Personal Data Protection Policy

Personal Data Protection Policy

Name and Contact Details of the Controller under the GDPR:

SOLOMONIDIS DENTAL CARE M.I.K.E.

DENTAL SERVICES

Venthiri 7, Athens

VAT No. 800822790, Tax Office (DOY) D’ Athens

Tel. 2107796158

The Security and Protection of Your Personal Data

The company SOLOMONIDIS DENTAL CARE M.I.K.E. (hereinafter the “Company”) considers respect for personal data a primary duty and prioritizes the security and protection of your personal data. We are committed to protecting your right to privacy and ensuring that all information you choose to provide us, both during your visit to our premises and on the Company’s website, is collected and used in full compliance with Regulation (EU) 2016/679 of the European Parliament, the applicable national legislation, as well as the Decisions, Guidelines, and Opinions of the competent supervisory Authority (“Applicable Legislation”).

This document contains the Company’s Personal Data Protection Policy and provides any person wishing to receive medical services from the Company, as well as any visitor/user of the Company’s website, with the necessary information about how the Company complies with the applicable legislation for the management and protection of personal data.

The Company unilaterally reserves the right to update, modify, add to, and alter its services and this Policy from time to time, whenever deemed necessary, without prior notice, always within the currently applicable legal framework and in line with any changes in the personal data protection legislation. The Company encourages every interested party to check this Policy at regular intervals to stay informed about any changes made.

What is the purpose of this Policy?

Definitions

This Policy aims to inform you about how the personal data of the Company’s clients and Website visitors are collected, stored, used, and disclosed, the security measures the Company takes to protect personal data, the reasons and duration for which they are stored, and the types of personal data collected.

For the purposes of this Personal Data Protection Policy, the definitions of the General Data Protection Regulation (GDPR) apply. Indicatively:

  • “personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, address, VAT number, contact telephone numbers, etc.,
  • “Special categories of personal data” means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person’s sex life or sexual orientation.
  • “processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
  • “controller” means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

The Company collects and processes your personal data only when absolutely necessary and essential for achieving the intended purposes and in accordance with the terms of this Policy. However, the Company reserves the right, in exceptional cases, to process your personal data to the extent permitted or required by law and/or by court decisions or prosecutorial orders/directives.

How are personal data collected?

Your personal data are collected in the following ways:

(a) you provide them to us when the Company provides medical services to you or to a person you accompany; when you contact us to obtain medical services for yourself or a third party; when you submit a job application to the Company; when you fill in electronic forms or send e-mail to request information about or use the services available on this website.

(b) automatically through the browser or the mobile device you use to access the Website.

(c) they are provided to us by a third-party partner with your consent (e.g., an insurance company).

Where your consent is required for the collection of your personal data—such as to receive a newsletter on a regular basis—this consent is explicitly requested from you and you have the right to withdraw it at any time.

What personal data are collected?

In summary, the personal data collected and further processed include:

– identification and demographic data of patients (i.e., full name, father’s name, mother’s name, date of birth/age, ID card number, passport number, Social Security Number (AMKA), VAT number, occupation or the company/organization where you work, etc.), address and general contact details (including e-mail address and telephone number), yours or your relatives’,

– health data related to medical or nursing services provided by the Company or health data for medical services not provided by us but reported to us either by you or by third parties; these may include, among others, medical and dental history, X-rays, clinical photographs, diagnostic and clinical tests, hospitalization, physicians’ referrals, clinical symptoms, medical staff or/and family or/and previous medical history, medication and treatment, medical opinions and medical findings,

– information you provide for our payment, such as bank card details,

– other information arising from the use of websites and other digital platforms we use to inform you, regarding the following services provided by the Company via its websites or following your registration to one or more of them: indicatively, receiving the newsletter on a regular basis and/or receiving e-mail or announcement/news mailings,

