INTRODUCTION AND APPLICABILITY OF THIS PRIVACY POLICY
These Personal Data Processing Terms (hereinafter the “Privacy Policy”) apply whenever Selus Kliinik OÜ (hereinafter the “Clinic”) processes the personal data of natural persons (hereinafter the “Data Subject”) as the data controller in connection with the provision of healthcare services to patients, as well as in connection with the provision of any other services in the course of its business activities to other recipients of such services (hereinafter collectively referred to as the “Patient”). This Privacy Policy also applies where a Data Subject applies for employment with the Clinic or where the Clinic actively seeks to recruit a new employee.
This Privacy Policy describes the principles and rules governing the Clinic’s processing of the personal data of Data Subjects (including Patients). The protection of personal data is of utmost importance to the Clinic. The Clinic asks all Data Subjects to read this Privacy Policy carefully and to contact the Clinic if they have any questions (see the contact details in Section 2).
Personal data is processed in accordance with the applicable legislation of the Republic of Estonia, the provisions of the General Data Protection Regulation (EU) 2016/679 (hereinafter the “GDPR”), and the Clinic’s internal data processing policies adopted pursuant to applicable law. In addition, the Clinic processes personal data in accordance with the requirements of the Health Services Organisation Act (hereinafter the “HSOA”).
The terms used in this Privacy Policy (such as controller, personal data, processing, etc.) shall have the meanings assigned to them in the GDPR and other applicable legislation.
This Privacy Policy is effective from the date indicated above. The Clinic reserves the right to amend this Privacy Policy unilaterally. Data Subjects will be informed of any amendments by email or by publishing the updated Privacy Policy on the Clinic’s website. In any event, the Clinic recommends that Data Subjects visit this page periodically to review any updates to the Privacy Policy.
Where this Privacy Policy is available in more than one language, the Estonian-language version shall prevail in the event of any discrepancies or inconsistencies.
DATA CONTROLLER
For the purposes set out in this Privacy Policy, the controller of personal data is Selus Kliinik OÜ (the “Clinic”), registered under registry code 17517210, with its registered address at Narva mnt 7b, Kesklinna linnaosa, 10117 Tallinn, Harju County, Estonia.
The Clinic’s website is available at www.seluskliinik.ee (hereinafter the “Website”).
If you have any questions regarding the processing of your personal data, you may contact the Clinic’s Data Protection Specialist by email at info@seluskliinik.ee.
Here’s a professional legal English translation suitable for a GDPR-compliant privacy notice:
PURPOSES OF PROCESSING PERSONAL DATA, CATEGORIES OF PERSONAL DATA, LEGAL BASES AND RETENTION PERIODS
The Clinic processes personal data only for specified purposes and in accordance with applicable legislation. The following provides an overview of the purposes for which the Clinic processes personal data, i.e. why the Clinic processes personal data. For each purpose, this Privacy Notice describes whose personal data are processed, what categories of personal data are processed, and the legal basis for the processing under the applicable legislation.
Planning of Healthcare Services and Other Services
Processing for this purpose includes activities related to the planning and preparation of healthcare services and other services, such as appointment booking, preparation for appointments, and communication in connection with the preparation of healthcare or other services, including the provision of organisational information and similar communications.
For this purpose, the Clinic primarily processes the following personal data relating to the Patient:
- the Patient’s name, personal identification code (or date of birth), email address and telephone number;
- the type of service being booked (e.g. psychiatric services, psychological services, occupational therapy services, diagnostic examinations, psychedelic therapy services, etc.), and, where applicable, the relevant subtype of the service;
- any notes provided by the Patient or the person making the booking, including the reason for the booking, which may also include the reason why the Patient wishes to receive the service;
- information relating to the appointment booking, including the date, time, location and details of the appointment;
- health-related information where its processing is necessary for the preparation of the appointment.
Where a service is booked by a person other than the Patient, the Clinic also processes the booker’s name, personal identification code (or date of birth), email address and telephone number.
Where the Clinic processes personal data for activities preceding the provision of healthcare services, the legal basis for processing is § 41(1)(2) of the Health Services Organisation Act (TTKS). Where an individual requests a service other than a healthcare service, the legal basis for processing is Article 6(1)(b) of the General Data Protection Regulation (GDPR), namely processing necessary to take steps at the request of the data subject prior to entering into a contract.
