Our fast access - Monday-Friday: 8.30-16.30

Product of the month: Microbiome test

Privacy Notice

 

PRIVACY NOTICE

ON THE PROCESSING OF PERSONAL DATA OF CUSTOMERS AND OTHER THIRD PARTIES

 

  1. Data Controller name

 

ENDOMEDIX Limited Liability Company

(hereinafter „Data Controller”)

Registered office: 1139 Budapest, Esztergomi út 66. building A. Fsz. Door 3..

Postal address: 1139 Budapest, 66 Esztergomi út, Block A, Ground Floor, Door 3

Company registration number. 01-09-885846

Telephone number: (1) 413-2500
E-mail address: info@endomedix.hu

Website: www.endomedix.hu

 

The Data Controller’s premises:
5700 Gyula, Nürnbergi utca 1/b.
8200 Veszprém, Egyetem utca 7.
9024 Győr, Bem József tér 14/b.
8600 Siófok, Semmelweis utca 1.
3527 Miskolc, Dózsa György út 12.
4031 Debrecen, Bartók Béla út 27.
7200 Dombóvár, VI utca 49.
5000 Szolnok, Tófenék utca 1-3. fszt. 124.

 

Contact details for the Data Protection Officer:

Gábor Veres

veres.gabor@endomedix.hu

+36 20 663 3989

 

 

  1. The legislation forming the basis for data processing

 

The data processing activities described in this notice are governed by the following legislation:

  • Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information;
  • Regulation (EU) 2016/679 of the European Parliament and of the Council;
  • Act XLVII of 1997 on the processing and protection of health and related personal data (hereinafter: Eüak);
  • Act CLIV of 1997 on Healthcare (hereinafter: the Healthcare Act);
  • Decree No. 62/1997 (21 December) of the Ministry of Health on certain aspects of the processing of health and related personal data

III. Definitions

 

  1. affected”: a natural person who is identified or identifiable on the basis of any information;
  2. personal data”: any information relating to the data subject;
  3. data of public interest”: information held by a body or person performing a state or local government function, or any other public function as defined by law, which relates to its activities or has arisen in connection with the performance of its public function, which does not fall within the definition of personal data, recorded in any manner or form, irrespective of the method of processing, whether it is individual or part of a collection, including, in particular, data relating to the body’s powers, jurisdiction, organisational structure, professional activities, the assessment of the effectiveness of those activities, the types of data held, the legislation governing its operations, as well as data relating to financial management and contracts entered into;
  4. data in the public interest”: any data not falling within the definition of data of public interest, the disclosure, availability or accessibility of which is required by law in the public interest;
  5. special categories of personal data (special data)” personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as genetic and biometric data intended to uniquely identify natural persons, health data and personal data relating to a natural person’s sex life or sexual orientation, as well as personal data relating to criminal offences;
  6. identifiable natural person”A natural person can be identified, directly or indirectly, in particular by reference to an identifier such as a name, number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
  7. data processing”: any operation or set of operations carried out on personal data or data files, whether by automated or non-automated means, including collection, recording, organisation, classification, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
  8. restriction of data processing”: the marking of stored personal data with a view to restricting its future processing;
  9. profiling”: any form of automated processing of personal data which is used to evaluate certain personal aspects relating to a natural person, in particular with regard to their performance at work, economic situation, state of health, personal preferences, interests, reliability, behaviour, location or movements;
  10. recording system”: a collection of personal data organised in any way – whether centralised, decentralised, or structured according to functional or geographical criteria – which is accessible on the basis of specific criteria;
  11. data controller”: a natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of processing are determined by Union or Member State law, Union or Member State law may also specify the controller or the specific criteria for designating the controller;
  12. data processor”: a natural or legal person, public authority, agency or any other body which processes personal data on behalf of the data controller;
  13. recipient”: any natural or legal person, public authority, agency or any other body to whom or to which personal data are disclosed, whether or not they are a third party. Public authorities which, in the context of an individual investigation, have access to personal data in accordance with Union or Member State law shall not be regarded as recipients; the processing of such data by those public authorities must comply with the applicable data protection rules in accordance with the purposes of the processing;
  14. third party”: a natural or legal person, a public authority, agency or any other body which is not the data subject, the data controller, the data processor or those persons authorised to process personal data under the direct authority of the data controller or data processor;
  15. the data subject’s consent”: a voluntary, specific and adequate information, by which the data subject, through a statement or a clear affirmative action, indicates that they consent to the processing of personal data relating to them;
  16. data breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data that is transmitted, stored or otherwise processed;
  17. business”: a natural or legal person engaged in economic activity, irrespective of its legal form, including partnerships and associations engaged in regular economic activity;
  18. group of companies”: the controlling undertaking and the undertakings it controls;
  19. regulatory authority”: an independent public authority established by a Member State in accordance with Article 51 of the Regulation; in Hungary, this is the National Authority for Data Protection and Freedom of Information;
  20. cross-border processing of personal data”:
  21. the processing of personal data within the Union carried out in connection with the activities of a controller or processor established in more than one Member State at its places of business in those Member States; or
  22. the processing of personal data within the Union which, in the context of the activities carried out at a single establishment of the data controller or data processor, substantially affects or is likely to substantially affect data subjects in more than one Member State;
  23. information society-related service”: a service within the meaning of Article 1(1)(b) of Directive (EU) 2015/1535 of the European Parliament and of the Council;

 

  1. Data processing arising from the services provided by the data controller and the use of the website

 

  1. Booking

 

Before your appointment, you can book a time slot via the website, by telephone or even in person.

 

SCOPE OF PERSONAL DATA

THE PURPOSE OF DATA PROCESSING

LEGAL BASIS

Name

Your name is required so that we can contact you

This is carried out in the interests of the contracting party for the purposes of preparing for the use of the services provided by the Data Controller and the conclusion and performance of the relevant contract, and the use of this data takes place exclusively in this context; therefore, the legal basis applied is Article 6 (1)(b) of the GDPR.

 

Email address

The email address is required for communication between the Data Controller and you

Phone number

The telephone number is required to facilitate communication between the Data Controller and you

Date of birth

You will need to log in

Type of examination, date and time

If the enquiry is made on behalf of a company, this will help to ensure that the request for a quotation is properly understood.

 

Advance booking of appointments is required so that the Data Controller can prepare for the examinations and so that data subjects can access the services with as little waiting time and inconvenience as possible.

 

  1. Provision of services

 

The provision of healthcare services is subject to strict regulations. In this regard, the provisions of the Health Care Act apply. Under the Health Care Act, it is also mandatory to compile medical records containing data relating to the examination and treatment of patients.

 

 

SCOPE OF PERSONAL DATA

THE PURPOSE OF DATA PROCESSING

LEGAL BASIS

Personal identification data

Required to verify your identity

This is carried out for the purpose of concluding and performing a contract, in the interests of the contracting party, and the use of this data is limited exclusively to this context; therefore, the legal basis applied is Article 6 (1)(b), and, in the case of personal data relating to health, the data subject’s explicit consent pursuant to Article 6(1)(c) of the GDPR.

 

The data subject may also restrict access to the data stored in the EESZT. The data subject may amend their access to personal data stored in the EESZT by making so-called digital self-determination (DÖR) declarations, as permitted by the provisions set out in Sections 35/H and 35/I of Act XLVII of 1997 . The data subject has the option to set restrictions and permissions relating to a specific institution, department, doctor or organisational unit, and may also impose a complete ban on the retrieval of their health data across the entire healthcare system.

 

The preparation of medical records is a legal obligation; therefore, the legal basis for the processing of data relating to examinations and medical treatment is Article 6(1)(c) of the GDPR.

 

 

Data relating to medical examinations and treatment


This is necessary for carrying out consultations and examinations. Understanding the patient’s medical history and recording the results of examinations are essential for the success of treatment

 

Compliance with the healthcare documentation requirements set out in Sections 136 and 137 of the Health Care Act by recording data relating to the examination and medical treatment of patients.

Social Security number

Verification of your identity; issuing prescriptions; uploading data to the EESZT system

Address

It may be needed for the purposes of keeping in touch.

Email address, telephone number

This may be necessary for communication purposes; the Data Controller will inform data subjects by email or telephone once the results of the investigations are available

Information required for issuing an invoice

The Data Controller is obliged to issue an invoice for the healthcare services provided in accordance with the conditions laid down by law. The invoice shall specify the name of the examination carried out, in addition to the fee payable.

The issuance and retention of invoices is a legal obligation; therefore, the legal basis for the processing of invoices is Article 6(1)(c) of the GDPR.

 

 

 

In order to comply with the retention obligation set out in Section 30 of the Health Care Act, the Data Controller shall retain medical records for at least 30 years from the date of data collection and the final report for at least 50 years.

