Information on the processing of personal data

In this document you will find information on the processing of personal data by myMedical Prague MMP s.r.o., ID No.: 27207391, with its registered office at Bolzanova 1679/3, Praha 1 – Nové Město, postal code: 110 00, entered in the register kept by the Municipal Court in Prague, section C , insert 104484 ( “Company“).

The Company provides mediation services in the field of plastic and aesthetic surgery and dentistry (“Health Services“), which are provided by medical facilities which the Company cooperates with (“Clinics“). Respectively, the Company will contact the persons who contact it via the website https://mymedicalprague.com/ (the “Website”) (the “Customers”), upon their request, mediate the conclusion of a contract for the provision of Health Services between the Customer and the relevant Clinic.

Furthermore, in the event that the Customer concludes a contract with one of the Clinics for the provision of Health Services, the Company offers the Customer additional services (e.g. transportation from the airport, arranging for accommodation, sending information and recommendations, etc.).

The Company processes personal data primarily as an administrator of personal data in order to provide services to the Customer.

The Company also processes personal data as a processor for individual Clinics, on the basis of agreements on processing concluded between the Company and the Clinics. In such a case, the Company follows the processing of personal data not only by generally binding legal regulations, but also by agreements on processing as well as the upon instructions of the Clinics. The scope and purposes of processing are always determined by the individual Clinic as administrator and is given mainly by the scope that is necessary for concluding a contract for the provision of Health Services between the Clinic and the Customer, or which is necessary for the provision of the Health Services by the Clinic.

1. Basic terms

To begin with, we would like to inform you about some of the basic terms which this document works with and which are also defined in Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“GDPR“).

Personal data is all (any) information that relates to a specific identified or identifiable person (natural person).

Data on health condition are personal data concerning the physical or mental health of a natural person, including data on the provision of health services, which testify to the health condition.

The data subject is a specific person whose personal data are in question in a given case.

Personal data administrator is the person who determines the purpose of personal data processing (i.e. the reason for which they are used) and the means that are used for processing. The administrator can authorize the processor to process.

Personal data processor is the person who processes personal data for the administrator, e.g. a person who has been entrusted by the administrator with a certain activity, for the performance of which it is necessary to process personal data (IT service provider, etc.).

Personal data recipient is the person to whom the personal data was provided. Apart from the circle of processors, personal data may also be provided to another administrator who is authorized to process the data for its own purposes (e.g. health insurance company).

Personal data processing is an activity dealing with personal data, which is performed by the administrator or processor (processing is, for example, collection, recording, storage, arrangement, structuring, adaptation, modification, retrieval, viewing, use, transmission, spreading, sorting, combining, deleting, etc.).

2. The Company’s position in relation to various categories of personal data

The Company, as administrator, processes your personal data, in particular the following categories of personal data:

  • identification and invoicing (title, name, surname, gender, date of birth, birth number, nationality, mailing and invoicing address, etc.);
  • contact details (e-mail, telephone number, etc.);
  • data necessary for the fulfilment of the Company’s legal obligations (e.g. identification number, tax number, etc.);
  • other data that are necessary for the performance of the contract (e.g. payment data, etc.), for the fulfilment of a legal obligation or the realization of a legitimate interest, or data for the processing of which the data subject has given his consent;
  • data on health condition only on the basis of your consent and to the extent necessary to fulfil the purpose for which you give your consent.

For the purposes of concluding a contract for the provision of Health Services and the provision of Health Services by a specific Clinic, the Company mediates your personal data as a processor for a specific Clinic, which is their administrator; this applies in particular to the following categories of personal data:

  • identification and invoicing (title, name, surname, gender, date of birth, birth number, nationality, mailing and invoicing address, etc.);
  • contact details (e-mail, telephone number, etc.);
  • other data that are necessary for the performance of the contract (e.g. payment data, etc.), for the fulfilment of a legal obligation or the realization of a legitimate interest, or data for the processing of which the data subject has given his consent;
  • visual or audio-visual recordings (photographs, video, etc.) of the area of your body on which the provision of Health Services by the Clinic should be focused (hereinafter referred to as “Records“);
  • data on health condition (e.g. data on diseases, injuries, prescribed and other medications, type and purpose of plastic and aesthetic surgery, etc.). If the Records contain data on the health condition of the data subject, these are also data on the health condition.

