PERSONAL DATA PRIVACY STATEMENT
Welcome to Lifecheck. Thank you for trusting us with the protection of your health. Our primary concern is to serve you promptly, reliably, and responsibly.
In order to provide our services to you properly, we collect and use information about you. Lifecheck is committed to protecting and respecting your privacy. This Privacy Statement describes your rights in relation to the personal data we process, as well as the measures we take to safeguard your privacy. Please read this Statement carefully in order to be informed of your rights. A table of contents follows, allowing you to navigate directly to the sections of interest to you.
Table of Contents
- Clarifications regarding certain key terms
- What types of personal data does the Company collect and process about you?
- For what purposes do we use your personal data?
- What does the legislation say about this?
- Are you required to provide us with the personal data we request?
- Is your data processed without any human intervention?
- How long do we retain your data?
- Do we disclose your data to third parties?
- Do we transfer your data outside the European Union?
- What are your rights?
Monitoring
- What applies in the event of changes to this Statement?
Clarifications regarding certain key terms
First, we would like to clarify how certain terms are used in this Statement.
Although it may seem self-evident, for the purposes of this Statement you will be referred to as “You”. By the terms “we” or “the Company” we mean Lifecheck. Our registered office is located at 163 Mesogeion Avenue, Athens. Our services (hereinafter referred to as “our Services”) concern the provision of primary healthcare medical services (laboratory and clinical examinations).
For the purposes of our Services, we use various IT information systems. In certain cases, we provide our customers with special applications to facilitate their service (Website / “Site”). The application allows you to be informed about the services provided by the Company, the insurance funds we serve, as well as the Company’s medical laboratories, so that you may choose the one that best suits your needs.
Finally, this Statement concerns the management of information that identifies individuals, such as you and your family. Such information includes, indicatively, identification details, demographic data, insurance fund information, and medical data. This type of information is commonly referred to as “Personal Information” or “Personally Identifiable Information”. In this Statement, we use the term “Personal Data.”
What types of personal data does the Company collect and process about you?
The personal data that the Company typically collects about you include, indicatively:
- Full name, father’s name, age, gender, residential address, spouse’s name, telephone number, ID card number, AMA, AMKA, email address, insurance fund, medical history.
In certain cases, when you communicate with us, we may keep records of such communications.
- Results of laboratory examinations.
For what purposes do we use your personal data?
The Company collects and processes personal data for the following purposes:
- To perform laboratory examinations
- To issue the results of the examinations performed
- To inform insurance funds of the services provided to you
- To collect fees for the services provided
- To develop and improve its systems and procedures. This mainly occurs in the context of using new IT systems and procedures, where information collected about you may be used as test data to verify the proper functioning of such systems, in cases where anonymized data cannot adequately replace real operational data
- To disclose data to third parties (see below)
- To comply with its obligations under applicable legislation, where required
- To fulfill its obligations as an employer towards you, in the event that you are an employee of the Company
Additionally, in the context of employee recruitment and employment:
- To comply with contractual obligations arising from employment or service agreements, as well as any other agreements or rules governing the contractual relationship with employees
- For human resources management purposes (e.g. absence management, training)
- For security and protection of persons, facilities, systems, and assets
- For monitoring compliance with internal policies and procedures
- For the management of communications and other systems used by Lifecheck (including internal contact databases)
- For the investigation and response to incidents and complaints
- For compliance with our obligations and rights and for cooperation with police, governmental, or supervisory authorities during investigations.
What does the legislation say about this?
In order to process your data, we must rely on one of the lawful bases provided by applicable legislation.
For individuals employed by or cooperating with the Company, data processing for these purposes is carried out on lawful bases such as the performance of a contract to which the data subject is a party (purposes 1 and 5–7), compliance with legal or regulatory obligations (purposes 5–7), and/or the legitimate interests of the Company in exercising its rights and conducting its activities in a manner that does not unjustifiably affect your interests, fundamental rights, or freedoms (purposes 1–4 and 7).
Where processing is necessary for the protection of the Company’s legitimate interests, we ensure that such processing is conducted in a manner whereby our legitimate interests prevail over any individual interests of data subjects. Outside the scope of the above purposes, we will process your personal data only on the basis of your consent (which constitutes an additional lawful basis for processing).
Are you required to provide us with the personal data we request?
It is necessary for you to provide us with your data in order for us to be able to offer you the services you request. This means that you are required to provide your personal data.
If you do not provide your data, we may not be able to enter into a contractual relationship with you or provide you with our services.
Is your data processed without any human intervention?
Yes. The Company may use automated systems and procedures in order to provide customers with the services requested.
How long do we retain your data?
The Company may (and in certain cases, depending on the type of information, is required to) retain your data for several years following the completion of the service provided. In general, we retain your personal data and laboratory examination results for ten (10) years, in accordance with Greek legislation.
Do we disclose your data to third parties?
As mentioned above, we disclose your data to third parties as follows:
- To insurance funds
- To external partners. For example, we may cooperate with a supplier who undertakes laboratory examinations not performed within our Company. Our supplier(s) are subject to contractual and other legal obligations to maintain the confidentiality of your data and respect your privacy and will have access only to the data necessary for the performance of their tasks. This also includes companies providing financial support and accounting services (which may require details regarding employees or independent contractors for invoicing and receivables processing), and/or human resources service providers performing payroll services
- To governmental, police, supervisory, and other competent authorities, where, at our sole discretion, we have a legal obligation or right to make such disclosure or consider it reasonable and prudent to do so
- In the context of due diligence procedures related to mergers, acquisitions, or other business transactions, where it may be necessary to disclose your data to a prospective buyer or seller and their advisors.
Do we transfer your data outside the European Union?
We do not transfer personal data outside the European Union.
What are your rights?
Right of access and to obtain copies of your personal data
You have the right to request confirmation as to whether we process your personal data. In such cases, you may access certain data (via a relevant application) and information regarding how your data are processed. In some cases, you may request that we provide you with an electronic copy of your data.
Right to rectification
If you are able to demonstrate that the data we hold about you are inaccurate, you may request that such data be updated or corrected.
Right to erasure (“right to be forgotten”)
In certain cases, you have the right to request the restriction of processing and/or the deletion of your data. You may submit such a request at any time, and the Company will assess whether it can be accepted, subject to other lawful rights or obligations we may have regarding data retention. Where, under the law, your request for deletion must be accepted, the Company will proceed with deletion without undue delay. Please note that once your data are deleted, the Company will no longer be able to provide services to you. If you wish to re-register, you will be required to resubmit your data.
Right to object
To the extent that processing of your data is based on the legitimate interest of the Company (and not on other lawful bases) or relates to direct marketing purposes, you have the right to object to such processing by specifying the particular circumstances of your case.
To exercise your rights, please send an email to [email protected].
If you contact us by email to exercise your rights, the Company may request identification details before processing your request.
Finally, you have the right to lodge a complaint with the competent Hellenic Data Protection Authority if you believe that an issue has arisen in relation to your data.
Monitoring
To the extent permitted by applicable legislation, the Company reserves the right to audit, monitor, and record access to, use of, and content of data stored or processed in our IT systems. This is done for the purposes outlined above, and we emphasize this specifically so that you are aware that your activities on our IT systems may be monitored by authorized persons.
How can you contact us?
If you have any questions or concerns regarding this Statement, if you would like additional information about the protection of your data, and/or if you wish to contact Lifecheck’s Data Protection Officer (DPO), please send an email to [email protected].
What applies in the event of changes to this Statement?
The terms of this Statement may be amended from time to time. Any significant changes will be announced through appropriate notifications on this website or via other available communication channels.
