Privacy Policy
Data subjects: Patients, employees, professionals and company representatives
Processing Activities
What processing do we carry out with your personal data?
In compliance with Regulation (EU) 2016/679 and the Spanish Organic Law on the Protection of Personal Data, we inform you that your personal data may be subject to some of the following processing activities:
- TS01 – Appointment management and scheduling (Legal basis: Regulation (EU) 2016/679)
- TS16 – Access to and management of clinical reports and/or medical records (Legal basis: Regulation (EU) 2016/679)
- TS17 – Management of ward and nursing activities (Legal basis: Regulation (EU) 2016/679)
- TS13 – Performance and management of diagnostic tests (Legal basis: Regulation (EU) 2016/679)
- TS10 – Preparation of compounded formulas and patient orders (Legal basis: Regulation (EU) 2016/679)
- TS19 – Management of courses, collaborations and events (Legal basis: Regulation (EU) 2016/679)
- TS02 – Management of new patient registration (Legal basis: Regulation (EU) 2016/679)
- TS05 – Complaints management (Legal basis: Regulation (EU) 2016/679, Decree No. 3/2014, of 31 January)
- TS18 – Management of patient discharge (Legal basis: Regulation (EU) 2016/679)
- TS14 – Performance of surgical procedures (Legal basis: Regulation (EU) 2016/679)
- TS08 – Issuing of diagnoses (Legal basis: Regulation (EU) 2016/679)
- TR04 – Advertising campaigns (Legal basis: Law 34/1988, of 11 November, on General Advertising)
- TR08 – Gathering data subjects’ opinions (Legal basis: Regulation (EU) 2016/679 on data protection and the Spanish Data Protection Act)
- TS04 – Hospital admission requests, room allocation and document management (Legal basis: Regulation (EU) 2016/679)
- TS15 – Provision and monitoring of physiotherapy treatments (Legal basis: Regulation (EU) 2016/679)
- TS20 – Monitoring of vital signs (Legal basis: Regulation (EU) 2016/679)
- TR03 – Recruitment of our own staff (Legal basis: Royal Legislative Decree 3/2015, of 23 October, approving the consolidated text of the Employment Act)
- TS11 – Preparation of unit-dose medication trolleys (Legal basis: Regulation (EU) 2016/679)
- TS03 – Verification of regular patients’ details (Legal basis: Regulation (EU) 2016/679)
- TS07 – Management of website and social media (Legal basis: Regulation (EU) 2016/679)
- TS12 – Sale of pharmaceutical products to private customers (Legal basis: Regulation (EU) 2016/679)
- TG01 – Our own accounting and bookkeeping management, as data controller (Legal basis: Royal Decree 1514/2007, of 16 November, regulating the General Accounting Plan)
- TG25 – Collection of data for our own tax management (Legal basis: Law 58/2003, of 17 December, General Tax Law)
- TG12 – Our own employment management: data collection (Legal basis: Royal Legislative Decree 1/1994, of 20 June, approving the consolidated text of the General Social Security Act)
- TR09 – Assurance of technical and organisational measures in the software used (Legal basis: Regulation (EU) 2016/679 on data protection and the Spanish Data Protection Act)
- TS22 – Filing, retention and safekeeping of clinical documentation (Legal basis: Decree 38/2012, of 13 March, on medical records)
- TE06 – Protection of Personal Data (Legal basis: Regulation (EU) 2016/679 and Organic Law 3/2018)
- TE02 – Occupational risk prevention (Legal basis: Law 31/1995, of 8 November, on the Prevention of Occupational Risks)
- TE07 – Document destruction (Legal basis: Regulation (EU) 2016/679)
- TR10 – Data Protection Officer (Legal basis: Regulation (EU) 2016/679 on data protection and the Spanish Data Protection Act)
- TS09 – Coding and dispatch of patient files (Legal basis: Regulation (EU) 2016/679, Decree 38/2012 of 13 March on medical records)
- TS21 – Management of discharge due to death (Legal basis: Decree 38/2012, of 13 March, on medical records)
- TVE01 – Provision of healthcare services to insurance mutuals and official bodies, acting as data processor (Legal basis: Commercial Code)
- TR05 – Emails (Legal basis: Commercial Code and other applicable legislation)
- TE03 – Crime prevention system (Criminal Compliance) (Legal basis: Article 31 bis of the Criminal Code)
- TR01 – Information requests received (Legal basis: Commercial Code and other commercial provisions)
- TR07 – Management of incidents and/or security breaches (Legal basis: Regulation (EU) 2016/679 on data protection and the Spanish Data Protection Act)
- TE04 – Management of the company’s own legal matters (Legal basis: Applicable commercial and employment legislation)
- TE01 – Maintenance of IT systems (Legal basis: Commercial Code)
- TS06 – Processing for the maintenance of ISO standards and reference frameworks (Legal basis: Applicable ISO standards and reference frameworks)
Data Controller
Who are we?
