
PRIVACY POLICY

PRIVACY POLICY
SANUSLIFE International GmbH Privacy Policy
1. Introduction
For SANUSLIFE International GmbH, operator of the website ecaia.it (“us”, “we”, “our company”), the protection and safeguarding of your data are important. This Privacy Policy (“Privacy Policy”) explains our data protection practices for the activities listed below. As is your right, we inform you about how we collect, store, access and otherwise process data relating to individuals. In this Policy, “personal data” means any information by which a person can be identified, either alone or in combination with other available information.
The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is:
SANUSLIFE International GmbH
Alte Tierserstraße 18
39053 Karneid (BZ), Italy
Email: info@ecaia.it
We are committed to protecting your privacy in accordance with the most comprehensive data protection regulations. We therefore comply with the obligations arising from the following provisions:
the EU General Data Protection Regulation (GDPR)
the Swiss Federal Act on Data Protection (revFADP/FADP)
Scope
This Policy applies to the website ecaia.it as well as to the content and services offered through it by SANUSLIFE International GmbH.
This Policy does not apply to third-party applications, websites, products, services or platforms that can be accessed via links (not SANUSLIFE International GmbH links) that we make available to you. Such websites are operated independently of us and are not owned by us. They have their own data protection and data collection practices. Personal data that you provide to these websites is subject to the privacy policy of the respective third party. We cannot accept any liability for the actions or policies of these independent websites and are not responsible for the content or data protection practices of such sites.
Processing activities
This Policy applies when you interact with us through any of the following activities:
When you visit one of our websites that is linked to this Privacy Policy.
This Privacy Policy was created with the support of Enzuzo’s privacy tool and adapted to the actual processing operations of the website.
2. Personal data we collect
The personal data we collect
When you communicate with us via contact forms, email or the communication widget, we may process personal data that you voluntarily provide to us. This includes, in particular, the contact details entered in the respective form (e.g. name and email address) as well as the content of your inquiry.
When you use the functions of our website or contact us, we process the following types of personal data:
Name and email address, if you contact us.
Message content and support requests.
Feedback, e.g. customer support or product reviews
Product-related inquiries and information that you voluntarily provide to us.
Content, e.g. posts, comments, audio or documents
How we collect your personal data
We collect personal data from the following sources:
From you. You may provide us with information such as your name, email address, message content, feedback and product-related inquiries by completing forms, using our website as well as our products or services, entering information online, or corresponding with us by post, email or other means.
This also includes personal data that you provide to us, for example, when you:
use our products or services;
create content about our products or services;
express interest in our products or services;
contact us if you have an inquiry or wish to report a problem (by telephone, email, social media or a messaging service);
Automated technologies or interactions: When you interact with our website, we may automatically collect the following types of data (all as described above): device data about your equipment, usage data about your browsing activities and patterns, as well as contact data if tasks that you performed via our website remain incomplete. We collect this data using cookies, server logs and other similar technologies. Further details can be found in the section on cookies below.
Third-party providers: We may receive personal data about you from various third-party providers, including:
content from communication services, including email providers and social networks, if you give us permission to access your data held by such third-party services or networks;
information from technical service providers, hosting providers and communication services, insofar as this is necessary for the operation of the website.
If you provide us or our service providers with personal data relating to other individuals, you thereby declare that you are authorised to do so and acknowledge that such data will be used in accordance with this Policy. If you believe that we have obtained your personal data improperly, or if you otherwise wish to exercise your rights regarding your personal data, please contact us using the information provided in the “Contact” section below.
Device and usage data
When you visit a SANUSLIFE International GmbH website, we automatically collect and store information about your visit using browser cookies (files sent by us to your computer) or similar technology. You can configure your browser to reject all cookies or to indicate when a cookie is being sent. The help function of most browsers provides information on how to accept or disable cookies or enable notifications about incoming new cookies. If you do not accept cookies, some features of our service may not be usable. We recommend that you leave them enabled.
We also process information when you use our website or interact with our contact and support functions.
This information may include:
IP address
Date and time of access
Browser type and browser version
Operating system
Referrer URL
Pages and content accessed
Other technical connection and usage data
This data is processed to ensure the security, stability and functionality of the website. The legal basis is Art. 6(1)(f) GDPR.