– data of job applicants to our Company contained in attached CVs or related forms (i.e., first name, last name, contact details, education, work experience, etc.), as well as data of our employees such as: first name, last name, father’s name, mother’s name, gender, date of birth, home address, telephone (landline/mobile), e-mail (corporate/personal), nationality, work experience, hire date, payroll details, allowances, evaluation reports, etc.,

– data of the Company’s suppliers and partners, such as full name, father’s name, gender, date of birth, telephone, home address, telephone (landline/mobile), e-mail (corporate/personal), ID card number, passport number, VAT number, Tax Office, IBAN, etc.,

– Beyond the above data you provide to the Company, technical information that constitute personal data may also be collected, such as the Internet Protocol (IP) address of your device [e.g., desktop computer, laptop, tablet, smartphone]. These technical details are used for the smooth operation and performance of the websites and electronic services and are not permanently stored in the Company’s infrastructure. More details about the technologies used on the Company’s websites (cookies, etc.) are provided below.

Which principles govern the Company’s processing of personal data?

The Company processes your personal data lawfully and fairly for clearly defined purposes described in this Policy. The personal data the Company processes are limited to what is strictly necessary to achieve these purposes, are accurate and up to date, are kept for a period determined by the purposes of processing, are protected by adequate security measures, and are not transferred to countries that do not ensure an adequate level of protection.

Note that the Company does not make decisions, nor does it carry out profiling, based on automated processing of your personal data.

How are my personal data collected and used?

The collection of personal data is carried out both by physical and electronic means, as the case may be, including: at the reception and service points of the Company’s premises; when completing various forms or during our electronic communication; when using our call center or website to schedule a visit or receive other medical or non-medical services; when you declare your intention to use your insurance policy,

Specifically, the collection of personal data through the Company’s Website takes place in the following cases:

– When you request information about the health services provided by the Company through the Website.
– When you register and request to receive the Company’s e-mail or announcement/news mailings.
– Through the use of “Cookies” or similar technologies (see further details below).

Who collects personal data and for what purpose? Are they disclosed to third parties?

Personal data are collected and processed by the Company’s employees authorized for each service, solely for the purposes of providing that service.

Upon your instruction, your personal data may also be transmitted to third parties (e.g., another physician of your choice) / businesses cooperating with the Company (e.g., insurance companies with which you have a contract).

The Company undertakes not to trade your personal data by selling/renting, giving/transferring/publishing, or disclosing them to third parties, nor to use them in any other way and for purposes that could jeopardize your privacy, rights, or freedoms, unless required by law, court decision/order, administrative act, or where it constitutes a contractual obligation necessary for the proper functioning of the Company’s Websites and the performance of their functions.

Furthermore, personal data may be transferred to third parties contractually bound to the Company, such as partner physicians and collaborating diagnostic centers, as well as to third parties to whom the Company has assigned the processing of personal data on its behalf. In particular, it may transfer your personal data to partners acting on its behalf, contractually bound to the Company, and/or to third-party cooperating companies that process your personal data on behalf of the Company for the purpose of providing services, indicatively for the evaluation and improvement of website functionality, marketing purposes, data management, and technical support.

In any case, third parties to whom your data may be transferred undertake to comply with the Terms of this Policy, ensuring the duty of confidentiality as well as all obligations provided for by the Applicable Legislation.

Your personal data may also be transferred to your public insurance fund/carrier when you make use of it, and

To private insurance companies, only on the condition that your prior explicit consent has been provided before such transfer.

If the transfer concerns a country outside the European Union (EU) or the European Economic Area (EEA), the Company checks whether: the Commission has issued an adequacy decision or an equivalent decision for the third country to which the transfer will be made. In any case, appropriate safeguards are maintained in accordance with the Applicable Legislation for the transfer of such data.

What are my rights? What can I do if I have an issue with the processing of my personal data?

The Company ensures it can promptly respond to requests to exercise your rights under the Applicable Legislation. These rights are as follows:

  1. right of access, i.e., the right to be informed about your personal data kept in the Company’s records and to obtain copies,
  2. right to rectification, i.e., the right to request the correction of inaccuracies and errors in your personal data kept in the Company’s records,

iii. right to erasure, i.e., the right to request that your personal data kept in the Company’s records be deleted or cease to be used, subject to the specific limitations provided for in the GDPR,

  1. right to restriction of processing of your personal data, again provided the conditions set out in the GDPR are met,
  2. right to data portability, i.e., the right to request that the clinic directly transfer the personal data concerning you to the organization you indicate, provided they are in a structured format, in accordance with the relevant legislation, and
  3. right to object to the processing of your personal data, unless there are compelling and legitimate grounds for the processing which override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims of our Company.
  4. v. You also have the right to withdraw consent: In cases where processing is based solely on your prior consent, e.g., for marketing activities, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Specifically, regarding the newsletter service, you can unsubscribe by following the instructions included in each newsletter, so that the processing of personal data related to this service stops.

For any matter regarding your personal data and/or clarifications, as well as to exercise the above rights, you may contact the Company via e-mail at [email protected]
or by fax at 2107796158. Every request submitted must be accompanied by appropriate identification documents and provide the necessary information (e.g., the data needing correction), as described in the terms of use of each service. The Company may request additional information necessary to confirm your identity.

The Company makes every effort to respond to your requests without delay and, in any case, within one month of receipt. This period may be extended by two (2) further months if necessary, taking into account the complexity of the request and the number of requests. You will be informed of any such extension and the reasons for the delay within one month from receipt of the request by the Company. If you submit the request by electronic means, the response will be provided to you, if possible, by electronic means, unless you request otherwise (e.g., a written letter).

In any case, if you believe your rights have been violated, you have the right to contact the competent Data Protection Authority (www.dpa.gr
) and/or to seek judicial remedy.

The competent supervisory authority for Greece is the Hellenic Data Protection Authority, Kifisias 1–3, 115 23, Athens, https://www.dpa.gr/
, tel. 2106475600.

Are my data secure?

The Company considers the privacy of individuals whose personal data it processes—whether customers, employees, or third parties—extremely important and makes every effort to protect it, both in terms of the confidentiality/secrecy of information and its integrity (not to be altered, not to be accidentally destroyed, etc.). In this context, the Company implements an Information Security Management System that follows best practices of international personal data protection standards.

The Company takes all appropriate organizational and technical measures designed to protect information from loss, misuse, unauthorized access, disclosure, distortion, or destruction and ensures the lawful and legitimate collection and processing of personal data as well as their secure retention in accordance with the relevant provisions of Greek, EU, and international law regarding the protection of individuals from the processing of personal data, as well as the decisions of the Hellenic Data Protection Authority, safeguarding the confidentiality and secrecy of any information that comes to its knowledge. In particular, this Policy fully takes into account the provisions and articles of Regulation (EU) 2016/679 of the European Parliament on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation – GDPR), and all relevant applicable European and national legislation, and continuously makes every effort to comply with it.

Access to the contact details of visitors/users of the Company’s Websites is limited to authorized persons bound by confidentiality—employees, service providers—and reasonably deemed to need to know such details to provide products or services to the visitors/users of the Websites or to perform their work.

The Company expressly prohibits within its premises the use by staff and partners of photo cameras, video cameras, as well as the use of the photography and video functions of mobile phones, unless the visitor has consented to this and for specific processing purposes, such as posting a photo or video on the Website/social media following the visitor’s explicit consent.

What is the purpose of collecting and processing personal data?

