1. Personal Data Controller
The controller of your personal data is:
Przychodnia MediPort Spółka z ograniczoną odpowiedzialnością, Aleja Zwycięstwa 239/lokal 12 II piętro, 81-521 Gdynia.
KRS: 0001198377, NIP: 5862422894, REGON: 542938005, hereinafter referred to as the “Controller” or the “Clinic”.
2. Contact regarding personal data protection
In matters related to the processing of personal data and the exercise of your rights, you may contact us by email at biuro@medi-port.pl or by post at the Controller’s registered address.
If the Controller has appointed a Data Protection Officer, the contact details of the DPO are available at the reception desk.
3. Purposes and legal bases of processing
Your personal data, including health data, is processed for the following purposes:
Provision of healthcare services
This includes diagnostics, treatment, medical consultations and maintaining medical documentation.
Legal basis: Article 6(1)(c) GDPR, Article 9(2)(h) GDPR, the provisions of the Act on Medical Activity and the Act on Patients’ Rights and the Patient Ombudsman.
Appointment registration and organisational contact
This includes confirming appointment dates, providing information about appointment changes, test results, reminders or cancellations.
Legal basis: Article 6(1)(f) GDPR.
Compliance with legal obligations
In particular obligations related to medical documentation, accounting and tax regulations.
Legal basis: Article 6(1)(c) GDPR.
Establishment, pursuit or defence of claims
Data may also be processed to ensure the legal security of the Controller.
Legal basis: Article 6(1)(f) GDPR.
4. Scope of processed data
The Controller may process, in particular, identification data, contact details, PESEL number, health data, treatment history, test results and information included in medical documentation.
5. Data recipients
Your data may be disclosed only to entities authorised under applicable law or to entities cooperating with the Controller, in particular:
- entities providing laboratory services,
- providers of IT and hosting services,
- entities providing legal and accounting services,
- entities processing data under data processing agreements,
- the National Health Fund,
- other authorities authorised under applicable law,
- persons authorised by the Patient.
6. Obligation to provide data
Providing personal data is necessary to deliver healthcare services and maintain medical documentation in accordance with applicable law. Failure to provide required data may prevent the provision of medical services.
7. Data retention period
Medical documentation is stored for the period required by law, generally for 20 years from the end of the calendar year in which the last entry was made in the medical documentation, unless specific provisions provide for a different period.
Data processed for the purpose of pursuing claims will be stored until the limitation period for such claims expires.
8. Rights of the data subject
You have the right to:
- access your data,
- obtain a copy of your data,
- rectify your data,
- restrict processing,
- object to processing based on the Controller’s legitimate interest,
- lodge a complaint with the President of the Personal Data Protection Office.
To the extent resulting from medical law, the right to erasure — the “right to be forgotten” — may be limited.
9. Transfers of data outside the European Economic Area
As a rule, your personal data is not transferred outside the European Economic Area. If IT solutions from providers outside the EEA are used, the Controller ensures appropriate safeguards required by the GDPR.
10. Automated decision-making and profiling
Your personal data is not used for automated decision-making or profiling within the meaning of the GDPR.
11. Data security
The Controller applies appropriate technical and organisational measures to protect personal data, in particular health data, against loss, destruction, disclosure or access by unauthorised persons.