Privacy Policy

Welcome

3DIEMME values your privacy and the protection of your personal data. This 3DIEMME Privacy Notice (“Notice”) explains how we collect, use, share, transfer, and process information collected from or about you (“Personal Data”) by any subsidiary or affiliate of 3DIEMME S.r.l. (collectively “3DIEMME,” “we,” “our,” or “us”).

Scope

This Notice describes the types of Personal Data that 3DIEMME may collect or process, how we may use and disclose that Personal Data, and how you may exercise any rights you may have regarding our processing of your Personal Data. This Notice applies to Personal Data collected or processed by us online (through websites, applications, and otherwise), when we provide products or services to you, your doctor, hospital, medical treatment or scanning facility, or other healthcare provider (collectively, “Healthcare Provider,” which refers both to the Healthcare Provider institution, organization, or company, and individuals employed by or working for or with such organization), or your patients, and in other situations where you interact with us, including anywhere this Notice is posted or referenced (products, services, websites, and other systems will be referred to in this Notice as “Products and Services”). This Notice also applies to Personal Data that is collected or processed when you interact with us in-person, by telephone, or by mail.

3DIEMME may have other unique privacy notices that apply to certain specific situations, such as privacy notices for specific Products and Services in various specific circumstances. To the extent you were provided with a different privacy notice or policy and those policies or notices apply, those policies or notices will govern our interactions with you, not this one.

If you provide Personal Data of anyone other than yourself, please note that you are responsible for complying with all applicable privacy and data protection laws prior to providing that information to 3DIEMME (including obtaining consent, if necessary and required).

Please carefully review this Notice. To the extent permitted by applicable law, by providing us your Personal Data or otherwise interacting with us, you are agreeing to this Notice.

The 3DIEMME subsidiary or affiliate with whom you, your Healthcare Provider, or your patient is interacting or who owns and operates the Product or Service is, where applicable, the entity responsible for the collection and use of your Personal Data (known in some jurisdictions as the data controller). A list of the data controllers can be found in Appendix 1 to this Notice, and contact details can be found in the Contact Us section at the end of this Notice.

Information Collection

Personal Data

“Personal Data” is any information that can be used to identify an individual or that we can link directly to an individual, such as name, address, email address, telephone number, credit card number, or health or treatment information, as applicable. Personal Data in some jurisdictions can include information that indirectly identifies a person – such as a unique number assigned to a patient by a Healthcare Provider, even absent other identifying information. Please note that, for patients, as described below, we often receive information about you from your Healthcare Provider.

Some examples of instances where we collect Personal Data include if you:

We will process any Personal Data we collect in accordance with applicable law and as explained in this Notice (unless, as explained above, one of our other policies or notices governs). In some circumstances, if you do not want to provide us with your information, certain Products and Services may be unavailable to you.

Below is a summary of how we collect, process, and use Personal Data and the potential recipients of your Personal Data. Some jurisdictions require us to state the legal bases for processing your Personal Data, which is included below, but please note that not all jurisdictions may recognize all legal bases.

Categories of Personal Data We Collect

·  Examples of Personal Data Processed

·  Sources of Personal Data

·  Purpose of Processing Personal Data

·  Legal Bases of Processing Personal Data

·  Recipients of Your Personal Data

Identity and Contact Information

·  Examples of Identity and Contact Information: First and last name, email address, postal address, phone number, job title, account username and password, IP address, and National Provider Identifier or state license number

·  Sources: Directly from you, your Healthcare Provider, or your patients; from your devices; from our business partners

·  Purpose: To provide you with our Products and Services; to communicate with you; to identify and authenticate you; to customize content for you; to detect security incidents; to protect against malicious or illegal activity; to ensure the appropriate use of our Products and Services; to improve our Products and Services; for short-term, transient use; for administrative purposes; for marketing, internal research, and development; and/or for quality assurance

·  Legal Bases: For the purposes of our legitimate interests; for medical diagnosis and the provision of healthcare and treatment; in the public interest; to comply with a legal obligation; to perform a contract; to protect vital interests; to ensure high standards of quality and safety of healthcare and medical devices; in circumstances where we have requested and received consent; and for other purposes that may be required or allowed by law*

·  Recipients: 3DIEMME, our affiliates, subsidiaries, and related companies; Healthcare Providers; patients; and partners that assist us in providing the Products or Services or help us improve our marketing or administration**

Demographic Information

·  Examples of Demographic Information: Age, gender, marital status, disability, and date of birth

·  Sources: Directly from you, your Healthcare Provider, or your patients; from your devices; from our business partners

·  Purpose: To provide you with our Products and Services; to communicate with you; to identify and authenticate you; to customize content for you; to detect security incidents; to protect against malicious or illegal activity; to ensure the appropriate use of our Products and Services; to improve our Products and Services; for short-term, transient use; for administrative purposes; for marketing, internal research, and development; and/or for quality assurance

