Privacy Policy

Privacy Policy / Data Protection Notice

HENRY DUNANT HOSPITAL CENTER

 

 

  1. Information about the Data Controller

 

The Company by the name “IMITHEA MONOPROSOPI ANONYMI ETAIREIA EKMETALLEFSIS NOSILEFTIKON MONADON KAI IATRIKON DIAGNOSTIKON KENTRON KAI PAROCHIS SYNAFON YPIRESION” (translated in English as “IMITHEA NURSING UNITS AND MEDICAL - DIAGNOSTIC CENTERS OPERATION AND KINDRED SERVICES SINGLE PERSON S.A.”) and the distinctive title “IMITHEA S.A.”, headquartered in Athens, 107, Mesogeion Avenue, Tax registration No 998936357, General Commercial Registry (GEMI) No: 006502201000, S.A. Reg. No: 59294/001/Β/05/0422, which operates at the above address the “HENRY DUNANT HOSPITAL CENTER” private clinic, hereinafter “HDHC”, which provides medical services, takes the rights associated with the protection of your personal data as well as its legal obligations seriously.

This Privacy Policy (hereinafter the “Policy”), describes how we use your personal data, which is collected for the purpose of providing health services to you. Please read this Policy carefully.  

“HDHC” is the controller of your personal data.

 

  1. The personal data we collect about you and the purposes of the processing

 

2.1. HDHC informs you that its medical and nursing staff collects, records and processes your personal data and data relating to the state of your health, as derived from your medical history, admission and course of hospitalization, from the consents to perform medical operations as well as from the results of the diagnostic and clinical tests carried out in the context of your treatment as a patient, in order to provide to you medical and nursing services, taking every appropriate and advised measure to safeguard the confidentiality of this information. The health data provided to us by you and processed by the medical and nursing staff are also covered by the privacy provisions of the Code of Medical Ethics and the Nursing Code, as applicable.

2.2. At the same time, as part of your information for the further processing of the data that you may have already shared with us during the recording of your general medical data, HDHC informs you that its Financial services (Inpatient Accounting Office, Outpatient Cashier’s Office, Laboratory Cashier’s Office, Submission Department , Central Accounting Office), have to process your personal data (name, surname, treating physician, date of admission, patient barcode, patient ticket, address, profession, ID card number, social insurance number (AMKA), tax identification number (AFM), Insurance carrier, recommending doctor) or limited health data (for instance: type of intervention, type of diagnostic test) in order to issue the legal document for the payment of the medical services we provide to you and to satisfy our legal business interest as well as our legal tax obligation.  If you don’t provide us the above data it will be impossible for us to provide any medical services and this will end the relationship between us.

2.3. Information about the transfer of data to public bodies: HDHC informs you that it may transfer (by electronic and natural means), in performance of a legal obligation, your personal and sensitive personal data (health data) to your public insurance carrier [EOPYY or other Insurance Fund] and its Auditors, in order to cover and reimburse you for your medical expenses, in combination with your health coverage. We will always ask for your consent for this transfer.

2.4. Information about the transfer of data to an insurance company: HDHC informs you that it may transfer (by electronic and natural means), in performance of a legal obligation, the above necessary information, your personal and sensitive personal data concerning your hospitalization to your insurance company and its Auditors, in order to cover and reimburse you for your medical expenses, in combination with your health coverage.

2.5 The website of Henry Dunant Hospital Center is a means of communicating with the public, which provides information and information services via the internet. Visitors / users / clients can visit this website to be informed about the services and important announcements of the Henry Dunant Hospital Center. The collection and storage of any information in our databases is subject to your consent and is in accordance with applicable law. If you decide to use our website’s contact form to request information about our services, you will be asked to provide specific personal information (personal data) for your convenience.

2.6. a) Henry Dunant Hospital Center is committed to keep the information provided to us confidential and secure, ensuring its privacy. To fill an electronic form (e.g. an application), you will be asked to give a separate consent

  1. b) Henry Dunant Hospital Center keeps a record of and processes personal data, in absolute confidentiality, for the sole purpose of processing the requests of interested parties and facilitating their access to the health services it provides.
  2. c) If you are a minor above the age limit requiring parental consent in your home country, you should check the terms of this Privacy Policy and Terms of Use with your parent or guardian to make sure you understand and accept these terms.
  3. d) Any data collected through the website will not be transferred or disclosed to third parties, unless required by law and / or the competent authorities.
  4. e) Henry Dunant Hospital Center respects your right to access the personal information collected and maintained through this website, gives you the right to be informed about your data upon request, which can be submitted through the contact form of the website. You also have the right to object to the processing of any data that concerns you at any time or to report, if you wish, any misuse of your personal information.

Objections are addressed in writing to our Data Protection Officer and must contain a request for specific action, such as correction, temporary non-use, blocking, non-transmission or deletion.

Please let us know of any changes to the information provided by you.

 

  1. f) The staff of Henry Dunant Hospital Center has been informed about the information privacy and security. Access to your personal information is restricted to authorized personnel only. HDHC makes every effort to maintain an excellent level of security, however it bears no responsibility if, despite its due diligence, the confidentiality of the information is violated.
  2. g) The personal data that you disclose to us through each event platform, are processed by HDHC with the sole purpose of informing you about our services. In this context, the data is collected exclusively for sending information material at your request and is not transmitted to third parties.