We are the controller responsible for processing your data. We therefore expressly, precisely and unequivocally inform both data subjects and the competent authorities of the following details regarding the data controller:
- SARRIA GARCÍA, JOSÉ RAMÓN
- 16088651J
- PLAZA GALA PLACIDIA Nº 23
- BARCELONA
- 08006
- BARCELONA
- dr.jsarria@gmail.com
Purposes
What do we use your personal data for?
Within this organisation, we may process your personal data exclusively for the following purposes:
- Checking that all necessary technical measures are being carried out for the correct management of personal data within the software used.
- Managing information requests received from data subjects regarding our products or services.
- Sending commercial and/or advertising information by email.
- Exclusive management of internal incidents detected in relation to compliance with GDPR requirements.
- Running advertising campaigns to promote our services and/or products.
- Gathering data subjects’ opinions.
- Recruiting staff to fill necessary job vacancies.
- Complying with all requirements set out in the Occupational Risk Prevention Act.
- Managing any legal matters affecting the company.
- Managing, maintaining and repairing IT storage systems.
- Actions to carry out our own employment management.
- Actions to carry out our own tax and accounting management.
- Appointment and activity of the Data Protection Officer.
- Provision of services to companies involving the processing of personal data / Administrative management of clients and/or indirect employees.
- Complying with the principle of limiting the retention period of personal data.
- Compliance with the requirements set out in Regulation (EU) 2016/679 and Organic Law 3/2018.
- Scheduling patient appointments.
- Management of new patient registration.
- Preparing compounded formulas tailored to the patient.
- Supplying medication to admitted patients.
- Sale of medication to patients.
- Diagnosing conditions or illnesses.
- Alleviating or eliminating the patient’s condition or illness.
- Patient rehabilitation.
- Understanding the patient’s condition, treatment and needs for appropriate care.
- Keeping all patient data up to date.
- Coordinating the various ward activities.
- Registering patient data upon hospital admission.
- Managing and recording patient discharge and any relevant information from a care perspective.
- Managing complaints filed by patients.
- Properly maintaining the ISO standards and reference frameworks implemented.
- Training, updating and specialisation of healthcare staff.
- Use of images for promotional purposes.
- Management of website and social media.
- Treating or assessing the patient’s condition or illness.
- Monitoring and checking the patient’s condition.
- Prescribing the appropriate treatment to eliminate the patient’s condition or illness.
- Compliance with obligations regarding the filing and safekeeping of clinical documentation.
- Registration and certification of deaths.
- Ensuring official bodies and insurance mutuals hold patient files.
- Exempting the legal entity from criminal liability.
Your personal data may be used for automated decision-making. Please note that the logic applied in automated individual decision-making and/or profiling is based on computer software that performs the calculations needed to precisely determine the value corresponding to each of the parameters analysed. You may contact us at the email address given in the first section for further information on this matter.
A commercial or user profile may be created based on the information provided or obtained. We expressly inform you that, under no circumstances, will profiles be created using a minor’s data.
The personal data you provide will be retained for as long as the contractual relationship lasts or, where applicable, for as long as you do not exercise your right to object or withdraw your consent. To do so, you may go to the relevant section on our website or send an email to the address given in the section relating to the data controller.
Lawfulness
Why do we use them? We are entitled to process your personal data for the following reasons:
Your unambiguous, informed and express consent, in those cases where this is legally required, without withdrawal of consent, in any case, affecting the performance of other processing activities based on a different legal basis, and without such withdrawal affecting the lawfulness of processing carried out prior to its withdrawal.
A legal obligation of the data controller.
The performance of the contract for the provision of services and/or purchase of the corresponding products, entered into by you.
The legal basis for processing your data is a legitimate interest of the data controller. This interest is based on a prior proportionality or balancing test between the controller’s legitimate interest and the interests, rights and freedoms of data subjects. This balancing exercise has involved assessing the interest, assessing the impact of the processing on data subjects, weighing up the two preceding concepts, and implementing additional safeguards. As the final balance favours the controller, the processing may be carried out in accordance with the applicable data protection regulations. For any questions or clarification, you may contact us via the email address provided in the section relating to the data controller.
Recipients
Who may we share your personal data with?
Your personal data will be disclosed to the following companies and bodies:
- Spanish Tax Agency
- Spanish Public Employment Service
- General Treasury of the Social Security
- Spanish Data Protection Agency
- Insurance mutuals
- Official public bodies
- Funeral home
- Courts and Tribunals
Your personal data will not be transferred to any third country or international organisation.
