Working hours:
Mon - Sun, 00–24h
Location: Serbia, Ugrinovački Put 16, Belgrade, 11080
Working hours: Mon - Sun, 00–24h

Location: Serbia, Ugrinovački Put 16, Belgrade, 11080
This website uses cookies to ensure you get the best experience
OK
Privacy Policy – Dr Vorobjev

SPECIAL HOSPITAL “DR VOROBJEV” BELGRADE


NOTICE ON PERSONAL DATA PROCESSING – PRIVACY POLICY

Dear Service Users,

When you request any of our services (through the website and social networks *9, email, the customer service centre – Call Centre, direct mail, personal contact, completion of medical documentation and records, including, without limitation, other types and forms of personal data sources), regardless of your citizenship, temporary residence or permanent residence, you have the right to the protection of your personal data.

You will be asked to provide us with several types of data *1. These data are necessary so that we can assess your request or need as accurately as possible and provide you with an appropriate response and/or service.

Providing our institution with truthful, accurate and complete information about yourself, as well as updating such information in a timely manner so that it remains truthful, accurate and complete, is your legal/statutory and contractual obligation, and the provision of such data is a necessary condition for entering into a contract with us.

Your refusal to provide the requested data, or the provision of incorrect information, may result in our inability to provide services of satisfactory quality or to provide the service at all.

The Republic of Serbia, for the purposes of harmonisation and in order to make national provisions understandable to the persons to whom they apply, has harmonised its national legislation – the Law on Personal Data Protection – with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council.


RISKS OF PERSONAL DATA PROCESSING

The Internet is transforming traditional market structures by providing a common, global infrastructure for the delivery of a wide range of electronic communications services. Publicly available electronic communications services over the Internet create new opportunities for users, but also new risks to their personal data and privacy *8.

It is generally recognised that there are significant risks to the protection of natural persons, particularly in connection with online activities. As a natural person, beyond our will or ability to control or influence such matters, you may be associated with online identifiers provided by your devices, applications, tools and protocols, such as Internet Protocol addresses, cookie identifiers or other identifiers such as radio-frequency identification tags.

This may leave traces which, particularly when combined with unique identifiers and other information received by servers, may be used to create profiles of natural persons and identify them.

Risks/sources of risk (personal data security breaches) include, without limitation, accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed. Such breaches may in particular result in physical, material or non-material damage, such as loss of control over your personal data or restriction of your rights, discrimination, identity theft or fraud, financial losses, unauthorised reversal of pseudonymisation, damage to reputation, loss of confidentiality of personal data protected by trade secrecy, or other significant economic or social damage.


SPECIAL PROTECTION OF CHILDREN IN THE USE OF PERSONAL DATA

Children deserve specific protection with regard to their personal data, as they may be less aware of the risks, consequences and safeguards concerned and of their rights in relation to the processing of personal data.

According to the Law on Patients’ Rights of the Republic of Serbia, a child is a person under 18 years of age.

In the course of receiving healthcare, a child capable of reasoning, regardless of age, has the right to confidential counselling without parental consent when this is in the best interests of the child.

A child who has reached the age of 15 and is capable of reasoning may independently consent to a proposed medical measure.

If a child who has reached the age of 15 and is capable of reasoning refuses a proposed medical measure, the competent healthcare professional is required to seek consent from the child’s legal representative.

A child who has reached the age of 15 and is capable of reasoning has the right to confidentiality of the information contained in their medical records.

Notwithstanding a child’s request that information concerning their health condition not be disclosed to their legal representative, the competent healthcare professional is required, where there is a serious danger to the child’s life or health, to disclose information concerning the child’s health condition to their legal representative.

If the patient is a child, the competent healthcare professional is required to inform the child’s legal representative or the competent guardianship authority, without delay, of the child leaving an inpatient healthcare institution.

If the patient is a child and the decision to leave the inpatient healthcare institution is made by the legal representative contrary to the child’s best interests, the competent healthcare professional is required to notify the competent guardianship authority without delay.


PURPOSE OF THE INTENDED PROCESSING AND LEGAL BASIS FOR PERSONAL DATA PROCESSING

Purpose of processing.

Personal data are collected for the purposes of scheduling services (reservations), preventive medicine, medical diagnosis, provision of healthcare, treatment or management of healthcare services/implementation of a treatment plan.

In accordance with the regulations of the Republic of Serbia, such data are collected and processed by a healthcare professional who is required by law and professional regulations to keep such data confidential.

Legal basis.

Pursuant to Article 2 of the Law on Health Documentation and Records in the Field of Healthcare (“Official Gazette of the Republic of Serbia”, Nos. 123/2014, 106/2015, 105/2017, 25/2019 (other law)), we are required to maintain health documentation and records in the manner, according to the procedure and within the time limits prescribed by this law.

Pursuant to Article 50 of the aforementioned Law, the maintenance, collection and processing of data from health documentation and records shall be carried out in accordance with the law governing personal data protection.

Pursuant to Article 54 of the Law on Healthcare (“Official Gazette of the Republic of Serbia”, No. 25/2019), the maintenance of health documentation, entry of data and handling of data contained in health documentation shall be performed exclusively by an authorised person appointed by a Decision of the Director *11.

Data are entered into forms used for maintaining health documentation and records before/on the basis of healthcare services provided, or when other measures in the field of healthcare are undertaken in accordance with the law and on the basis of data contained in public and other documents.

Exceptionally, where data cannot be entered into health documentation and records on the basis of information contained in public and other documents, they shall be entered on the basis of a statement made by the person from whom the information entered into the health documentation and records is obtained *12.

We maintain health documentation and records in written and/or electronic form.

Our healthcare institution, as well as every engaged healthcare professional, healthcare associate and other authorised person, maintains medical documentation and records in accordance with the Law on Patients’ Rights, the law governing health documentation and records in the field of healthcare, and regulations adopted for the implementation of those laws.

They are required to protect patients’ medical documentation and records against unauthorised access, inspection, copying and misuse, regardless of the form in which the data from medical documentation are stored (paper, microfilm, optical and laser discs, magnetic media, electronic records, etc.).

Our healthcare institution has established and maintains a security system that includes measures to ensure the security of the data we hold in accordance with the law.

We apply security procedures and technical and physical restrictions on access to and use of personal data. Only authorised employees/administrators may access personal data for the purpose of performing tasks related to the services we provide.

We retain the data obtained indefinitely, or in accordance with statutory retention periods.

From time to time, we engage third parties – lawyers – who perform certain tasks and functions for us and on our behalf. They are subject to confidentiality obligations and therefore may not use, provide or disclose your data for any other purpose.

Our healthcare institution does not sell or transfer collected personal data.

We may restrict the exercise of your rights and may disclose your personal data and information about you in the following cases:

- where required by law;
- to protect the rights of our healthcare institution;
- for the prevention of crime or in the interests of national security;
- for the protection of personal or public safety;
- where such information is necessary for preventing and resolving various disputes;
- for other important objectives of general public interest;
- for the protection of the rights and freedoms of other persons;
- for the establishment, exercise or enforcement of claims in civil matters.

Our healthcare institution will also process your personal data for the purpose of informing you about our services through an established printed or electronic mailing list / Newsletter.


VIDEO SURVEILLANCE

Our healthcare institution has installed video surveillance in order to protect the vital interests of individuals, particularly life, health and physical integrity, to control entry and exit, protect business secrets and protect property. These purposes also constitute the purpose of the data processing.

Video surveillance has been introduced only in areas of the premises where the above-mentioned interests must be protected, namely:

Special Hospital for Psychiatric Diseases “DR VOROBJEV” – Sremskih Boraca St., Belgrade, Zemun, 11010

- Hallway
- Living room
- Kitchen
- Storage room
- Gym
- Therapist area
- Terrace
- Courtyard
- Entrance
- Gate
- Area behind the building
- Rooms
- Upstairs hallway
- Upstairs office
- Procedure room

With regard to the method of data collection, we collect data through a video surveillance system consisting of 25 cameras that record images only, without sound.

In areas where recording takes place, clearly visible notices are displayed indicating that the area is under video surveillance, together with a graphic video surveillance symbol, the name of the Controller and a telephone number at which additional information can be obtained.

The data retention period is 30 days.

By entering the premises of our healthcare institution protected by video surveillance, you give your consent, through “conclusive conduct”, to the processing of your data.


PROCESSING UNDER THE AUTHORITY OF THE CONTROLLER OR PROCESSOR

The Processor and any person acting under the authority of the Controller or Processor who has access to personal data shall process such data only on instructions from the Controller.

The Controller *3 of personal data processing is:

Special Hospital for Psychiatric Diseases “DR VOROBJEV”, with its registered office in Belgrade, Sremskih Boraca St., Belgrade, Zemun, 11010,
contact telephone: 062/256-582,
email: operater@drvorobjev.rs
representative/authorised person: Director of the Clinic.

The Joint Controller *4 of personal data processing is:

Special Hospital for Addiction Diseases “DR VOROBJEV”, with its registered office in Belgrade, 2e Sremskih Boraca St.,
contact telephone: +381114221435,
email: operater@drvorobjev.rs,
representative/authorised person: Director of the Clinic.

The Personal Data Protection Officer is: Živka Rangelov.

Contact:
telephone: +381114221435
email: operater@drvorobjev.rs
address: 2e Sremskih Boraca St., Belgrade.


LEGITIMATE INTEREST OF THE CONTROLLER

The legitimate interest of the Controller is based on:

1. Your consent as the data subject *2;
2. A written or oral contract concluded with you as the data subject, or taking steps at your request prior to entering into a contract, including through “conclusive conduct”;
3. Compliance with the Controller’s legal obligations;
4. Protection of your vital interests or those of another natural person;
5. Performance of a task carried out in the public interest or exercise of powers vested in the Controller by law;
6. Processing of personal data necessary for the purposes of fraud prevention;
7. Processing of personal data for direct marketing purposes;
8. Pursuit of other legitimate interests of the Controller or a third party for specifically defined purposes based on – including, without limitation:

- Law on Healthcare
- Law on Health Documentation and Records in the Field of Healthcare
- Law on Patients’ Rights
- Law on Social Insurance
- Law on Protection of the Population from Infectious Diseases
- Law on Sanitary Supervision
- Law on Prevention of Domestic Violence
- Law on Transfusion Medicine
- Law on the Procedure for Termination of Pregnancy in a Healthcare Institution
- Law on the Protection of Trade Secrets
- Law on Information Security
- Law on Private Security
- Personal Data Protection Strategy
- Law on Biomedically Assisted Fertilisation
- Labour Law
- Law on Chambers of Healthcare Professionals
- Law on Human Cells and Tissues
- Law on Psychoactive Controlled Substances
- Law on the Prevention of Money Laundering and Terrorist Financing
- Law on Foreigners
- Law on Cultural Heritage
- Criminal Code of the Republic of Serbia
- Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Consolidated Text incorporating the Amendments)
- Additional Protocol to the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data regarding supervisory authorities and transborder data flows
- Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on Privacy and Electronic Communications)
- Directive 2006/24/EC of the European Parliament and of the Council of 15 March 2006 on the retention of data generated or processed in connection with the provision of publicly available electronic communications services or public communications networks and amending Directive 2002/58/EC
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)


