INFORMATIVA SULLA PRIVACY

Sito web: michellesavard.com
Data Controller: Michelle Savard – Studio Medico
PIVA 11124810008
Indirizzo: Via Carlo Ignazio Giulio 2, 10122 Turin (TO), Italy
email: info@michellesavard.com
Telefono: +39 349 343 5060

Ultimo aggiornamento: February 5, 2026

  1. INTRODUZIONE

La presente Informativa sulla privacy descrive le modalità di raccolta, trattamento, conservazione e protezione dei dati personali degli utenti che visitano e utilizzano il sito web michellesavard.com (di seguito “Sito web”).

Il Titolare del trattamento si impegna a tutelare la privacy degli utenti in conformità con:

  • Regolamento (UE) 2016/679 (Regolamento generale sulla protezione dei dati – GDPR)
  • Decreto legislativo n. 196 del 2003, modificato dal decreto legislativo n. 101 del 2018 (Codice della privacy)
  • Normativa italiana ed europea applicabile in materia di protezione dei dati personali
  1. TITOLARE DEL TRATTAMENTO

Il titolare del trattamento è:

Michelle Savard
Via Carlo Ignazio Giulio 2, 10122 Turin (TO), Italy
VAT: 11124810008
Email: info@michellesavard.com
Phone: +39 349 343 5060

  1. TIPI DI DATI RACCOLTI

3.1 Dati di navigazione

Durante la normale navigazione, i sistemi informatici e le procedure software preposte al funzionamento del sito web acquisiscono automaticamente alcuni dati la cui trasmissione è implicita nell’uso dei protocolli di comunicazione di Internet.

Tali dati comprendono:

  • Indirizzi IP o nomi di dominio dei dispositivi utilizzati
  • Indirizzi URI (Uniform Resource Identifier) delle risorse richieste
  • Time of request
  • Method used to submit the request to the server
  • Size of the file obtained in response
  • Numerical code indicating the server response status
  • User’s operating system and computer environment
  • Other parameters related to the operating system and computer environment

Questi dati vengono utilizzati esclusivamente per ottenere informazioni statistiche anonime sull'utilizzo del sito web e per verificarne il corretto funzionamento.

3.2 Dati forniti volontariamente dagli utenti

Il sito web raccoglie dati personali quando gli utenti:

  1. a) Complete the contact form

Tramite i moduli di contatto presenti nelle pagine “Contatti” e “Home” vengono raccolti i seguenti dati:

  • Nome
  • Email
  • Phone number
  • Message subject
  • Message/request content
  1. b) Book an appointment

Through the online booking system (Trafft), accessed via the “Book Now” link, the following may be collected:

  • First and last name
  • Email address
  • Phone number
  • Requested appointment date and time
  • Type of service requested
  • Any notes or additional information
  1. c) Subscribe to the newsletter or communications

If such service is available, the following may be collected:

  • Email address
  • Name (optional)
  • Communication preferences

3.3 Cookies and Similar Technologies

The Website uses cookies and similar tracking technologies. For more information, please refer to the Cookie Policy available on the Website through the consent management banner.

The categories of cookies used are:

  • Technical/functional cookies: necessary for Website operation
  • Preference cookies: to store user choices
  • Statistical/analytical cookies: to analyze Website usage in anonymous or aggregate form
  • Marketing cookies: for profiling and personalized advertising
  1. PURPOSES OF PROCESSING AND LEGAL BASIS

Personal data is processed for the following purposes:

4.1 Management of Contact Requests

Purpose: To respond to information requests sent through the Website contact forms.

Legal basis: Performance of pre-contractual measures taken at the data subject’s request (Art. 6, par. 1, lett. b) GDPR) and/or legitimate interest of the Controller in responding to user requests (Art. 6, par. 1, lett. f) GDPR).

Nature of provision: Providing data is optional but necessary to receive a response to requests.

4.2 Appointment Management

Purpose: To manage booking, confirmation, modification, or cancellation of appointments for consultations and treatments.

Legal basis: Performance of a contract or pre-contractual measures (Art. 6, par. 1, lett. b) GDPR).

Nature of provision: Providing data is mandatory for appointment booking. Refusal makes it impossible to provide the service.

4.3 Provision of Wellness Consultation Services

Purpose: To provide holistic consultation services, women’s wellness support, sleep coaching, and craniosacral treatments as described on the Website.

Legal basis: Performance of the service contract (Art. 6, par. 1, lett. b) GDPR).

Nature of provision: Mandatory for providing requested services.

