Privacy Policy
Last updated: 27 July 2026
This notice describes how Dr. Leonardo Gaggio Garcia processes the personal data of visitors and users of this website, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR").
1. Data controller
The controller of the data collected through this website is Dr. Leonardo Gaggio Garcia, Aesthetic and Maxillofacial Surgeon, VAT number 02514180518, registered with the Medical Board of Arezzo (Ordine dei Medici Chirurghi) under no. 0344. For any request regarding the processing of your personal data, you can write to dottor@gaggiogarcia.com.
2. Data collected
Through the contact form we collect the data you voluntarily provide: name, email address and message content. The site also collects, in aggregate form and only with your consent, statistical browsing data via Google Analytics — see our Cookie Policy for details.
3. Special category data possibly included in the message
The message field of the contact form is free text: describing your request, you may include information about your health, which the GDPR classifies as a special category of data (Art. 9). We process this data only with your explicit consent, given via the dedicated checkbox when submitting the form, and solely to respond to your request. We recommend not including sensitive health details that are not strictly necessary: you can discuss them with the doctor directly during your visit.
4. Purposes and legal basis
Data collected through the form is processed to respond to requests for information and appointment bookings (legal basis: consent, Art. 6(1)(a) GDPR, and where applicable pre-contractual measures, Art. 6(1)(b)) and, where present, to handle health-related data included in the message (legal basis: explicit consent, Art. 9(2)(a) GDPR). We do not use your data for marketing purposes nor do we transfer it to third parties for commercial purposes.
5. Processing methods and retention
Messages sent through the form are delivered by email to the practice's mailbox (dottor@gaggiogarcia.com), managed through the Google Workspace service, together with a record of the date and time you gave your consent. To ensure a prompt response, the practice also receives an automatic Telegram notification signalling that a new request has arrived: this notification contains no personal data. Data is kept for as long as necessary to handle your request, and in any case no longer than 24 months from the last contact, unless different retention periods are required by law (for example, regulations on clinical documentation, should the request develop into a care relationship).
6. Recipients and data processors
Your data may be known to: the Controller and his authorised practice staff; Google Ireland Limited, as the provider of the email service (Google Workspace) through which we receive form messages and, only if you have consented to statistical cookies, of Google Analytics; Sanity.io, for hosting the blog's editorial content; Vercel Inc., as the website's hosting provider. Appropriate contractual safeguards required by the GDPR (Art. 28) are in place with these providers. Telegram only receives an automatic notification containing no personal data and therefore does not process any visitor data.
7. Transfers outside the EU
Google and Vercel Inc. may process data outside the European Economic Area (respectively for the email/Analytics service and for website hosting). Such transfers rely on the safeguards provided by the GDPR, such as both providers' adherence to the EU-US Data Privacy Framework and the European Commission's Standard Contractual Clauses.
8. Your rights
As a data subject, you have the right to request access to your data, rectification or erasure, restriction of processing, data portability, and to object to processing at any time (Articles 15-22 GDPR). You can exercise these rights by writing to dottor@gaggiogarcia.com. You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) if you believe the processing violates applicable law.
9. Minors
This website is not intended to knowingly collect data from minors under 16. If you believe a minor has provided us with personal data without the consent of a parent or guardian, please contact us so we can remove it.
10. Security
We adopt appropriate technical and organisational measures to protect your data against unauthorised access, loss or improper disclosure.
11. Changes to this notice
This notice may be updated over time, for example following regulatory changes or changes to the services used. The date of the last update is shown at the top of the page.