pro.therapy Mykhailo Harkavka, based in Warsaw, ul. Koncertowa 4 , 02-787, NIP: 7123344315, REGON: 527132802, fulfilling the obligations arising from applicable legal provisions regarding the protection of personal data, including the Regulation of the European Parliament and of the Council (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as GDPR), wishes to provide you with information regarding the processing and protection of your personal data.
The information contained in the Privacy Policy will help you understand what personal data is collected
and processed by pro.therapy Mykhailo Harkavka, for what purpose it is used, and what rights you have in connection with the protection of personal data.
We invite you to read the following information.
WHO COLLECTS AND PROCESSES YOUR PERSONAL DATA, I.E., WHO IS THE CONTROLLER OF YOUR PERSONAL DATA?
pro.therapy Mykhailo Harkavka, based in Warsaw, ul. Koncertowa 4 , 02-787,
(hereinafter referred to as the “Controller” – personal data controller, Controller).
HOW CAN YOU CONTACT THE CONTROLLER?
You can contact the controller:
- via e-mail: kontakt@protherapy.pl,
- by phone: +48 570 037 096,
- by post: ul. Koncertowa 4 , 02-787 Warsaw,
- via the contact form available at https://protherapy.pl/ (including the “Book now” button, which redirects to the Booksy system)
- the provision of medical services;
- undertaken marketing activities;
- establishing contact via forms available on the websites;
- established commercial relations.
- identifying data, including but not limited to: first name, last name, PESEL (national identification number), date of birth;
- contact details, including but not limited to: address, phone number, e-mail address;
- data collected and processed to make a diagnosis and carry out the treatment process, including in particular data concerning health, provided that this applies exclusively to persons using the medical services provided by pro.therapy Mykhailo Harkavka.
- If you use medical services provided by pro.therapy Mykhailo Harkavka:
- If marketing activities are undertaken towards you by pro.therapy Mykhailo Harkavka / a newsletter is sent:
- employees and associates of the Data Controller authorized to process your personal data on the instructions of the Data Controller;
- in the case of personal data processed to provide medical services – other medical entities to ensure treatment continuity and availability of health services;
- entities to which the Data Controller has entrusted the processing of personal data, including:
- providers of technical and organizational services (in particular, providers of ICT services, suppliers of medical equipment, entities providing postal and courier services);
- providers of legal and advisory services, including in the case of pursuing claims related to the business activity conducted by pro.therapy Mykhailo Harkavka and defending against claims;
- ordering parties with whom the Data Controller has concluded contracts for the provision of medical services;
- other entities, persons, or authorities – to the extent and under the conditions specified by law, including persons authorized by you as part of exercising patient rights;
- Proassist sp. z o.o. based in Krakow, os. Handlowe 5, 31-935 Krakow, KRS: 0000378475, NIP: 6762436420, REGON: 121461470 – as the entity operating the Booksy application, through which it is possible to book an appointment and schedule a visit at the Controller’s enterprise;
- The right to information about the processing of personal data – the Controller provides information about the processing of personal data, primarily about the purposes and legal grounds for processing, the scope of data held, the entities to which personal data are disclosed, and the planned date of their deletion;
- The right to obtain a copy of the data – the Controller provides a copy of the processed data regarding the person making the request;
- The right to rectification – the Controller removes any inconsistencies or errors regarding processed personal data, and supplements or updates them if they are incomplete or have changed;
- The right to erasure (the so-called right to be forgotten) – constitutes a basis to request the deletion of data whose processing is no longer necessary to carry out any of the purposes for which they were collected;
- The right to restrict processing – the Controller ceases carrying out operations on personal data, with the exception of operations consented to by the data subject and their storage, in accordance with the adopted retention rules, or until the reasons for restricting data processing cease to exist (e.g., a decision of a supervisory authority is issued allowing for further data processing);
- The right to data portability – to the extent that data is processed in connection with a concluded contract or explicit consent, the Controller provides the data provided by the data subject in a format that can be read by a computer. It is also possible to request that this data be sent to another entity – provided that both the Controller and the other entity to which the data is sent have appropriate technical means enabling such a transfer;
- The right to object to data processing for marketing purposes – the data subject may object at any time to the processing of personal data for marketing purposes, without having to justify such an objection;
- The right to object to other processing purposes – the data subject may object at any time to the processing of personal data on the basis of the Controller’s legitimate interest (e.g., for analytical or statistical purposes or for reasons related to the protection of property). An objection in this respect should contain a justification and is subject to the Controller’s assessment;
- The right to withdraw consent – if data is processed on the basis of consent, the data subject has the right to withdraw it at any time, which, however, does not affect the lawfulness of the processing carried out before the withdrawal of this consent;
- The right to complain – in the event of concluding that the processing of personal data violates the provisions of the GDPR or other provisions regarding the protection of personal data, the data subject may submit a complaint to the President of the Personal Data Protection Office.
- via e-mail: kontakt@protherapy.pl;
- by post: ul. Koncertowa 4 , 02-787 Warsaw,
- via the contact form available at https://protherapy.pl/
- SOCIAL MEDIA
- The Controller processes the personal data of Users visiting the Controller’s profiles run on social media (Facebook or Youtube). This data is processed solely in connection with running the profile, including to inform Users about the Controller’s activities and promote various events, services, and products, as well as to communicate with users via functionalities available on social media. The legal basis for processing personal data by the Controller for this purpose is its legitimate interest (Art. 6 sec. 1 lit. f GDPR) consisting in promoting its own brand and building and maintaining a community related to the brand.
- Integrated social media plugins are visible on the Website. This means that if a User clicks on one of such buttons (such as “Like” on Facebook), certain information will be shared with the providers of these social channels. If the User is simultaneously logged into a given social account, the social service provider may link this information to the User’s social channel account and make activities on the User’s profile public in such a way that they will be shared with other network users.
- Social media plug-ins, including Facebook.com and Youtube and others, may be located on the Website pages. The associated services are provided respectively by Facebook Inc. and Google.
- Facebook and Instagram are operated by Facebook Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2 and Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA Facebook https://developers.facebook.com/docs/plugins ; https://help.instagram.com/519522125107875;
- Youtube is operated by Google, 1600 Amphitheatre Parkway Mountain View, CA 94043 United States: www.google.de/intl/de/policies/privacy;
- The plugin provides its provider only with information about the time the User had access to the Website. If, while viewing the Website or staying on it, the User is logged into their account located e.g., on Facebook or Instagram, the provider is able to combine the User’s interests, information preferences, and other data obtained, for example, by clicking the “Like” button or leaving a comment, or entering the profile name in the search. Such information will also be transmitted directly to the provider by the browser. To avoid recording the visit on the selected User account by Facebook or Instagram on the Website’s page, you must log out of the account before starting to browse the Website.
- The Website also contains links to websites administered by entities independent of the Controller, i.e., Facebook and You Tube. Separate privacy protection clauses or policies may apply to them. The Controller encourages you to familiarize yourself with their content, as the Controller has no influence on the data collected and data processing procedures, nor knowledge of the full scope of their acquisition, the purpose of their processing, or the time of their storage. The Controller also has no information regarding the deletion of data collected by plugin providers.
- Addresses of plugin providers and URLs for their privacy policies:
- Facebook: http://www.facebook.com/policy.php; further information on data acquisition: http://www.facebook.com/help/186325668085084 ; http://www.facebook.com/about/privacy/your-info-on-other#applications and http://www.facebook.com/about/privacy/your-info#everyoneinfo. Facebook joined the “Privacy Shield” agreement concluded between the EU and the USA, https://www.privacyshield.gov/EU-US-Framework.
- Youtube: www.google.de/intl/de/policies/privacy;
- Evaluations from clients or patients of the Controller’s enterprise are also published on the Website, which evaluations are added by them on the Controller’s fanpage maintained on the Facebook portal. The User’s use of the Facebook portal is subject to the Facebook portal’s personal data protection rules, which can be read at the links indicated in paragraph 5 above.
- After adding an opinion and evaluation of the Controller’s enterprise on the Controller’s fanpage maintained on the Facebook portal, the user’s opinion and evaluation will be displayed on the Website at the address: pro.therapy Mykhailo Harkavka. The rating, the content of the opinion, and the name data (usually first and last name) of the account on the Facebook portal from which the given opinion was issued will be visible. By adding an opinion on the Facebook portal, you automatically consent to their display on the Website.
- In the absence of consent to display opinions on the Website, please contact us:
- via e-mail: kontakt@protherapy.pl,
- by phone: +48 70 037 096,
- by post: ul. Koncertowa 4 , 02-787 Warsaw.
- This consent may be withdrawn at any time, and the Controller will remove the opinion from the Website.
- The Website also features an integrated messenger used for contact with the Controller, based on the Messenger communicator belonging to the Facebook company.
- If the User establishes contact with the Controller using this messenger, the User has the option to either log into their Facebook account in order to converse with the Controller from their Facebook account and the associated Messenger, or to converse as a guest. In the latter case, however, the conversation will remain available for a maximum period of 24 hours after the chat is closed.
- If the User chooses the option to converse with the Controller while logged into their Facebook account, personal data and the content of the conversation will be fully visible and accessible to the Facebook portal, which will process the User’s personal data in accordance with its personal data processing rules, which are described here: https://www.messenger.com/privacy?locale=en_US.
- If the User chooses the option to converse with the Controller as a guest, the Facebook portal will also have access to the conversation content and the data contained therein, however, this conversation will not be linked to the User’s account on the Facebook portal.
