INFORMATION ABOUT THE CONTROLLER AND ITS CONTACT INFORMATION
- The Personal Data Processing Controller is iVF Riga SIA (hereinafter referred to as the Clinic), unified registration No. 40103352569, registered address: 1 Zaļā Street, Riga, LV-1010
information for matters related to the processing of personal data:
- By post: 1 Zaļā Street, Riga, LV-1010
- By phone: +371 61 111 17
- By e-mail: firstname.lastname@example.org
TERMS AND CONDITIONS
- Data Controller
Data Controller means the natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal information is processed.
- Data Processor
Data Processor means any natural or legal person who processes the data on behalf of the Data Controller.
- Data Subject
Data Subject means any living individual who is using the services of our Database.
- Database Services
Information available on this Website.
An informative description of a person who is willing to donate his/her genetic material, has undergone all necessary examinations (including genetic examinations) for donation and has been accepted in the iVF Riga Donor Program.
The information in this description is for information purposes only and does not in any way reveal the identity of the person.
A qualified medical consultant who is an employee of iVF Riga and represents your interests in the services provided by iVF Riga Clinic.
- Access to and use of this Website and the information available through this Website (hereinafter referred to as the “Database Services”) are subject to the following terms and conditions (hereinafter referred to as the “Terms and Conditions”). By using the Website (www.ivfrigadonors.eu – hereinafter referred to as the “Website”), you agree to all of the Terms and Conditions of the Website. As terms and conditions may be updated by us from time to time, you should check this page regularly to take notice of any changes we may have made to the Terms and Conditions.
- Access to this Website is permitted on a temporary basis, and we reserve the right to withdraw or amend the Database Services without notice. We will not be liable if for any reason this Website is unavailable at any time or for any period. From time to time, we may restrict access to some parts or all of this Website.
- The Database Services provided offer only informative content about the Donors available, and your request will be carefully checked by our Coordinators and accepted or declined by your Coordinator within 24 hours from receiving your request, except for Saturday and Sunday (GMT +2) when the Coordinator will contact you within the next business day.
- The e-mail which you will receive immediately after confirming the chosen donor is informative and confirms only the fact that we have received your request and it has been forwarded for confirmation to our Coordinators.
- Information about the availability of your requested donor will be provided to you within 24 hours by the Coordinator to your specified e-mail except for Saturday and Sunday (GMT +2) when the Coordinator will contact you within next business day.
- The Website only provides an informative description of the Donors, which does not in any way reveal the identity of the Donors, and the identity of the Recipient is also not revealed to the Donors.
- natural persons – Clients (patients and donors) of the Clinic (including potential, past and present clients);
- visitors to the Clinic, including those subject to video surveillance;
- visitors to the Clinic’s Website.
- The Clinic shall protect the Patients’ privacy and their personal data, and shall respect the Clients’ right to legitimate processing of their personal data pursuant to the applicable law – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data; the Personal Data Protection Law; the Law on the Rights of Patients; the Medical Treatment Law and other applicable privacy and data processing rules and regulations.
its operation, the Clinic:
- protects the Data Subject’s personal data by implementing administrative, technical and physical security measures as far as they are proportionate to the risks involved;
- informs and explains what personal data is required for receiving the services and how it will be used;
- transfers data to third parties in compliance with the applicable regulatory framework;
- implements measures to provide regular training and information to its personnel on the protection of personal data in order to reduce the likelihood of incidents occurring;
- implements internal control procedures that help minimise the likelihood and consequences of security incidents.
PURPOSES AND LEGAL BASIS FOR THE PROCESSING OF PERSONAL DATA
Clinic processes personal data for the following purposes:
and administration of health care services:
- identification of the patient;
- processing the patient’s appointment with the Clinic’s specialists;
- drawing up of the patient’s medical documentation in accordance with the requirements set out in laws and regulations;
- reminding the patients of the planned appointments with the Clinic’s specialists;
- carrying out medical examinations;
- providing doctors’ advice and carrying out medical procedures;
- assessing the state of health of patients or other natural persons;
- administrating payments;
- debt collection from debtors;
- examining patients’ objections and ensuring quality control;
- promoting patients’ loyalty and measuring satisfaction;
- preparing and signing contracts with patients;
- website maintenance and performance improvement;
- conducting scientific activities related to clinical research;
- providing information to public administration institutions and bodies performing operational activities in the cases and to the extent provided for in external regulations.
- ensuring the safety and property protection of patients and the Clinic’s staff;
- entering information into the National Unified Medical Information System (E-health).
- Provision and administration of health care services:
Clinic processes patients’ personal data on the following legal basis:
- for the purposes of medical diagnosis and treatment (Article 9(2)(h) of the Regulation);
- with the consent of the data subject (patient) (Article 9(2)(a) of the Regulation; Section 10(2) of the Law on the Rights of Patients);
- for the purposes of complying with laws and regulations – in order to carry out the obligations set out in external laws and regulations binding on the Clinic or exercise the rights of the data subject set out in external laws and regulations (Article 9(2)(b) of the Regulation; Section 10 of the Law on the Rights of Patients);
- in cases where processing is necessary for the exercise or defence of the Clinic’s legal interests in the court (Article 9(2)(f) of the Regulation);
- in cases where processing is necessary for the exercise of the Clinic’s legal interests (to organise an efficient process for the provision of health care services, to ensure an efficient process for requesting and cancelling patients’ appointments and to receive payments for the provided health care services);
- in cases where processing is necessary for the performance of a contract to which the data subject (patient) is party or in order to take steps at the request of the data subject prior to entering into a contract (Article 6(1)(b) of the Regulation);
- in cases where processing is necessary in order to protect the vital interests of the data subject (patient) or of another natural person (Article 6(1)(d) of the Regulation).
AMOUNT OF INFORMATION ACCUMULATED
- In its
core activities, the Clinic primarily obtains basic information from the
Data Subject that is needed to unambiguously identify the individual concerned
for the provision of medical services and communication:
- Given name
- ID number (identification number)
- Phone number and/or e-mail address
- As part of the provision of the Services, the Clinic may obtain additional information from the Data Subject and other third parties, which includes, but is not limited to, referral information, information about previous medical treatment cases and information obtained in the context of a specific treatment episode.
- The specific amount of information depends on the nature of the service to be provided and the applicable laws and regulations governing the provision of the service.
- The Clinic is aware that in the course of providing its services, it processes health data which is considered to be special categories of personal data in the context of the Regulation.
PROCESSING AND PROTECTION OF PERSONAL DATA
- The Clinic processes the Patient’s data by means of advanced technologies, taking into account the current risks to privacy, as well as organisational, financial and technical resources available to it the Clinic.
- The Clinic is constantly developing and supplementing the technical solutions at its disposal, taking into account the current industry trends and opportunities, based on the identified risks.
CONDITIONS OF USE AND RELEASE OF DATA
data available to the Clinic and obtained during the provision of services
- to ensure the operation of the Clinic and to the extent necessary for the provision of the highest quality services possible;
- to build cooperation with other third parties and to implement the patient’s treatment process.
- The Clinic, in cooperation with third parties, carries out its activities only in accordance with the laws and regulations governing the Clinic’s capabilities for the exchange of personal data in relation to the collection and transfer of necessary data.
- In its daily work, the Clinic takes measures to minimise the amount of personal data processing for its staff by ensuring that the staff have access only to the data of patients they need in order to perform their job duties.
- The Clinic ensures that personal data available to it are transferred only to the Data Subject himself or herself. The data are transferred to third parties, including persons related to the Data Subject, only in cases where the Data Subject’s written consent has been received or the case where such transfer of data is permitted is prescribed in laws and regulations.
- The Clinic does not transfer data if it cannot verify the Data Subject’s identity or suspects that the Data Subject’s presented identity does not match his or her true identity.
- In cases where the transfer of data is implemented via the means of e-mail communication, the Clinic ensures that such an operation is carried out only after receipt of the consent of the Data Subject.
- When transferring data via the means of e-mail communication or other online data exchange solutions, including self-service information system platforms, the Clinic implements measures to protect the relevant data by applying data access protection or encryption methods.
- The Clinic transfers personal data to third parties, ensuring that such third parties maintain the confidentiality of personal data and provide appropriate protection.
