PERSONAL DATA PROTECTION POLICY (GDPR)
This Data Protection Policy describes the way in which Jovian Health Lab, hereinafter referred to as the "Center", collects, processes, and protects the personal data of its patients, visitors, and partners, in accordance with the General Data Protection Regulation (EU 2016/679 – GDPR), Greek legislation, and the specific provisions governing healthcare services.
The Data Controller is the Medical Center located at 82 Vasilissis Sofias Avenue, with contact telephone number 2107489100 and website www.jovianhealth.gr. For any matter related to the protection of personal data, interested parties may contact us at info@jovianhealth.gr.
The Center collects the necessary data for the provision of healthcare services. During a visit or collaboration with the Center, identification data may be collected, such as full name, date of birth, address, contact details, and insurance information, as well as health data, including medical history, diagnoses, examinations, treatment records, and medication. Administrative and financial data for service invoicing may also be collected, as well as technical browsing data, such as cookies or usage statistics, if a website is used.
The Center does not collect data beyond what is necessary for the provision and organization of healthcare services.
Personal data is processed exclusively for the purposes of providing medical care, maintaining medical records, scheduling appointments, issuing referrals, medical certificates and test results, as well as communicating with patients regarding therapeutic instructions. In addition, the data is used for the fulfillment of tax and administrative obligations, as well as for cooperation with insurance providers when requested by the patient. No automated decision-making or profiling is carried out, except to the extent that this is strictly necessary for the provision of healthcare services.
The legal bases for data processing include the provision of healthcare services in accordance with Article 9 of the GDPR, compliance with legal obligations under Article 6, the performance of a contract under Article 6, and consent where required under Article 6.
Access to personal data is limited to authorized members of the Center's staff, such as doctors, therapists, and administrative personnel. Data may also be disclosed to collaborating diagnostic laboratories or insurance organizations where this is required for the provision of services or requested by the patient. In cases of legal obligation, access may be granted to the competent authorities.
All partners are bound by confidentiality clauses and data processing agreements. In the event that, in the future, the Center establishes or collaborates with new units operating under the Center's framework and status, access to personal data will be carried out exclusively through the Center's central database, under its direct supervision and control. These units will be required to strictly comply with the same high standards of security and personal data protection applied by the Center, in accordance with the GDPR and applicable legislation.
Personal data is retained for the period required by healthcare legislation, specifically for at least ten years, or for a longer period where necessary for the support of legal claims. Data collected on the basis of consent is retained until such consent is withdrawn. After the end of these periods, the data is securely deleted or anonymized.
Patients have a number of rights under the GDPR, including the right of access to their data, the right to rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent where consent constitutes the legal basis for processing.
The Center implements appropriate technical and organizational security measures to protect personal data, such as encryption, secure file storage, controlled access to health records, updated information system protection measures, confidentiality procedures, and data backup processes.
The Center does not transfer data to countries outside the European Union. If such a transfer is required in the future, it will be carried out in accordance with Articles 44–49 of the GDPR and only after the patient has been fully informed.
If any individual believes that their rights have been violated, they may contact the Center or the Hellenic Data Protection Authority through its website.
The Center reserves the right to update this policy whenever necessary. The latest version will be available at the Center's premises or on its website.