Welcome to the privacy policy of cardioline.com. This policy will help you understand what data we collect, why we collect it, and what your rights are in relation to it.
Last modified: 27/07/2026
Foreword
The protection of personal data and respect for the privacy of users are fundamental values for Cardioline S.p.A., a company active in the development, production and marketing of medical devices and digital solutions for cardiology and telemedicine. Cardioline pays particular attention to the protection of personal data processed in the performance of its activities and undertakes to ensure that all processing is carried out in compliance with the principles of lawfulness, fairness, transparency, minimisation, integrity and confidentiality provided for by Regulation (EU) 2016/679 ("GDPR") and applicable national legislation.
This Privacy Policy describes the ways in which Cardioline S.p.A. collects, uses, stores and protects the personal data of users who visit the www.cardioline.com website, as well as the rights granted to the data subjects and the methods for exercising them.
The objective of this policy is to provide users with clear, transparent and easily accessible information about the processing of personal data carried out through the site, allowing them to understand what data is collected, for what purposes, on what legal basis and for how long they are stored.
The use of the site involves the processing of personal data that may take place for technical purposes necessary for the operation of the site itself, for the management of requests made by users, for the fulfillment of legal obligations, as well as, where required and subject to the consent of the interested party, for marketing purposes.
Users are therefore invited to read this Privacy Policy carefully before using the website and to consult it periodically, as its content may be updated in the event of regulatory, organisational or technological changes.
1. Data Controller
Cardioline S.P.A.
Via Linz, 151 – 38121 – Trento (TN) – Italia
VAT Number: 03153711209
PEC: [email protected] and e-mail: [email protected]
2. Data Protection Officer (DPO)
inVetta Legal S.r.l.s.
Code and VAT Number 03341960122
Registered office Via Carlo Cattaneo, 2, 21100 – Varese (VA)
In the person – just special power of attorney – of the Director Francesco Cerra
Tax code CRRFNC83M18L682A
The main office in Via Carlo Cattaneo, 2, 21100 – Varese (VA)
Secondary office in Piazza Giovine Italia, 3, 20123 – Milano (MI)
Pec: [email protected]
E-mail: [email protected].
3.Type of Data We Collect
Personal Data collected by this Website, either independently or through third parties, may include:
- identification data (such as name and surname);
- contact details (such as email address, telephone number and business contact details);
- professional and business data (such as profession, role, company, organisation or structure to which you belong);
- data relating to professional location (such as country, city and type of establishment);
- data relating to products, services, events or information materials of interest to the User;
- information and content included in requests, messages or forms completed by the User;
- website navigation and use data;
- information about the device you use to access the site;
- cookies and other tracking tools as described in the Cookie Policy.
Personal Data may be freely provided by the User or, in the case of browsing and usage data, collected automatically during the use of the Website. Unless otherwise indicated, the data requested in the forms on the Site are necessary to allow the Data Controller to manage the User's request, provide the requested information or services and comply with applicable legal obligations. Failure to provide the data marked as mandatory may prevent the Data Controller from following up on the request or providing the requested service. Any data indicated as optional may be omitted without any consequence on the possibility of browsing the Site or using the main services offered. Users who have doubts about which data are mandatory can contact the Data Controller at the addresses indicated in this policy. Any use of cookies or other tracking tools by this Website or by third-party providers used by the Data Controller is aimed at providing the service requested by the User and for the additional purposes described in this Privacy Policy and in the Cookie Policy. The User assumes responsibility for the Personal Data of third parties that may be communicated, published or shared through this Website and guarantees that he/she has the right to communicate them, freeing the Data Controller from any liability towards third parties.
4. Purposes of the Processing of the Data collected
The personal data collected through the www.cardioline.com website will be processed for the following purposes:
- management and operation of the website;
- responding to requests sent by users;
- fulfilment of legal and regulatory obligations;
- protection of the rights of the Data Controller;
- prevention of fraudulent activities or illegal uses;
- compilation of statistics on the use of the site;
- optimization of site performance and security;
- display of content from external platforms;
- marketing and commercial communication activities, where applicable and subject to the consent of the data subject, when required by current legislation.