RECORDS OF PROCESSING ACTIVITIES AND DATA COLLECTIONS

Records of processing activities and data collections *4:

The Controller and its representative, and the Processor *6 and its representative, shall maintain records of processing activities *5 for which they are responsible, containing information on:

1. the name and contact details of the Controller, Joint Controllers, the Controller’s representative and the Personal Data Protection Officer;
2. the purposes of processing;
3. the categories of data subjects and categories of personal data;
4. the categories of recipients to whom the personal data have been or will be disclosed, including recipients in other countries or international organisations;
5. transfers of personal data to other countries or international organisations, including identification of such other country or international organisation;
6. evidence of the assessment performed and the safeguards implemented where personal data are transferred to other countries or international organisations and such transfer takes place;
7. notification to the Commissioner of a transfer carried out in accordance with Article 69, paragraph 2 in conjunction with paragraph 3;
8. notification to the data subject of the transfer of personal data to other countries or international organisations and of the legitimate interest pursued by the Controller through such transfer;
9. the time limits after which certain categories of personal data are erased, where such time limits have been established;
10. a general description of security measures.


LOGGING OF PROCESSING ACTIVITIES

When a processing system / automated processing system is used, the following processing activities are logged in that system:

entry, alteration, access, disclosure, including transfer, comparison and deletion.

The logging of access to and disclosure of personal data makes it possible to determine the reasons for the processing activities, the date and time when the processing activities were performed and, where possible, the identity of the person who accessed or disclosed the personal data, as well as the identity of the recipient of such data.

Such logging may be used exclusively for the purposes of assessing the lawfulness of processing, internal supervision, ensuring the integrity and security of data, and initiating and conducting criminal proceedings.

The entry of personal data into records and other tasks related to such records are performed by an authorised person of the Personal Data Controller.

Records of personal data collections contain information on:

the serial number;
the date on which the personal data collection was established;
the date of amendments and supplements to the records;
the category of personal data recorded and the name of the personal data collection;
the type of processing activity;
the purpose of processing;
the legal basis for processing or establishing the data collection;
the category of data subjects;
the type and level of confidentiality of personal data;
the method of collecting and storing personal data;
the period for retaining and using personal data;
the name, registered name, registered office and address of the user of personal data;
an indication of the import or export of personal data into or from the Republic of Serbia, including the name of the country, international organisation or foreign user;
the legal basis and purpose of importing or exporting personal data;
the data protection measures undertaken;
and notes.


TYPE OF PERSONAL DATA AND NAME OF THE DATA COLLECTION

Information concerning the type of personal data contains a list of all categories of personal data included in the processing records.

The name of the personal data collection is determined by the Controller through a separate decision specifying the method and purpose of personal data processing.

Method of data collection and storage.

Through the website, social networks *9, email, the customer service centre – Call Centre, direct mail, personal contact, completion of medical documentation and records, including, without limitation, other types and forms of personal data sources.


PROCESSING IN THE FIELD OF LABOUR AND EMPLOYMENT

Processing in the field of labour and employment is subject to the provisions of laws governing labour and employment and occupational safety and health, together with the provisions of the Law on Personal Data Protection.

Processing is necessary for the performance of obligations and the exercise of specific rights of the Controller or you, as the data subject, in the field of employment law, performance of an employment contract, planning and organisation of work, equality and diversity in the workplace, protection of the property of the employer or clients/patients, and social insurance and social protection rights.

The processing of personal data relating to criminal and misdemeanour convictions shall be accompanied by appropriate safeguards.


PERSONAL DATA SECURITY – SECURITY OF PROCESSING

Taking into account the state of technological development, the nature, scope, context and purposes of processing, as well as the likelihood and severity of risks to the rights and freedoms of natural persons, the Controller and Processor shall implement appropriate technical, organisational and personnel measures to ensure a level of security appropriate to the risk.

These measures shall include in particular:

1. cryptographic protection of personal data;
2. ensuring the ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident;
3. a process for regularly testing, assessing and evaluating the effectiveness of technical, organisational and personnel measures for ensuring the security of processing.

When assessing the appropriate level of security, particular account shall be taken of the risks presented by processing, especially risks arising from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed.

The Controller and Processor shall take measures to ensure that every natural person authorised by the Controller or Processor to access personal data processes such data only on instructions from the Controller or where required to do so by law.

Recipients *7 of personal data are:

Institute of Public Health, insurance companies, banks.

Users or categories of users of personal data:

Accounting, Finance, IT, Management, Technical Services and insurance companies.

Categories of data subjects:

job applicants, all engaged employees and other personnel, persons whose employment has ended, patients and persons accompanying patients.


PERSONAL DATA RETENTION PERIOD AND CRITERIA FOR DETERMINING IT

The periods for which personal data are retained are determined by the applicable regulations of the Republic of Serbia (listed in greater detail in the section “Legitimate Interest of the Controller”) and by our internal regulations.

In order to ensure that personal data are not retained for longer than necessary, the Controller reviews, once a year at the beginning of the calendar year, the legal basis for deleting and/or archiving data and documentation.

