Version 3.2 — July 21, 2026
This policy transparently describes how OmniNeo processes the personal data of its users, in accordance with EU Regulation 2016/679 (GDPR) and Italian Legislative Decree 196/2003 (Privacy Code) as amended by Decree 101/2018.
Ciro Barone, individual operator of the OmniNeo project.
Email: privacy@omni-test.it
Site: https://omni-test.it
OmniNeo is in commercial launch phase; a dedicated company will be incorporated upon reaching the revenue thresholds set by Italian tax law. This policy will be updated accordingly.
The principle of data minimization (Art. 5 GDPR) governs collection: we ask for the minimum required by the service.
| Category | Examples | Source |
|---|---|---|
| Account identifiers | Email, name, password (stored only as bcrypt hash) | Provided by user at signup |
| Professional data | Role (physician/nurse/midwife), medical board registration number, country | Provided by user — verifiable via public board registry |
| Access data | IP address, user agent, device, city/country (approximate geolocation) | Computed at login (no external services: GeoLite2 local DB) |
| Payment data | Stripe customer ID, no credit card data on our servers | Stripe Inc. (US) processes payments |
| Billing data | Tax code (Codice Fiscale), billing address, VAT number if any — required to issue the electronic invoice to the Italian Interchange System (SdI) | Provided by the user at purchase (e-invoicing legal requirement) |
| AI Assistant usage | Daily counts (number of calls, model used, credits consumed). NO message contents. | Computed automatically |
| Forum / community | Posts, replies, public profile | Provided by user |
| Clinical / editorial reports | Reports of errors in drug formulary and clinical sheets | Provided by user |
| Security events | Audit log of sensitive actions (login, password change, account deletion...) | Computed automatically |
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Provide the service (signup, login, content access) | Contract performance (Art. 6.1.b) |
| Manage subscriptions and billing | Contract + legal obligation (Art. 6.1.b + 6.1.c) |
| Account security (rate limit, lockout, audit log, admin 2FA) | Legitimate interest — user protection (Art. 6.1.f) |
| AI Assistant operation | Contract (Art. 6.1.b) + legitimate interest (no prompt persistence — Art. 6.1.f) |
| Verification of professional registry membership ("Verified" badge) | Legitimate interest — clinical audience reliability (Art. 6.1.f); data already public by board registry law |
| Forum / community (public posts) | Consent (Art. 6.1.a) |
| Functional / security / statistics cookies | Consent (Art. 6.1.a) |
| Issuance and transmission of the electronic invoice to the SdI (Italian Revenue Agency) and compliant archiving | Legal obligation (Art. 6.1.c) |
| Compliance with legal obligations (billing, AML, GDPR accountability) | Legal obligation (Art. 6.1.c) |
To operate the service we rely on the following entities, bound by Data Processing Agreement (DPA) or equivalent:
| Supplier | Role | Location | Transfer |
|---|---|---|---|
| Netsons S.r.l. | cPanel hosting, MySQL database, SMTP email | Italy (EU) | None outside EU |
| Stripe Inc. / Stripe Payments Europe Ltd. | Payments, subscriptions, web IAP | USA / Ireland (EU) | SCC 2021 + DPA |
| Openapi S.p.A. | Electronic invoicing: generation and transmission of the FatturaPA to the Interchange System (SdI), compliant archiving | Italy (EU) | None outside the EU — DPA Art. 28 |
| Anthropic PBC | AI models (Claude Haiku/Sonnet) | USA | SCC 2021 + DPA — no prompt persistence |
| Intuition Machines / hCaptcha | Anti-bot verification on signup and login | USA | SCC 2021 |
| Google LLC (future) | OAuth Sign-In, Play Billing (Android) | USA | SCC 2021 + DPA — only after explicit user consent |
| Apple Inc. (future) | Sign-In with Apple, IAP (iOS) | USA | SCC 2021 + DPA — only after explicit user consent |
| Backblaze Inc. (future Phase 4c) | Encrypted backup | USA | SCC 2021 + DPA — encryption key not shared with provider |
The current list and related DPAs are available by writing to privacy@omni-test.it.
| Category | Period | Reason |
|---|---|---|
| User profile | Until deletion request | Service provision |
| Billing data (Stripe, Openapi — compliant archiving) | 10 years | Italian tax obligation (D.P.R. 633/1972, Art. 22 and 39) |
| Login history | 12 months | Account security (legitimate interest) |
| Login attempts log (rate limit) | 30 days | Account security |
| Security events (audit) | 12 months | GDPR accountability |
| AI usage counts | Until deletion request | Account stats / billing |
| AI message contents | 0 seconds (not stored) | Privacy by design — Art. 25 GDPR |
| Forum: public posts | Until user deletion (with anonymization, unless full deletion requested) | Community continuity |
We implement appropriate technical and organizational measures (Art. 32 GDPR) consistent with a processing operation outside Art. 9 (no patient health data):
A complete technical description is available at security.html (non-technical summary) and security-ai.html (anti-PII detail).
In accordance with the transparency obligations of EU Regulation 2024/1689 (AI Act), we inform you that:
You may exercise the rights granted by Articles 15–22 GDPR at any time:
OmniNeo uses three categories of cookies/SDK:
We do not use profiling or advertising cookies. Consent is collected via banner compliant with the Italian Garante Guidelines of June 10, 2021 (3 buttons with equal visual weight: "Accept all" / "Reject all" / "Customize"). Persistence: 12 months, with automatic re-prompt at expiry. You may modify your choices at any time by reopening the banner from the homepage footer.
Some suppliers are based in the United States. Transfers comply with Standard Contractual Clauses (SCC) approved by the European Commission with Decision 2021/914, supplemented by additional measures where required by CJEU C-311/18 (Schrems II): transport encryption, no provider-managed keys for the most sensitive data, no transfer of health data.
The Controller has assessed mandatory DPO appointment criteria (Art. 37 GDPR + WP243 Guidelines) and has not appointed a DPO because:
For privacy questions you may always write to the Controller at privacy@omni-test.it — you will receive a reply within 30 days (Art. 12.3).
This policy may be updated for regulatory changes or service evolution. We will notify substantive changes by email. The current version is always available at https://omni-test.it/privacy_en.html. Version history available upon request.
Privacy / DSAR: privacy@omni-test.it
Security / vulnerability disclosure: security@omni-test.it
General support: support@omni-test.it