The following sections describe in detail the specific processing activities carried out through the website, with an indication of the purposes pursued, the categories of personal data processed and, where applicable, the third parties involved in the provision of the related services.
4.1. Website Management and Maintenance
The website is developed and managed using the WordPress platform, which is used as a content management system (CMS).
Data processed
- browsing data;
- technical data relating to the device and browser used;
- Information collected automatically when you use the site.
Purpose
The information collected is used to ensure the proper functioning of the site, content management, technical maintenance and monitoring of the security of the IT infrastructure.
Legal basis
Legitimate interest of the Data Controller to ensure the operation, technical management, security and maintenance of the website (art. 6, par. 1, lett. f GDPR).
4.2. Traffic optimization and distribution
To improve site performance and ensure fast loading times and high levels of service availability, Cardioline uses vendors that specialize in optimizing and delivering web content through content delivery networks (CDNs).
These services may process information relating to the connections made by users, including IP addresses, technical navigation data and other information necessary for the correct provision of the requested content.
Purpose
Improve the performance, security, reliability, and loading speed of the website, as well as ensure efficient delivery of content to users.
Legal basis
The Data Controller's legitimate interest in ensuring the security, efficiency, operational continuity and performance of the website and online services offered to users, pursuant to art. 6(1)(f) GDPR.
4.2.1. Bunny CDN
Bunny CDN is a Content Delivery Network service provided by BunnyWay d.o.o., which is used to distribute the content of the site through a global network of servers.
Data processed
- usage data;
- IP address;
- technical information relating to the device and navigation.
Place of processing Slovenia and further locations of the servers used by the provider.
4.2.2. Cloudflare
Cloudflare is a performance optimization, security, and traffic distribution service provided by Cloudflare Inc.
The service acts as an intermediary between the website and the user's browser, helping to protect against cyberattacks, improve performance and collect statistical information on traffic.
Data processed
- IP address;
- usage data;
- cookies and other tracking tools;
- additional categories of data indicated in the supplier's privacy documentation.
Place of processing in the United States and other countries in which Cloudflare operates, subject to the guarantees provided for in Chapter V of the GDPR.
4.3. Handling contact requests
Users can contact Cardioline through the appropriate forms on the website. Filling in the form involves the processing of personal data provided by the user in order to provide feedback to requests for information, assistance, quotes or other communications sent through the site.
Data processed
- Company/Structure
- Profession
- Surname
- Name
- Phone
- Country
- City
- any additional information voluntarily provided by the user in the message.
Purpose
To respond to requests for information, assistance, quotes or other communications sent by the user through the contact channels on the website.
Legal basis
Execution of pre-contractual measures adopted at the request of the data subject pursuant to art. 6, par. 1, letter b) GDPR and pursuit of the legitimate interest of the Data Controller in managing the communications received.
4.4. Direct Marketing
Subject to the free, specific and optional consent of the data subject, the Data Controller may process personal data for the sending, via e-mail or other electronic communication tools, newsletters, information and commercial communications, updates on products and services, technical documentation, information material, as well as invitations to trade fairs, events, training courses, webinars and other initiatives organized or promoted by the Data Controller.
Cardioline does not use the data referred to in this paragraph to carry out user profiling activities nor does it adopt automated decision-making processes aimed at analysing the preferences, behaviours, habits or interests of data subjects in order to send personalised commercial communications.
Data processed
Identification, professional and contact data
Purpose
Sending newsletters, information and commercial communications, updates on products and services, technical documentation, information material and invitations to events, fairs, webinars, training courses and other initiatives promoted by the Data Controller.
