GDPR
Privacy policy
Introduction
Our dermatology and aesthetic medicine clinic (under the brand name “Skina”, hereinafter referred to as the “Clinic”) respects your privacy and is committed to protecting the personal data it collects and processes in accordance with applicable data protection legislation, in particular the General Data Protection Regulation (GDPR).
Types of Data Collected
We collect personal data when you interact with our website, through phone calls, when you use our services, or when you are present at the clinic. This data may include:
- name, surname, email address, PIN (personal identification number), phone number
- health data necessary for the provision of medical services, respecting professional secrecy
- financial and banking data (e.g. account number, account or bank card holder, card validity) for verification of payments or receipts, bank transfers between the Clinic and you or vice versa
- video images via surveillance systems in our premises
- data related to the profiling of our website users according to the Cookies Policy (access here)
Purpose of Processing
Your personal data is processed for the following purposes:
- providing dermatology and aesthetic medicine services such as scheduling services, registering patients, establishing diagnoses, administering medical care or treatments to the data subject, tracking the evolution of treatment over time, issuing results and/or medical prescriptions, sending SMS messages for appointments/appointment confirmations
- maintaining patient and staff security through video surveillance
- reports to state institutions with which the Clinic interacts or will interact in the future (DSP, Ministry of Health, etc.)
- marketing communications and promotional offers, with your prior consent
- exercising or defending a right in court, regardless of the stage of the dispute
- resolving requests or complaints made by data subjects.
- improving your experience on our website
Legal Basis
The processing of your data is based on:
- explicit consent for the processing of health data and for marketing purposes; you have the right to withdraw your consent at any time, the withdrawal of consent will not affect the data processing carried out up to the moment of withdrawal
- legal obligations for the processing of medical data
- conclusion or execution of a medical services contract
- legitimate interest in ensuring security within the clinic premises
- video surveillance – the Clinic uses video surveillance systems to protect staff, patients and property. The images are stored securely and are only accessible to authorized personnel. They are kept for a limited period, in accordance with applicable law, and are subsequently deleted, unless required for legal investigations.
Rights of the Personal Data Subject
According to GDPR, you have the right:
- to access and request a copy of your personal data.
- to rectify incorrect data.
- to request the deletion of your data, subject to certain conditions.
- to restrict the processing of your data.
- to object to processing based on legitimate interest.
- to data portability.
- of withdrawal of consent, without affecting the lawfulness of processing carried out on the basis of consent before withdrawal.
To exercise these rights, please contact us using the contact details provided in this policy.
Data Recipients
The Clinic may disclose personal data to the following categories of recipients, with strict observance of professional secrecy and for which there is a confidentiality agreement concluded with the Clinic:
- public authorities and institutions that request this on legal grounds
- insurers, other medical service providers who can help the Clinic's patients with other types of medical investigations/analysis
- authorized persons who process personal data for or on behalf of the Clinic (e.g. debt collection companies, direct marketing service providers, etc.).
The information sent to these Recipients will be to the point, limited in relation to the purposes for which it was collected and disclosed.
Data Security
We implement appropriate technical and organizational measures to protect personal data against loss, theft or unauthorized access, disclosure, alteration or destruction.
Data Transfer
Personal data is not transferred outside the EU, to third countries (outside the EU) or international organizations.
Privacy Policy Changes
We reserve the right to modify this privacy policy. Any changes will be communicated on our website and, if applicable, by email.
Contact
For any questions or requests related to the processing of your personal data, please contact us at:
office@skina.ro
031-005-1471
Professor Dr. Mihail Georgescu Street 7, Bucharest 030167
This privacy policy is effective as of 15.02.2024.