·  Legal Bases: For the purposes of our legitimate interests; for medical diagnosis and the provision of healthcare and treatment; in the public interest; to comply with a legal obligation; to perform a contract; to protect vital interests; to ensure high standards of quality and safety of healthcare and medical devices; in circumstances where we have requested and received consent; and for other purposes that may be required or allowed by law*

·  Recipients: 3DIEMME, our affiliates, subsidiaries, and related companies; Healthcare Providers; patients; and partners that assist us in providing the Products or Services or help us improve our marketing or administration**

Commercial and Financial Information

·  Examples of Commercial and Financial Information: Transaction records, Products and Services purchased, obtained, or considered, request documentation, customer service records, financial transaction history, payment information such as banking information, payment card number, expiration date, delivery address, and billing address, and financial account number

·  Sources: Directly from you, your Healthcare Provider, or your patients; from your devices; from our business partners

·  Purpose: To provide you with our Products and Services; to communicate with you; to identify and authenticate you; to customize content for you; to detect security incidents; to protect against malicious or illegal activity; to ensure the appropriate use of our Products and Services; to improve our Products and Services; for short-term, transient use; for administrative purposes; for marketing, internal research, and development; and/or for quality assurance

·  Legal Bases: For the purposes of our legitimate interests; for medical diagnosis and the provision of healthcare and treatment; in the public interest; to comply with a legal obligation; to perform a contract; to protect vital interests; to ensure high standards of quality and safety of healthcare and medical devices; in circumstances where we have requested and received consent; and for other purposes that may be required or allowed by law*

·  Recipients: 3DIEMME, our affiliates, subsidiaries, and related companies; Healthcare Providers; and partners that assist us in providing the Products or Services or help us improve our marketing or administration**

Health Information

·  Examples of Health Information: Information regarding your treatment, including your date of birth, sex/gender, treatment dates, medical history, and treatment information, patient-reported outcome measures (e.g., responses to questionnaires and surveys), X-rays, magnetic resonance imaging, medical scans, user activity, pictures and videos of treatment activities, therapy completion and use details, and communications with your Healthcare Provider and/or patient, including audio and/or video from telehealth sessions

·  Sources: Directly from you, your Healthcare Provider, or your patients; from your devices; from our business partners

·  Purpose: To provide you with our Products and Services; to communicate with you; to identify and authenticate you; to customize content for you; to detect security incidents; to protect against malicious or illegal activity; to ensure the appropriate use of our Products and Services; to improve our Products and Services; for short-term, transient use; for administrative purposes; for marketing, internal research, and development; and/or for quality assurance

·  Legal Bases: For the purposes of medical diagnosis and the provision of healthcare and treatment; for scientific or historical research or statistical purposes; to ensure high standards of quality and safety of healthcare and medical devices; in circumstances where we have requested and received consent; and for other purposes that may be required or allowed by law*

·  Recipients: 3DIEMME, our affiliates, subsidiaries, and related companies; Healthcare Providers; patients; and partners that assist us in providing the Products or Services or help us improve our marketing or administration**

Professional and Educational Information

·  Examples of Professional and Education Information: Job title or position, employer, National Provider Identifier number, state medical license number, work skills, employment history, graduate degree, certification, specialized training, responses to surveys and questionnaires, and enrollment history for our education and training events

·  Sources: Directly from you; from your devices; from our business partners

·  Purpose: To provide you with our Products and Services; to communicate with you; to identify and authenticate you; to customize content for you; to detect security incidents; to protect against malicious or illegal activity; to ensure the appropriate use of our Products and Services; to improve our Products and Services; for short-term, transient use; for administrative purposes; for marketing, internal research, and development; and/or for quality assurance

·  Legal Bases: For the purposes of our legitimate interests; for medical diagnosis and the provision of healthcare and treatment; in the public interest; to comply with a legal obligation; to perform a contract; to protect vital interests; to ensure high standards of quality and safety of healthcare and medical devices; in circumstances where we have requested and received consent; and for other purposes that may be required or allowed by law*

·  Recipients: 3DIEMME, our affiliates, subsidiaries, and related companies; Healthcare Providers; and partners that assist us in providing the Products or Services or help us improve our marketing or administration**

Technical Information

·  Examples of Technical Information: Internet Protocol (IP) addresses, browser type, browser language, device type, hardware type, media access control (“MAC”) address, international mobile equipment identity (“IMEI”), the version of your mobile operating system, the platform used to access or download  our Products or Services (e.g., Apple, Google, Amazon, Windows), location information, usage information about your device, advertising IDs associated with your device (such as Apple’s Identifier for Advertising (IDFA) or Android’s Advertising ID (AAID)), the date and time you use our Products and Services, Uniform Resource Locators, or URLs (i.e., website addresses) visited prior to arriving and after leaving our Products and Services, activity on our Products and Services and referring websites or applications, data collected from cookies or other similar technologies**, and geolocation information

