Skip to content
TeleLILT
IT EN

Privacy · Regulation (EU) 2016/679 — GDPR

Your health data stays yours.

TeleLILT is the LILT Palermo app for prevention and care: bookings, messages with the people who look after you, reports, video visits. It was designed around the GDPR from day one: data is encrypted, only your care team can see it, and you can download or delete it yourself, whenever you want.

  • AES-256 encryption
  • No ads, no trackers
  • Download or delete everything in the app

What you see

Name
Giulia Bianchi
Report
Mammogram · 12 March
Message
See you Thursday at 9

What the database holds

Name
9f3a·c21e·77b0·4d1a
Report
b7d0·48aa·e3f9·015c
Message
02ce·e9f1·6ab4·d870
Illustrative example: names, reports and messages are stored in encrypted form only.

The app

Prevention and care, in your pocket.

One place to stay in touch with LILT Palermo, from the check-up reminder to the video visit.

  • Appointments

    Book a visit in person or by video, answer proposed times and get a reminder the day before.

  • Messages

    Write to the professionals who follow you and to the front desk. Photos and documents can be attached in the conversation.

  • Documents

    Receive reports and upload your tests: they stay encrypted, opened only by you and your care team.

  • Health

    Fill in your medical history once and record measurements at home: your doctor sees them before the visit.

  • Prevention

    A personal plan of recommended check-ups, with a reminder when the time comes.

  • Video visits

    Talk to your doctor by video. The call is encrypted device to device and is never recorded.

Your data

What we process, and why.

Only what is needed to give you the service. Nothing is collected "just in case" or for future uses.

Your account

  • First and last name, email
  • Date of birth and sex (you may leave it unspecified)
  • App language
  • Tax code, phone and address, if you give them to the front desk
What it is for
To create your account, recognise you and contact you about the service you asked for.
Legal basis
Performance of the service — Art. 6(1)(b)

Your health

  • Medical history and measurements
  • Reports and documents
  • Messages with professionals
  • Appointments and reason for the visit
  • Prevention plan and clinical notes
What it is for
Prevention and care: this is the information the professionals who follow you work with.
Legal basis
Only with your explicit consent, which you can withdraw — Art. 9(2)(a)

Security

  • Devices connected to your account
  • Date, time and IP address of sign-ins
  • Activity log: who did what, and when
What it is for
To protect your account and be able to trace every access to your data. The log holds no clinical data.
Legal basis
Security of processing — Art. 32 and Art. 6(1)(f)

Your choices

  • The documents you accepted, with version and date
  • Your notification preferences
  • Your phone's identifier for push notifications, if you turn them on
What it is for
To honour what you decided and be able to prove it.
Legal basis
Proof of consent — Art. 7(1)

The app is for adults only. Informational messages arrive only if you asked for them, and you can turn them off at any time.

Protection

Protected at every step.

Data protection is not an add-on: it is how the app is built.

  1. 1

    On your phone

    Access keys live in the system's protected storage and never end up in phone backups.

  2. 2

    In transit

    Every exchange with the server travels over an encrypted connection (TLS). Never in clear text.

  3. 3

    On the server

    Each piece of personal data is encrypted individually before it is stored.

  4. 4

    With your care team

    Only the professionals on your care path see it, after two-step verification.

  • Field-by-field encryption

    AES-256-GCM, with a different key for each kind of data. There is not a single name in clear text in the database.

  • Search without reading

    To find a patient the system compares encrypted fingerprints, not readable text.

  • Every file has its own key

    Reports and attachments are encrypted one by one. Deleting a file means destroying its key too.

  • Only those who follow you

    Access is role-based: doctors and front desk see only the patients in their remit. Signing in always requires two-step verification.

  • Every access leaves a trace

    A tamper-evident log records every consultation of your data.

  • Sessions that expire

    The app's access keys last a few minutes and renew themselves. Passwords are kept only as a fingerprint (Argon2id).

  • Encrypted in backups too

    In backups the data stays encrypted: without the keys, kept separately, it is unreadable.

  • Discreet notifications

    Your phone shows only a generic notice, such as "You have a new message". Never clinical data.

Our promises

What we do not do. Ever.

  • No advertising and no commercial profiling.
  • No trackers and no third-party analytics: the app talks only to our server.
  • Your data is not sold and not handed to anyone.
  • Video visits are not recorded.
  • No automated decisions about your health: the people caring for you decide.
  • No clinical data in notifications or emails.

Your rights

Your rights, one tap away.

The GDPR gives you precise rights. In TeleLILT the most important ones are exercised right in the app, with no forms and no waiting.

Get a copy of your dataAccess and portability — Arts. 15 and 20

Request the full archive: a readable summary, the data in a standard format, your documents and messages. It is ready in a few minutes, you confirm with your password and it stays downloadable for 7 days.

In the app ProfileMy dataRequest a copy

Delete everythingErasure — Art. 17

Request the deletion of your account in the app. You have 30 days to change your mind; then data, documents and encryption keys are destroyed. Only the proof of the consents you gave and, until it expires, the security log remain; the log holds no clinical data.

In the app ProfileMy dataDelete my account

Withdraw a consentWithdrawal — Art. 7(3)

Every consent is as easy to withdraw as it is to give. If you withdraw the one for health data, care features switch off at once until you give it again.

In the app ProfileConsents

Decide what you receiveObjection — Art. 21

You choose, category by category, which notices to receive and on which channel. Only those essential to the service stay on, such as an appointment confirmation.

In the app ProfileNotifications

Check who is connectedSecurity of your account

See the devices connected to your account and disconnect them with one tap. The archive of your data also includes the access log, with the role of whoever consulted it.

In the app ProfileSecurityConnected devices

Correct a detailRectification — Art. 16

Personal details are updated by the front desk at your request: just write to them from the app or contact the office.

In the app MessagesFront desk

Retention

For how long.

Data stays as long as it is needed to care for you. Everything else has an expiry date.

  • ∞until you decide

    Account and record

    They stay for the whole duration of the service. You delete them whenever you want in the app.

  • 30days

    Second thoughts

    After a deletion request you can cancel it. Then deletion is final.

  • 7days

    Archive of your data

    The copy you request stays downloadable, encrypted, and is then destroyed.

  • 60days

    Idle sign-in

    If you do not open the app, the device is disconnected and you will need to sign in again.

  • 24months

    Security log

    Sign-ins and operations recorded for security are removed automatically when they expire.

The proof of the consents you gave is kept for the time needed to be able to demonstrate them, as the law requires.

Where the data is

Where, and with whom.

Data is stored on a server in Germany, within the European Union. Health data does not leave the Union.

Who helps us provide the service

  • The server providerSupplies the machine the service runs on. The data it hosts is encrypted.
  • Apple and Google, for push notifications onlyIf you turn notifications on, they receive your phone's identifier and a generic notice to deliver. No clinical data.

No one else receives your data.

Contacts

Who is responsible for your data.

Data controller
LILT — Lega Italiana per la Lotta contro i Tumori · Associazione Provinciale di Palermo APS

The quickest way to exercise your rights is the app: Profile → My data. The full privacy notice is shown when you create your account and is always available under Profile → Consents.