Your account
- First and last name, email
- Date of birth and sex (you may leave it unspecified)
- App language
- Tax code, phone and address, if you give them to the front desk
Privacy · Regulation (EU) 2016/679 — GDPR
TeleLILT is the LILT Palermo app for prevention and care: bookings, messages with the people who look after you, reports, video visits. It was designed around the GDPR from day one: data is encrypted, only your care team can see it, and you can download or delete it yourself, whenever you want.
What you see
What the database holds
9f3a·c21e·77b0·4d1ab7d0·48aa·e3f9·015c02ce·e9f1·6ab4·d870The app
One place to stay in touch with LILT Palermo, from the check-up reminder to the video visit.
Book a visit in person or by video, answer proposed times and get a reminder the day before.
Write to the professionals who follow you and to the front desk. Photos and documents can be attached in the conversation.
Receive reports and upload your tests: they stay encrypted, opened only by you and your care team.
Fill in your medical history once and record measurements at home: your doctor sees them before the visit.
A personal plan of recommended check-ups, with a reminder when the time comes.
Talk to your doctor by video. The call is encrypted device to device and is never recorded.
Your data
Only what is needed to give you the service. Nothing is collected "just in case" or for future uses.
The app is for adults only. Informational messages arrive only if you asked for them, and you can turn them off at any time.
Protection
Data protection is not an add-on: it is how the app is built.
Access keys live in the system's protected storage and never end up in phone backups.
Every exchange with the server travels over an encrypted connection (TLS). Never in clear text.
Each piece of personal data is encrypted individually before it is stored.
Only the professionals on your care path see it, after two-step verification.
AES-256-GCM, with a different key for each kind of data. There is not a single name in clear text in the database.
To find a patient the system compares encrypted fingerprints, not readable text.
Reports and attachments are encrypted one by one. Deleting a file means destroying its key too.
Access is role-based: doctors and front desk see only the patients in their remit. Signing in always requires two-step verification.
A tamper-evident log records every consultation of your data.
The app's access keys last a few minutes and renew themselves. Passwords are kept only as a fingerprint (Argon2id).
In backups the data stays encrypted: without the keys, kept separately, it is unreadable.
Your phone shows only a generic notice, such as "You have a new message". Never clinical data.
Our promises
Your rights
The GDPR gives you precise rights. In TeleLILT the most important ones are exercised right in the app, with no forms and no waiting.
Request the full archive: a readable summary, the data in a standard format, your documents and messages. It is ready in a few minutes, you confirm with your password and it stays downloadable for 7 days.
In the app ProfileMy dataRequest a copy
Request the deletion of your account in the app. You have 30 days to change your mind; then data, documents and encryption keys are destroyed. Only the proof of the consents you gave and, until it expires, the security log remain; the log holds no clinical data.
In the app ProfileMy dataDelete my account
Every consent is as easy to withdraw as it is to give. If you withdraw the one for health data, care features switch off at once until you give it again.
In the app ProfileConsents
You choose, category by category, which notices to receive and on which channel. Only those essential to the service stay on, such as an appointment confirmation.
In the app ProfileNotifications
See the devices connected to your account and disconnect them with one tap. The archive of your data also includes the access log, with the role of whoever consulted it.
In the app ProfileSecurityConnected devices
Personal details are updated by the front desk at your request: just write to them from the app or contact the office.
In the app MessagesFront desk
Retention
Data stays as long as it is needed to care for you. Everything else has an expiry date.
∞until you decide
They stay for the whole duration of the service. You delete them whenever you want in the app.
30days
After a deletion request you can cancel it. Then deletion is final.
7days
The copy you request stays downloadable, encrypted, and is then destroyed.
60days
If you do not open the app, the device is disconnected and you will need to sign in again.
24months
Sign-ins and operations recorded for security are removed automatically when they expire.
The proof of the consents you gave is kept for the time needed to be able to demonstrate them, as the law requires.
Where the data is
Data is stored on a server in Germany, within the European Union. Health data does not leave the Union.
No one else receives your data.
Contacts
The quickest way to exercise your rights is the app: Profile → My data. The full privacy notice is shown when you create your account and is always available under Profile → Consents.