Provision of Healthcare Services or Other Services
Processing for this purpose includes activities such as diagnosing and treating the Patient, communicating in connection with the provision of healthcare services, providing follow-up care and monitoring, and carrying out other related activities.
Provision of Healthcare Services or Other Services
For this purpose, the Clinic processes the following categories of personal data relating to the following Data Subjects:
- Patient’s personal data – the same categories of personal data described above under Planning of Healthcare Services and Other Services (see Section 2), as well as any other information disclosed by the Patient during the consultation, including, among other things, information concerning the Patient’s lifestyle, habits, family relationships, and similar matters;
- Family members’ personal data may also be processed to a limited extent where necessary for the provision of services to the Patient (for example, information regarding hereditary or familial medical conditions);
- where the service is paid for by a person other than the Patient, the Clinic also processes the payer’s personal data, including the payer’s name and relevant payment information;
- where the service is booked by a person other than the Patient, the Clinic also processes the booker’s personal data, consisting of the same categories of personal data described above under Planning of Healthcare Services and Other Services (see Section 2);
- where the Patient designates an emergency or contact person, the Clinic processes that person’s name, personal identification code (or date of birth), email address, telephone number, and relationship to the Patient.
Where the Clinic processes personal data for the provision of healthcare services, the legal basis for processing is Section 41(1)(1) of the Health Services Organisation Act (TTKS). Where the Clinic provides a service that does not constitute a healthcare service, the legal basis for processing is the performance of a contract concluded between the Clinic and the Patient pursuant to Article 6(1)(b) of the GDPR.
Where the service is paid for by a person other than the Patient, the Clinic processes the payer’s personal data on the basis of its legitimate interests pursuant to Article 6(1)(f) of the GDPR. The Clinic’s legitimate interest is to obtain payment for the services provided and, for that purpose, to process the payer’s personal data.
Quality Management of Healthcare and Other Services, Including Complaint Handling and Documentation of Patient Safety Incidents
Processing for this purpose includes activities aimed at ensuring the quality of the services provided, including healthcare services. This may include retrospective reviews and assessments of services that have already been provided. This purpose also includes handling complaints submitted by Patients and documenting patient safety incidents in accordance with applicable legislation.
For this purpose, the Clinic processes the following personal data:
- the Patient’s personal data and, where healthcare services are involved, the relevant health data, as well as any personal data relating to a complaint where a complaint has been submitted;
- where a complaint is submitted by the Patient’s representative, the representative’s name, the legal basis of the representation, and contact details.
For healthcare services, the legal basis for processing is the assurance of healthcare quality and the documentation of patient safety incidents pursuant to Section 41(1)(3) of the Health Services Organisation Act (TTKS) and Article 9(2)(f) of the GDPR.
For services other than healthcare services, the legal basis for processing is the Clinic’s legitimate interests pursuant to Article 6(1)(f) of the GDPR. The Clinic’s legitimate interest is to ensure and continuously improve the quality of the services it provides.
Compliance with the Clinic’s Legal Obligations
Processing for this purpose includes activities that the Clinic is required to carry out under applicable legislation.
For this purpose, the Clinic may process:
- any personal data relating to any Data Subject to the extent required by the applicable legal obligation;
- for the purposes of complying with obligations under the Health Services Organisation Act (TTKS), personal data such as the Patient’s consent to a particular procedure, information subject to statutory documentation requirements, health data required under the TTKS, and the Patient’s personal data recorded in the medical record;
- for the purposes of complying with obligations under accounting legislation, personal data contained in accounting records, including payment information.
Where the Clinic’s legal obligation relates to the provision of healthcare services, the legal basis for processing is Section 41(1)(1) of the Health Services Organisation Act (TTKS), together with the specific legal provision imposing the relevant obligation. Where the Clinic is required to document a patient safety incident, the legal basis is Section 41(1)(3) of the Health Services Organisation Act (TTKS). Where the processing does not involve health data, the legal basis is Article 6(1)(c) of the GDPR (compliance with a legal obligation).
Exercise and Protection of the Clinic’s Legal Rights
Processing for this purpose includes activities necessary for the exercise and protection of the Clinic’s legal rights. The specific processing activities are determined on a case-by-case basis, depending on the legal right being exercised by the Clinic. Such rights may include the establishment, exercise or defence of legal claims, which may require the processing of personal data.
For this purpose, the Clinic may process any personal data relating to any Data Subject to the extent necessary for the exercise or protection of its legal rights.
Where the Clinic processes special categories of personal data (such as health data) for the purpose of establishing, exercising or defending legal claims, the legal basis for processing is Article 9(2)(f) of the GDPR. Other personal data are processed on the basis of the Clinic’s legitimate interests pursuant to Article 6(1)(f) of the GDPR. The Clinic’s legitimate interest is to establish, exercise and defend its legal rights where necessary.
Conducting Scientific Research
As a general rule, where data are processed for scientific research purposes, they are anonymised in advance. Once anonymised, the data no longer constitute personal data, and the rules governing the processing of personal data, including the GDPR, no longer apply.
However, the Clinic may request the Patient’s consent to process the Patient’s identifiable health data for scientific research purposes. In such cases, the processing is limited to the Patient’s health data and is carried out only where the Patient has provided prior explicit consent in accordance with Article 9(2)(a) of the GDPR. If the Patient does not provide such consent, the Patient’s personal data will not be processed for scientific research purposes.
Recruitment and Assessment of Candidates
Processing for this purpose includes activities necessary to identify suitable candidates (for example, by searching through recruitment service providers) and to assess candidates’ suitability for employment (including communicating with candidates).
For this purpose, the Clinic may process, among other things, the following personal data relating to job applicants or prospective candidates:
- name;
- current position;
- email address;
- telephone number;
- address;
- curriculum vitae (CV);
- education;
- work experience;
- skills;
- qualifications; and
- other information obtained from publicly available sources.
Where an individual applies for a position with the Clinic on their own initiative, the legal basis for processing is Article 6(1)(b) of the GDPR, namely the taking of steps at the request of the data subject prior to entering into an employment contract.
Where the Clinic actively searches for prospective employees, the legal basis for processing is the Clinic’s legitimate interests pursuant to Article 6(1)(f) of the GDPR. The Clinic’s legitimate interest is to recruit suitable personnel.
Where a candidate is not recruited but the Clinic wishes to retain the candidate’s personal data for more than one year following the end of the recruitment process, the data will be retained only with the candidate’s consent pursuant to Article 6(1)(a) of the GDPR.
Collection of Website Usage Statistics and Analysis of Website Use
Processing for this purpose includes the collection and processing of data through analytical cookies in order to compile website usage statistics and analyse how the Website is used.
The personal data processed for this purpose are collected through analytical cookies and relate to the use of and visits to the Website, including information about the visitor’s activities on the Website. Further information regarding cookies is provided in Section 8 of this Privacy Notice.
The legal basis for processing is the Website visitor’s consent pursuant to Article 6(1)(a) of the GDPR. Website visitors may withdraw their consent at any time.
SOURCES OF PERSONAL DATA AND DISCLOSURE OF PERSONAL DATA
The Clinic obtains the Patient’s personal data both directly from the Patient and from third-party sources. Such third-party sources may include, in particular, the national Health Information System, other healthcare providers, the Estonian Health Insurance Fund, the Prescription Centre, the Medical Imaging Archive (Pildipank), other health-related information systems, insurers (where an insurance claim is involved), and, in certain cases, the Patient’s representative, a family member or other close person, or the individual who booked the appointment on the Patient’s behalf.
The Clinic obtains personal data relating to job applicants both directly from the applicants themselves and from publicly available third-party sources (such as publicly accessible information available online). Personal data relating to Website visitors are obtained primarily through the Website. Personal data relating to other Data Subjects may likewise be obtained either directly from the Data Subject or from third-party sources.
The provision of certain personal data relating to the provision of healthcare services is mandatory, as the Clinic is required to comply with applicable legislation governing the provision, documentation and quality management of healthcare services, which requires the processing of specified categories of personal data. If the required personal data are not provided, the Clinic will be unable to provide healthcare services to the Patient.
Similarly, where the Clinic provides services other than healthcare services, the provision of the personal data necessary for those services may be required. Failure to provide such personal data may prevent the Clinic from entering into a contract for the provision of the requested service (for example, where the service recipient does not disclose their name) or from performing such a contract.
