Privacy Policy

Centrum Zdrowia BIOMED

At Centrum Zdrowia BIOMED, we respect your privacy and understand that by sharing your personal information with us, you place your trust in our hands. We want to be transparent about how we handle your personal data.

This Privacy Policy explains how and when we collect personal data, the purposes for which we use it, who we share it with, how long we keep it, and what rights you have in connection with data processing.

This document has been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and applicable Polish law.

1. Definitions

In this Policy, we use the following terms:

Controller (Administrator) – Hanna Ormańczyk, conducting business under the name Centrum Zdrowia BIOMED Hanna Ormańczyk, based in Gdańsk, ul. Rajska 14, 80-850 Gdańsk, NIP: 6040236462, REGON: 524272193.

Patient / User – an individual using the services of the Centre or visiting the website www.centrumzdrowiabiomed.com.

Personal Data – any information that can identify a natural person, such as name, surname, personal identification number (PESEL), e-mail address, or health data.

Processing of Personal Data – any operation performed on data, such as collecting, storing, transferring, or deleting.

Processor – an external entity that processes data on behalf of the Controller (e.g. booking system provider, payment operator).

Newsletter – a service consisting of sending e-mails containing information about news, services, and events.

Cookies – small text files stored on the user’s device that enable the proper functioning of the website and the analysis of its use.

GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.

Consent – a freely given, specific, informed, and unambiguous indication of a person’s wishes to process personal data for a specific purpose.

Profiling – automated processing of personal data to tailor services or content to a user’s preferences.

2. Data Controller

The data controller is:

Centrum Zdrowia BIOMED Hanna Ormańczyk
ul. Rajska 14, 80-850 Gdańsk
Email: infocentrumzdrowiabiomed@gmail.com
Phone: +48 880 110 060

Centrum Zdrowia BIOMED is a medical entity registered in the Register of Healthcare Providers.

3. Scope and Sources of Personal Data

We process personal data that you provide voluntarily or that is necessary for the provision of medical services, including:

  • name, surname, personal identification number (PESEL), date of birth, address of residence,
  • phone number, e-mail address,
  • health information, visit history, test results, medical recommendations,
  • billing data (e.g. tax number, bank account, invoice details),
  • technical data related to website use (IP address, cookies).

4. Purposes and Legal Bases for Processing

Your personal data is processed for the following purposes:

4.1. Provision of Healthcare Services

To maintain medical records, provide consultations, diagnostics, and therapy.
Legal basis: Article 6(1)(c) and Article 9(2)(h) GDPR.

4.2. Online Appointment Booking

Managing online bookings through:

  • Calendesk 
  • ZnanyLekarz.pl 

These systems act as data processors within the meaning of Article 28 GDPR.
If you use your ZnanyLekarz account, ZnanyLekarz acts as the data controller for that scope.
Legal basis: Article 6(1)(b) GDPR (performance of a contract).

4.3. Online Payments

You can purchase gift vouchers for BIOMED services through our website.
Payments are processed via Przelewy24, operated by PayPro S.A. (ul. Pastelowa 8, 60-198 Poznań).
For transaction processing, we share necessary data (e.g. name, e-mail, phone number, payment amount, order number).
Legal basis: Article 6(1)(b) GDPR (performance of a contract).
Details on Przelewy24’s data processing are available at: https://www.przelewy24.pl/polityka-prywatnosci.

4.4. Contact and Inquiry Handling

Responding to messages sent via contact forms, e-mail, or social media.
Legal basis: Article 6(1)(b) and (f) GDPR (contract / legitimate interest).

4.5. Newsletter and Marketing Communication

Sending e-mail or SMS messages about news, services, and events.
Legal basis: Article 6(1)(a) GDPR (consent), Article 10 of the Act on Electronic Services, and Article 172 of the Telecommunications Law.

4.6. Feedback and Satisfaction Surveys

We may contact patients after their visits (e.g. via e-mail or SMS) to request feedback or invite them to complete a short survey.
Legal basis: Article 6(1)(f) GDPR (legitimate interest – quality improvement).

External service providers specializing in collecting patient feedback may process data solely on behalf of BIOMED under data processing agreements.
If a patient’s opinion is published (e.g. on the website or social media), it is done based on voluntary consent under Article 9(2)(a) GDPR, which can be withdrawn at any time.

4.7. Social Media

Managing BIOMED profiles on Facebook and Instagram to communicate with patients and promote services.
Legal basis: Article 6(1)(f) GDPR (legitimate interest).
In relation to statistical data, Centrum Zdrowia BIOMED and Meta Platforms Ireland Ltd. act as joint controllers under Article 26 GDPR.

4.8. Website Analytics and Security

Using analytical and marketing tools (e.g. Google Analytics, Meta Pixel).
Legal basis: Article 6(1)(f) GDPR (statistics, security) and Article 6(1)(a) GDPR (cookie consent).

5. Data Recipients

Personal data may be shared with:

  • medical professionals, associates, and partner laboratories,
  • hosting, booking, accounting, payment, marketing, or IT service providers,
  • system operators,
  • public authorities where required by law.

All entities process data under data processing agreements (Article 28 GDPR).

6. Data Transfers Outside the EEA

Some data (e.g. cookies, analytics) may be transferred to third countries, primarily the United States, through tools provided by Google and Meta.
Such transfers are carried out in accordance with the European Commission’s adequacy decision (EU–US Data Privacy Framework) or under Standard Contractual Clauses (SCC).

7. Data Retention Periods

We store personal data only as long as necessary, in accordance with legal requirements and the data minimization principle.

Medical Records
Patient documentation is stored for 20 years from the last entry date, 30 years in cases of death caused by injury or poisoning, and 10 years for X-ray images stored outside medical records, pursuant to the Polish Patient Rights Act.

Financial and Accounting Data
Kept for 5 years as required by tax regulations.

Booking and Contact Data
Kept for up to 2 years from the visit or last contact, to confirm arrangements or respond to follow-up inquiries.

Marketing and Newsletter Data
Kept until consent is withdrawn. You may unsubscribe at any time via the link in each email or by contacting us at info@centrumzdrowiabiomed.pl.

Feedback and Survey Data
Stored for up to 2 years to analyze and improve service quality.

Technical and Cookie Data
Stored until consent is withdrawn or cookies are deleted from the browser.

8. Cookies

Our website uses cookies to:

  • ensure proper functionality (necessary cookies),
  • analyze website traffic and statistics (analytical cookies),
  • tailor content and ads (marketing cookies).

A cookie banner is displayed during your first visit, allowing you to manage your preferences.
Consent is voluntary and can be withdrawn at any time.

9. Data Security

We apply appropriate technical and organizational measures to protect personal data against loss, unauthorized access, or disclosure.
Access to data is granted only to authorized individuals bound by confidentiality obligations.

10. Changes to the Privacy Policy

This Policy may be updated due to legal changes or modifications in data processing practices.
The current version is always available at:
www.centrumzdrowiabiomed.pl/polityka-prywatnosci

envelopephone-handsetmap-marker linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram