LDV LDV Software

Privacy notice

Effective from 11 September 2026 · Version 1.0

This notice explains what data we collect through the softwareldv.com website and the LDV Software applications, why we process it, who we share it with and what rights the people concerned have. It is drawn up under articles 13 and 14 of Regulation (EU) 2016/679 («GDPR»).

The supplier

LDV Consulting FZCO

IFZA Properties, DSO-IFZA, Dubai Silicon Oasis, Dubai 342001, United Arab Emirates

Tax Registration Number (TRN): 104336951900003

Email: ldvconsulting360@gmail.com · Phone: +39 331 392 5773

Trading name: «LDV Software» · Website: softwareldv.com

Products: «Dr. Coro»

1. Controller and representative

The controller for data relating to customer accounts, the website and invoicing is LDV Consulting FZCO, at the contact details above. Representative in the European Union under art. 27 GDPR: to be appointed — required for a controller established outside the EU that offers services to people in the EU. For any request concerning personal data write to ldvconsulting360@gmail.com.

2. Two distinct roles

3. What data we process

Category Data Source
Customer account Practice or business name, email address, password (stored only in hashed form by the authentication provider), role, public link to the Google listing Provided by the customer
Service usage Invitation identifier, visit type, dates and times, invitation status, keys of the questions drawn, positions chosen on the scales (numbers 1 to 5), outcome of the automatic check Generated by use
Invoicing Company name, address, tax identifier, last four digits and expiry of the card, payment history Collected and stored by Stripe; we process only the customer identifier and the subscription status
Technical data IP address, device and browser type, technical error logs Collected automatically by the infrastructure

4. What we never store

These are design choices in our applications, not configurable settings:

5. Purposes and legal bases

Purpose Legal basis
Providing the service, managing access and support Performance of the contract (art. 6.1.b GDPR)
Managing subscriptions, payments and invoices Contract and legal obligations (arts. 6.1.b and 6.1.c)
Security, abuse prevention, technical logs Legitimate interest in a secure service (art. 6.1.f)
Aggregate statistics on usage and text quality Legitimate interest in improving the service (art. 6.1.f)
Service emails to the customer Performance of the contract (art. 6.1.b)

Patients' answers are processed on behalf of the practice, on the basis of the practice's legitimate interest in collecting the opinion of those who received the service; participation is voluntary and the patient may simply not answer.

6. How long we keep it

7. Who we share data with

We do not sell personal data and do not pass it on for third-party marketing. We use the following providers, appointed as processors:

Provider Function Where
Supabase Database and authentication European Union (Ireland)
Vercel Application hosting European Union (Ireland) · US company
Anthropic Automated text processing. It receives the content only for the duration of the request; it is not used to train models United States
Stripe Payments, subscriptions and invoices Ireland · United States
Resend Sending service emails European Union
Google Reading the public review count and average rating of the customer's listing European Union · United States

Transfers to third countries take place on the basis of the standard contractual clauses approved by the European Commission or other appropriate safeguards under Chapter V of the GDPR. A copy of the safeguards can be requested at the contact details above.

8. Cookies and similar technologies

This website uses no profiling cookies, hosts no third-party analytics and does not track visitors: that is why you are shown no consent banner. The customer applications use only technical cookies needed to keep you signed in: without them authentication does not work, and they require no consent.

9. Security

Traffic is encrypted with HTTPS. Passwords are handled by the authentication provider and are not visible to us. Access to the database is restricted and protected by row-level security rules. Card details never pass through our systems: they are entered directly on Stripe pages, which operates to the PCI DSS standard.

10. Your rights

You may ask us at any time for access to your data, rectification, erasure, restriction of processing, portability, and you may object to processing based on legitimate interest (arts. 15–22 GDPR). Write to ldvconsulting360@gmail.com: we reply within one month. If you believe the processing breaches the law you may lodge a complaint with the supervisory authority of your country — in Italy the Garante per la protezione dei dati personali (garanteprivacy.it).

If you are a patient who received an invitation from a practice and wish to exercise your rights, please contact the practice first, as it is the controller: we assist it for our part.

11. Changes

If we update this notice we publish the new version on this page with its effective date; material changes are notified to customers by email.