Amethyst Radiotherapy privacy policy

We make every effort to ensure your right to privacy and privacy, respecting the confidentiality of the personal data you provide us about you, and at the same time respecting the applicable European and national data protection rules, including the General Data Protection Regulation (EU ) 2016/679 (hereinafter referred to as the “Regulation” or “GDPR”).

The purpose of this document is to inform about the processing of your personal data by the Data Operator.

The data operator is Amethyst Clinic (hereinafter referred to as “Clinic”, “Amethyst Clinic”. By “Amethyst clinic” is meant the Associated Operators R.T.C. Radiology Therapeutic Center S.R.L., Radiotherapy Center Cluj S.R.L., R.T.T. Centrul De Radioterapie Timișoara S.R.L..

If you have any questions about this policy, or about the use of personal data, we are at your disposal and you can contact us in writing at dpo@amethyst-radiotherapy.com, or at: Bucharest, sector 4, Str . Oitail, no. 7, floor 1, apartment 1, office 9

Through this policy we explain how the data controller collects, uses and manages personal data, so please read carefully to understand for what purposes and what personal data we collect, as well as all the rights you have regarding your data, in accordance with Regulation 2016/679 on the protection of personal data and national provisions on the protection of personal data.

Please check for updates to this Policy. If we make changes that we consider important, you will be able to consult them in this section, the most recent version of the Policy being published, indicating the date of the last changes.

In addition to this Privacy Policy, please also read the Cookie Policy, to find out how the Clinic uses cookies through the managed website, namely www.amethyst-radiotherapy.ro

Definitions:

Terms with the following meanings are used in this Policy:

“personal data” – any information regarding an identified or identifiable natural person (“data subject”); an identifiable natural person is a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more many specific elements, specific to his physical, physiological, genetic, psychological, economic, cultural or social identity;

“processing” – any operation or set of operations performed on personal data or sets of personal data, with or without the use of automated means, such as collection, recording, organization, structuring, storage, adaptation or modification, extract, consult, use, disclose by transmission, disseminate or otherwise make available, align or combine, restrict, delete or destroy;

“restriction of processing” – means the marking of stored personal data in order to limit their future processing.
“profiling” – means any form of automatic processing of personal data that consists in the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects of performance at the workplace work, economic situation, health, personal preferences, interests, reliability, behavior, the place where the respective natural person is or his movements;

“data subject consent” – any manifestation of the data subject’s free, specific, informed and unambiguous will by which he accepts, through a statement or an unequivocal action, that personal data concerning him be processed ;

“Operator” – entity that establishes the purposes and means of personal data processing, when the purposes and means of processing are established in accordance with the applicable legal provisions

“consent of the data subject” – Any manifestation of free, specific, informed and unambiguous will of the data subject by which he accepts, through a statement or an unequivocal action, that the personal data concerning him be processed .

“supervisory authority” – the National Supervisory Authority for the Processing of Personal Data

“Online platform” – the website developed under the domain name www.amethyst-radiotherapy.ro

“Cookies” are small text files stored on your device (computer, tablet or mobile) when you are on the Internet, including the website.

Collection and processing of personal data.

The clinic processes your personal data for the performance of the activity and for the provision of complete services.

Thus, we collect personal data in the following situations:

  • When you use or communicate with us via social media; 
  • When you communicate with us by phone, email;
  • When you send us any kind of address;
  • When you send us your CV for employment / recruitment;
  • When you browse our website;
  • When you make appointments for any of the services offered by the clinic.

The table below shows the purposes for which we can process your personal data, based on the legal grounds indicated for each of them and the retention period for each of the purposes, as follows:

Purpose of processing

Personal data processed

Basis of processing

Duration of processing

Recipients/ Authorized

Providing answers to requests regarding the processing of Personal Data

Name, surname, telephone number, e-mail address, postal address, voice, data provided in the message sent

Legal obligation

During the resolution of the request, as well as 3 years from the date of resolution

public authorities

Online appointments

Name and surname, e-mail, clinic, phone number, appointment date and time, services of interest

steps taken by the data subject to conclude a contract

Until the appointment date

 

 

 