Data we collect from third parties
We may receive your personal data from third parties, in particular from technical service providers, communication services or business partners, insofar as this is necessary for the operation of the website. This personal data is not collected by us but by third parties and is subject to the data protection and data collection policy of the respective third party. Insofar as personal data is processed directly by third-party providers, their respective data protection provisions apply. We have no influence over specific data processing carried out outside our area of responsibility. As always, you have the right to review and correct this information. If you have any questions, you should first contact the relevant third party to obtain further information about your personal data. If you have questions about the processing of your personal data or wish to exercise your data protection rights, please contact SANUSLIFE International GmbH at info@ecaia.it or via the contact details published in the website’s legal notice.
Links to third-party providers
Our websites and services may contain links to other websites and services operated by third parties. The data protection practices of such other services, or of social media networks that host our brand’s pages on social media, are subject to the privacy policies of third parties. You should read these policies to better understand the data protection practices of such third parties.
Purpose and legal basis for the processing of personal data
We collect and use personal data in order to provide, maintain and further develop our website as well as our contact and support services.
The purposes include:
providing information about our products and services
creating a secure environment
investigating and preventing security incidents such as breaches, attacks and hacks
delivering, developing and improving our website as well as the content and services offered
delivering, maintaining, troubleshooting and improving our website
providing technical and customer support
communicating with you about the products and services
Contact form and chat function
When you use the contact form or chat function provided on our website, we process the personal data you provide solely for the purpose of handling your inquiry, communicating with you and technically providing and documenting the inquiry.
The legal basis is Art. 6(1)(b) GDPR, insofar as the inquiry is aimed at entering into or performing a contract or taking pre-contractual measures, as well as Art. 6(1)(f) GDPR on the basis of our legitimate interest in efficiently handling inquiries and providing customer service.
We process personal data exclusively on the basis of the applicable legal grounds.
Insofar as processing is based on our legitimate interests, this is carried out in particular to ensure the security of our website, handle inquiries, improve our content and services, and prevent misuse and security incidents. Insofar as processing is based on your consent, such consent is obtained prior to the respective processing. If processing activities are materially changed and consent is required for this purpose, affected individuals will be informed accordingly and, where applicable, asked to provide their consent again. If certain functions or services require your consent, failure to provide or withdrawal of such consent may result in individual functions being available only to a limited extent or not at all.
The processing of personal data is carried out in particular on the following legal bases:
Art. 6(1)(b) GDPR for handling inquiries and carrying out pre-contractual measures;
Art. 6(1)(c) GDPR for compliance with legal obligations;
Art. 6(1)(f) GDPR on the basis of our legitimate interests in the secure operation of the website, the handling of inquiries and the prevention of misuse and security incidents;
Art. 6(1)(a) GDPR, insofar as you have consented to certain processing activities (e.g. optional cookies).
Third-party tools
We use the following third-party services for the operation of our website, communication with visitors, and the processing and storage of personal data:
Brevo: processing and management of incoming communications as well as provision of email communication, insofar as necessary for handling inquiries.
Framer: technical provision, hosting and delivery of the website, including the processing of technically necessary connection and server data.
Lime Connect: provision of communication and contact functions, processing of contact inquiries, and management of customer communication processes, insofar as used on this website.
Cloudflare: security, performance and protection measures against misuse and automated access.
Further information on data processing by these providers can be found in their respective privacy notices.
International data transfers
Some of the service providers we use may process personal data in countries outside the European Economic Area (EEA) or access data from such countries.
Where personal data is transferred to third countries, such transfer takes place exclusively in compliance with the requirements of Art. 44 et seq. GDPR. Where there is no adequacy decision by the European Commission, we base the transfer on the Standard Contractual Clauses (SCCs) approved by the European Commission or other legally permissible safeguards.
Further information about the service providers used and the applicable safeguards can be requested at info@ecaia.it.
This also applies to the use of sub-processors by our service providers. Where personal data is processed outside the European Economic Area in this context, this takes place exclusively on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR.
