Privacy

Privacy Policy for Carol Users

Ver 2.0 – May 2026

Dear User, privacy legislation (specifically EU Regulation 2016/679, the “General Data Protection Regulation” known by the English acronym “GDPR”) requires us to provide you with the following information regarding the processing of your Personal Data, pursuant to Art. 13 of the GDPR.

“Processing of Personal Data”, in simple terms, is any operation concerning any “information relating to an identified or identifiable natural person”. For example, first and last name, or an email address with a “username” that identifies you (e.g., mariorossi@….), is considered “Personal Data”, and the act of collecting and recording it is considered “Processing”; so too are (always by way of example) communication to other subjects and erasure. You, as the “natural person to whom the Personal Data refer”, are defined as the “Data Subject”, and you have the right to receive the following information on who processes your data, why, how and for how long, and what obligations and rights you have in this regard.

A) Who are we?

CAROL S.r.l., Tax Code/VAT no. 16350161002, with registered office at Via Eleonora Pimentel, 2 – 00195 Rome, REA RM-1651076, share capital Euro 12,595 f.p., in the person of its legal representative pro tempore, hereinafter for brevity also “the Company”.

B) What are the categories of persons to whom this information is addressed?

The Users and/or Beneficiaries of the services provided by Carol (via web or app), as defined in the Terms and Conditions, including any family members added to the Household account.

C) Why do we process Personal Data (Purposes) and what is the legal basis for the Processing?

Personal data, including those of a special nature, are processed for the following purposes:

  1. user registration on the platform: to satisfy your request for registration on the platform, based on the necessity of performing pre-contractual measures – Art. 6 § 1.b GDPR;
  2. to use the services made available via web or app, based on the necessity of executing the terms and conditions of the service – Art. 6 § 1.b GDPR;
  3. technical monitoring of the platform and improvement of user experience: to ensure the correct technical operation of the service, detect application anomalies and improve the usability of the platform, Carol employs observability tools (log monitoring and session replay on mobile devices). Session replay is configured with masking options for sensitive fields; application logs are subject to automatic detection and redaction of configured identifying data (Sensitive Data Scanner). Such processing is qualified as pseudonymization/partial redaction and not as complete anonymization. The legal basis is the legitimate interest of the controller pursuant to Art. 6 § 1.f GDPR, recognizable in the need to guarantee the technical quality of the service, with an impact on the rights of the data subjects contained by reason of the minimization measures adopted;
  4. performance of activities necessary for diagnosis, medical history, care, health therapy, rehabilitation or for any other medical or healthcare performance requested, including pharmaceutical and specialist ones – Art. 6 § 1.b GDPR and Art. 9 § 2.h GDPR;
  5. for medical reports, for consultation, for consults or collaborations for the management of clinical problems – Art. 6 § 1.b GDPR and Art. 9 § 2.h GDPR;
  6. administrative activities connected to services and performances of a medical or healthcare nature (by way of a non-exhaustive example, the sending of reminder communications intended to remind the registered patient of the booking date of appointments and/or video appointments; to provide the preparation steps to the registered patient for the preparation for appointments and/or video appointments; the sending of communications relating to the availability of medical reports, etc.) – Art. 6 § 1.b and Art. 9 § 2 letter i) GDPR and Art. 2-sexies paragraph 2 letter t) of Legislative Decree no. 196/2003;
  7. sharing of clinical data via the Health record (see Glossary); the legal basis is the necessity of pursuing purposes of diagnosis, assistance or health therapy, under the responsibility of a professional subject to professional secrecy (Art. 9 § 2.h GDPR in conjunction with Art. 6 § 1.f GDPR (legitimate interest of the controller in continuity of care);
  8. consultation of the data contained in the Health record if deemed indispensable for the protection of the health of a third party or the community (for example, in cases of risk of onset of pathologies in third parties) – Art. 9 § 2.i GDPR;
  9. statistics relating to the actual use of Carol services by Users (for example, based on surveys regarding percentages by age and gender, family type, type of performance, days of the week and time slots, etc.). This processing is carried out with technical and organizational measures aimed at guaranteeing the principle of data minimization, with aggregation and minimization measures aimed at reducing the re-identifiability of the data subjects to a minimum; to the extent that the data are effectively anonymous pursuant to Recital 26 of the GDPR, they fall outside the scope of application of the GDPR;
  10. sending of the newsletter, informative and/or promotional material, via e-mail, push notifications and other digital channels, based on explicit consent – Art. 6 § 1.a GDPR;
  11. identifying and defining the preferences, habits, needs and choices of your person (so-called profiling), based on explicit consent pursuant to Art. 9 § 2.a GDPR, which may be revoked at any time. Such consent is optional. It is specified that profiling is not based on the direct detection of health data and/or data referable to medical performances;
  12. fulfilling obligations provided for by the Applicable Regulation (accounting, tax, security, etc.) and/or executing orders issued by Authorities – Art. 6 § 1.c GDPR;
  13. ascertaining, exercising and/or defending a right in the competent venues, based on legitimate interest – Art. 6 § 1.f GDPR.
D) To whom do we communicate the data (Categories of Recipients)?