4.4 Informational Communications and Newsletter

Purpose: To send communications regarding offered services, articles, recipes, wellness tips, and updates.

Legal basis: Consent of the data subject (Art. 6, par. 1, lett. a) GDPR).

Nature of provision: Optional. Consent can be withdrawn at any time.

4.5 Legal Compliance

Purpose: To comply with fiscal, accounting, and legal obligations.

Legal basis: Legal obligation (Art. 6, par. 1, lett. c) GDPR).

Nature of provision: Mandatory by law.

4.6 Statistical Analysis and Website Improvement

Purpose: To analyze Website usage to improve offered services and user experience.

Legal basis: Legitimate interest of the Controller (Art. 6, par. 1, lett. f) GDPR) subject to consent for non-technical analytical cookies.

Nature of provision: Optional.

4.7 Protection of Rights

Purpose: To assert or defend the Controller’s rights in legal proceedings.

Legal basis: Legitimate interest of the Controller (Art. 6, par. 1, lett. f) GDPR).

  1. PROCESSING METHODS

Personal data is processed using automated and manual tools, with logic strictly related to the indicated purposes and, in any case, in a manner that ensures data security and confidentiality.

Processing is carried out through:

  • Data collection via web forms
  • Storage in protected databases
  • Management through Customer Relationship Management (CRM) systems
  • Email and secure communication systems
  • Online booking platforms (Trafft)
  • Backup and archiving systems

Security Measures

The Controller adopts appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of transmitted data (HTTPS protocol)
  • Access control to data
  • Authentication systems
  • Periodic backups
  • Security incident management procedures
  • Training of authorized personnel
  1. DATA RETENTION

Personal data is retained for the time strictly necessary to achieve the purposes for which it was collected:

Purpose

Retention Period

Contact requests

24 months from receipt of request

Appointment management

10 years for fiscal and accounting obligations

Service provision

Duration of relationship + 10 years for legal obligations

Newsletter and marketing

Until consent withdrawal

Browsing data (logs)

Maximum 12 months

Protection of rights in court

Until litigation resolution + limitation periods

At the end of the indicated periods, data will be deleted or irreversibly anonymized, unless its further retention is necessary to comply with legal obligations or to defend rights in legal proceedings.

  1. DATA RECIPIENTS

Personal data may be communicated to:

7.1 Authorized Personnel

Employees, collaborators, and consultants of the Controller specifically authorized and trained on personal data processing (e.g., assistants, IT consultants).

7.2 Data Processors

External service providers who process data on behalf of the Controller as Data Processors pursuant to Art. 28 GDPR, including:

  • Web hosting and server providers: for Website hosting
  • Email services: for communication management
  • Online booking platforms: Trafft for appointment management
  • Newsletter and email marketing services: if used for sending communications
  • Cookie management systems: for consent management
  • IT and technical consultants: for Website maintenance
  • Backup and data archiving services
  • Professionals and consultants: accountants, lawyers, tax consultants

7.3 Public Entities

Judicial authorities, public administrations, and other public entities when required by legal obligations.

Data will not be disclosed to third parties or transferred to private entities without the data subject’s consent, except as required by law.

  1. INTERNATIONAL DATA TRANSFERS

Some service providers used may transfer personal data outside the European Economic Area (EEA).

In such cases, the Controller ensures that the transfer takes place in compliance with GDPR through:

  • Adequacy decisions of the European Commission (Art. 45 GDPR)
  • Standard contractual clauses approved by the European Commission (Art. 46 GDPR)
  • Binding Corporate Rules
  • Other safeguards provided by GDPR

Users can obtain specific information about international transfers by contacting the Controller.

  1. DATA SUBJECT RIGHTS

As a data subject, users can exercise the following rights under GDPR:

9.1 Right of Access (Art. 15 GDPR)

Obtain confirmation of the existence of personal data and access to such data, as well as receive information about processing.

9.2 Right to Rectification (Art. 16 GDPR)

Obtain rectification of inaccurate personal data and completion of incomplete data.

9.3 Right to Erasure / “Right to Be Forgotten” (Art. 17 GDPR)

Obtain deletion of personal data in cases provided by law.

9.4 Right to Restriction (Art. 18 GDPR)

Obtain restriction of processing of personal data in the cases provided.

9.5 Right to Data Portability (Art. 20 GDPR)

Receive provided data in a structured and readable format and transmit it to another controller, where technically feasible.

9.6 Right to Object (Art. 21 GDPR)

Object to processing of personal data for legitimate reasons or for direct marketing purposes.