Disclosure and sharing
We disclose personal data to third parties only if this is described in this Privacy Policy, is legally permitted, or you have given your consent.
Recipients of personal data may include, in particular, the following service providers:
Framer
Brevo
Lime Connect
In addition, IT and hosting service providers, support service providers or authorities may receive personal data insofar as this is necessary for the operation of the website or due to legal obligations.
Legal requirements
We may use or disclose your personal data in order to comply with a legal obligation in connection with a request from a public authority or government body, or in connection with legal proceedings, in order to prevent injury or death, or to protect our rights or property.
Where legally permissible and practically feasible, we will inform affected individuals before such disclosure.
Service providers and other third parties
We may use external service providers, processors or technical partners to provide and improve the operation of our website, our communication services and our support services. We may disclose personal data to technical service providers, hosting providers, communication services, email service providers and providers of backup and security solutions insofar as this is necessary for the operation and improvement of our website and our communication services. If you require further information about the recipients of your personal data, please contact us at info@ecaia.it or via the contact details published in the legal notice. Insofar as external service providers process personal data on our behalf, data processing agreements pursuant to Art. 28 GDPR have been concluded with them.
3. Cookies
What are cookies?
Cookies are small files that are stored by a website on a user’s device. They may be used to provide certain functions of the website or to store user settings.
How we use cookies
We use exclusively technically necessary cookies and preference cookies that are required to provide the website and store your selections.
The website currently does not use analytics, statistics or marketing cookies. Should such technologies be used in the future, this will take place exclusively after the prior consent of the affected users.
How you can manage cookies
You can configure your browser so that cookies are blocked, restricted or deleted. Please note that this may impair individual functions of the website.
4. Retention and deletion
We store personal data only for as long as necessary for the respective processing purposes or as required by statutory retention obligations. Contact inquiries are generally stored for up to 24 months insofar as this is necessary for handling follow-up questions, documenting communications or safeguarding legitimate interests. Server log files are regularly deleted or anonymised. When personal data is no longer required for the purposes for which it was collected and no statutory retention obligations prevent this, it is deleted or anonymised.
5. Merger or acquisition
If we are involved in a merger, acquisition or sale of assets, your personal data may be transferred. We will inform you of this, insofar as legally required or permitted, before your personal data becomes subject to another privacy policy. Under certain circumstances, we may be required to disclose your personal data where this is required by law or pursuant to lawful requests from competent courts, authorities or other public bodies.
6. How we protect your data
We have appropriate technical and organisational measures in place to protect your personal data against accidental loss, unauthorised use, unauthorised access, alteration or disclosure. Communication between your browser and our website takes place via a secure, encrypted connection when your personal data is involved.
We require every third party commissioned to process your personal data on our behalf to take security measures to protect your data and to handle such data in accordance with the law.
In the event of a personal data breach, we will notify affected individuals and the competent supervisory authorities insofar as required under applicable data protection laws.
7. Children’s privacy
We do not knowingly collect personal data from children under the age of 16.
8. Your rights regarding your personal data
Your rights are governed by the applicable data protection laws, in particular the General Data Protection Regulation (GDPR), as well as, where applicable, other relevant data protection provisions. These rights may include:
Right of access (GDPR Article 15)
You have the right to know whether we process your personal data, and you have the right to request a copy of the personal data that we process about you.
Right to rectification (GDPR Article 16)
You have the right to have incomplete or inaccurate personal data that we process about you corrected.
Right to erasure (GDPR Article 17)
You have the right to request that we delete personal data that we process about you, unless we are required to retain this data in order to comply with a legal obligation or to establish, exercise or defend legal claims.
Right to restriction of processing (GDPR Article 18)
You have the right to restrict our processing of your personal data under certain circumstances. In this case, we will process your data for no purpose other than storage.
Right to data portability (GDPR Article 20)
You have the right to receive the personal data that we hold about you in a structured electronic format and to transfer such data to another controller where (a) it concerns personal data that you have provided to us and (b) we process this data on the basis of your consent or in order to perform a contract with you or a third party using the services.
