- The Personal Data Administrator is SynappseHealth Sp. z o.o. with registered office at 14A Kopalniana St apt 11, 01-321 Warsaw, Poland, Tax ID (NIP): 522-319-07-38, National Business Registry Number (REGON): 38722896700000, email: firstname.lastname@example.org.
- With respect to your rights as personal data subjects (i.e. people to whom the data relates) and with respect to the mandatory rules of law, including especially the Regulation of the European Parliament and the Council (EU) 2016/679 of 27 April 2016 on protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing directive 95/46/WE (General Data Protection Regulation), hereinafter referred to as GDPR, the Polish personal data protection Act (hereinafter referred to as the Act) and other relevant personal data protection laws, we commit to maintaining the safety and confidentiality of all personal data that you share with us. Personal Data Administrator, has introduced new security measures, as well as technical and organisational means, in order to ensure the highest possible level of personal data protection. We have introduced appropriate procedures and policies to process personal data in accordance with GDPR, so that personal data processing occurs lawfully and reliably and you, as the persons to whom the data relates, may execute all your relevant rights. Additionally, if needed, we cooperate with the regulatory body within the territory of the Republic of Poland, i.e. the President of the Data Protection Authority (hereinafter referred to as PDPA).
Our company as a Personal Data Administrator has appointed a Data Protection Officer, which is Karol Zaczek, tel. 791-083-441. Any questions, requests or complaints relating to personal data processing in our company (the Personal Data Administrator), hereinafter referred to as Applications, should be sent via e-mail to the following e-mail address: email@example.com, or in writing to the postal address of the Data Protection Supervisor, i.e. 14A Kopalniana St apt 11, 01-321 Warsaw, Poland. The Applications should clearly contain:
a) the data of the person or persons to whom the Application relates,
b) the event that the Application relates to,
c) the filed requests and their legal basis,
d) the desired means of solving the issue.
We collect the following personal data on our Website/Mobile Application:
a) name and surname – In order to use the Services of our Website, and the Mobile Application "SynappseHealth: Health Records", you will be asked to provide your name so that we can provide the services and have the opportunity to contact you,
b) date of birth - it is necessary to verify whether the person using the Website and the Mobile Application "SynappseHealth: Health Records" is able to give consent to the processing of personal data on his/her own.
c) e-mail address – we shall use the e-mail address to contact you. If you are subscribing to our newsletter, we shall also be able to send you marketing information few times a month; email address is also used as a login to our Website and in the Mobile Application "SynappseHealth: Health Records",
d) IP address of the end device – the general information relating to the usage of Internet-based connections, such as IP address (and other information contained in the system logons) are used by the Administrator for technical reasons. The IP addresses may also be used for statistical purposes, especially collecting general demographic data (e.g. about the region from which a connection is received),
f) Other personal data shall be provided by the data subject on a voluntary basis,
g) The use of the Mobile App is fully anonymous and does not require registration or creation of an Account, however, in order to take advantage of particular functionalities, in particular the e-advice of a doctor, it is necessary to give consent to the processing of personal data that are specially protected, including personal data concerning health condition, racial and ethnic origin and genetic data, which are necessary to provide e-advice.
h) Use of the Mobile Application "SynappseHealth: Health Records" also requires Users to provide information about their nationality. Features of the Mobile Application "SynappseHealth: Health Records" are also available on the Website.
Provision of the data specified above is mandatory in the following circumstances:
a) in order to use the functionality of our Website, Mobile Applications managed by the Administrator,
b) in order to set up an account on the Website, which is voluntary; in such a case, we store the data provided by you in our database in order to facilitate your future use of the services on our Website,
c) in order to execute the newsletter service (subscription) – if you want to be informed of interesting events and marketing offers, you may subscribe to our newsletter; the subscription is not mandatory and you may unsubscribe at any time.
d) sensitive personal data, i.e. personal data concerning health condition, racial and ethnic origin and genetic data, are processed by the Administrator only with the explicit consent of the data subject. The aforementioned sensitive personal data are processed in the case of a desire to use the functionality of the Mobile Application "SynappseHealth: Health Records" which allows the collect and storage of information containing data on the health of registered Users and the Mobile Application "Talk to a Doctor", which allows for anonymous questioning of the doctor, in order to obtain a medical opinion online. In the situation referred to above, the doctor to whom the inquiry is addressed does not receive information or personal data allowing to identify the person who asks the question via the Mobile Application.