For more information on the processing of your personal data by the Clinic as an administrator, please contact the relevant Clinic directly, which you will conclude a contract for the provision of Health Services with. The name of the Clinic will always be communicated to you on request.

3. Purposes and legal basis of personal data processing

We process your personal data for the following purposes and on the legal bases listed below and for the purposes listed below.

As an administrator:

a) for the purpose of providing services by the Company on the basis of your request;

(b) for the purpose of fulfilling legal obligations (e.g. legal obligations in the field of accounting);

c) for the purposes of the legitimate interests of the Company (e.g. communication of the contracting parties, proving the claims of the Company, ensuring the security and protection of property, marketing purposes of the Company, etc.);

d) on the basis of consent and for the purposes, for which you give such consent (if any).

The provision of your data for the purposes of the provision of services by the Company is necessary, without their provision the Company cannot provide the Services to you; this does not apply to data provided on the basis of consent.

As a processor for the Clinic, which concludes a contract with you on the provision of health services and which is therefore the administrator of your personal data:

a) for the purposes of concluding a contract for the provision of Health Services between you and the Clinic, on the basis of your request, to conclude this Contract with the Clinic;

b) for the purposes of fulfilling the legal obligations of the Clinic (e.g. legal obligations in the field of accounting, obligations arising from the legal regulation governing the provision of health services, etc.);

c) for the purposes of the legitimate interests of the Clinic (e.g. communication of the contracting parties, proving the claims of the Clinic, ensuring the safety and protection of property, etc.);

d) on the basis of consent and for the purposes, for which you give such consent (if any).

Providing your data to the Clinic is necessary for concluding and fulfilling the contract for the provision of Health Services with the Clinic, and without their provision it is not possible to conclude a contract with the Clinic.

The Company does not assess the Data on health condition, the Company will only pass this Data to a specific Clinic, which assesses it for the purpose of providing Health Services (e.g. to assess possible risks that could be posed to you by performing the procedure with respect to your health).

4. Personal data processing on the basis of consent

If you give your prior consent, we will process your personal data for the purposes for which you give this consent. In connection with the provision of services, the Company may ask you to grant voluntary consent for the following purposes:

a) consent to the processing of personal data, including Data on health condition for the purpose of providing services of the Company according to your preferences, e.g. an offer of mediation of health services with the relevant Clinic according to the specialization of aesthetic or dental surgery you will require, recommendation of a Clinic based on the lowest price of the required operation, etc., for a period of 1 year;

b) consent to the processing of personal data, including data on health condition for the purpose of sending informative and recommendable marketing messages related to the requested / submitted Health Service (e.g. information on the need to inspect or replace the implant, etc.), for a maximum of 15 years ;

c) business and marketing communications of the Company’s contractual partners (e.g. offers of cooperating Clinics), for a maximum period of 15 years.

You give your consent in the order form. If you do not give your consent to the Company, the Company will not process your personal data for the given purposes. If you grant your consent only to one of the above purposes, your Data on health condition will only be processed for this purpose.

The consent can be revoked at any time free of charge, by sending information to the e-mail address info@mymedicalprague.com and if consent is given to sending marketing messages, then also in the manner specified in the specific message that will be sent to you, e.g. by clicking on the link in e-mail.

We will process the Data on health condition only to the extent necessary to fulfil the purpose for which you give your consent (usually only to the extent of the type of medical service you have undergone (i.e. the type of plastic or aesthetic surgery, including the type of implant). The data are then processed only for the period for which the consent was granted, if you revoke your consent before the expiration of this period, then until the revocation of this consent.

