HFbioVR Human Flow
Health Tech
Technology Products Contact
IT EN ES

Privacy Policy

Version 1.0 Last updated 2026-06-09 pursuant to art. 13 GDPR (EU Reg. 2016/679)

Index

  1. Data Controller
  2. Personal data collected
  3. Purposes of processing and legal bases
  4. Special provision — Wellness packages and future medical devices
  5. Data retention
  6. Recipients and extra-EU transfers
  7. Rights of the data subject (art. 15-22 GDPR)
  8. Cookies and tracking technologies
  9. Complaints to the Supervisory Authority
  10. Changes to this Policy

1Data Controller

The Data Controller for personal data processing pursuant to art. 4, par. 7 of EU Regulation 2016/679 (hereinafter "GDPR") is:

Legal entityHuman Flow Health Technology SRLS
Registered officeVia Monsignor Giuseppe Bolla, 14036 Moncalvo (AT), Italia
VAT number / Tax code01782670051
REA numberREA: to be added after registration with Business Registry
Certified email (PEC)boido.ermete@pec.it
Phone+39 340 3838609
Privacy contact emailprivacy@humanflowhealthtech.com

Data Protection Officer (DPO). The Controller has not, at present, appointed a DPO pursuant to art. 37 GDPR, as the activities do not fall among those mandatorily requiring such appointment (systematic large-scale monitoring of data subjects or large-scale processing of special categories of data). For any request relating to the processing of personal data, the Controller may be contacted at the addresses indicated above.

2Personal data collected

In providing its HFbioVR services (virtual reality brain training platform, Cognitive wellness packages and — in the future, post-certification — Psychological and Functional packages as medical devices), the Controller collects and processes various types of personal data, described below.

2.1 Data collected through the public contact form

When the user fills out the "Request demo / activation" form on public pages (catalog, demo, contact), the following are collected:

  • name of the clinic / practice / center
  • contact's first and last name
  • professional email address
  • phone number (optional)
  • city of practice (optional)
  • type of facility
  • free notes and clinical needs (optional)
  • consent to processing and marketing

2.2 Customer registration data (clinic account)

When a clinic / center / practice subscribes to an HFbioVR package and creates its own administration account, the following are collected:

  • login email and password (stored in encrypted form via one-way hash function)
  • administrator's first and last name
  • phone number
  • clinic's legal name, VAT, address
  • billing data (SDI recipient code or PEC)

2.3 Data of service users (therapists and end users)

The clinic customer's administrator may create profiles for their operators (therapists) and end users. For each profile, the following are collected:

  • email and password (for operators; password in encrypted form)
  • first and last name
  • role (operator, end user)

In such cases, the Controller acts as a Processor on behalf of the clinic customer, who is the autonomous Controller for the data of its own end users.

2.4 Session data and performance metrics

During VR exercises, the system records experience performance data: reaction times, response percentages, session durations, selected level, paradigm execution parameters. Such data is associated with the user profile via internal identifier.

For Cognitive packages (wellness / brain training), these metrics represent behavioral performance data and do not constitute health-related data within the meaning of art. 9, par. 1 GDPR. See section 4 for the special provision.

2.5 Payment data

The Controller does not store payment card data. The entire payment process is managed through the provider Stripe (Stripe Payments Europe Limited and Stripe, Inc.), which operates in compliance with PCI-DSS standards. The Controller receives from Stripe only the transaction outcome and the billing data strictly necessary for the issuance of the fiscal document.