The collection and processing of personal data aim at:

– Providing health services, i.e., scheduling the medical appointment and/or—following prior identification of examinees—providing medical services and health care in general; sending/delivering your medical test results to you; maintaining and updating your medical record, etc. Regarding the processing of special categories of data, i.e., sensitive data (health data), processing is necessary for the purposes of preventive medicine, diagnosis, provision of health care, or treatment. The legal bases for processing these data are: (a) the necessity of processing your data for preventive or occupational medicine, medical diagnosis, or treatment, or under a contract with a health professional, and (b) the necessity of processing to comply with obligations and exercise specific rights of ours or yours in the field of social security law, or to perform a task carried out in the public interest, (c) the necessity of processing your data to protect your vital interests or those of the person you accompany, (d) the necessity of processing your data for the establishment, exercise, or defense of rights and legal claims in cases related to medical liability and the provision of health services in general, (e) the necessity of processing data for reasons of public interest in the field of public health.

We will never process your medical data if none of the above legal bases exists or unless we have previously obtained your explicit consent where required by the Applicable Legislation and after first informing you of the specific purpose of processing. If you use a public insurance fund/carrier, certain personal data will be processed on the legal basis of the necessity of processing for the provision of health or social care, as well as the necessity of processing to comply with obligations and exercise specific rights of yours in the field of social security law or to perform a task carried out in the public interest.

– Personalized information regarding the provision of health services by us according to the user’s preferences and characteristics; sending newsletters about the Company’s news; meeting user requests; and direct communication to inform you about new health services of the Company. The legal basis for processing in this case is your prior explicit consent.

– The lawful conclusion and performance of contracts that the Company enters into with third parties. The legal basis for processing in this case is the necessity of processing your data in the context of performing our contractual obligation or at the pre-contractual stage.

– Verifying the truthfulness and accuracy of the user’s details to prevent and detect fraud, in which case the legal basis is the Company’s legitimate interest.

– Statistical analysis of traffic and use of the Company’s websites, with the user’s consent and regarding the cookies policy.

How long do we retain your personal data?

Personal data collected by the Company are kept for a predetermined and limited period, depending on the purpose of processing, after which the data are deleted and/or securely destroyed, unless a different retention period is provided or permitted by the applicable law. The retention period of your data is indicatively defined based on certain specific criteria and depending on the case. Indicatively:

(a) Your personal data are mandatorily kept for the entire duration required by the purpose of their processing and/or the applicable legal framework. Upon the expiry of this period, the data are kept in accordance with the applicable institutional framework for the period provided from the end of the transactional relationship or for as long as necessary to defend the Company’s rights before a Court or other competent Authority.

(b) When processing is imposed as an obligation by provisions of the applicable legal framework, your personal data will be stored for at least as long as the relevant provisions require (indicatively, according to the Code of Medical Ethics Law 3418/2005).

(c) In any other case where processing is based on your consent, your personal data are kept until you withdraw your consent, without affecting the lawfulness of processing based on consent before its withdrawal. To withdraw consent, you must submit a request to the Company. Alternatively, and for the purposes of promoting the Company’s products and services, you can also use the unsubscribe options by following the relevant link included in our electronic communications. For as long as your e-mail address remains in our database, you may receive periodic newsletters from us.

What applies on the Company’s Website regarding children’s personal data?

The Company undertakes not to process personal data from patients/users of its Website under sixteen (16) years of age without first obtaining the consent of the person who has parental responsibility for the child (parent or guardian), through direct communication, outside an electronic connection or via the internet. The Company will request proof of the relationship between the holder of parental responsibility and the child and, if this is provided, you may (according to applicable law) request the deletion of the child’s personal data. The Company further undertakes that no information campaigns via social media are directed at minors (under 18 years of age).

What are Cookies and how are they used on our Website?

The Company’s website uses cookies to improve visitors’ browsing experience, analyze traffic, and provide personalized content. Cookies are small text files stored on your device when you visit our website.

Upon your first visit to the website, a cookie banner appears informing you about the use of cookies and giving you the option to accept or reject non-essential cookies. You also have the option to manage your preferences by cookie category (e.g., functional, statistical, preferences) through the banner and/or your browser settings. For more information, please see our Policy regarding our use of Cookies at the following link […].’

What applies with respect to links to other websites?

The Company’s Websites may contain references via hyperlinks to other websites, for the content and services of which the Company bears no responsibility, nor does it guarantee their continuous and secure accessibility. Under no circumstances should the Company be considered to accept or adopt the content or services of the linked websites or to be connected to them in any way. For any issue that may arise when using such websites, the owner of that website is solely responsible. In the case of hyperlinks to other websites, the Company is not responsible for the data management and protection terms they follow. We use social media to present the Company’s work and services through widely used, modern channels. The Company’s use of social media is specifically indicated on our Websites. For example, you can watch informative videos by healthcare professionals who staff the Company’s clinics, which we post on our YouTube page, and follow (from our Websites) our links on Twitter and LinkedIn.

The Company strongly encourages users to consult each third party’s respective policy (e.g., search engine service providers, social media service providers such as Facebook, LinkedIn, Twitter, etc.) to be informed about the practices they follow to protect their personal data.

What is SSL Encryption?

This website uses SSL encryption for security reasons and to protect the secure transmission of sensitive information, such as queries you send to the Company as the Website Administrator. You can recognize the encrypted connection when the address in the browser changes from “http://” to “https://” and the padlock symbol appears in the browser bar. When SSL encryption is activated, the information you send us is not visible to third parties.

Date of last update of the Policy:

26.05.2025

Name and contact details of the person responsible in accordance with GDPR legislation:

SOLOMONIDIS
ATHENIC MULTI-DENTAL DENTAL SHOP
Konstantinou Ventiri 7 – Athens - Postal Code 11528

Tax Identification Number 000000000 – Tax Office Athens
Tel. 210 77 96 158 | [email protected]
G.E.MI. No.: 000000000000

Security and Protection of your Personal Data

SOLOMONIDIS (hereinafter referred to as “the Company”) considers respect for personal data as its primary duty and has as a priority the security and protection of your personal data. We are committed to protecting your right to privacy and will ensure that any information you choose to provide us with when you visit this Company website is collected and used in full compliance with Regulation (EU) 2016/679 of the European Parliament.

This document contains the Company’s privacy policy and provides any person interested in receiving medical services from the Company, as well as any visitor/user of the Company’s website with the necessary information on the ways in which the Company complies with the European Union legislation on the management and protection of personal data. You can access this notice from the bottom of each page of this website by clicking on the appropriate link. Any changes that occur will be published in this section.

What is the purpose of this Policy?

The purpose of this Policy is to provide information on how the personal data of persons receiving the Company’s services are collected, stored, used and transmitted, the security measures taken by the Company for the protection of personal data, the reasons and the period for which they are stored, as well as the type of personal data collected. It concerns any operation or series of operations performed, with or without the use of automated means, on personal data or on sets of personal data, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or any other form of making available, association or combination, restriction, erasure or destruction. The Company unilaterally reserves the right to update, modify, add, change its services and this Policy, from time to time, whenever it deems it necessary, without prior notice, always within the legal framework in force and in accordance with any changes in the applicable legislation on personal data protection. The Company encourages all interested parties to check this Policy periodically to be informed of any changes that have taken place.

What is personal data?

Personal data is any information relating to a specific natural person or a person whose identity can be verified (e.g. name, ID number, address, etc.). Data relating to health (physical or mental condition, receipt of medical services, etc.) are included in the general term personal data but constitute a special category of data. The Company will not process your personal data without your consent. However, the Company reserves the right, in exceptional cases, to process your personal data to the extent permitted or required by law, and/or by court decisions or prosecution orders/orders.

How is personal data collected?

Your personal data is collected in the following ways:

(a) you provide it to us when the Company provides medical services to you or a person you are accompanying, when you contact us to obtain medical services for you or a third party, when you apply for employment with the Company, when you fill out online forms or send an email (“e-mail”) in order to obtain information about or use the services available on this website.

(b) automatically through the browser or mobile device you use to access the Website.

