This Privacy Policy sets out the rules for the processing of personal data of website users, persons contacting the controller, persons placing orders, persons using forms available on the website, patients, and persons interested in the services offered by BEAUTYdoc Praktyka Lekarska Barbara Parda-Głomska.
This document is intended to explain what personal data may be processed, for what purposes, on what legal bases, for how long, and what rights are granted to the data subjects. The Privacy Policy also includes information regarding cookies and other similar technologies used within the website.
The controller of your personal data is BEAUTYdoc Praktyka Lekarska Barbara Parda-Głomska, with its registered office in Piaseczno at ul. Gruszek i Jabłuszek 7, NIP: 7391279121, REGON: 510686416.
The personal data controller may be contacted:
This Privacy Policy applies to the processing of personal data in connection with the use of the website, contact with the controller, registration or appointment booking, placing orders, payment handling, performance of services, maintenance of medical records, marketing communication, and the use of cookies.
In the case of patients and persons using healthcare services, the processing of data also includes information required by medical law, including data necessary for maintaining medical records, diagnostics, prevention, therapy, and management of healthcare services.
As a rule, personal data is obtained directly from the data subject. This may occur, in particular, during telephone contact, e-mail contact, use of the contact form, order form, e-registration system, placing an order, booking an appointment, providing invoice or bill details, as well as during an in-person visit to the facility.
In the case of continuation of treatment started elsewhere, personal data may also be received from other medical facilities or healthcare providers, if this is necessary to ensure continuity of healthcare services.
In special situations justified by the health condition, personal data may also be obtained from close relatives, legal representatives, de facto caregivers, or persons authorised by the patient.
Depending on the purpose of contact, the type of service, and the manner of using the website, the controller may process various categories of personal data.
In the case of telephone contact, e-mail contact, or contact via the contact form, such data as first name, last name, e-mail address, telephone number, message content, and other information voluntarily provided by the person contacting the controller may be processed.
For the purposes of appointment booking, identity verification, and provision of healthcare services, the controller may process data including, in particular, first name, last name, gender, PESEL number, and in the absence of a PESEL number — date of birth, telephone number, e-mail address, health information, data contained in medical records, and information concerning the course of diagnostics, prevention, therapy, and treatment.
When placing orders or using services available via the website, the controller may process data necessary for handling and fulfilling the order, including first name, last name, e-mail address, telephone number, address data, invoice or bill details, information concerning the selected service or product, payment status, payment method, and data necessary for handling settlements.
For the purposes of issuing bills, invoices, or keeping settlements, the controller may process identification data, contact details, address data, tax identification number (NIP), transaction details, and other data required by accounting and tax law.
If the data subject gives consent to marketing communication, the controller may process such data as first name, last name, e-mail address, or telephone number for the purpose of sending information concerning products, services, offers, promotions, events, or other activities conducted by the controller.
When using the website, technical and operational data may be processed, such as IP address, date and time of connection to the website, browser type, device type, operating system, visited subpages, source of access to the website, cookie identifiers, and other information recorded in server logs or by means of similar technologies.
Personal data is processed solely for specific and lawful purposes. The scope of processing depends on how the user uses the website, for what purpose they contact the controller, and whether they are a patient, client, person placing an order, or a person interested in the controller’s offer.
Personal data provided in an e-mail, contact form, or during telephone contact is processed for the purpose of responding, handling the inquiry, conducting correspondence, and taking actions consistent with the content of the request.
The legal basis for processing is the controller’s legitimate interest consisting in handling correspondence and communication with persons contacting the controller, i.e. Article 6(1)(f) GDPR. If the contact is aimed at concluding or performing a contract, the legal basis may also be Article 6(1)(b) GDPR.
Patients’ personal data is processed for the purpose of booking appointments, verifying identity, providing healthcare services, conducting diagnostics, prevention, therapy, documenting the treatment process, and managing healthcare services.
The legal basis for processing the data is Article 9(2)(h) GDPR in conjunction with legal provisions regulating the process of providing healthcare services, in particular the Act of 15 April 2011 on medical activity, the Act of 6 November 2008 on patient rights and the Patient Ombudsman, the Act of 27 August 2004 on healthcare services financed from public funds, and the Act on the professions of physician and dentist.
