The Operator provides the affected person / legal representative (hereinafter referred to as the “affected person”) with this information in accordance with the provisions of Section 19 of Act No. 18/2018 Coll. on Personal Data Protection (hereinafter referred to as the “Personal Data Protection Act”).
The collection and processing of personal data is carried out in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46 / EC, Act No. 18. / 2018 Coll on Personal Data Protection (hereinafter referred to as the “Personal Data Protection Act”), as well as other generally binding legal regulations.
1. Operator identification:
The person concerned shall provide his / her personal data to the operator, who is a healthcare provider in a medical facility in a specialized outpatient health care clinic in the medical profession dentist, in the field of study of dentistry and in the specialized field of dentistry, namely:
BLAHA DENT, s.r.o .; ID: 36 854 361; Registered seat: Závodská cesta 2963/4, Žilina 010 01; Registered in the Commercial Register of the District Court of Žilina, Section: sro, File No .: 19824 / L; Represented by: MUDr. Martin Blaha, managing director; PZS code: P70128016201.
2. Submission of questions and requests for personal data:
You can submit your questions and requests regarding personal data in paper or electronic form, either by letter delivered to the address of the operator’s registered office or electronically by e-mail to the address firstname.lastname@example.org
3. Purpose and legal basis of the processing of personal data:
a) Personal data according to Act no. 576/2004 Coll. on health care, services related to the provision of health care, which are processed, provided and made available for the purpose of providing health care and keeping a medical record, while the consent, data consent is not required for the processing, provision and access to such data.
These are the following personal data of the person concerned: name, surname, date of birth, birth number, residential address, medical data necessary to obtain a medical history, data on instruction and informed consent, data on the person’s illness, request for examinations of joint examination and treatment units, data on the course and results of examinations, treatment and other significant circumstances related to the health condition of the person and the procedure for providing health care, data on the scope of health care provided, data on services related to health care provision, data on temporary incapacity for work, data on treatment regimen and facts important for the assessment of medical fitness to perform work, epidemiologically important facts, identification data of the relevant health insurance company.
b) Personal data, the processing of which is necessary for the protection of the legitimate interests of the operator, in accordance with § 13 par. 1 letter f) of the Personal Data Protection Act, while the consent of the data subject is not required for the processing, provision and disclosure of such data.
These are the following personal data of the data subject: mobile phone number and recordings from the camera system located in the entrance hall, waiting room / reception as well as in each ambulance.
The mobile phone number is used by the operator exclusively for the purpose of contacting the patient in order to confirm whether the patient will arrive at the reserved date for treatment. The operator’s employee contacts the patient one to two working days before the booked treatment date.
The recordings from the camera system serve to protect the operator’s property, and at the same time represent a form of technical measure necessary to ensure the security of personal data protection and will be used exclusively for the purpose of possible criminal proceedings.
c) Personal data, the processing of which is necessary for the performance of the contract, in accordance with § 13 par. 1 letter b) of the Personal Data Protection Act, while the consent of the data subject is not required for the processing, provision and disclosure of such data.
These are the following personal data of the data subject: e-mail of the data subject and information provided by the data subject to the operator if he uses the website www.blahadent.sk for communication with the operator. The data subject will provide his e-mail to the operator only if he requests from operator to send information by e-mail.
4. Recipient of personal data:
Personal data is processed exclusively:
(a) by the operator’s staff
(b) the competent health insurance company
c) its suppliers providing technical support for the operation of IT software, which are bound by the obligation to protect personal data and the obligation to maintain the confidentiality of personal data.
The operator maintains all personal data in strict confidentiality.
Personal data shall not be provided to other third parties, except to those to whom the controller has a legal obligation or right to provide such data in accordance with applicable law.
Camera footage shall be provided to law enforcement authorities if necessary.
5.Dead of retention of personal data:
Personal data according to point 3 letter (a) and data on the mobile telephone number shall be kept for a period of 20 years from the last provision of healthcare to the person concerned.
Personal data from the camera recording is stored for 3-7 days depending on the amount of recorded data.
Personal data provided by the data subject to the operator if he uses the website www.blahadent.sk to communicate with the operator are not stored, unless they also fall into another category of personal data.
6.Right of the person concerned:
The person concerned (patient) has the right to:
(a) require the controller to have access to personal data concerning the data subject;
b) for the correction of personal data,
c) to delete personal data or to restrict the processing of personal data in accordance with the relevant legal regulations,
d) object to the processing of personal data,
e) for the portability of personal data,
f) file a motion to initiate proceedings pursuant to Section 100 of the Personal Data Protection Act.
The person concerned has the right to address his request under letter a) to e) in paper or electronic form, either by application delivered to the address of the registered office of the operator or electronically by e-mail to the address email@example.com
7. Refusal to provide personal data:
As the data subject has a legal obligation to provide personal data in accordance with the above information, he acknowledges that the controller has the right to refuse to provide healthcare except in cases of urgent care under Act no. 576/2004 Coll. on health care, services related to the provision of health care.
In Žilina, 21.5.2018