Services Price

INFORMATION CLAUSE FOR PATIENTS

from April 27, 2016

INFORMATION CLAUSE FOR PATIENTS

In accordance with Article 13 paragraphs 1 and 2 and Article 14 paragraphs 1 and 2 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter referred to as "GDPR"), we hereby inform you that:

a.i.1. ​ ​Personal data administrator

The controller of your personal data is MISTODENT Sp. z o. o. Aleja Gen. Antoniego Chruściela "Montera" 88A, 04-412 Warsaw, entered into the National Court Register maintained by the District Court for the capital city of Warsaw, 13th Commercial Division under KRS number 0000991988, REGON number 523113133, NIP number 5213984106.

You can contact the Administrator by e-mail: mistodent@gmail.com

2. ​Data Protection Officer (DPO)

The Administrator has appointed a Data Protection Officer who can be contacted by e-mail: iod@mistodent.com.ua

3. ​Purposes and basis of processing

a) Provision and management of healthcare services – pursuant to Article 6(1)(c) of the GDPR (legal obligation) and Article 9(2)(h) of the GDPR (processing of special categories of data for the purpose of providing healthcare), within the meaning of the Act of 15 April 2011 on medical activity, while ensuring the security of the IT system in which these data are processed;

b) Documenting the health condition and health services provided – pursuant to Article 6 paragraph 1 letter c of the GDPR and Article 9 paragraph 2 letter h of the GDPR, in connection with the legal provisions regulating the maintenance of medical records, in particular the provisions of the Act of 15 April 2011 on medical activity, the Act of 6 November 2008 on patients’ rights and the Patient Ombudsman and the Act of 27 August 2004 on health care declarations financed from public funds and the Act on the professions of physician and dentist;

c) Concluding and performing a contract, including ensuring the correct quality of services – pursuant to Article 6(1)(b) of the GDPR (necessity to perform the contract);

d) Fulfillment of legal obligations incumbent on the Dental Office, in particular:

a. issuing and storing invoices,
b. keeping accounting books,
c. consideration of complaints,

– pursuant to Article 6(1)(c) of the GDPR;

e) Pursuing or defending against claims arising from the contract – pursuant to Article 6(1)(f) of the GDPR (legitimate interest of the controller in protecting rights and interests);

f) Marketing of own services during the term of the contract – pursuant to Article 6(1)(f) of the GDPR (legitimate interest of the controller);

g) Marketing activities, if you consent to the use of your data for this purpose – pursuant to Article 6(1)(a) of the GDPR (consent), which may be withdrawn at any time without affecting the lawfulness of processing based on consent before its withdrawal;

h) Conducting online visits (teleconsultations) based on the patient's consent, including recording the online meeting in order to defend against potential claims, ensure the proper functioning of communication tools and the legal security of the parties – on the basis of: Article 6 paragraph 1 letter a of the GDPR – consent of the data subject, Article 9 paragraph 2 letter a of the GDPR – explicit consent to the processing of special categories of data (health data), Article 6 paragraph 1 letter f of the GDPR – legitimate interest of the controller in securing and defending against potential claims.

i) Ensuring the safety of persons and property through the use of video surveillance in medical facilities, as well as protecting infrastructure and maintaining the confidentiality of medical records – pursuant to Article 6 paragraph 1 letter f of the GDPR – the legitimate interest of the controller in ensuring the safety of patients, staff and the protection of property and information.

4. ​Recipients of personal data

Your personal data may be transferred to entities that support the Controller in achieving the above-mentioned purposes, including entities entrusted by the Controller with the processing of personal data in accordance with Article 28 of the GDPR, including entities providing maintenance services for IT systems used in data processing, accounting firms, IT companies, security agencies, as well as, for example, banks, insurance companies, postal and courier operators, law firms and entities authorized to do so under the law.

