Our fast access - Monday-Friday: 8.30-16.30

Product of the month: Microbiome test

Privacy Notice

 

PRIVACY NOTICE

ON THE PROCESSING OF PERSONAL DATA OF CUSTOMERS AND OTHER THIRD PARTIES

 

  1. Data Controller name

 

ENDOMEDIX Limited Liability Company

(hereinafter „Data Controller”)

Registered office: 1139 Budapest, Esztergomi út 66. building A. Fsz. Door 3..

Postal address: 1139 Budapest, 66 Esztergomi út, Block A, Ground Floor, Door 3

Company registration number. 01-09-885846

Telephone number: (1) 413-2500
E-mail address: info@endomedix.hu

Website: www.endomedix.hu

 

The Data Controller’s premises:
5700 Gyula, Nürnbergi utca 1/b.
8200 Veszprém, Egyetem utca 7.
9024 Győr, Bem József tér 14/b.
8600 Siófok, Semmelweis utca 1.
3527 Miskolc, Dózsa György út 12.
4031 Debrecen, Bartók Béla út 27.
7200 Dombóvár, VI utca 49.
5000 Szolnok, Tófenék utca 1-3. fszt. 124.

 

Contact details for the Data Protection Officer:

Gábor Veres

veres.gabor@endomedix.hu

+36 20 663 3989

 

 

  1. The legislation forming the basis for data processing

 

The data processing activities described in this notice are governed by the following legislation:

  • Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information;
  • Regulation (EU) 2016/679 of the European Parliament and of the Council;
  • Act XLVII of 1997 on the processing and protection of health and related personal data (hereinafter: Eüak);
  • Act CLIV of 1997 on Healthcare (hereinafter: the Healthcare Act);
  • Decree No. 62/1997 (21 December) of the Ministry of Health on certain aspects of the processing of health and related personal data

III. Definitions

 

  1. affected”: a natural person who is identified or identifiable on the basis of any information;
  2. personal data”: any information relating to the data subject;
  3. data of public interest”: information held by a body or person performing a state or local government function, or any other public function as defined by law, which relates to its activities or has arisen in connection with the performance of its public function, which does not fall within the definition of personal data, recorded in any manner or form, irrespective of the method of processing, whether it is individual or part of a collection, including, in particular, data relating to the body’s powers, jurisdiction, organisational structure, professional activities, the assessment of the effectiveness of those activities, the types of data held, the legislation governing its operations, as well as data relating to financial management and contracts entered into;
  4. data in the public interest”: any data not falling within the definition of data of public interest, the disclosure, availability or accessibility of which is required by law in the public interest;
  5. special categories of personal data (special data)” personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as genetic and biometric data intended to uniquely identify natural persons, health data and personal data relating to a natural person’s sex life or sexual orientation, as well as personal data relating to criminal offences;
  6. identifiable natural person”A natural person can be identified, directly or indirectly, in particular by reference to an identifier such as a name, number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
  7. data processing”: any operation or set of operations carried out on personal data or data files, whether by automated or non-automated means, including collection, recording, organisation, classification, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
  8. restriction of data processing”: the marking of stored personal data with a view to restricting its future processing;
  9. profiling”: any form of automated processing of personal data which is used to evaluate certain personal aspects relating to a natural person, in particular with regard to their performance at work, economic situation, state of health, personal preferences, interests, reliability, behaviour, location or movements;
  10. recording system”: a collection of personal data organised in any way – whether centralised, decentralised, or structured according to functional or geographical criteria – which is accessible on the basis of specific criteria;
  11. data controller”: a natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of processing are determined by Union or Member State law, Union or Member State law may also specify the controller or the specific criteria for designating the controller;
  12. data processor”: a natural or legal person, public authority, agency or any other body which processes personal data on behalf of the data controller;
  13. recipient”: any natural or legal person, public authority, agency or any other body to whom or to which personal data are disclosed, whether or not they are a third party. Public authorities which, in the context of an individual investigation, have access to personal data in accordance with Union or Member State law shall not be regarded as recipients; the processing of such data by those public authorities must comply with the applicable data protection rules in accordance with the purposes of the processing;
  14. third party”: a natural or legal person, a public authority, agency or any other body which is not the data subject, the data controller, the data processor or those persons authorised to process personal data under the direct authority of the data controller or data processor;
  15. the data subject’s consent”: a voluntary, specific and adequate information, by which the data subject, through a statement or a clear affirmative action, indicates that they consent to the processing of personal data relating to them;
  16. data breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data that is transmitted, stored or otherwise processed;
  17. business”: a natural or legal person engaged in economic activity, irrespective of its legal form, including partnerships and associations engaged in regular economic activity;
  18. group of companies”: the controlling undertaking and the undertakings it controls;
  19. regulatory authority”: an independent public authority established by a Member State in accordance with Article 51 of the Regulation; in Hungary, this is the National Authority for Data Protection and Freedom of Information;
  20. cross-border processing of personal data”:
  21. the processing of personal data within the Union carried out in connection with the activities of a controller or processor established in more than one Member State at its places of business in those Member States; or
  22. the processing of personal data within the Union which, in the context of the activities carried out at a single establishment of the data controller or data processor, substantially affects or is likely to substantially affect data subjects in more than one Member State;
  23. information society-related service”: a service within the meaning of Article 1(1)(b) of Directive (EU) 2015/1535 of the European Parliament and of the Council;

