The Company with the name "VASIMBOSIS P. GEORGE – HEALTH CARE", which is based at 66-68 Vizyis Street, Thessaloniki, P.C. 54454, tel. 2313041364, ensures the privacy and confidentiality of your personal data and adopts the General Data Protection Regulation 679/2016 of the European Union in all procedures and stages of communication with you.

 

Purpose of this policy

This policy provides every person interested in receiving nursing services from the Company and every visitor/user of the Company's website with concise and transparent information regarding the practices followed for the management and protection of personal data.

It concerns any act or set of acts which is performed, with or without the use of automated means, on personal data or on sets of personal data, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, information retrieval, use, disclosure by transmission, dissemination or any other form of making available, alignment or combination, restriction, erasure or destruction.

The Policy is updated periodically and may be modified whenever necessary, without prior notice, always within the applicable legal framework and in accordance with any changes in the applicable legislation on personal data protection. We therefore recommend that you check this Policy periodically to be informed of any changes that may have been made.

 

What is personal data?

Personal data is any information that concerns a specific natural person or a person whose identity can be verified (e.g. name, ID number, address, etc.). Data related to health (physical or mental condition, receipt of medical services, etc.) are included in the general term personal data but constitute a special category of data.

 

How is your personal data collected?

Your personal data is collected in the following ways:

(a) you provide them to us when the Company provides nursing services to you or a relative of yours

(b) it is provided to us by a third party partner after you have given your consent (e.g. your treating physician).

(c) when you submit a job application to the Company. The provision of your personal data in the context of submitting a CV to find a job with the Company takes place voluntarily, as otherwise it would not be possible to assess your likelihood of being hired.

Processing is necessary to take steps at the request of the data subject prior to entering into a contract, in accordance with Article 6b of the Regulation.

(d) when you fill out electronic forms or send an e-mail, in order to obtain information or use the services provided that are available on the Company's website www.ygeias-merimna.grThe submission of your basic information is done at your choice and their processing is done with your consent for the sole purpose of informing you in accordance with article 6.b of the Regulation,

(e) automatically through the browser or mobile device you use to access our Website www.ygeias-merimna.gr

 

What kind of personal data is collected and for what purpose?

The personal data collected and further processed include:

your identity information, demographic information, address and general contact information (including email address and telephone number), yours or your relatives'The purpose of the collection is the execution of the health service contract and/or to safeguard your vital interests. The Company may transfer them within or outside the European Union to private and/or public insurance providers, partners/processors, and/or competent judicial, police or tax authorities in accordance with the applicable legal framework.

health data regarding nursing services provided by the Company or health data for medical or nursing services not provided by us but reported to us either by you or through third parties, e.g. your clinical symptoms, the medical treatments you have received, your personal medical history, the medication you are taking. The purpose of collecting the data and keeping them is the provision of nursing services and the administrative management of these services. The processing is necessary for the purposes of medical diagnosis & provision of healthcare, in accordance with Reg. 679/2016, article 9.2or.

identification data such as your CV data, knowledge, professional training and professional experience. The collection and processing is necessary to take steps at the request of the data subject prior to entering into a contract, in accordance with Article 6b of the Regulation and is done for the sole purpose of evaluating the company for the possibility of taking on a job position. Your data is kept only for this purpose and is processed by the Administration.

identification, financial, tax and communication data, such as VAT number, tax office number, contact details, address, etc. The receipt, processing and retention of your data belonging to the above categories, in accordance with article 6f of the Regulation, is necessary for the Company's compliance with its legal obligations.

identification and contact data such as name and e-mail. The receipt, processing and retention of your above data, in accordance with article 6a of the Regulation, is done with your consent for the exclusive purpose of informing you about the Company's services and products.

The Company will not process your personal data without your consent. However, the Company reserves the right, in exceptional cases, to process your personal data to the extent permitted or required by law, and/or by court decisions or prosecutorial orders/provisions.

In addition to the above data you provide to us, when you use our Website, your device automatically provides us with data so that we can serve and tailor our response to you. The type of information we collect by automated means generally includes technical information about your computer, such as your IP address or other device identifier, the type of device you are using, and the operating system version. The data we collect may also include usage information and statistics about your interaction with the Website. It may also include information about the URLs of the websites you visited, referring and exit pages, page views, time spent on a page, number of clicks, platform type, location data (if you have enabled access to your location) and other information about how you used the Platform.

This information is collected using Cookies and other similar tracking technologies. We recommend that you review our Cookies Policy to learn more about Cookies, how they are used, and how you can control their use.

More details about the technologies used on our website are listed in Policy Cookies.