Your data may be made available to entities authorized under the law, in particular in accordance with Article 26 of the Act of 6 November 2008 on Patients' Rights and the Patient Ombudsman, including, among others, entities providing healthcare services to ensure the continuity of healthcare services, and public authorities, including the Patient Ombudsman, the National Health Fund, medical professions self-government bodies, and national and provincial consultants, to the extent necessary for these entities to perform their tasks, in particular supervision and control.

5. ​Data transfer

Your data may be transferred when using remote communication tools such as Microsoft 365, provided by Microsoft. Because the Controller uses Microsoft IT services, your data may be transferred to the USA. The Controller has entered into agreements with Microsoft – so-called Standard Contractual Clauses. This means that, in accordance with European Commission Decision No. 2021/914 EU of 4 June 2021, your personal data may be processed by Microsoft in the USA. Microsoft is implementing additional measures to ensure the compliance of data transfers outside the EEA. More information can be found in the ​" Data Protection Addendum for Microsoft Products and Services (DPA) " ​​on the provider's official website.

Additionally, personal data may be transferred to entities providing services in Ukraine, based on standard contractual clauses, in accordance with Article 46 paragraph 2 letter c of the GDPR

6. ​Data storage period

Your personal data will be processed for the period specified by law, in particular for the period specified in Article 29 of the Act of 6 November 2008 on Patients' Rights and the Patient Ombudsman. Medical records are generally stored for at least 20 years from the end of the calendar year in which the last entry was made. After the statutory retention period, medical records will be destroyed in a manner that prevents the identification of the patient to whom they pertain, or they will be released to you or a person authorized by you.

Your personal data will be processed for the duration of your provision of services to the Controller. Data processed to fulfill the Controller's legal obligations will be processed for as long as required by applicable law regulating the given obligation. Data processed in connection with the pursuit of claims will be processed until the statute of limitations expires. Personal data processed based on the Controller's legitimate interest will be processed until you object. Personal data processed based on your consent will be stored for the duration of the purpose for which the consent was given or until you withdraw your consent.

7. ​Data subject rights

To the extent permitted by law, you have the right to: access your data and receive a copy thereof; rectify your personal data; delete your personal data; restrict the processing of your personal data; and transfer your personal data.

If processing is based on consent (Article 6(1)(a) or Article 9(2)(a) of the GDPR), you have the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

You have the right to object, for reasons related to your particular situation, to the processing of your data for the purpose resulting from the legitimate interests of the Controller - Article 6 paragraph 1 letter f) of the GDPR.

You have the right to lodge a complaint about unlawful processing of your personal data with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw.

8. ​Information about the requirement to provide personal data

a) providing personal data that are necessary to provide services is mandatory and necessary for the purposes of their processing;

b) providing other, additional personal data is voluntary. Giving the consents referred to in point 3, letters e) and f) is also voluntary.

9. ​Information about automated decision-making, including profiling

The processing of your personal data will not be subject to automated decision-making, including profiling, referred to in Article 22(1) and (4) of the GDPR.

Privacy Policy 

CONTACTS

 ​​​​Poland, Warsaw, str. Waliców 11

 ​mistodent@gmail.com

 +48 (223) 82-15-30  +48 (223) 82-15-31  +380 (96) 861-09-50

 ​​Poland, Warsaw, str. Powązkowska 44

 ​mistodent@gmail.com

 +48 (223) 82-15-30  +48 (223) 82-15-31  +380 (96) 861-09-50
SIGN UP FOR A CONSULTATION WITH A SPECIALIST AT OUR CENTER

In accordance with Article 13(1) and (2) of the GDPR, we hereby inform you that the Controller of your data is LLC "MISTODENT", which will process your personal data for the purpose of responding to your inquiry. More information can be found in the Privacy Policy.​

​Call for nu​​mbers:

 +48 (223) 82-15-30  +48 (223) 82-15-31  +380 (96) 861-09-50

​We will give you feedback on all your concerns or we will make an appointment for a consultation at your convenience.