 

  1. Data processing arising from the services provided by the data controller and the use of the website

 

  1. Booking

 

Before your appointment, you can book a time slot via the website, by telephone or even in person.

 

SCOPE OF PERSONAL DATA

THE PURPOSE OF DATA PROCESSING

LEGAL BASIS

Name

Your name is required so that we can contact you

This is carried out in the interests of the contracting party for the purposes of preparing for the use of the services provided by the Data Controller and the conclusion and performance of the relevant contract, and the use of this data takes place exclusively in this context; therefore, the legal basis applied is Article 6 (1)(b) of the GDPR.

 

Email address

The email address is required for communication between the Data Controller and you

Phone number

The telephone number is required to facilitate communication between the Data Controller and you

Date of birth

You will need to log in

Type of examination, date and time

If the enquiry is made on behalf of a company, this will help to ensure that the request for a quotation is properly understood.

 

Advance booking of appointments is required so that the Data Controller can prepare for the examinations and so that data subjects can access the services with as little waiting time and inconvenience as possible.

 

  1. Provision of services

 

The provision of healthcare services is subject to strict regulations. In this regard, the provisions of the Health Care Act apply. Under the Health Care Act, it is also mandatory to compile medical records containing data relating to the examination and treatment of patients.

 

 

SCOPE OF PERSONAL DATA

THE PURPOSE OF DATA PROCESSING

LEGAL BASIS

Personal identification data

Required to verify your identity

This is carried out for the purpose of concluding and performing a contract, in the interests of the contracting party, and the use of this data is limited exclusively to this context; therefore, the legal basis applied is Article 6 (1)(b), and, in the case of personal data relating to health, the data subject’s explicit consent pursuant to Article 6(1)(c) of the GDPR.

 

The data subject may also restrict access to the data stored in the EESZT. The data subject may amend their access to personal data stored in the EESZT by making so-called digital self-determination (DÖR) declarations, as permitted by the provisions set out in Sections 35/H and 35/I of Act XLVII of 1997 . The data subject has the option to set restrictions and permissions relating to a specific institution, department, doctor or organisational unit, and may also impose a complete ban on the retrieval of their health data across the entire healthcare system.

 

The preparation of medical records is a legal obligation; therefore, the legal basis for the processing of data relating to examinations and medical treatment is Article 6(1)(c) of the GDPR.

 

 

Data relating to medical examinations and treatment


This is necessary for carrying out consultations and examinations. Understanding the patient’s medical history and recording the results of examinations are essential for the success of treatment

 

Compliance with the healthcare documentation requirements set out in Sections 136 and 137 of the Health Care Act by recording data relating to the examination and medical treatment of patients.

