Privacy policy
How DrillDown S.r.l. processes the personal data of professionals and patients who use Careness, including special categories of health and biometric data. Data Controller: DrillDown S.r.l., viale Isonzo 8, 20135 Milano (MI).
Last updated: 2026-09-24
Notice on the processing of personal data
pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR)
This document describes the manner in which personal data is processed in connection with the use of the following services operated by Drilldown S.r.l. and making up the Careness Ecosystem:
• Careness App: Meal plans (hereinafter, the “App”): mobile application intended for End Users for the management of shopping lists, recipes, nutritional profile, loyalty cards, food-saving and, in Patient Mode, for nutritional monitoring, the tracking of anthropometric parameters and the receipt of personalised plans;
• Tuduu Platform (hereinafter, the “Platform”): professional web platform accessible at platform.tuduu.it, intended for nutrition and fitness Professionals for the management of their own patients/clients, the creation and assignment of nutritional and training plans, the monitoring of parameters and the generation of linking codes;
• Careness Care Service (hereinafter, “Care”): intermediation service accessible at careness.it/care which puts End Users in touch with nutrition professionals belonging to the Careness network;
• Careness website (hereinafter, the “Site”): the institutional and informational site careness.it and its sub-pages.
The App, the Platform, the Care Service and the Site constitute an integrated ecosystem (hereinafter, jointly, the “Services” or the “Ecosystem”) designed to connect nutrition and fitness professionals with users/patients in a pathway of nutritional and physical well-being monitoring.
1 – Data Controller
The Data Controller is Drilldown S.r.l., with registered office in Milan, Viale Isonzo no. 8, tax code/VAT number 12392590969 (hereinafter, “Drilldown” or the “Controller”). The services described in this privacy notice are offered under the “Careness” trade mark and delivered through the proprietary technology platform “Tuduu” (“powered by Tuduu”).
The Controller may be contacted at any time free of charge:
• E-mail: info@tuduu.it
• Certified e-mail (PEC): drilldownsrl@pec.it
• Support: supporto@tuduu.it
2 – Definitions and roles
Professional: the nutritionist, dietician physician, nutrition biologist, personal trainer, athletic trainer or other qualified professional who uses the Platform to manage and monitor their own patients/clients.
Patient/Linked user: the natural person who accesses the App in Patient Mode by means of a unique code generated by the Professional on the Platform.
Standalone user: the natural person who uses the App in Basic Mode, without being linked to a Professional, for the personal monitoring of their own nutrition and well-being.
Care User: the natural person who accesses the Care Service in order to identify and get in touch with a nutrition professional belonging to the Careness network.
Care Professional: the nutrition professional belonging to the Careness network who receives referrals of potential patients through the Care Service.
2.1 – Controllership relationships
Drilldown acts as Data Controller for: (i) the data collected and processed in connection with the operation of the App, the Platform, the Care Service and the Site; (ii) the registration and professional data of the Professionals; (iii) the data of Standalone users; (iv) the data of Care Users collected through the Care Service; (v) the data processed for marketing, profiling and statistical analysis purposes.
The Professional who accesses the data of their own patients through the Platform acts as an independent Data Controller for the purposes of care, nutritional diagnosis, monitoring and prescription. Drilldown makes the technical infrastructure available but does not access the content of the nutritional plans or the clinical data for its own care purposes.
The Care Professional who receives the contact data of a Care User through the Care Service becomes an independent Data Controller from the moment of receipt, for the purposes connected with their own professional activity. Drilldown transmits solely the data strictly necessary for contacting and taking charge of the user.
3 – Categories of personal data processed
3.1 – Browsing data
The IT systems used by the Services acquire, in the course of their normal operation, data whose transmission is implicit in the use of web protocols: IP addresses, date and time of access, pages visited, information on the device and on the operating system.
3.2 – Registration and identification data
For Patients and Standalone users (App): first name, surname, sex, date of birth, e-mail address, access credentials. For linked Patients: unique code generated by the Professional.
For Professionals (Platform): first name, surname, e-mail address, telephone number, access credentials, data relating to professional qualification (title, registration number with the professional register where applicable, specialisation), billing data (company name, VAT number, tax code, address of the practice/professional office), SDI code or certified e-mail address (PEC) for electronic invoicing.
For Care Users: first name, surname, e-mail address, telephone number, information on nutritional needs and dietary preferences provided voluntarily through the Care form.
3.3 – Health data (special categories under Article 9 GDPR)
The Services process data capable of revealing the User’s state of health, including:
• Personalised nutritional plans created by the Professional on the Platform and assigned to the Patient through the App.
• Anthropometric data entered manually or measured through integrated tools (weight, height, BMI, body circumferences, body composition, fat/lean mass).
• Dietary preferences and restrictions attributable to health conditions (allergies, intolerances, metabolic diseases, specific dietary regimes).
• Health and well-being objectives declared by the User.
• Change over time of the monitored parameters, history of measurements and progress.
• Annotations and notes entered by the Professional in the Platform relating to the Patient’s nutritional pathway.
• Personalised training plans and related performance parameters (where the Fitness Module is activated).
3.4 – Biometric data and body images
The App integrates tools that allow the collection of anthropometric data through photographs of the User’s body (exclusively rear and side shots, without capturing the face), including: three-dimensional body scan, image-based body composition analysis and visual monitoring of physical change over time. Such data, being derived from images of the body and used to identify or monitor the physical condition of the person, may qualify as biometric data and/or data concerning health within the meaning of Article 9 GDPR and are subject to strengthened safeguards.
The photographs and the data resulting from the anthropometric analysis are processed with the following safeguards:
• They are acquired solely with the User’s explicit consent for each shooting session.
• They are stored in encrypted form on the Controller’s servers located in the EU/EEA.
• They are accessible solely to the User and, where linked, to the relevant Professional through the Platform.
• They may be deleted by the User at any time directly from the App.
• They are in no case transferred to third parties for commercial purposes, nor used for the training of algorithms without express authorisation.
3.5 – Platform usage data (Professionals)
For Professionals who use the Platform, Drilldown also processes:
• Usage data: access frequency, functions and modules used, number of patients/clients managed, plans created.
• Activity logs: record of accesses to patient data, operations carried out on the Platform (for security and audit purposes).
• Data relating to the subscription and to payments: type of plan subscribed to, payment history, payment method (full credit card data is processed solely by Stripe).
3.6 – Data originating from third-party applications
Subject to the User’s explicit consent, the App may integrate with third-party applications (for example Apple Health / HealthKit, Google Health Connect) in order to import or export data relating to health and physical activity. The data originating from such integrations is processed with the same safeguards provided for health data and is never used for advertising or data mining purposes, in compliance with Apple HealthKit policies (section 5.1.3 of the App Review Guidelines).
3.7 – Data collected through the Care Service
Within the Care Service, Drilldown collects from the Care User: contact data (first name, surname, e-mail, telephone) and information on nutritional needs and dietary preferences voluntarily expressed by the User. Some of this information may fall within the special categories of data under Article 9 GDPR (data concerning health, preferences capable of revealing religious or philosophical beliefs). The data collected through Care is transmitted solely to the Care Professional selected by the User and is not used for other purposes.
3.8 – Location data
Only subject to specific consent, the Services may process approximate location data derived from the IP address of the device.
3.9 – Data collected through cookies and similar technologies
For details relating to the cookies used on the Site and on the Platform, please refer to the Cookie Policy available at careness.it.
4 – Purposes and legal bases of the processing
Personal data is processed for the following purposes:
• a) Delivery of the Services and operation of the App and the Platform. Includes: registration and authentication; profile management; Professional-Patient linking by means of a unique code; creation, assignment and display of nutritional and training plans; monitoring of the change in parameters; subscription management. Legal basis: performance of the contract (Article 6(1)(b) GDPR). For health and biometric data: explicit consent (Article 9(2)(a) GDPR). Provision is necessary; refusal prevents use of the Services.
• b) Collection and processing of anthropometric data through images. Includes the acquisition of body photographs for the measurement of anthropometric parameters. Legal basis: explicit and specific consent (Article 9(2)(a) GDPR), requested at the time of each session. Optional.
• c) Integration with third-party applications. Import/export of health and physical activity data. Legal basis: explicit consent (Article 9(2)(a) GDPR), which may be withdrawn at any time.
• d) Management of the contractual relationship with Professionals. Management of the Platform account, invoicing, assistance, verification of professional qualification. Legal basis: performance of the contract (Article 6(1)(b) GDPR) and legal obligations (Article 6(1)(c) GDPR).
• e) Care Service – nutritional intermediation. Collection of the Care User’s data, matching with Care Professionals, transmission of the data to the selected Professional. Legal basis: for contact data, performance of the service (Article 6(1)(b) GDPR); for special category data, explicit consent (Article 9(2)(a) GDPR).
• f) Security, audit and prevention of abuse. Logging, monitoring, prevention of unauthorised access, data breach management. Legal basis: legitimate interest (Article 6(1)(f) GDPR) and legal obligation (Article 6(1)(c) GDPR).
• g) Statistical analysis and improvement of the Services. Analysis of browsing and usage data in aggregate and anonymous form. Legal basis: legitimate interest (Article 6(1)(f) GDPR).
• h) Marketing and promotional communications. Sending of newsletters, informational and promotional communications. Legal basis: the User’s consent (Article 6(1)(a) GDPR), which may be withdrawn. Soft spam under Article 130(4) of the Italian Privacy Code (Codice Privacy).
• i) Profiling of nutritional habits. Analysis of dietary preferences for personalised content. Legal basis: explicit consent (Article 6(1)(a) and, for health data, Article 9(2)(a) GDPR).
• j) Disclosure of data to commercial Partners. Transfer to partners for their own marketing. Never health, biometric or professional data. Legal basis: the User’s consent (Article 6(1)(a) GDPR).
• k) Compliance with legal obligations. Regulatory, accounting and tax obligations. Legal basis: legal obligation (Article 6(1)(c) GDPR).
5 – Manner in which consent for health data is collected
Given the particularly sensitive nature of the data processed, consent for the processing of special categories of data is collected in a form that is:
• Explicit: by means of separate, non-pre-ticked opt-in check boxes for each purpose.
• Specific: separate for each purpose, with three granular levels: (i) consent to the linking with the Professional; (ii) consent to anthropometric measurement through photography; (iii) consent to integrations with external platforms.
• Informed: preceded by this privacy notice, made available and consultable before collection.
• Freely given: the refusal of one or more consents does not preclude access to the basic functions that do not require special category data.
• Documented: the evidence of consent (timestamp, version of the privacy notice, details of the flags activated) is retained by the Controller in accordance with the accountability principle.
For the Care Service, consent to the processing of special category data (nutritional needs) is collected through the online form, with a separate check box and a dedicated privacy notice, before the data is transmitted to the Care Professional.
6 – Professional-Patient relationship and respective responsibilities
6.1 – How the link works
The Professional accesses the Platform and generates a unique code for each Patient. The Patient enters that code in the App in order to activate Patient Mode. From that moment, the Professional may view on the dashboard the Patient’s data (anthropometric parameters, change over time, photographs where authorised) and assign nutritional and/or training plans which the Patient receives directly in the App.
6.2 – Controllership of the Professional
In relation to the Patient data accessible through the Platform, the Professional acts as an independent Data Controller. In particular, the Professional is required to:
• Provide their own patients with an independent privacy notice relating to the processing carried out within the care relationship.
• Collect, where necessary, consent for the processing of health data within their own professional activity.
• Process the data solely for the declared professional purposes and in compliance with professional ethics.
• Adopt adequate security measures and ensure confidentiality in compliance with professional secrecy.
• Not extract, copy or transfer patient data from the Platform for purposes unconnected with the care activity.
6.3 – Role of Drilldown
Drilldown, as Controller for the operation of the Services, makes the technical infrastructure available and ensures security, the segregation of data between different Professionals and the integrity of communications between the App and the Platform. Vis-à-vis the Professional, Drilldown also acts as Data Processor under Article 28 GDPR, limited to the storage and processing of patient data, on the terms governed by Annex 1 to the General Conditions of the Careness Ecosystem.
6.4 – Termination of the relationship
In the event of termination of the Professional-Patient relationship or of deletion of the Professional’s account, the link is deactivated. The Patient’s historical data (measurements, photographs) remains accessible to the Patient in the App. The data held on the Platform is retained for the period indicated in Article 8 and subsequently deleted.
6.5 – Data flow in the Care Service
In the Care Service, the flow of personal data is as follows:
• Collection: the Care User completes the online form at careness.it/care, providing contact data and information on their own nutritional needs. Drilldown is the Controller of this collection.
• Matching: Drilldown identifies one or more Care Professionals compatible with the needs expressed by the User.
• Transmission: subject to the User’s explicit consent, the contact data and nutritional needs are transmitted to the selected Care Professional (data minimisation principle).
• Independent controllership: from the moment of transmission, the Care Professional becomes an independent Controller for their own professional purposes.
• Retention: Drilldown retains the Care User’s data for a maximum of 6 months from transmission, save for legal obligations.
7 – Categories of recipients
Personal data may be disclosed to the following categories of recipients:
• Data Processors: IT and hosting service providers (Microsoft Azure, EU region), technical maintenance, analytics services, providers of the body scan and anthropometric analysis service (SizeYou S.r.l., and where activated 3DLook Inc.), payment provider (Stripe Inc.).
• The relevant Professional: solely for Patients linked by means of a unique code, within the limits of the necessary data.
• Care Professional: solely for Care Users, within the limits of the contact data and nutritional needs, subject to consent.
• Commercial partners: only subject to explicit consent and limited to ordinary data (never health, biometric or professional data).
• Competent authorities: where required by legal obligations.
The up-to-date list of sub-processors is available in Annex 2 to the General Conditions of the Careness Ecosystem.
Transfers outside the EEA. Processing takes place mainly on servers in the EU region (Microsoft Azure). Any transfers to third countries take place in compliance with Chapter V of the GDPR, on the basis of: (i) an adequacy decision (e.g. the EU-US Data Privacy Framework); (ii) standard contractual clauses (SCC); or (iii) other appropriate safeguards under Articles 44 et seq. GDPR.
