Respecting the privacy of those who have entrusted us with their personal data, we present this Privacy Policy of Medicadent Stomatologia Sp. z o.o. It will provide you with an easy and accessible way to learn how we process your personal data
I . WHO ARE WE?
In accordance with the General Data Protection Regulation of April 27, 2016. (GDPR), the administrators of your personal data are Medicadent Stomatologia Sp. z o.o. with its registered office at 110a, U2 Piątkowska St., 60-649 Poznań (Medicadent) and United Clinics Services Sp. z o.o. with its registered office at 28 Towarowa St., 00-839 Warsaw (UTD) (hereinafter together referred to as Joint Administrators or Administrator).
The Joint Administrators, in accordance with Article 26 (2) sentence 2 of the RODO, inform you that Medicadent is responsible for exercising the rights guaranteed to you by the GDPR, as well as for fulfilling the information obligation towards you. The Joint Administrators have decided to establish a point of contact based in Warsaw (00-839 Warsaw), 28 Towarowa Street, which can be contacted in writing at the address indicated and by email at iod@utdclinics.com for all matters relating to the Joint Administrators’ personal data.
In some cases, the administrator of your personal data may be only Medicadent Stomatologia Ltd. In that case, we will use the term: Medicadent.
For all matters related to the processing of your personal data, you may contact the Administrator’s designated Data Protection Officer by writing to the e-mail address iod.medicadent@utdclinics.com.
II . HOW DO WE PROCESS YOUR PERSONAL DATA?
Depending on the relationship you have with us, we may process your personal data for different purposes. Below you will find detailed information on this subject with a breakdown of the dependencies between you and us.
1. HOW DO WE PROCESS YOUR PERSONAL DATA?
We process your personal data only to the extent necessary for the following processing purposes:
- in order to provide health care services, and to document your health condition and health care services provided – the basis for processing is the performance of the contract for the provision of health care services (Article 6, sec. 1, b GDPR) and the fulfillment of obligations under the laws governing the provision of health care services and the maintenance of medical records (Article 6 sec. 1, c GDPR) in connection with the Law on Medical Activity (Article 3) and the Law on Patient’s Rights and the Ombudsman for Patient’s Rights (Article 24), until the expiration of the period provided for in the Law on Patient’s Rights and the Ombudsman for Patient’s Rights;
- for the purpose of accounting for services provided (Article 6 sec. 1, b of the GDPR) and fulfilling obligations under the provisions of the Accounting Act and tax regulations (Article 6 sec. 1, c of the GDPR), until the expiration of the periods provided for in the law;
- for the purpose of establishing, investigating and defending against potential claims related to the services provided to you – the basis of processing is the legitimate interest of the Administrator (Article 6 sec. 1, f GDPR), until the expiration of the period of limitation of claims;
- for the purpose of direct marketing of our services by email (including newsletters) or telephone – the basis for processing is your consent (Article 6 sec. 1, a GDPR), until you withdraw your consent.
2. IF YOU’RE IN THE RECRUITMENT PROCESS
If you are a candidate for a Medicadent employee or associate, we process your personal data to the extent necessary for the recruitment process and for the purpose of the recruitment process. This data includes your name, date of birth, contact details and information about your education, professional qualifications and previous employment history. We process these data because they are necessary to conclude a contract with you (legal basis Article 6 sec. 1, b GDPR). Provision of this data is necessary to start the recruitment process.
Other personal data you provide to us in your resume or cover letter, such as information about your linguistic skills or interests, we process on the basis of your consent (legal basis Article 6 sec. 1, a GDPR). Their provision is voluntary. Therefore, please add the following clause in your recruitment documents sent to us (CV, e-mail containing your resume or otherwise): I agree that Medicadent Sp. z o.o. and United Clinics Services Sp. z o.o. based in Warsaw, Poland, may process my personal data contained in this document/application for the purpose of recruitment by Medicadent. I have been informed that I may withdraw my consent at any time and that withdrawal will not affect the legality of processing prior to withdrawal.
If you want us to consider your candidacy also for other recruitment processes, add an additional sentence: I also agree to the processing of my personal data for the purposes of future recruitment processes.
We process your personal data for the time necessary to conduct the recruitment, no longer than for a period of 6 months, unless you have agreed to processing also for the purposes of conducting future recruitment processes.
