Privacy notice
Effective from 11 September 2026 · Version 1.0
This notice explains what data we collect through the softwareldv.com website and the LDV Software applications, why we process it, who we share it with and what rights the people concerned have. It is drawn up under articles 13 and 14 of Regulation (EU) 2016/679 («GDPR»).
The supplier
LDV Consulting FZCO
IFZA Properties, DSO-IFZA, Dubai Silicon Oasis, Dubai 342001, United Arab Emirates
Tax Registration Number (TRN): 104336951900003
Email: ldvconsulting360@gmail.com · Phone: +39 331 392 5773
Trading name: «LDV Software» · Website: softwareldv.com
Products: «Dr. Coro»
1. Controller and representative
The controller for data relating to customer accounts, the website and invoicing is LDV Consulting FZCO, at the contact details above. Representative in the European Union under art. 27 GDPR: to be appointed — required for a controller established outside the EU that offers services to people in the EU. For any request concerning personal data write to ldvconsulting360@gmail.com.
2. Two distinct roles
- Customer data (sign-up, use of the application, invoicing): we are the controller.
- Data collected through invitations to patients in Dr. Coro: the practice is the controller and we act as processor on its behalf, following the instructions set out in the Terms and in an art. 28 GDPR agreement provided on request.
3. What data we process
| Category | Data | Source |
|---|---|---|
| Customer account | Practice or business name, email address, password (stored only in hashed form by the authentication provider), role, public link to the Google listing | Provided by the customer |
| Service usage | Invitation identifier, visit type, dates and times, invitation status, keys of the questions drawn, positions chosen on the scales (numbers 1 to 5), outcome of the automatic check | Generated by use |
| Invoicing | Company name, address, tax identifier, last four digits and expiry of the card, payment history | Collected and stored by Stripe; we process only the customer identifier and the subscription status |
| Technical data | IP address, device and browser type, technical error logs | Collected automatically by the infrastructure |
4. What we never store
These are design choices in our applications, not configurable settings:
- The patient's phone number never enters our systems. The invitation is sent from the messaging application installed on the practice's phone, which opens its own contact picker.
- The text written by the patient is never saved. It is received, used to compose the text, returned to the patient's browser and discarded: it does not reach the database, the technical logs or error-monitoring systems.
- The composed review text is not saved.
- The reviews pasted in by the customer and the suggested replies are not saved.
- We do not collect health data about patients.
5. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the service, managing access and support | Performance of the contract (art. 6.1.b GDPR) |
| Managing subscriptions, payments and invoices | Contract and legal obligations (arts. 6.1.b and 6.1.c) |
| Security, abuse prevention, technical logs | Legitimate interest in a secure service (art. 6.1.f) |
| Aggregate statistics on usage and text quality | Legitimate interest in improving the service (art. 6.1.f) |
| Service emails to the customer | Performance of the contract (art. 6.1.b) |
Patients' answers are processed on behalf of the practice, on the basis of the practice's legitimate interest in collecting the opinion of those who received the service; participation is voluntary and the patient may simply not answer.
6. How long we keep it
- Account data: for the duration of the subscription and for 12 months after closure, then deleted or anonymised.
- Usage data and statistics: 24 months.
- Technical logs: 30 days.
- Tax and payment records: for the period required by applicable law.
- Free text, reviews and replies: not retained at all, as set out in point 4.
7. Who we share data with
We do not sell personal data and do not pass it on for third-party marketing. We use the following providers, appointed as processors:
| Provider | Function | Where |
|---|---|---|
| Supabase | Database and authentication | European Union (Ireland) |
| Vercel | Application hosting | European Union (Ireland) · US company |
| Anthropic | Automated text processing. It receives the content only for the duration of the request; it is not used to train models | United States |
| Stripe | Payments, subscriptions and invoices | Ireland · United States |
| Resend | Sending service emails | European Union |
| Reading the public review count and average rating of the customer's listing | European Union · United States |
Transfers to third countries take place on the basis of the standard contractual clauses approved by the European Commission or other appropriate safeguards under Chapter V of the GDPR. A copy of the safeguards can be requested at the contact details above.
8. Cookies and similar technologies
This website uses no profiling cookies, hosts no third-party analytics and does not track visitors: that is why you are shown no consent banner. The customer applications use only technical cookies needed to keep you signed in: without them authentication does not work, and they require no consent.
9. Security
Traffic is encrypted with HTTPS. Passwords are handled by the authentication provider and are not visible to us. Access to the database is restricted and protected by row-level security rules. Card details never pass through our systems: they are entered directly on Stripe pages, which operates to the PCI DSS standard.
10. Your rights
You may ask us at any time for access to your data, rectification, erasure, restriction of processing, portability, and you may object to processing based on legitimate interest (arts. 15–22 GDPR). Write to ldvconsulting360@gmail.com: we reply within one month. If you believe the processing breaches the law you may lodge a complaint with the supervisory authority of your country — in Italy the Garante per la protezione dei dati personali (garanteprivacy.it).
If you are a patient who received an invitation from a practice and wish to exercise your rights, please contact the practice first, as it is the controller: we assist it for our part.
11. Changes
If we update this notice we publish the new version on this page with its effective date; material changes are notified to customers by email.