(c) provided to us by a third party partner after you have given your consent (e.g. an insurance company).

In cases where your consent is required for the collection of your personal data, such as for receiving a newsletter on a regular basis, it is explicitly requested from you and you have the right to withdraw it at any time.

What personal data is collected?

In summary, the personal data collected and further processed include: your name, address and general contact details (including email address and telephone number), yours or your relatives’, health data relating to medical or nursing services provided by the Company or health data for medical services not provided by us but referred to us either by you or by third parties information you give us for our payment, such as Receiving a newsletter on a regular basis. Receiving e-mail or news/announcement mailings Managing your medical records if you have received services from our Company. Entering health data and receiving information. Submitting queries in relation to services related to Medical Tourism. In addition to the above data that you provide to the Group, technical information that constitutes personal data may be collected, such as, for example, the Internet Protocol address (“IP address”) of your device [e.g. computer, laptop, tablet, smart mobile phone (“smartphone”)]. This technical information is used for the smooth operation and performance of the websites and online services, and is not permanently stored in the Company’s infrastructure. Further details on the technologies used on the Company’s websites (“cookies” etc.) are set out in the Company’s Privacy Policy.

What principles govern the processing of personal data by the Company?

The Company processes your personal data in a fair and lawful manner for clearly defined purposes set out in this Policy. Your personal data processed by the Company is limited to what is strictly necessary to achieve these purposes, is accurate and up-to-date, is kept for a period of time determined by the purposes of processing, is protected by adequate security measures and is not transferred to countries that do not ensure a satisfactory level of protection.

Who collects the personal data and for what purpose? Are they passed on to third parties?

Personal data is collected and processed by the Company’s employees authorized by the service, for the purposes of providing the service in question. They are disclosed only to authorized third parties who are bound to confidentiality, when they are required to have access in the context of providing the services in question (e.g. doctors for diagnostic purposes).

At your request, your personal data may be transferred to third parties (e.g. another doctor of your choice) / companies cooperating with the Company (e.g. insurance companies you have contracted with).

The Company undertakes that it will not trade your personal data by making them available for sale/rent by giving them/transferring/publishing or disclosing them to third parties or use them in any other way and for other purposes that may compromise privacy, your rights or freedoms, unless it is required by law, a court decision / order, an administrative act or if it is a contractual obligation necessary for the proper functioning of the Company’s Websites and the realization of their functions.

Personal data may be transferred to partners or third parties, who comply with the terms of this Policy and are committed to confidentiality, who act on behalf of the Company for further processing for the purpose of providing services, evaluating and improving the functionality of the website, marketing purposes, data management and technical support, only after the user has been informed in advance and his/her consent has been obtained.These third parties have been contractually bound to the Company.

For how long is my personal data kept?

Your personal data are kept for as long as required by the nature of the service provided by the Company that you have chosen and, in addition, for as long as the relevant legislation determines.

What are my rights? What can I do if I have an issue with the processing of my personal data?

You have the right to ask us at any time what personal data we process, for what purposes we do so, whether we provide it to third parties and to whom, and other relevant information. You also have the right to receive a copy of your personal data free of charge at your request.

Other rights you have under the relevant legislation on personal data protection include the right to request the updating and/or correction of your data, the cessation and/or restriction of their processing and their deletion from the Company’s systems, unless there is no other legal obligation to retain them. You also retain the right to portability and/or to object to the processing of your personal data. In particular, with regard to the newsletter service, it is possible to unsubscribe by following the instructions included in each newsletter in order to stop the processing of personal data related to this service.You can exercise all the above rights by submitting a request in writing to [email protected]/solomonidis.

For any issue you may have regarding your personal data and/or for clarifications, you can contact the Company’s Data Protection Officer via e-mail, at [email protected]/solomonidis or by fax at 210 440 5055. In any case, you have the right to contact the competent Authority for the Protection of Personal Data (DPAA, www.dpa.gr) and/or to take legal action. Any request submitted must be accompanied by appropriate proof of identification and the required information (e.g. the data that need to be corrected) must be provided, as described in the terms of use of the service in question. The Company may request additional information necessary to confirm your identity.

