+30 210 46 11 204
The protection of personal data of patients, visitors, and associates is a fundamental commitment of Cosmoclinic and an integral part of its operation. The assurance of privacy and information confidentiality is handled with the utmost professionalism and a deep sense of responsibility.
The Clinic fully complies with the General Data Protection Regulation (GDPR) and the current European and national legislative framework. The Personal Data Protection Policy describes in detail the types of data collected and processed, the legal basis for processing, retention periods, potential recipients, and the technical and organizational measures taken for their protection.
Through the systematic implementation of strict information security standards, we ensure that all data processing is conducted with transparency, legality, and respect for the rights of data subjects. This commitment strengthens trust and confirms Cosmoclinic's steadfast dedication to protecting the privacy and dignity of every individual.
Cosmoclinic has taken the necessary measures to fully ensure your privacy and the security of your personal data, in accordance with current European and national legislation. This document describes the Clinic’s Policy regarding the processing of patients' personal data during the provision of healthcare services. Specifically, it describes and analyzes: the type of personal data the Clinic processes, the purposes and legal basis of the processing, the data retention period, the recipients thereof, as well as the technical and organizational measures the Clinic has implemented to guarantee the security of your privacy.
Data We Process
The Clinic collects your personal data to provide you with the medical services you request (identity data, demographic data, contact details, payment and insurance information, medical history and other health data, image and visual data from security cameras installed in the Clinic for the prevention of criminal acts and the safeguarding of its legitimate interests), as well as your email address if you indicate that you wish us to send your medical test results or if you wish to receive updates regarding our corporate social responsibility (CSR) initiatives. In this context, if you wish, we process and store previous medical reports you provide us for medical diagnosis purposes. Furthermore, upon your explicit consent, we store the contact details of your next of kin, which will be used strictly in case of emergency. If you visit the Clinic upon referral by a private physician, we inform the latter of your test results only if deemed necessary for the purposes of a proper medical diagnosis.
Legal Basis for Processing Your Data
Cosmoclinic processes your personal data transparently, in accordance with the principles of lawfulness, fairness, purpose limitation, accuracy, confidentiality and integrity, and storage limitation. The legal basis for processing your personal data, depending on the case, may be: scheduling a medical appointment, the provision of medical services to you, your consent (for sharing your medical test results with third parties, sending them via email, or sending you updates regarding specific social responsibility initiatives), the safeguarding of our legitimate interests, and compliance with our legal obligations.
Data Retention Period
Our Clinic retains the personal data you have provided us for the provision of medical services for a period of 20 years, as stipulated by national legislation. After the expiration of this period, we proceed with the secure deletion of your personal data. Exceptionally, the Clinic may retain your personal data for a period exceeding 20 years only if this is necessary for the serving of its legitimate interests. In this latter case, you will be notified accordingly.
Recipients of Your Personal Data
The Clinic discloses your personal data to three different categories of recipients:
i) To third-party partners: Cosmoclinic maintains external partnerships with third parties, which include: physicians, healthcare providers, IT engineers, legal advisors, insurance companies for the provision of civil liability insurance, and debt collection agencies for overdue receivables. These parties process personal data in the name and on behalf of the Clinic under strong contractual commitments, and they have been selected based on their substantive implementation of high-level security measures regarding personal data protection.
ii) To third parties with whom there is no partnership: The Clinic discloses your personal data to third-party recipients (with whom it has no partnership) only in the following cases:
In the event that disclosure is required within the framework of an insurance contract you maintain with a specific insurance company.
For the purpose of safeguarding your vital interests.
Provided it is required by a specific legislative provision.
iii) To third-party healthcare providers upon your request: Cosmoclinic discloses your personal data to third-party healthcare providers solely upon your written request. For more information on how your personal data is transmitted to third parties, you may consult our website or the Clinic’s secretariat.
iv) To ELSTAT (Hellenic Statistical Authority): It is clarified that the Clinic bears no responsibility for the aforementioned processing of your personal data by third parties in the event that the disclosure is made upon your own request.
Recording of Letters, Faxes, or Emails You Send Us
We may retain the letters, faxes, or emails you send us. We utilize the above to evaluate, analyze, and improve our services, train our staff, manage or prevent potential risks, and detect any potential criminal acts.
Security of Your Data
The Clinic's priority is keeping your personal data secure. Our Clinic has adopted and implements a series of measures to keep your personal data safe and protected. These measures, depending on the case, include role-based access control (RBAC), as well as pseudonymization, encryption, or other technical and organizational measures.
Your Rights
We inform you that you have the right to:
Access your data
Rectify your data in case of inaccuracy
Erase your data in specific cases
Restrict the processing of your data
Object to the processing of your data
Transmit your data to another healthcare provider (Data Portability)
Lodge a complaint with the Hellenic Data Protection Authority in the unfortunate event of a data breach.
Our Clinic will respond to your potential requests to exercise the above rights within one month of receiving them; exceptionally, this deadline may be extended by another 2 months if further time is required. Should you need clarification or further information regarding your above rights, you may contact the Clinic’s secretariat or the Data Protection Officer (contact details below).
Contact / Controllers
We inform you that you may contact our Clinic regarding any issue concerning the security of your data at the following telephone number: +30 210 46 11 204, as well as via email: dpo@cosmoclinic.gr. If you are not satisfied with the way your data is processed, you may lodge a complaint with the Hellenic Data Protection Authority. However, we would appreciate the opportunity to resolve any complaint you may have as soon as possible before you proceed with a complaint to the Hellenic Data Protection Authority.