 

Is the data transferred to third parties?

We may disclose your personal information (in whole or in part, as required each time) to, for example:

a) all authorized persons of our Company, e.g. legal advisors, associate nurses, etc.

b) to the providers of support systems for processing such data,

c) to the insurance company you notified us of, (e.g. EOPYY)

d) to judicial or other supervisory or audit authorities, e.g. KEELPNO, YPEDYFKA etc. within the framework of their jurisdiction

e) to third parties who have a legitimate interest, for the establishment, exercise or support of legal claims,

g) to third parties (e.g. another doctor of your choice) / companies collaborating with the Company (e.g. insurance companies with which you have contracted), upon your instruction.

In cases where your consent is required for the disclosure of your data to third parties (where they are not mentioned by law), this will be explicitly requested from you and you have the right to withdraw it at any time. In these cases, the Company assures you that it is constantly vigilant and takes all the necessary security measures so that the transmission of personal data is carried out in the safest possible manner.

They are only transferred to authorized third parties who are bound to maintain confidentiality, when they are required to have access in the context of providing the services in question (e.g. doctors for diagnostic purposes). The Company reserves the right, in exceptional cases, to process your personal information to the extent permitted or required by law, and/or by court decisions or prosecutorial orders/provisions.

The Company undertakes not to trade your personal data by making it available for sale/rent, giving it/transferring it/publishing it or disclosing it to third parties or to use it in any other way and for other purposes that may jeopardize your privacy, rights or freedoms, unless required by law, a court decision/order, an administrative act or if it constitutes a contractual obligation necessary for the proper functioning of the Company's Website and the performance of its functions.

Personal data may be transferred to partners or third parties, complying with the terms of this Policy and committed to maintaining confidentiality, who act on behalf of the Company for further processing for the purpose of providing services, evaluating and improving the functionality of the website, marketing purposes, data management and technical support, only after the user has been informed in advance and his consent has been obtained.

These third parties have contractually committed to the Company that they will use the personal data only for the above reasons, and will not transfer the personal information to third parties, nor will they disclose it to third parties unless required by law.

 

 

 

How long is my personal data kept?

The retention period can vary significantly depending on the type of data and how it is used. The determination of data retention time is based on criteria such as legal retention periods, pending or potential disputes, intellectual property or proprietary rights, contractual requirements, business instructions, or archiving needs.

According to the Code of Medical Ethics (Law 3418/2005, Government Gazette A 287/28.11.2005), “Article 14§4: The obligation to maintain medical records applies: a) in private practices and other primary health care units in the private sector, for one decade from the patient's last visit and b) in any other case, for one twenty years since the patient's last visit."

CVs are collected by the Administration and retained for 1 year after the job position is filled.

Tax information is retained in accordance with tax legislation.

 

What are my rights regarding the processing of my personal data?

You have the right at any time to request: a) access to your personal data, b) correction of your personal data if it is inaccurate or incomplete, c) the deletion of your personal data, unless their processing is necessary for the exercise of the legal rights of the Company or third parties, for the fulfillment of a legal obligation, for reasons of public interest or for the defense of our legal rights before judicial or other authorities, d) the restriction of the processing of your personal data only for specific purposes.

In order to exercise any of the above rights, please use the “Rights Exercise Request Form" and send it either by letter to the Company's headquarters (27 Grigoriou Lambraki, Thessaloniki, P.C. 54351, tel. 2313041364), or by email (to the email account: [email protected]), always stating your full details and the reason for your communication.

In the event of exercising one of your above rights, the Company will take every possible measure to satisfy the request within one month of its receipt, informing you in writing of the satisfaction of your request or of the reasons that prevent the satisfaction of one or more of them, as well as of the reasons for any delay beyond the above period of one month and in any case no later than three months. The Company will also inform you of your further rights in the event of its inadequate response. This information is in principle provided free of charge by the Company, provided that the request for notification and information is not made repeatedly, excessively and/or is manifestly unjustified.

If you believe that the Company in any way violates the applicable legislation on personal data, you reserve the right to submit a complaint/report to the competent Supervisory Authority for Personal Data Protection: http://www.dpa.gr, Kifissias 1-3, P.C. 115 23, Athens, tel. 210 6475600, email: [email protected].

In this case, we would greatly appreciate your prior communication with the Company's Data Protection Officer either by letter to the Company's headquarters (27 Grigoriou Lambraki, Thessaloniki, P.C. 54351, tel. 2313041364), or via Email (to the Email account of the Data Protection Officer: [email protected]), always stating your full details and the reason for your contact.