The Company makes every effort to respond to your requests without delay and in any case within one month of receipt. This deadline may be extended by two (2) more months, if necessary, taking into account the complexity of the request and the number of requests. You will be informed of such extension and the reasons for the delay within one month of receipt of the request by the Company. If you submit the request by electronic means, the response will be provided to you, if possible, by electronic means, unless you request otherwise (e.g. a written letter).

In any case, you may address the Company’s Data Protection Officer, the Personal Data Protection Authority (PDPA) and/or take legal action if you believe that your above rights have been violated.

Is my data safe?

The Company considers the privacy of the persons whose personal data it processes, whether they are its customers, employees or third parties, to be of utmost importance and makes every effort to protect them, both in terms of confidentiality/secrecy of the information and its integrity (not to be altered, not to be accidentally destroyed, etc.). In this context, the Company implements an Information Security Management System, which follows the best practices of international standards of personal data protection.

The Company takes all appropriate organizational and technical measures designed to protect the information from loss, misuse, unauthorized access, disclosure, distortion or destruction and ensures the legitimate and lawful collection and processing of personal data as well as their safe keeping in accordance with the relevant provisions of Greek, Community and international law on the protection of individuals with regard to the processing of personal data, as well as the decisions of the Greek Data Protection Authority. In particular, this Policy takes full account of the provisions and articles of Regulation (EU) 2016/679 of the European Parliament on the protection of individuals with regard to the processing of personal data and on the free movement of data (“General Data Protection Regulation” – “GDPR”) and continuously makes every effort to comply with it.

Access to the contact details of visitors/users of the Company’s Websites is limited to authorized persons who are bound to confidentiality (employees, service providers) and are reasonably considered to need to know these details for the provision of products or services to visitors/users of the Websites or for the performance of their work.

The company expressly prohibits the use of cameras, video cameras and the use of the photography and video recording functions of mobile phones by its staff and partners within the company’s work areas.

How is my personal data collected and used on the Website?

The collection of personal data on this Company’s Website is carried out in the following cases:

When you request information about the health services provided by the Company through the Website. When you register and request to receive emails or news/announcement mailings from the Company. By using “Cookies” or similar technologies (see next question below for more details).

The personal data collected on a case-by-case basis include, but are not limited to:

  • Receive a newsletter on a regular basis: e-mail address.
  • Management of the medical records of patients who have received health services from the Company: all personal data contained in the medical records, including health data, medical test results, medical opinions, financial data, etc.
  • Entering health data and receiving information: medical history, contact details [e-mail address, postal address, telephone number, etc.].
  • Submit queries in relation to health services related to Medical Tourism: name, age, health/medical history, contact details [e-mail address, postal address, telephone number, etc.].
  • Monitoring the smooth operation and improving the functionality and performance of websites: internet protocol address (“Internet Protocol address”), browsing patterns, information about the use of a website, browser history, geolocation data, HTTP protocol data, etc. This data is kept in an aggregated form so that users cannot be identified as far as possible.

The collection and processing of personal data is for the sole purpose of:

  • personalised information and service provision,
  • the provision of health services according to the user’s preferences and characteristics,
  • contacting the user to remind him/her of the scheduled receipt of services from the Company
  • confirming the truth and accuracy of the user’s data in order to avoid and detect fraud
  • the statistical analysis of the traffic and use of the Company’s websites,
  • the satisfaction of users’ requirements and direct communication in order to inform them about new health services of the Company (provided that the users have given their consent).

Further transmission to third party partners will be done upon request of the visitors/users themselves. The user’s consent is explicitly requested after being informed of the purposes and legal basis for the use of personal data and is a basic condition for any processing or transfer of the user’s personal data.