Right to object (GDPR Article 21)
Where the legal basis for our processing of your personal data is our legitimate interest, you have the right to object to such processing on grounds relating to your particular situation. We will comply with your request unless we have compelling legitimate grounds for the processing that override your interests and rights, or unless we need to continue processing the personal data in order to establish, exercise or defend legal claims.
Right to lodge a complaint (GDPR Article 77)
You have the right to lodge a complaint with the data protection authority responsible for you.
If you are resident in the EEA, please visit this website for a list of local data protection authorities:
https://edpb.europa.eu/about-edpb/about-edpb/members_de
You may additionally contact the competent Italian data protection supervisory authority:
Garante per la Protezione dei Dati Personali
Piazza Venezia 11
00187 Roma
Insofar as the Swiss Data Protection Act (revFADP) applies, affected individuals additionally have the rights of access, rectification and other data protection claims provided for therein.
Withdrawing consent
If you have given your consent to the processing of your personal data, you have the right to withdraw your consent at any time free of charge. This applies, for example, to processing based on your consent, such as the use of certain optional cookies or contacting you via voluntarily provided communication channels.
If you wish to withdraw your consent, please contact us at info@ecaia.it or via the contact details published in the legal notice.
How you can exercise your rights
You can submit a request to exercise your data protection rights by contacting us at info@ecaia.it or via the contact details published in the legal notice.
To ensure the protection and security of your data, we may, at our discretion, require you to verify your identity before we provide the requested information.
There is no decision-making based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR.
9. Changes
We may amend this Policy at any time. If we make changes to this Policy, we will publish an updated version of this Policy on this website. We recommend that you review this Privacy Policy regularly in order to stay informed about any changes. Changes to this Privacy Policy will be published on this website.
10. Contact
If you have questions about data protection or wish to exercise your rights as a data subject, you can contact us at any time.
To contact us, please send an email to info@ecaia.it.
Write to us at:
SANUSLIFE International GmbH
Alte Tierserstrasse 18, 39053 Karneid (BZ), Italy, South Tyrol
Competent data protection supervisory authority:
Garante per la Protezione dei Dati Personali
Piazza Venezia 11
00187 Roma
For affected individuals in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC) may also be responsible:
Last updated: 31.08.2026
SANUSLIFE International GmbH Privacy Policy
1. Introduction
For SANUSLIFE International GmbH, operator of the website ecaia.it (“us”, “we”, “our company”), the protection and safeguarding of your data are important. This Privacy Policy (“Privacy Policy”) explains our data protection practices for the activities listed below. As is your right, we inform you about how we collect, store, access and otherwise process data relating to individuals. In this Policy, “personal data” means any information by which a person can be identified, either alone or in combination with other available information.
The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is:
SANUSLIFE International GmbH
Alte Tierserstraße 18
39053 Karneid (BZ), Italy
Email: info@ecaia.it
We are committed to protecting your privacy in accordance with the most comprehensive data protection regulations. We therefore comply with the obligations arising from the following provisions:
the EU General Data Protection Regulation (GDPR)
the Swiss Federal Act on Data Protection (revFADP/FADP)
Scope
This Policy applies to the website ecaia.it as well as to the content and services offered through it by SANUSLIFE International GmbH.
This Policy does not apply to third-party applications, websites, products, services or platforms that can be accessed via links (not SANUSLIFE International GmbH links) that we make available to you. Such websites are operated independently of us and are not owned by us. They have their own data protection and data collection practices. Personal data that you provide to these websites is subject to the privacy policy of the respective third party. We cannot accept any liability for the actions or policies of these independent websites and are not responsible for the content or data protection practices of such sites.
Processing activities
This Policy applies when you interact with us through any of the following activities:
When you visit one of our websites that is linked to this Privacy Policy.
This Privacy Policy was created with the support of Enzuzo’s privacy tool and adapted to the actual processing operations of the website.
2. Personal data we collect
The personal data we collect
When you communicate with us via contact forms, email or the communication widget, we may process personal data that you voluntarily provide to us. This includes, in particular, the contact details entered in the respective form (e.g. name and email address) as well as the content of your inquiry.
When you use the functions of our website or contact us, we process the following types of personal data:
Name and email address, if you contact us.
Message content and support requests.