The controller, as an entity providing healthcare services, is obliged to maintain and store medical records. Medical records may contain the patient’s identification data, information on health status, data concerning the course of diagnostics and treatment, information on procedures performed, recommendations, and other data required by law.
The legal basis for processing data for this purpose is Article 9(2)(h) GDPR in conjunction with applicable medical law provisions, in particular the Act on patient rights and the Patient Ombudsman.
Personal data provided when placing an order or using services available on the website is processed for the purpose of accepting the order, confirming its placement, handling payments, fulfilling the order, providing organisational information, handling requests, complaints, or returns, as well as ensuring proper communication with the person placing the order.
The legal basis for processing data is Article 6(1)(b) GDPR, where processing is necessary for the conclusion or performance of a contract, and Article 6(1)(c) GDPR, where processing results from legal obligations incumbent upon the controller.
Personal data may be processed for the purpose of keeping accounting records, issuing invoices or bills, documenting transactions, handling payments, and fulfilling tax and accounting obligations.
The legal basis for processing is Article 6(1)(c) GDPR in conjunction with the provisions of the Act of 29 September 1994 on accounting and the Act of 11 March 2004 on tax on goods and services.
Personal data may be processed for the purpose of establishing, pursuing, or defending claims related to the conducted business activity, healthcare services provided, services performed, handling of orders, or contact with the controller.
The legal basis for processing is Article 6(1)(f) GDPR, i.e. the controller’s legitimate interest consisting in the protection of its rights and interests. In the case of special categories of data, including health data, the legal basis may be Article 9(2)(f) GDPR.
If the data subject has given consent to marketing communication, their personal data may be processed for the purpose of sending information about products, services, offers, promotions, events, or other activities conducted by the controller.
The legal basis for processing data for marketing purposes is the consent of the data subject, i.e. Article 6(1)(a) GDPR. Marketing contact using an e-mail address, telephone number, or other means of electronic communication takes place solely on the basis of prior consent, in accordance with applicable regulations governing electronic communications.
Consent to marketing communication is voluntary and may be withdrawn at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
Technical and operational data may be processed for the purpose of ensuring the proper functioning of the website, maintaining the security of IT systems, detecting abuse, diagnosing technical errors, compiling technical statistics, and administering the server.
The legal basis for processing is Article 6(1)(f) GDPR, i.e. the controller’s legitimate interest consisting in ensuring the security, stability, and proper functioning of the website.
Personal data is stored for the period necessary to achieve the purpose for which it was collected, and then for the period resulting from legal provisions, limitation periods for claims, or the period necessary to protect the controller’s rights.
Medical records are stored for the period resulting from applicable law, as a rule for at least 20 years from the end of the calendar year in which the last entry was made, subject to exceptions provided for by law. After the expiry of the statutory retention period, medical records are destroyed in a manner preventing identification of the patient to whom they related, or issued to the patient or a person authorised by them, if such a possibility is provided for by law.
Data processed for handling inquiries is stored for the time necessary to provide a response and complete the correspondence, and then for the period needed to secure possible claims.
Data processed in connection with the fulfilment of orders, services, or payments is stored for the time necessary to perform the contract, handle the order, settle the transaction, and for the period resulting from legal provisions or the limitation period for claims.
Data processed for accounting and tax purposes is stored for a period of 5 years from the end of the calendar year in which the tax obligation arose, unless the law provides for a longer retention period.
Data processed on the basis of consent, including data used for marketing communication, is stored until consent is withdrawn, the purpose of processing ceases, or it is found that the data has become outdated, whichever occurs first.
Technical data, server logs, and information related to website use are stored for the period necessary to ensure the security and proper functioning of the website, and in the case of cookies — for the period resulting from the settings of a given cookie or until they are deleted by the user.
Personal data may be disclosed to entities authorised to receive it under legal provisions, in particular public administration bodies, supervisory bodies, courts, the public prosecutor’s office, the Patient Ombudsman, the National Health Fund, bodies of medical professional self-government, national and provincial consultants, and other entities to whom the controller is obliged to transfer data under applicable law.
To the extent necessary to ensure continuity of healthcare services, personal data may be disclosed to other healthcare providers, in accordance with the provisions of the Act on patient rights and the Patient Ombudsman.
