Privacy Policy of OrtoGo Medical Centre Ltd
The security of our patients' data is a top priority for us. In accordance with applicable legal regulations, we have established a policy outlining the principles regarding the collection, processing, and use of personal data by OrtoGo Medical Centre Ltd.
Data Controller
The data controller of your personal data is OrtoGo Medical Centre Ltd, with its registered office at 25 Wiatraczna street, flat U2, 04-384 Warsaw.
Data Protection Officer
We have appointed a Data Protection Officer. For all matters related to the processing of your personal data, you can contact them via:
- Email: [email protected]
- Post: Inspektor Ochrony Danych Osobowych, ul. Wiatraczna 25 lok. U2, 04-384 Warszawa
Source of Personal Data
All the data we have is obtained solely from the patients.
Scope of Personal Data Processing
To provide healthcare services to a patient, we require the following data: first name, surname, PESEL number, and residential address to verify identity before providing the healthcare service, as well as a phone number (in case of appointment cancellation or rescheduling). In accordance with regulations, we create medical documentation for each patient, which includes all information regarding the treatment process. If you have consented to the processing of data for marketing purposes and the sending of commercial information electronically in accordance with the Act of 18 July, 2002 on Providing Services by Electronic Means (information about medical activities, current offers, free visits/tests or discounts) - the information will be sent to the provided email address, via SMS, or by phone.
Purpose of Personal Data Processing
- To verify the patient's identity in order to schedule a medical appointment, particularly through phone appointments, as well as in person at our facilities in Płock and Warsaw.
- In accordance with the Patient's Rights and the Patient's Rights Ombudsman act, we are required as a medical entity to maintain medical documentation.
- We uphold Patient Rights by collecting and archiving declarations in which the patient authorises other individuals to obtain information about their health condition and provided healthcare services.
- We use the patient's phone number to confirm, change, or cancel appointment times, and to inform about preparation for tests or the collection of test results.
- Personal data may be shared with other authorised entities based on legal regulations, as well as with entities with which the controller has entered into data processing agreements related to providing services to the controller (e.g. law firms, laboratories, software providers, accounting firms).
- Ensuring the safety of individuals and property (surveillance monitoring at the Medical Centre on Wschowska Street in Warsaw).
- Handling any potential complaints.
Transfer of Personal Data to Third Countries or International Organisations
The controller does not intend to transfer personal data to a third country or international organisation.
Retention Period of Personal Data
Your personal data will be stored for the period specified by law, i.e., the Act of 6th of November, 2008 on Patient's Rights and the Patient's Rights Ombudsman, Article 29: for 20 years, counting from the end of the calendar year in which the last entry was made, except for:
- medical documentation in the case of a patient's death due to bodily injury or poisoning, which is stored for 30 years, counting from the end of the calendar year in which the death occurred;
- x-ray images stored separately from the patient’s medical documentation, which are stored for 10 years, counting from the end of the calendar year in which the image was taken;
- referrals for tests or doctor's orders, which are stored for 5 years, counting from the end of the calendar year in which the service subject to the referral or order was provided;
- Medical documentation concerning children up to 2 years of age is stored for 22 years.
After the periods mentioned in paragraph 1, the healthcare provider destroys the medical documentation in a way that prevents the identification of the patient concerned.
Additionally, if you have consented to the processing of data for marketing purposes, we will process your data from the moment of consent until it is withdrawn.
Providing Personal Data
Providing personal data is a statutory requirement. The patient is obliged to provide it, and failure to provide the necessary data will result in the refusal of healthcare services.
Rights Regarding Personal Data Protection
The patient has the following rights related to the processing of personal data:
- The right to access their personal data - to rectify, delete, or restrict processing,
- The right to withdraw consent for marketing purposes and the sending of commercial information electronically in accordance with the Act of 18 July, 2002 on Providing Services by Electronic Means,
- The right to lodge a complaint with the supervisory authority responsible for data protection, i.e., the Data Protection Commissioner.