Information on the retention and use period of personal data includes the date on which the data collection was established and the periods for retaining and using personal data prescribed by law or other regulations.

Where the period of use of personal data is not determined by law or other regulation, the records shall specify the period necessary to achieve the purpose of processing for which the personal data were collected.

The records shall also contain an indication that personal data are to be deleted after the expiry of the applicable retention and use period.


RIGHT TO REQUEST ACCESS, RECTIFICATION AND RESTRICTION OF PROCESSING

As a data subject, you have the right to have inaccurate personal data concerning you rectified without undue delay.

Depending on the purposes of processing, you have the right to have incomplete personal data completed, including by providing a supplementary statement.

To exercise the aforementioned rights, you must submit a written request to us.

We are required to notify all recipients to whom your personal data have been disclosed of any rectification or erasure of personal data or restriction of processing, unless this proves impossible or involves disproportionate effort.

At your request, we will provide you with information about any recipients of your personal data.

To exercise the aforementioned rights, you must submit a written request to us.


RIGHT TO REQUEST ERASURE OF PERSONAL DATA

You have the right to request in writing that the Controller erase your personal data in the following cases:

1. where the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;

2. where you withdraw the consent on which the processing was based and there is no other legal ground for the processing;

3. where you object to the processing and there are no overriding legal grounds for the processing that take precedence over your legitimate interests, rights or freedoms, or where the processing is connected with the establishment, exercise or defence of one of our legal claims;

4. where you object to the processing of personal data for direct marketing purposes, including profiling to the extent that it is related to such direct marketing. Following an objection to processing for direct marketing purposes, your personal data will no longer be processed for such purposes;

5. where your personal data have been unlawfully processed;

6. where erasure is necessary for compliance with a legal obligation to which the Controller is subject.


INFORMATION ON THE SOURCE OF PERSONAL DATA WHERE PERSONAL DATA HAVE NOT BEEN COLLECTED FROM THE DATA SUBJECT

We may also obtain your personal data by collecting information from members of your immediate and/or extended family who have been or are still users of our services through a “Family Medical History (anamnesis familiae, Latin)”.

This includes collecting information about illnesses in the immediate and extended family by asking questions concerning hereditary or family-related illnesses and conditions (tuberculosis, cancers, diabetes, hypotension, hypertension, heart disease, mental illnesses, possible suicides in the family and similar matters).

Data obtained in this manner are retained in accordance with the statutory obligation of professional confidentiality.


RIGHT TO WITHDRAW CONSENT

You may withdraw your consent to the processing of personal data in writing at any time.

Withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal:

where processing is necessary for the performance of a contract concluded with you as the data subject or in order to take steps at your request prior to entering into a contract, or as a result of your “conclusive conduct”;

where processing is necessary for compliance with a legal obligation to which the Controller is subject;

where processing is necessary in order to protect the vital interests of the data subject or another natural person;

where processing is necessary for the performance of a task carried out in the public interest or in the exercise of powers vested in the Controller by law.


INTENTION TO FURTHER PROCESS PERSONAL DATA FOR PURPOSES OTHER THAN THOSE FOR WHICH THE DATA WERE COLLECTED

We intend to further process your personal data for the following purpose:

direct marketing.


PROVISION OF A COPY OF PERSONAL DATA BEING PROCESSED

The Controller is required, upon your written request, to provide you with a copy of the personal data being processed.

The Controller may charge a fee covering the necessary costs of producing additional copies requested by you.

Where a request for a copy is submitted electronically, the information shall be provided in a commonly used electronic format unless you request otherwise.
RIGHT TO DATA PORTABILITY

You have the right to receive the personal data concerning you that you have previously provided to the Controller in a structured, commonly used and machine-readable electronic format, and you have the right to transmit those data to another Controller or to have your personal data transmitted directly to another Controller by the Controller to whom those data were previously provided / by our institution, where technically feasible.

This right may not be exercised where the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.

We are required to notify all recipients to whom your personal data have been disclosed of any rectification or erasure of personal data or restriction of their processing, unless this proves impossible or involves disproportionate effort.

At your request, we will provide you with information about all possible recipients of your personal data.

To exercise the aforementioned rights, you must submit a written request to us.


TRANSFER OF PERSONAL DATA TO ANOTHER COUNTRY OR INTERNATIONAL ORGANISATION

Personal data may be transferred to another country, a part of its territory, one or more specified sectors within that country, or to an international organisation, with the approval of the Commissioner or without prior approval where it has been established that such other country, part of its territory, one or more specified sectors within that country, or such international organisation ensures an adequate level of personal data protection.

An adequate level of protection shall be considered to exist in countries and international organisations that are parties to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, as well as in countries, parts of their territories, one or more specified sectors within those countries, or international organisations that the European Union has determined provide an adequate level of protection.

The Government of the Republic of Serbia may determine that a country, part of its territory, area of activity or legal regulation, or an international organisation does not provide an adequate level of protection, except in the case of parties to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data.

An adequate level of protection shall also be considered to exist where an international agreement on the transfer of personal data has been concluded with another country or international organisation.

The Controller shall notify all recipients to whom personal data have been disclosed of any rectification or erasure of personal data or restriction of their processing, unless this proves impossible or involves disproportionate effort.

At your request, the Controller shall inform you, as the data subject, of all recipients in the event of a transfer, as well as of the manner in which you may obtain information about the safeguards applied.