Likewise, if a job applicant chooses not to provide the personal data required for the recruitment process, the Clinic will not be able to consider that individual for employment.
Where the Clinic has not identified the provision of personal data as mandatory, the provision of such personal data is voluntary, and failure to provide it will not result in any adverse consequences for the Data Subject.
RETENTION OF PERSONAL DATA
The Clinic retains personal data only for as long as necessary to fulfil the purposes for which the personal data were collected or as otherwise required by applicable law.
With respect to health data, the Clinic applies the following retention periods:
- audit logs of the Clinic’s information systems are retained for five (5) years;
- pursuant to Sections 42(4) and 42(5) of the Health Services Organisation Act (TTKS), records evidencing the provision of healthcare services are retained for thirty (30) years following the confirmation of the records relating to the healthcare services provided to the Patient.
In addition, the following retention periods apply:
- where personal data are processed for the purpose described in Section 4 (Quality Management of Healthcare and Other Services), such personal data are retained for as long as necessary for the relevant case, but generally for no longer than ten (10) years;
- where personal data are processed for the purpose described in Section 7 (Conducting Scientific Research), such personal data are retained until the Data Subject withdraws their consent and, in any event, for no longer than seven (7) years;
- where personal data are processed for the purpose described in Section 8 (Recruitment and Assessment of Candidates), the personal data are retained as follows:
- if the candidate is not employed under an employment contract or other similar agreement, the personal data are deleted one (1) year after the recruitment process has ended;
- where the candidate has consented to longer retention, the personal data are retained until the consent is withdrawn, but in any event for no longer than three (3) years;
- accounting records containing personal data are retained for seven (7) years following the end of the relevant financial year, in accordance with the Accounting Act;
- the retention of cookies is governed by the provisions set out in Section 8 (Cookies) of this Privacy Notice.
Note: For an international audience, I would recommend replacing the Estonian abbreviations TTKS and IKÜM with their full English names on first reference (i.e., Health Services Organisation Act and General Data Protection Regulation (GDPR)) and thereafter using the English abbreviations or simply “GDPR”. This is the drafting approach typically used in English-language privacy notices.
DISCLOSURE OF PERSONAL DATA TO THIRD PARTIES
The Clinic discloses personal data to third parties only where such disclosure is required or permitted by applicable law, or where it is necessary for the provision of services to the Patient or for the Clinic’s day-to-day operations.
The Clinic may disclose personal data to the following categories of third parties, which generally act as data processorson behalf of the Clinic:
- The Clinic discloses personal data (including health data) to providers of medical software used in its daily operations for the provision of healthcare services, such as Connected OÜ (Estonia), which operates the eKliiniksystem.
- The Clinic also discloses personal data to software providers, such as Microsoft Ireland Operations Limited(Ireland), because the Clinic uses Microsoft software, including Microsoft Office. In addition, the Clinic discloses personal data to Tandem Health AB (Sweden), which provides clinical documentation services. During this process, consultations are audio-recorded and transcribed using the documentation software. The audio recording is deleted on a rolling basis immediately after transcription has been completed.
- The Clinic discloses personal data to IT service providers, such as Elisa Eesti AS (Estonia), which provides IT infrastructure and support services and may, where necessary, have access to health data.
- The Clinic also discloses personal data to accounting software providers, such as Merit Tarkvara AS (Estonia), which provides accounting software and has access to invoices and the personal data contained therein.
- Website-related data may be disclosed to providers of analytical cookie services, such as Google LLC (Ireland), which provides website analytics services. In certain cases, Google acts as an independent controller with respect to such processing.
All data processors engaged by the Clinic are required to process personal data in accordance with applicable data protection legislation, including the GDPR, and to ensure the confidentiality and security of the personal data entrusted to them.
As a general rule, the Clinic does not transfer health data outside the European Economic Area.
The Clinic may also disclose personal data to third parties acting as independent data controllers, including the following:
- In connection with the provision of healthcare services, the Clinic discloses personal data to the Health Information System, the national health information database established under applicable law. The Health Information System enables healthcare providers to exchange information and access health data previously submitted by other healthcare providers. The joint controllers of the Health Information System are the Ministry of Social Affairs and the Estonian Health Insurance Fund (Tervisekassa). Health information submitted to the Health Information System is also made available to the Estonian Medical Imaging Foundation (Sihtasutus Eesti Tervishoiu Pildipank), which, as a processor of the Health Information System, manages, processes and archives medical imaging data. The Health Information System is administered by the Health and Welfare Information Systems Centre (TEHIK), acting as its processor.