- Your personal data is processed by our company, the Personal Data Administrator, in order to execution Contracts, as well as other services provided to you (i.e. persons to whom the data relates) and offered by the Website/Mobile App, i.e. on the basis of Article 6(1)(b) of GDPR. With regard to the processing of sensitive personal data, the legal basis for the processing of personal data is Article 9(2)(a) of GDPR, i.e. the explicit consent of the data subject. As per the rule of minimization, we only process the categories of personal data that are considered necessary to achieve purposes specified in the previous sentence.
- We shall process the personal data only for however long it is necessary to achieve said purposes. The personal data may be processed for a longer period of time only when the Personal Data Administrator is required by the relevant mandatory rules of law to do so, or when the provided service is continuous (e.g. newsletter subscription).
- The source of the personal data processed by the Personal Data Administrator are the persons to whom the data relates.
- Your personal data is transferred to a third country within the meaning of the provisions of the GDPR, i.e. to the United States of America, which is necessary for the performance of the Contract, as the company providing hosting services to the Administrator of Personal Data, being a processor, has its registered office in the United States. The company providing hosting services is: DigitalOcean, LLC, with its registered office at 101 Avenue of the Americas, New York, New York 10013. However, this entity is covered by the so-called Privacy Shield, which ensures an adequate level of personal data protection, and enforceability of rights of data subjects, therefore the Personal Data Administrator is entitled to use the services of the above mentioned entity..
- No personal data is shared with any third parties without express consent of the person to whom the data relates. Personal data may be shared without the consent of the person to whom it relates only with legal public bodies, i.e. government and administrative bodies (e.g. tax offices, judicial authorities and other entities with a mandate stipulated by the relevant mandatory rules of law).
Personal data may be shared with entities that process the data on our request, i.e. on the request of the Personal Data Administrator. In such cases, as the Personal Data Administrator, we conclude a contract for personal data processing with such an entity. The processing entity processes the shared personal data solely for purposes specified in the aforementioned contract. Without sharing the personal data with such entities we would not be able to conduct our business activity in our Website/Mobile App. As the Personal Data Administrator, we share the personal data for processing with entities:
a) providing hosting services for the Website/Mobile App website: DigitalOcean, LLC, 101 Avenue of the Americas, New York, New York 10013;
b) If necessary, the company providing legal services to the Administrator of Personal Data, i.e. the Data Protection Officer Karol Zaczek conducting business activity under the name REGIDO Karol Zaczek, with its registered office at 32B Partynicka St apt 5, 53-031 Wrocław, Poland, NIP: 6631856943, REGON: 381485195, telephone: 791-083-441.
The personal data is not profiled by the Personal Data Administrator.
