Privacy Policy
Information on the processing of personal data, provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”)
1. Data controller
The controller of the personal data collected through this website is:
SOCIETE TLPSANISERVICE S.A.R.L. — limited liability company under Moroccan law, share capital MAD 100,000.00
Registered office: LOT 325/A, Assaka, Agadir — Morocco
ICE 002926427000052
Telephone: +212 661 935 543
Email: info@tlpsaniservice.com
The controller has not appointed a Data Protection Officer (DPO).
2. Who this notice applies to
This notice describes the processing of personal data of:
- visitors to the website;
- healthcare professionals who submit their application and curriculum vitae;
- contact persons at healthcare facilities who complete the information request form.
The use of cookies and tracking tools is described in the Cookie Policy, which forms an integral part of this notice.
3. Browsing data
The IT systems and software procedures that operate this website acquire, during their normal operation, certain data whose transmission is implicit in the use of Internet communication protocols: IP addresses, browser and device type, operating system, date and time of the request, pages visited, outcome of the request.
- Purpose: to enable use of the website, ensure its security and stability, and detect any abuse or intrusion attempts.
- Legal basis: the controller’s legitimate interest in the security of its systems (Art. 6(1)(f) GDPR).
- Retention: technical logs are kept for 30 days, unless required to investigate offences or abuse.
These data are not used to identify users, nor are they combined with other information.
4. Professionals submitting a curriculum vitae
4.1 Data processed
Through the “Send your CV” form we collect:
- identification and contact details (first name, surname, email, telephone number, country of residence);
- the attached curriculum vitae and all information contained in it: education, professional qualifications and licences, work experience, language skills, and any photograph;
- the content of any free-text messages entered in the form.
4.2 Notice regarding special categories of data
The curriculum vitae should contain only information relevant to the assessment of the application. We ask candidates not to include data concerning health, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, sex life or sexual orientation, nor data relating to criminal convictions.
Should such data nevertheless appear in the curriculum vitae, their processing is based on the explicit consent that the data subject expresses by voluntarily submitting the document (Art. 9(2)(a) GDPR), and is limited to recruitment purposes. Consent may be withdrawn at any time by writing to the addresses given in section 9.
4.3 Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Assessment of the application, verification of requirements, interviews and selection | Performance of pre-contractual measures requested by the data subject (Art. 6(1)(b) GDPR; Art. 111-bis of Italian Legislative Decree 196/2003) |
| Presentation of the profile to interested client healthcare facilities | Performance of pre-contractual measures requested by the data subject (Art. 6(1)(b) GDPR) |
| Retention of the profile for future opportunities, beyond the current selection process | Optional and revocable consent of the data subject (Art. 6(1)(a) GDPR) |
| Compliance with legal obligations concerning entry, residence and employment | Legal obligation (Art. 6(1)(c) GDPR) |
As provided by Art. 111-bis of the Italian Personal Data Protection Code, consent to the processing of data contained in a curriculum vitae is not required within the limits of recruitment purposes: the checkbox in the form serves solely to confirm that this notice has been read.
4.4 How curricula are handled
A curriculum vitae submitted through the form is not stored on the website: it is transmitted to a professional email account of the controller and subsequently kept in the controller’s internal archives, in a restricted-access folder of the company mail and archiving system.
Access is limited to the controller’s staff expressly authorised and instructed pursuant to Art. 29 GDPR.
4.5 Recipients
Candidates’ data may be disclosed to:
- client healthcare facilities and clinics interested in the profile, in Italy and in other European Union countries. Such facilities process the data as independent controllers, under their own privacy notices;
- authorities and administrative bodies responsible for visa, residence permit and professional qualification recognition procedures, where necessary;
- the technical providers listed in section 6.