Legal basis
Free, specific, informed and optional consent of the data subject pursuant to art. 6, par. 1, letter a) of the GDPR. Consent can be revoked at any time without affecting the lawfulness of the processing carried out before the revocation. The provision of data for these purposes is optional. Failure to provide consent does not affect the possibility of browsing the website, requesting information, receiving the requested material or obtaining feedback to one's requests.
4.5. Cookies and tracking tools
The website uses cookies and other tracking tools for technical, security, functionality, measurement purposes and, subject to consent, for activities related to information and direct marketing communications.
The characteristics of the cookies and tracking tools used, their purposes, the providers involved, the storage times, the methods for collecting consent and the instructions for managing preferences are described in the Cookie Policy, which can be consulted via the appropriate link on the website.
Data processed
- usage data;
- device information;
- online identifiers and tracking tools.
Purpose
Analysis of user interactions with the website and measurement of the effectiveness of marketing and communication activities using tracking tools.
Legal basisConsent of the data subject pursuant to art. 6, par. 1, letter a) GDPR. You can revoke your consent at any time.
5. Methods and place of processing of the Data collected
5.1. Processing methods
The Data Controller adopts appropriate technical and organizational measures aimed at ensuring the security of Personal Data and preventing unauthorized access, disclosure, modification or destruction. The processing is carried out using IT and telematic tools according to the principles of lawfulness, fairness, transparency and minimisation, with methods strictly related to the purposes indicated in this policy.
5.2. Place of processing
Personal Data are processed at the offices of the Data Controller and at the offices of the service providers used for the purposes described in this Privacy Policy.
The data is generally processed within the European Economic Area (EEA). However, some services used by the Data Controller for the management of the website, IT systems, electronic communications, cloud platforms, webinars or marketing activities may involve the transfer of personal data to countries located outside the EEA.
If such transfers take place, the Data Controller guarantees that they take place in compliance with Articles 44 et seq. of Regulation (EU) 2016/679 ("GDPR"), adopting the guarantees provided for by applicable legislation, such as adequacy decisions adopted by the European Commission or Standard Contractual Clauses (SCCs) approved by the European Commission.
The User can obtain further information regarding the international transfers of personal data and the guarantees adopted by the Data Controller by contacting him at the addresses indicated in this Privacy Policy.
6. Recipients of personal data
Personal Data may be processed by the Data Controller's authorized personnel and communicated, exclusively within the limits necessary for the pursuit of the purposes indicated, to subjects who provide services to support the Data Controller's activities, such as IT service providers, website hosting and management, CRM system providers and platforms for sending information or commercial communications, consultants and professionals, sales personnel, distributors and business partners competent for the territory or type of product, as well as public authorities or other subjects in the cases provided for by law.
These subjects operate, as the case may be, as duly appointed Data Processors pursuant to art. 28 of the GDPR or as independent Data Controllers. The updated list of recipients and Data Processors can be requested at any time from the Data Controller.
7. Retention period
Personal Data are stored for the time strictly necessary to pursue the purposes for which they were collected and, subsequently, for the periods provided for by applicable legislation or necessary for the protection of the rights of the Data Controller.
In particular, the data are stored according to the following criteria:
| Purpose of the processing | Data categories | Retention period |
|---|---|---|
| Website management and security | Browsing data, technical logs, IP addresses, device and browser data | For the time strictly necessary to ensure the operation and security of the site and, except for the need to ascertain crimes or defend rights, no later than 12 months from the collection |
| Handling contact requests | Identification, professional, contact data and content of requests sent through the forms on the site | For the time necessary to manage the request and thereafter for a maximum period of 24 months from the last interaction, unless a contractual relationship or legal obligations are established |
| Management of commercial requests, quotes and pre-contractual information | Identification, professional and contact data | For the time necessary to manage the request and, in the event of failure to establish the relationship, for a maximum of 24 months from the last interaction |
| Direct marketing activities (newsletters, events, webinars, product updates) | Identification, professional and contact data | Until the withdrawal of consent and in any case no later than 24 months from the collection or from the last significant interaction of the data subject |
| Security logs and prevention of fraudulent or abusive activity | IP addresses, browsing data, security events, and system logs | Up to 12 months from collection, except for the need to ascertain, exercise or defend a right in court |
| Data collected through cookies and trackers | Technical cookies, preferences and other online identifiers | For the periods indicated in the Cookie Policy and in the settings of the individual tracking tools used by the site |
| Compliance with legal obligations and protection of the rights of the Data Controller | Any category of data relevant to the specific case | For the period provided for by applicable legislation and, in any case, until the statute of limitations of the rights exercisable by the Data Controller |
At the end of the storage periods indicated above, Personal Data will be deleted, anonymized or stored only in the cases and within the limits permitted by current legislation. The data subject may request further information on the retention criteria applied to individual processing operations by contacting the Data Controller at the addresses indicated in this policy.
