Privacy policy
Cosmodent Kft. hereby informs its patients of its data processing related to dental or other relevant services according to the Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: GDPR):
1. Identity and contact details of the controller
Patient’s data is processed by Cosmodent Kft., whose business data are the following:
Name of the company: Cosmodent Kft.
Seat: 1118 Budapest, Budaörsi út 9.
Phone: +36 1 2001378
E-mail adress: info@cosmodent.hu
Representative: Dr. Óvári Zoltán managing director
2. Short description of the data processing
Cosmodent Kft. processes the below personal data of the patient:
- personal identifiers (in particular, forename and surname, maiden name, sex, date and place of birth, mother’s maiden forename and surname, residence, domicile, social security number);
- data concerning health insurance and other insurance;
- electronic contact details (in particular, phone number, email address);
- data concerning health, in particular personal data related to the physical or mental health of the patient, including the provision of health care services, which reveal information about his or her health status provided directly by the patient or by a third party e.g. by the below specified Online Agency;
- data concerning the patient’s travelling’s;
- required data for issuance of invoice;
- other personal data provided by the patient to Cosmodent Kft.
At first Cosmodent Kft. receives the patient’s personal data from the online dental agency (hereinafter: „Online Agency”), which contacted the patient. The Online Agency transfers personal data to Cosmodent Kft. in order Cosmodent Kft. could prepare a treatment plan and an offer for the patient for the preparation of the health care and treatment services agreement.
Cosmodent Kft. forwards or makes available the treatment plan and the offer to the Online Agency.
If the patients choose Cosmodent Kft. to carry out the treatment, Cosmodent Kft. helps to organize the travelling of the patient to Hungary and its commuting and lodging in Hungary.
Cosmodent Kft. concludes an agreement with the patient for the provision of health care and treatment services. During the provision of health care and treatment services Cosmodent Kft. engages other health care services providers, professionals, laboratories depending on the nature of the health care and treatment services.
If the patient has any question after the provision of health care and treatment services and addresses its question to Cosmodent Kft. via the Online Agency, then Cosmodent Kft. sends its answer to the Online Agency.
If the insurance company named by the patient addresses a question to Cosmodent Kft. regarding the health care and treatment services, Cosmodent Kft. sends its answer to the insurance company. If the insurance company addresses its question to Cosmodent Kft. via the Online Agency, then Cosmodent Kft. sends its answer to the Online Agency.
3. Contact details of the data protection officer
Contact details of Cosmodent Kft.’s data protection officer are the following:
Name: Hámori Adrienn
Email: hamori.adrienn@webflow-dental.com
Tel.: +36 70 623 1261
4. Purposes of the processing of personal data
Cosmodent Kft. processes patient's personal data for the below purposes:
- to prepare treatment plan and offer to the patient on the basis of the data provided by the Online Agency and return them to the Online Agency;
- to prepare and perform health care and treatment services agreement concluded with the patient;
- to comply with legal obligations relating to the health care and treatment services;
- to perform additional services based on the agreement concluded with the patient, in particular to organize travelling;
- to comply with legal obligations to which Cosmodent Kft. is subject, in particular to comply with the legal obligations regarding information providing on healthcare services, issuance of invoices and accounting obligations;
- accounting, certifying and post-audit the performance of services provided upon the service agreement concluded with the patient, enforcement of claims arising from the agreement;
- to answer the questions of the patients after the treatment, if the patient addresses its question to Cosmodent Kft. via the Online Agency, then Cosmodent Kft. sends its answer to the Online Agency;
- to report to the patient’s insurance company, if the insurance company’s request is forward by the Online Agency to Cosmodent Kft. , then Cosmodent Kft. sends its answer to the Online Agency.
5. Legal basis for the processing of personal data
Cosmodent Kft. processes patient's personal data in accordance with below legal basis:
- in accordance with par. b) of paragraph 1) Article 6 of the GDPR, i.e. processing is necessary in order to take steps at the request of the patient prior to entering into a contract;
- in accordance with par. b) of paragraph 1) Article 6 of the GDPR, i.e. processing is necessary for the performance of a contract to which the patient is party;
- in accordance with par. c) of paragraph 1) Article 6 of the GDPR, i.e processing is necessary for compliance with a legal obligation to which Cosmodent Kft. is subject;
- in accordance with par. f) of paragraph 1) of Article 6 of the GDPR, i.e processing is necessary for the purposes of the legitimate interests pursued by Cosmodent Kft. The legitimate interest of Cosmodent Kft. includes the enforcement of rights and claims arising from the service agreement concluded with the patient, and also the defence from any claims raised against Cosmodent Kft.
Cosmodent Kft. processes patient's personal data concerning health in accordance with below legal basis:
- in accordance with par. f) of paragraph 2) of Article 9 of the GDPR, i.e processing is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in their judicial capacity;
- in accordance with par. h) of paragraph 2) of Article 9 of the GDPR, i.e processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of Union or Member State law or pursuant to contract with a health professional;
- regarding the reporting and data transmission of data concerning health to the Online Agency and to the patient’s insurance company, the legal basis is par. a) of paragraph 2) of Article 9 of the GDPR, i.e. the patient’s consent.