Telephone appointments

Name and surname, voice, clinic, phone number, appointment date and time, services of interest

steps taken by the data subject to conclude a contract

Until the appointment date

 

Hospitalization

Name and surname, CNP, CI data, telephone number, e-mail address, citizenship, signature, date and place of birth, picture, sex, address, health data (medical history, diagnosis / procedures carried out in the clinic) , period of treatment, proof of insurance (employee certificate – medical leave taken in the last 12 months, pension slip, retirement decision, pupil / student / military certificate), histopathological report

Legal obligation

100 years

Public authorities

Patient file

Name and surname, CNP, CI data, telephone number, e-mail address, citizenship, signature, date and place of birth, picture, sex, address, health data (medical history, diagnosis / procedures carried out in the clinic) , treatment period, medical conclusions, medical consent

Legal obligation

100 years

Public authorities

Medical services contract

Name and surname, CNP, CI data, telephone number, e-mail address, citizenship, signature, date and place of birth, picture, sex, address, health data (medical history, diagnosis / procedures carried out in the clinic) , treatment period, patient consent

Legal obligation

10 years

Public authorities

Patient bills

Name and surname, address, health data (diagnosis / procedures carried out in the clinic), date of issue, costs

Legal obligation

10 years

Public authorities

Monitoring of premises and/or assets

Image, location

Legal obligation (Law no. 333/2006)

30 days from the date of image registration

CCTV system provider, security company, public authorities

Employment / Recruitment

The data contained in the CV, name and surname, telephone number, e-mail address, as well as references, employment test results, recruiter’s notes, signature

Conclusion of a contract

During the recruitment process, as well as 6 months from the date of its conclusion

 

Creating a CV database

The data contained in the CV, employment test results, recruiter’s notes, address, telephone number, e-mail address

Consent

2 years from the date of consent or until its withdrawal

/

Engagement

Name and surname, address, e-mail address, telephone number, CNP, CI data, professional experience, completed studies, diplomas, certifications,

Contract execution

75 years

Public authorities

Initiation of contracts or execution of contracts concluded by the Company

Name, surname, function, telephone, e-mail, signature

Contractual obligation

During the duration of the contract, as well as 3 years from the date of its termination

public authorities

Initiating and developing relations between the Clinic and the representatives of the public authorities with which they interact in the course of their current activity

Name, surname, function, telephone, e-mail, signature

Legal obligation

During the performance of the activity

public authorities

Use of social media platforms Facebook, Instagram, Youtube

Name and surname / pseudonym used, picture, other public information on the user’s profile

Consent

The data will not be stored in the Clinic’s databases, but due to the functionality of social platforms, we may have access to public information from your account

 /

In addition to the previous mentions, it must be specified that we will keep documents containing personal data for a longer period, under the following conditions:

– If the legal provisions require it;

– If the documents are required for any current or future legal proceedings;

– To establish, execute or defend our rights before courts and beyond.

Use of cookies

Within the website we use cookies to collect technical information that can identify the user, respectively: IP address, type of internet browser used to navigate our website, your operating system, domain name or the host of the domain through which the user navigates the website.

The use of cookies is mainly intended for the following:

– Ensuring a better functioning of the website;

– Correct display of content;

– Customizing the interface, ensuring the security of the website/application against fraud or illegal use;

– The creation of statistics to know the reactions of users in relation to the content of the website;

For information about the specific cookies placed on the website, as well as for information about the possibility to control or disable Cookies, see the Cookie Policy.

Possible recipients of your personal data

To carry out the activity and offer complete services, we can use the services of contractual partners, to whom personal data can be provided with the aim of being used strictly in the fulfillment of obligations.

Our contractual partners have the capacity of Authorized Persons, within the meaning of Regulation 2016/679, the Clinic, as an operator, rigorously establishing the instructions that the contractual partners must comply with. We make every effort to ensure that all entities we work with process your personal data safely and securely.

Personal data may also be disclosed to authorities and/or public institutions(Ministry of Health, Health Insurance House, The National Authority for the Supervision of the Processing of Personal Data, the Territorial Labor Inspectorate, the Authority for Consumer Protection, the National Agency for Fiscal Administration, structures within the Ministry of Internal Affairs or the Public Ministry, courts, bailiffs) if there is a legal obligation in this regard, at their express and written request or if there are suspicions regarding the commission of a crime.

