We make every effort to ensure your right to privacy and privacy, respecting the confidentiality of the personal data you provide us about you, and at the same time respecting the applicable European and national data protection rules, including the General Data Protection Regulation (EU ) 2016/679 (hereinafter referred to as the “Regulation” or “GDPR”).
The purpose of this document is to inform about the processing of your personal data by the Data Operator.
The data operator is Amethyst Clinic (hereinafter referred to as “Clinic”, “Amethyst Clinic”. By “Amethyst clinic” is meant the Associated Operators R.T.C. Radiology Therapeutic Center S.R.L., Radiotherapy Center Cluj S.R.L., R.T.T. Centrul De Radioterapie Timișoara S.R.L..
If you have any questions about this policy, or about the use of personal data, we are at your disposal and you can contact us in writing at dpo@amethyst-radiotherapy.com, or at: Bucharest, sector 4, Str . Oitail, no. 7, floor 1, apartment 1, office 9
Through this policy we explain how the data controller collects, uses and manages personal data, so please read carefully to understand for what purposes and what personal data we collect, as well as all the rights you have regarding your data, in accordance with Regulation 2016/679 on the protection of personal data and national provisions on the protection of personal data.
Please check for updates to this Policy. If we make changes that we consider important, you will be able to consult them in this section, the most recent version of the Policy being published, indicating the date of the last changes.
In addition to this Privacy Policy, please also read the Cookie Policy, to find out how the Clinic uses cookies through the managed website, namely www.amethyst-radiotherapy.ro
Definitions:
Terms with the following meanings are used in this Policy:
“personal data” – any information regarding an identified or identifiable natural person (“data subject”); an identifiable natural person is a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more many specific elements, specific to his physical, physiological, genetic, psychological, economic, cultural or social identity;
“processing” – any operation or set of operations performed on personal data or sets of personal data, with or without the use of automated means, such as collection, recording, organization, structuring, storage, adaptation or modification, extract, consult, use, disclose by transmission, disseminate or otherwise make available, align or combine, restrict, delete or destroy;
“restriction of processing” – means the marking of stored personal data in order to limit their future processing.
“profiling” – means any form of automatic processing of personal data that consists in the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects of performance at the workplace work, economic situation, health, personal preferences, interests, reliability, behavior, the place where the respective natural person is or his movements;
“data subject consent” – any manifestation of the data subject’s free, specific, informed and unambiguous will by which he accepts, through a statement or an unequivocal action, that personal data concerning him be processed ;
“Operator” – entity that establishes the purposes and means of personal data processing, when the purposes and means of processing are established in accordance with the applicable legal provisions
“consent of the data subject” – Any manifestation of free, specific, informed and unambiguous will of the data subject by which he accepts, through a statement or an unequivocal action, that the personal data concerning him be processed .
“supervisory authority” – the National Supervisory Authority for the Processing of Personal Data
“Online platform” – the website developed under the domain name www.amethyst-radiotherapy.ro
“Cookies” are small text files stored on your device (computer, tablet or mobile) when you are on the Internet, including the website.
Collection and processing of personal data.
The clinic processes your personal data for the performance of the activity and for the provision of complete services.
Thus, we collect personal data in the following situations:
The table below shows the purposes for which we can process your personal data, based on the legal grounds indicated for each of them and the retention period for each of the purposes, as follows:
Purpose of processing |
Personal data processed |
Basis of processing |
Duration of processing |
Recipients/ Authorized |
Providing answers to requests regarding the processing of Personal Data |
Name, surname, telephone number, e-mail address, postal address, voice, data provided in the message sent |
Legal obligation |
During the resolution of the request, as well as 3 years from the date of resolution |
public authorities |
Online appointments |
Name and surname, e-mail, clinic, phone number, appointment date and time, services of interest |
steps taken by the data subject to conclude a contract |
Until the appointment date
|
|
Telephone appointments |
Name and surname, voice, clinic, phone number, appointment date and time, services of interest |
steps taken by the data subject to conclude a contract |
Until the appointment date |
|
Hospitalization |
Name and surname, CNP, CI data, telephone number, e-mail address, citizenship, signature, date and place of birth, picture, sex, address, health data (medical history, diagnosis / procedures carried out in the clinic) , period of treatment, proof of insurance (employee certificate – medical leave taken in the last 12 months, pension slip, retirement decision, pupil / student / military certificate), histopathological report |
Legal obligation |
100 years |
Public authorities |
Patient file |
Name and surname, CNP, CI data, telephone number, e-mail address, citizenship, signature, date and place of birth, picture, sex, address, health data (medical history, diagnosis / procedures carried out in the clinic) , treatment period, medical conclusions, medical consent |
Legal obligation |
100 years |
Public authorities |
Medical services contract |
Name and surname, CNP, CI data, telephone number, e-mail address, citizenship, signature, date and place of birth, picture, sex, address, health data (medical history, diagnosis / procedures carried out in the clinic) , treatment period, patient consent |
Legal obligation |
10 years |
Public authorities |
Patient bills |
Name and surname, address, health data (diagnosis / procedures carried out in the clinic), date of issue, costs |
Legal obligation |
10 years |
Public authorities |
Monitoring of premises and/or assets |
Image, location |
Legal obligation (Law no. 333/2006) |
30 days from the date of image registration |
CCTV system provider, security company, public authorities |
Employment / Recruitment |
The data contained in the CV, name and surname, telephone number, e-mail address, as well as references, employment test results, recruiter’s notes, signature |
Conclusion of a contract |
During the recruitment process, as well as 6 months from the date of its conclusion |
|
Creating a CV database |
The data contained in the CV, employment test results, recruiter’s notes, address, telephone number, e-mail address |
Consent |
2 years from the date of consent or until its withdrawal |
/ |
Engagement |
Name and surname, address, e-mail address, telephone number, CNP, CI data, professional experience, completed studies, diplomas, certifications, |
Contract execution |
75 years |
Public authorities |
Initiation of contracts or execution of contracts concluded by the Company |
Name, surname, function, telephone, e-mail, signature |
Contractual obligation |
During the duration of the contract, as well as 3 years from the date of its termination |
public authorities |
Initiating and developing relations between the Clinic and the representatives of the public authorities with which they interact in the course of their current activity |
Name, surname, function, telephone, e-mail, signature |
Legal obligation |
During the performance of the activity |
public authorities |
Use of social media platforms Facebook, Instagram, Youtube |
Name and surname / pseudonym used, picture, other public information on the user’s profile |
Consent |
The data will not be stored in the Clinic’s databases, but due to the functionality of social platforms, we may have access to public information from your account |
/ |
In addition to the previous mentions, it must be specified that we will keep documents containing personal data for a longer period, under the following conditions:
– If the legal provisions require it;
– If the documents are required for any current or future legal proceedings;
– To establish, execute or defend our rights before courts and beyond.
Use of cookies
Within the website we use cookies to collect technical information that can identify the user, respectively: IP address, type of internet browser used to navigate our website, your operating system, domain name or the host of the domain through which the user navigates the website.
The use of cookies is mainly intended for the following:
– Ensuring a better functioning of the website;
– Correct display of content;
– Customizing the interface, ensuring the security of the website/application against fraud or illegal use;
– The creation of statistics to know the reactions of users in relation to the content of the website;
For information about the specific cookies placed on the website, as well as for information about the possibility to control or disable Cookies, see the Cookie Policy.
Possible recipients of your personal data
To carry out the activity and offer complete services, we can use the services of contractual partners, to whom personal data can be provided with the aim of being used strictly in the fulfillment of obligations.
Our contractual partners have the capacity of Authorized Persons, within the meaning of Regulation 2016/679, the Clinic, as an operator, rigorously establishing the instructions that the contractual partners must comply with. We make every effort to ensure that all entities we work with process your personal data safely and securely.
Personal data may also be disclosed to authorities and/or public institutions(Ministry of Health, Health Insurance House, The National Authority for the Supervision of the Processing of Personal Data, the Territorial Labor Inspectorate, the Authority for Consumer Protection, the National Agency for Fiscal Administration, structures within the Ministry of Internal Affairs or the Public Ministry, courts, bailiffs) if there is a legal obligation in this regard, at their express and written request or if there are suspicions regarding the commission of a crime.
Transfer of personal data abroad
Clinica Amethyst assures you that any data transfer, if necessary, is done in strict compliance with the legislation in the field, respectively with all the legal requirements provided by Regulation 2016/679.
Security of data processing
Amethyst Clinic is committed to constantly evaluating and updating the security measures implemented to ensure that they are adequate to protect the rights and freedoms of natural persons.
In this sense, the Amethyst Clinic implements the latest technical solutions to maintain security at an adequate level.
At the same time, the Amethyst Clinic regularly conducts training and training sessions with the staff who operate activities likely to interact in any way with Personal Data.
The rights of data subjects
Note that, in accordance with the provisions of Regulation 2016/679, as a data subject you always have the following rights:
To exercise any of these rights, to make requests or complaints, please write to us by e-mail at: dpo@amethyst-radiotherapy.com.
We also note that from the moment of receiving the request, our company will formulate an answer within one month. If there are reasonable suspicions about the person who sent the request, we may take steps to clarify and confirm that the request was sent by the data subject.
You can contact the National Authority for the Supervision of Personal Data Processing by phone +40.318.059.211 or email anspdcp@dataprotection.ro sau pe adresa București sector 1, B-dul G-ral. Gheorghe Magheru 28-30.
Changes to this policy
This Privacy Policy may undergo changes and may be updated by the Clinic, to comply with any legislative changes regarding the protection of personal data, as well as whenever it deems necessary. Clinica Amethyst will publish the most recent version of the Privacy Policy on the website.
Date of last update: 08/08/2022