This Policy concerns cookies and relates to the ways they are used on the website receptanacito.pl/en (hereinafter also referred to as the “Website”).
General Information, Contact Details
The data controller in accordance with the GDPR is Futuremed spółka z ograniczoną odpowiedzialnością based in Warsaw, Aleja „Solidarności” 117 / 207, 00-140 Warsaw, registered in the register of entrepreneurs of the National Court Register maintained by the District Court for the capital city of Warsaw in Warsaw, XII Commercial Division of the National Court Register, under KRS No.: 0001086342, NIP: 5252991458, REGON: 527690979, email address kontakt@receptanacito.pl (hereinafter also referred to as the “Controller”).
If you have any questions regarding the processing of your personal data, you may at any time contact the Controller at the email address kontakt@receptanacito.pl.
What Are Cookies?
Cookies mean IT data, in particular text files, stored in the end devices of users intended for using websites. These files allow recognition of the user’s device and appropriately display the website adjusted to their individual preferences. Cookies typically contain the name of the website they originate from, the storage time on the end device, and a unique number.
Cookies do not generally allow identifying natural persons but only the identification of the computer and browser. However, due to the care the Controller applies to protect personal data, protective measures applicable to personal data are applied to these files. Storing cookies in the browser’s memory does not negatively affect your software or hardware. A cookie allows the information contained in it to be read only by the server from which it originates.
The Controller makes every effort to ensure that the use of cookies on the Website is safe for your device. Using cookies does not mean obtaining confidential information from you. Storing or accessing cookies does not cause configuration changes on your device.
Upon your first visit to the Website using a particular device, information about the use of cookies is displayed along with a request for your consent to use them.
What Are Cookies Used For?
Cookies are used to adapt the Website content to your preferences and to optimize the use of the Website, including:
- recognizing users’ devices and properly displaying the Website;
- adjusting and optimizing the Website to users’ needs, remembering preferences concerning the Website (language, color, layout, content arrangement);
- creating anonymous, aggregated statistics that help understand how users use the Website, which allows improving its structure and content, excluding personal identification of the user;
- ensuring security and reliability of use of the Website.
What types of cookies are used on the Website and how long are they stored?
The following types of cookies are used on the Website:
- session cookies – these are temporary information stored in the browser memory until the session ends, i.e., the browser is closed. These cookies operate during your visit to the Website and are then automatically deleted. They are necessary for the proper functioning of some functionalities on the Website;
- persistent cookies – after visiting the Website, they remain on your device along with saved information, e.g., about your configured computer setup, and restore settings during your subsequent visits, making the Website easier for you to use.
Deleting cookies
- By default, software used to browse websites allows placing cookies on the end device. These settings can be changed to block automatic handling of cookies in the web browser settings or to inform about each sending of cookies to the user’s device. Detailed information on managing cookies is available in the software settings (web browser).
- Limiting the use of cookies may affect some functionalities available on the Website.
How to change browser settings to manage or completely block cookies?
- Firefox: http://support.mozilla.org/pl/kb/ciasteczka
- Chrome: http://support.google.com/chrome/bin/answer.py?hl=pl&answer=95647
- Internet Explorer: http://windows.microsoft.com/pl-PL/windows7/How-to-manage-cookies-in-Internet-Explorer-9
- Safari: http://support.apple.com/kb/HT1677?viewlocale=pl_PL&
Privacy Policy
Pursuant to Articles 13 and 14 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as the “GDPR”), we are obliged to provide information to persons whose personal data we process. This information covers the main aspects related to the processing of personal data of users of the Futuremed Sp. z o.o. website, available at www.receptanacito.pl/en (hereinafter also the “Website”), persons using health services provided by the Controller, and persons cooperating with the Controller in other matters.
General Information, Contact Details
- The personal data controller under the GDPR is Futuremed spółka z ograniczoną odpowiedzialnością based in Warsaw, Aleja „Solidarności” 117 / 207, 00-140 Warsaw, entered into the register of entrepreneurs of the National Court Register maintained by the District Court for the Capital City of Warsaw in Warsaw, XII Commercial Division of the National Court Register, under KRS No.: 0000991552, NIP: 5252924491, REGON: 523172957, email: kontakt@receptanacito.pl (hereinafter also the “Controller”).
- In matters concerning personal data protection and the exercise of rights arising from the GDPR, you may contact the Data Protection Officer – Karolina Zakrzewska, email: iod@futuremed.pl. The Data Protection Officer answers all questions regarding data processing and the exercise of rights (access, correction, restriction, deletion, objection, data portability).
Main Principles
- The protection of your personal data is of particular importance to us. We take all due care to keep your personal data confidential and secure, especially properly protected against access by unauthorized persons.
- The Controller processes your personal data only to the extent necessary for the functioning of the Website, providing electronic services, delivering health services, as well as performing other activities described in this document.
- The Controller processes your personal data in accordance with applicable regulations, including the GDPR.
- Providing personal data in most cases is voluntary. However, failure to provide certain data specified in the Privacy Policy will result in not being able to use the health services offered by the Controller.
What Are Personal Data and What Constitutes Their Processing?
- Under the GDPR, “personal data” means any information relating to an identified or identifiable natural person.
- An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- The GDPR distinguishes “special categories of data” within the general notion of personal data. According to the Regulation, special categories of data include personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic and biometric data processed to uniquely identify a natural person, as well as data concerning health, sexuality, or sexual orientation of a natural person.
- Your personal data processed by the Controller may include special categories of data in the form of health data.
- Processing of personal data means any operation performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Purposes of Processing Personal Data – General Information
- The Controller collects and processes personal data especially in connection with:
- providing electronic services, including enabling registration for telemedical consultation (consultation via teleinformatics systems or communication systems within the meaning of Article 3(1) and (2a) of the Act on medical activity),
- providing health services,
- undertaking marketing activities,
- archiving personal data containing documents,
- maintaining profiles and accounts on social media.
- Your personal data may also be processed for other purposes; in such cases, you will be informed by the Controller in a manner consistent with the information obligation under the GDPR (Articles 13 and 14).
- The scope of personal data processed by the Controller depends on the purpose for which the data are processed and may include:
- identification data: first name, last name, PESEL, date of birth, age, IP address of the device used to access electronic services;
- contact data: residence address, correspondence address, billing address, phone number, email address;
- data necessary to schedule consultations: description of health problems, medical documentation submitted by persons using health services provided by the Controller;
- data processed for the provision of health services: health status data, including test results, diagnoses, treatment methods, medications and medical devices used; data necessary for billing: bank account number;
- data necessary for cooperation within business operations: data of persons involved in providing services to the Controller, personal data obtained in connection with business cooperation.
- Regarding some of your personal data (listed below), because of the possibility of pursuing claims against the Controller related to provided services, the Controller will process your data until the expiration of the limitation period of potential claims.
- Currently, limitation periods are regulated by civil law. The general limitation period for claims by individuals in matters unrelated to business activity is 6 years. However, civil law includes special provisions allowing longer limitation periods for claims related to torts, crimes, or personal injuries. Furthermore, the limitation period may be interrupted or suspended. Therefore, the Controller will monitor whether limitation periods have expired to determine the appropriate data retention period.