8 – Data retention periods
In accordance with the storage limitation principle (Article 5(1)(e) GDPR), personal data is retained for the time strictly necessary to achieve the purposes for which it is processed and, where applicable, for the period necessary to comply with legal obligations and to protect the Controller’s rights in legal proceedings. Pursuant to Article 13(2)(a) GDPR, where it is not possible to indicate a fixed term, the criteria used to determine the retention period are set out below:
| Type of data | Retention criterion |
|---|---|
| Browsing / session data | Limited period, for security and service operation purposes |
| Registration data (End Users) | For the duration of the relationship and for the subsequent period necessary to manage compliance and to protect rights |
| Registration data (Professionals) | For the duration of the relationship; accounting and tax data is retained for 10 years (legal obligation) |
| Health data and nutritional plans | For the duration of the relationship and for the period necessary to establish or defend a right |
| Body images (photographs) | For the time necessary to monitor the pathway; |
| Anthropometric measurements (numerical) | For the duration of the relationship and for the period necessary to establish or defend a right |
| Data from third-party integrations | Until consent is withdrawn or the connection is severed |
| Platform access logs | Limited period, for security and audit purposes |
| Consents and opt-in evidence | For the time necessary to demonstrate the lawfulness of the processing (accountability) |
| Data for marketing purposes | Until consent is withdrawn, with periodic review |
| Care User data | For the time necessary for the intermediation, after which it is deleted |
| Data for legal obligations | 10 years (legal obligation for accounting and tax data) |
At the end of the periods indicated, or when the data is no longer necessary in relation to the purposes, it is deleted or irreversibly anonymised, without prejudice to legal obligations.
9 – Security measures
Taking into account the nature of the data processed, the Controller adopts technical and organisational security measures appropriate to the risk pursuant to Article 32 GDPR. Such measures are subject to review and progressive strengthening in line with the evolution of the service and of the risks; by way of example:
• Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
• Hosting on Microsoft Azure infrastructure (EU region), which adopts internationally recognised security standards (e.g. ISO 27001, SOC 2).
• Role-based access control (RBAC) and user authentication mechanisms.
• Logical segregation of data: each Professional accesses only the data of their own patients.
• Specific measures for body images: encryption at rest, restricted access, no use for the training of algorithms without authorisation.
• Periodic data backups and restore procedures.
• Logging and monitoring of accesses to health data.
• Authorised personnel bound by confidentiality obligations and made aware of data protection.
• Security verification activities, including through testing, as required.
• Procedures for incident management and for the notification of data breaches pursuant to Articles 33-34 GDPR.
10 – Impact assessment (DPIA)
The Controller has carried out a Data Protection Impact Assessment (DPIA) pursuant to Article 35 GDPR, taking into account: the nature of the data processed (health, biometric, body images); the use of innovative technologies for anthropometric analysis; the systematic monitoring of parameters through the App and the Platform; the linking between different application environments; and the flow of data to third parties in the Care Service. The outcomes of the DPIA are available on request.
11 – Rights of Data Subjects
Pursuant to Articles 15-22 GDPR, every User and every Professional has the right to:
• Access (Article 15): obtain confirmation of the existence of the processing and access their own data.
• Rectification (Article 16): obtain the correction of inaccurate data.
• Erasure (Article 17): obtain the erasure of their own data. Deletion of the account from the Platform entails the deactivation of the links with the Patients.
• Restriction (Article 18): obtain the restriction of processing.
• Portability (Article 20): receive their own data in a structured format. The App and the Platform offer export functions (CSV, JSON, PDF).
• Objection (Article 21): object to the processing on legitimate grounds, including direct marketing.
• Withdrawal of consent: withdraw at any time the consents given, without prejudice to the lawfulness of the previous processing.
• Not to be subject to automated decisions (Article 22): not to be subject to decisions based solely on automated processing.
These rights may be exercised by contacting the Controller at the contact details indicated in Article 1, without formalities and free of charge.
The User and the Professional also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) (www.garanteprivacy.it).
Note: for data processed by the Professional or by the Care Professional as an independent Controller, requests to exercise these rights must be addressed directly to the relevant professional.
12 – Minors
The Services are not intended for persons under 18 years of age. The Controller does not knowingly collect personal data of minors. Should the Controller become aware that it has inadvertently collected data of a minor, it will proceed to delete it promptly.
13 – Updates and amendments
The Controller reserves the right to amend, supplement or update this privacy notice from time to time. Amendments will be communicated by means of an in-app notification, a notification on the Platform and an update of the Site. In the event of substantial amendments to the purposes or means of processing of health data, a new explicit consent will be requested.