3. IF YOU’RE OUR EMPLOYEE OR ASSOCIATE
If you are an employee of Medicadent or you are a party to a cooperation agreement or a similar civil law relationship, we process your personal data in accordance with the requirements of the provisions of the Labor Code Act of June 26, 1974, in the concluded employment contract and other documents signed during the course of your employment or to the extent necessary for the performance of the civil law contract concluded with you and for the other processing purposes listed below:
- for the performance of the employment contract or civil law contract concluded with you (Article 6 sec. 1, b GDPR) for the duration of the contract, and after its termination for the period after which claims under the contract become time barred. In addition, if you participate in the production of videos, photo and image sessions, multimedia presentations, training and integration meetings, etc., your name, image, voice and/or statements may be used by the Administrator free of charge and repeatedly (unlimited in quantity and territory) for the duration of the concluded contract and for a period of 10 years from the date of termination of this contract;
- for archival and evidentiary purposes in the event of a legal need to prove facts, in particular in the context of complaint, court and administrative proceedings (Article 6 sec. 1, f GDPR), for the duration of the contract concluded with Medicadent and, after its termination, for the period after which claims under the contract become time-barred;
- for archival purposes concerning settlements of wages due to you under the concluded employment contract or civil law contract and tax settlements resulting from the law (Article 6 sec. 1, c GDPR), for the duration of the contract and for 50 years after its termination or 10 years from the end of the calendar year in which you terminated your employment with Medicadent, if you were reported by Medicadent for insurance after December 31, 2018 or an information report was filed, as referred to in Article 4 para. 6a of the Social Security Act of October 13, 1998, in accordance with the provisions of the Social Insurance Fund Pensions Act of December 17, 1998;
- for the purpose of reporting, updating and deleting your data to the Social Insurance Institution and the settlement of social insurance contributions (Art. 6 sec. 1, c GDPR), for the duration of the contract and for 50 years after its termination or 10 years from the end of the calendar year in which you terminated your employment with Medicadent, if you were reported by Medicadent for insurance after December 31, 2018 or an information report was filed, as referred to in Art. 4 sec. 6a of the Act of October 13, 1998 on the social insurance system, in accordance with the provisions of the Act of December 17, 1998 on pensions from the Social Insurance Fund.
Provision of personal data is voluntary, but it is a condition for the conclusion of an employment contract or a civil law contract, as failure to provide it prevents the conclusion of the contracts in question with you.
4. IF WE HAVE OBTAINED YOUR PERSONAL DATA FROM THIRD PARTIES OR ENTITIES
- We may have obtained your personal data from a person close to you – your spouse, partner, parent or legal guardian, ascendant or descendant, or from a third party not related to you, in order to authorize you to inspect medical records or to be contacted by the person from whom we obtained your data. In this case, we process your personal data in order to fulfill our obligations under the laws governing the provision of health services and the maintenance of medical records (Article 6 sec. 1, c GDPR) in connection with the Law on Medical Activity (Article 3) and the Law on Patients’ Rights and Patients’ Rights Ombudsman (Article 24), until the expiration of the period provided for in the Law on Patients’ Rights and Patients’ Rights Ombudsman. Your data will be processed to the extent necessary to achieve the purpose of the processing, which will include at most identification and contact information.
- We may have also obtained your personal data on the basis of a contract for the provision of medical services concluded with our business partner. In that case, we will process your personal data in order to perform the contract in question (Article 6 sec. 1, b GDPR) and to provide medical services to you. The extent of the processing of your personal data and the period for which we will process it will depend on the contract concluded with our business partner.
The source of your personal data is PZU Zdrowie S.A. with its registered office in Warsaw, at Rondo Ignacego Daszyńskiego 4, 00-843 Warsaw.
5. IF YOU’RE A PERSON WHO CORRESPONDS WITH US
If you are a person contacted by Medicadent for a business purpose, or if you are a person who contacts Medicadent for the purpose of soliciting or making an offer of cooperation to Medicadent or for any other business purpose, Medicadent will process your personal data for the purpose of business correspondence, to the extent identical to the content of that correspondence, including, in particular, your name, business email address and telephone number (if provided), and business position (Article 6 sec. 1, f GDPR). Processing will take place for the duration of the correspondence – until its purpose has been achieved – and after its termination for the period after which any claims that may arise from it are barred. Provision of personal data is voluntary but is a prerequisite for correspondence.