2.6 Technical navigation data and logs

The Controller's IT systems and those of its hosting providers automatically collect some technical data as part of the normal operation of web services:

  • device IP address
  • browser type and operating system
  • date and time of access
  • pages visited and actions performed
  • technical session identifier

3Purposes of processing and legal bases

Personal data is processed for the following purposes, each based on a specific legal basis pursuant to art. 6 (and art. 9 where applicable) of the GDPR:

Purpose Legal basis
Provision of services (platform access, exercises, monitoring dashboard) Performance of a contract to which the data subject is a party, or implementation of pre-contractual measures (art. 6.1.b GDPR)
Administrative and accounting management, invoicing, tax obligations Legal obligation (art. 6.1.c GDPR) and Italian tax regulations
Response to information and demo requests coming from public forms Consent of the data subject (art. 6.1.a GDPR) and legitimate interest in commercial follow-up
Transactional communications (registration confirmations, payment confirmations, deadlines) Performance of the contract (art. 6.1.b GDPR)
Sending commercial communications, newsletters, product updates Explicit and revocable consent of the data subject (art. 6.1.a GDPR)
IT security, abuse and fraud prevention, technical logs Legitimate interest of the Controller (art. 6.1.f GDPR)
Anonymous and product analytics (aggregated statistics on exercise usage) Legitimate interest of the Controller in service improvement (art. 6.1.f GDPR)

Provision of data. The provision of data for the purposes of contractual performance and legal compliance is necessary: any refusal to provide them makes it impossible to provide the service. The provision for marketing and commercial communication purposes is optional, and consent is revocable at any time.

4Special provision — Wellness packages and future medical devices

🧠 Cognitive packages (currently available) — Brain training tools

The Cognitive packages of HFbioVR, currently available, are cognitive enhancement and mental wellbeing tools (virtual reality brain training). They are not medical devices within the meaning of EU Regulation 2017/745 and subsequent amendments, they are not intended for the diagnosis, screening or treatment of any clinical condition, and they do not in any way replace the assessment, diagnosis or intervention of qualified healthcare professionals.

Consequently, the performance metrics collected during the use of Cognitive packages (reaction times, accuracy, percentage of correct responses, session durations, completed levels) constitute behavioral performance data within the context of a brain training experience, and do not constitute health-related data within the meaning of art. 4, par. 15 and art. 9, par. 1 GDPR.

Such data is processed on the legal basis of consent or contractual performance (see section 3) and not on the legal basis of special categories of data referred to in art. 9 GDPR.

Psychological, Functional and Mega Suite packages — Future provision

The Psychological, Functional and Mega Suite packages are currently awaiting CE certification as medical devices pursuant to EU Regulation 2017/745 (MDR). Until certification is granted, such packages cannot be used in a clinical-rehabilitation context and are not accessible through the commercial catalog.

Upon the issuance of CE MDR certification, this privacy policy will be updated to include:

  • the processing of health-related data of end users in the context of rehabilitation activities
  • the specific legal basis pursuant to art. 9, par. 2 GDPR (for example: letter h, purposes of medical diagnosis, healthcare assistance or therapy, by or under the responsibility of a professional bound by professional secrecy)
  • enhanced security measures for special categories of data
  • specific retention periods established for clinical data
  • the role of the Controller as medical device provider and the consequent vigilance obligations

Users of CE-certified packages will be expressly informed and will need to provide specific consent, distinct from that required for today's wellness services.

5Data retention

The Controller retains personal data only for the time necessary to pursue the purposes for which it was collected, and in any case for the time required by law.

Data category Retention period
Lead data collected from public forms (demo / information requests) 24 months from the date of request, unless converted to a customer
Registration and account data of customers (clinic / center) For the entire duration of the contractual relationship and for 12 months after termination
End user profile data For the entire duration of the clinic customer's relationship, until a request for cancellation by the Data Controller (the clinic)
Session data and performance metrics For the entire duration of the relationship and for 12 months after termination
Technical access and navigation logs 12 months from collection
Accounting documentation and invoices 10 years, as required by Italian tax legislation (art. 2220 Civil Code)
Consent and marketing preferences data For the entire validity period of consent, until revocation, and for 5 years thereafter for evidentiary purposes

6Recipients and extra-EU transfers

Personal data may be communicated to the following categories of recipients, each of whom acts as a Processor pursuant to art. 28 GDPR (with appropriate agreement) or as an autonomous Controller:

Recipient Role / purpose
Aruba S.p.A. (Italy) Web infrastructure and database hosting (Processor)
Stripe Payments Europe Limited (Ireland) and Stripe, Inc. (USA) Processing of electronic payments (autonomous Controller for payment data, Processor for billing metadata)
Meta Platforms, Inc. (USA) Distribution of the VR application through Meta Horizon Store / App Lab; minimal technical installation data and crash reporting
Transactional email and CRM providers (potential, in the future) Sending transactional emails and managing the customer relationship (Processors)
Professional consultants, accountant, lawyers Tax, accounting, legal compliance (Processors or autonomous Controllers depending on the case)
Judicial, tax and public security authorities Compliance with legal obligations or with Authority orders

Extra-EU transfers

The processing of some data may involve transfer outside the European Economic Area, in particular to the United States of America (Stripe, Meta). Such transfers take place in compliance with art. 46 GDPR, through the adoption of Standard Contractual Clauses approved by the European Commission and — where applicable — based on the EU-US Data Privacy Framework adequacy decision for participating recipients.

The data subject may request a copy of the guarantees adopted at the Controller's contact details.

7Rights of the data subject

The data subject has, at all times, the rights provided by arts. 15-22 of the GDPR:

  • Right of access (art. 15) — obtain confirmation of the existence of processing and access to the data
  • Right to rectification (art. 16) — request correction of inaccurate data or completion of incomplete data
  • Right to erasure (art. 17) — the "right to be forgotten", within the limits provided by law
  • Right to restriction (art. 18) — request temporary suspension of processing
  • Right to data portability (art. 20) — receive your data in a structured, commonly used and machine-readable format
  • Right to object (art. 21) — object to processing for reasons related to your personal situation, in particular for marketing purposes
  • Right not to be subject to automated decisions (art. 22), including profiling, except in cases provided for by the GDPR
  • Right to withdraw consent at any time, without prejudice to the lawfulness of processing based on consent given before withdrawal

How to exercise your rights

To exercise one or more of the rights listed above, the data subject may write to the email address privacy@humanflowhealthtech.com, attaching a copy of a valid identity document to allow verification of the requester's identity. The Controller will respond within 30 days of receipt of the request, except for the right to extend this term by up to a further 60 days in case of particularly complex requests, notifying the data subject.

8Cookies and tracking technologies

The website uses exclusively technical cookies essential for the operation of services. At present, the website does not use profiling cookies nor third-party cookies intended for behavioral advertising.

Cookie Purpose Duration
HASTA_SESSID Technical session cookie required to maintain authentication Duration of the browsing session
hf_lang (localStorage) Storage of the user's language preference Persistent

As these are exclusively technical cookies, a consent banner is not required under currently applicable regulations. Should the Controller introduce in the future profiling cookies or third-party analytics, the user will be informed through a specific Cookie Policy and prior consent will be requested.

9Complaints to the Supervisory Authority

Without prejudice to any other administrative or judicial action, the data subject who believes that the processing of their personal data violates the provisions of the GDPR has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali):

  • Piazza Venezia, 11 — 00187 Rome, Italy
  • Switchboard: +39 06 696771
  • Email: protocollo@gpdp.it
  • Website: www.garanteprivacy.it

10Changes to this Policy

The Controller reserves the right to modify, integrate or update this Privacy Policy as a result of regulatory developments or changes in the processing operations performed. The current version is always published on this page with indication of the last update date (see header of the document).

In case of substantial changes — in particular upon the issuance of CE MDR certification for the Psychological / Functional packages and the consequent processing of health-related data — the Controller will inform registered data subjects via email to the address provided at the time of registration.

For requests or clarifications regarding this Policy, please write to privacy@humanflowhealthtech.com.

© 2026 Human Flow Health Technology SRLS. Human Flow Health Technology SRLS. All rights reserved.
Home · Catalogo · Terms