Back to Medical Accreditation

Privacy Policy – Medical Accreditation Program

Last Updated: May 2026

Pursuant to Regulation (EU) 2016/679 ("GDPR") and applicable international data protection laws, Medcare Engineering S.r.l. ("MCE"), with registered office in Centro Direzionale Isola A/3, 80143 Naples, Italy, VAT No. 10682981211, acts as Data Controller for the processing of personal data collected within the Medical Accreditation Program.

1. Purpose of Processing

Personal data provided by applicants may be processed for purposes related to:

  • management of medical accreditation applications;
  • professional identity verification and credential validation;
  • assessment of eligibility and compliance requirements;
  • access to digital platforms and healthcare services connected to the Universal Doctor® ecosystem;
  • fraud prevention, cybersecurity and platform protection;
  • compliance with legal, regulatory and contractual obligations.

2. Categories of Data Processed

The Data Controller may process:

  • identification and contact data;
  • professional and licensing information;
  • curriculum vitae and supporting documentation;
  • healthcare-related professional information;
  • technical, access and security logs generated through digital platforms.

3. Legal Basis of Processing

Personal data are processed pursuant to Article 6 of Regulation (EU) 2016/679 ("GDPR"), including:

  • performance of pre-contractual measures requested by the data subject;
  • compliance with legal obligations;
  • legitimate interests pursued by the Data Controller relating to security, fraud prevention, professional verification and management of the healthcare network;
  • explicit consent of the data subject, where required.

Where special categories of personal data are processed, Article 9 GDPR and applicable legal safeguards shall apply.

4. Processing Methods and Security Measures

Data are processed using electronic and organizational procedures designed to ensure confidentiality, integrity, availability and security of personal data.

Medcare Engineering S.r.l. adopts appropriate technical and organizational safeguards aimed at preventing unauthorized access, disclosure, alteration, loss or unlawful processing of personal data.

5. Data Retention

Personal data shall be retained for the following periods:

  • Application data: 24 months from submission or rejection;
  • Accredited professionals: duration of accreditation + 10 years (regulatory compliance);
  • Technical logs: 12 months (security purposes);
  • Rejected applications: 12 months, unless legal claims arise.

Upon expiration, data shall be securely deleted or anonymized in accordance with applicable legal and regulatory obligations.

6. Data Sharing and International Transfers

Personal data may be disclosed to:

  • Cloud infrastructure providers (e.g., Supabase, AWS);
  • Identity verification and compliance service providers;
  • Cybersecurity and fraud prevention partners;
  • Legal and regulatory authorities, where required by law.

All third-party processors are bound by data processing agreements compliant with Article 28 GDPR.

Where international data transfers to countries outside the European Economic Area occur, Medcare Engineering S.r.l. ensures appropriate safeguards pursuant to Chapter V GDPR, including:

  • Standard Contractual Clauses approved by the European Commission;
  • Adequacy Decisions issued by the European Commission;
  • Binding Corporate Rules, where applicable.

7. Rights of the Data Subject

Data subjects may exercise, at any time, the rights provided under Articles 15–22 GDPR, including:

  • right of access;
  • rectification;
  • erasure;
  • restriction of processing;
  • objection to processing;
  • data portability;
  • withdrawal of consent, where applicable.

Requests may be submitted using the contact details below.

8. Data Controller

Medcare Engineering S.r.l.
Centro Direzionale Isola A/3
80143 Naples – Italy
VAT No. 10682981211
Website: www.mcecorporate.com
Email: privacy@mcecorporate.com

9. Right to Lodge a Complaint

Without prejudice to any other administrative or judicial remedy, data subjects have the right to lodge a complaint with the competent supervisory authority:

Garante per la Protezione dei Dati Personali
Piazza Venezia, 11 – 00187 Rome, Italy
Tel: +39 06.696771
Email: garante@gpdp.it
Website: www.garanteprivacy.it

10. Automated Decision-Making and Profiling

No automated decision-making processes, including profiling as defined under Article 22 GDPR, are carried out within the Medical Accreditation Program that produce legal effects or similarly significantly affect applicants.

All accreditation decisions are subject to human review and assessment.

11. Obligation to Provide Personal Data

The provision of personal data is necessary for:

  • processing your accreditation application;
  • verifying professional credentials and eligibility;
  • granting access to the Universal Doctor® platform.

Failure to provide required data will result in the inability to process your application or provide access to platform services.