4.6 Retention
| Scenario | Period |
|---|---|
| Unsuccessful application, without consent to retention | 12 months from receipt |
| Application retained with consent for future opportunities | 24 months from receipt or from the last update, renewable |
| Application resulting in placement with a client facility | For the duration of the relationship and the statutory periods thereafter |
5. Healthcare facilities: information request form
5.1 Data processed
First name and surname of the contact person, name of the facility, role, email, telephone, country and city, and the content of the request.
5.2 Purposes and legal bases
- Responding to the information request and preparing a service proposal — performance of pre-contractual measures (Art. 6(1)(b) GDPR).
- Accounting and tax obligations, where a business relationship is established — legal obligation (Art. 6(1)(c) GDPR).
5.3 Retention
24 months from the last meaningful contact where no contractual relationship exists; for the duration of the relationship and the following 10 years where a contractual relationship exists, under applicable civil and tax obligations.
6. Recipients and processors
For the operation of the website and the management of communications, the controller uses providers that process the data on its behalf as processors:
| Provider | Service | Data location |
|---|---|---|
| Aruba S.p.A. | Website and database hosting | Italy (EU) |
| Aruba S.p.A. | Email account receiving the forms | Italy (EU) |
| Cloudflare, Inc. | Anti-spam protection for forms (Turnstile): receives the IP address and technical browser data of anyone completing a form | United States and global network |
An up-to-date list of providers is available on request by writing to the addresses given in section 9. Data are not disseminated or transferred to third parties for commercial purposes.
7. Transfers of data to third countries
The controller is established in Morocco, a country for which the European Commission has not adopted an adequacy decision under Art. 45 GDPR. The website and its database are hosted on servers located in the European Union (Aruba S.p.A., Italy); however, data submitted through the forms (curricula, requests from facilities) are transmitted to an email account of the controller and kept in its internal archives, with possible processing outside the European Economic Area.
The Turnstile anti-spam service additionally involves the transmission of the IP address and technical browser data to Cloudflare, Inc., established in the United States.
Where transfers subject to Chapter V of the GDPR occur, the controller applies the appropriate safeguards provided for by Art. 46 GDPR, in particular the standard contractual clauses approved by the European Commission by Implementing Decision (EU) 2021/914, together with any supplementary measures deemed necessary. A copy of the safeguards adopted may be requested at the addresses given in section 9.
Processing is also subject to Moroccan personal data protection legislation (Law No. 09-08) and to the requirements of the CNDP — Commission Nationale de contrôle de la protection des Données à caractère Personnel.
8. Nature of the provision of data and automated decision-making
Providing the data marked as mandatory in the forms is necessary in order to act on the request: without them, it will not be possible to assess the application or respond to the information request. Providing the remaining data is optional.
The controller does not carry out automated decision-making, including profiling, producing legal effects or similarly significantly affecting data subjects.
9. Rights of data subjects
Data subjects may exercise at any time the rights provided for by Articles 15 to 22 GDPR:
- access to their data and to information about the processing;
- rectification of inaccurate data and completion of incomplete data;
- erasure of data (“right to be forgotten”), in the cases provided for;
- restriction of processing;
- portability of data processed on the basis of a contract or consent;
- objection to processing based on legitimate interest;
- withdrawal of consent given, without affecting the lawfulness of processing carried out beforehand.
Requests should be sent to info@tlpsaniservice.com or by post to the address given in section 1. The controller responds within one month of receipt, extendable by two months for complex requests.
Complaints. Data subjects located in the European Union may lodge a complaint with the supervisory authority of their country of residence or work; in Italy, with the Garante per la protezione dei dati personali (garanteprivacy.it). Data subjects located in Morocco may contact the CNDP.
10. Security measures
The controller implements appropriate technical and organisational measures to protect data against unauthorised destruction, loss, alteration, disclosure or access: encrypted connection (HTTPS), named accounts protected by strong credentials, access limited to authorised staff only, periodic backups, and continuous updating of the website software.
11. Changes to this notice
The controller reserves the right to amend this notice in order to reflect regulatory or organisational changes. The version in force is always published on this page, together with the date it was last updated.