8. Your rights under the General Data Protection Regulation (GDPR)
Users may exercise certain rights with reference to the Data processed by the Data Controller.
In particular, within the limits provided for by law, the User has the right to:
- withdraw consent at any time. The User may revoke the consent to the processing of their Personal Data previously expressed.
- object to the processing of their Data. The User may object to the processing of their Data when it takes place on a legal basis other than consent.
- access your Data. The User has the right to obtain information on the Data processed by the Data Controller, on certain aspects of the processing and to receive a copy of the Data processed.
- verify and request rectification. You can verify the accuracy of your Data and request that it be updated or corrected.
- obtain the restriction of processing. The User may request the restriction of the processing of their Data. In this case, the Data Controller will not process the Data for any other purpose than their storage.
- obtain the deletion or removal of your Personal Data. The User may request the deletion of his/her Data by the Data Controller.
- receive your Data or have them transferred to another controller. The User has the right to receive his/her Data in a structured, commonly used and machine-readable format and, where technically feasible, to obtain its unhindered transfer to another controller.
- lodge a complaint. The User may lodge a complaint with the competent data protection supervisory authority or take legal action.
Users have the right to obtain information regarding the legal basis for the transfer of Data abroad including to any international organization governed by international law or constituted by two or more countries, such as the UN, as well as regarding the security measures adopted by the Data Controller to protect their Data.
8.1.Details of the right to object
When Personal Data are processed in the public interest, in the exercise of official authority vested in the Data Controller or to pursue a legitimate interest of the Data Controller, Users have the right to object to the processing for reasons related to their particular situation.
8.2.How to exercise your rights
Any requests to exercise the User's rights can be addressed to the Data Controller through the contact details provided in this document. The request is free of charge and the Data Controller will respond as soon as possible, in any case within one month, providing the User with all the information required by law. Any rectification, erasure or limitation of processing will be communicated by the Data Controller to each of the recipients, if any, to whom the Personal Data have been transmitted, unless this proves impossible or involves a disproportionate effort. The Data Controller shall notify the User of these recipients if he/she so requests.
9. Further information on processing
Defense in court
The User's Personal Data may be used by the Data Controller in court or in the preparatory stages of its possible establishment for the defense against abuse in the use of this Website or related Services by the User. The User declares to be aware that the Owner may be obliged to disclose the Data by order of public authorities.
Specific information
At the request of the User, in addition to the information contained in this privacy policy, this Website may provide the User with additional and contextual information regarding specific Services, or the collection and processing of Personal Data.
System logs and maintenance
For operation and maintenance purposes, this Website and any third-party services used by it may collect system logs, i.e. files that record interactions and which may also contain Personal Data, such as the User's IP address.
Information not contained in this policy
Further information in relation to the processing of Personal Data may be requested at any time from the Data Controller using the contact details.
Changes to this privacy policy
The Data Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Website and, if technically and legally feasible, by sending a notification to Users through one of the contact details it has. Please consult this page frequently, referring to the date of last modification indicated at the bottom.
Legal references
Unless otherwise specified, this policy applies exclusively to this Website.

