Your privacy is important to us.
This data protection commitment explains what personal information ATHENA HEALTH SRL collects from you through your interactions with our website and how we use this data.
In order to be able to respond to your needs through specific and innovative services, it is necessary for us to collect, store and use certain personal information about our patients and clients. It is our intention to treat all personal data provided with the utmost care and respect, in accordance with the principles set out below.
What is personal data?
"Personal data" means unique information relating to an identified or identifiable natural person ("data subject"), such as: name, address, personal identification number, IP address or telephone number.
Visitors to the website are data subjects within the meaning of the law — that is, persons who can be identified, directly or indirectly, in particular by an identifier (name, identification number, location data, online identifier) or by one or more elements specific to their physical, physiological, genetic, mental, economic, cultural or social identity.
From time to time, we may request personal information from you through the Site to send you requested materials, answer your questions, or provide you with a service. Whenever we request personal information, we clearly explain the purpose for which it is required, where it is stored, and who has access to it. We also inform you that you have the right to access and, upon request, request the deletion of your data at any time.
Who owns this site?
The owner of the site is ATHENA HEALTH SRL, Unique Registration Code RO50043385.
Contact details of the Data Protection Officer (DPO): dpo@metropolitan-hospital.ro.
More information is available on the Contact page.
Legal basis for processing personal data
Data provided voluntarily (via form or e-mail): the legal basis is art. 6 para. (1) letter b of Regulation (EU) 679/2016 — steps taken at the request of the data subject prior to the conclusion of a contract.
- Automatically collected data (cookies, analytics tools): the legal basis is your explicit consent.
- Data processed for legal obligations (e.g. billing, medical archiving): the legal basis is art. 6 para. (1) letter c of the Regulation.
The legal bases for transmitting information to third parties include:
- Patient Law;
- Law No. 95/2006 on healthcare reform;
- Transplantation legislation and applicable European directives.
Purposes of data processing
We process your data for:
- to communicate with you and respond to requests;
- to provide medical and administrative services;
- to ensure the operation and security of the site;
- to improve the services offered;
- to send marketing messages (only with prior consent).
You can withdraw your consent for promotional communications at any time, via the unsubscribe link included in the messages sent or by a direct request to the DPO.
Data retention period
Personal data is stored only for the period necessary to fulfill the aforementioned purposes, but no more than 5 years from the last interaction.
If an invoice has been issued, the data will be kept for 10 years, according to tax legislation.
For employees, the retention period is 75 years (Labor Code).
For patients, medical records are kept for 30 years, according to healthcare legislation.
Who has access to your data?
We will not disclose your data to third parties for marketing purposes without explicit consent.
We may transmit data to:
- Service providers (invoicing, sending emails, etc.), acting as processors;
- Competent authorities, based on legal requests:
- Territorial Labor Inspectorate
- Employment Agency
- Judicial authorities
- Specialist doctors
- National Transplant Agency
- Bucharest City Hall
- Ministry of Health
Any other disclosure is made only with your express consent.
Rights of the data subject
According to Regulation (EU) 679/2016 (GDPR), you have the following rights:
- The right to information and access to data;
- The right to rectification;
- The right to erasure ("the right to be forgotten");
- The right to restriction of processing;
- The right to data portability;
- Right to object;
- The right not to be subject to automated decision-making, including profiling;
- The right to file a complaint with the National Supervisory Authority for Personal Data Processing: www.dataprotection.ro.
Privacy Policy Updates
In order to remain in compliance with legislative changes and operational practices, ATHENA HEALTH SRL reserves the right to update this policy at any time.
Any change becomes mandatory from the moment of publication on the site.