Information clause on the processing of personal data

In accord with article 13 paragraph 1 of the Regulation of the European Parliament and of the (EU) Council 2016/679 of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and the repeal of Directive 95/46/WE (hereinafter referred to as: GDPR), we wish to inform that:

The administrator of your personal data is Meissner & Partners Maja Meissner-Filipek with its registered office in Milanówek at Krasińskiego 51 Street, NIP 739-222-35-07, REGON 141079630 (hereinafter reffered to as: HIFU CLINIC).
You can contact us in the following way:
- by mail to: Meissner & Partners Maja Meissner-Filipek, Krasińskiego 51 Street, 05-822 Milanówek
- via the contact form at https://hifu.pl
- by email: kontakt@hifu.pl
- by phone +48 512 077 461
In matters related to the processing and protection of personal data, you can contact our Data Protection Officer, email address: rodo@hifu.pl
We will process your personal data pursuant to art. 6 par. 1 points a) - c) GDPR in order to perform legal obligations, financial settlements, including issuing accounting documents, detecting and preventing fraud, pursuing claims, creating statements, analyzes and statistics, verification of payment credibility, handling complaints and applications.
Your personal data regarding your health condition will be processed on the basis of art. 9 paragraph 2 point h) GDPR and pursuant to the provisions of Polish laws in the field of medical law, which are related to health goals to the extent necessary for the purposes of prevention, medical diagnosis, health care, treatment.
HIFU CLINIC is entitled to transfer your personal data to third parties (hereinafter referred to as: HIFU CLINIC subcontractors) for the purpose and to the extent necessary for the correct and proper implementation of health services. Therefore, your personal data may be transferred to HIFU CLINIC subcontractors based on the agreement to entrust personal data processing between HIFU CLINIC and HIFU CLINIC’s subcontractors.
Your personal data regarding the state of your health recorded in the medical records are made available under the rules provided for in the provisions of the Act of 6 November 2008 on patients' rights and the Patient's Rights Ombudsman. In addition, HIFU CLINIC is obliged to provide your personal data on the basis of applicable law, including at the request of authorized courts, authorities and institutions.
Your personal data is not transferred outside the EEA (European Economic Area) without your express written consent, filled in each time.
Your personal data will be kept for the duration of your contract with HIFU CLINIC for health services performed by HIFU CLINIC, as a result of which your personal data is processed, and after that period until the expiration of your claims related to HIFU CLINIC and the contract for health services provided by HIFU CLINIC. However, your personal data recorded in medical or accounting documentation will be kept for the period specified in applicable law, including the provisions on health services and tax regulations.
Subject to the limitations resulting from GDPR and other legal provisions, you have the right to access your personal data and the right to rectify, delete, limit processing, the right to transfer personal data, the right to raise objections, and the right to withdraw consent at any time if processing it takes place on the basis of your consent.
Medical records (or a copy thereof) may be issued to a patient or his legal representative with a receipt, if the patient so wishes in writing.
Based on the provisions of the GDPR you have the right to lodge a complaint with a supervisory, when you believe that the processing of your personal data violates the provisions of the GDPR.
Failure to provide personal data necessary to perform health services performed by HIFU CLINIC may result in refusal to provide health services.
In the scope of health services and other services, you will not be subject to a decision based solely on the automated processing of personal data, including profiling.