·  Sources: Directly from you; from your devices; from our business partners

·  Purpose: To provide you with our Products and Services; to communicate with you; to identify and authenticate you; to customize content for you; to detect security incidents; to protect against malicious or illegal activity; to ensure the appropriate use of our Products and Services; to improve our Products and Services; for short-term, transient use; for administrative purposes; for marketing, internal research, and development; and/or for quality assurance

·  Legal Bases: For the purposes of our legitimate interests; for medical diagnosis and the provision of healthcare and treatment; in the public interest; to comply with a legal obligation; to perform a contract; to protect vital interests; to ensure high standards of quality and safety of healthcare and medical devices; in circumstances where we have requested and received consent; and for other purposes that may be required or allowed by law*

·  Recipients: 3DIEMME, our affiliates, subsidiaries, and related companies; Healthcare Providers; and partners that assist us in providing the Products and Services or help us improve our marketing or administration**

Anonymized / De?identified Data

·  Anonymized data is data for which your individual personal characteristics have been removed such that you are not identified and the information is no longer consider Personal Data under data protection laws***

·  Sources: Directly from you, your Healthcare Provider, or your patients; from your devices; from our business partners

·  Purpose: To improve our Products and Services; for short-term, transient use; for administrative purposes; for marketing, internal research, and development; for quality assurance; and/or for our own purposes

·  Legal Bases: We rely on the following purposes to anonymize personal data, after which time the data is no longer Personal Data under relevant data protection laws -- For the purposes of our legitimate interests; for medical diagnosis and the provision of healthcare and treatment; in the public interest; to comply with a legal obligation; for scientific or historical research or statistical purposes; to perform a contract; to protect vital interests; to ensure high standards of quality and safety of healthcare and medical devices; in circumstances where we have requested and received consent; and for other purposes that may be required or allowed by law*

*The legal bases relied upon by 3DIEMME under the European Union’s General Data Protection Regulation (“GDPR”) include those enumerated in Articles 6 and 9, depending on the type of Personal Data.

**In limited circumstances, recipients may include, (1) in the event of a sale, assignment, or transfer, to the buyer, assignee, or transferee; and, (2) government officials, law enforcement, or others when permitted by this Notice or required by law.

***This includes in the United States the removal of identifiers from protected health information required under the Health Insurance Portability and Accountability Act (HIPAA), 45 CFR § 164.514(b)(2), for such data to be considered deidentified.

Cookies and Similar Tools

When you visit 3DIEMME websites or applications, we may use “cookies,” web beacons, and other technologies to help us serve users better and to help us evaluate and improve the content or functions of the Products or Services. A cookie is a small piece of data (a unique numeric code) sent from a website or application and stored on a user’s device while the user is browsing the website or using the application. Cookies do lots of different jobs, like identifying previous activity so that your use of the Product or Service is more efficient and enjoyable, remembering your preferences (like language choices), and authenticating you.

Common uses for cookies include:

Web beacons (also known as Internet tags, pixel tags, and clear GIFs) are small pieces of code that may be placed on our websites or other Products and Services that allow us to obtain information about usage. Web beacons cannot identify you as an individual and are used to help display content to visitors and to generate statistics regarding web traffic and trends.

If you would like to opt-out or withdraw consent to use non-essential cookies and related technologies, you can set your web browser to prevent the use of cookies from 3DIEMME websites, as well as other websites that you may visit (see www.aboutcookies.org for more information on how to do this). If you do so, you can still use 3DIEMME Products and Services, but it is possible that some portions of the Products and Services will not function properly or may perform more slowly. You may also be able to opt-out / withdraw consent to use non-essential cookies and related technologies by clicking the “Preferences” button at the bottom of this Product or Service. By using our Products and Services and not disabling cookies, you consent to their use.

For more information on our use of cookies, web beacons, and similar technologies, please see the 3DIEMME Cookie Notice

Children’s Information

3DIEMME does not knowingly collect, maintain, disclose, or otherwise process Personal Data from minors below the age of 16 without the permission of such minor’s parents or legal guardians.

Combination of Data

We may combine information we collect, whether Personal Data or not, with Personal Data that we may obtain from third parties, including Healthcare Providers.

Interactive Features of Our Websites

To the extent we offer any public or group forums on our Products or Services, such as newsfeeds, blogs, message boards, or similar tools (“Interactive Features”), the posts or comments you make may be public and viewed by others. You should use care before posting information about yourself, including Personal Data. You acknowledge and understand that you have no expectation of privacy or confidentiality in the content you submit to Interactive Features over the Products and Services. Except when required to do so by applicable law, we assume no obligation to remove Personal Data you post on our Products and Services, and you disclose any Personal Data at your own risk.