 

Under the Accounting Act (Section 169(2)), the retention period for invoices is 8 years from the date of issue.

 

  1. Newsletter subscription, sending direct marketing messages

 

The data controller enables subscribers to receive the newsletters it produces, and data subjects may also receive direct marketing messages. Newsletters are sent by email and only with the recipient’s voluntary consent.

 

SCOPE OF PERSONAL DATA

THE PURPOSE OF DATA PROCESSING

LEGAL BASIS

Name

Your name is required to keep in touch with you

Data subjects will only receive marketing messages and newsletters if they have given their explicit consent; accordingly, the legal basis for this is Article 6(1)(a) of the GDPR.

Email address

Required for sending newsletters and marketing messages

 

The data subject may give their consent to direct marketing and newsletters separately, and may withdraw such consent free of charge at any time.

 

The details of newsletter subscribers will be deleted if the data subject indicates in writing that they no longer wish to receive newsletters or direct marketing messages. The Data Controller shall in all cases regard the cancellation of registration as a withdrawal of consent.

 

Withdrawal of consent for data processing for the purposes of direct marketing and/or newsletters shall not be construed as simultaneous withdrawal of other consents to data processing given on the website; a separate withdrawal is required in respect of data processed for specific purposes. The withdrawal or cancellation of individual consents will be recorded within 3 days.

 

  1. Registration, profile

 

The data subject can register on the website, where they can enter the details required to order products (email address, delivery address) under their profile, and can also book appointments for the specified tests.

 

SCOPE OF PERSONAL DATA

THE PURPOSE OF DATA PROCESSING

LEGAL BASIS

Name

Your name is required so that we can contact you

Data processing is necessary for the preparation and performance of contracts relating to the purchase of products ordered by the data subject, including delivery; therefore, the legal basis for data processing is Article 6(1)(a) of the GDPR.

Email address

This is required for maintaining contact and managing the contract conclusion process.

Bank account details

This can be specified when paying online.

Given that the data subject also has the option of paying for the products on delivery, the provision of bank account details is voluntary; therefore, the legal basis for data processing is Article 6(1)(c) of the GDPR.

Delivery address

The address provided for the delivery of the selected products. The address provided does not necessarily have to be your home address; if you specify a parcel collection point or a delivery address other than your home address, the product will not be collected from your home.

Given that the data subject can place an order online with the Data Controller, it is strictly necessary for the performance of the contract that the data subject provides an address where the ordered product can be collected, even if this is not their place of residence. The legal basis for data processing is Article 6(1)(a) of the GDPR.

 

The Data Controller shall process the data provided under the profile created by the data subject – given that this is done on a voluntary basis – until such consent is withdrawn. The Data Controller shall regard the deletion of the profile as a withdrawal of consent and shall no longer process any data provided by the data subject under their profile. If the data subject’s profile remains inactive for at least 5 years (no logins), the Data Controller is entitled to delete the profile and erase all personal data recorded in connection with it.

 

 

 

 

  1. Online shopping

 

SCOPE OF PERSONAL DATA

THE PURPOSE OF DATA PROCESSING

LEGAL BASIS

Name

Your name is required so that we can contact you

Data processing is necessary for the preparation and performance of contracts relating to the purchase of products ordered by the data subject, including delivery; therefore, the legal basis for data processing is Article 6(1)(a) of the GDPR.

Email address

This is required for maintaining contact and managing the contract conclusion process.

Bank account details

When paying online

Given that the data subject also has the option of paying for the products on delivery, the provision of bank account details is voluntary; therefore, the legal basis for data processing is Article 6(1)(c) of the GDPR.

Delivery address

The address provided for the delivery of the selected products. The address provided does not necessarily have to be your home address; if you specify a parcel collection point or a delivery address other than your home address, the product will not be collected from your home.

Given that the data subject can place an order online with the Data Controller, it is strictly necessary for the performance of the contract that the data subject provides an address where the ordered product can be collected, even if this is not their place of residence. The legal basis for data processing is Article 6(1)(a) of the GDPR.

Information required for issuing an invoice

The Data Controller is obliged to issue an invoice for the healthcare services provided in accordance with the conditions laid down by law. The invoice shall specify the name of the examination carried out, in addition to the fee payable.

The issuance and retention of invoices is a legal obligation; therefore, the legal basis for the processing of invoices is Article 6(1)(c) of the GDPR.

 

 

 

 

Under the Accounting Act (Section 169(2)), the retention period for invoices is 8 years from the date of issue.

