In compliance with the principles of legality and transparency and in order to provide the information to the interested parties established in articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council, of April 27, 2016, Regarding the protection of natural persons with regard to the processing of personal data, hereinafter RGPD, we inform you of the characteristics of the Personal data processing activities carried out under the responsibility of JMD LAB, SL:
Treatment: (I) Human Resources Management. (II) Attention of applications received through the Web. (III) Preparation and monitoring of Budgets. (IV) Invoicing, accounting and tax management. (V) Administrative management. (VI) Management of medical records. (VII) Attention to the exercise of rights. (VIII) Notification of security breaches when appropriate. (IX) Video surveillance.
Purpose: Purpose: (I) Selection of personnel, training, preparation and sending of paystubs and other documents necessary for the employment relationship. (II) Attention to requests received through the Web. (III) Preparation and monitoring of Budgets. (IV) Preparation of invoices to clients, preparation of official accounting and calculation, presentation and settlement of taxes, preparation of commercial documents, such as balance sheets and reports. (V) Administrative management involving collections and payments and relations with suppliers. (VI) Provision of medical services and treatment. (VII) Handling requests for the exercise of rights related to personal data. (VIII) Notifying data subjects and the Supervisory Authority of security breaches that may affect the rights and freedoms of data subjects. (IX) To ensure the security of persons, property and facilities.
Legitimation: (I) and (III) Application of contractual and pre-contractual measures. (II) Legitimate interest. (IV) Law 58/2003, of 17 December, General Taxation. (V) Legitimate interest. (VI) Law 41/2002, basic law regulating patient autonomy and rights and obligations regarding clinical information and documentation. (VII) and (VIII) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data. (IX) Legitimate Interest.
Retention period: (I) Duration of the employment contract and the period necessary to meet liabilities arising from the provision of employment. (II) The period necessary to comply with the request, as well as for the duration of the liabilities that may arise therefrom. (III) The period of validity of the proposal. (IV) and (V) Six years for commercial purposes, and the period necessary to meet liabilities arising from the settlement of taxes. (VI) Five years after the end of the care process and the period necessary to meet liabilities arising therefrom. (VII) and (VIII) The period necessary for the fulfillment of said purpose,as well as for the duration of the liabilities that may derive therefrom.
Addressees: (VI) Healthcare professionals. (VII) and (VIII) Spanish Data Protection Agency.
Exercise of rights: You may exercise your right of access, rectification, deletion, limitation and opposition to processing, under the terms and conditions established in the personal data protection regulations Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals, with regard to the processing of personal data, by sending a request by email to email@example.com firstname.lastname@example.org or in writing to: Calle México, 10, Arrecife, CP 35500, Las Palmas, indicating in any case the Reference: "Data Protection" together with some document that accredits your identity such as a photocopy of your ID card, as well as to file a complaint with the Spanish Data Protection Agency.
Who is responsible for the processing of your data?
The owner of the dental clinic and of this website is JMD LAB, S.L., and therefore any personal data that you provide through this website or through the data collection forms that you fill out in person will be processed under the responsibility of JMD LAB, S.L.
What personal data do we collect? (How do we obtain them
We will ask you for the minimum data necessary to carry out the purposes indicated in the previous section, normally name and surname, address, contact details to notify you of appointments.
In addition, in relation to your medical history, all the data and health history that we are required by law to request.
How do we use the personal data that we manage under our responsibility?
We use your data for the following purposes:
- Management of the Human Resources of the clinic.
- Administrative management that implies, issuance of appointments and invoicing of clients/patients, collections and payments and relationship with suppliers.
- Provision of laboratory services for clinical analysis and management of clinical documentation.
- Respond to requests to exercise rights related to personal data.
- Surveillance of facilities.
- Impartation of training activities and issuance of training certificates.
- Administrative management of services to third parties (appointments and billing of clients/patients).
- Preparation of labor and Social Security documents.
- Appointment request//information request.
- Preparation of official accounts. Calculation and presentation of tax returns and settlements.
- Web download of analysis and test results.
When the processing of data is imposed by a regulation, this normally incorporates the period during which the data must be processed or stored, thus Law 41/2002 on Patient Autonomy establishes that the period of conservation of clinical documentation must be for a minimum of five years, term after which the information will be eliminated, term after which they will be conveniently anonymized and kept for another 10 years, solely for the purpose of being able to demonstrate the provision of services performed.
Disclosure to third parties
As in the previous cases, the data that we communicate to third parties is always limited to the minimum necessary, so on occasions we communicate patient data to other health professionals, when this is necessary to prepare a complex diagnosis or to complement a treatment with professionals from other specialties. Always under the obligation of professional secrecy.
What security measures do we apply to personal data?
JMD LAB, S.L. has appropriate policies and technical and organizational measures to safeguard and protect your personal data against illegal or unauthorized access, accidental loss or destruction, damage, illegal or unauthorized use and disclosure. The encryption for the data transfer necessary for downloading web results is done through the SSL protocol.
In any case, the user is informed that any data transmission over the Internet is not completely secure and, as such, is done at their own risk. Although we will do our best to protect your personal data, JMD LAB, S.L. cannot guarantee the security of the personal data that you transmit to us through email, by WhatsApp or from the web form, so we ask you to exercise extreme caution and never communicate health data or sensitive information through the Internet or public communication networks, unless it is done in an encrypted way or through private networks.
What are your rights as the owner of the data?
You have the right to request the deletion of your data when, among other reasons, the data is no longer necessary for the purposes for which it was collected. You have the right to obtain confirmation as to whether JMD LAB, S.L. is processing your personal data or not. You have the right to access your personal data and obtain a copy of them, as well as to request the rectification of inaccurate data or, where appropriate, request its deletion when, among other reasons, the data is no longer necessary for the purposes that they were picked up. In certain circumstances, you may request the limitation of the processing of your data, in which case we will only keep them for the exercise or defense of claims. In certain circumstances and for reasons related to your particular situation, you may object to the processing of your data. JMD LAB, S.L., will stop processing the data, except for compelling legitimate reasons, or the exercise or defense of possible claims. Likewise, you can exercise the right to data portability, as well as revoke the consents you have provided. You can exercise these rights by requesting an email addressed to email@example.com or in writing to: Calle México, 10, Arrecife, CP 35500, Las Palmas, attaching a copy of your ID or other document that proves your identity, and clearly indicating the right you want to exercise. Finally, indicate that you can file a claim with the Spanish Data Protection Agency, especially when you have not obtained satisfaction in the exercise of your rights.