- Detailed purposes of processing personal data with legal basis and retention periods are presented in the table below:
Data Processed for Providing Electronic Services:
| No. | Purpose of Data Processing | Legal Basis | Retention Period |
|---|---|---|---|
| 1. | Enable Patient to register for a telemedical consultation | Art. 6(1)(b) GDPR, Art. 9(2)(h) GDPR in connection with Art. 3(1) of the Medical Activity Act and Art. 24 of the Patient’s Rights Act and the Regulation of the Minister of Health of April 6, 2020, on types, scope and templates of medical documentation and its processing | Retention period of medical documentation as provided by applicable law |
| 2. | Enable the patient to fill out an electronic form to obtain e-prescriptions, e-sick leaves, e-referrals | Art. 6(1)(b) GDPR, Art. 9(2)(h) GDPR in connection with Art. 3(1) of the Medical Activity Act and Art. 24 of the Patient’s Rights Act and the Regulation of the Minister of Health of April 6, 2020, on types, scope and templates of medical documentation and its processing | Retention period of medical documentation as provided by applicable law |
| 3. | Contacting the patient to enable telemedical consultation, confirm consultation appointment, cancel the appointment, conduct video call | Art. 6(1)(b) GDPR, Art. 9(2)(h) GDPR in connection with Art. 3(1) of the Medical Activity Act and Art. 24 of the Patient’s Rights Act; legitimate interest of the Controller in providing patient service (Art. 6(1)(f) GDPR) | Retention period of medical documentation as provided by applicable law |
| 4. | Contact via contact form on the Website | Your consent arising from initiating contact (Art. 6(1)(a) GDPR) and Controller’s legitimate interest in cooperation, servicing clients, and conducting business (Art. 6(1)(f) GDPR) | For the duration of correspondence and thereafter for the period of the Controller’s legitimate interest, but no longer than the limitation period of potential claims related to the correspondence |
Data Processed for Providing Health Services:
| No. | Purpose of Data Processing | Legal Basis | Retention Period |
|---|---|---|---|
| 1. | Provision of health services, including medical documentation management, medical diagnosis | Art. 6(1)(b) GDPR, Art. 9(2)(h) GDPR as above | Retention period of medical documentation as provided by applicable law |
| 2. | Identifying patient’s identity prior to providing health services | Art. 6(1)(b) and (c) GDPR, Art. 9(2)(h) GDPR as above | Retention period of medical documentation as provided by applicable law; if identification is solely based on shown identity documents, data is processed only until the consultation ends |
| 3. | Managing social security services, including issuing certificates or medical leave | Art. 6(1)(b) and (c) GDPR, Art. 9(2)(h) GDPR as above, Art. 54 of the Act on Benefits from Social Insurance in case of Sickness and Maternity | Retention period of medical documentation as provided by applicable law |
| 4. | Conducting health prevention activities | Art. 6(1)(b) GDPR, Art. 9(2)(h) GDPR in connection with Art. 3(2) of the Medical Activity Act and Art. 24 of the Patient’s Rights Act | Retention period of medical documentation as provided by applicable law |
| 5. | Issuing e-prescriptions, e-referrals for tests or medical consultations | Art. 6(1)(b) and (c) GDPR, Art. 9(2)(h) GDPR as above, Medical Profession Act | Retention period of medical documentation as provided by applicable law |
| 6. | Exercise of patients’ rights, including access to medical documentation and designation of authorized persons to provide access or inform about patient’s health status | Art. 6(1)(c) GDPR in connection with Art. 9(h) GDPR and Art. 26(1) of the Patient’s Rights Act, and § 8(1) of the Minister of Health Regulation on medical documentation | Retention period of medical documentation as provided by applicable law |
| 7. | Performing settlements with patients, issuing billing documents, fulfilling legal obligations including tax and accounting laws | Art. 6(1)(b) GDPR | Until expiration of claims resulting or potentially resulting from services performed |
| 8. | Keeping accounting records and tax documentation if your data were provided in contracts or related documents with the Controller to fulfill legal obligations, especially tax and accounting laws | Art. 6(1)(b) and (c) GDPR in connection with accounting and tax laws | For the retention period of tax and accounting documentation as required by applicable law |
| 9. | Receiving complaints from Users regarding provided services and electronic services | Art. 6(1)(b) and (f) GDPR (for ordinary data – processed under legitimate interest of Controller for patient service) and Art. 9(2)(h) GDPR (for special category data) | Until expiration of claims resulting or potentially resulting from services performed |
Data Processed in Connection with Contracts for Cooperation within Business Activity (processing of data of contractors, business partners, suppliers, service providers):
| No. | Purpose of Data Processing | Legal Basis | Retention Period |
|---|---|---|---|
| 1. | Conclusion and execution of contracts with service providers, suppliers, doctors providing health services, and other persons cooperating with the Controller within business activity | Art. 6(1)(b) GDPR | Until expiration of claims resulting or potentially resulting from cooperation |
