PRIVACY AND DATA PROTECTION POLICY
In compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter, GDPR), Law 34/2002 of 11 July on Information Society Services and Electronic Commerce (hereinafter, LSSI-CE) and Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights, OXIAGING S.L. (hereinafter, The Owner) guarantees the protection and confidentiality of personal data of any kind provided to us by our clients, in accordance with the provisions of the General Data Protection Regulation.
The Data Protection Policy of OXIAGING S.L. (hereinafter, “The Owner”) is based on the principle of proactive responsibility, according to which the Data Controller is responsible for compliance with the regulatory and jurisprudential framework, being able to demonstrate this to the corresponding supervisory authorities.
The data provided will be processed in accordance with the GDPR; in this regard, the Data Controller has adopted the legally required levels of protection and has implemented all available technical measures to prevent loss, misuse, alteration, or unauthorized access by third parties, as detailed below. However, users should be aware that internet security measures are not infallible.
What personal data do we process and where does it come from?
In connection with your relationship with us, the following categories of personal data may be processed:
• Identifying data, contact details of patients or their representatives (including signature, image, health card, social security or mutual insurance number) and any other administrative information
• Health-related data integrated into the patient's medical record
• Personal characteristics, social or socio-health circumstances
• Transactional data (payments, income, transfers, debits)
The data may come from the patient themselves or, where applicable, from their legal or voluntary representative and/or healthcare personnel. In the case of contact forms from our website, only the data described in that form will be collected.
Data controller: Who are we?
Denomination: OXIAGING S.L
CIF: B10626257
Address:: Apartado de Correos 962 CP 02080
Phone: 661668582
Email info@oxiaging.es
Purpose of processing: What will we use your data for?
1. Provision of healthcare:
Your personal data is processed in order to provide you with the healthcare you require, as well as to properly manage the healthcare and administrative services of the clinic necessary for this, for example:
– Remind them of their appointments and check-ups;
– Issue proof of your attendance at the health center to family members or people linked to you who request it, within the framework allowed by the regulations;
– To handle any communication with the health center reported by the patient;
- To manage any incident or complaint filed by the user and/or patient; - To conduct surveys in order to understand your opinion on the care received, which will be used solely to improve and develop our healthcare and management services;
2. Provision of Patient Space Service:
If the patient registers as a user of the portal, the users' personal data may be processed in order to manage access to the tool, as well as its use.
3. Handling requests for information of any kind, including commercial, complaints, suggestions, claims, exercise of data protection rights, etc.:
In these cases, your data will be processed for the purpose of managing and processing the request.
4. Compliance with legal obligations:
It may be necessary to process personal data to comply with applicable legal requirements. Specifically, to comply with legislation regarding data protection, taxation, healthcare, etc.
5. Formalization and execution of the contract:
The patient's personal data is processed for the purpose of managing the contractual relationship with the patient.
6. Sending commercial communications always with your prior consent:
The data collected will be processed for the specified purposes and in no case in a manner incompatible with those purposes. Please note that processing for scientific research or statistical purposes is not considered incompatible with the initial purpose.
In any case, we process your data to always serve you with the same level of quality care, regardless of the channel you use to communicate with us (health center, center website, whether in person, by phone or electronically).
Legitimacy of processing: Why do we need your data?
Purpose Basis for Treatment
Provision of healthcare
Processing necessary for the performance of a contract to which the data subject is a party; consent of the data subject; legitimate interests of the controller; protection of the data subject's interests.
Handling requests
Consent of the interested party and/or legitimate interests of the Controller
Compliance with legal obligations Processing necessary for compliance with a legal obligation applicable to the Controller
Formalization and execution of the contract. Execution of a contract in which the interested party is a party.
Sending commercial communications. Consent of the interested party.
Recipients: Who do we share your data with?
To ensure proper service provision, it is necessary for certain service providers and/or entities to process data on behalf of the controller and as processors of your personal data.
Your personal data will not be disclosed to third parties except where legally required, in cases of vital interest, or with the prior consent of the interested party, only in the cases and to the recipients detailed below:
1. Since the patient may have an insurance contract under which a third party (e.g., insurance companies, mutual insurance companies, public administrations, or even those of a third party in the case of liability insurance) is responsible for paying for the healthcare services provided by the healthcare center, provided the patient informs us, we may share their data with these entities in order to manage, validate, verify, and monitor payment for the healthcare services provided. You expressly and unequivocally authorize this transfer of data.