Personal data may also be entrusted to processors acting on behalf of the controller. These may include, in particular, IT service providers, hosting providers, entities maintaining the website, providers of online registration systems, e-mail service providers, payment operators, banks, accounting offices, law firms, entities providing accounting services, courier or postal companies, marketing tool providers, marketing agencies, and entities supporting the controller in handling orders, communication, and conducting business activity.
Entities processing personal data on behalf of the controller act on the basis of appropriate agreements and are obliged to process data solely in accordance with the controller’s instructions and while maintaining the required security measures.
The controller does not, as a rule, transfer personal data outside the European Economic Area, unless this is connected with the use of specific IT, analytical, marketing, communication tools, or services provided by suppliers established outside the European Economic Area or using infrastructure located outside that area.
If, in connection with the use of such tools, data is transferred outside the European Economic Area, the controller ensures the application of legally required safeguards, in particular standard contractual clauses, adequacy decisions, or other instruments provided for by the GDPR.
The website may use cookies, i.e. small text files stored on the user’s device. Cookies may be used for the purpose of ensuring the proper functioning of the website, maintaining a session, remembering user settings, handling forms, improving security, compiling statistics, analysing the manner of using the website, and — where the user gives appropriate consent — for marketing purposes.
The following types of cookies may be used on the website:
Necessary cookies may be used in order to ensure the proper functioning of the website. Other categories of cookies are used in accordance with user preferences and the consents granted.
The user may manage cookies through the settings of their internet browser. Depending on the browser used, it is possible, among other things, to block cookies, delete previously stored cookies, limit their use, or receive information about attempts to store them.
Restricting or disabling cookies may affect the operation of certain website functions, in particular forms, the cart, registration, remembering preferences, or other functions requiring the storage of technical information.
Providing personal data is voluntary; however, in some cases it is necessary in order to achieve a specific purpose. Failure to provide data required to handle an inquiry may make it impossible to provide a response. Failure to provide data necessary to place an order, handle a payment, or perform a service may make it impossible to conclude or perform a contract.
Providing personal data in connection with the provision of healthcare services is necessary due to legal requirements imposed on the controller, including the obligation to verify the patient’s identity and maintain medical records. Refusal to provide data required by law may constitute grounds for refusal to provide a healthcare service, except in situations where the law requires assistance to be provided despite the lack of complete data.
Providing data for accounting, bookkeeping, and tax purposes may be required by law, in particular in the case of issuing an invoice or bill.
Providing data for marketing purposes is entirely voluntary. Failure to consent to marketing communication does not affect the possibility of using healthcare services, placing an order, or using the controller’s services, unless the given service consists solely in receiving marketing communication, such as a newsletter.
The data subject is entitled to the rights provided for in the GDPR, subject to limitations resulting from specific provisions, including those concerning the maintenance and storage of medical records.
The data subject has the right to:
In order to exercise the rights to which they are entitled, the data subject should contact the personal data controller using the contact details indicated in this Privacy Policy.
Irrespective of the rights arising from the GDPR, the patient is entitled to the rights specified in the regulations concerning patient rights, including the right of access to medical records concerning their health status and healthcare services provided, on the terms provided for by applicable law.
Medical records may be made available to the patient, their legal representative, a person authorised by the patient, and other entities authorised under the law.
In the case of healthcare services provided to minors, the controller may process the data of the child and the data of the child’s parent, legal guardian, statutory representative, or person authorised to act on behalf of the child. The scope of processed data depends on the purpose of processing and on obligations arising from medical law.
Personal data is not used for decision-making based solely on automated processing, including profiling that produces legal effects concerning the person or similarly significantly affects them.
If the website uses analytical or marketing tools, they may be used for statistical analysis of website traffic or for tailoring marketing content, however they are not used by the controller to make decisions producing legal effects with regard to the user.
The controller applies appropriate technical and organisational measures intended to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access, and other unlawful forms of processing.
Access to personal data is granted only to persons and entities that need such access in connection with the performance of specific tasks and are obliged to maintain confidentiality or to process data in accordance with concluded agreements and applicable law.
The controller may update the Privacy Policy in the event of changes in legal provisions, changes in the operation of the website, changes in the technical tools used, changes in the scope of services provided, or changes in the manner of processing personal data.
The current version of the Privacy Policy is available on the controller’s website.