TRANSFER OR DISCLOSURE OF PERSONAL DATA ON THE BASIS OF A DECISION OF AN AUTHORITY OF ANOTHER COUNTRY

Decisions of a court or administrative authority of another country requiring the Controller or Processor to transfer or disclose personal data may be recognised or enforced in the Republic of Serbia only if they are based on an international agreement, such as an international legal assistance agreement concluded between the Republic of Serbia and that other country.

Transfer documentation shall contain information on the date and time of the transfer, the recipient of the data, the reasons for the transfer and the personal data transferred.


TRANSFER OF DATA IN SPECIAL SITUATIONS

Your data may be transferred to another country or international organisation only where one of the following conditions applies:

1. You, as the data subject, have explicitly consented to the proposed transfer after having been informed of the possible risks of such transfer due to the absence of an adequacy decision and appropriate safeguards;

2. the transfer is necessary for the performance of a contract between the data subject and the Controller or for the implementation of pre-contractual measures taken at the request of the data subject;

3. the transfer is necessary for the conclusion or performance of a contract concluded in the interests of the data subject between the Controller and another natural or legal person;

4. the transfer is necessary for important reasons of public interest prescribed by the laws of the Republic of Serbia, provided that the transfer of certain categories of personal data is not restricted by such law;

5. the transfer is necessary for the establishment, exercise or defence of a legal claim;

6. the transfer is necessary in order to protect the vital interests of the data subject or another natural person where the data subject is physically or legally incapable of giving consent;

7. the transfer concerns certain personal data contained in a public register that is available to the public or to any person who can demonstrate a legitimate interest, but only to the extent that the statutory conditions for access in that particular case are fulfilled.

If the transfer cannot be carried out in accordance with points 1) to 7) above, personal data may be transferred to another country or international organisation only if all of the following conditions are fulfilled:

1. the transfer is not repetitive;

2. the transfer concerns data relating to a limited number of natural persons;

3. the transfer is necessary for the purposes of compelling legitimate interests pursued by the Controller which are not overridden by the interests, rights or freedoms of the data subject;

4. the Controller has ensured the application of appropriate personal data protection measures on the basis of a prior assessment of all circumstances surrounding the transfer.

The Controller shall also provide information concerning such transfer, including information about the legitimate interest pursued by the Controller through the transfer.

Transfer documentation shall contain information on the date and time of the transfer, the recipient of the data, the reasons for the transfer and the personal data transferred.


RIGHT TO OBJECT

Where you consider it justified by your particular situation, you have the right at any time to object to the Controller to the processing of your personal data.

The Controller shall cease processing the personal data of the person who has submitted the objection unless there are compelling legitimate grounds for the processing which override your interests, rights or freedoms as the data subject, or where the processing is related to the establishment, exercise or defence of a legal claim by the Controller.


RIGHT TO OBJECT TO PROCESSING FOR DIRECT MARKETING PURPOSES

You have the right at any time to object to the processing of your personal data for direct marketing purposes, including profiling to the extent that it is related to such direct marketing.

If you object to processing for direct marketing purposes, your personal data may no longer be processed for such purposes.


RIGHT TO OBJECT TO PROCESSING FOR CLINICAL TRIALS, SCIENTIFIC OR HISTORICAL RESEARCH OR STATISTICAL PURPOSES

Where personal data are processed for the purposes of clinical trials, scientific or historical research or for statistical purposes, you have the right, on grounds relating to your particular situation, to object to the processing of your personal data unless the processing is necessary for the performance of a task carried out in the public interest.

Statistical purposes mean that the result of processing for statistical purposes does not consist of personal data, but of aggregated data, and that such result or data are not used to support measures or decisions concerning a specific natural person.


NOTIFICATION OF THE DATA SUBJECT OF A PERSONAL DATA BREACH

Where a personal data breach is likely to result in a high risk to your rights and freedoms, the Controller shall notify you, as the data subject, of the breach without undue delay so that you can take the necessary precautionary measures.

In the notification, the Controller shall:

- describe the nature of the personal data breach;
- provide the name and contact details of the Personal Data Protection Officer or information on another means through which information concerning the breach may be obtained;
- describe the likely consequences of the personal data breach;
- describe the measures taken or proposed to be taken by the Controller to address the breach, including measures taken to mitigate its adverse effects;
- provide recommendations enabling the natural person to mitigate potential adverse consequences.


NOTIFICATION OF THE COMMISSIONER OF A PERSONAL DATA BREACH

The Controller is required to notify the Commissioner of a personal data breach that may result in a risk to the rights and freedoms of natural persons without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach.


NO OBLIGATION TO NOTIFY THE DATA SUBJECT OF A PERSONAL DATA BREACH

The Controller is not required to notify you of a personal data breach where:

- the Controller has implemented appropriate technical, organisational and personnel protection measures in relation to the personal data affected by the breach, particularly where cryptographic protection or other measures have rendered the data unintelligible to any person who is not authorised to access them;

- the Controller has subsequently taken measures ensuring that the personal data breach which posed a high risk to the rights and freedoms of the data subject is no longer likely to result in consequences for that person;

- notifying the data subject would involve disproportionate effort.

In such a case, the Controller shall provide the notification to the data subject by means of a public communication or another equally effective method.


INFORMATION ON ACTION TAKEN IN RESPONSE TO A REQUEST

After verifying the identity of the person submitting the request, the Controller is required to provide the data subject with information on action taken on the request without delay and no later than 30 days from the date of receipt of the request.

This period may be extended by an additional 60 days where necessary, taking into account the complexity and number of requests.

