

  • Access (Art. 15) — obtain confirmation of processing and a copy of the data;
  • Rectification (Art. 16) — correct inaccurate data or complete incomplete data;
  • Erasure (Art. 17) — the «right to be forgotten», within the limits set by law;
  • Restriction (Art. 18) — restrict processing in certain circumstances;
  • Portability (Art. 20) — receive the data provided in a structured format;
  • Objection (Art. 21) — object to processing based on legitimate interest;
  • Withdrawal of consent (Art. 7) — where processing is based on consent, without affecting the lawfulness of processing already carried out.

Requests may be sent by email to privacy@fbov.it or to the DPO at dpo@fbov.it. The Controller will respond within 30 days of receipt (extendable by a further 60 days in particularly complex cases, pursuant to Art. 12(3) GDPR).

10. Right to lodge a complaint

A data subject who considers that the processing of their personal data infringes the GDPR has the right to lodge a complaint with the competent supervisory authority. In Italy: Garante per la protezione dei dati personali (the Italian Data Protection Authority) — Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it.

11. Minors

The services offered on this website are addressed to an adult professional audience (ophthalmology residents and practising professionals). FBOV does not knowingly collect personal data of individuals under the age of 18. Should any such processing be identified, the data will be deleted promptly.

12. Automated decision-making

The Controller does not carry out solely automated decision-making, including profiling, producing legal effects or similarly significantly affecting data subjects. Course registration requests are assessed by FBOV staff.

13. Changes to this notice

This notice may be updated at any time to reflect regulatory or organisational changes. The updated version is published on this page together with the date it was last updated. Readers are encouraged to consult it periodically.