| 2. | Conclusion and execution by the Controller of a contract with the entity you represent or are employed by | Legitimate interest of the Controller to maintain contact with representatives of the other party (Art. 6(1)(b) and (f) GDPR) | Duration of the contract |
| 3. | Performing settlements with cooperating entities | Art. 6(1)(b) GDPR | Until expiration of claims resulting or potentially resulting from cooperation |
| 4. | Maintaining accounting and tax documentation if your data are included in contracts or other documents related to the Controller’s fulfillment of legal obligations, especially tax and accounting regulations | Art. 6(1)(b) and (c) GDPR in connection with accounting and tax laws | For the retention period of tax and accounting documentation as required by applicable law |
Data Processed for Marketing Activities:
| No. | Purpose of Data Processing | Legal Basis | Retention Period |
|---|---|---|---|
| 1. | Conducting marketing activities related to the Controller’s business, including building commercial relationships – under the Controller’s legitimate interest or your consent | Legitimate interest of the Controller in marketing products and services (Art. 6(1)(f) GDPR) | Duration of the Controller’s legitimate interest, but no longer than until: 1) you object to data processing for this purpose; 2) you withdraw consent for receiving ordered commercial information, if given |
| 2. | Analyzing data collected automatically via the Website, including profiling preferences to tailor offers; profiling does not affect your legal situation nor uses special categories of data obtained for health service provision | Legitimate interest of the Controller in marketing, ensuring correct Website functioning, and statistics (Art. 6(1)(f) GDPR) | Duration of the Controller’s legitimate interest, but no longer than until you object |
| 3. | Sending surveys regarding satisfaction with provided services | Legitimate interest of the Controller in obtaining customer satisfaction information (Art. 6(1)(f) GDPR), patient consent to receive and fill the survey (Art. 6(1)(a) GDPR) | Duration of the Controller’s legitimate interest, but no longer than until the patient objects or withdraws consent |
| 4. | Managing the Controller’s profiles on Facebook and Instagram | Legitimate interest of the Controller in collecting data via Facebook and Instagram on profile activity, anonymous user group analysis, content presentation (Art. 6(1)(f) GDPR). Processing is also based on user consent via activity on these profiles (Art. 6(1)(a) GDPR) | For the duration of the Controller’s legitimate interest, but no longer than until (i) you unlike the Controller’s profile and (ii) delete all activity on these profiles. Processing also ends if the user deletes accounts or the Controller deletes its profiles. The described actions do not equal deletion of archived data regarding activity. |
Personal Data Processed for Archival and Evidence Purposes:
| No. | Purpose of Data Processing | Legal Basis | Retention Period |
|---|---|---|---|
| 1. | Archiving documents created by the Controller as part of its business activity | Art. 6(1)(c) GDPR, Art. 9(2)(h) GDPR as above, and legitimate interest of the Controller in securing evidence (Art. 6(1)(f) GDPR) | For the retention period of documents under applicable law and for the duration of the Controller’s legitimate interest |
| 2. | Establishing or pursuing claims, defending against claims or allegations | Legitimate interest of the Controller in claims establishment or defense (Art. 6(1)(f) GDPR) | Until expiration of claims under applicable law |
| 3. | Creating registers of processing activities and records required under GDPR | Art. 6(1)(c) GDPR in connection with Art. 30(1) and (2) GDPR (legal obligation) | For the duration of the Controller’s business activity |
Regarding management of the Controller’s profiles on Facebook and Instagram, the following detailed rules apply:
- User data may be processed by the Controller when any activity occurs on the Controller’s profile on Facebook or Instagram (e.g., liking the profile, posting a comment, liking a post).
- Via Facebook or Instagram, the Controller may receive personal data categorized by user types, such as total visits, reactions to posts, comments, distribution of visitors by gender, visit source, information about clicks on specific content (maps, contact info), post reach.
- User activity on the Controller’s Facebook and Instagram profiles is entirely voluntary but implies personal data processing. The Controller cannot influence or stop analysis creation or data collection for this purpose. If you wish to limit connection with the Controller’s profiles, you can use Facebook or Instagram functions to unfollow or unsubscribe.
- Additionally, Facebook and Instagram may use your data for their own purposes, including market research and advertising. Cookies may be stored on your device analyzing behavior during use. Other information about your devices and internet connection may be collected and linked to your account. Facebook and Instagram may create profiles even if you are not logged in or do not have accounts. These profiles can be used for targeted ads on these platforms.
- The provider of Facebook and Instagram is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
- Details of data processing on Facebook are regulated in privacy documents available at https://www.facebook.com/privacy/policy/?entry_point=data_policy_redirect&entry=0.