Social Security number

Verification of your identity; issuing prescriptions; uploading data to the EESZT system

Address

It may be needed for the purposes of keeping in touch.

Email address, telephone number

This may be necessary for communication purposes; the Data Controller will inform data subjects by email or telephone once the results of the investigations are available

Information required for issuing an invoice

The Data Controller is obliged to issue an invoice for the healthcare services provided in accordance with the conditions laid down by law. The invoice shall specify the name of the examination carried out, in addition to the fee payable.

The issuance and retention of invoices is a legal obligation; therefore, the legal basis for the processing of invoices is Article 6(1)(c) of the GDPR.

 

 

 

In order to comply with the retention obligation set out in Section 30 of the Health Care Act, the Data Controller shall retain medical records for at least 30 years from the date of data collection and the final report for at least 50 years.

 

Under the Accounting Act (Section 169(2)), the retention period for invoices is 8 years from the date of issue.

 

  1. Newsletter subscription, sending direct marketing messages

 

The data controller enables subscribers to receive the newsletters it produces, and data subjects may also receive direct marketing messages. Newsletters are sent by email and only with the recipient’s voluntary consent.

 

SCOPE OF PERSONAL DATA

THE PURPOSE OF DATA PROCESSING

LEGAL BASIS

Name

Your name is required to keep in touch with you

Data subjects will only receive marketing messages and newsletters if they have given their explicit consent; accordingly, the legal basis for this is Article 6(1)(a) of the GDPR.

Email address

Required for sending newsletters and marketing messages

 

The data subject may give their consent to direct marketing and newsletters separately, and may withdraw such consent free of charge at any time.

 

The details of newsletter subscribers will be deleted if the data subject indicates in writing that they no longer wish to receive newsletters or direct marketing messages. The Data Controller shall in all cases regard the cancellation of registration as a withdrawal of consent.

 

Withdrawal of consent for data processing for the purposes of direct marketing and/or newsletters shall not be construed as simultaneous withdrawal of other consents to data processing given on the website; a separate withdrawal is required in respect of data processed for specific purposes. The withdrawal or cancellation of individual consents will be recorded within 3 days.

 

  1. Registration, profile

 

The data subject can register on the website, where they can enter the details required to order products (email address, delivery address) under their profile, and can also book appointments for the specified tests.

 

SCOPE OF PERSONAL DATA

THE PURPOSE OF DATA PROCESSING

LEGAL BASIS

Name

Your name is required so that we can contact you

Data processing is necessary for the preparation and performance of contracts relating to the purchase of products ordered by the data subject, including delivery; therefore, the legal basis for data processing is Article 6(1)(a) of the GDPR.

Email address

This is required for maintaining contact and managing the contract conclusion process.

Bank account details

This can be specified when paying online.

Given that the data subject also has the option of paying for the products on delivery, the provision of bank account details is voluntary; therefore, the legal basis for data processing is Article 6(1)(c) of the GDPR.

Delivery address

The address provided for the delivery of the selected products. The address provided does not necessarily have to be your home address; if you specify a parcel collection point or a delivery address other than your home address, the product will not be collected from your home.

Given that the data subject can place an order online with the Data Controller, it is strictly necessary for the performance of the contract that the data subject provides an address where the ordered product can be collected, even if this is not their place of residence. The legal basis for data processing is Article 6(1)(a) of the GDPR.

 

The Data Controller shall process the data provided under the profile created by the data subject – given that this is done on a voluntary basis – until such consent is withdrawn. The Data Controller shall regard the deletion of the profile as a withdrawal of consent and shall no longer process any data provided by the data subject under their profile. If the data subject’s profile remains inactive for at least 5 years (no logins), the Data Controller is entitled to delete the profile and erase all personal data recorded in connection with it.

 

 

 

 

  1. Online shopping

 

SCOPE OF PERSONAL DATA

THE PURPOSE OF DATA PROCESSING

LEGAL BASIS

Name

Your name is required so that we can contact you

Data processing is necessary for the preparation and performance of contracts relating to the purchase of products ordered by the data subject, including delivery; therefore, the legal basis for data processing is Article 6(1)(a) of the GDPR.

