Privacy Policy

Your privacy is important to us. This policy explains how we collect, use and protect your data.

Last updated: July 2025

1. Data Controller

NEUROQUANTIC SRLS

info@neuroquantic.com

Viale Papa Giovanni XXIII 21
20093 Cologno Monzese (MI), ITALY

2. Types of Data Collected

Personal data collected by NeuroQuantic may include:

  • Identification data (name, surname, company name)
  • Contact data (email, phone, address)
  • Professional data (institution, role, qualifications)
  • Research project data (only in anonymized and aggregated form)
  • Navigation data (technical cookies, access logs)

3. Purpose of Processing

Personal data is processed for the following purposes:

3.1 Neurophysiological Analysis Services

  • Management of research projects and data analysis
  • Communications related to requested services
  • Contractual and administrative obligations

3.2 Communications and Marketing

  • Sending information about our services (with consent)
  • Scientific newsletters and updates (with consent)
  • Invitations to events and webinars (with consent)

4. Legal Basis for Processing

The processing of personal data is based on:

  • Contract: for the performance of requested services
  • Legal obligation: for fiscal and administrative compliance
  • Consent: for marketing and communication activities
  • Legitimate interest: to improve our services

5. Processing Methods

Data is processed using electronic and paper tools, adopting adequate security measures to ensure:

  • Data confidentiality and integrity
  • Protection from unauthorized access
  • Regular backups and disaster recovery
  • End-to-end encryption for sensitive data

6. Neurophysiological and Research Data

IMPORTANT: All neurophysiological data (EEG, MEG, EP) are processed exclusively in:

  • Anonymized form: without any reference to subject identity
  • Pseudonymized form: with codes that do not allow direct identification
  • Aggregated form: for group statistical analysis

NeuroQuantic has no access to identifying data of study participants and operates according to the highest ethical and security standards for scientific research.

7. Data Communication and Disclosure

Personal data may be communicated to:

  • Authorized NeuroQuantic personnel
  • Consultants and professionals for fiscal/legal compliance
  • IT service providers (hosting, cloud, backup)
  • Scientific partners (anonymized data only)

Data will never be sold or transferred to third parties for commercial purposes.

8. Data Transfer Outside the EU

Data is stored on servers located within the European Union. In case of transfer outside the EU, we will adopt appropriate safeguards provided by GDPR (standard contractual clauses, adequacy decision).

9. Data Retention Period

  • Contractual data: 10 years from the end of the relationship
  • Marketing data: until consent withdrawal
  • Navigation data: 6 months
  • Anonymized research data: unlimited retention for scientific purposes

10. Data Subject Rights

You may exercise the following rights at any time:

  • Access: obtain information about your data
  • Rectification: correct inaccurate data
  • Erasure: request data deletion
  • Restriction: limit processing
  • Portability: receive data in a structured format
  • Objection: object to processing
  • Consent withdrawal: at any time

How to Exercise Your Rights

To exercise your rights, send a request to:

Email: info@neuroquantic.com
PEC: neuroquantic@legalmail.it

We will respond within 30 days of receiving the request.

11. Cookie Policy

Our website uses only essential technical cookies for operation. We do not use profiling or tracking cookies. For more information, please see our Cookie Policy.

12. Data Security

NeuroQuantic adopts security measures compliant with ISO 27001 standards and industry best practices:

  • SSL certification for all communications
  • Firewall and intrusion detection systems
  • Limited and controlled data access
  • Regular staff training
  • Regular security audits

13. Changes to this Policy

We reserve the right to modify this policy. Changes will be published on this page with indication of the update date.

14. Complaints

If you believe that the processing of your data violates the GDPR, you have the right to lodge a complaint with the Data Protection Authority:

Garante Privacy
Piazza Venezia 11, 00187 Roma
Email: protocollo@gpdp.it
Web: www.garanteprivacy.it