The Application does not provide personal data to third parties, except in the necessary measures described below. Data may be communicated to:

a) subjects necessary for the execution of activities connected and consequent to the execution of the contract (e.g., IT service providers) or technological partners who support the execution of ancillary services (e.g., online booking at affiliated facilities) acting as Data Processors;

b) authorized internal personnel, committed to confidentiality or recipients of a legal obligation of confidentiality;

c) doctors and healthcare providers operating at Carol S.r.l. who have performed or perform services in connection with clinical events treated within the Company, through availability via the Health record, limited to the professionals who are treating the patient at the specific moment of the performance and according to the principle of segregation by specialist competence;

d) Analysis laboratories, Diagnostic Centers, Polyclinics in the event that the booking takes place through Carol services;

e) structures of the Regional and National Health Service and affiliated facilities;

f) consultants (by way of example, law firms, accountants, labor consultants, etc.) who perform outsourcing activities on behalf of the Controller;

g) insurance, social security and assistance companies;

h) public organizations and Authorities, if and within the limits in which this is required by the applicable regulation or their orders, or for the exercise, ascertainment and/or defense of a right in court;

i) domain administrators and/or third-party resellers who provide assistance in the use of the service to the User.

E) Do we transfer personal data outside the European Union?

Yes, as follows. For the provision of certain technological services (identity and authentication management, messaging, video appointment, customer care, payment processing), Carol uses services of companies established outside the European Economic Area, particularly in the United States. In such cases, the transfer is carried out on the basis of one or more of the following guarantees: adequacy decision of the European Commission (e.g., EU-USA Data Privacy Framework of July 10, 2023); standard contractual clauses pursuant to Art. 46 § 2 letter c GDPR (EU Implementing Decision 2021/914); supplementary technical and organizational measures compliant with EDPB Recommendations 01/2020. In general, we ensure that data transfers take place only towards countries that guarantee an adequate level of protection, for which an adequacy decision of the European Commission exists, or on the basis of one of the other guarantees provided for by Chapter V of the GDPR. Some of our healthcare providers may operate from countries outside the European Economic Area. In such cases, Carol guarantees that the processing takes place exclusively through its own secure systems, without any local storage of data, and that every transfer is legitimized by adequate guarantees such as the Standard Contractual Clauses of the European Commission, accompanied by rigorous technical and organizational security measures to ensure a level of data protection substantially equivalent to the European one.

F) How long do we keep the Data?

Personal data will be kept according to the following timelines, related to the purposes:

  1. health data (medical reports, medical history, prescriptions, content of the Health record): storage for the time necessary for the purpose of care and, subsequently, for the period provided for by the legislation for healthcare professional liability (ten years from the termination of the relationship, pursuant to the applicable limitation period – Art. 2946 of the Civil Code) or for the protection of rights in court;
  2. administrative and accounting data (invoices): ten years, as per civil and tax obligation (Art. 2220 of the Civil Code);
  3. data linked to consents (marketing, profiling): until revocation of consent by the user;
  4. account registration data: until the deletion of the account by the user. Deletion is performed in two phases: immediate deactivation of the data (soft delete) and definitive and unrecoverable elimination within 30 days of the request, via automated procedure. Data subject to statutory retention obligations are in the meantime kept in anonymized form and then eliminated upon expiry of the applicable term, without prejudice to further legal obligations.
G) Are you obliged to provide us with personal data? What are the consequences of any refusal?

