Privacy Policy

MB Viena klinika

Personal Data Processing Policy

  1. General Provisions

  1. This personal data processing policy governs the conditions under which MB Viena klinika (legal entity code 305614464; the “Data Controller”) processes the personal data of the Data Controller’s clients and persons using the Data Controller’s website https://clinicep.lt/ (the “Website”) (the “Privacy Policy”).
  2. The Data Controller processes data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the “Regulation”), as well as other legal requirements applicable in the Republic of Lithuania.
  3. The Data Controller may update and/or amend the Privacy Policy at any time unilaterally, by publishing the updated Privacy Policy on the Website, as well as by individually notifying users by email. Any Privacy Policy published on the Website replaces all previous versions of the Privacy Policy and takes effect immediately upon publication, or from the date specified in the Privacy Policy.
  4. Every user who uses the Website, as well as every user of the services provided by the Data Controller, agrees to this Privacy Policy. If a user does not agree with the Privacy Policy, they may not use the Website, and also have the right not to use the services provided by the Data Controller.
  5. [contact details, should you wish to get in touch]
  6. The Data Controller processes personal data in accordance with the principles of lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality, as set out in the Regulation.
  7. The Data Controller processes the following personal data of users:
    1. name, surname, date of birth, contact information;
    2. information about the client’s state of health;
    3. the client’s image;
    4. information collected by cookies about browsing on the Website.

  1. Purposes and Retention Periods for the Collection and Processing of Personal Data

 PurposeDataData Retention Period
2.1.Conclusion and performance of the agreement with the clientName, surname, date of birth, phone number10 years after the last time services were provided to the client
2.2.Provision of services; verification of whether the client’s medical condition is suitable for the provision of servicesInformation on whether the client is of legal age; information on the client’s state of health according to the questionnaire submitted together with the agreement10 years after the last time services were provided to the client
2.3.MarketingEmail address, phone number, client’s image3 years after the last time services were provided to the client

  1. Methods by Which Data Is Collected

  1. In order to achieve the purposes specified in Clause 2, the Data Controller collects data in the following ways:
    1. Directly from the client, who completes the agreement and questionnaire about the client’s state of health provided to them. In some cases, data may be collected directly from the client through communication by phone, email, or other electronic correspondence (for example, correspondence on social media);
    2. When browsing the Website, technical information such as the IP address, information about the device and software, and cookies may be collected automatically;
    3. The client’s image is collected directly from the client, during their visit to the Data Controller and during the provision of services.

  1. Transfer of Information to Third Parties

  1. The Data Controller has the right to transfer collected data to providers of legal, accounting, bookkeeping, audit, and other services, ensuring that such persons have taken the necessary and proportionate measures to protect the data.
  2. The Data Controller may provide Users’ personal data to the authorities and law enforcement institutions, bodies, organizations, banks, and other entities of the Republic of Lithuania that have a right, established by the laws of the Republic of Lithuania or other legal acts in force in the Republic of Lithuania, to access personal data.

  1. Users’ Rights Related to Personal Data

  1. Without prejudice to any rights provided for in applicable legislation, the Data Controller’s clients and Website users have the following rights:
    1. Right of access to data. The user has the right to know whether the Data Controller processes the user’s data and, if the Data Controller does process such data, to access this data;
    2. Right to rectification of data. The user has the right, taking into account the purpose of data processing, to have inaccurate personal data corrected and incomplete information completed;
    3. Right to erasure of personal data. The user has the right to request the Data Controller to erase personal data collected about the user, provided that such a request is sufficiently substantiated. Notwithstanding such a request, the Data Controller may refuse to erase the data if there is a sufficient legal basis to retain the data, including, but not limited to, the purposes for which the data was collected;
    4. Right to restrict data processing. The user has the right to ask the Data Controller to restrict the processing of personal data, provided that such a request is sufficiently substantiated;
    5. Right to data portability. The user has the right to receive the personal data collected by the Data Controller about them in a structured, commonly used, and machine-readable format;
    6. Right to object to data processing. The user has the right to object to the processing of their personal data, however the Data Controller has the right to continue processing the data if there is a legitimate basis for the data processing;
    7. Right to lodge a complaint. The user has the right to lodge a complaint with the State Data Protection Inspectorate. The Data Controller is always ready to resolve any disputes amicably, however the user has the right to contact the State Data Protection Inspectorate directly and lodge a complaint.

  1. Cookies

  1. The Data Controller uses cookies on the Website.
  2. The following cookies are used on the Website:

 NameProviderDescription
6.2.1.LanguagesData ControllersTechnical cookie