Privacy policy

PRIVACY POLICY

 

Last updated on 9 August 2021.  

 Scope of this policy

This policy describes how Spektrum Sp. z o.o. ul. Zaolziańska 4, 53-334 Wrocław, webpage: www.spektrum.wroc.pl, collects, uses, consults or otherwise processes an individual's personal data in the context of use of the medical services and the usage of webpage (hereinafter the "Service"). 

This policy includes a description of your data protection rights, including a right to object to some of the processing activities we carry out.

In this privacy policy „we" or "us" refers to SPEKTRUM Sp. z o.o. ul. Zaolziańska 4, 53-334 Wrocław. We are registered at District Court for Wrocław - Fabryczna, VI Commercial Division of KRS under KRS 0000016751, NIP 8971658338, REGON 932632951, phone number +48 71 345 31 41, e-mail address biuro@spektrum.wroc.pl We will process your personal data as a data controller.

This policy is to be read as consistent with the other applicable rules, such as collecting and processing the personal data received from you only for the preparation of information, certificates, medical documentation.

For the purpose of this policy, the following term "Data Protection Legislation" shall mean the Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the "GDPR"), as well as any legislation and/or regulation implementing or created pursuant to the GDPR and the e-Privacy legislation, or which amends, replaces, re-enacts or consolidates any of them, and all other national applicable laws relating to processing of personal data and privacy that may exist under applicable law, in particular The Polish Act of 10 May 2018 on protection of personal data.

For the purpose of this policy, "controller", "processor", "third party", "supervisory authority", "personal data", "processing", "data subject", shall have the meanings set out in the applicable Data Protection Legislation.

Your personal data may be processed by the administrator for the purpose of: health prophylaxis, medical diagnosis, treatment and provision of health care;  keeping medical records;  ensuring the continuity of healthcare services;  performance of the contract for the provision of services;  resulting from legitimate interests pursued by the administrator, eg for contact regarding confirmation, amendment or cancellation of a planned visit or medical procedure;ü  marketing activities, if you give your separate consent.

On what legal basis do we process your personal data?Your personal data is processed on the basis of Article 9 paragraph 2 point (h) of Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data ("GDPR"), which provides that the processing of special categories of personal data concerning health is necessary for the purposes of preventive healthcare, medical diagnosis, the provision of health treatment or the management of health services. In case of data processing for marketing purposes, the legal basis is your separate, explicit consent. Moreover, following provisions of GDPR are the basis of data processing: 

  1. Art. 6. sec. 1 point a: the data subject has given consent to the processing of his or her personal data for one or more specific purposes.
  2. Art. 6 sec. 1 point b:  processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
  3. Art. 6. sec. 1 point c: processing is necessary for compliance with a legal obligation to which the controller is subject.
  4. Art. 6. sec. 1 point d: processing is necessary in order to protect the vital interests of the data subject or of another natural person.

Who can receive your personal data?

Personal data entered into the contact form or sent directly to the e-mail addresses provided on the website www.spektrum.wroc.pl are not transferred to third parties, except for the cases indicated in the Personal Data Security Policy, i.e. made available to government authorities or law enforcement officers, if it is required by them and if it is required by law, or to other entities, if it is required by the protection of the legal interest of the data controller, only in cases provided for by law.

Is your personal data used for direct marketing communications?

If you have explicitly consented, we may, from time to time, contact you with information about our Service.  Consent to marketing communication can be withdrawn at any time by contacting us at the end of the Policy.

How long is your personal data stored?

We will retain your information only for the period necessary to fulfil the purposes outlined in this Privacy Policy, unless a longer retention period is required by law.

How is your personal data shared with third parties?

We only share or disclose information as described herein, including with third parties. The transfer of data takes place in a safe manner, with the obligation of the entity receiving the data to secure them and maintain confidentiality.

Your personal data will also be shared with government authorities and/or law enforcement officials if required for the purposes above, if mandated by law or if required for the legal protection of the data controller legitimate interests in compliance with applicable laws.

Is your personal data transferred outside the European Economic Area (EEA)?

Your personal data will not be transferred outside the EEA. 

What are your rights?

Once you have provided your personal data, several rights are recognized under the Data Protection Legislation, which you can in principle exercise free of charge, subject to statutory exceptions. In particular, you have the following rights:

Right to withdraw consent: if your personal data is processed on the basis of you consent, you have the right to withdraw your consent at any time you choose and on your own initiative. You can do so in any form, in particular by personal contact in offices of SPEKTRUM Sp. z o.o., ul. Zaolziańska 4, 53-334 Wrocław or by phone number +48 71 345 31 41, e-mail address biuro@spektrum.wroc.pl

The withdrawal of your consent will not affect the lawfulness of the collection and processing of your data based on your consent up until the moment of withdrawing your consent. 

  • Right to access, review, and rectify your data: you have the right to access, review, and rectify your personal data. You may be entitled to ask us for a copy of your information, to review or correct it if you wish to review or rectify any information like your name, email address, post address and other data, you can easily do so by personal contact in offices of the Company or via e-mail: biuro@spektrum.wroc.pl.
  • Right to erasure: you have the right to erasure of all the personal data processed by as described herein in case it is no longer needed for the purposes for which the personal data was initially collected or processed, in accordance with the Data Protection Legislation.  
  • Right to object or restriction of processing: under certain circumstances described in the Data Protection Legislation, you may ask for a restriction of processing or object to the processing of your personal data. 
  • Right to object to processing for direct marketing: where your personal data is processed for direct marketing purposes, you may object to such processing, in any form.
  • Right to data portability: you have the right to receive the Personal Data processed in a format which is structured, commonly used and machine-readable and to transmit this data to another service provider.

These rights may be limited, for example if fulfilling your request would reveal personal data about another person, or if you ask us to delete information which we are required by law to keep or have compelling legitimate interests in keeping.

To exercise any of these rights, you can get in touch with us using the details set out below.

If you have unresolved concerns, you have the right to lodge a complaint with an EU data protection authority where you live, work or where you believe a breach may have occurred. In Poland, such authority is President of the Office for Personal Data Protection, ul. Stawki 2, 00-193 Warszawa, POLAND, phone +48 22 531 03 00, e-mail: kancelaria@uodo.gov.pl.

What security measures are put in place?

Appropriate technical and organisational measures are implemented in order to ensure an appropriate level of security of your personal data, including but without limitation: personal data are stored only in IT systems protected against unauthorized access by third parties (password protected computer, anti-virus and anti-malware software, network protection using a firewall), and personal data recorded on paper, are in a locked room, accessible only to persons authorized by SPEKTRUM Sp. z o.o.

In the event personal information is compromised as a result of a security breach and where the breach is likely to result in a high risk to the rights and freedoms, we will make the necessary notifications, as required under the Data Protection Legislation.

Changes to this policy

We reserve the right to modify and update this privacy policy from time to time. We will bring these changes to your attention should they be indicative of a fundamental change to the processing or be relevant to the nature of the processing or be relevant to you and impact your data protection rights.

How can you be contacted?

Questions, comments, remarks, requests or complaints regarding this Privacy Policy are welcome and should be addressed to the Personal Data Protection Officer, Mr. Sebastian Stecyszyn, who can be contacted by calling telephone number +48 71 345 31 41 or by the following e-mail address: iod@spektrum.wroc.pl and by correspondence at: ul. Zaolziańska 4, 53-334 Wrocław, POLAND.

 

Contracts with insurers

  • NFZ - Narodowy Fundusz Zdrowia
  • Compensa