1. general information
- This policy applies to the Website, operating at url: https://leczeniedepresji.com
- The operator of the website and the Administrator of personal data is: Remedios Sopockie Centrum Leczenia Bólu i Rehabilitacji sp. z o.o. Aleja Niepodległości 754, 81-868 Sopot NIP: 5851497434 | REGON: 522075643 | KRS: 0000972730
- Operator’s email contact address: kontakt@remedios.clinic
- The Operator is the Administrator of your personal data with respect to the data you voluntarily provided to Service.
- The Service uses personal data for the following purposes:
- Handling inquiries via form
- Through voluntarily entered data in the forms, which are entered into the Operator’s systems.
- By storing cookies (so-called “cookies”) on end devices.
2 Selected data protection methods used by the Operator
- The login and personal data entry sites are protected in the transmission layer (SSL certificate). This ensures that the personal and login data entered on the site are encrypted in the user’s computer and can only be read on the target server.
- Personal data stored in database is encrypted in such a way that only those holding the Operator key can read it. This ensures that the data is protected in case the database is stolen from the server.
- User passwords are stored in hashed form. The hash function works one-way – it is not possible to reverse it, which is now the modern standard for storing user passwords.
- The operator periodically changes its administrative passwords.
- In order to minimize the risk of unauthorized access from the data, Operator uses compound passwords, containing lowercase and uppercase letters, digits and special characters, not shorter than 8 characters.
- An important element of data protection is the regular updating of all software, used by the Operator to process personal data, which in particular means regular updates of software components.
- In order to protect the data, the Operator regularly makes security copies.
3. hosting
- The service is hosted (technically maintained) on the operator’s server: zenbox.pl
- Registration details of the hosting company: cyber_Folks S.A. with its registered seat in Poznań, Wierzbięcice 1B, 61-569 Poznań, registered in the National Court Register by the District Court Poznań – Nowe Miasto and Wilda in Poznań, VIII Economic Department of the National Court Register under the KRS number 0000685595, REGON 367731587, NIP 7792467259, share capital PLN 306,288.00 fully paid up.
- At https://zenbox.pl you can learn more about hosting and check the hosting company’s privacy policy.
-
Web hosting company:
- employs measures to protect against data loss (e.g., disk arrays, regular security copies),
- applies adequate measures to protect processing sites in case of fire (e.g., special systems firefighting),
- uses adequate measures to protect processing systems in the event of a sudden power failure (e.g., dual power paths, generators, UPS voltage backup systems),
- applies physical access protection measures to data processing sites (e.g., access control, monitoring),
- applies measures to ensure appropriate environmental conditions for servers as components of the data processing system (e.g. control of environmental conditions, specialized air conditioning systems),
- applies organizational solutions to ensure the highest possible degree of protection and confidentiality (training, internal regulations, password policies, etc.),
- has appointed a Data Protection Officer.
-
The hosting company, in order to ensure technical reliability, keeps logs at the server level. The
record may be subject to:
- resources specified by a URL identifier (addresses of the requested resources – pages, files),
- time of arrival of inquiry,
- time to send a response,
- the name of the client station – identification implemented by the HTTP protocol,
- Information about errors that occurred during the execution of HTTP transactions,
- URL address of the page previously visited by the user (referer link) – in case the Service was accessed via a link,
- information about the user’s browser,
- IP address information,
- diagnostic information related to the process of self-ordering services through registrars at ,
- information related to the handling of e-mails addressed to the Operator and sent by Operator.
4. your rights and additional information about how your data will be used
-
In certain situations, the Administrator has the right to transfer your personal data to other recipients, if it will
be necessary to perform the contract concluded with you or to fulfill the obligations of
the Administrator. This applies to such groups of recipients:
- hosting company on a trust basis
- authorized employees and associates who use the data to fulfill the purpose of the site
- companies, providing marketing services to the Administrator
- Your personal data processed by the Administrator for no longer than it is necessary to perform related activities specified by separate regulations (e.g. on accounting). With respect to marketing data, data will not be processed for longer than 3 years.
-
You have the right to request from the Administrator:
- Access to personal data concerning you,
- their correction,
- removals,
- processing restrictions,
- and data portability.