- The Clinic has the right to transfer personal data to the Clinic’s service providers that assist the Clinic in the performance of its functions. In this case, the principle of minimising the data to be transferred is respected.
- In the case referred to in Paragraph 22, the Clinic’s service providers receiving and processing personal data are regarded as personal data controllers within the meaning of the Regulation, and a written contract is concluded with them stating that the Clinic requests the data recipients to commit to use the information received only for the purposes for which they have been transferred and in accordance with the applicable laws and regulations in the field of data processing and data protection.
- The Clinic transfers data to third countries (countries outside the European Union and the European Economic Area) only in cases where the Data Subject’s written consent has been received.
DURATION OF STORAGE OF PERSONAL DATA
Clinic stores and processes the Clients’ personal data as long as at least
one of the following criteria exists:
- as long as the obligations arising from the contract signed between the Clinic and the Client are being fulfilled or the Client is being provided with health care services;
- as long as the Clinic has a statutory obligation to store the relevant data;
- as long as the Client’s request/application is being fully examined and/or fulfilled;
- as long as the Client’s consent to the relevant processing of personal data is valid, unless there is another legitimate basis for the data processing;
- personal data (video recordings) obtained through video surveillance are stored for a maximum of 30 days from the date of the recording.
- Upon the occurrence of conditions which provide that further storage of the Client’s data is not necessary, the Client’s personal data shall be deleted.
ACCESS TO PERSONAL DATA AND OTHER CLIENTS’ RIGHTS
- The Clinic provides the patient with the right to receive statutory information regarding the processing of his/her data.
- In accordance with laws and regulations, the Client also has the right to request the Clinic to provide him/her with access to his/her personal data, as well as to request their completion, rectification or erasure from the Clinic, or restriction of processing concerning the Client or the right to object to processing, as well as the right to data portability. These rights shall be exercised insofar as the data processing does not result from the obligations imposed on the Clinic by the applicable laws and regulations.
Client may submit a request for the exercise of his/her rights:
- in person at the Clinic in writing, presenting an identification document;
- by e-mail, signing the letter with a secure electronic signature and sending it to the following e-mail address: email@example.com;
- by sending a letter to the Clinic by post.
- Upon receipt of the Client’s request for the exercise of his/her rights, the Clinic verifies the Client’s identity, assesses the request and fulfils it in accordance with laws and regulations.
- The Clinic sends a reply to the Client as soon as possible, taking into account the method of receipt of the response indicated by the Client.
- If the reply is sent by post, it is addressed to the Data Subject (the person whose personal data is requested) by registered letter. If the reply is provided electronically, it is signed with a secure electronic signature (if the application has been submitted with a secure electronic signature).
- The Clinic ensures fulfilment of data processing and protection requirements in accordance with laws and regulations and in case of the Client’s objections takes action to resolve the objection.
- The Client has the right to receive one copy free of charge containing his/her personal data processed by the Clinic.
- The receipt and/or use of the information referred to in Paragraph 34 of this document may be limited in order to prevent adverse effects on the rights and freedoms of other persons (including the Clinic’s staff).
- The Clinic undertakes to ensure the accuracy of the personal data and relies on its Clients, suppliers and other third parties providing the personal data to ensure that the transferred personal data are complete and correct.
CLIENTS’ CONSENT TO DATA PROCESSING AND RIGHT TO WITHDRAW IT
- The Client may consent to the processing of personal data, the legal basis of which is the consent, in person at the Clinic, by sending it in paper format by post or by sending it by e-mail signed with a secure electronic signature.
- The Client has the right at any time to withdraw the consent given to the data processing in the same way as it was given, in which case further processing of the data based on the previously given consent for the specific purpose will not be carried out anymore.
- Withdrawal of the consent will not affect the data processing carried out at a time when the Client’s consent was in force.
- Processing of data carried out on the basis of other legal grounds (for example, in accordance with external laws and regulations or a contract between the Clinic and the Client) may not be terminated by withdrawing the consent.
VISITING OF WEBSITES AND PROCESSING OF COOKIES
- The websites of the Clinic may include links to third-party internet websites, which have their own usage and personal data protection rules, and which are not the responsibility of the Clinic.