The controller of the personal data is MED&CARE Tomasz Witkowski with registered seat at 13 Mławska Street in Gdynia, NIP [Tax Identification Number]: 782-199-58-32 (hereinafter referred to as: MED&CARE).
We attach particular importance to protecting the privacy of Users visiting the website in the domain * medandcare.pl. We make sure that the processing of personal data is in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter referred to as: “GDPR”), the Act on Personal Data Protection and special provisions.
What we use your personal data for
MED&CARE may collect personal information which is done, depending on the nature of the data – automatically or as a result of the actions of site visitors.
Users’ personal data may be processed by MED&CARE:
- if the User of the site agrees to this in request forms on the website in order to take actions to which these forms pertain (Article 6, paragraph 1, point (a) of the GDPR) or
- when processing is necessary for the performance of the contract to which the User of the website is a party (Article 6, paragraph 1, point (b) of the GDPR), in case when the website makes it possible to conclude an agreement between the Controller and the website User.
As part of the service, personal data are processed, which are only voluntarily provided by website Users. MED&CARE processes personal data of website Users only to the extent necessary for the objectives stated above and for a period necessary to achieve these objectives, or until the User withdraws his or her consent. The lack of data provided by the website User may in some situations result in the inability to achieve the objectives for which providing data is necessary.
As part of the request forms or for the purpose of implementing the agreements that can be concluded within the website, the following personal data of the website User may be collected: name, surname, address, shipping address, e-mail address, telephone number, login, password.
The data included in the request forms, provided to MED&CARE by the website User, may be transferred to third parties that cooperate with MED&CARE in connection with the implementation of the objectives stated above.
The data provided in the request forms on the site are processed for purposes that result from the function of a given request form, moreover, they can also be used by MED&CARE for archival and statistical purposes. Consent of the data subject is expressed by selecting the appropriate box in the form.
The service User, if the website has such functionality, by selecting the appropriate box in the registration form, may refuse or consent to receive commercial information by electronic means, in accordance with the Act of 18 July 2002 on the provision of electronic services (Journal of Laws of 2017, item 1219, as of 2018, item 650).
If the website User has consented to receive commercial information via electronic means, s/he has the right to withdraw such consent at any time, by sending an e-mail to MED&CARE address (email@example.com) with an appropriate request together with the User’s first and last name.
The data provided in the request forms may be transferred to entities technically performing certain services – in particular, this concerns the transfer of information about the holder of the registered domain to entities that are the Internet domain operators or other entities with which MED&CARE cooperates in this respect.
The personal data of website Users are stored in a database in which technical and organizational measures ensuring protection of data processed in accordance with the requirements of the relevant regulations have been applied.
To prevent re-registration of people whose participation in the service has been terminated due to improper use of the service, MED&CARE may refuse to delete personal data necessary to block the possibility of re-registration. The legal basis for the refusal is art. 19 paragraph 2 point 3 in connection with art. 21 paragraph 1 of the Act of 18 July 2002 on the provision of electronic services. A refusal by MED&CARE to remove personal data of service Users may also occur in other cases provided for by law.
In cases provided for by law, MED&CARE may share some of the personal data of website users with third parties for purposes related to the protection of the rights of third parties.
Under what terms and on what basis we process personal data
We ensure that your personal information is:
- processed lawfully, fairly and in a transparent manner;
- collected for specific and legitimate purposes;
- appropriate, relevant and limited to what is necessary;
- correct and, if necessary, updated;
- stored for no longer than necessary;
- processed in a manner ensuring adequate security.
How long do we process personal data?
The time by which we process your personal data depends on the legal basis that constitutes a legal prerequisite for the processing of personal data by MED&CARE.
We process personal data for the time necessary to implement the contract concluded with the User, and then for the period and to the extent required by law and the period after which claims arising from the contract expire.
If we process personal data on the basis of a justified interest, in particular for the purpose of direct marketing, we store the data until the User file an objection to such processing. After this time, further data storage can be performed only due to the implementation of the contract or the provisions law.
What rights you are entitled to?
Each website User has the following rights:
- The right of access to data
The data subject is entitled to obtain confirmation from MED & CARE whether personal data concerning him/her is being processed and, if so, s/he is entitled to have access to it. MED & CARE shall provide the data subject with a copy of the personal data that is being processed.
- The right of rectification of data
The data subject has the right to request from MED&CARE immediate rectification of their personal data that are incorrect.
- The right to have their data erased („the right to be forgotten”)
The data subject has the right to request from MED&CARE immediate deletion of their personal data, and MED & CARE is obliged to delete personal data without undue delay if one of the following circumstances applies:
- personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
- the data subject has withdrawn the consent on which the processing is based;
- the data subject has filed an objection under Article 21 par. 1 against processing and there are no overriding legitimate grounds for processing.
- The right to have the processing restricted
The data subject has the right to request from MED & CARE imposing restrictions on processing data in the following cases :
- When the data is incorrect – until it is improved;
- The data subject has objected to the processing – until it is established whether the legitimate grounds on the part of MED & CARE override the grounds for objection made by the data subject;
- The processing is unlawful and the data subject opposes the removal of personal data, requesting to limit its use instead.
- The right to data portability
The data subject has the right to receive, in a structured, commonly used, machine-readable format, personal data concerning him/her provided by MED&CARE and s/he has the right to send this personal data to another administrator without any hindrance from MED&CARE to whom this personal data was provided. The data subject has the right to request that personal data be sent by MED&CAR directly to another administrator, if technically possible. The right referred to in this point may not adversely affect the rights and freedoms of others.
- The right to object
If personal data are processed for direct marketing purposes, the data subject has the right to object at any time to the processing of his/her personal data for such marketing purposes, including profiling, to the extent that such processing is necessary for such direct marketing.
Execution of the above rights of website Users may be paid for in cases where the relevant provisions of law provide for it.
In case of violation of the above rights or the declaration by the User that his/her personal data are not being processed by MED&CARE in compliance with the applicable laws, the website User has the right to lodge a complaint to the supervisory body.
The mechanism of Cookies on website
The Cookies mechanism is used to obtain information about website users or to track their navigation (Google Analitics). Cookies used on website store personal data and other information collected from users.
On the website periodically a session cookie file can be used to save the fact that you have read the highlighted information.
The last update of this document took place on September 12, 2018.