Feedback, e.g. customer support or product reviews
Product-related inquiries and information that you voluntarily provide to us.
Content, e.g. posts, comments, audio or documents
How we collect your personal data
We collect personal data from the following sources:
From you. You may provide us with information such as your name, email address, message content, feedback and product-related inquiries by completing forms, using our website as well as our products or services, entering information online, or corresponding with us by post, email or other means.
This also includes personal data that you provide to us, for example, when you:
use our products or services;
create content about our products or services;
express interest in our products or services;
contact us if you have an inquiry or wish to report a problem (by telephone, email, social media or a messaging service);
Automated technologies or interactions: When you interact with our website, we may automatically collect the following types of data (all as described above): device data about your equipment, usage data about your browsing activities and patterns, as well as contact data if tasks that you performed via our website remain incomplete. We collect this data using cookies, server logs and other similar technologies. Further details can be found in the section on cookies below.
Third-party providers: We may receive personal data about you from various third-party providers, including:
content from communication services, including email providers and social networks, if you give us permission to access your data held by such third-party services or networks;
information from technical service providers, hosting providers and communication services, insofar as this is necessary for the operation of the website.
If you provide us or our service providers with personal data relating to other individuals, you thereby declare that you are authorised to do so and acknowledge that such data will be used in accordance with this Policy. If you believe that we have obtained your personal data improperly, or if you otherwise wish to exercise your rights regarding your personal data, please contact us using the information provided in the “Contact” section below.
Device and usage data
When you visit a SANUSLIFE International GmbH website, we automatically collect and store information about your visit using browser cookies (files sent by us to your computer) or similar technology. You can configure your browser to reject all cookies or to indicate when a cookie is being sent. The help function of most browsers provides information on how to accept or disable cookies or enable notifications about incoming new cookies. If you do not accept cookies, some features of our service may not be usable. We recommend that you leave them enabled.
We also process information when you use our website or interact with our contact and support functions.
This information may include:
IP address
Date and time of access
Browser type and browser version
Operating system
Referrer URL
Pages and content accessed
Other technical connection and usage data
This data is processed to ensure the security, stability and functionality of the website. The legal basis is Art. 6(1)(f) GDPR.
Data we collect from third parties
We may receive your personal data from third parties, in particular from technical service providers, communication services or business partners, insofar as this is necessary for the operation of the website. This personal data is not collected by us but by third parties and is subject to the data protection and data collection policy of the respective third party. Insofar as personal data is processed directly by third-party providers, their respective data protection provisions apply. We have no influence over specific data processing carried out outside our area of responsibility. As always, you have the right to review and correct this information. If you have any questions, you should first contact the relevant third party to obtain further information about your personal data. If you have questions about the processing of your personal data or wish to exercise your data protection rights, please contact SANUSLIFE International GmbH at info@ecaia.it or via the contact details published in the website’s legal notice.
Links to third-party providers
Our websites and services may contain links to other websites and services operated by third parties. The data protection practices of such other services, or of social media networks that host our brand’s pages on social media, are subject to the privacy policies of third parties. You should read these policies to better understand the data protection practices of such third parties.
Purpose and legal basis for the processing of personal data
We collect and use personal data in order to provide, maintain and further develop our website as well as our contact and support services.
The purposes include:
providing information about our products and services
creating a secure environment
investigating and preventing security incidents such as breaches, attacks and hacks
delivering, developing and improving our website as well as the content and services offered
delivering, maintaining, troubleshooting and improving our website
providing technical and customer support
communicating with you about the products and services
Contact form and chat function
When you use the contact form or chat function provided on our website, we process the personal data you provide solely for the purpose of handling your inquiry, communicating with you and technically providing and documenting the inquiry.
The legal basis is Art. 6(1)(b) GDPR, insofar as the inquiry is aimed at entering into or performing a contract or taking pre-contractual measures, as well as Art. 6(1)(f) GDPR on the basis of our legitimate interest in efficiently handling inquiries and providing customer service.
We process personal data exclusively on the basis of the applicable legal grounds.