 

  1. h) You have the opportunity at any time to express your wish to rectify your information or to ask us to delete it or to unsubscribe from our newsletter if you have chosen to be informed by it. We take all possible measures to secure your data; however, third-party email service providers will necessarily be involved in sending the material, for the services of whom we are not responsible.

 

  1. Data Protection Officer and your rights

 

HDHC informs you that it has a Data Protection Officer and you can contact him at: dpo@dunant.gr about the exercise of your rights, as described below, or for any question.

 

  1. Retention time of your data

 

We inform you that HDHC is obliged to keep your Medical Record in its Medical Records Archive for twenty (20) years (in application of our legal obligation under L. 3418/2005), from each of your hospitalizations as well as from the need to preserve your life, your health and to provide the appropriate treatment. Outpatient data are kept in our Archive for 20 years, while purely accounting-tax records are kept for 5 years.

The contents of a Medical Record comprise any data related to your health as well as the personal data that you have provided to us for the execution of the contract for the provision of medical services between us. 

If the time limits change, we will inform you of any change.

The data we receive through our website to make an appointment are kept secure in our computer system and are integrated in the medical records that we keep in the Archive as above.

 

  1. News, promotions and personalized offers

 

If you have agreed to it, you will receive our newsletter, be informed about promotions and personalized offers and receive health-related news.

 For our promotions we will process the minimum personal data required, i.e your name and e-mail address, for which your consent will be required in accordance with Article 6 (1) (a) of the General Data Protection Regulation (GDPR).

In each promotion you participate in, the terms and conditions of your participation will be made available to you and you will be provided with more detailed information about the processing of your personal data.

If you decide that you no longer wish to receive news and personalized offers, as mentioned above, you can just as easily subscribe to the newsletter, revoke your consent and unsubscribe. 

 

  1. Your rights

 

You have the following rights in relation to your personal data:

 

Right to revoke your consent: as the case may be, you have the right to revoke your consent at any time without prejudice to the lawfulness of any processing carried out with your consent prior to its revocation. 

 

Right to access, rectification and erasure: you have the right to request access to any of your personal data that we may hold, to request that any inaccurate data about you be rectified and, in certain cases, to request the erasure of your personal data. 

 

Right of data portability: under certain conditions, you have the right get the personal data you have provided to us in a structured, widely used and machine-readable format as well as to request that we transfer it to another controller where technically feasible. For example, you can contact us to send a Medical Record or diagnostic tests to another clinic or hospital by any available means.

 

Right to restrict processing: you have the right to restrict our processing of your personal data if:

  • you question the accuracy of such personal data until we have taken the necessary steps to correct or verify its accuracy;
  • you think such processing is illegal, but you do not want us to erase the data;
  • we no longer need your personal data for processing purposes, but you need same data to establish, pursue or defend legal claims; or
  • you have objected to the processing for reasons of legitimate interest (see below), pending verification as to whether we have compelling legitimate grounds to continue the processing.

Where the personal data is subject to such restrictions, we will process it solely with your consent or for the establishment, exercise, or defence of legal claims.

 

Right to object to the processing: as long as the conditions set by law are met, you have the right to object to the processing of your personal data. If you object to it, we will have to discontinue the processing, unless we can demonstrate compelling legitimate grounds for processing which override your interests, rights and freedoms or where we need to process the data for the establishment, exercise or defence of legal claims.

If you consider that the processing of your personal data violates the applicable law you have the right to file a complaint to: 

 

Hellenic Authority for the Protection of Personal Data,

1-3 Kifissias Avenue, 115 23, Athens, Greece

Telephone: +30-210 6475600

Fax: +30-210 6475628

E-mail: contact@dpa.gr

 

For more information regarding the exercise of your rights or for any question regarding the processing of your personal data, please contact us at dpo@dunant.gr and we will respond to your request within the applicable time frames.

 

  1. Data Security

 

HDHC uses the appropriate technical and organizational protection measures to ensure that the personal data you entrust to us is secure, whether stored in physical form or electronically.

When HDHC assigns to a third party as processor (including our service providers) to collect or process personal data on our behalf, such processor is carefully selected based on its know-how, reliability and available resources as well as based on the technical and organizational security measures it takes to secure the processing, according to the specifications set by the General Regulation of Data Protection.

Despite the measures one takes, one cannot guarantee that data transmission over the Internet is completely secure or that any electronic data storage system is 100% secure. If you have reason to believe that your interaction with us is no longer secure, for example if you feel that the security of any of the personal data you may have sent us has been compromised, please notify us immediately.

 

  1. Changes to the Privacy Policy

 

We regularly review this Privacy Policy and reserve the right to review and make changes to it in order to include any changes to our business activities, to the legal requirements and how we process personal data.

Whenever we take those actions, we will notify you through our website or upon your arrival at HDHC.

In any case, we encourage you to check this Privacy Policy from time to time for possible changes so that you are informed in time.

 

  1. Contact us

 

Finally, we assure you once again that we are at your disposal for any questions you may have regarding the processing of your personal data or this Privacy Policy at dpo@dunant.gr, the e-mail address of the Data Protection Officer at the Henry Dunant Hospital Center.