The Controller shall inform the data subject of any such extension and the reasons for it within 30 days from the date of receipt of the request.

Where the data subject submits a request electronically, the information shall be provided electronically where possible, unless the data subject has requested that it be provided by other means.

Where the Controller does not act on the request of the data subject, it shall inform that person without delay, and no later than 30 days from the date of receipt of the request, of the reasons for not taking action, as well as of the right to lodge a complaint with the Commissioner or bring legal proceedings before a court.

The Controller shall provide information relating to the exercise of rights free of charge.

Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, the Controller may:

- charge a reasonable fee covering the necessary administrative costs of providing the information or taking the requested action; or

- refuse to act on the request.


RIGHT TO LODGE A COMPLAINT WITH THE COMMISSIONER

As the data subject, you have the right to lodge a complaint with the Commissioner if you consider that the processing of your personal data has been carried out contrary to the applicable regulations of the Republic of Serbia.

The Commissioner is required to inform you of the progress and outcome of the proceedings, as well as of your right to initiate judicial proceedings.

The Commissioner shall prescribe the complaint form and enable complaints to be submitted electronically, without excluding other means of communication.


RIGHT TO JUDICIAL PROTECTION

You have the right to judicial protection if you consider that the Controller or Processor, through the processing of your personal data, has infringed a right granted to you under the applicable regulations of the Republic of Serbia.


PROCESSING OF THE UNIQUE CITIZEN IDENTIFICATION NUMBER

The processing of the unique citizen identification number is subject to the provisions of the law governing the unique citizen identification number or another applicable law, together with the provisions of the Law on Personal Data Protection relating to the protection of the rights and freedoms of data subjects.


OBLIGATION OF A FOREIGN NATIONAL

A foreign national / foreigner / non-resident is responsible for independently obtaining information and translating from Serbian into their own language the data and information contained in this “Notice on Personal Data Processing – Privacy Policy”, including information published on the website, regardless of any translation provided.


RESTRICTIONS ON THE EXERCISE OF DATA SUBJECT RIGHTS

The aforementioned rights and obligations may be restricted for the protection of:

1. national security;

2. defence;

3. public security;

4. the prevention, investigation and detection of criminal offences, prosecution of offenders or enforcement of criminal sanctions, including the prevention of and protection against threats to public security;

5. other important objectives of general public interest, particularly important state or financial interests of the Republic of Serbia, including monetary policy, the budget, the tax system, public health and social protection;

6. the independence of the judiciary and judicial proceedings;

7. the prevention, investigation, detection and prosecution of breaches of professional ethics;

8. the data subject or the rights and freedoms of other persons;

9. the establishment, exercise or enforcement of claims in civil matters.


APPLICATION OF THE “NOTICE ON PERSONAL DATA PROCESSING – PRIVACY POLICY” AND OTHER RULES

All matters not governed by the provisions of this “Notice on Personal Data Processing – Privacy Policy” and other Rules shall be governed exclusively by the laws and regulations of the Republic of Serbia.


JURISDICTION IN THE EVENT OF A DISPUTE AND APPLICABLE LAW

In the event of a dispute concerning any matter arising from the initial contact with our institution and/or the institution’s website and thereafter, taking into account the published rules / terms / prorogation agreement – “Jurisdiction in the Event of a Dispute” – the parties to the dispute shall first attempt to resolve the dispute amicably on their own within 90 days from the registration of the dispute with the institution.

If the dispute is not resolved within the specified period, then, taking into account the “Jurisdiction in the Event of a Dispute” and regardless of the state, country, province, region, place, etc., including any existing or future criteria for determining jurisdiction, conditional clauses and/or jurisdiction arising from the use of the Internet/website, the place of use and/or the place from which our website may be accessed and/or jurisdiction determined according to an “in rem” logic based on the location of the registry or authorised Internet domain name registry, the sole and exclusive court having subject-matter, territorial and personal jurisdiction (both general and specific personal jurisdiction) shall be the competent court in Belgrade.

The legal remedies, standards, procedures and regulations of the Republic of Serbia and the rules/internal regulations adopted by our institution in the Serbian language shall apply.


CONTACT

If you have any questions concerning personal data protection, please contact Živka Rangelov, psychologist at the Special Hospital for Addiction Diseases “DR VOROBJEV” Belgrade, verbally or in writing, by telephone at +381114221435 or by email at:

operater@drvorobjev.rs

By signing the written statement “Consent to Personal Data Processing” or by clicking/checking the “I Accept the Rules” box online (“tick-the-box”), you perform a clear affirmative action expressing your freely given, specific, informed and unambiguous consent, as the data subject, to the processing of your personal data.

Such consent may be expressed in the form of your written statement, electronic statement, oral statement or through conclusive conduct.


ENTRY INTO FORCE OF THE NOTICE ON PERSONAL DATA PROCESSING – PRIVACY POLICY

The Notice on Personal Data Processing – Privacy Policy entered into force on 20 August 2019.

The Notice on Personal Data Processing – Privacy Policy shall be subject to regular review, and each updated version shall be printed and placed at the reception desk or published on our website.


____________________________________

Director of the Clinic


*1 “Personal data” means any information relating to a natural person whose identity is identified or identifiable, directly or indirectly, in particular by reference to an identifier such as a name and identification number, location data, an identifier in electronic communications networks, or one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity.

*2 “Consent” of the data subject means any freely given, specific, informed and unambiguous indication of the wishes of that person by which the person, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to them.

