Home / Privacy Policy

Privacy Policy

I INTRODUCTION

1. The personal data controller, in particular collected via the wilmed.pl website (the Service), is BIOCONCEPT Sp. z o.o., operating the Wilmed Medical Center
ul. Czerska 18, 00-732 Warsaw; phone: 692-407-540; email address: przychodnia@wilmed.pl (the Controller).
2. The Controller is responsible for the security of the provided personal data and for processing it in accordance with legal regulations.
3. The Controller has appointed a Data Protection Officer (DPO), who can be contacted
regarding matters related to the processing of personal data and the exercise of rights granted to users under data protection regulations: inspektor@mbrk.pl
4. Personal data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (GDPR), as well as other currently applicable data protection laws.
5. During visits to the Service, the following data is collected:
– personal data provided by the user,
– data obtained and recorded automatically.
6. The purpose and scope of data used by the Controller are detailed in the further part of the privacy policy.

II COLLECTED DATA – BASIC INFORMATION

1. The following information applies to all methods of using personal data provided by users indicated in chapters III and IV by the Controller.
2. Data will not be used for decisions based solely on automated processing of personal data, including profiling within the meaning of Article 22 GDPR.
3. Subject to all data security guarantees, personal data processed via the Service may be transferred – in addition to persons authorized by the Controller – to other entities, including:
– entities authorized to receive them under legal provisions,
– entities processing data on behalf of the Controller (e.g., technical service providers and advisory service providers),
– other data controllers to the extent necessary for the provision of services and legal requirements (e.g., notary or legal offices).
4. The Controller informs that in connection with the processing of personal data obtained via the Service, every data subject has the right to submit a request regarding:
– access to data (information about personal data processing or a copy of the data),
– rectification of data (if incorrect),
– deletion of personal data (right to be forgotten),
– restriction of personal data processing,
– data portability to another controller,
– withdrawal of consent where the Controller processes the client’s personal data based on consent, at any time and in any manner, without affecting the lawfulness of processing based on consent before its withdrawal,
– objection to data processing where the basis is the Controller’s legitimate interest,
5. Every data subject has the right to lodge a complaint with the supervisory authority (President of the Personal Data Protection Office, https://uodo.gov.pl/pl/83/155) if they believe that personal data processing is not compliant with regulations.
6. Data has been obtained by the Controller directly from the user. The Controller may also process personal data of other persons provided by the user during the use of services described in the privacy policy.

III PERSONAL DATA PROVIDED BY THE USER

III A EMAIL OR TELEPHONE CONTACT

1. The Controller processes personal data, in particular contact phone number or email address and other information provided by the user, to the extent necessary to handle inquiries and fulfill requests, including communication and responding to questions asked via the contact phone number and email address provided on the Service (legal basis – Art. 6(1)(f) GDPR) – „legitimate interest”. If the user provides special categories of data (e.g., health information), they declare consent to their use for proper handling of the inquiry and request fulfillment, including communication and response (legal basis – Art. 9(2)(a) GDPR) – „consent”.
2. The Controller has the right to process personal data for the period necessary to achieve the above purposes. Depending on the legal basis, this will be:
– the time necessary to fulfill the inquiry, including responding to the question or handling matters related to the correspondence or conversation,
– the time until the user withdraws consent (including withdrawal of consent for use of special categories of data).
3. Withdrawal of consent may be made, in particular, by contacting the Controller or the DPO. Withdrawal of consent does not affect the lawfulness of data use during the period when consent was valid.
4. Providing data is voluntary but necessary to respond to the submitted question or properly handle the inquiry and fulfill the request. Failure to provide personal data may result in the inability to respond or fulfill the request.

III B CONTACT FORM

1. The Controller may collect personal data, in particular contact phone number or email address and other information provided by the user, via the contact form available on the Service.
2. The Controller processes personal data to the extent necessary to fulfill the inquiry, including responding to questions asked via the contact form provided on the Service (legal basis – Art. 6(1)(f) GDPR) – „legitimate interest”. If the user provides special categories of data (e.g., health information), they declare consent to their use for proper handling of the inquiry and request fulfillment, including communication and response (legal basis – Art. 9(2)(a) GDPR) – „consent”.
3. The Controller has the right to process personal data for the period necessary to achieve the above purposes. Depending on the legal basis, this will be:
– the time necessary to respond to the inquiry sent by the user via the contact form,
– the time until the user withdraws consent (including withdrawal of consent for use of special categories of data).
4. Withdrawal of consent may be made, in particular, by contacting the Controller or the DPO. Withdrawal of consent does not affect the lawfulness of data use during the period when consent was valid.
5. Providing data indicated in the contact form is voluntary but necessary to respond to the submitted question or properly handle the inquiry and fulfill the request. Failure to provide personal data results in the inability to send a response to the user.

