Quick contact – Monday-Friday: 8.30-16.30

Product of the month: Microbiome test

Privacy Notice

 

PRIVACY NOTICE

ON THE PROCESSING OF THE PERSONAL DATA OF CLIENTS AND OTHER THIRD PARTIES

 

  1. Data controller name

 

ENDOMEDIX Korlátolt Felelősségű Társaság

(hereinafter “Data controller”)

Registered office: 1139 Budapest, Esztergomi út 66, Building A, Ground Floor, Door 3.

Postal address: 1139 Budapest, Esztergomi út 66. A. ép. Fsz. 3. ajtó

Company registration number. 01-09-885846

Phone number: (1) 413-2500
E-mail address: info@endomedix.hu

Website: www.endomedix.hu

 

The Data Controller's sites:
5700 Gyula, Nürnbergi utca 1/b.
8200 Veszprém, Egyetem utca 7.
9024 Győr, Bem József tér 14/b.
8600 Siófok, Semmelweis utca 1.
3527 Miskolc, Dózsa György út 12.
4031 Debrecen, Bartók Béla út 27.
7200 Dombóvár, VI utca 49.
5000 Szolnok, Tófenék utca 1-3. fszt. 124.

 

Contact details of the data protection officer:

Veres Gábor

veres.gabor@endomedix.hu

+36 20 663 3989

 

 

  1. Legislation on which the data processing is based

 

The following legislation applies to the data processing covered by this notice:

  • Act CXII of 2011 on the right to informational self-determination and freedom of information;
  • Regulation (EU) 2016/679 of the European Parliament and of the Council;
  • Act XLVII of 1997 on the processing and protection of health and related personal data (hereinafter: Eüak.);
  • Act CLIV of 1997 on healthcare (hereinafter: Eütv.);
  • Decree No. 62/1997. (XII.21) NM on certain issues of the processing of health and related personal data

III. Definitions

 

  1. „data subject”: any natural person identified or identifiable on the basis of any information;
  2. „personal data”: any information relating to the data subject;
  3. „data of public interest”: any information or knowledge, not falling under the concept of personal data, recorded in any manner or form, that is held by a body or person performing state or local government tasks or other public tasks defined by law and relates to its activities or was generated in connection with the performance of its public tasks, irrespective of the manner in which it is processed or its individual or collective nature, including in particular data concerning powers, competence, organisational structure, professional activities and the evaluation of their effectiveness, the types of data held and the legislation governing operations, as well as financial management and contracts concluded;
  4. „data public on grounds of public interest”: all data not falling under the concept of data of public interest whose disclosure, availability or accessibility is required by law in the public interest;
  5. „special categories of personal data (special data)” personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic and biometric data for the purpose of uniquely identifying natural persons, data concerning health and personal data concerning the sex life or sexual orientation of natural persons, as well as personal data relating to criminal offences;
  6. „identifiable natural person” an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, a number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
  7. „processing”: any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
  8. „restriction of processing”: the marking of stored personal data with the aim of limiting their processing in the future;
  9. „profiling”: any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;
  10. „filing system”: any structured set of personal data which are accessible according to specific criteria – whether centralised, decentralised or dispersed on a functional or geographical basis;
  11. „controller”: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
  12. „processor”: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
  13. „recipient”: a natural or legal person, public authority, agency or other body to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;
  14. „third party”: a natural or legal person, public authority, agency or body other than the data subject, the controller, the processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data;
  15. „consent of the data subject”: any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;
  16. „personal data breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;
  17. „enterprise”: a natural or legal person engaged in an economic activity, irrespective of its legal form, including partnerships or associations regularly engaged in an economic activity;
  18. „group of undertakings”: a controlling undertaking and its controlled undertakings;
  19. „supervisory authority”: an independent public authority established by a Member State pursuant to Article 51 of the Regulation; in Hungary, the Nemzeti Adatvédelmi és Információszabadság Hatóság (Hungarian National Authority for Data Protection and Freedom of Information);
  20. „cross-border processing of personal data”:
  21. processing of personal data which takes place in the Union in the context of the activities of establishments in more than one Member State of a controller or processor established in more than one Member State; or
  22. processing of personal data which takes place in the Union in the context of the activities of a single establishment of a controller or processor but which substantially affects or is likely to substantially affect data subjects in more than one Member State;
  23. „information society service”: a service as defined in point (b) of Article 1(1) of Directive (EU) 2015/1535 of the European Parliament and of the Council;

 

  1. Data processing arising in connection with the services provided by the data controller and the use of the website

 

  1. Appointment booking

 

Before attending for treatment, you can book an appointment via the website, by phone or even in person.

 

SCOPE OF PERSONAL DATA

PURPOSE OF DATA PROCESSING

LEGAL BASIS

Name

your name is needed in order to contact you

It is carried out for the purpose of preparing the use of the services provided by the Data Controller and of concluding and performing the relevant contract, in the interest of the contracting partner, and these data are used exclusively in this connection; the legal basis applied is therefore Article 6(1)(b) GDPR.

 

E-mail address

the e-mail address is needed for communication between the Data Controller and you

Phone number

the phone number is needed for communication between the Data Controller and you

Date of birth

Needed to identify you

Type of examination, date and time

If the enquiry is made on behalf of a company, it helps us to understand the request for a quotation.

 

Booking appointments in advance is necessary so that the Data Controller can prepare for the examinations and data subjects can use the services with as little waiting and inconvenience as possible.

 

  1. Provision of services

 

The provision of healthcare services is subject to strict rules, and the provisions of the Eüak apply. Under the Eütv., it is also mandatory to prepare medical records containing data relating to the examination and treatment of patients.

 

 

SCOPE OF PERSONAL DATA

PURPOSE OF DATA PROCESSING

LEGAL BASIS

Personal identification data

Needed to identify you

It is carried out for the purpose of concluding and performing the contract, in the interest of the contracting partner, and these data are used exclusively in this connection; the legal basis applied is therefore Article 6(1)(b) GDPR and, with regard to personal health data, the data subject's explicit consent under Article 6(1)(c) GDPR.

 

The data subject is also entitled to restrict access to data stored in the EESZT (Hungarian Electronic Health Service Space). The data subject can change access to the personal data stored in the EESZT by making so-called digital self-determination (DÖR) declarations, which are made possible by the provisions of § 35/H and § 35/I of Act XLVII of 1997 on the processing and protection of health and related personal data. The data subject can set restricting and permitting provisions relating to an institution, a particular department, a specific doctor or an organisational unit, and can also impose a complete ban on queries of their health data across all healthcare providers.

 

Preparing medical records is a legal obligation; the legal basis for processing data relating to examinations and treatment is therefore Article 6(1)(c) GDPR.

 

 

Data relating to examinations and treatment


Needed to carry out consultations and examinations. Knowing the medical history and recording examination results are essential for successful treatment

 

Fulfilment of the medical documentation obligation under § 136 and § 137 of the Eütv. by recording data relating to the patient's examination and treatment.

TAJ number (social security number)

Identifying you; issuing prescriptions, uploading data to the EESZT system

Home address

may be needed for contact purposes.

E-mail address, phone number

May be needed for contact purposes; the Data Controller informs data subjects by e-mail or phone when their examination results are ready

Data needed to issue an invoice

The Data Controller is obliged to issue an invoice for the healthcare services provided in accordance with the conditions laid down by law. The invoice – in addition to the fee payable – also shows the name of the examination performed.

Issuing and retaining invoices is a legal obligation; the legal basis for processing invoices is therefore Article 6(1)(c) GDPR.

 

 

 

To fulfil the retention obligation under § 30 of the Eüak., the Data Controller retains medical records for at least 30 years from the date of data collection, and final reports for at least 50 years.

 

Under the Accounting Act (§ 169 (2)), invoices are retained for 8 years from the date of issue.

 

  1. Newsletter subscription, sending direct marketing messages

 

The data controller enables subscribers to receive the newsletters it edits, and data subjects may also receive direct marketing messages. Newsletters are sent by e-mail and only with voluntary consent.

 

SCOPE OF PERSONAL DATA

PURPOSE OF DATA PROCESSING

LEGAL BASIS

Name

your name is needed in order to stay in contact with you

Data subjects only receive marketing messages and newsletters if they have expressly consented to this; accordingly, the legal basis is Article 6(1)(a) GDPR.

E-mail address

Needed to send newsletters and marketing messages

 

The data subject can give consent to direct marketing and to the newsletter separately, and can withdraw it/them free of charge at any time.

 

The data of newsletter subscribers are deleted when the data subject indicates in writing that they no longer wish to receive newsletters or direct marketing messages. The Data Controller regards deletion of the registration as withdrawal of consent in all cases.

 

Withdrawal of consent to data processing for direct marketing and/or newsletter purposes cannot be interpreted as simultaneous withdrawal of other consents to data processing given on the website; data processed for separate purposes require separate withdrawal. The withdrawal of individual consents or unsubscriptions is registered within 3 days.

 

  1. Registration, profile

 

The data subject can register on the site, where they can provide the data needed to order products under their profile (e-mail address, delivery address), and can also start booking appointments for specified examinations.

 

SCOPE OF PERSONAL DATA

PURPOSE OF DATA PROCESSING

LEGAL BASIS

Name

your name is needed for keeping in contact with you

Data processing is necessary to prepare and perform the contracts for the purchase of products ordered by the data subject, including delivery; the basis for data processing is therefore Article 6(1)(a) GDPR.

E-mail address

Needed for communication and for managing the contract conclusion process.

Bank account details

May be provided in the case of online payment.

Given that the data subject also has the option of paying for products by cash on delivery, bank account details are provided voluntarily; the legal basis for data processing is therefore Article 6(1)(c) GDPR.

Delivery address

The address provided for delivery of the selected products. The address provided is not necessarily the home address; in the case of a parcel point or a delivery address other than the home address, the product is not received at the place of residence.

Given that the data subject can order online from the Data Controller, it is essential for the performance of the contract that the data subject provides an address where the ordered product can be received, even if it is not their place of residence. The basis for data processing is Article 6(1)(a) GDPR.

 

Given its voluntary nature, the Data Controller processes the data provided under the profile created by the data subject until consent is withdrawn. The Data Controller regards deletion of the profile as withdrawal of consent and no longer processes any data that the data subject provided under their profile. If the data subject's profile is inactive (no logins) for at least 5 years, the Data Controller is entitled to terminate the profile and delete all personal data recorded in connection with it.

 

 

 

 

  1. Online shopping

 

SCOPE OF PERSONAL DATA

PURPOSE OF DATA PROCESSING

LEGAL BASIS

Name

your name is needed for keeping in contact with you

Data processing is necessary to prepare and perform the contracts for the purchase of products ordered by the data subject, including delivery; the basis for data processing is therefore Article 6(1)(a) GDPR.

E-mail address

Needed for communication and for managing the contract conclusion process.

Bank account details

In the case of online payment

Given that the data subject also has the option of paying for products by cash on delivery, bank account details are provided voluntarily; the legal basis for data processing is therefore Article 6(1)(c) GDPR.

Delivery address

The address provided for delivery of the selected products. The address provided is not necessarily the home address; in the case of a parcel point or a delivery address other than the home address, the product is not received at the place of residence.

Given that the data subject can order online from the Data Controller, it is essential for the performance of the contract that the data subject provides an address where the ordered product can be received, even if it is not their place of residence. The basis for data processing is Article 6(1)(a) GDPR.

Data needed to issue an invoice

The Data Controller is obliged to issue an invoice for the healthcare services provided in accordance with the conditions laid down by law. The invoice – in addition to the fee payable – also shows the name of the examination performed.

Issuing and retaining invoices is a legal obligation; the legal basis for processing invoices is therefore Article 6(1)(c) GDPR.

 

 

 

 

Under the Accounting Act (§ 169 (2)), invoices are retained for 8 years from the date of issue.

 

  1. Protection of personal data

 

The Data Controller pays particular attention to ensuring that, even within the Data Controller's organisation, only those who are authorised to do so can access the data provided by data subjects; thus reception staff cannot and may not give information about examination results, and individual service providers, in their capacity as data processors, receive only the data strictly necessary to perform their contractual tasks.