6. IF YOU’RE AN EMPLOYEE OR ASSOCIATE OF OUR CONTRACTOR
If you are a person representing the Administrator’s business partner in dealing with the Administrator or in signing a contract with the Administrator, or if you are a person indicated by the business partner in the content of the concluded contract for contact, the Administrator processes your personal data in order to perform the contract concluded with the business partner. The scope of the processed data does not go beyond those provided in the contract or business correspondence and includes, in particular, your name, business email address and telephone number (if provided), and business position (Article 6 sec. 1, b GDPR). Processing will take place for the duration of the contract and, after its termination, for the period after which any claims that may arise therefrom are barred.
7. IF YOU’RE A USER OF THE WEBSITE OR PROFILES ON SOCIAL NETWORKS
When you use profiles on Medicadent’s social networks, you share your personal information with us, which corresponds to the consents you have given to the social network administrators and the levels at which your profiles are completed and made public, such as your name, nickname, image, ID number, email address and others, by interacting with our profiles and the content we publish. On the other hand, if you are a user of our websites, cookies are placed automatically on your device you use to browse the pages. They are safe for your device and do not pose a risk of downloading unwanted/malicious software to your device or getting viruses. For detailed information on the processing of your personal data in connection with your use of Medicadent’s social media pages and cookies, please visit our website in the Cookie Policy.
On our website you also can ask us a question or make a reservation for a service appointment. In this case, we process your personal data to answer your question or register a service at our office, based on our legitimate interest (Article 6 sec. 1, f GDPR).
III . YOUR RIGHTS
In accordance with the provisions of the GDPR, we guarantee you the following rights in connection with the processing of your personal data:
- access to data – you have the opportunity to receive full information about whether, what and how we process your personal data, including receiving a copy of the data we process that concerns you;
- correction (rectification) of data – you can request immediate correction of your personal data that is incorrect and completion of incomplete personal data;
- deletion of data (being forgotten) – you have the right to request the deletion of your personal data from our datasets and those of other controllers of your personal data;
- limitation of processing – you can request the limitation of the processing of your personal data in relation to the amount to the purposes of processing or the time of processing;
- transfer of personal data – you have the right to request to receive in a structured, commonly used machine-readable format your personal data and to have it sent to another controller.
If we process your personal data based on your consent, you may withdraw it at any time. At the same time, this action will not affect the lawfulness of the processing that took place before the withdrawal.
If our processing of your data is based on our legitimate interests, you can object to our processing of your data at any time. Then, after considering your request, we will not be able to process your data about which you have made an objection, unless we can demonstrate that we have a valid legitimate interest in processing your personal data that is legally deemed to override your interests, rights and freedoms, or if we have grounds to establish, assert or defend against claims.
You can submit a request to exercise your rights by writing to iod.medicadent@utdclinics.com.
The request should include data that will allow us to uniquely identify you – at least your name and PESEL number. You should also clearly specify which right you want to exercise. We will endeavor to process your request promptly, no later than within 30 days of its correct submission (including identification data).
In connection with the processing of your personal data, you have the right to lodge a complaint to the supervisory authority, which in Poland is the President of the Office for Personal Data Protection, 2 Stawki Street, 00-193 Warsaw, e-mail: kancelaria@uodo.gov.pl, tel. 22 531-03-00.
IV . NATURE OF DATA PROCESSING AND SHARING
The nature of the processing of personal data includes collecting, capturing, organizing, structuring, storing, adapting or modifying, downloading, viewing, using, disclosing by sending, distributing or otherwise making available, matching or combining, limiting, deleting and destroying.
We share your personal data with our employees and associates to the extent necessary to fulfill the accepted purposes of processing. We may also share them with our partners to whom we outsource health care services, such as prosthetists.
To the extent necessary to achieve the purposes of processing, we may share your personal data with entities with whom we cooperate in providing services related to our operations, e.g., providers of medical record-keeping systems, entities providing accounting, human resources, legal services to us, etc.
Recipients of your personal data may also be:
- persons and entities indicated in Article 26 of the Law on Patients’ Rights and Patients’ Rights Ombudsman, including persons authorized by the Patient to obtain information about his/her health condition or authorized to access medical records;
- authorized authorities, for example: national tax administration authorities, Social Security, inspection authorities;
- other entities, if you have given separate consent.
V . PROFILING AND DATA TRANSFER
Your personal data will not be subjected to profiling by us and will not be used by us to make automated decisions.
The Administrator will not transfer your personal data outside the European Economic Area (which includes the European Union, Norway, Liechtenstein and Iceland) or to international organizations.