III C FACEBOOK

1. The Controller processes personal data of users visiting the Controller’s accounts managed on social media.
2. BIOCONCEPT Sp. z o.o. is the personal data controller of users using products and services offered by Facebook who visit the Controller’s page available at https://www.facebook.com/wilmedprzychodnia (hereinafter the Fanpage). As Controller, it is responsible for the security of the provided personal data and for processing it in accordance with legal regulations.
3. The Controller processes personal data of users who, using Facebook products and services, visit the Fanpage. These data are processed:
4. in connection with managing the Fanpage, including promoting its own brand (legal basis – Art. 6(1)(f) GDPR) – „legitimate interest”;
5. to respond to questions asked via Messenger or other Facebook services (legal basis – Art. 6(1)(f) GDPR) – „legitimate interest”; if the user provides special categories of data (e.g., health information), they declare consent to their use for proper handling of the inquiry and request fulfillment, including communication and response (legal basis – Art. 9(2)(a) GDPR) – „consent”;
6. The Controller has the right to process:
7. publicly available personal data (such as username, profile picture, Facebook or Messenger activity status), comment content, and other information publicly shared by the user using Facebook products and services,
8. personal data provided by the user visiting the Fanpage, including information shared in the user’s profile and other content, comments, messages, and communications (e.g., photos, contact data, place of residence, information about interests or beliefs),
9. other personal data provided by users in messages via Messenger or other Facebook services (including contact data and health data) to respond to inquiries or fulfill contact requests.
10. The scope of personal data processing, detailed purposes, and user rights and obligations when using Facebook products and services are directly derived from Facebook’s terms of service (available at: https://www.facebook.com/legal/terms) and „Data Policy” (available at https://www.facebook.com/policy) or legal regulations and are specified by user actions on the Facebook social network.
11. The Controller has the right to process personal data for the period necessary to achieve the above purposes. Depending on the legal basis, this will be:
12. the time until objection is raised (or the Facebook user account is deleted),
13. the time until consent is withdrawn (or the Facebook user account is deleted). Withdrawal of consent does not affect the lawfulness of data processing during the period when consent was valid;
14. the period necessary to handle inquiries sent by the user via Messenger or other Facebook services.
15. The list of recipients of personal data processed by the Controller primarily depends on the range of products and services used by the Facebook user, but also on user consent or legal provisions. Subject to all data security guarantees, the Controller may transfer personal data of users visiting the Fanpage – in addition to persons authorized by the Controller – to other entities, including entities processing data on behalf of the Controller, e.g., technical service providers and advisory service providers (including legal offices) and contractors providing services to the Controller under contracts.
16. The Controller will not transfer personal data of users using Facebook products and services to countries outside the European Economic Area (countries other than EU countries and Iceland, Norway, and Liechtenstein).
17. The Controller may process personal data of users using Facebook products and services who visit the Fanpage for analysis of how users use the Controller’s page and related content (conducting statistics) – if user activity on the Fanpage and related content triggers an event for page statistics involving personal data processing (legal basis – Art. 6(1)(f) GDPR) – „legitimate interest”.
18. For personal data processed for statistics regarding user actions on the Fanpage (including following or unfollowing the page, recommending the page in a post or comment, liking the page or post, unliking), the Controller and Facebook Ireland Limited
(4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) are joint controllers of users’ personal data. Types of data, scope of processing, privacy protection rules, and user rights are detailed:
19. in this document,
20. in the „Data Policy” document published on Facebook at https://www.facebook.com/policy.
21. Facebook is responsible for notifying users of Facebook products and services about data processing for page statistics and enabling them to exercise their rights under GDPR (information about data used for page statistics is available on Facebook at: https://www.facebook.com/legal/terms/information_about_page_insights _data).
22. The Facebook Data Protection Officer can be contacted via a form available on Facebook at https://www.facebook.com/help/contact/540977946302970.