Links to Other Websites

Our Products or Services may contain links to other websites, applications, products, or services that are not owned or operated by 3DIEMME, such as social media websites and applications like Facebook and Twitter. You should carefully review the privacy policies and practices of other websites, products, and services as we cannot control and are not responsible for privacy policies, notices, or practices of third party websites, applications, products, and services.

Social Media Plug-Ins

Our Products or Services may use social media plug-ins (e.g, the Facebook “Like” button, “Share to Twitter” button) to enable you to easily share information with others.  When you visit our Products or Services, the operator of the social media plug-in can place a cookie on your computer or other electronic device that enables that operator to recognize individuals who have previously visited our Products and Services.  If you are logged into the social media website (e.g., Facebook, Twitter) while browsing on our Products and Services, the social media plug-in allows that social media website to receive information that you have visited our Products or Services.  The social media plug-in also allows the social media website to share information about your activities on our Products or Services with other users of their social media website.  These sharing settings are managed by the social media website and governed by its privacy policy.

Safeguarding Information

Consistent with applicable laws and requirements, 3DIEMME has put in place physical, technical, and administrative safeguards to protect Personal Data from loss, misuse, alteration, theft, unauthorized access, and unauthorized disclosure, consistent with legal obligations and industry practices. We evaluate these safeguards to help minimize risks from new security threats. However, as is the case with all websites, applications, products, and services, we unfortunately are not able to guarantee security for data collected through our Products and Services.

Your Rights Regarding Your Personal Data and How to Exercise Them

You may have a right under your jurisdiction’s data protection law to the following with respect to some or all of your Personal Data:

To exercise these rights, please write to us at support@3diemme.it or 3DIEMME S.r.l., Via Risorgimento, 9, 22063 Cantù - CO Italy. We may, after receiving your request, require additional information from you to honor the request and verify your identity. Please be aware that we may be unable to afford these rights to you under certain circumstances, such as if we are legally prevented from doing so.

If you are concerned about how your Personal Data is used, please email us or contact us. You may also have the right to lodge a complaint against us. To do so, contact your local data protection authority (if one exists in your country).

Transfer of Personal Data Across National Borders

Please be aware that Personal Data we collect and process may be transferred and maintained outside your state, province, country, or other jurisdiction, where the privacy laws may not be as protective as those in your location, including the United States. 3DIEMME has put in place safeguards, in accordance with applicable legal requirements, to protect your Personal Data irrespective of the standards in the country where your Personal Data may be transferred. This includes entering into agreements with third parties, such as service providers, to require them to adopt standards that ensure an equivalent level of protection for data as those we adopt.

Marketing and Promotional Emails

You may unsubscribe from any marketing or promotional emails. To do so, please email us at support@3diemme.it or use the unsubscribe mechanism offered in our marketing emails or other communications, as applicable. Please note that if you already have requested our Products or Services when you decide to withdraw consent, a short period of time may elapse before we can update your preferences and ensure that we honor your request.

How Long We Keep Your Personal Data

We will retain your Personal Data for as long as we maintain a relationship with you, your Healthcare Provider, or your patient and/or for as long as we provide a Product or Service to you or to customers that serve you. We may retain Personal Data therefore as long as is reasonably necessary for legitimate business purposes or legal and regulatory purposes.

Special Note to Patients in the United States

If you are a U.S. patient, please note that this Notice is distinct from your Healthcare Provider’s HIPAA Notice of Privacy Practices, which describes how your Healthcare Provider uses and discloses individually identifiable information about your health that it collects, as well as any other privacy practices it applies. 3DIEMME collects, uses, and discloses Personal Data it receives on behalf of your Healthcare Provider in accordance with your Healthcare Provider’s HIPAA Notice of Privacy Practices.

Changes to This Privacy Notice

We may update this Notice from time to time without notice. As such, you should review this Notice periodically. Your continued interactions with us and/or the use of our Products and Services subject to this Notice constitutes your agreement to this Notice.

Contact Us

If you have any questions, including how to access this Notice in an alternative format, please email us at support@3diemme.it or write to us at 3DIEMME S.r.l., Via Risorgimento, 9, 22063 Cantù - CO Italy.  3DIEMME is the controller processing your data.

If you are located outside of the United States, such as in the European Economic Area or the United Kingdom, you may contact our Data Protection Officer at support@3diemme.it. You may also write to us at 3DIEMME S.r.l., Via Risorgimento, 9, 22063 Cantù - CO Italy.

Updated: October 2021

© 2021 3DIEMME. All Rights Reserved.