Transfer of personal data abroad

Clinica Amethyst assures you that any data transfer, if necessary, is done in strict compliance with the legislation in the field, respectively with all the legal requirements provided by Regulation 2016/679.

Security of data processing

Amethyst Clinic is committed to constantly evaluating and updating the security measures implemented to ensure that they are adequate to protect the rights and freedoms of natural persons.

In this sense, the Amethyst Clinic implements the latest technical solutions to maintain security at an adequate level.

At the same time, the Amethyst Clinic regularly conducts training and training sessions with the staff who operate activities likely to interact in any way with Personal Data.

The rights of data subjects

Note that, in accordance with the provisions of Regulation 2016/679, as a data subject you always have the following rights:

  • Right of access to processed personal data: you have the right to obtain confirmation of whether or not your personal data is processed by Clinica Amethyst and, if so, to request a copy of them; In the situation where you request copies of the information already communicated and/or in the situation of repeated requests, the Amethyst Clinic has the right to charge a reasonable fee to be communicated in advance. Amethyst Clinic has the right to refuse to respond in the event of excessive, repeated, unfounded requests.
  • The right to request rectification or completion of inaccurate or incomplete personal data; The rectification will be communicated to each recipient to whom the data were sent, unless this proves impossible or involves disproportionate efforts.
  • Right to obtain restriction processing, if:
  1. consider that the personal data processed is inaccurate, for a period that allows Amethyst Clinic to verify the accuracy of the personal data;
  2. the processing is illegal, but you do not want the deletion of the processed personal data, but the restriction of the use of this data;
  • if the Amethyst Clinic no longer needs your personal data for the defined purposes, but you need the data to establish, exercise or defend a right in court or
  1. you have objected to the processing, for the period of time necessary to verify whether the legitimate grounds prevail over your rights;
  • The right to request the deletion of processed personal data concerning you, if one of the following reasons applies:
  1. the personal data are no longer necessary to fulfill the purposes for which they were collected or processed,
  2. the data subject withdraws the consent on the basis of which the processing takes place, and there is no other legal basis for the continuation of the processing,
  • the data subject exercises his right to object, and the operator has no legitimate reasons that prevail to continue the processing;
  1. the data were processed illegally;
  2. deletion is necessary to comply with European or national legislation
  • The right to withdraw your consent at any time regarding the processing, when the processing is based on consent, but without affecting the legality of the processing activities carried out up to that moment;
  • The right to object regarding data processing for reasons related to your particular situation, when processing is based on legitimate interest, as well as to object at any time to data processing for direct marketing purposes, including profiling; All personal data processed by our company are legally owned, and the processing is carried out in a transparent way, which allows the data subject to exercise his legally guaranteed rights.
  • The right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning or similarly affects the data subject in a significant way;
  • The right to data portability, meaning the right to receive your personal data that you have provided to the Amethyst Clinic in a structured, commonly used and machine-readable form, as well as the right to transfer said data to another operator, in if the processing is based on your consent or the execution of a contract and is carried out by automatic means;
  • The right to file a complaint to the National Authority for the Supervision of the Processing of Personal Data.

To exercise any of these rights, to make requests or complaints, please write to us by e-mail at: dpo@amethyst-radiotherapy.com.

We also note that from the moment of receiving the request, our company will formulate an answer within one month. If there are reasonable suspicions about the person who sent the request, we may take steps to clarify and confirm that the request was sent by the data subject.

You can contact the National Authority for the Supervision of Personal Data Processing by phone +40.318.059.211 or email anspdcp@dataprotection.ro sau pe adresa București sector 1, B-dul G-ral. Gheorghe Magheru 28-30.

Changes to this policy

This Privacy Policy may undergo changes and may be updated by the Clinic, to comply with any legislative changes regarding the protection of personal data, as well as whenever it deems necessary. Clinica Amethyst will publish the most recent version of the Privacy Policy on the website.

Date of last update: 08/08/2022