GDPR and data subject rights

Data subject rights and how to exercise them under Regulation (EU) 2016/679, consistent with the framework privacy notice of NexStudio S.r.l. (Italy, [INDIRIZZO_COMPLETO]). For LexAura and MediAura, product-specific operational details are set out in the privacy notices published on the dedicated SaaS portals.

Version 1.1 · In force from [DATA] · Last updated [DATA]

Related documents: Privacy notice · Cookie policy · Terms of use

Contents

  1. 1. Regulatory framework and scope
  2. 2. Rights granted to data subjects
  3. 3. Who to contact to exercise rights
  4. 4. Identity verification and request handling
  5. 5. Cases of limitation or refusal
  6. 6. International transfers and safeguards
  7. 7. Coordination with SaaS privacy notices

1. Regulatory framework and scope

Regulation (EU) 2016/679 (GDPR) protects data subjects’ rights and governs the processing of personal data. This page explains how to exercise those rights vis-à-vis NexStudio in the context of the corporate portal and related services.

2. Rights granted to data subjects

Within the limits provided by applicable law, the data subject may exercise the following rights:

  • Access to personal data and obtaining a copy in an intelligible format;
  • Rectification of inaccurate data and completion of incomplete data;
  • Erasure of data (right to be forgotten), where the relevant conditions are met;
  • Restriction of processing where the conditions set out in the GDPR apply;
  • Data portability for data processed by automated means on the basis of consent or contract;
  • Objection to processing based on legitimate interest, including objection to marketing communications;
  • Withdrawal of consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
  • Complaint to the competent supervisory authority.

3. Who to contact to exercise rights

  • Email: privacy@nexstudio.com
  • Form: nexstudio.ai/contatti
  • For processing in SaaS tenants (LexAura/MediAura): contact the customer controller first (law firm, healthcare organization). NexStudio supports the customer controller under the DPA and contractual agreements.

Competent supervisory authority: Italian Data Protection Authority — Garante per la protezione dei dati personali (www.garanteprivacy.it) — for processing subject to the GDPR.

4. Identity verification and request handling

To protect confidentiality and security, NexStudio may request the minimum additional information needed to verify the requester’s identity. Requests are handled under tracked procedures and acknowledged within the time limits set by the GDPR; for complex or multiple requests, the deadlines may be extended within the limits permitted by law, with a reasoned notice.

5. Cases of limitation or refusal

The exercise of rights may be limited or refused where overriding legal obligations, needs of defense in legal proceedings, protection of third-party rights, or other exceptions provided by law apply. In such cases NexStudio provides a reasoned response and indicates the available remedies, including the right to lodge a complaint with the competent authority.

6. International transfers and safeguards

Where processing involves transfers outside the EEA/EU, NexStudio adopts the measures required by law (e.g. standard contractual clauses and supplementary measures). Data primarily resides in the EU via Cloudflare infrastructure.

7. Coordination with SaaS privacy notices

The privacy policies of the LexAura and MediAura SaaS portals detail, for each product, data flows, retention periods, privacy roles, and dedicated channels. In case of differences between documents, the service-specific documents and applicable contractual agreements prevail.

To consult product privacy notices:

  • LexAura: see the dedicated portal
  • MediAura: mediaura.doctor/privacy