IV AUTOMATICALLY COLLECTED DATA

1. Using the Service involves sending requests to the server, which are automatically recorded in event logs.
2. Event logs record data concerning user sessions. In particular, these include: IP address, type and name of device, date and time of visit to our service, information about the web browser and operating system.
3. The data indicated in point 2 above are not associated with specific individuals.
4. Access to the contents of event logs is granted to persons authorized by the Controller to administer the Service.
5. The chronological record of event information serves solely as auxiliary material used for administrative purposes. Analysis of event logs enables, in particular, threat detection, ensuring appropriate Service security, and performing statistics to better understand how users use the Service.
6. The data indicated in point 2 above are used to diagnose problems related to the functioning of the Service and analyze potential security breaches, manage the Service, and perform statistics (legal basis – Art. 6(1)(f) GDPR) – „legitimate interest”.
7. The Service uses cookies for its operation. More information on this is provided in chapter V COOKIE POLICY

V COOKIE POLICY

1. BIOCONCEPT Sp. z o.o. (the Controller), pursuant to Articles 173-174 of the Telecommunications Law Act of 16 July 2004, informs that the wilmed.pl website (the Service) uses cookies.
2. Additionally, the Controller informs about the use of other internet technologies such as IndexedDB and Web Storage. These technologies operate on the same principle as cookies.
3. Only anonymous statistical data about users are collected via cookies and other technologies. Information obtained through these technologies is not assigned to any specific person and does not allow identification.
4. Placing and using cookies and other technologies is not harmful to the user’s device (e.g., computer, smartphone, tablet), nor does it cause any changes to the device’s configuration or installed software and applications.
5. The purpose of using the above-mentioned technologies by the Service is:
a) creating analyses, reports, and statistics regarding how users use the Service pages;
b) adapting the Service content to user preferences and optimizing the use of the Service;
c) presentation of advertisements.
6. While using the Service, small text files (cookies) are placed on the user’s device. Typically, these files contain the following information:
a) the name of the Service from which the cookie was sent;
b) a generated unique number;
c) the file storage time.

7. The Controller, besides cookies, also uses browser capabilities that can store information. The following data storage technologies can be distinguished:
a) IndexedDB – data stored as objects, accessible only to appropriate data sources – domains or subdomains from which they were saved;
b) Session Storage – a data store equivalent to cookies but with much larger data capacity. Data stored in Session Storage is deleted after closing the browser window;
c) Local Storage – a data store where information is saved persistently in the user’s web browser until deleted.
8. The Controller uses, in particular but not exclusively, services of the following external companies:
a) Google LLC (more information at: https://support.google.com/google-ads/answer/10000067?hl=en#zippy=%2Cconsent-mode-behaviors-in-your-conversion-tracking-tags)
9. These entities have their own privacy policies and practices regarding the use of internet technologies; therefore, to better understand these rules, please review the privacy and cookie policies of each entity.
10. Additionally, the Service contains embedded buttons, tools, or content directing to services of other companies, including links to external websites, videos (YouTube). Using these applications may cause information to be transmitted via internet technologies to the mentioned external entities.
11. The user can change settings or disable cookies and other technologies in their browser at any time, but this may cause improper functioning of the Service.
12. Changes made to cookie settings in the web browser also apply to the use of other internet technologies.
13. If the user does not change the default browser settings regarding cookies, data-collecting files will be placed on the end device and used according to the rules set by the browser provider.
14. Information on managing cookies in specific browsers – including instructions on blocking cookies – can be found on dedicated pages for each browser:
a) Chrome: https://support.google.com/chrome/answer/95647?hl=pl
b) Firefox: https://support.mozilla.org/pl/kb/ciasteczka
c) Internet Explorer: https://support.microsoft.com/pl-pl/help/17442/windows-internet-explorer-delete-manage-cookies
d) Microsoft Edge: https://support.microsoft.com/pl-pl/help/4468242/microsoft-edge-browsing-data-and-privacy-microsoft-privacy
e) Opera: https://help.opera.com/pl/latest/web-preferences/#cookies
f) Safari: https://support.apple.com/pl-pl/HT201265
15. Users who, after reviewing the information available on the Service, do not want cookies, IndexedDB, and Web Storage to remain stored in their browser should delete them from their browser after finishing their visit to the Service.

VI FINAL PROVISIONS

1. This privacy policy is informational and applies in particular to the wilmed.pl website.
2. The Service may contain links to other websites (including those cooperating with the Controller, partners, and other external entities). The Controller recommends that every user, after visiting other sites, familiarize themselves with the applicable privacy policies there.
3. The Controller reserves the right to introduce changes to the current privacy policy, in particular in the case of:
– technological development,
– changes in generally applicable laws, including data protection or information security,
– development of the Service.
4. The Controller will notify users of relevant changes to the privacy policy by posting a message on the Service page.