The provision of personal data is necessary for the use of the services offered by the Application and is intended only for the provision of these. Any refusal to provide personal data or to consent to their processing determines the impossibility of providing the services covered by the contract. The provision of data for Marketing purposes is instead optional: you can decide not to provide any data or to subsequently deny the possibility of processing data already provided.

H) What rights do you have?

You, as the person to whom the data refer (“Data Subject”), have the right to:

a) access the data in the possession of the Controller, and to ask for a copy, except in the case where the exercise of the right harms the rights and freedoms of other natural persons;

b) ask for the rectification of any incomplete or inaccurate data;

c) ask for the erasure of the data, subject to the exclusions or limitations established by the applicable regulation (e.g., by Art. 17 § 3 GDPR);

d) ask for the restriction of processing, where the conditions are met and subject to the exclusions established by Art. 18 § 2 GDPR;

e) request data portability (i.e., to receive them in a structured, commonly used and machine-readable format, in order to be able to transmit them to another Controller without hindrance), within the limits in which the processing is based on consent or on the necessity of executing a contract, where technically possible and except in the case where the exercise of the right harms the rights and freedoms of other natural persons;

f) lodge a complaint with the Authority for the Protection of Personal Data (in Italy, www.garanteprivacy.it), or with the Supervisory Authority of the EU State where you habitually reside or work, or of the place where the alleged violation occurred.

Specific rights relating to the Health Record With reference to the Health record, you have the following specific rights:

a) to object to the sharing of clinical events with healthcare providers operating in Carol, objecting to the processing initially or at any subsequent time;

b) to hide individual clinical events (so-called “blackout”): you can deny the visibility, to professionals other than those who produced them, of the data relating to individual clinical events present in your record. In such a case, the persons authorized to access will not be able to automatically become aware of the fact that you have made such a choice (so-called “blackout of the blackout”);

c) to know who has consulted your record: you can request the complete list of who has consulted your Health record. Carol S.r.l. will provide this list within a maximum period of 15 days from the request, indicating: author of the access, date, time and document consulted.

Right to object You may object to processing based on:

  1. consent for marketing and profiling purposes, upon simple request, by sending an email to the address indicated in the following point and, subsequently, by using the revocation function present in each communication received;
  2. legitimate interest for the sharing of data via the Health record, for reasons related to your particular situation, by sending an email to the address indicated in the following point. It is warned that opposition to the Health record may result in the impossibility for healthcare providers to access your previous clinical history, with possible limitations in the quality of the care path;
  3. legitimate interest for other purposes, for reasons related to your particular situation, save for the demonstration by the controller of a compelling and overriding legitimate interest pursuant to Art. 21 § 1 GDPR.

The exercise of the rights mentioned above may also be delayed, limited or excluded in the cases provided for by Art. 2-undecies of Legislative Decree 196/2003.

I) Exercise of your rights
  1. Sending an email to the address: privacy@carol.health
  2. writing by post to the address: Carol S.r.l., Via Eleonora Pimentel 2, 00195 Rome, to the attention of the privacy referent. The Controller has also designated a Data Protection Officer (“RPD” or “DPO”) who is available for every request concerning privacy at the address dpo@carol.health.
J) Changes to the Privacy Policy

Carol reserves the right to make changes to this Privacy Policy at any time, giving notice to Users. Please therefore consult the specific section of the site and/or platform often, taking as reference the date of last modification indicated therein. Previous versions of this information notice can be consulted in the archive of the Legal and Privacy Area available at https://www.carol.health/privacy/. This Privacy Policy concerns exclusively the processing of personal data of the platform user.

GLOSSARY

“Health Record”: the set of personal data generated by current and past clinical events concerning you, shared logically by the healthcare providers assisting you, in order to document your medical history and offer you a better care process. This tool is established at Carol S.r.l. as sole data controller, within which multiple healthcare providers operate (cf. guidelines regarding the Electronic Health Record and the health record of July 16, 2009, web doc. no. 1634116, and update of June 4, 2015, web doc. 4084632).

Torna su