Home Privacy

Privacy Policy

Version 3.2 — July 21, 2026

Italiano English Español

This policy transparently describes how OmniNeo processes the personal data of its users, in accordance with EU Regulation 2016/679 (GDPR) and Italian Legislative Decree 196/2003 (Privacy Code) as amended by Decree 101/2018.

In a nutshell. OmniNeo is an educational tool for neonatologists/pediatricians. We do not collect or store patient data. Messages sent to the AI Assistant are not stored on our servers and are filtered server-side to block accidental transmission of identifying data. We do not use profiling or advertising cookies.

1. Data Controller

Ciro Barone, individual operator of the OmniNeo project.
Email: privacy@omni-test.it
Site: https://omni-test.it

OmniNeo is in commercial launch phase; a dedicated company will be incorporated upon reaching the revenue thresholds set by Italian tax law. This policy will be updated accordingly.

2. Categories of data processed

The principle of data minimization (Art. 5 GDPR) governs collection: we ask for the minimum required by the service.

CategoryExamplesSource
Account identifiersEmail, name, password (stored only as bcrypt hash)Provided by user at signup
Professional dataRole (physician/nurse/midwife), medical board registration number, countryProvided by user — verifiable via public board registry
Access dataIP address, user agent, device, city/country (approximate geolocation)Computed at login (no external services: GeoLite2 local DB)
Payment dataStripe customer ID, no credit card data on our serversStripe Inc. (US) processes payments
Billing dataTax code (Codice Fiscale), billing address, VAT number if any — required to issue the electronic invoice to the Italian Interchange System (SdI)Provided by the user at purchase (e-invoicing legal requirement)
AI Assistant usageDaily counts (number of calls, model used, credits consumed). NO message contents.Computed automatically
Forum / communityPosts, replies, public profileProvided by user
Clinical / editorial reportsReports of errors in drug formulary and clinical sheetsProvided by user
Security eventsAudit log of sensitive actions (login, password change, account deletion...)Computed automatically
Special categories (Art. 9 GDPR — health data). OmniNeo does not process patient health data. The product is an educational tool for licensed healthcare professionals: the content is medical literature and abstract clinical reasoning, never identifying data of real patients. The automatic anti-PII filter described in §6 technically blocks accidental transmission of fiscal codes, IBAN, NHS/SSN, clinical prefixes (Mr./Sr. + Surname), birth dates, etc. If a user accidentally transmits such data, the system halts the operation and educates them to rephrase anonymously.

3. Purposes and legal bases

PurposeLegal basis (Art. 6 GDPR)
Provide the service (signup, login, content access)Contract performance (Art. 6.1.b)
Manage subscriptions and billingContract + legal obligation (Art. 6.1.b + 6.1.c)
Account security (rate limit, lockout, audit log, admin 2FA)Legitimate interest — user protection (Art. 6.1.f)
AI Assistant operationContract (Art. 6.1.b) + legitimate interest (no prompt persistence — Art. 6.1.f)
Verification of professional registry membership ("Verified" badge)Legitimate interest — clinical audience reliability (Art. 6.1.f); data already public by board registry law
Forum / community (public posts)Consent (Art. 6.1.a)
Functional / security / statistics cookiesConsent (Art. 6.1.a)
Issuance and transmission of the electronic invoice to the SdI (Italian Revenue Agency) and compliant archivingLegal obligation (Art. 6.1.c)
Compliance with legal obligations (billing, AML, GDPR accountability)Legal obligation (Art. 6.1.c)

4. Suppliers (data processors — Art. 28)

To operate the service we rely on the following entities, bound by Data Processing Agreement (DPA) or equivalent:

SupplierRoleLocationTransfer
Netsons S.r.l.cPanel hosting, MySQL database, SMTP emailItaly (EU)None outside EU
Stripe Inc. / Stripe Payments Europe Ltd.Payments, subscriptions, web IAPUSA / Ireland (EU)SCC 2021 + DPA
Openapi S.p.A.Electronic invoicing: generation and transmission of the FatturaPA to the Interchange System (SdI), compliant archivingItaly (EU)None outside the EU — DPA Art. 28
Anthropic PBCAI models (Claude Haiku/Sonnet)USASCC 2021 + DPA — no prompt persistence
Intuition Machines / hCaptchaAnti-bot verification on signup and loginUSASCC 2021
Google LLC (future)OAuth Sign-In, Play Billing (Android)USASCC 2021 + DPA — only after explicit user consent
Apple Inc. (future)Sign-In with Apple, IAP (iOS)USASCC 2021 + DPA — only after explicit user consent
Backblaze Inc. (future Phase 4c)Encrypted backupUSASCC 2021 + DPA — encryption key not shared with provider

The current list and related DPAs are available by writing to privacy@omni-test.it.

5. Retention periods

CategoryPeriodReason
User profileUntil deletion requestService provision
Billing data (Stripe, Openapi — compliant archiving)10 yearsItalian tax obligation (D.P.R. 633/1972, Art. 22 and 39)
Login history12 monthsAccount security (legitimate interest)
Login attempts log (rate limit)30 daysAccount security
Security events (audit)12 monthsGDPR accountability
AI usage countsUntil deletion requestAccount stats / billing
AI message contents0 seconds (not stored)Privacy by design — Art. 25 GDPR
Forum: public postsUntil user deletion (with anonymization, unless full deletion requested)Community continuity

6. Security measures

We implement appropriate technical and organizational measures (Art. 32 GDPR) consistent with a processing operation outside Art. 9 (no patient health data):

A complete technical description is available at security.html (non-technical summary) and security-ai.html (anti-PII detail).

7. Artificial-intelligence transparency (EU Regulation 2024/1689 — AI Act)

In accordance with the transparency obligations of EU Regulation 2024/1689 (AI Act), we inform you that:

8. Data subject rights

You may exercise the rights granted by Articles 15–22 GDPR at any time:

9. Cookies

OmniNeo uses three categories of cookies/SDK:

We do not use profiling or advertising cookies. Consent is collected via banner compliant with the Italian Garante Guidelines of June 10, 2021 (3 buttons with equal visual weight: "Accept all" / "Reject all" / "Customize"). Persistence: 12 months, with automatic re-prompt at expiry. You may modify your choices at any time by reopening the banner from the homepage footer.

10. Extra-EU transfers

Some suppliers are based in the United States. Transfers comply with Standard Contractual Clauses (SCC) approved by the European Commission with Decision 2021/914, supplemented by additional measures where required by CJEU C-311/18 (Schrems II): transport encryption, no provider-managed keys for the most sensitive data, no transfer of health data.

11. Data Protection Officer (DPO)

The Controller has assessed mandatory DPO appointment criteria (Art. 37 GDPR + WP243 Guidelines) and has not appointed a DPO because:

For privacy questions you may always write to the Controller at privacy@omni-test.it — you will receive a reply within 30 days (Art. 12.3).

12. Policy updates

This policy may be updated for regulatory changes or service evolution. We will notify substantive changes by email. The current version is always available at https://omni-test.it/privacy_en.html. Version history available upon request.


Contacts

Privacy / DSAR: privacy@omni-test.it
Security / vulnerability disclosure: security@omni-test.it
General support: support@omni-test.it