- You have the right to object to the processing indicated in 3.3 c) to processing of personal data for the purpose of carrying out the legitimate interests pursued by the Administrator, including profiling, with the right to object not being exercisable if there are valid legitimate grounds for processing overriding your interests, rights and freedoms, in particular the establishment, assertion or defense of claims.
- The Administrator’s actions may be complained about to the President of the Office for Personal Data Protection, 2 Stawki Street, 00-193 Warsaw.
- Provision of personal data is voluntary, but necessary to operate the Service.
- Automated decision-making activities may be undertaken in relation to you, including profiling for the purpose of providing services under the concluded agreement and for the purpose of direct marketing by the Administrator.
- Personal data is transferred from third countries in terms of data protection regulations. This means that we send it outside the European Union.
5. information in forms
- The service collects information voluntarily provided by the user, including personal data, if provided.
- The service can save information about the connection parameters (time stamp, IP address).
- The site, in some cases, may record information to facilitate linking the data in the form to the e-mail address of the user filling out the form. In this case, the user’s e-mail address appears inside the url of the page containing the form.
- The data provided in the form is processed for the purpose resulting from the function of the specific form, e.g. to perform the process of service request or business contact, registration of services, etc. Each time the context and description of the form clearly informs what it is used for.
6. administrator’s logs
- User behavior information on the site may be subject to logging. This data is used for administration of the site.
7. important marketing techniques
- The operator uses statistical analysis of website traffic, through Google Analytics (Google Inc., based in the USA). The operator does not transmit personal data to operator of this service, but only anonymized information. The service is based on the use of cookies on the user’s terminal device. Regarding the information about user preferences collected by the Google advertising network, the user can view and edit the information resulting from cookies using the following tool: https://www.google.com/ads/preferences/
- The operator uses the Facebook pixel. This technology causes Facebook (Facebook Inc. based in the USA) to know that a person registered with it is using of the Website. In this case, it relies on data in relation to which it is itself a controller; the Operator does not transfer any additional personal data from itself to Facebook. The service is based on the use of cookies on the user’s terminal device.
- The Operator uses remarketing techniques to match advertising messages with the user’s behavior on the site, which may give the illusion that the user’s personal data are used to track the user, but in practice no personal data are transferred from the Operator to advertising operators. A technological prerequisite for such activities is that cookies are enabled.
- The Operator uses a solution that automates the operation of the Website with respect to users, e.g., that can send an email to the user after visiting a specific subpage, provided that the user has agreed to receive commercial correspondence from Operator.
8 Information about cookies
- The website uses cookies.
- Cookies (so-called “cookies”) are IT data, in particular text files, which are stored on the Service User’s terminal device and are intended for use on the website of the Service. Cookies usually contain the name of the website from which they come, the time they are stored on the end device and a unique number.
- The entity placing cookies on the Service User’s terminal equipment and accessing them is the Service operator.
-
Cookies are used for the following purposes:
- maintaining the session of the Service user (after logging in), thanks to which the user does not have to re-enter his/her login and password on each sub-page of the Service;
- to achieve the objectives set forth above under “Important marketing techniques.”
- The Service uses two main types of cookies: “session” (session cookies) and “permanent” (persistent cookies). “Session” cookies are temporary files that are stored on the User’s end device until the User logs out, leaves the website or shuts down the software (web browser). “Permanent” cookies are stored on the User’s final device for the time specified in the parameters of the cookies or until they are deleted by the User.
- Web browsing software (Internet browser) usually allows to store cookies on the User’s terminal device by default. Users of the Website may change settings in this regard. The Internet browser allows deleting cookies. It is also possible to automatically block cookies For details, please refer to the help or documentation of your web browser.
- Restrictions on the use of cookies may affect some of the functionality available on the website of the Service.
- Cookies placed in the Service User’s terminal equipment may also be used by entities cooperating with the Service Operator, in particular this concerns companies: Google (Google Inc. with headquarters in the USA), Facebook (Facebook Inc. with headquarters in the USA), Twitter (Twitter Inc. with headquarters in the USA).
9. cookie management – how to give and withdraw consent in practice?
- If you do not wish to receive cookies, you can change your browser settings. We stipulate that disabling cookies necessary for authentication processes, security, maintenance of user preferences may hinder, and in extreme cases may prevent the use of websites
-
To manage your cookie settings, select the web browser you are using from the list below and
follow the instructions:
Mobile devices: