WEBSITE PRIVACY POLICY

pursuant to Article 13 of Regulation (EU) 2016/679

1. Introduction

The purpose of this Privacy Policy is to describe, pursuant to Article 13 of Regulation (EU) 2016/679, hereinafter also referred to as the “GDPR”, the methods of processing the personal data of users and visitors, hereinafter also referred to as “data subjects”, who visit the website accessible at the following address:

vsl3pharma.com

hereinafter also referred to as the “Site”.

This Privacy Policy applies exclusively to the above-mentioned Site and not to other websites, sections, pages or areas belonging to third parties that may be accessed by the user through links available on the Site.

This Privacy Policy provides users with information relating to the processing of their personal data in connection with browsing and using the Site. Where processing is based on consent, such consent is collected separately, in accordance with the applicable personal data protection legislation.

Users are advised to read this Privacy Policy carefully, as well as any other privacy policy applicable to third-party websites that may be accessed through links available on the Site.

2. Data Controller

The Data Controller is:

ACTIAL FARMACEUTICA SRL
VAT No.: IT14019081000
Registered office: Viale Shakespeare, 47, 00144 Rome, Italy
Email: info@vsl3pharma.com
Telephone: +39 06 54211033

3. Data Processed

The personal data processed consists of ordinary personal data and may include the following categories.

3.1 Data voluntarily provided by the data subject

This consists of personal data freely provided by the user or visitor through any forms available on the Site, such as a contact form, or by voluntarily sending communications to the contact details indicated on the Site.

Such data may include, by way of example, first name, surname, email address, telephone number, company or organisation, as well as any other information voluntarily provided by the user in connection with their request.

3.2 Browsing data

The IT systems and software procedures used to operate the Site acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols.

This category of data may include, in particular: IP addresses, the type of browser used, the operating system, the domain name, information relating to the pages viewed by users on the Site, the access time, the time spent on the pages, the internal browsing path, as well as other parameters relating to the user’s operating system and IT environment.

For further information concerning the use of cookies and other tracking technologies, users are invited to consult the Site’s Cookie Policy.

4. Purposes of processing and legal basis

The data is processed:

a) to respond to requests submitted by users or to follow up on communications received. The legal basis for the processing is the performance of pre-contractual measures, pursuant to Article 6(1)(b) of the GDPR;

b) to validate and manage an order, comply with accounting and tax obligations and handle any complaints. The legal basis for the processing is the performance of a contract, pursuant to Article 6(1)(b) of the GDPR;

c) for marketing purposes, including offers or promotions concerning products or services marketed by the Data Controller. The legal basis for the processing is consent, pursuant to Article 6(1)(a) of the GDPR;

d) the Data Controller may also process the personal data of data subjects in order to offer them products and services tailored to their preferences and consumer profile (“soft spam”). The legal basis for the processing is the legitimate interest in understanding customers and offering products and services that may be of interest to them, pursuant to Article 6(1)(f) of the GDPR. Data subjects may object to this processing of their personal data at any time;

e) to meet any requirements relating to legal defence, as well as in out-of-court matters and pre-litigation phases. The legal basis for the processing is the legitimate interest consisting of the need to meet legal defence requirements in judicial proceedings, as well as in out-of-court matters and pre-litigation phases, pursuant to Article 6(1)(f) of the GDPR.

f) Technical data necessary for browsing the public pages of the Site may also be used for the following purposes:

– to enable the display and proper operation of the Site;
– to ensure the security of the Site and prevent unlawful use;
– to obtain statistical information concerning the use of the Site, where applicable;
– to verify the proper technical operation of the Site;
– to establish possible liability in the event of computer-related offences or cyberattacks against the Site.

The legal basis for the processing is the Data Controller’s legitimate interest in ensuring the operation, security and improvement of the Site, pursuant to Article 6(1)(f) of the GDPR.

5. Methods of processing personal data

Personal data is processed using electronic, IT and telematic tools, in a manner designed to ensure its security, confidentiality, integrity and availability.

The processing is carried out in compliance with the principles of lawfulness, fairness, transparency, data minimisation, accuracy, storage limitation, integrity and confidentiality, in accordance with the GDPR.

The Data Controller adopts appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance, in particular, with Article 32 of the GDPR.

5. Retention period for personal data

Personal data provided by the data subject — including data relating to telephone support requests, data sent by email or data entered in the registration form — will be retained for the purposes referred to in Article 4(a) and (b), in a non-anonymised form, for the period reasonably necessary to fulfil the purposes for which it was collected and, in any event, for no longer than 10 years.

