Privacy Policy.
Last updated: 5 May 2026 · Version 1.0 · J-Care S.r.l.
1. Data Controller
The data controller for all personal data processed through this website and through the provision of JetSetDoctor services is:
J-Care S.r.l.
Piazza Cavour 7, 20121 Milano (MI), Italia
P.IVA / C.F.: 11830790967
PEC: j-care@legalmail.it
Email privacy: privacy@jcare.it
DPO: dpo@jcare.it
2. Data We Collect
A. Enquiry and Contact Data
When you submit an enquiry through our contact form or communicate with us directly, we collect: first name, last name, email address, telephone number, service of interest, travel dates and route, and any contextual information you choose to provide. We also record the IP address and timestamp of the submission for anti-spam and security purposes.
B. Technical and Analytical Data
When you visit this website, we collect anonymised technical data including browser type, device type, pages visited, and session duration. This data is aggregated and cannot be used to identify you personally. We do not use advertising or profiling cookies. See our Cookie Policy.
C. Clinical and Service Data
When a service engagement commences, we collect and process: clinical history relevant to the engagement, medication lists, emergency contact details, identification documents required for travel, and billing information. This data is processed solely for the purpose of delivering the contracted service.
3. Purposes & Legal Basis
| Purpose | Legal Basis (GDPR) | Notes |
|---|---|---|
| Responding to enquiries | Art. 6(1)(b) — pre-contractual measures | |
| Marketing communications | Art. 6(1)(a) — consent | Revocable at any time |
| Legal obligations (invoicing, tax) | Art. 6(1)(c) — legal obligation | D.Lgs 127/2015 |
| Legitimate interest (security, fraud prevention) | Art. 6(1)(f) — legitimate interest | Balanced test conducted |
| Provision of healthcare services | Art. 9(2)(h) — healthcare provision | Clinical data only |
| Vital interest (emergency) | Art. 9(2)(f) — vital interests | Emergency situations only |
Regarding health advertising: content on this website relating to our services is designed in accordance with L. 145/2018, Art. 1 commi 525–526, which governs the advertising of healthcare services in Italy. We make no therapeutic claims and no guarantees of clinical outcome.
4. Clinical Data & Medical Confidentiality
All clinical data is processed under:
- Art. 622 c.p. (segreto professionale) — professional secrecy applicable to every licensed healthcare professional in our network.
- Art. 9(2)(h) GDPR — processing necessary for the provision of healthcare services under a contract with a healthcare professional bound by professional secrecy obligations.
- Provvedimento Garante 7 marzo 2019 — Italian Data Protection Authority guidelines on the management of health data and clinical records.
- Codes of conduct of the relevant professional orders: FNOMCeO (physicians), FNOPI (nurses).
Clinical records are stored in an encrypted, access-controlled private clinical system. Access is strictly limited to the assigned physician and J-Care medical leadership. No clinical data is shared with third parties beyond those listed in Section 5 without explicit written consent, except where required by law or by a vital interest situation.
5. Recipients
Your personal data may be accessed by or disclosed to the following categories of recipients:
- Internal staff: J-Care S.r.l. administrative and clinical staff, on a need-to-know basis.
- Assigned physician: the specific healthcare professional deployed for your engagement, under professional secrecy and NDA.
- Data processors (DPA in place): Odoo SaaS (CRM and operations), hosting provider, WhatsApp Business / Meta (click-to-chat only), email provider, anonymised analytics provider. A full current list of processors is available on request.
- Payment providers: for billing and invoicing purposes only.
- Destination clinics and hospitals: where clinical handover is required as part of the service, and only to the extent clinically necessary.
- Public authorities: where required by law.
- Legal and insurance advisors: under confidentiality obligations, where required to defend or exercise legal claims.
We do not sell personal data. We do not use personal data for advertising or profiling.
