Privacy policy
Last updated: 2026-06-01
This policy describes how Nutrilia processes the personal data of professionals using the Service and, indirectly, of patients whose data are entered into the platform by the professional. Processing is carried out in compliance with Regulation (EU) 2016/679 (GDPR) and applicable Italian law.
1. Data controller
Nutrilia is a service operated by Cloudify, an Italian sole proprietorship, VAT IT02563250444. For any request regarding your personal data you can reach us at info@nutrilia.it.
2. Definitions
- Service or Platform: the Nutrilia web application available at nutrilia.it.
- Cloudify or we: the sole proprietorship that operates the Service, acting as either controller or processor depending on the data.
- Professional: the licensed nutritionist, dietitian, biologist or medical nutritionist who registers to the Service to manage their own practice.
- Patient: the person whose clinical data are entered into the Service by the Professional.
- GDPR: Regulation (EU) 2016/679.
- Controller and Processor: as defined by Art. 4 GDPR.
3. Dual role: controller and external processor
Nutrilia plays two distinct roles:
- Controller for the Professional's data (account, tax details, subscription billing, technical logs). For these data we decide the purpose and means of processing.
- External Processor for the Patient data entered by the Professional (personal details, anamnesis, measurements, diet plans, clinical documents). The Controller of this data is the Professional, who decides which data to collect, how to obtain the patient's consent and how long to keep them.
We process patient data solely to provide the Service to the Professional, on their instructions, under the data processing agreement (DPA) accepted at registration and incorporated into the Terms of service.
4. Data collected
We collect:
- Professional registration data: first name, last name, email.
- Professional tax data: VAT, tax code, tax regime, IBAN, billing address, ENPAB enrolment if any.
- Subscription payment data: handled through Stripe. We do not store card details directly.
- Patient data entered by the Professional: personal details, anamnesis, anthropometric and body composition measurements, diet plans, appointments, clinical documents, scans of paper-signed consent forms uploaded by the Professional. Free-text anamnesis fields are encrypted at rest.
- Technical data: IP address, browser user agent, security events (logins, failed access).
- Aggregated usage data: measured via Mixpanel only after explicit consent on the cookie banner. The IP address is dropped server-side and no events are tied to your name.
5. Purposes and legal bases
We process data for the following purposes:
| Purpose | Legal basis |
|---|---|
| Provide the practice management Service to the Professional | Contract performance (Art. 6.1.b GDPR) |
| Manage the subscription and bill the Professional | Contract performance + tax obligations (Arts. 6.1.b and 6.1.c GDPR) |
| Comply with accounting and tax obligations | Legal obligation (Art. 6.1.c GDPR) |
| Ensure the security of the Service and prevent abuse | Legitimate interest (Art. 6.1.f GDPR) |
| Improve the Service through aggregated analytics | Consent (Art. 6.1.a GDPR), withdrawable at any time |
| Respond to support requests | Contract performance (Art. 6.1.b GDPR) |
| Process Patient data on behalf of the Professional | Controller's instructions, who obtains the patient's consent under Art. 9.2.a GDPR |
6. Sub-processors
To deliver the Service we rely on the following providers, all bound by a data processing agreement (DPA) and, where data leave the EU, by the Standard Contractual Clauses (SCC) approved by the European Commission:
| Provider | Role | Data location |
|---|---|---|
| Vercel | Application hosting | EU |
| Neon | PostgreSQL database | EU |
| Amazon Web Services (S3) | Document and image storage | EU (eu-west-1, Ireland) |
| Resend | Transactional email delivery | USA, with SCC |
| Stripe | Subscription payment processing | Ireland / USA, with SCC |
| Anthropic | AI features (diet plan generation and suggestions) | USA, with SCC |
| Mixpanel | Aggregated analytics on Service usage | EU, IP dropped |
| Cloudflare (Turnstile) | Anti-bot protection on the login form (magic-link request only) | EU/USA, with SCC |
| Sentry | Error tracking / technical diagnostics (no patient data in payloads, automatic scrub) | EU (Frankfurt) |
The list is up to date as of the date shown at the top of this document. Material changes are communicated by email to Professionals.
7. Data retention
- Account and configuration data: for the duration of the contract.
- Subscription billing data: 10 years, as required by Italian tax law.
- Patient data: for the duration of the Professional's contract. Upon termination the Professional has 30 days to export or request earlier deletion. After 30 days we automatically delete the patient data, unless the Professional (as Controller) gives different written instructions. Compliance with the retention periods set by healthcare law remains the Professional's responsibility as Controller.
- Technical logs: up to 12 months.
- Backups: 30 days, then overwritten.
8. Non-EU transfers
Some sub-processors (Resend, Stripe, Anthropic, Cloudflare) are based in the United States or use its global infrastructure. Transfers take place on the basis of the Standard Contractual Clauses approved by the European Commission or, where applicable, an adequacy decision (Data Privacy Framework). All data that can stay in the EU stay in the EU.
9. Data subject rights
If you are a Professional registered with Nutrilia, you have the right to:
- access your data (Art. 15 GDPR);
- rectify it (Art. 16 GDPR);
- request its erasure (Art. 17 GDPR), within the limits of legal obligations;
- restrict its processing (Art. 18 GDPR);
- receive it in a portable format (Art. 20 GDPR);
- object to processing (Art. 21 GDPR);
- withdraw the consent given for analytics.
To exercise these rights write to info@nutrilia.it. We will reply within 30 days. You also have the right to lodge a complaint with the Italian Data Protection Authority at www.garanteprivacy.it.
10. Security measures
We apply appropriate technical and organizational measures:
- AES-256-GCM at-rest encryption of sensitive clinical fields (free-text anamnesis);
- TLS encryption in transit across the platform;
- multi-tenant isolation via Postgres Row Level Security;
- authentication via magic link or Google OAuth, with no reused passwords;
- access logs on all patient data;
- documents and scans uploaded by the Professional (clinical reports, lab results, paper-signed consents) are stored in a private bucket encrypted at rest and accessible only via short-lived signed URLs;
- encrypted daily backups;
- restricted and audited access to production data.
11. If you are a Patient
If your data have been entered into Nutrilia by a nutritionist, the Controller of your data is the nutritionist who treats you, not Cloudify. To exercise your GDPR rights (access, rectification, erasure, portability) you must reach out directly to your nutritionist, who has already given you their privacy notice at the first appointment.
Cloudify processes your data solely to provide your nutritionist with the practice management tool and applies the security measures described in section 10. We do not use your data for our own purposes, we do not share them for marketing, we do not sell them.
12. Changes to this policy
We may update this policy to reflect changes to the Service, to the sub-processors or to applicable law. Material changes are communicated by email to Professionals at least 30 days before they take effect. The last update date is shown at the top of this document.
13. Contact
For any question about the processing of your personal data or to exercise your rights, write to info@nutrilia.it.