*3 “Controller” means a natural or legal person or public authority which, alone or jointly with others, determines the purposes and means of processing. Where the purposes and means of processing are determined by law, the Controller may also be designated by such law or the criteria for its designation may be prescribed.

*4 “Joint Controllers” means two or more Controllers that jointly determine the purposes and means of processing.

Joint Controllers shall determine their respective responsibilities for compliance with the obligations prescribed by law, particularly obligations relating to the exercise of data subject rights and the fulfilment of their obligations to provide information to the data subject.

Such responsibilities shall be regulated by an arrangement between the Joint Controllers, unless those responsibilities are prescribed by law applicable to the Controllers.

The arrangement shall designate a contact point for the data subject and regulate the relationship of each Joint Controller with the data subject.

The essence of the provisions of the arrangement must be made available to the data subject.

Irrespective of the terms of the arrangement, the data subject may exercise the rights provided by law in respect of and against each of the Joint Controllers individually.

*5 “Data collection” means any structured set of personal data accessible according to specific criteria, regardless of whether the collection is centralised, decentralised or organised according to functional or geographical criteria.

*6 “Processing of personal data” means any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, classification, grouping or structuring, storage, adaptation or alteration, disclosure, consultation, use, disclosure by transmission or provision, reproduction, dissemination or otherwise making available, comparison, restriction, erasure or destruction.

*7 “Processor” means a natural or legal person or public authority that processes personal data on behalf of the Controller.

*8 “Recipient” means a natural or legal person or public authority to whom personal data are disclosed, whether or not a third party, except for public authorities that receive personal data in accordance with the law in the context of an investigation of a particular case and process such data in accordance with the personal data protection rules applicable to the purposes of processing.


*9

- Location data may relate to the latitude, longitude and altitude of the user’s terminal equipment, the direction of travel, the degree of accuracy of the location information, identification of the network cell in which the terminal equipment is located at a particular point in time, and the time at which the location information was recorded.

- A communication may include any name, number or address information provided by the sender of a communication or by the user of a connection for the purpose of carrying out the communication. Traffic data may include any translation of this information performed by the network over which the communication is transmitted for the purpose of carrying out the transmission. Traffic data may, inter alia, consist of data relating to the routing, duration, time or volume of a communication, the protocol used, the location of the terminal equipment of the sender or recipient, the network from which the communication originates or on which it terminates, or the beginning, end or duration of a connection. They may also consist of the format in which the communication is conveyed by the network.

- In cases where an individual subscriber or user receiving information can be identified, for example in “video-on-demand” services, the transmitted information falls within the meaning of a communication.

- Consent may be given by any appropriate method enabling a freely given, specific and informed indication of the user’s wishes, including by ticking a box when visiting an Internet website.

- Application of certain requirements relating to the presentation and restriction of calling and connected line identification and to automatic call forwarding to subscriber lines connected to analogue exchanges.

- Service providers offering publicly available electronic communications services over the Internet should inform users and subscribers of measures they can take to protect the security of their communications, for example by using specific types of software or encryption technologies. The obligation to inform subscribers of particular security risks does not relieve a service provider of its obligation to take, at its own expense, appropriate and immediate measures to remedy any new and unforeseen security risks and restore the normal level of security of the service.

- Measures should be taken to prevent unauthorised access to communications in order to protect the confidentiality of communications, including their content and any data relating to such communications, through public communications networks and publicly available electronic communications services.

- The prohibition on storing communications and related traffic data by persons other than users or without their consent is not intended to prohibit automatic, intermediate and transient storage of such information insofar as it takes place for the sole purpose of carrying out transmission in an electronic communications network, provided that the information is not stored for any period longer than necessary for transmission and traffic management purposes and that confidentiality remains guaranteed throughout the storage period.

- Confidentiality of communications should also be ensured in the course of lawful business practice. Where necessary and legally authorised, communications may be recorded for the purpose of providing evidence of a business transaction/communication. Parties to communications should be informed, before the recording is created, of the recording, its purpose and the duration of its storage. Recorded communications should be erased as soon as possible and in any event no later than the end of the period during which the transaction/communication may lawfully be challenged.

- The terminal equipment of users of electronic communications networks and any information stored on such equipment form part of the users’ private sphere and require protection under the European Convention for the Protection of Human Rights and Fundamental Freedoms. So-called “spyware”, “web bugs”, hidden identifiers and other similar devices may enter a user’s terminal without their knowledge in order to gain access to information, store hidden information or track the user’s activities, and may seriously infringe the privacy of such users. The use of such devices should be permitted only for legitimate purposes and provided that the users concerned are informed accordingly.

- Such devices, for example so-called “cookies”, may, however, constitute legitimate and useful tools, for example in analysing the effectiveness of website design and advertising and in verifying the identity of users engaged in online transactions. Where such devices, such as cookies, are intended for a legitimate purpose, such as facilitating the provision of information society services, their use should be permitted provided that users are given clear and precise information about the purpose of cookies or similar devices so that they are aware of the information being placed on the terminal equipment they use.

Users should have the opportunity to refuse the storage of cookies or similar devices on their terminal equipment. This is particularly important where users other than the original user have access to the terminal equipment and therefore to any privacy-sensitive information stored on it.

Information and the right to refuse may be offered once for the use of various devices to be installed on the user’s terminal equipment during the same connection, also covering any further use of those devices during subsequent connections.

Methods of providing information, offering the right to refuse or requesting consent should be made as user-friendly as possible.

Access to specific website content may still be made conditional upon informed acceptance of a cookie or similar device where it is used for a legitimate purpose.