- Video materials hosted on YouTube are published on the Website. For all these videos, the “extended data protection mode” is used, which means that no data about you as users is transmitted to YouTube unless you play the videos. Only when the video is played are the data listed in paragraph 4 transmitted. We have no influence on this kind of data transmission.
- In the event of a visit to the Website and playback of a given video material hosted on the YouTube portal, the YouTube service receives information that you have opened the given video material on the Website, which involves the transmission of personal data to YouTube. This happens regardless of whether YouTube provides a User account through which you are logged in, or if there is no User account. If you are logged into Google (and consequently also into the YouTube portal), your data is assigned directly to your account. If you do not wish to be assigned to your YouTube profile, you must log out before playing the video material. YouTube saves your data as user profiles and uses it for advertising purposes, market research, and to design its website according to demand. Such analysis is carried out primarily (also for unlogged users) in order to present advertisements tailored to the demand, as well as to inform other social network users about your activities on our website. You have the right to object to the creation of such user profiles, however, to exercise this right you must contact YouTube.
- More information regarding the purpose and scope of data collection and processing by YouTube can be obtained from the privacy policy statement. There you will also receive further information regarding your rights and the possibilities of making settings to protect your privacy sphere: www.google.de/intl/de/policies/privacy. Google also processes your personal data in the USA and complies with the EU-US-Privacy-Shield agreement, www.privacyshield.gov/EU-US-Framework.
- “SERVICE” COOKIES
- The Controller uses so-called service cookies primarily to provide the User with services provided electronically and to improve the quality of these services. In connection with this, the Controller and other entities providing analytical and statistical services on its behalf use cookies, storing information or accessing information already stored in the User’s telecommunications end device (computer, phone, tablet, etc.). Cookies used for this purpose include:
- cookies with data entered by the User (session ID) for the duration of a session (user input cookies);
- authentication cookies used for services that require authentication for the duration of a session (authentication cookies);
- cookies used to ensure security, e.g., used to detect authentication fraud (user centric security cookies);
- multimedia player session cookies (e.g., flash player cookies), for the duration of a session (multimedia player session cookies);
- persistent cookies used to personalize the User’s interface for the duration of a session or slightly longer (user interface customization cookies),
- cookies used to remember the contents of a shopping cart for the duration of a session (shopping cart cookies);
- To collect statistics, the Controller uses the Google Analytics product; thus, data regarding the User visiting the Service will be received by Google, 1600 Amphitheatre Parkway Mountain View, CA 94043 United States. Google is certified under the Privacy Shield program. As part of an agreement between the USA and the European Commission, the latter has determined an adequate level of data protection in the case of enterprises holding a Privacy Shield certificate. It is possible to block Google Analytics access to User data after the User installs a plugin in their browser, which can be found at this link: https://tools.google.com/dlpage/gaoptout/. If you are interested in details related to data processing under Google Analytics, we encourage you to read the explanations prepared by Google: https://policies.google.com/privacy?hl=en.
- “MARKETING” COOKIES
- The Controller also uses cookies for marketing purposes, including in connection with directing behavioral advertising to Users. For this purpose, the Controller stores information or accesses information already stored in the User’s telecommunications end device (computer, phone, tablet, etc.). The use of cookies and personal data collected through them for marketing purposes requires the User’s consent. This consent can be expressed through appropriate browser configuration, and it can also be withdrawn at any time, in particular by clearing the cookie history and disabling cookies in the browser settings.
- GOOGLE ADS.
- The Website uses the Google Ads program.
- Google Ads is a program by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States (“Google”). As part of Google Ads, the Controller applies so-called conversion tracking. When you click an ad displayed by Google, a conversion tracking cookie is generated. Cookies are small text files saved in the web browser on the user’s computer. Such cookies expire after 30 days and are not used for personal identification. If the user visits certain pages of this website and the cookie has not yet expired, Google and the Website are informed that the user was redirected to this page after clicking the ad.
- Every Google Ads client receives a different cookie. Cookies cannot be tracked through the websites of Ads clients. Information collected via a conversion cookie is used to compile conversion statistics for Ads clients who have opted for conversion tracking. Clients receive information about the total number of users who clicked the ad and were redirected to a page tagged with a conversion tracking tag. However, they do not receive information that can personally identify a user. If you do not wish to participate in conversion tracking, you can object to the use of this function. To do this, simply deactivate the Google conversion tracking cookie in your web browser. You will then not be included in the conversion tracking statistics.
- The storage of the conversion cookie takes place on the basis of Art. 6 sec. 1 lit. f GDPR. The website operator has a legitimate interest in analyzing user activity in order to optimize both its website offer and its advertising.
- More information on Google Ads and Google Conversion Tracking can be found in Google’s privacy policy at: https://www.google.pl/policies/privacy/.
- You can set your browser to inform you about the generation of cookies and to allow them only on a case-by-case basis, to exclude the acceptance of cookies in certain cases or in general, and to activate the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.