 

  1. Protection of personal data

 

The Data Controller takes particular care to ensure that, even within the Data Controller’s organisation, only those with the appropriate authorisation have access to the data provided by data subjects, thus reception staff are unable to, and are not permitted to, provide information on the results of investigations, whilst data processors acting on behalf of individual service providers receive only the data strictly necessary for them to perform their contractual duties.

 

The Data Controller stores the data in software operated by a reliable service provider, which also ensures that backups are made.

 

The Data Controller minimises the use of paper-based data processing; the results of examinations are communicated verbally or by email, and data subjects can access their relevant health data via the EESZT system. The Data Controller protects the offices it uses with an alarm system; even during opening hours, access to the waiting room is only possible after the reception staff have unlocked the door. An alarm system is in operation after closing time. In addition, the Data Controller has installed alarm systems.

 

 

V.I Rights relating to the use of cookies

 

What are cookies?

 

When the data subject visits the website, the Data Controller places a small data file, known as a cookie (hereinafter: cookie), on the data subject’s computer, which may serve a number of purposes.

 

The Data Controller uses only those cookies that are strictly necessary for the operation of the website, that support user sessions, that serve to identify individual user sessions, and that facilitate a more convenient user experience on the website.

 

Some of the cookies we use are temporary and are deleted when you close your browser, whilst there are also convenience cookies, which are stored on your computer for one month; if you visit our website regularly, your browser will remember your previous settings, so you do not need to accept our cookie policy again every time you visit or regularly adjust the filtering criteria to suit your needs.

 

The purpose of cookies

 

Some of the cookies we use are essential for the website to function properly (session cookie – session cookie), whilst others are designed to make the website easier to use. By recording visitors’ settings and usage patterns, they help to facilitate navigation on the site and, consequently, make it easier to use the website.

 

Types of biscuits

 

  1. Session cookies

with session cookies These are necessary for browsing the website and using its features; amongst other things, they enable the website to record the actions carried out by the data subject on a particular page, feature or service. Without the use of „session cookies”, the seamless operation of the website cannot be guaranteed. Their validity period covers the duration of the visit in question; the „cookies” are automatically deleted at the end of the session or when the browser is closed.

 

  1. Convenience cookies that enhance the user experience

These cookies enable the website to remember which settings you have chosen (for example: whether you have accepted the cookie notice and the sort order in which results are displayed in the search results list). This is done so that, on your next visit, you do not have to accept the cookie notice again and again or set the sort order in which you wish to view the content displayed on the site. Without the information stored in the cookies that hold your preferences, the website will still function, albeit less smoothly.

 

No personal data is stored in convenience cookies; we store only an identification number, which informs the website that the cookie policy has previously been accepted. The convenience cookie is stored by the browser on the user’s device and expires after one month. 

 

Checking your browser’s cookie settings, disabling cookies

 

Modern web browsers allow you to change your cookie settings. Some browsers accept cookies automatically by default, but this setting can be changed so that, in future, the user can prevent cookies from being accepted automatically. Once the settings have been changed, the browser will offer you the option to choose your cookie settings each time you visit the site.

 

It should be noted that, as the purpose of cookies is to support and facilitate the usability and processes of the website, if cookies are disabled, there is no guarantee that the data subject will be able to make full use of all the website’s functions. In this case, the website may not function as intended in the browser.

  1. Further details on the cookie settings for the following browsers

 

In addition to the information provided above regarding the use of cookies stored on your device, you can find detailed information under the „Cookie settings” menu, where you can also adjust your preferences regarding cookies.

 

  1. Data processors engaged in data processing

 

Data processors:

 

 

Operation of software (Főnix-Pro) designed to support healthcare-specific administrative and decision-making tasks:

Béker-Soft Informatika Kft. (registered office: 1184 Budapest, 73 Hengersor Street, Company registration number: 01-09-940913, tax number: 22729066-2-43.):

Carrying out laboratory tests:

Buda Partner Kft (registered office: 2049 Diósd, Álmos fejedelem u. 27.), Company Registration Number: 01-09-877515, tax number: 13869920-2-43

SPEKTRUM-LAB KFT (registered office: 1038 Budapest, Papírgyár utca 58–59; company registration number: 01-09-382851; tax number: 29191280-2-41)

Carrying out histological examinations:

LIGETI BT (registered office: 8200 Veszprém, Fűrész utca 19, Company Registration Number: 19-06-506325, tax number: 21097065-1-19)

