- Who is the controller of your personal data processing?
- Why are your data processed?
- What data are processed and from what source are they obtained?
- Why is it lawful for us to process your data?
- Who receives your data?
- For how long will your data be stored?
- What are your rights?
This Data Protection Policy has been specifically adapted to Grupo Hospitalario HLA’s website (www.grupohla.com/es), and to any applications and other products and services that the data subject may use through this page (jointly, the “Services”). Consequently, in the terms described in its Data Protection Policy, Grupo Hospitalario HLA may communicate your personal data to other Group companies, if this is necessary for the provision of such Services.
This Data Protection Policy may be changed by Grupo Hospitalario HLA, after informing the data subject through its website or otherwise, in order to be adequately informed and to continue using our Services. Continued enjoyment of our Services after you have been notified of such changes will constitute your acceptance thereof, unless your express consent is necessary.
Who is your personal data controller?
The controller in charge of any personal data provided by a data subject on the website (www.grupohla.com/es) is the company HLA LAVINIA SALUD, SLU (HLA), domiciled in calle Juan Ignacio Luca de Tena, 12, 28027 Madrid.
In order to adequately manage your personal data processing, HLA has designated a Data Protection Officer who may be addressed to resolve any issue you may need, available at the following e-mail: DPO@grupohla.com.
Why do we process your data?
At HLA, we may process personal data gathered from a data subject, for the following purposes:
1. Contact: to manage the data of any data subjects contacting HLA through the forms made available to users by HLA. Likewise, your data will be processed in order to handle any consultations you may forward through the channels in place to that end on our website.
2. Working for us: to handle any c.v.’s received by e-mail, as well as any personal data that may be generated should you participate in selection processes, in order to analyse your professional profile and allow you to participate in HLA’s staff selection processes, if vacancies or new jobs periodically arise, and to process your ultimate recruitment as part of HLA staff. Please note that we will save your data for no longer than one year, if we consider that you may fit any of our existing employment profiles in the future.
3. Advertising of our products and services: After we have gathered your consent in accordance with current data protection regulations, HLA may forward advertising by post, e-mail, SMS or other electronic means of communication, both of a general nature and adapted to your characteristics, related to the company’s services.
4. Profiling with external sources: Based on your previously gathered consent and the necessary information, HLA may conduct profiling based on information provided by third parties, through marketing studies and techniques and statistic and segmentation procedures, in order to personalise its range of products and services in line with your characteristics and needs. Your acceptance will not entail any automated decision-making.
5. Other channels: In the terms foreseen in current regulations. HLA may also contact the data subject and gather his data through other channels, such as by telephone, e-mail, Apps owned by HLA or social networks, in which case you will be informed of the purposes for which your data will be processed, and your consent will be accordingly gathered as necessary through each one of these channels.
What data are processed and from what source are they obtained?
The processed data derive from:
- Data provided by the data subject, by completing the forms in place to that end and further to his relations with HLA.
- Data derived from the service provided: indirectly, arising from the service provided and maintenance of this activity. This category includes navigation details obtained from the public website or access to the Patient’s Portal.
- Data obtained from marketing studies, in which the patient has agreed to participate and has given his consent to this data use.
Depending on the service, the processed data will cover the following types:
- Identification details (e.g. name, surnames, identity card, postal address, e-mail, telephone number).
- Socioeconomic data (e.g. economic, financial and insurance).
- Data on transactions involving goods and services (e.g. payments of services rendered).
- Sales information data (e.g. interest in products or services).
- Socioeconomic data (economic, financial and insurance).
- Health data.
Why is it lawful to process your data?
The processing of your “Contact” data, access to the Patient’s Portal and other communication channels available, is based on the need to maintain your request and, eventually, to provide the services contracted.
Likewise, the legal grounds on which your data are processed are the provision of patient services by HLA.
All data related to “Working with Us” are processed according to the voluntary c.v. provided and its conservation, further to a legitimate interest.
Delivery of advertising and marketing on company products or similar to those contracted by the data subject, or third party advertising, is based on the data subject’s consent, which must be necessarily requested.
Who receives your data?
Any personal data processed by HLA to achieve the aforementioned purposes may be notified to the following recipients, based on the lawfulness of such communication.
Further to the foregoing, the following data communications seek to guarantee an adequate development of your contractual relationship, and to fulfil the legal obligations required by such communications:
- Authorities and Public Administrations.
- A professional civil liability insurance company, strictly for the processing and management of claims covered by the insuMedical and administrative professionals and institutions confirming a legitimate and necessary interest in prevention, medical diagnosis, healthcare, medical treatment, healthcare service management or the supervision of a clinical process and administrative management.
- A professional civil liability insurance company, strictly for the processing and management of claims covered by the insurance policy taken out.
- Entities holding data service files on solvency and creditworthiness, both for consultation in the cases legally foreseen and in the event of a breach of your monetary obligations.
For how long will your data be stored?
Your personal data will be saved for the time established in patient autonomy regulations. Once these timeframes expire, all data will be erased as foreseen in data protection regulations. As a result, data access will be blocked and data only made available at the request of Judges and Tribunals, the Ombudsman, the State Prosecution Service or the competent Public Administrations, until any potential actions have lapsed and, thereafter, such data will be fully erased.
What are your rights?
Any data subject will be entitled to receive confirmation as to whether HLA is or not processing his personal data.
Likewise, as foreseen in the General Data Protection Regulation, a data subject may exercise the following rights:
- To access his data in order to know how the data subject’s personal data are being processed by HLA.
- To request a rectification is a data subject considers that data are inaccurate and are being processed by HLA.
- To apply for a limitation on his data processing, if this is foreseen by law. In these cases, HLA will keep the limited data in order to bring or defend itself against claims, as foreseen in the General Data Protection Regulation.
Furthermore, a data subject may at any time object to a delivery of advertising by HLA by electronic means, and may withdraw his consent, without this affecting the lawfulness of the processing prior to such consent.
Likewise, a data subject may exercise the aforementioned rights by sending a written request to HLA LAVINIA SALUD, SLU (HLA), at calle Juan Ignacio Luca de Tena 12, 28027 Madrid, or by sending an e-mail to DPO@grupohla.com, stating “Data Protection Policy” as the reference in either case.
Finally, a data subject may bring a claim before the Spanish Data Protection Agency, particularly when he has been unable to satisfactorily uphold his rights.