Privacy policy
Last updated: 22 August 2026
Who we are
MappaMedica is a public professional directory of healthcare professionals, helping people find them by specialty, location, and language. We publish professionals' professional information so that patients can find and contact them. There is no account for visitors: we use no analytics or tracking tools and we build no profiles. The only technical data processed when you browse the directory, minimal and transient, is described in the "Visitor data" section.
Data controller
mappamedica.it is operated from Switzerland by Beatrice Dalla Via, Frohburgstrasse 301, 8057 Zurich, Switzerland, the "data controller" under the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nLPD/revFADP). For any question about this policy or about how data is handled, write to the contact address below.
Contact: beahiveproject@gmail.com
Representative in the European Union (Art. 27 GDPR)
As we operate from Switzerland while addressing users in the European Union, under Art. 27 GDPR we have designated a representative established in the EU, acting as the point of contact for data subjects and supervisory authorities: Camilla Dalla Via, Via Brolo del Conte 3, 36015 Schio (Italy) — beahiveprojecteu@gmail.com. The same person is also our legal representative in the Union under Art. 13 of Regulation (EU) 2022/2065 (Digital Services Act).
How a listing comes about
A listing comes about in one way only: by self-registration. The professional requests and manages their own listing directly; we never create listings on behalf of professionals who have not asked for one. Before publication we verify professional identity against the public registers of the professional orders (for Italy, FNOMCeO and the orders of the healthcare professions recognized under Law 3/2018), and for each listing we store the outcome and the date of the check.
What data we store
For each professional listed in the directory we store professional data only: their name, professional contact details (work phone, email, website, and booking link), practice address(es) and opening hours, specialties, languages spoken, education history, a professional photo, the register number together with the outcome of our check (outcome and date) and, if the professional chooses to link one, a Google Place ID, used to show the live Google rating. At registration we also store the date and the version of the terms of service accepted and of the privacy notice read, as evidence of joining the service. We do not process special categories of data (Art. 9 GDPR).
Visitor data
You can browse and search the directory without any account. When you do, we process only: the text you type into search (see the dedicated note in the service-providers section); your IP address, in short-lived temporary counters used solely to limit abuse (rate limiting); and the IP address your browser gives to CARTO when it requests the map's background images. If you choose to write to us by email, or to fill in the optional questionnaire linked on the About page, we receive what you share and use it solely to read it and reply to you.
Legal basis
The legal bases vary with the processing. For professionals' listings the basis is the contract (Art. 6, para. 1, point b GDPR): publishing the listing is exactly the service the professional asks us for by self-registering; without the data the registration form requires, the listing can be neither created nor published. Search functionality and anti-abuse measures rest on legitimate interest (Art. 6, para. 1, point f GDPR); voluntary contacts (email, questionnaire) rest on consent, which you can withdraw at any time without affecting the lawfulness of processing already carried out, or on pre-contractual measures. All processing is carried out in compliance with both the GDPR and the Swiss Federal Act on Data Protection (nLPD/revFADP).
Where your data is hosted and transferred
Our database and the files uploaded to it (such as profile photos) are hosted by Supabase in the EU Ireland region (AWS eu-west-1); the application is served by Vercel from an EU region (Frankfurt). Several of the providers we use are US companies (Supabase, Vercel, Upstash, Resend, OpenAI, Google): even when they keep data in EU regions, they remain subject to US law, so the corresponding transfers are protected, depending on the provider, by the EU–US Data Privacy Framework or by the European Commission's Standard Contractual Clauses (SCCs). You can obtain a copy of the applicable safeguards by writing to the contact address above. Two operations take place in the United States by their nature: the text you type into search, sent to OpenAI (which may retain it for up to 30 days for abuse monitoring, after which it deletes it, and does not use it to train its models), and the Place ID used to retrieve the Google rating. Calls to Google are made exclusively from our servers: your IP address is never sent to Google. The equivalent Swiss safeguards apply under the nLPD.
Service providers we use
We rely on a small number of third-party service providers to run the directory. Each processes only what its function requires. Most process data on our behalf as data processors; Google, CARTO and OpenStreetMap process the data they receive as independent controllers, under their own privacy policies:
- Supabase — hosts the database and uploaded photos in the EU (Ireland).
- Vercel — hosts and serves the application from an EU region (Frankfurt).
- Google Places — when a professional links a Place ID, supplies the live average rating, the review count, and up to five review texts shown on the profile. The request is made only from our servers (your IP address is never sent to Google) and the content stays in a 24-hour technical cache, never in our database.
- OpenAI — interprets visitors' search text (typo correction and intent detection) and converts it, together with listing text (biography, FAQs, and so on), into numerical vectors for semantic search and, if a professional uses the profile translation feature, translates their listing's text between Italian and English (the texts are sent to OpenAI for these purposes). OpenAI may retain the texts it receives for up to 30 days for abuse monitoring, after which it deletes them, and does not use them to train its models.
- OpenStreetMap / Nominatim — resolves a typed location phrase (such as a city name) into map coordinates; the request is made from our servers.
- CARTO — serves the map's background images (tiles). Your browser fetches them directly from CARTO's servers, which therefore receive your IP address. No cookies are set.
- Upstash — stores, in an EU region, short-lived counters for rate limiting, which include IP addresses, to protect the site from abuse.
- Resend — sends the transactional email (magic-link sign-in, submission and review notifications) from an EU region; Resend's account data and delivery logs are kept in the United States.
- Tally — collects your answers if you choose to fill in the optional questionnaire linked on the About page; hosted in the EU.
The text you type into search may reveal information about the kind of care you are looking for, so we treat it with particular caution: it is used to return your results (sent to OpenAI, which keeps it for at most 30 days for abuse monitoring, and, for location phrases, to Nominatim) and kept by us only in anonymous form — the normalised search text, with no IP address, session, or any other identifier — to improve the quality of results. We cannot link searches back to you and we do not build any profile of visitors.
Data retention
Administrative audit logs (the records of admin actions on listings) are automatically deleted after 12 months. Professional listing data including the register-verification log is retained for as long as the listing remains published, or until a removal request is honoured. The data provided with a registration that never reaches publication (because it was rejected or left pending) is deleted 12 months after its last update, together with the related terms-acceptance record. A sign-in account that is created but never linked to a professional listing is deleted after 30 days. Profiles being built and profiles voluntarily paused are kept while active; after 24 months without sign-in, editing, publishing, pausing/resuming or administrative activity, we give 30 days' notice and then delete the profile unless activity resumes. Suspended profiles are retained while the suspension, investigation, review, appeal or a related legal claim remains active and are reviewed at least annually; when the matter ends, the profile is restored or moved to the appropriate final delisting/deletion outcome. Changes to your page that you have not published yet (the studio draft) are deleted after 1 month without changes, together with any photos uploaded only for that draft. The anonymous search text is kept for 24 months. Google content (rating and reviews) stays only in a 24-hour technical cache. The emails you choose to send us remain in our mailbox, with no automatic deletion; you can ask for them to be deleted at any time by writing to the same address.
Security
We protect data with appropriate technical and organisational measures: encrypted transmission (HTTPS/HSTS), a restrictive Content Security Policy, keys and credentials kept strictly server-side, calls to sensitive external services made only from our servers, minimisation of the data collected, and automatic deletion when a retention period expires.
Your rights and removal requests
Under the GDPR, anyone can at any time request access to the data concerning them, its rectification, the restriction of processing, portability (for data processed on a contractual basis), or erasure; in practice these requests come above all from the professionals listed in the directory, the only people whose identifying data we keep. We act on requests without undue delay and in any event within 30 days: the listing is delisted and, where erasure has been requested, permanently removed. To protect professionals, we may ask you to verify your identity before acting on a request. You also have the right to lodge a complaint with a supervisory authority: in Italy the Garante per la protezione dei dati personali, in Switzerland the Federal Data Protection and Information Commissioner (FDPIC).
To request removal, contact: beahiveproject@gmail.com
Your right to object
For the processing founded on legitimate interest, the running of search, the anti-abuse measures, and the internal audit logs, you have the right to object at any time, on grounds relating to your particular situation (Art. 21 GDPR), by writing to the contact address above. Professionals' listings are not founded on legitimate interest: whoever manages their own listing can ask for its removal at any time, as described in the previous section.
Cookies
We use strictly necessary technical cookies only: the session cookies that keep signed-in administrators and healthcare professionals logged in (in the profile studio). If you do not sign in to a restricted area, no cookie is set for you: the interface language, for example, is carried in the page address and needs no cookie. We do not use analytics, tracking, or advertising cookies, so in line with the Garante's guidelines no cookie consent banner is required.
This English text is a courtesy translation. The Italian version of this privacy policy is the authoritative one: in the event of any discrepancy between the two, the Italian version prevails.