Last updated: Maggio 22, 2026
1. Data Controller
The Data Controller is Istituto Flebologico Italiano S.r.l. (hereinafter "IFI"), with registered office in Padua, Italy. Tax Code and VAT no. 05147230287, REA No. PD-446723, share capital fully paid-in € 10,000. Email: info@istitutoflebologico.it. Website: www.istitutoflebologico.it.
For matters related to the Phlebosophy 2026 congress, the Organizing Secretariat is Junia Eventi (info@juniaeventi.com), acting as data processor pursuant to art. 28 GDPR.
2. Types of data processed
We process the following categories of personal data:
- Identification data: name, surname, tax code (where applicable for invoicing).
- Contact data: email, telephone, postal address.
- Professional data: specialty, affiliation institution/hospital, role.
- Billing data: company name, VAT, address (where applicable).
- Browsing data: IP address, browser, pages visited, dates and times of access (collected automatically).
3. Purposes and legal bases
- Registration to the congress and provision of related services
Legal basis: contract (art. 6.1.b GDPR). Mandatory data — failure to provide makes registration impossible.
- Fulfillment of legal obligations
Legal basis: legal obligation (art. 6.1.c GDPR). Includes tax, accounting and CME accreditation requirements.
- Sending replies to information requests
Legal basis: pre-contractual measures (art. 6.1.b GDPR).
- Sending of marketing communications on future events
Legal basis: explicit consent (art. 6.1.a GDPR), withdrawable at any time.
- Statistics and improvement of the service
Legal basis: legitimate interest of the Controller (art. 6.1.f GDPR) in measuring traffic and improving usability.
4. Data retention period
- Registration data: 10 years (tax obligations).
- Marketing data: until consent is withdrawn or for max. 24 months after the last interaction.
- Browsing data (logs): max. 12 months.
5. Data recipients
Personal data may be communicated to:
- Junia Eventi (Organizing Secretariat) — appointed data processor.
- SIDV (CME Provider n.2974) for accreditation purposes.
- Net Tower Hotel and connected suppliers (catering, transfers, hotel) limited to logistical needs of the package.
- IT service providers (hosting, email, SaaS) appointed as data processors.
- Public authorities only where required by law.
No data is disclosed nor transferred to countries outside the European Economic Area.
6. Rights of the data subject
You have the right to:
- Access your data (art. 15 GDPR);
- Request rectification (art. 16);
- Request erasure (art. 17 — "right to be forgotten");
- Restrict processing (art. 18);
- Data portability (art. 20);
- Object to processing (art. 21);
- Withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
To exercise these rights write to info@istitutoflebologico.it. You also have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).
7. Security measures
IFI adopts adequate technical and organizational measures to protect data against unauthorized access, loss, destruction or disclosure: HTTPS encryption, restricted access, periodic backups, anti-intrusion systems, staff training.
8. Changes
This information may be updated. We recommend you check this page periodically. The date of the last update is shown at the top.
See also our Cookie Policy and the IFI Privacy Policy.