- The Clinic also discloses personal data to the Prescription Centre (Retseptikeskus), whose controller is the Estonian Health Insurance Fund (Tervisekassa). The Prescription Centre is the national database used for issuing and processing electronic prescriptions and medical device prescriptions and for administering pharmaceutical and medical device reimbursements in accordance with the Health Insurance Act. Its purpose is to safeguard public health, enable supervision over the lawful and justified dispensing of prescription medicines, and support the compilation of national pharmaceutical statistics.
- The Clinic may disclose health data to other healthcare providers where required or permitted under applicable legislation.
- The Clinic may disclose personal data to relevant insurers. For example, the Clinic has professional liability insurance with PZU (the Estonian branch of AB Lietuvos draudimas), and in the event of an insured claim, the Patient’s health data and other relevant personal data may be disclosed to the insurer.
- Where the Patient has private health insurance, the Clinic may disclose personal data to the insurer with whom the Patient has concluded the relevant insurance contract.
- Where a Patient or another relevant Data Subject has failed to pay for services provided by the Clinic, the Clinic may disclose the personal data necessary for debt recovery—including the Data Subject’s name, telephone number, postal address, email address, invoices giving rise to the debt, together with information contained in those invoices and information relating to previous collection efforts—to the Clinic’s contracted debt collection service providers, as well as to courts, bailiffs and other persons or authorities authorised by law to process personal data in connection with debt recovery proceedings.
- The Clinic may also disclose personal data to other public authorities or third parties where it is legally required to do so, for example to law enforcement authorities.
The service providers and cooperation partners listed above are provided for illustrative purposes only. The Clinic may replace or change service providers from time to time without being required to amend this Privacy Notice on each such occasion.
DATA SUBJECT RIGHTS
Data Subjects (including Patients) may contact the Clinic at any time by email at info@seluskliinik.ee or through the Clinic’s reception to exercise their rights under applicable data protection legislation, including the right to:
- request access to their personal data processed by the Clinic;
- request the rectification of inaccurate or incomplete personal data;
- request the erasure of personal data;
- request the restriction of processing;
- object to the processing of personal data;
- request the portability of personal data;
- request not to be subject to a decision based solely on automated processing;
- withdraw consent at any time where processing is based on consent; and
- lodge a complaint regarding the processing of personal data.
Please note that these rights are not absolute. Their exercise may be limited by the GDPR, other applicable legislation, or the legitimate rights and obligations of the Clinic. For example, the Clinic cannot erase personal data where applicable law requires their retention. Where the Clinic is entitled to refuse or limit a request, it will explain the reasons to the Data Subject.
Requests submitted to the Clinic must be digitally signed or, if submitted in person, the Data Subject must verify their identity by presenting a valid identity document. Where personal data are provided electronically, they will be transmitted only in encrypted form. For security reasons, personal data will not be disclosed over the telephone.
Data Subjects also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) (Tatari 39, 10134 Tallinn, Estonia; email: info@aki.ee).
COOKIES
The Clinic’s Website uses cookies. Cookies are small text files stored in a user’s web browser or device when visiting the Website. Cookies may be either first-party cookies, which are set directly by the Clinic’s Website, or third-party cookies, which are placed by external service providers.
The Clinic uses the following categories of cookies:
a) Strictly Necessary and Functional Cookies
These cookies are required for the operation of the Website. They are deleted automatically at the end of the browsing session, i.e. when the user closes the Website.
b) Analytics Cookies
These cookies are used to compile statistics regarding the use of the Website and to analyse visitor behaviour, such as the number of visitors, how the Website is used, and how visitors reach the Website.
For these purposes, the Clinic uses Google Analytics cookies (including the _ga cookie and related cookies, retained for up to two (2) years) and Google Tag Manager.
Website visitors may refuse the use of analytics cookies by declining consent, withdrawing previously given consent, or configuring their web browser accordingly. Visitors may also delete cookies already stored on their device. Most web browsers provide instructions for disabling cookies through their Help function.
Further information about cookies and how to disable them is available at www.allaboutcookies.org.