What are Cookies & internet tags?

Cookies are small text files (bits) containing information stored in the browser of the visitor’s/user’s computer while browsing the Website and can be removed at any time and do not have access to any file document on the computer. The Company’s Websites use cookies for the following purposes:

  • For the smooth operation of the Websites, with the required speed.
  • To identify the device you use to browse the Website, the browser and/or the operating system you use, in order to provide a personalized browsing experience and/or use of the Company’s Websites.
  • To save your settings during a visit or between visits (such as your registered username, your preferred language or your social media usage), so that you can avoid having to re-enter certain data.
  • To improve the performance and/or security of the Website.
  • To provide content based on your interests and needs.
  • To analyse how you browse and/or use the Website.

The Company does NOT use cookies in the following cases:

  • To collect personal data without your consent.
  • For the transmission of your data to advertising companies.
  • To transfer your data to third parties without your consent.

The types of cookies used by the Company’s Websites are “persistent cookies” and “session cookies”. Also, some third-party services enabled on the Sites, such as “social media buttons”, place their own cookies on your computer, which are not under the control of the Company’s Site administrators.

The session cookies used by the Company’s Websites are deleted after the end of your browsing and/or after closing the browser. Persistent cookies remain on your computer or other device until you delete them or until the interval specified in the cookie. You can configure the server (browser) you use in such a way that it either warns you about the use of cookies in certain services of the Sites or does not allow the acceptance of the use of cookies in any case. More information about the general use of cookies and the methods of blocking or restricting them can be found at http://cookiepedia.co.uk/all-aboutcookies and http://www.allaboutcookies.org/.

You can also delete cookies from your computer or device at any time you want. However, please note that by not accepting cookies or some of them, some of the features of a website may not be fully available.

The Company’s Websites also use “internet tags”. This method is used to measure the response of visitors to the Websites. The Company assures that, through the use of “internet tags” and cookies, no personally identifiable information about visitors to the Website, such as names, addresses, email addresses or telephone numbers, is collected or sought.

What applies to the Company’s Website regarding children’s personal data?

The Company undertakes that it will not process personal data of visitors/users of its Website under the age of sixteen (16) without having previously obtained the consent of the person having parental responsibility of the child (parent or guardian), through direct communication, offline or via the Internet. The Company will ask for practical proof of the relationship between the person having parental responsibility and the child and if this happens, you may (in accordance with applicable law) request that the child’s personal data be deleted. The Company further undertakes that no information campaign via social networking sites is directed at minors (under 18 years of age).

What about links to other websites?

The Company’s Websites may contain hyperlinks to other websites, for the content and services of which the Company bears no responsibility, nor does it guarantee their permanent and safe accessibility. The Company shall under no circumstances be deemed to accept or adopt the content or services of the hyperlink websites or to be associated with them in any way. For any problem that may arise during the use of the aforementioned websites, the respective owner of the website is solely responsible. In the case of hyperlinks to other websites, the Company is not responsible for the terms of management and protection of personal data that they follow. We use social media to present the Company’s work and services through widely used and modern channels. The Company’s use of social media is specifically highlighted on our Websites. For example, you can watch informative videos of health scientists staffing our Company’s clinics, which we post on our personal “YouTube” page, and follow (from our Websites) our Twitter and LinkedIn links.

The Company strongly urges users to consult the respective policy of each third party (e.g. search engine service providers, social media service providers such as Facebook, Linkedin, Twitter, etc.) in order to be informed about the practices they follow in order to protect their personal data.

What is SSL Encryption?

This website uses SSL encryption for security reasons and to protect the secure transmission of sensitive information, such as queries sent to the Company in its capacity as the Website Administrator. You can recognize the connection under encryption when the address in the browser changes from “http://” to “https://” and the lock symbol appears in the browser bar. When SSL encryption is enabled, the information you send us is not visible to third parties.

Scroll to Top
Call Now Button