2. If the patient has insurance with an entity located outside the European Economic Area (EEA) whose legislation does not offer a level of data protection equivalent to that of the European Union, an international data transfer may be necessary, subject to the patient's explicit consent after having been informed of the risks. These transfers are only made to assist the patient and facilitate payment for the healthcare services provided; in short, these transfers only occur to manage and verify payment for services with the insurer as efficiently as possible when the patient has an insurance policy with an entity located outside the EEA.
3. If you object to the communication of your data, these entities may refuse to pay for the healthcare services received, and you will be responsible for the payment, as these entities do not have the possibility of verifying, checking, validating or controlling the correct billing by the healthcare center for each of your healthcare processes.
We also inform you that your personal data may be shared with suppliers of medical equipment, prostheses, and implants due to legal obligations, and with ambulance services based on the patient's vital interests. All information provided to us will be treated confidentially and in strict compliance with the necessary security measures to prevent access by unauthorized third parties.
Retention: How long will we keep your data?
In general, your data will only be kept for as long as strictly necessary for the purpose for which it was collected.
The personal data provided, as well as those derived from the healthcare provided, will be kept for the time appropriate to each case (according to medical and legal criteria), and at least ten years from the date of discharge of each healthcare process, unless the regional and/or specific regulations establish a minimum retention period different from the one indicated, in which case the provisions of the applicable regulations will be observed.
Once the aforementioned minimum period has elapsed, and the care and contractual relationship has ended, the responsible party will keep your data duly blocked, for the term of the periods corresponding to the legal prescription.
Personal data provided for the purpose of managing any request for information, complaint, suggestion, claim, exercise of data protection rights, etc., will be kept for the time necessary to process the request, and in any case for the legally established time, as well as for the period necessary for the formulation, exercise or defense of claims.
Data processed for compliance with legal obligations will be kept for the
time established in the applicable legislation.
The data collected for the formalization and execution of the contract will be kept for the duration of the contractual relationship, as well as for the period necessary for the formulation, exercise or defense of claims.
Security: How will we protect your data?
We make every reasonable effort to maintain the confidentiality of personal information processed on our systems. We maintain strict security measures to protect the personal data we process against accidental loss and unauthorized access, processing, or disclosure, taking into account the state of the art, the nature of the data, and the risks to which it is exposed. However, we cannot be held responsible for your use of the data (including username and password) you use on our website. Our staff adhere to strict privacy policies, and if we engage third parties to provide support services, we require them to comply with the same policies and allow us to audit them to verify their compliance.
Your rights: What rights can you exercise as a data subject?
We inform you that you may exercise the following rights:
a) Right of access to your personal data, to know which data are being processed and the processing operations carried out with them;
b) c) Right to rectification of any inaccurate personal data;
Right to erasure of your personal data, where this is possible (for example, due to a legal requirement);
d) Right to limit the processing of your personal data when the accuracy, legality or necessity of the processing of the data is in doubt, in which case we may retain them for the exercise or defense of claims.
Derecho de oposición al tratamiento de sus datos personales, cuando la base legal que nos habilite para su tratamiento de las indicadas sea nuestro interés legítimo. OXIAGING S.L. dejará de tratar tus datos salvo que tenga un interés legítimo o sea necesario para la defensa de reclamaciones, cuando proceda este derecho.
f) Derecho a la portabilidad de sus datos, cuando la base legal que nos habilite para su tratamiento sea la existencia de una relación contractual o su consentimiento.
g) Right to revoke the consent given to OXIAGING S.L.
Para ejercitar sus derechos, puede hacerlo de manera gratuita y en cualquier momento, contactando con nosotros en la dirección Apartado de Correos 962 CP 02080, o escribiendo un correo a info@oxiaging.es.
Protection of rights: Where can you file a complaint?
If you believe that your rights have been disregarded by our organization, you may file a complaint with the Spanish Data Protection Agency through one of the following means:
.
– Electronic headquarters: https://www.aepd.es
.
– Postal mail: Agencia Española de Protección de Datos, C/ Jorge Juan, 6, 28001, Madrid
.
- Phone: 901.100.099 y 912.663.517
Filing a complaint with the Spanish Data Protection Agency is free of charge and does not require the assistance of a lawyer or solicitor.
e) Updates: What changes may occur in this Privacy Policy?
The Owner reserves the right to modify this policy to adapt it to new legislation or case law that may affect compliance with it.
In order to guarantee compliance with regulations on the protection of personal data, OXIAGING S.L. has received consulting and advisory services from ClickDatos.