We process personal data for the purpose of sending business and marketing messages to the Company (e.g. offers of our new services) only if the data subject has not refused to send them in advance. The data subject can easily unsubscribe from receiving commercial and marketing messages by a link in each individual e-mail containing the commercial and / or marketing message. The data subject may also unsubscribe from receiving commercial and marketing communications by sending an e-mail to the Company’s e-mail below.

5. Processing of personal data on health condition by the Clinic as an administrator

The Clinic is a provider of health services and processes data on health condition for the purposes of providing Health Services on the basis of special legal regulations, whereas the processing of data on health condition is necessary for the purposes of medical diagnostics, the provision of health care and treatment and the provision of health services by the Clinic. The Company does not evaluate data on health condition in any way, these are evaluated by the Clinic.

In some cases, we may process your data on health condition as a processor for the Clinic, which is the administrator of this personal data, however, only if you provide us with these data for the purpose of passing them on to the Clinic. The processing of data on health condition then consists in their transfer to the Clinic, together with other data required for the conclusion of a contract for the provision of Health Services between you and the Clinic.

6. Contact Information

In matters relating to the processing of personal data by the Company, you can reach the Company via the following contacts:

  • e-mail: info@mymedicalprague.com
  • telephone: +420 776 817 044
  • mailing address: My Medical Prague MMP, Praha 1, 110 00, Bolzanova 3

7. Processing period

Your data will be processed for the longest:

  • for the purposes of performance under the contract concluded with the Company for the duration of this contract;
  • for the purposes of fulfilling the legal obligations of the Company for the time necessary for the fulfilment of these obligations and if the processing time is determined by a legal regulation, then for the period specified therein;
  • for the purpose of defending the legal claims of the Company for at least one year from the end of the limitation period of these claims;
  • for processing on the basis of a legitimate interest of the Company for a maximum period of time for which processing is necessary regarding this legitimate interest;
  • for the purposes of processing on the basis of your consent for the period for which it was granted.

For information on the processing of your personal data by the Clinic as an administrator, please contact the Clinic which you will conclude a contract for the provision of Health Services with (or which you will negotiate its conclusion with if this contract is not concluded).

8. Recipients and processors of personal data

Personal data provided by you, which the Company processes for its own purposes, may be passed on / made available to other recipients (e.g. providers of IT services, accounting, tax or legal services, etc.), furthermore, personal data may be provided to public authorities (tax office, courts, law enforcement agencies, etc.).

The company may also provide personal data disclosed by you to third parties (e.g. to accommodation facilities, carriers, etc.) on the basis of your request in the case of the provision of certain additional services (e.g. accommodation, transport from the airport, etc.). In such a case, personal data is always provided only to the extent necessary to ensure the service provided.

The personal data provided by you may be transferred to the Clinic for the purpose of concluding a contract for the provision of Health Services, the Clinic then further processes this data as the administrator of personal data (the Clinic may then involve the Company in some processing operations).

9. Data source

Personal data is obtained directly from you, i.e. from the data subject.

10. Rights of data subjects

The company processes personal data transparently, correctly, in accordance with the GDPR and generally binding legal regulations.

According to the GDPR, the data subject may

a) request access to personal data,

b) request the correction or updating of personal data,

c) request the completion of incomplete personal data,

d) request the deletion or restriction of processing,

e) object to the processing,

f) request the termination of the processing of his personal data and / or their removal,

g) file a complaint with the Office for Personal Data Protection.

In the case of processing personal data on the basis of the voluntarily granted consent to the Company, the data subject may revoke the consent at any time by sending an e-mail to the Company’s address specified in Article 5.1. of this document, if this consent has been granted to the Company as an administrator of personal data. Revoking the consent does not affect the processing of personal data made on the basis of consent before its revocation and the processing of personal data on the basis of another legal basis specified in the GDPR or other applicable legislation (e.g. if the processing is necessary for performance of the contract, legal obligations, etc.) .

f you are not sure whether or how your data is processed, you want to update or correct your data, you want to request their deletion or restriction of processing, or raise an objection to processing, you can contact the Company through the contacts listed in Article 6. above.

