Preamble

Our company “Pefkos Medical Center” (hereinafter referred to as “Central Clinic” or “the Company”) acts as the Controller of the personal data of users of this website and ensures that all business activities are conducted in accordance with the principles of protection of privacy, respect for human dignity, protection of personal data and confidentiality of communications, as we believe that they demonstrate our unwavering commitment to ethical and responsible practices.

The present Policy describes our standards regarding the management and protection of Personal Data by or on behalf of our Company and applies to any activity we conduct, in every area, which is related with the processing of information relating to natural persons, including, inter alia, the operation of research and therapy center, the research and promotion of medical science and in application of modern scientific developments in care and treatment of patients, corporate support and transmission of data that are necessary for the conduct of the above mentioned activities.

This  Privacy Policy for the protection of personal data is valid and applies to all facilities or/and digital environments and applications, which belong to Central Clinic and are related to Central Clinic’s activity.

Definitions

 For the purposes hereof, the following concepts are understood as follows:

“Personal Data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

“Special Categories of Personal Data”: personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation.

“Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

“Anonymization” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject.

“Pseudonymisation” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

“Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller

“Consent” of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.

“Existing legislation”: provisions that already exist in Greek, EU or other legislations, in which Central Clinic submits, and define personal data protection issues.

Controller

Any processing of personal data carried out by the Company or its affiliates, solely for the purposes and in a manner that the Company determines, Pefkos Medical Center is considered as the Data Controller. In some cases, the Company might act as a Data Processor on behalf of other legal persons, with which we are contractually bound.

What kind of personal data does the Company collect?

Central Clinic, within the context of its normal operation, may collect personal data from both its patients and its employees, as well as from its partners in general, along with other natural persons, with whom it interacts within its sphere of competence. In addition, Central Clinic collects the personal data of the users of its website.

A. Categories of Personal Data:

Depending on the form of processing, Central Clinic may collect and process data on the following categories of data subjects:

  1. Patients Data: We collect personal and sensitive data, which you provide to us yourselves, as well as all the sensitive personal data collected from medical exams and procedures that you perform or present to us, which are stored in the patient’s medical record.
  2. Employee Candidates: If you are an employee candidate and in order to learn more about the data processed by the company, you can read the privacy marking for employee candidates, which is available on Central Clinic’s website.
  3. Employee Data:  Collected any personal information required to complete the hiring and the contractual relationship of the parties.
  4. Partners Data: Collected any personal information required to complete the contractual relationship of the parties.
  5. Website Users Data: All personal data necessary to provide appropriate services to users of our website are automatically collected, while further personal data that users voluntarily provided for specific purposes may be collected.

B. Type of Personal Data

Certain personal data collected are the following:

Lawful basis for Processing Data

We process your personal data with transparency, according to principles of legality, proportionality, confidentiality and integrity, the purpose limitation and accuracy principle, of storage limitation and data minimization.

Purposes of Data Processing

Company’s purposes regarding data processing are always based in lawful basis of processing and they vary according to the categories of data subjects.

Specifically, some purposes of data processing are the following:

Transmission of Personal Data

We may transmit your personal data to third parties in the following cases:

Transmission in third countries or/and International Organizations

 Your personal data may be transmitted outside of the EU, only if appropriate safeguards are respected in accordance with the current legislation (the company checks if the Commission has adopted a decision of competence for the third country to which the transmission will take place or if appropriate safeguards are respected in accordance with the Regulation on the transmission of such data).

Duration of Personal Data Keeping

All the personal data we process are kept for predetermined and limited duration depending on the purpose of the processing, after which, the personal data are deleted from our databases. According to the Code of Medical Ethics, your medical records will be kept for 20 years since your last visit to the Central Clinic.

Under no circumstances may the maintenance period be shorter than required by law (e.g. keeping a medical record, tax documents, etc.) and data is not deleted for as long as there is a connection with the natural persons, e.g. through the contractual relationship and for the period of time during which any legal claims may rise.

Data Subjects Rights

 We take care to protect and respect your rights. Specifically, always keep the following rights:

  1. The Right of access
  2. The Right to rectification
  3. The Right to erasure (‘the right to be forgotten’)
  4. The Right to restriction of processing
  5. The Right to data portability
  6. The Right to object
  7. The Right to withdraw consent.

You can submit a request, that we will satisfy as soon as possible, without any cost. However, and only in certain cases, we may charge a certain amount, and we will notify you of the possibility of such charges upon receipt of your request for access and we will await the confirmation of your desire to proceed with the satisfaction of your request.

Furthermore, in case of exercising one or more of the above rights of rectification, erasure or restriction of processing of your personal data, these requests will also be transmitted to any third party to whom the personal data may have been transmitted in the context of the previously mentioned purposes of processing.

To exercise any of the above rights, you may contact the Data Protection Officer in the email: pefkosmedicalcenter@gmail.com

In case of exercising any of your above-mentioned rights, the Company should respond to you within one month (1 month) of the receipt and identification of your request. This period may be extended by two (2) months, if required, taking into account the complexity of the request and the number of requests. In this case, the company will provide information for such an extension within a month (1 month) of receipt of the request, as well as for the reasons of the delay.

Data Protection Officer

In order to ensure the effective protection of personal data, the subjects may address requests and questions about this privacy policy via e-mail at pefkosmedicalcenter@gmail.comand on the telephone number +30 694 4644 888.

If you are unsatisfied with the way your personal information is processed by our Company, you may contact the Hellenic Data Protection Authority (DPA) as follows:

Website: www.dpa.gr

Postal address: Kifissias Avenue 1-3, P.c., 115 23 Athens

Call Center: + 30 210 6475600

Fax: + 30 210 6475628

E-mail: contact@dpa.gr

However, we would be very pleased if we were given the opportunity to resolve your issue internally, before contacting the DPA.

Changes to the current Policy

The current Privacy Policy may be revised from time to time, according with the requirements of the applicable legislation. In case of any change of the current policy, notice will be posted on our Company’s website.