- Details of data processing on Instagram are regulated in privacy documents available at https://help.instagram.com/196883487377501?ref=dp.
- The Controller uses Google Analytics tools on the Website. The following apply:
- Google Analytics uses methods allowing to analyze your use of the Website, e.g., cookies. Service details are at: https://analytics.google.com/analytics/web/provision/?hl=pl#/provision.
- Data processed include the IP address of your device and information on activity on the Website. Such personal data are not saved or archived.
- For Google users in the European Economic Area and Switzerland, Google Ireland Limited, Dublin, is responsible (Gordon House Barrow Street Dublin 4 Ireland).
- Automatically collected information about Website use may be transmitted to Google’s servers and stored there. Google applies European data protection mechanisms. Details at: https://policies.google.com/privacy?hl=pl.
- You can prevent cookies from recording Website usage data (including IP address) by Google and processing these data by downloading and installing a browser plugin at: https://tools.google.com/dlpage/gaoptout?hl=pl.
From What Sources Do We Obtain Personal Data?
The Controller obtains personal data from various sources, depending on the data subject and purpose:
- patient data – obtained directly from patients, their legal representatives or guardians, and other authorized persons, based on completed forms and during the provision of health services;
- marketing recipients data – provided directly by you, the entity you represent, or from publicly available sources. If data is obtained from other entities or publicly available sources, it includes name, company name, address, position or function, email, and phone number.
- data obtained from public registers – related to business operations, the Controller may collect data from public registers like CRBR, KRS, CEIDG, REGON and other necessary sources. This data may include name, PESEL, NIP, REGON, business name, addresses, phone number, email, registration data, representatives’ data.
Recipients of Personal Data
- The Controller carefully selects entities it cooperates with or whose services it uses to process personal data, aiming to ensure maximum protection of your personal data.
- The Controller does not disclose your personal data to third parties unless necessary for proper data processing and business operation. Data is or may be disclosed or entrusted to the following entities:
- recipients of personal data:
- other medical entities, to ensure continuity of treatment and availability of health services,
- postal and courier service providers,
- banks (for monetary settlements),
- internet payment providers,
- entities to whom the Controller is legally obliged to provide personal data, including persons authorized by you under patient rights;
- processors (under data processing agreements):
- entities with access to your personal data providing hosting, email, and other electronic communication services maintaining the Controller’s databases and IT systems,
- accounting service providers,
- Google, due to the use of Google tools on the Website,
- legal service providers to the Controller.
- The Controller may transfer your personal data to third countries only when using IT systems provided by entities based outside the European Union and the European Economic Area, or as required by applicable Union or national law. The Controller ensures data are transferred only to countries where the European Commission has issued adequacy decisions or under legal safeguards including appropriate agreements containing data protection clauses adopted by the Commission.
- recipients of personal data:
Right to Object to Personal Data Processing
Where the Controller processes your personal data based on its legitimate interest (Art. 6(1)(f) GDPR), you may object at any time to such processing. Objections can be made in any form, including via the contact details provided in point I above.
Other Rights Related to Processing Your Personal Data
- The GDPR grants you the following rights related to the processing of your personal data:
- the right to request access to your personal data,
- the right to request correction of personal data,
- the right to request deletion of personal data (right to be forgotten),
- the right to request restriction of processing,
- the right to data portability
- If processing is based on your consent, you may withdraw the consent at any time, without giving reasons, in any form, particularly by sending an email to the contact details in point I above. Withdrawal does not affect the lawfulness of processing based on consent prior to withdrawal.
- You have the right to lodge a complaint with the President of the Personal Data Protection Office if you consider that the Controller violates applicable data protection regulations.
- Not all rights in paragraph 1 apply to every processing situation. This depends on the type and legal basis of processing.
- The Controller may make automated decisions, including profiling, but this will not produce legal effects or similarly significantly affect your situation.
Final Provisions
- By using the Website or cooperating or communicating with the Controller in any matter, you must comply with the law and good practices, respect personal data, copyrights, and personal rights of third parties.
- The scope of the Controller’s activities may change and develop, and accordingly, the Privacy Policy will also change. The Controller will inform you about the scope and content of such changes on the Website and fulfill its information obligations accordingly.