Personal data collected for the marketing purposes referred to in Article 4(c) will be retained until consent is withdrawn and, in any event, for no longer than 24 months.

Personal data collected for the “soft spam” purposes referred to in Article 4(d) will be retained for as long as reasonably necessary to pursue the legitimate interests of the Data Controller and, in any event, until the data subject objects to such processing.

Browsing data is retained for the period strictly necessary for the technical, security and operational purposes of the Site. Where such data is used for statistical purposes, it is processed, where possible, in aggregated or anonymised form.

6. Recipients of personal data

Personal data may be accessed by authorised personnel of ACTIAL FARMACEUTICA SRL, only to the extent necessary for the performance of their duties and on a need-to-know basis.

The data may also be disclosed to the following categories of recipients:

companies appointed as data processors that provide services essential to the activities of the Data Controller, such as IT, technical, hosting, maintenance and Site management service providers; administrative or technical support service providers and consultants;
providers of analytics or audience measurement services, where such services are used;
consultants, professionals and external advisers, where necessary for the exercise or defence of a legal right;
public authorities, supervisory bodies or other entities to which the data must be disclosed pursuant to a legal obligation.

Given that the Site is built using Google Sites, the data may also be processed by Google, as the provider of the Google Sites service, to the extent necessary for the operation, security, hosting and technical management of the Site.

Personal data is not transferred to third parties for marketing or profiling purposes.

7. Transfer of personal data outside the European Economic Area

The personal data collected is not transferred outside the EU/EEA.

However, the use of Google Services, including Google Forms, results in transfers outside the European Economic Area, in particular to servers operated by Google LLC in the United States of America, for hosting and storage purposes.

Such cross-border transfers are carried out in accordance with Regulation (EU) 2016/679, insofar as Google LLC participates in the EU–US Data Privacy Framework and, as a supplementary safeguard, applies the European Commission’s Standard Contractual Clauses.

Should the Data Controller decide to use other cloud services, including CRM services, it will give priority to providers that adhere to the European Code of Conduct for Cloud Service Providers.

In any event, any transfer outside the EU/EEA will be based on an adequacy decision, Standard Contractual Clauses or another appropriate legal basis, in compliance with Recommendation 01/2020 of the European Data Protection Board.

8. Rights of the data subject

The data subject may exercise the rights granted under Articles 15 to 22 of the GDPR at any time, within the limits and under the conditions laid down by the applicable legislation.

In particular, the data subject has the following rights.

Right of access

The data subject may obtain confirmation as to whether or not personal data concerning them is being processed and, where it is, obtain access to such data and information concerning the processing.

Right to rectification

The data subject may request the correction, amendment or updating of inaccurate data, as well as the completion of incomplete data.

Right to erasure

The data subject may request the erasure of their personal data where the conditions set out in Article 17 of the GDPR are met.

Right to restriction of processing

The data subject may request the restriction of the processing of their personal data in the cases provided for under Article 18 of the GDPR.

Right to data portability

Where processing is based on consent or on a contract and is carried out by automated means, the data subject may request to receive the personal data concerning them in a structured, commonly used and machine-readable format.

Right to withdraw consent

Where processing is based on consent, the data subject may withdraw such consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

Right to object

The data subject may object, at any time, to the processing of their personal data based on the legitimate interests of the Data Controller, on grounds relating to their particular situation.

Right to lodge a complaint

The data subject has the right to lodge a complaint with the competent supervisory authority, in particular with the French Data Protection Authority, the Commission Nationale de l’Informatique et des Libertés (CNIL), where applicable, or with the Italian Data Protection Authority.

9. How to exercise your rights

To exercise their rights or for any questions concerning the processing of their personal data, the data subject may contact ACTIAL FARMACEUTICA SRL using the following contact details:

ACTIAL FARMACEUTICA SRL
Viale Shakespeare, 47
00144 Rome, Italy
Email: info@vsl3pharma.com

The request may also be sent by registered letter with acknowledgement of receipt to the registered office address indicated above.

The Data Controller will respond to requests within the time limits laid down by the applicable legislation.

10. Updates to this Privacy Policy

The Data Controller reserves the right to amend or update this Privacy Policy at any time, in particular in the event of changes to the applicable legislation, the processing activities carried out or the features of the Site.

In the event of substantial changes concerning the processing of personal data, a specific notice may be published on the Site.

Last updated: 02/07/2026