9.7 Right to Withdraw Consent (Art. 7 GDPR)

Withdraw consent at any time, without affecting the lawfulness of processing based on consent given before withdrawal.

9.8 Right to Lodge a Complaint

Lodge a complaint with the Supervisory Authority (Italian Data Protection Authority) in case of processing deemed non-compliant.

How to Exercise Rights

To exercise the above rights, users can contact the Controller:

  • By email: info@michellesavard.com
  • By mail: Michelle Savard, Via Carlo Ignazio Giulio 2, 10122 Turin (TO), Italy
  • By phone: +39 349 343 5060

The Controller will respond to requests without undue delay and, in any case, within one month of receipt. This period may be extended by two months in case of particular complexity of the request.

  1. SUPERVISORY AUTHORITY

The competent supervisory authority for Italy is:

Italian Data Protection Authority (Garante per la Protezione dei Dati Personali)
Piazza Venezia, 11 – 00187 Rome
Phone: (+39) 06.696771
Fax: (+39) 06.69677.3785
Email: garante@gpdp.it
PEC: protocollo@pec.gpdp.it
Website: www.garanteprivacy.it

Users have the right to lodge a complaint with the Supervisory Authority if they believe that the processing of their personal data violates GDPR.

  1. COOKIES AND TRACKING TECHNOLOGIES

The Website uses cookies and similar technologies. For detailed information on:

  • Types of cookies used
  • Cookie purposes
  • Third-party cookies
  • Methods for managing and disabling cookies

Please consult the complete Cookie Policy, accessible through the consent management banner on the Website or upon request to the Controller.

  1. THIRD-PARTY SERVICES

The Website may integrate third-party services that involve the collection of personal data, including:

12.1 Trafft Booking System

For appointment booking, the Website uses the Trafft platform (https://trafft.com/). Data entered in the booking system is also processed by Trafft according to its own privacy policy, available on their website.

12.2 Social Media

The Website includes links to the Controller’s social media profiles on:

  • Facebook (facebook.com/msnaturopath)
  • Instagram (instagram.com/michellesavard)
  • Pinterest (pinterest.fr/michellesavard)

Interaction with these platforms is subject to their respective privacy policies.

12.3 Google Maps / Map Services

The Website may use map services to display the studio location. Such services may collect browsing data.

12.4 Analytics Services

The Website may use statistical analysis services (e.g., Google Analytics) to better understand Website usage. Such services may use cookies and collect data in aggregate form.

  1. LINKS TO THIRD-PARTY SITES

The Website may contain links to third-party websites. The Controller is not responsible for the privacy practices of such sites. We recommend consulting the privacy policies of external sites visited.

  1. MINORS

The services offered through the Website are intended for adults. The Controller does not knowingly collect personal data of minors under 16 years of age without parental consent or consent from those exercising parental responsibility.

Should the Controller become aware of having collected data from minors without the necessary consent, it will proceed with its immediate deletion.

  1. CHANGES TO THE PRIVACY POLICY

This Privacy Policy may be modified or updated periodically. Substantial changes will be communicated to users through notice on the Website or via email.

We recommend consulting this page periodically to stay informed about personal data processing methods.

Last modification date: February 5, 2026

  1. MEDICAL DISCLAIMER

As stated on the Website, the services offered are for wellness support purposes and are educational and informational in nature. They do not constitute medical advice, diagnosis, or medical treatment.

Michelle Savard is not a licensed physician or authorized healthcare professional in Italy. The services do not diagnose, treat, or cure medical conditions.

Users must always consult a licensed physician for medical matters or before making health-related decisions.

Health-related data potentially shared during consultations is treated with particular care as “special categories of data” pursuant to Art. 9 GDPR, based on:

  • Explicit consent of the data subject
  • Necessity for preventive medicine purposes and assessment of work capacity (where applicable)
  • Public interest in the public health sector (where applicable)
  1. CONTACT

For any information regarding this Privacy Policy or to exercise your rights, you can contact:

Michelle Savard
Via Carlo Ignazio Giulio 2, 10122 Turin (TO), Italy
Email: info@michellesavard.com
Phone: +39 349 343 5060
VAT: 11124810008

  1. ACCEPTANCE OF PRIVACY POLICY

Use of the Website and its services implies acceptance of this Privacy Policy. Users who do not accept the processing methods described are invited not to use the Website.

For specific activities requiring explicit consent (newsletter, non-technical cookies, etc.), separate consent will be requested through appropriate mechanisms (checkboxes, banners, etc.).

© 2026 Michelle Savard – All Rights Reserved