Regarding personal data concerning health Cosmodent Kft. hereby informs its patients that health related data are processed by or under the responsibility of a professional subject to the obligation of professional secrecy under Hungarian law.
6. Categories of recipients of personal data
Cosmodent Kft. transfers patient's personal data to the below recipients:
- contracting health care service providers and professionals, dental technology laboratories, and other laboratories of Cosmodent Kft.;
- accountant;
- auditor;
- taxi driver providing shuttle services;
- public authorities;
- central register, in particular Central Register of Implants;
- IT service provider;
- attorney-at-law;
- patient’s insurance company;
- Online Agency.
7. Data retention period
Medical documentation shall be stored for 30 years from obtaining data, the final report shall be stored for 50 years pursuant to Act XLVII of 1997 on the Processing and Protection of Personal Data in the Field of Medicine.
8. Data transfer to a third country
Cosmodent Kft. transfers the data of Swiss patients or Swiss resident patients to Switzerland. The Commission has decided that Switzerland ensures an adequate level of protection in respect of data processing.
9. Patients’ rights
9.1 Right of access
The patient shall have the right to obtain from Cosmodent Kft. confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information:
- the purposes of the processing;
- the categories of personal data concerned;
- the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
- where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
- the existence of the right of the patient to request from Cosmodent Kft. rectification or erasure of personal data or restriction of processing of personal data concerning the patient or to object to such processing;
- the right to lodge a complaint with a supervisory authority;
- where the personal data are not collected from the patient, any available information as to their source.
Where personal data are transferred to a third country or to an international organisation, the patient shall have the right to be informed of the appropriate safeguards pursuant to GDPR relating to the transfer.
Cosmodent Kft. shall provide a copy of the personal data undergoing processing. For any further copies requested by the patient, Cosmodent Kft. may charge a reasonable fee based on administrative costs. Where the patient makes the request by electronic means, and unless otherwise requested by patient, the information shall be provided in a commonly used electronic form. The right to obtain a copy referred to in the present section shall not adversely affect the rights and freedoms of others.
Cosmodent Kft. hereby informs the patients that it does not applies automated decision-making, and profiling.
9.2 Right to rectification
The patient shall have the right to obtain from Cosmodent Kft. without undue delay the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the processing, the patient shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
9.3 Right to erasure
Since the data processing is necessary for compliance with a legal obligation which requies processing by Hungarian law to which Cosmondent Kft. is subject, and the data retention period is defined by the law, the patient is not entitled to the right to erasure pursuant to paragraph 3) of Article 17 of the GDPR.
9.4 Right to restriction of processing
The patient shall have the right to obtain from Cosmodent Kft. restriction of processing where one of the following applies:
- the accuracy of the personal data is contested by the patient, for a period enabling Cosmodent Kft. to verify the accuracy of the personal data;
- the processing is unlawful and the patient opposes the erasure of the personal data and requests the restriction of their use instead;
- Cosmodent Kft. no longer needs the personal data for the purposes of the processing, but they are required by the patient for the establishment, exercise or defence of legal claims.
Where processing has been restricted under the above, such personal data shall, with the exception of storage, only be processed with the patient's consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.
Cosmodent Kft. hereby informs the patient who has obtained restriction of processing before the restriction of processing is lifted.
9.5 Right to object
The patient shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is necessary for the purposes of the legitimate interest pursued by Cosmodent Kft. In this case, Cosmodent Kft. shall no longer process the personal data unless Cosmodent Kft. demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.
Cosmodent Kft. hereby informs the patient, that its personal data are not processed for direct marketing purposes.
9.6 Right to data portability
Since the processing is not carried out by automated means, the patient is not entitled to the right to data portability.
9.7 Right to withdraw the consent
The legal basis for the reporting and transmission of data concerning health to the Online Agency and to the patient’s insurance company is the consent of the patient. The patient has a right to withdraw his or her consent. The withdrawal of consent shall not affect the lawfulness of reporting and data transmission based on consent before its withdrawal.
The right to withdraw consent affects only the reporting and transmission of data concerning health to the Online Agency and to the patient’s insurance company.
Therefore, in case the withdrawal of consent, Cosmodent Kft. is still entilted to
- to process data concerning health according to the legal basis listed in par. a)-f) of Section 5 hereof;
- to transfer personal data that is not concerning health to the Online Agency or to the insurance company according to the agreement concluded with the patient.
9.8 Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, every patient shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the patient considers that the processing of personal data relating to him or her infringes the GDPR.
In Hungary the below supervisory authority is competent:
Official name: Hungarian National Authority for Data Protection and Freedom of Information
Seat: 1125 Budapest, Szilágyi Erzsébet fasor 22/c.
Address: 1530 Budapest, Pf.: 5.
Phone: +36 (1) 391-1400
Fax: +36 (1) 391-1410
E-mail: ugyfelszolgalat@naih.hu
URL of the webpage: http://www.naih.hu
10. Grounds for provision of personal data
Since without providing patient’s personal data the provision of health care and treatment services would be impossible, the provision of personal data is a precondition for concluding the health care and treatment service agreement. The failure to provide the personal data detailed in par. g) of Section 10., does not affect the performance of the agreement concluded with the patient, however the data which are not provided will be obviously ignored during the performance of the agreement.