The controller of Users’ personal data processed in order to enable the creation of an account and the use of the Website functionalities specified in these Terms and Conditions in accordance with Article 4(7) GDPR is Sport Medica.
In all matters related to the processing of personal data, the User may contact the Data Protection Officer, Ms. Katarzyna Pisarzewska, via email: daneosobowe@luxmed.pl.
Providing personal data, accepting these Terms and Conditions and using the Service are free of charge and voluntary. Providing the data specified in section 4 is necessary to use the Service.
In order to make an Appointment Booking, the User provides their first name, last name, telephone number, email address and PESEL number or date of birth in the case of a child younger than six months.
When using the Service, Sport Medica may also process special categories of personal data relating to health (information about booking an appointment) as well as data related to granted marketing consents, and – where applicable – also the data referred to in point 6 of this section.
Personal data are processed in order to enable the use of the Service (Article 6(1)(a) and (b) GDPR). If the User consents to receiving marketing communications or to the processing of their data for marketing purposes, the data controllers are companies belonging to the LUX MED Group. A full list of companies together with their registration data can be found on the LUX MED website as well as at their registered offices and medical facilities.
Sport Medica may also process personal data in order to pursue claims arising from business activities (Article 6(1)(b) and (f) GDPR – legitimate interest of the controller). As a business entity, Sport Medica also keeps accounting records and fulfills tax obligations, which may involve the processing of personal data.
In order to ensure proper organization of its activities, including IT infrastructure and day-to-day operations, personal data may be transferred to the following categories of recipients:
- providers of technical and organizational services supporting Sport Medica’s operations (including IT service providers, courier and postal companies),
- providers of legal and advisory services assisting Sport Medica in pursuing claims (including law firms and debt collection agencies),
- providers of marketing support services (advertising agencies, SMS and email distribution providers),
- other medical entities cooperating with Sport Medica to ensure continuity of treatment and access to healthcare services.
Due to the use of external service providers (e.g. IT support), personal data may be transferred outside the European Union. In such cases Sport Medica ensures that appropriate legal safeguards are applied, such as standard contractual clauses approved by the European Commission or adequacy decisions of the European Commission.
Personal data are processed for 5 years and subsequently for the period necessary to pursue possible claims arising from business activities under the Civil Code. If the User is also a patient of Sport Medica and medical documentation has been created, it must be stored for at least 20 years from the date of the last entry. Accounting and tax-related data are processed for 5 years from the end of the calendar year in which the tax obligation arose. Data processed on the basis of marketing consent are processed until the consent is withdrawn. After these periods, the data are deleted or anonymized.
Users have the right to access their data, rectify them, request deletion or restriction of processing, object to processing and transfer their data to another controller. In order to exercise these rights, Users may contact the Data Protection Officer, the Sport Medica hotline, the website or visit any of the Facilities.
Users also have the right to lodge a complaint with the supervisory authority responsible for personal data protection.