- Data relating to subscribers are processed within electronic communications networks for the purposes of establishing connections and transmitting information containing details concerning the private lives of natural persons and their right to respect for their correspondence, or concerning the legitimate interests of legal persons.

Such data may be stored only to the extent necessary for the provision of the service, for billing and interconnection payments, and only for a limited period.

Any further processing of such data that a provider of publicly available electronic communications services may wish to carry out for the marketing of electronic communications services or for the provision of value-added services may be permitted only where the subscriber has consented to it on the basis of accurate and complete information provided by the service provider concerning the types of further processing it intends to carry out and the subscriber’s right not to give or to withdraw consent to such processing.

Traffic data used for marketing communications services or for the provision of value-added services should also be erased or made anonymous after the provision of the service.

Service providers should always keep subscribers informed of the types of data they process, the purposes of processing and the period for which such processing is carried out.

- The exact point at which the transmission of a communication is completed, after which traffic data should be erased except for billing purposes, may depend on the type of electronic communications service provided.

For example, in the case of a voice telephony call, transmission is completed as soon as either user terminates the connection.

For electronic mail, transmission is completed as soon as the addressee retrieves the message, typically from the server of their service provider.

- The obligation to erase traffic data or render such data anonymous when they are no longer required for the purpose of transmitting a communication is not inconsistent with Internet procedures such as caching IP addresses in the domain name system, caching IP addresses for the purpose of linking physical addresses, or using log-in information to control access rights to networks or services.

- A service provider may process traffic data relating to subscribers and users where necessary in individual cases in order to detect a technical fault or errors in transmission.

Traffic data for billing purposes may also be processed by a provider in order to detect and stop fraud involving unpaid use of electronic communications services.

- Where a provider of electronic communications services or a value-added service subcontracts to another entity the processing of personal data necessary for the provision of those services, such subcontracting and subsequent processing of data should fully comply with the requirements relating to Controllers and Processors of personal data.

Where the provision of a value-added service requires traffic or location data to be forwarded from an electronic communications service provider to a value-added service provider, the subscribers or users to whom such data relate should also be fully informed of such forwarding before giving their consent to the processing of the data.

- The introduction of itemised billing has improved subscribers’ ability to verify the accuracy of charges imposed by service providers, but at the same time it may jeopardise the privacy of users of electronic communications services.

- With regard to calling-line identification, it is necessary to protect the right of the calling party to prevent the presentation of the identification of the line from which the call is made, and the right of the called party to reject calls from unidentified lines.

There are grounds for overriding the elimination of calling-line identification presentation in specific cases.

Certain subscribers, particularly helplines and similar organisations, have an interest in guaranteeing the anonymity of callers.

With regard to connected-line identification, it is necessary to protect the right and legitimate interest of the called party to prevent presentation of the identification of the line to which the calling party is actually connected, particularly in the case of forwarded calls.

Providers of publicly available electronic communications services should inform their subscribers of the existence of calling and connected-line identification within the network, of all services offered on the basis of calling and connected-line identification, and of the available privacy options.

This enables subscribers to make an informed choice regarding the privacy facilities they may wish to use.

- In digital mobile networks, location data providing the geographical position of a mobile user’s terminal equipment are processed in order to enable the transmission of communications.

In addition, digital mobile networks may have the capacity to process location data that are more precise than necessary for the transmission of communications and that are used to provide value-added services, such as services providing individualised traffic information and guidance to drivers.

Processing of such data for value-added services should be permitted only where subscribers have given their consent.

Even where subscribers have given their consent, they should have a simple means of temporarily refusing the processing of location data free of charge.

- States may restrict users’ and subscribers’ privacy rights with regard to calling-line identification where necessary for tracing nuisance calls and, with regard to calling-line identification and location data, where necessary to enable emergency services to perform their tasks as effectively as possible.

For these purposes, States may adopt specific provisions authorising electronic communications service providers to provide access to calling-line identification and location data without the prior consent of the user or subscriber concerned.

- Subscribers should be provided with safeguards against nuisance that may be caused by automatic forwarding of calls by others.

Furthermore, in such cases, subscribers must be able to stop forwarded calls from being passed to their terminal by making a simple request to the provider of the publicly available electronic communications service.

- Safeguards should be provided for subscribers against intrusion into their privacy through unsolicited communications for direct marketing purposes, particularly through automated telephone calls, fax and electronic mail, including SMS messages.

Such forms of unsolicited commercial communications may, on the one hand, be relatively easy and inexpensive to send while, on the other hand, imposing a burden and/or cost on the recipient.

Moreover, in some cases their volume may also cause difficulties for electronic communications networks and terminal equipment.

For such forms of unsolicited communications for direct marketing purposes, it is justified to require the recipients’ explicit prior consent before such communications are sent to them.


*10 List of domains:

https://cellulestaminali-clinica.com/


“Electronic communications identifier” includes, without limitation, other types and forms of identifying individuals on the basis of their devices, applications, tools and protocols, such as Internet Protocol addresses, cookie identifiers or other identifiers such as radio-frequency tags, biometric data obtained from “smart cameras”, etc.


*11 Information on the purposes of processing contains a description of the purpose for which personal data are collected in a particular data collection, together with an indication of whether the purpose of processing is prescribed by law or determined by the Controller with the consent of the data subject or another authorised person.


*12 Decision appointing a person responsible for maintaining documentation, entering data and handling data.


*13 Statement of the person from whom the data entered into health documentation are obtained.