RODO - EN
PROCESSING OF PERSONAL DATA AT SALUS SP. Z O.O. (SALUS Health Center and SALUS Hospital)
Dear Patient, Customer of SALUS Health Center and SALUS Hospital!
When providing you with medical services at our clinics and hospital, we are required to process your personal data in many places and in many ways. In order to provide you with absolute safety of both treatment and processing of your personal data, we have applied appropriate safeguards and ensured that they are processed lawfully. At all stages of service, treatment and processing, we exercise special and due care to protect the rights of patients and customers whose data are subject to processing, and in particular we ensure that the data are:
- processed lawfully, reliably and in a transparent manner,
- collected for legitimate purposes,
- not further processed in a way incompatible with purposes stated in the information obligation,
- accurate and, where necessary, updated,
- factually correct and adequate in relation to purposes for which they are processed,
- adequately protected against unauthorized access, destruction, disclosure and unlawful use,
- stored in a form enabling identification of data subjects for no longer than it is necessary to achieve the purpose of processing.
The Controller of your personal data is SALUS Sp. z o.o., 76-200 Slupsk, Zielona Street no. 8
The Data Protection Supervisor overseeing the safety of personal data processing is Tadeusz Wardziak, SALUS Sp. z o.o., 76-200 Slupsk, Zielona Street no. 8, e-mail: iod [AT] salus [DOT] com.pl
We process your data for the following purposes:
Purpose of processing
Scope of data processing
Provision of medical services (including registration and reservation of appointments/tests)
Name and surname
Provision of occupational medicine services
Name and surname
Handling complaints and claims
Name and surname
In addition, your personal data may be processed in order to:
- ensure the safety of persons and property in the area and around the facility of the clinic and hospital at Zielona Street no. 8 in Slupsk - through image recording in the video monitoring system
- fulfill legal obligations arising from generally applicable laws, e.g. accounting or tax law - in financial and accounting documents
- in case of separate and voluntary consent, your data may also be processed for other purposes, including SMS, telephone, e-mail and letter communication related to agreeing on dates and scopes of services provided and assessing the quality of services, as well as in the context of post-accidental investigations concerning accidents at work.
The basis for processing your data is:
- performing our legal obligations to protect the life and health of patients (6(1)(c) of the GDPR)
- protecting the vital interests of patients, i.e. their life and health (6(1)(d) of the GDPR)
- performing contracts with public and private institutions and entities in the field of health care (6(1)(f) of the GDPR)
- pursuit of the legitimate interests of the controller (6(1)(f) of the GDPR)
- consent given by the patient (6(1)(a) of the GDPR)
We may also process personal data under other specific provisions, such as the Electronic Services Act.
Data retention period:
The period of personal data processing depends on the basis and purpose for data processing. Examples of personal data retention periods:
- Personal data related to the provision of medical services will be stored in accordance with legal requirements for this type of service or until SALUS Sp. z o.o. ceases to provide medical services, unless separate provisions of law require their longer processing.
- Personal data processed in connection with the implementation of applicable laws (e.g. for invoicing purposes) will be processed within the period required by generally applicable accounting and tax laws.
- Personal data processed on the basis of consent to the processing of such data will be processed until the consent is withdrawn.
- Personal data processed using cookies and similar technologies will be processed until these files are deleted using browser or device settings and objection to their processing is raised.
Recipients of personal data:
Recipients of personal data processed by us may be subcontractors to whom SALUS Sp. z o.o. entrusted data processing in order to provide medical services to SALUS Sp. z o.o. patients, as well as those who operate and provide us with ICT systems used in the provision of our services.
Rights of data subjects:
Each SALUS Sp. z o.o. patient whose personal data we process have rights related to this processing. The possibility of exercising the rights below depends on the legal basis of personal data processing.
Right of access to data
The data subject has the right to obtain confirmation from us as to whether personal data relating to him/her are being processed.
Right to rectify data
The data subject has the right to request us to immediately rectify personal data concerning him/her that are incorrect.
Right to be forgotten
The data subject has the right to request us to immediately delete personal data concerning him/her, if one of the following circumstances applies:
- consent to the processing of personal data has been withdrawn and there is no other basis for processing,
- made an effective objection to the processing,
- personal data were processed unlawfully,
- personal data must be deleted in order to fulfill the legal obligation,
- data were collected in connection with the offering of information society services.
Right to restrict processing
The data subject has the right to request us to restrict processing in the following cases:
- the data subject challenges the accuracy of personal data - for a period allowing us to verify the accuracy of personal data;
- the processing is unlawful and the data subject objects to the deletion of personal data, requesting instead that their use be restricted;
- we no longer need personal data for the purposes of processing, but they are needed by the data subject to establish, exercise or defend claims;
- the data subject raised an objection under Article 21(1) of the GDPR to the processing - until such time as it is determined whether the legitimate grounds on the part of the controller override the data subject's grounds for objection.
Right to object
The data subject has the right to object at any time - on grounds relating to his/her particular situation - to the processing of personal data concerning him/her on the basis of Article 6(1)(f) (legitimate interest of the controller), including profiling. We shall then no longer be permitted to process those personal data unless we can demonstrate the existence of compelling legitimate grounds for the processing, which override the interests, rights and freedoms of the data subject, or grounds for the establishment, exercise and defense of claims.
The patient may also lodge a complaint with the President of the Office for Personal Data Protection, if he/she believes that the processing of his/her data is in violation of the law.
Is it mandatory to provide the data?