According to the GDPR, each person whose personal data is being processed by the Personal Data Administrator as the right to:
a) be informed of the processing of their personal data, as per art. 12 of the GDPR – the Administrator is obliged to share information specified in the GDPR (incl. relating to data itself, contact details, purposes and legal basis for personal data processing, personal data recipients or categories of recipients, if any exist, or the period for which the data shall be processed or criteria, based on which such a period is set) with the person to whom the data relates; this obligation should be executed immediately at the moment when the data is first acquired (e.g. when an order is placed by a client in the Website/Mobile App), and if the data is not acquired from the person to whom it relates, but from another source, then it should be executed within a reasonable time frame, depending on the circumstances; the Administrator may choose to not provide this information to the person to whom the data relates if this person has already been informed,
b) have access to their personal data, as per art. 15 of the GDPR – when providing us with your personal data, you have the right to access and review it; it does not mean, however, that you have access to all documents that contain your data, seeing as such documents may contain confidential information; you do have the right to be informed as to which of your data is being processed and how, as well as the right to receive copies of your personal data, with the first copy being issued free of charge, and for each subsequent one, according to the GDPR, we may charge a relevant administrative fee relating to the making of the copy,
c) correct or update the personal data, as per art. 16 of the GDPR – if your personal data has changed, please inform us, as the Personal Data Administrator, of this fact, so that the personal data we are holding corresponds to the actual information and is up to date; also, in situations where the personal data has not changed, but for some reason the data we hold is incorrect or has been incorrectly saved (e.g. due to an editorial mistake), please inform us of this, so that we may correct the relevant data points,
d) delete the data (the right to be forgotten), as per art. 17 of the GDPR – in other words, you have the right to demand that we "delete" the data held by us, as the Personal Data Administrator, and the right to request that we, as the Personal Data Administrator, inform other administrators we shared your data with, of your wish to have it deleted. You may request deletion of your personal data first and foremost when:
- the purposes for which the personal data had been shared have been fulfilled,
- the basis for the processing of your personal data was an express consent that was subsequently withdrawn and there is no other legal basis for us to further process your personal data, e.g. when you unsubscribe from our newsletter and do not use any of our services,
- you filed a rejection of the processing of your personal data by us, as per art. 21 of the GDPR, and believe that we have no underlying legal basis allowing us to further process your personal data,
- your personal data was being processed illegally, i.e. for purposes that were against the law or without any legal basis for its processing – please remember that in such cases you will need to provide a basis for such a request,
- the need to delete your personal data results from the mandatory rules of law,
- the personal data relates to a minor and was collected as part of an information society service,
e) limit the processing, as per art. 18 of the GDPR – you may request from our company that we limit the scope of the processing of your personal data (meaning that until the matter is clarified, we would limit ourselves to merely storing the data), if:
- you question the accuracy of your personal data, or
- you believe that we are processing your personal data without a legal basis, but simultaneously you do not want us to delete the personal data (i.e. you are not realising the aforementioned right), or
- you filed a Rejection, as per the letter f) of this point, or
- your personal data is needed to ascertain or defend against claims, e.g. before a court of law,
f) transfer the data, as per art. 20 of the GDPR – you have the right to receive your data in a format allowing you to review it on your computer and the right to transfer the data in such format to another administrator; you have this right only when the basis for the processing of your personal data was an express consent (e.g. via subscribing to the newsletter service) or the data was processed automatically,
g) file a rejection to the processing of the personal data, as per art. 21 of the GDPR – you have the right to file a rejection, if you do not agree to us processing your personal data that we had processed thus far for specific purposes, in accordance with the mandatory rules of law,
h) refuse profiling, as per art. 22, relating to art. 4.4 of the GDPR – in our Website/Mobile App you shall not be subject to automated decision-making or profiling, as per the GDPR, unless you provide us with an express consent to do so; additionally, you shall always be informed of any instances of profiling, should they occur,
i) file a complaint to a regulatory body (i.e. to the President of the Data Protection Authority), as per art. 77 of the GDPR – if you believe we are processing your personal data illegally or in any way that violates your rights resulting from the mandatory rules of personal data protection laws.
In relation to the right to delete the data (the right to be forgotten), please note that, according to the GDPR, this right is not applicable, if:
a) processing your personal data is necessary in order to exercise the right to freedom of speech, e.g. if you placed your data in a blog or comments, etc.
b) processing your personal data is necessary for our company to fulfil its statutory legal duty – we cannot delete your data, as long as we are bound by exercising certain legal (e.g. tax-related) obligations.
c) processing your personal data is performed for the purposes of investigating, ascertaining or defending against claims.
If you wish to exercise your rights referred to in the preceding point, please use the appropriate tabs on the Website/Mobile Application, which allow you to delete your account and data stored on our Website/Mobile Application, or send an e-mail to the e-mail address of the Data Protection Officer referred to in point 3 above: firstname.lastname@example.org or contact the Data Protection Officer by telephone number: 791-083-441.
- Each ascertained instance of security breach is documented, and should any of the events, as described by the GDPR or the Act, occur, the persons to whom the data relates, as well as the PDPA, if applicable, shall be informed of it.