 

The Data Controller stores the data in software operated by a reliable service provider, which also takes care of making backups.

 

The Data Controller minimises paper-based data processing; examination results are provided orally or by e-mail, and data subjects can access their relevant health data in the EESZT system. The Data Controller protects the offices it uses with an alarm; even during opening hours, the waiting room can only be entered after the reception staff have opened the door. An alarm system operates after closing. The Data Controller has also installed alarm devices.

 

 

V.I Rights relating to cookie management

 

What are cookies

 

When the data subject visits the website, the Data Controller places a small data file, a so-called cookie (hereinafter: cookie), on the data subject's computer, which may serve several purposes.

 

The Data Controller only uses cookies that are strictly necessary for the site to function, that support sessions and identify individual user sessions, and that make the website more convenient to use.

 

Some of the cookies we use are only temporary and disappear when the browser is closed, while there are convenience cookies that are stored on your computer for 1 month so that, if you visit our website regularly, your browser remembers the settings you used previously; this way you do not need to accept our cookie notice again every time you view the site or regularly set the filter conditions you need.

 

Purpose of cookies

 

Some of the cookies we use are essential for the site to work properly (session cookies), while others help to make the website more convenient to use. By recording the visitor's settings and usage habits, they make navigating the site, and thus using the website, easier.

 

Types of cookies

 

  1. Session cookies

The session cookies are needed to browse the website and use its functions; among other things, they make it possible to remember operations performed by the data subject on a given page, function or service. Without “session cookies”, smooth use of the website cannot be guaranteed. They are valid for the duration of the visit; the “cookies” are deleted automatically at the end of the session or when the browser is closed.

 

  1. Convenience cookies supporting use

These cookies allow the website to remember the mode of operation chosen by the data subject (for example, that they have accepted the cookie notice, and the sort order in which results in the search results list should be displayed). This is so that on the next visit the data subject does not have to accept the cookie notice again and again or set the order in which they wish to view the content displayed on the site. Without the information in cookies that store preferences, the website can still work, albeit less smoothly.

 

No personal data are recorded in convenience cookies; we only store an identification number that tells the site that the cookie notice has previously been accepted. The convenience cookie is stored by the client computer's browser with an expiry time of 1 month. 

 

Checking browser cookie settings, disabling cookies

 

Modern browsers allow cookie settings to be changed. Some browsers accept cookies automatically by default, but this setting can also be changed so that the user prevents automatic acceptance in the future. Once changed, the browser will offer the choice of cookie settings every time.

 

It should be noted that, since the purpose of cookies is to support and facilitate the usability and processes of the website, if cookies are disabled there is no guarantee that the data subject will be able to use all of the website's functions in full. In this case, the website may work differently than intended in the browser.

  1. Further detailed information on the cookie settings of the following browsers

 

In addition to the above, you can obtain detailed information about the use of cookies placed on the website under the “cookie settings” menu item, where you can also set your cookie preferences.

 

  1. Data processors used in data processing

 

Data processors:

 

 

Operation of healthcare-specific software supporting administrative and decision-making tasks (Főnix-Pro):

Béker-Soft Informatika Kft. (registered office: 1184 Budapest, Hengersor utca 73. , company registration number: 01-09-940913, tax number: 22729066-2-43.):

Laboratory testing:

Buda Partner Kft (registered office: 2049 Diósd, Álmos fejedelem u. 27.), company registration number: 01-09-877515, tax number:13869920-2-43

SPEKTRUM-LAB KFT (registered office:1038 Budapest, Papírgyár utca 58-59., company registration number: 01-09-382851, tax number: 29191280-2-41

Histological examinations:

LIGETI BT (registered office: 8200 Veszprém, Fűrész utca 19., company registration number: 19-06-506325, tax number: 21097065-1-19)

VOTY-MED Egészségügyi és Szolgáltató Kft, registered office: 9023 Győr, Vasvári Pál utca 15. 2 em. 3, company registration number: 08-09-019495, tax number: 12431948-2-08):

Outsourced accounting services

Berényi Mariann E. V. (registered office: 1103 Budapest Sorház utca 7/1, registration number:52620685, tax number: 74692389-1-33

Provision of outsourced IT services:

TBL Support Services Informatikai, Szolgáltató és Kereskedelmi Kft, (registered office: 1196 Budapest Batthyány utca 57., company registration number: 01-09-321156, tax number: 26269416-2-43

 

 

  1. Rights relating to data processing

 

  1. The right to request information (right of access)

The data subject may at any time request information in writing from the Data Controller, via the contact details given in section I, as to:

– what personal data,

– on what legal basis,

– for what data processing purpose,

– from what source,

– and for how long it processes,

– to whom, when and on the basis of which legislation the Data Controller has granted access to which of their personal data

or to whom it has transferred their personal data.

The Data Controller fulfils the data subject's request within 30 days at most, by letter sent to the contact details provided by the employee.

 

  1. The right to rectification

The data subject may at any time request in writing, via the contact details given in section I, that the Data Controller modify any of their personal data (for example, they may change their e-mail address at any time). Before fulfilling the request, the Data Controller may ask for appropriate proof of the change in the personal data (for example, a change of address or a change of name). The Data Controller fulfils the request within 30 days at most and notifies the data subject of this by letter sent to the contact details provided by the data subject.

 

  1. The right to erasure

The data subject may request the Data Controller in writing, via the contact details given in section I, to erase their personal data. The Data Controller will reject the erasure request if legislation or an internal policy obliges the Data Controller to continue storing the personal data. If there is no such obligation, however, the Data Controller fulfils the data subject's request within 30 days at most and notifies the data subject of this by letter sent to the contact details provided by the data subject.

 

  1. The right to blocking (restriction of processing)

The data subject may request in writing, via the contact details given in section I, that the Data Controller block their personal data. Blocking lasts as long as the reason indicated by the data subject makes it necessary to store the data. The data subject may request blocking, for example, if they believe that the Data Controller has processed the data unlawfully, but it is necessary for the Data Controller not to erase the data for the purposes of official or court proceedings initiated by the data subject. In this case, the Data Controller will continue to store the personal data until the authority or court makes a request, and will then erase the data.

 

  1. The right to data portability

The data subject has the right to receive the personal data concerning them, which they have provided to a controller, in a structured, commonly used and machine-readable format, and has the right to transmit those data to another controller; accordingly, at the data subject's request, the Data Controller will write the data to a CD and hand it over to the data subject.

 

  1. The right to object

The data subject may object in writing to data processing, via the contact details given in section I, if the Data Controller would transfer or use personal data for direct marketing, opinion polling or scientific research. For example, the data subject may object if the Data Controller were to use their personal data for scientific research without their consent. The data subject may also object to data processing if, in their view, the processing is necessary solely for the Data Controller to fulfil a legal obligation or to enforce its legitimate interests, except for data processing based on statutory authorisation. For example, they cannot object if, during ongoing official proceedings, the Data Controller passes a request containing their personal data on to the authority.

 

  1. Options for enforcing your rights in relation to data processing

 

If you have any complaint about the processing of your personal data, please contact us first. We will do everything we can to resolve your complaint satisfactorily as soon as possible.

  1. Initiating court proceedings

In the event of unlawful data processing experienced by the data subject, they may bring a civil action against the Data Controller. The case falls within the jurisdiction of the regional court. A list of the regional courts and their contact details can be viewed via the following link:

https://birosag.hu/torvenyszekek

 

  1. Complaint to the Supervisory Authority

The data subject may initiate an investigation by filing a complaint on the grounds that the processing of their personal data has infringed their rights or that there is an imminent risk of this:

Nemzeti Adatvédelmi és Információszabadság Hatóság (Hungarian National Authority for Data Protection and Freedom of Information):

1055 Budapest, Falk Miksa utca 9-11.,

postal address: 1363 Budapest, Pf. 9.

+36 1 391 1400

+36 1 391 1410 (fax)

ugyfelszolgalat@naih.hu

www.naih.hu