Insofar as processing is based on our legitimate interests, this is carried out in particular to ensure the security of our website, handle inquiries, improve our content and services, and prevent misuse and security incidents. Insofar as processing is based on your consent, such consent is obtained prior to the respective processing. If processing activities are materially changed and consent is required for this purpose, affected individuals will be informed accordingly and, where applicable, asked to provide their consent again. If certain functions or services require your consent, failure to provide or withdrawal of such consent may result in individual functions being available only to a limited extent or not at all.
The processing of personal data is carried out in particular on the following legal bases:
Art. 6(1)(b) GDPR for handling inquiries and carrying out pre-contractual measures;
Art. 6(1)(c) GDPR for compliance with legal obligations;
Art. 6(1)(f) GDPR on the basis of our legitimate interests in the secure operation of the website, the handling of inquiries and the prevention of misuse and security incidents;
Art. 6(1)(a) GDPR, insofar as you have consented to certain processing activities (e.g. optional cookies).
Third-party tools
We use the following third-party services for the operation of our website, communication with visitors, and the processing and storage of personal data:
Brevo: processing and management of incoming communications as well as provision of email communication, insofar as necessary for handling inquiries.
Framer: technical provision, hosting and delivery of the website, including the processing of technically necessary connection and server data.
Lime Connect: provision of communication and contact functions, processing of contact inquiries, and management of customer communication processes, insofar as used on this website.
Cloudflare: security, performance and protection measures against misuse and automated access.
Further information on data processing by these providers can be found in their respective privacy notices.
International data transfers
Some of the service providers we use may process personal data in countries outside the European Economic Area (EEA) or access data from such countries.
Where personal data is transferred to third countries, such transfer takes place exclusively in compliance with the requirements of Art. 44 et seq. GDPR. Where there is no adequacy decision by the European Commission, we base the transfer on the Standard Contractual Clauses (SCCs) approved by the European Commission or other legally permissible safeguards.
Further information about the service providers used and the applicable safeguards can be requested at info@ecaia.it.
This also applies to the use of sub-processors by our service providers. Where personal data is processed outside the European Economic Area in this context, this takes place exclusively on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR.
Disclosure and sharing
We disclose personal data to third parties only if this is described in this Privacy Policy, is legally permitted, or you have given your consent.
Recipients of personal data may include, in particular, the following service providers:
Framer
Brevo
Lime Connect
In addition, IT and hosting service providers, support service providers or authorities may receive personal data insofar as this is necessary for the operation of the website or due to legal obligations.
Legal requirements
We may use or disclose your personal data in order to comply with a legal obligation in connection with a request from a public authority or government body, or in connection with legal proceedings, in order to prevent injury or death, or to protect our rights or property.
Where legally permissible and practically feasible, we will inform affected individuals before such disclosure.
Service providers and other third parties
We may use external service providers, processors or technical partners to provide and improve the operation of our website, our communication services and our support services. We may disclose personal data to technical service providers, hosting providers, communication services, email service providers and providers of backup and security solutions insofar as this is necessary for the operation and improvement of our website and our communication services. If you require further information about the recipients of your personal data, please contact us at info@ecaia.it or via the contact details published in the legal notice. Insofar as external service providers process personal data on our behalf, data processing agreements pursuant to Art. 28 GDPR have been concluded with them.
3. Cookies
What are cookies?
Cookies are small files that are stored by a website on a user’s device. They may be used to provide certain functions of the website or to store user settings.
How we use cookies
We use exclusively technically necessary cookies and preference cookies that are required to provide the website and store your selections.
The website currently does not use analytics, statistics or marketing cookies. Should such technologies be used in the future, this will take place exclusively after the prior consent of the affected users.
How you can manage cookies
You can configure your browser so that cookies are blocked, restricted or deleted. Please note that this may impair individual functions of the website.
4. Retention and deletion
We store personal data only for as long as necessary for the respective processing purposes or as required by statutory retention obligations. Contact inquiries are generally stored for up to 24 months insofar as this is necessary for handling follow-up questions, documenting communications or safeguarding legitimate interests. Server log files are regularly deleted or anonymised. When personal data is no longer required for the purposes for which it was collected and no statutory retention obligations prevent this, it is deleted or anonymised.