If you believe that your data is being processed by the Company in violation of legal regulations, you can file a complaint with the Office for Personal Data Protection. However, in order to arrange a remedy as soon as possible, we recommend that you contact the Company first.

In cases where the Clinic is the administrator of your personal data, please contact the Clinic directly for more information. Also exercise your rights relating to such processing directly with the Clinic (If you exercise your rights with the Company, the Company will forward your application to the Clinic for processing).

11. Information on personal data processing through cookies

The Company further processes cookies from the Website operated by the Company. Cookies are short text files that websites store in your browser. Cookies allow websites to function properly and record information about the customer’s visit (such as settings, preferred language, etc.). 

If you have cookies enabled in your web browser, the Company processes information on the behaviour contained in cookies placed on the Website as so-called technical cookies for the purpose of proper functioning and operation of the Website (e.g. to enable activities on the Website, use of their basic functions, creation and completion of the order, etc.), the so-called functional cookies enabling the adaptation of the Website content to the customer’s preferences (e.g. language), anonymously, the so-called performance and analytical cookies, which collect information about traffic and use and operation of the Website for information purposes and possible marketing cookies for targeting online advertising and marketing purposes if you agree with them. 

By opening and using the Website, the customer accepts the storage and processing of so-called essential cookies, which are necessary for the proper functioning of the Website, the so-called functional cookies, so-called performance and analytical cookies, which collect information about traffic and use and operation of the Website, in order to analyse website traffic, improve the functioning of the Website. Performance and analytical cookies are always assessed in an anonymous form, which does not allow the identification of the individual.

The cookies collected are processed by other processors, a Google Analytics provider operated by Google Inc., located at 1600 Amphitheater Parkway, Mountain View, CA 94043, USA. Analytics policies can be found at this link: https://support.google.com/analytics/answer/4597324. The company also allows some business partners to use cookies through its website, thanks to which they can then provide selected services (especially services in the field of website traffic analysis, market and marketing activities).

Cookies are processed for the period specified in the following table:

Publisher / name of cookiesType:Data retention periodDescription
WordPress
pll_language
Functional12 monthsUsed to remember a website’s preferred language choice.
wordpress_test_cookieFunctionalwhile the page is being opened in a browser windowIt helps to determine whether the user has cookies enabled in the browser.
Google Analytics
(_ga,_gid a _gat)
Analytical
24 months after save / restore
Used to distinguish individual users for traffic analysis. The cookie is refreshed every time data is sent to Google Analytics.

Setting the use of cookies is part of your internet browser. The rules for cookies can be set using your internet browser (Google Chrome, Safari, Internet Explorer, etc.), or you can reject or disable their storage. Cookies already saved can be deleted. Some browsers also offer the option of browsing websites in the so-called incognito mode, in which case cookies created when browsing in incognito mode are usually deleted after closing all incognito windows. For more information on restricting the use of cookies, you can visit the website: www.youronlinechoices.com. This site is not operated by the Company and the Company is therefore not responsible for its content.

If the Website contains hyperlinks and references to other websites, please note that this Privacy and Processing Information does not apply to such websites. The Company is not responsible for the privacy practices or practices of websites that are not managed by it, and we encourage you to carefully read the terms of protection and processing of personal information on such websites.

12. Personal data protection

The Company cares about the protection of the rights of data subjects and the proper security of personal data, therefore when processing personal data it takes care to ensure the highest possible level of security corresponding to the possible risks of the relevant processing through appropriate technical and organizational measures.

FeedBack

    Feedback

    How do you like the web pages?


    Thanks for cooperation
    myMedical Prague

    Close