Everything related to individuals and their lives can be described as data. Such personal data includes, for example, a person’s name, address, contact details, etc. Personal data also includes various sensitive data, such as personal medical data.
Ortopeedia Arstid AS (hereinafter ‘OA’) has a legal responsibility to protect the privacy of its patients, customers and employees. Thus, here we describe the policy we follow for the collection, use, disclosure, transfer and storage of the data of the aforementioned stakeholders.
LEGAL BASES FOR DATA PROCESSING
1.1. OA is a healthcare provider, which has the right and obligation to process any personal data necessary for the provision of healthcare services, including sensitive personal data arising from legislation in force in the Republic of Estonia (Health Services Organisation Act, Health Insurance Act, Medicinal Products Act, Health Information System Statute).
1.2. The personal data of job applicants and employees shall be processed in accordance with the Employment Contracts Act.
SECURITY OF DATA
2.1. The security of the data stored in OA’s information systems is ensured through the implementation of security measures for protecting the data against loss, misuse and alteration. The security and privacy policy shall be reviewed periodically and updated as necessary. Only authorised persons shall have access to the data.
2.2. OA’s website www.ortopeediaarstid.ee contains the necessary measures to protect the integrity, accuracy and privacy of collected personal data. The website is secured with an updated SSL certificate, which enables the use of a private encrypted communications channel over public Internet (HTTPS) and ensures the confidentiality and integrity of transmitted data.
PROTECTION OF PERSONAL DATA
3.1. Ortopeedia Arstid AS shall take all precautionary measures (including administrative, technical and physical measures) for the protection of the personal data of its patients, customers and staff. Access to personal data for amendment and processing is only provided to authorised persons.
3.2 We collect personal data from the following sources:
3.3. We collect and process your personal data whenever:
3.4. Upon submitting personal data, you also grant us permission to process the data.
DISCLOSURE OF DATA TO THIRD PARTIES
4.1. OA may disclose your personal data:
ACCESSING PERSONAL DATA
5.1. You have the right to access the personal data we have collected about you, request the correction or deletion of the data, object to or request the restriction of the processing of the data, provided that it does not conflict with the legislation in force in the Republic of Estonia. Requests may be submitted via our units’ reception desk or digitally signed and submitted by e-mail to orto@ortopeediaarstid.ee. Data shall be issued on the basis of an identity document or in an encrypted form on the basis of a personal identification code.
5.2 Ortopeedia Arstid AS has the right to charge a reasonable service fee for handling requests, if it involves an unreasonable amount of work or financial costs, for example, making copies of original documents, reviewing information related to medical records, etc.
Note! In the interest of the security of your data, we shall not issue data or the results of examinations/analyses by phone.
5.2 Personal information shall not be issued, if this may:
DATA RETENTION
6.1 Patients’ and customers’ medical records shall be retained for 110 years from the date of birth of the patient or customer. Referrals, nursing records, analysis results, etc. related to medical histories shall be retained for up to 30 years after the end of the medical history (legal basis: Regulation No. 56 of the Minister of Social Affairs).
6.2 Employees’ employment contracts shall be retained for 10 years after the expiry of the employment contract.
6.3 Accounting documents shall be retained for 7 years (legal basis: the Accounting Act)
PROTECTION OF RIGHTS AND CONTACT INFORMATION
7.1. In matters related to the processing of personal data, please contact our data protection specialist. The data protection specialist of Ortopeedia Arstid AS is Mart Jalakas, e-mail address: andmekaitse@ortopeediaarstid.ee, address: Paldiski mnt 68a, 10617 Tallinn.
7.2. The chief processor is Ortopeedia Arstid AS, registry code 11096463, located at Paldiski mnt 68a, 10617 Tallinn, e-mail address: orto@ortopeediaarstid.ee, website: www.ortopeediaarstid.ee, phone: 606 7747.
7.3. If you believe that we have violated your rights during the processing of your personal data, you may submit a complaint to the hospital’s data protection specialist or the Estonian Data Protection Inspectorate (Väike-Ameerika 19, Tallinn 10129, e-mail address: info@aki.ee).
Ortopeedia Arstid AS shall do everything in its power to protect your personal data and comply with data protection and privacy laws!
...This website uses Cookies to help us provide best customer experience. By using our website you agree to use cookies. More info
The cookie settings on this website are set to "allow cookies" to give you the best browsing experience possible. If you continue to use this website without changing your cookie settings or you click "Accept" below then you are consenting to this.