Email address

This is required for maintaining contact and managing the contract conclusion process.

Bank account details

When paying online

Given that the data subject also has the option of paying for the products on delivery, the provision of bank account details is voluntary; therefore, the legal basis for data processing is Article 6(1)(c) of the GDPR.

Delivery address

The address provided for the delivery of the selected products. The address provided does not necessarily have to be your home address; if you specify a parcel collection point or a delivery address other than your home address, the product will not be collected from your home.

Given that the data subject can place an order online with the Data Controller, it is strictly necessary for the performance of the contract that the data subject provides an address where the ordered product can be collected, even if this is not their place of residence. The legal basis for data processing is Article 6(1)(a) of the GDPR.

Information required for issuing an invoice

The Data Controller is obliged to issue an invoice for the healthcare services provided in accordance with the conditions laid down by law. The invoice shall specify the name of the examination carried out, in addition to the fee payable.

The issuance and retention of invoices is a legal obligation; therefore, the legal basis for the processing of invoices is Article 6(1)(c) of the GDPR.

 

 

 

 

Under the Accounting Act (Section 169(2)), the retention period for invoices is 8 years from the date of issue.

 

  1. Protection of personal data

 

The Data Controller takes particular care to ensure that, even within the Data Controller’s organisation, only those with the appropriate authorisation have access to the data provided by data subjects, thus reception staff are unable to, and are not permitted to, provide information on the results of investigations, whilst data processors acting on behalf of individual service providers receive only the data strictly necessary for them to perform their contractual duties.

 

The Data Controller stores the data in software operated by a reliable service provider, which also ensures that backups are made.

 

The Data Controller minimises the use of paper-based data processing; the results of examinations are communicated verbally or by email, and data subjects can access their relevant health data via the EESZT system. The Data Controller protects the offices it uses with an alarm system; even during opening hours, access to the waiting room is only possible after the reception staff have unlocked the door. An alarm system is in operation after closing time. In addition, the Data Controller has installed alarm systems.

 

 

V.I Rights relating to the use of cookies

 

What are cookies?

 

When the data subject visits the website, the Data Controller places a small data file, known as a cookie (hereinafter: cookie), on the data subject’s computer, which may serve a number of purposes.

 

The Data Controller uses only those cookies that are strictly necessary for the operation of the website, that support user sessions, that serve to identify individual user sessions, and that facilitate a more convenient user experience on the website.

 

Some of the cookies we use are temporary and are deleted when you close your browser, whilst there are also convenience cookies, which are stored on your computer for one month; if you visit our website regularly, your browser will remember your previous settings, so you do not need to accept our cookie policy again every time you visit or regularly adjust the filtering criteria to suit your needs.

 

The purpose of cookies

 

Some of the cookies we use are essential for the website to function properly (session cookie – session cookie), whilst others are designed to make the website easier to use. By recording visitors’ settings and usage patterns, they help to facilitate navigation on the site and, consequently, make it easier to use the website.

 

Types of biscuits

 

  1. Session cookies

with session cookies These are necessary for browsing the website and using its features; amongst other things, they enable the website to record the actions carried out by the data subject on a particular page, feature or service. Without the use of „session cookies”, the seamless operation of the website cannot be guaranteed. Their validity period covers the duration of the visit in question; the „cookies” are automatically deleted at the end of the session or when the browser is closed.

 

  1. Convenience cookies that enhance the user experience

These cookies enable the website to remember which settings you have chosen (for example: whether you have accepted the cookie notice and the sort order in which results are displayed in the search results list). This is done so that, on your next visit, you do not have to accept the cookie notice again and again or set the sort order in which you wish to view the content displayed on the site. Without the information stored in the cookies that hold your preferences, the website will still function, albeit less smoothly.

 

No personal data is stored in convenience cookies; we store only an identification number, which informs the website that the cookie policy has previously been accepted. The convenience cookie is stored by the browser on the user’s device and expires after one month. 

 

Checking your browser’s cookie settings, disabling cookies

 

Modern web browsers allow you to change your cookie settings. Some browsers accept cookies automatically by default, but this setting can be changed so that, in future, the user can prevent cookies from being accepted automatically. Once the settings have been changed, the browser will offer you the option to choose your cookie settings each time you visit the site.

 

It should be noted that, as the purpose of cookies is to support and facilitate the usability and processes of the website, if cookies are disabled, there is no guarantee that the data subject will be able to make full use of all the website’s functions. In this case, the website may not function as intended in the browser.

  1. Further details on the cookie settings for the following browsers

 

A holnapon elhelyezett sütik használatáról a fentieket meghaladóan a „sütibeállítások” menüpont alatt kaphat részletes tájékoztatást, ahol lehetősége van a sütik kapcsán beállított preferenciák beállítására is.

 

  1. Adatkezelés során igénybe vett adatfeldolgozók

 

Adatfeldolgozók:

 

 

Egészségügy specifikus, adminisztrációs és döntéshozatali feladatokat támogató szoftver (Főnix-Pro) üzemeltetése:

Béker-Soft Informatika Kft. (székhely: 1184 Budapest, Hengersor utca 73. , Cégjegyzékszám: 01-09-940913, adószám: 22729066-2-43.):

Laborvizsgálatok elvégzése:

Buda Partner Kft (székhely: 2049 Diósd, Álmos fejedelem u. 27.), Cégjegyzékszám: 01-09-877515, adószám:13869920-2-43

SPEKTRUM-LAB KFT (székhely:1038 Budapest, Papírgyár utca 58-59., Cégjegyzékszám: 01-09-382851, adószám: 29191280-2-41

Szövettani vizsgálatok elvégzése:

LIGETI BT (székhely: 8200 Veszprém, Fűrész utca 19., Cégjegyzékszám: 19-06-506325, adószám: 21097065-1-19)

VOTY-MED Egészségügyi és Szolgáltató Kft, székhely: 9023 Győr, Vasvári Pál utca 15. 2 em. 3, Cégjegyzékszám: 08-09-019495, adószám: 12431948-2-08):

Kiszervezett könyvelési szolgáltatások

Berényi Mariann E. V. (székhely: 1103 Budapest Sorház utca 7/1, Nyilvántartási szám:52620685, adószám: 74692389-1-33

Kiszervezett IT szolgáltatások biztosítása:

TBL Support Services Informatikai, Szolgáltató és Kereskedelmi Kft, (székhely: 1196 Budapest Batthyány utca 57., Cégjegyzékszám: 01-09-321156, adószám: 26269416-2-43

 

 

  1. Az adatkezeléssel kapcsolatos jogok

 

  1. A tájékoztatáskéréshez való jog (hozzáférés joga)

Az érintett az I. pontban megadott elérhetőségeken keresztül, írásban bármikor tájékoztatást kérhet az Adatkezelőtől, hogy az Adatkezelő tájékoztassa:

– milyen személyes adatot,

– milyen jogalapon,

– milyen adatkezelési cél miatt,

– milyen forrásból,

– mennyi ideig kezeli,

– az Adatkezelő kinek, mikor, milyen jogszabály alapján, mely személyes adataihoz

biztosított hozzáférést vagy kinek továbbította a személyes adatait.

Az Adatkezelő az érintett kérelmét legfeljebb 30 napon belül, a munkavállaló által megadott elérhetőségre küldött levélben teljesíti.

 

  1. A helyesbítéshez való jog

Az érintett az I. pontban megadott elérhetőségeken keresztül, írásban bármikor kérheti, hogy az Adatkezelő módosítsa valamely személyes adatát (például bármikor megváltoztathatja az e-mail címét). A kérelem teljesítését megelőzően az Adatkezelő kérheti a személyes adatban történt változás megfelelő igazolását (például lakcím megváltozása, viselt név megváltozása). Az Adatkezelő a kérelmet legfeljebb 30 napon belül teljesíti, és erről az érintett által megadott elérhetőségre küldött levélben értesíti az érintettet.