6. International Transfers
Some processing activities may involve the transfer of personal data outside the European Economic Area (EEA). All such transfers are conducted using one or more of the following mechanisms under Chapter V GDPR:
- Standard Contractual Clauses (SCC): EU Commission Decision 2021/914.
- Adequacy decisions: where the destination country has been recognised as providing an adequate level of protection.
- Art. 49 derogations: for performance of a contract with you (Art. 49(1)(b)) or to protect vital interests (Art. 49(1)(f)) in emergency situations.
Country-specific frameworks noted for planned 2026–2028 expansion: USA (DPF EU-US; HIPAA where applicable); UAE/Bahrain (PDPL); Nigeria (NDPR 2019); Kenya (Data Protection Act 2019).
7. Retention Periods
| Category | Retention Period | Legal Basis |
|---|---|---|
| Enquiry data (no service commenced) | 24 months | Legitimate interest |
| Contracts and billing records | 10 years | D.Lgs 127/2015 |
| Clinical records (active client) | 10 years from last entry | Italian healthcare regulation |
| Clinical records (discharged) | Up to permanent where mandated | Healthcare normative IT |
| Marketing (with consent) | Until withdrawal of consent | Art. 6(1)(a) GDPR |
| Security and access logs | 12 months | Art. 6(1)(f) GDPR |
| Cookie consent records | See Cookie Policy |
8. Your Rights
Under Arts. 15–22 GDPR, you have the following rights in relation to your personal data:
- Access (Art. 15): obtain confirmation of processing and a copy of your data.
- Rectification (Art. 16): request correction of inaccurate or incomplete data.
- Erasure (Art. 17): request deletion where processing is no longer necessary, consent is withdrawn, or processing is unlawful — subject to legal retention obligations.
- Restriction (Art. 18): request limited processing in certain circumstances.
- Portability (Art. 20): receive data in a structured, machine-readable format where processing is based on consent or contract.
- Objection (Art. 21): object to processing based on legitimate interest.
- Withdraw consent (Art. 7(3)): at any time without affecting prior lawful processing.
- No automated decision-making (Art. 22): we do not use automated decisions with legal or significant effects.
Requests are responded to within 30 days, extendable by 60 days in cases of complexity (Art. 12(3) GDPR). Contact: privacy@jcare.it.
9. Security Measures
We implement appropriate technical and organisational measures pursuant to Art. 32 GDPR, aligned with ISO/IEC 27001:2022 and ISO/IEC 27701:2019 principles. Key measures include: TLS encryption in transit; encryption at rest for clinical records; role-based access control and multi-factor authentication; audit logging; data segregation between brands; NDA for all staff; regular vulnerability assessment; and a breach notification procedure ensuring Garante notification within 72 hours of awareness of a notifiable breach (Arts. 33–34 GDPR), and communication to affected individuals without undue delay where a high risk is identified.
10. Cookies
For a full description of the cookies used on this website, please refer to our Cookie Policy.
11. Minors
This website is not directed at children under the age of 16. We do not knowingly collect personal data from minors without the verifiable consent of a parent or legal guardian (Art. 8 GDPR; Art. 2-quinquies D.Lgs 196/2003). Where a minor is covered under a family service engagement, the responsible adult takes responsibility for the necessary authorisations.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in law, regulatory guidance, or our operational practices. The "Last updated" date indicates the most recent revision. Where changes are material, active clients will be notified through their primary contact channel. The current version is always available at this URL.
13. Contact & Complaints
Privacy Officer / DPO:
privacy@jcare.it (general privacy enquiries)
dpo@jcare.it (Data Protection Officer)
Post: J-Care S.r.l., Privacy Office, Piazza Cavour 7, 20121 Milano (MI), Italia
Supervisory Authority (Italy):
Garante per la Protezione dei Dati Personali
Piazza Venezia 11, 00187 Roma
www.garanteprivacy.it
If you are resident in another EEA member state, you also have the right to lodge a complaint with the supervisory authority of your country of residence.