Dr. Gaggio Garcia
Legal notice

Privacy Policy

Last updated: 27 July 2026

This notice describes how Dr. Leonardo Gaggio Garcia processes the personal data of visitors and users of this website, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR").

1. Data controller

The controller of the data collected through this website is Dr. Leonardo Gaggio Garcia, Aesthetic and Maxillofacial Surgeon, VAT number 02514180518, registered with the Medical Board of Arezzo (Ordine dei Medici Chirurghi) under no. 0344. For any request regarding the processing of your personal data, you can write to dottor@gaggiogarcia.com.

2. Data collected

Through the contact form we collect the data you voluntarily provide: name, email address and message content. The site also collects, in aggregate form and only with your consent, statistical browsing data via Google Analytics - see our Cookie Policy for details.

3. Special category data possibly included in the message

The message field of the contact form is free text: describing your request, you may include information about your health, which the GDPR classifies as a special category of data (Art. 9). We process this data only with your explicit consent, given via the dedicated checkbox when submitting the form, and solely to respond to your request. We recommend not including sensitive health details that are not strictly necessary: you can discuss them with the doctor directly during your visit.

4. Booking a video consultation

When you book a video consultation through this website we collect your name, email address, phone number (optional) and any reason for the consultation you provide. This data is used to schedule the appointment and is recorded in the practice's Google Workspace calendar, which generates the Google Meet video call link; Google sends a copy of the invitation to the address you provided. The website keeps no copy of the booking: the practice's calendar is the only record. The legal basis is the performance of pre-contractual measures taken at your request and, for any health data you include in the reason field, your explicit consent (Art. 9(2)(a) GDPR). To prevent automated bookings we use Cloudflare Turnstile, which uses no cookies and does not profile visitors. You can cancel the appointment at any time using the link in your confirmation email.

5. Pre-visit medical history form

After booking you receive a personal link to the medical history form, which we ask you to complete before the visit. The form collects data concerning your health (Art. 9 GDPR) and is processed solely on the basis of your explicit consent, given via the dedicated checkbox. The data you enter is not stored on this website or in any database: on submission it is sent directly to the practice's mailbox, which is the only copy, and the calendar retains only the fact that the form was completed. Completing it is optional: you may skip it and give the same information verbally during the consultation. The link is personal, valid only for your appointment and expires with it. The practice keeps the form data for as long as necessary for your care and for medical record-keeping obligations.

6. Purposes and legal basis

Data collected through the form is processed to respond to requests for information and appointment bookings (legal basis: consent, Art. 6(1)(a) GDPR, and where applicable pre-contractual measures, Art. 6(1)(b)) and, where present, to handle health-related data included in the message (legal basis: explicit consent, Art. 9(2)(a) GDPR). We do not use your data for marketing purposes nor do we transfer it to third parties for commercial purposes.

7. Processing methods and retention

Messages sent through the form are delivered by email to the practice's mailbox (dottor@gaggiogarcia.com), managed through the Google Workspace service, together with a record of the date and time you gave your consent. To ensure a prompt response, the practice also receives an automatic Telegram notification signalling that a new request has arrived: this notification contains no personal data. Data is kept for as long as necessary to handle your request, and in any case no longer than 24 months from the last contact, unless different retention periods are required by law (for example, regulations on clinical documentation, should the request develop into a care relationship).

8. Recipients and data processors

Your data may be known to: the Controller and his authorised practice staff; Google Ireland Limited, as the provider of the email service (Google Workspace) through which we receive form messages and, only if you have consented to statistical cookies, of Google Analytics; Sanity.io, for hosting the blog's editorial content; Vercel Inc., as the website's hosting provider. Appropriate contractual safeguards required by the GDPR (Art. 28) are in place with these providers. Telegram only receives an automatic notification containing no personal data and therefore does not process any visitor data. For online bookings the following are also involved: Google Ireland Limited, as provider of the Google Calendar and Google Meet services used to schedule and hold the appointment; Cloudflare, Inc., for the Turnstile anti-bot service protecting the booking form.

9. Transfers outside the EU

Google and Vercel Inc. may process data outside the European Economic Area (respectively for the email/Analytics service and for website hosting). Such transfers rely on the safeguards provided by the GDPR, such as both providers' adherence to the EU-US Data Privacy Framework and the European Commission's Standard Contractual Clauses.

10. Your rights

As a data subject, you have the right to request access to your data, rectification or erasure, restriction of processing, data portability, and to object to processing at any time (Articles 15-22 GDPR). You can exercise these rights by writing to dottor@gaggiogarcia.com. You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) if you believe the processing violates applicable law.

11. Minors

This website is not intended to knowingly collect data from minors under 16. If you believe a minor has provided us with personal data without the consent of a parent or guardian, please contact us so we can remove it.

12. Security

We adopt appropriate technical and organisational measures to protect your data against unauthorised access, loss or improper disclosure.

13. Changes to this notice

This notice may be updated over time, for example following regulatory changes or changes to the services used. The date of the last update is shown at the top of the page.