VOTY-MED Healthcare and Services Ltd, registered office: 9023 Győr, Vasvári Pál utca 15, 2nd floor, flat 3, Company registration number: 08-09-019495, tax number: 12431948-2-08):

Outsourced accounting services

Mariann E. V. Berényi (registered office: 7/1 Sorház utca, 1103 Budapest; registration number: 52620685; tax number: 74692389-1-33)

Provision of outsourced IT services:

TBL Support Services IT, Services and Trading Ltd (registered office: 57 Batthyány utca, 1196 Budapest; Company Registration Number: 01-09-321156, tax number: 26269416-2-43

 

 

  1. Rights relating to data processing

 

  1. The right to request information (right of access)

The data subject may, at any time, request information in writing from the Data Controller via the contact details provided in Section I, asking the Data Controller to provide the following information:

– what personal data,

– on what legal grounds,

– for what purpose in relation to data processing,

– from what source,

– how long will the treatment last,

– to whom, when, on what legal basis, and which personal data the Data Controller has disclosed

who was granted access or to whom their personal data was disclosed.

The Data Controller shall respond to the data subject’s request within a maximum of 30 days by letter sent to the contact details provided by the employee.

 

  1. The right to a correction

The data subject may, at any time, request in writing, via the contact details provided in Section I, that the Data Controller amend any of their personal data (for example, they may change their email address at any time). Prior to complying with the request, the Data Controller may request appropriate proof of the change to the personal data (for example, a change of address or a change of name). The Data Controller shall comply with the request within a maximum of 30 days and shall notify the data subject of this in a letter sent to the contact details provided by the data subject.

 

  1. The right to erasure

The data subject may request the Data Controller in writing to erase their personal data using the contact details provided in Section I. The Data Controller shall reject a request for erasure if legislation or an internal policy obliges the Data Controller to continue storing the personal data. However, if there is no such obligation, the Data Controller shall comply with the data subject’s request within a maximum of 30 days and shall notify the data subject of this in a letter sent to the contact details provided by the data subject.

 

  1. To lock the right (to restrict data processing)

The data subject may request, in writing via the contact details provided in Section I, that the Data Controller block their personal data. The blocking shall remain in place for as long as the reason specified by the data subject necessitates the storage of the data. The data subject may request the blocking of the data, for example, if they believe that the Data Controller has processed the data unlawfully, but it is necessary for the purposes of administrative or court proceedings initiated by the data subject that the Data Controller does not erase the data. In such cases, the Data Controller will continue to store the personal data until requested to do so by the relevant authority or court, after which the data will be erased.

 

  1. Right to data portability

The data subject has the right to receive the personal data concerning them, which they have provided to a data controller, in a structured, commonly used and machine-readable format; they also have the right to transmit this data to another data controller, therefore, at the data subject’s request, the Data Controller shall provide the data to the data subject by burning it onto a CD.

 

  1. The right to protest

The data subject may object in writing to the processing of their personal data via the contact details provided in Section I if the Data Controller were to transfer or use their personal data for the purposes of direct marketing, opinion polling or scientific research. For example, the data subject may object if the Data Controller were to use their personal data for scientific research purposes without their consent. The data subject may also object to the processing of data if, in their view, the Data Controller processes the data solely to fulfil a legal obligation or to pursue its legitimate interests, except where such processing is based on statutory authorisation. For example, the data subject may not object if, in the course of ongoing administrative proceedings, the Data Controller discloses a request containing the data subject’s personal data to the relevant authority.

 

  1. Options for enforcing one’s rights in relation to data processing

 

Should you have any complaints regarding the processing of your personal data, please contact us in the first instance. We will do everything we can to resolve your complaint to your satisfaction as soon as possible.

  1. Initiating legal proceedings

In the event of unlawful data processing experienced by the data subject, they may bring a civil action against the Data Controller. The case falls within the jurisdiction of the regional court. You can view a list of regional courts and their contact details via the link below:

https://birosag.hu/torvenyszekek

 

  1. Notification to the Supervisory Authority

The data subject may lodge a complaint to initiate an investigation on the grounds that their personal data have been processed in a manner that infringes their rights, or that there is an imminent risk of such an infringement:

National Authority for Data Protection and Freedom of Information:

1055 Budapest, 9–11 Falk Miksa Street,

Postal address: 1363 Budapest, PO Box 9.

+36 1 391 1400

+36 1 391 1410 (fax)

ugyfelszolgalat@naih.hu

www.naih.hu