5. Merger or acquisition
If we are involved in a merger, acquisition or sale of assets, your personal data may be transferred. We will inform you of this, insofar as legally required or permitted, before your personal data becomes subject to another privacy policy. Under certain circumstances, we may be required to disclose your personal data where this is required by law or pursuant to lawful requests from competent courts, authorities or other public bodies.
6. How we protect your data
We have appropriate technical and organisational measures in place to protect your personal data against accidental loss, unauthorised use, unauthorised access, alteration or disclosure. Communication between your browser and our website takes place via a secure, encrypted connection when your personal data is involved.
We require every third party commissioned to process your personal data on our behalf to take security measures to protect your data and to handle such data in accordance with the law.
In the event of a personal data breach, we will notify affected individuals and the competent supervisory authorities insofar as required under applicable data protection laws.
7. Children’s privacy
We do not knowingly collect personal data from children under the age of 16.
8. Your rights regarding your personal data
Your rights are governed by the applicable data protection laws, in particular the General Data Protection Regulation (GDPR), as well as, where applicable, other relevant data protection provisions. These rights may include:
Right of access (GDPR Article 15)
You have the right to know whether we process your personal data, and you have the right to request a copy of the personal data that we process about you.
Right to rectification (GDPR Article 16)
You have the right to have incomplete or inaccurate personal data that we process about you corrected.
Right to erasure (GDPR Article 17)
You have the right to request that we delete personal data that we process about you, unless we are required to retain this data in order to comply with a legal obligation or to establish, exercise or defend legal claims.
Right to restriction of processing (GDPR Article 18)
You have the right to restrict our processing of your personal data under certain circumstances. In this case, we will process your data for no purpose other than storage.
Right to data portability (GDPR Article 20)
You have the right to receive the personal data that we hold about you in a structured electronic format and to transfer such data to another controller where (a) it concerns personal data that you have provided to us and (b) we process this data on the basis of your consent or in order to perform a contract with you or a third party using the services.
Right to object (GDPR Article 21)
Where the legal basis for our processing of your personal data is our legitimate interest, you have the right to object to such processing on grounds relating to your particular situation. We will comply with your request unless we have compelling legitimate grounds for the processing that override your interests and rights, or unless we need to continue processing the personal data in order to establish, exercise or defend legal claims.
Right to lodge a complaint (GDPR Article 77)
You have the right to lodge a complaint with the data protection authority responsible for you.
If you are resident in the EEA, please visit this website for a list of local data protection authorities:
https://edpb.europa.eu/about-edpb/about-edpb/members_de
You may additionally contact the competent Italian data protection supervisory authority:
Garante per la Protezione dei Dati Personali
Piazza Venezia 11
00187 Roma
Insofar as the Swiss Data Protection Act (revFADP) applies, affected individuals additionally have the rights of access, rectification and other data protection claims provided for therein.
Withdrawing consent
If you have given your consent to the processing of your personal data, you have the right to withdraw your consent at any time free of charge. This applies, for example, to processing based on your consent, such as the use of certain optional cookies or contacting you via voluntarily provided communication channels.
If you wish to withdraw your consent, please contact us at info@ecaia.it or via the contact details published in the legal notice.
How you can exercise your rights
You can submit a request to exercise your data protection rights by contacting us at info@ecaia.it or via the contact details published in the legal notice.
To ensure the protection and security of your data, we may, at our discretion, require you to verify your identity before we provide the requested information.
There is no decision-making based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR.
9. Changes
We may amend this Policy at any time. If we make changes to this Policy, we will publish an updated version of this Policy on this website. We recommend that you review this Privacy Policy regularly in order to stay informed about any changes. Changes to this Privacy Policy will be published on this website.
10. Contact
If you have questions about data protection or wish to exercise your rights as a data subject, you can contact us at any time.
To contact us, please send an email to info@ecaia.it.
Write to us at:
SANUSLIFE International GmbH
Alte Tierserstrasse 18, 39053 Karneid (BZ), Italy, South Tyrol
Competent data protection supervisory authority:
Garante per la Protezione dei Dati Personali
Piazza Venezia 11
00187 Roma
For affected individuals in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC) may also be responsible:
Last updated: 31.08.2026