Privacy Policy
At tufisio.online (hereinafter, the “Service”), we take privacy and personal data protection very seriously. This Privacy Policy explains what data we process, for what purpose, how long we keep it, and what your rights are.
1. Data Controller
The data controller is the owner of tufisio.online.
Privacy Contact: use the form on the page /en/contact or write to contact@tufisio.online
2. Data We Process
Depending on the use of the site, we may process:
2.1 Contact Data (when requesting a demo or contacting)
- Name
- Phone (if provided)
- Clinic/Company Name (if provided)
- City/Country (if provided)
- Message or request
2.2 Technical and Browsing Data
- IP address, device type, browser
- Pages visited and interactions (e.g., button clicks)
- Aggregated statistical data (analytics)
If a clinic uses the software to manage patient/appointment information, the clinic typically acts as the Controller of that data and tufisio.online as the Processor, in accordance with the applicable contract between the parties (where applicable).
3. Purposes of Processing
We process data to:
- Respond to requests (demo, contact, support).
- Manage communications related to the Service.
- Improve the site and Service through metrics and analytics.
- Security: prevent fraud, abuse, and unauthorized access.
- Compliance with legal obligations where applicable.
4. Legal Basis
The legal basis can be:
- Consent (when you submit a form or accept cookies).
- Pre-contractual/Contractual Measures (to manage a demo or business relationship).
- Legitimate Interest (security and service improvement).
- Legal Obligation (where applicable).
5. Data Retention
We retain data for the time necessary to fulfill the purpose:
- Demo/contact requests: for a reasonable period for management and follow-up.
- Analytics/cookies: according to cookie settings and standard retention periods.
- Contractual relationship: during the term and subsequent legal periods where applicable.
6. Recipients and Providers
We may use providers who provide necessary services (e.g., hosting, analytics, email). These providers may process data following instructions from the site owner and under conditions of confidentiality and security.
We do not sell personal data.
7. International Transfers
If any provider is located outside the EEA, appropriate legal mechanisms will be applied (e.g., standard contractual clauses or other recognized mechanisms).
8. Security
We apply reasonable measures to protect data (access control, encryption in transit, security best practices, etc.). No system is infallible, but we work to minimize risks.
9. Rights
You may request:
- Access, rectification, deletion
- Limitation or opposition
- Portability (where applicable)
- Withdraw consent (where applicable)
To exercise rights, use /en/contact and select “Privacy” in the message.
You may also lodge a complaint with the competent data protection authority.
10. Cookies
You can check more information at /en/cookies.
11. Changes to this Policy
We may update this policy. The “Last updated” date will reflect changes.