Sources
What data do we process and how have we obtained it?
Your personal data will be added to the following files, owned by the organisation:
- FE01 IT maintenance
- FE02 Occupational risk prevention
- FE03 Crime prevention system (Criminal Compliance)
- FE04 The company’s own legal matters
- FE07 Document destruction
- FE08 Protection of Personal Data
- FG01 Our own accounting management
- FG02 Our own employment management
- FG15 Our own tax management. Data collection
- FR01 Information requests received
- FR03 Recruitment of our own staff
- FR04 Advertising campaigns
- FR05 Emails
- FR07 Management of incidents and/or security breaches
- FR08 Gathering data subjects’ opinions
- FR09 Software and hardware assurance
- FR10 Data Protection Officer
- FS01 Patient admission file
- FS02 Complaints management file
- FS03 ISO standards and reference frameworks maintenance file
- FS04 Communications and CSR file
- FS05 Outpatient consultations and emergencies file
- FS06 Pharmacy service management
- FS07 Diagnostic tests management
- FS08 Surgical specialities management
- FS09 Physiotherapy file
- FS10 Internal medicine and ward management file
- FS11 Training file
- FS12 Coding and clinical documentation file
- FS13 Deaths file
- FS14 Paper-based clinical documents file
- FS15 Vital signs monitoring file
- FVE01 Provision of services to companies involving the processing of personal data of clients and/or indirect employees
The types of data that come from sources other than the data subject themselves are:
- Diagnosis data
- Medical test data
- Hospital data
- Death data
- Staff identification data
- Vital signs data
The personal data we process within our organisation comes from the following sources:
- The data subject themselves
- The referring company
- Medical diagnosis
- Hospital
Your Rights
What rights can you exercise?
We guarantee your ability to exercise the rights available to you in relation to the processing of your personal data.
In particular, we inform you that you have the right to:
- Obtain confirmation as to whether your data is being processed.
- Exercise the right of access to the personal data we hold, obtaining information about the purposes of the processing, the category of data processed, the possible recipients, the retention period, the origin of the data and, where applicable, the existence of profiling or automated decision-making.
- Exercise the right to rectification. To this end, we remind you that the personal data we hold must always accurately reflect reality, so please do not hesitate to exercise this right should any data be modified, changed or cancelled. You guarantee that the personal data you have provided to us by any means is true and accurate, and undertake to notify us of any change or modification to it, being solely responsible for any loss or damage caused to the controller or any third party as a result of the communication of erroneous, inaccurate or incomplete information.
- For reasons relating to your particular situation, you may object to the processing of your data, in which case our organisation will stop processing the data, unless there are legitimate grounds preventing this.
- Request the erasure of your personal data when, among other reasons, it is no longer necessary for the purposes described above, or we no longer have a legal basis for processing it.
- Request the portability of your data, where the processing is carried out by automated means and provided you are linked to our organisation through a signed contract or have given consent for the processing carried out. In these cases, you will have the right to receive your personal data in a structured, commonly used, machine-readable format, or to have it transmitted directly to another controller, where technically possible.
- In certain circumstances, you may request the restriction of the processing of your data, in which case we will only retain it for the exercise or defence of legal claims.
- Object to automated decision-making, including profiling.
These rights may be exercised free of charge, except in the cases legally provided for, by means of a written, signed request from you or, where applicable, your representative, addressed to the data controller, at the addresses provided for this purpose in the first section, or in person at any of our premises.
You also have the right to lodge a complaint, either with the Spanish Data Protection Agency (at https://www.aepd.es/) or with the relevant supervisory authority.
Likewise, you may go to the Courts and Tribunals to claim compensation.
Finally, you have the right to withdraw your consent as easily as you gave it. To do so, you may visit our website, where you will find the information needed to quickly and easily cancel the authorisation granted to us for these communications. You may also send an email to the address given in the section relating to the data controller.
We also inform you that, for each instance of processing your personal data, the potential threats and impacts that may arise as a result are identified, mitigating or eliminating potential harm where possible, through the application of the corresponding security measures, which are periodically reviewed to determine their effectiveness.
Our control system also enables us to comply with the principles of data processing, allowing us to demonstrate to the data subject the principle of purpose limitation, the principle of storage limitation, the principle of data minimisation, as well as the principle of integrity and confidentiality.
Finally, we also inform you that you will periodically receive surveys allowing us to learn your opinion regarding any suggestions relating to the processing of your personal data, as well as enabling us to comply with the principle of transparency and accuracy of the data processed.
For any questions or clarification, you may contact us via the email address provided in the first section.
Yours faithfully,
The Data Controller.