 

  1. A törléshez való jog

Az érintett az I. pontban megadott elérhetőségeken keresztül, írásban kérheti az Adatkezelőtől a személyes adatainak a törlését. A törlési kérelmet az Adatkezelő abban az esetben utasítja el, ha a jogszabály vagy valamely belső szabályzat az Adatkezelőt a személyes adatok további tárolására kötelezi. Amennyiben azonban nincs ilyen kötelezettség, akkor az Adatkezelő az érintett kérelmét legfeljebb 30 napon belül teljesíti, és erről az érintett által megadott elérhetőségre küldött levélben értesíti az érintetett.

 

  1. A zároláshoz (adatkezelés korlátozásához) való jog

Az érintett az I. pontban megadott elérhetőségeken keresztül, írásban kérheti, hogy a személyes adatait az Adatkezelő zárolja. A zárolás addig tart, amíg az érintett által megjelölt indok szükségessé teszi az adatok tárolását. Az adatok zárolását kérheti az érintett például abban az esetben, ha úgy gondolja, hogy az adatokat az Adatkezelő jogellenesen kezelte, azonban az érintett által kezdeményezet hatósági vagy bírósági eljárás érdekében szükséges az, hogy az adatokat az Adatkezelő ne törölje. Ebben az esetben a hatóság vagy a bíróság megkereséséig az Adatkezelő tovább tárolja a személyes adatot, ezt követően törli az adatokat.

 

  1. Adathordozhatósághoz való jog

Az érintett jogosult arra, hogy a rá vonatkozó, általa egy adatkezelő rendelkezésére bocsátott személyes adatokat tagolt, széles körben használt, géppel olvasható formátumban megkapja, továbbá jogosult arra, hogy ezeket az adatokat egy másik adatkezelőnek továbbítsa, tehát az érintett kérésére az Adatkezelő az adatokat CD-re kiírva az érintettnek átadja.

 

  1. A tiltakozáshoz való jog

Az érintett az I. pontban megadott elérhetőségeken keresztül, írásban tiltakozhat az adatkezelés ellen, ha az Adatkezelő személyes adatot közvetlen üzletszerzés, közvélemény-kutatás vagy tudományos kutatás céljából továbbítaná, felhasználná. Így például az érintett tiltakozhat az ellen, ha az Adatkezelő hozzájárulása nélkül személyes adatait tudományos kutatás céljából felhasználná. Az érintett tiltakozhat az adatkezelés ellen akkor is, ha az érintett szerint az Adatkezelő kizárólag jogi kötelezettség teljesítéséhez vagy jogos érdekének érvényesítéséhez szükséges, kivéve a jogszabályi felhatalmazáson alapuló adatkezeléseket. Így például nem tiltakozhat az ellen, ha folyamatban lévő hatósági eljárás során a személyes adatait tartalmazó megkeresését az Adatkezelő átadja a hatóság számára.

 

  1. Az adatkezeléssel kapcsolatos jogérvényesítési lehetősége

 

Amennyiben a személyes adatainak kezelésével kapcsolatban bármilyen panasza merül fel, kérjük, hogy azzal elsősorban hozzánk forduljon. Mi mindent megteszünk annak érdekében, hogy panaszát mielőbb megnyugtatóan kezeljük.

  1. Bírósági eljárás kezdeményezése

Az érintett által tapasztalt jogellenes adatkezelés esetén polgári pert kezdeményezhet az Adatkezelő ellen. A per elbírálása a törvényszék hatáskörébe tartozik. A törvényszékek felsorolását és elérhetőségét az alábbi linken keresztül tekintheti meg:

https://birosag.hu/torvenyszekek

 

  1. Felügyeleti Hatósághoz intézett bejelentés

Az érintett bejelentéssel vizsgálatot kezdeményezhet arra hivatkozással, hogy személyes adatainak a kezelésével jogsérelem érte, vagy annak közvetlen veszélye fennáll:

Nemzeti Adatvédelmi és Információszabadság Hatóság:

1055 Budapest, Falk Miksa utca 9-11.,

postacím: 1363 Budapest, Pf. 9.

+36 1 391 1400

+36 1 391 1410 (fax)

ugyfelszolgalat@naih.hu

www.naih.hu