Your personal data are processed for the purpose of using the services of Maritime Hair Center, in particular the provision of medical services, healthcare, and the management of healthcare services.
Data required for the provision of services: first name, last name, date of birth, residential address, PESEL number (or national identification number), e-mail address, phone number. In the case of sensitive data: information about health status, past illnesses, medications taken, and current medical treatment.
We process data for the following purposes:
Healthcare and provision of services – providing health services, medical diagnosis, and treatment. Art. 6(1)(b) GDPR and Art. 9(2)(h) GDPR.
Appointment booking – entering data into the facility's IT system, registering the visit, and verifying identity on the day of the planned procedure. Art. 6(1)(c) GDPR and Art. 9(2)(h) GDPR. Required data: first name, last name, residential address, phone number, e-mail address.
Phone or e-mail contact – appointment confirmation, rescheduling or cancellation, providing information about the procedure, pre- and post-operative instructions, and assessment of health status. Art. 6(1)(c) GDPR and Art. 9(2)(h) GDPR.
Maintaining medical records – keeping, storing, and archiving documentation containing personal data, diagnosis, treatment methods, and recommendations. Art. 9(2)(h) GDPR.
Social security – issuing medical certificates or sick leaves. Art. 9(2)(h) GDPR.
Preventive healthcare – conducting follow-up visits at the Maritime Hair Center facility. Art. 9(2)(h) GDPR. Required data: first name, last name, phone number, e-mail address.
Ensuring continuity of care – contacting another medical entity to ensure the continuity of medical care. Art. 9(2)(h) GDPR. Required data: first name, last name, residential address, phone number, e-mail address and (in the case of sensitive data) information about health status, past illnesses, medications taken, and current treatment.
Transfer of data to public registries – as a medical entity, we are required to transfer patient data to public registries. Art. 6(1)(c) GDPR.
Performing auxiliary activities – as a medical entity, we may perform other auxiliary activities in the provision of health services. Art. 9(2)(h) GDPR.
Exercising data protection rights – fulfilling obligations arising from the GDPR. Articles 16-21, 33, 34 GDPR.
Establishment, exercise, and defense of claims – processing data to establish and pursue claims arising from business activities and to defend against them. Art. 6(1)(f) GDPR.
Realization of patient rights – access to information about health status, keeping, archiving, and sharing medical records. Art. 6(1)(c) GDPR, Art. 9(2)(c) and (h) GDPR.
Accounting and tax obligations – issuing invoices for provided medical services. Art. 6(1)(c) GDPR.
Providing data is necessary to conclude an agreement for the provision of healthcare services and to perform such services. Refusal to provide data results in the inability to provide healthcare services.