Dr. Schirmer Clinic
Privacy Policy
Introduction.
We value and protect your privacy. We always strive to maintain a high level of data protection (for example, we will never sell your personal information to another company). In this privacy policy, we outline your privacy rights and how we collect, use, disclose, transfer, and store your personal data, and we describe your rights and how to exercise them. In order for Medyk Läkartjänster AB to conduct its business and provide services, we must process personal data while bearing a great responsibility to ensure the proper and secure processing of your personal data. We want you all to feel secure in your dealings with Medyk Läkartjänster AB—this is our top priority. It is important that you read, understand, and accept our privacy policy, knowing that we process your personal data with care for every relevant detail in accordance with the applicable laws of Sweden. If you have any further questions, you can always contact us by sending an email to: gdpr.dr.schirmerclinic@gmail.com.
Terms used in this policy.
When we say “Medyk Läkartjänster AB,” “we,” “our,” or “us,” we are referring to Medyk Läkartjänster AB, Bankgatan 15A, 223 52 Lund, Sweden. Organization number: (559064-8233), which is the entity responsible for processing your personal data.
When we say “website,” “sales platform,” or “service,” we mean all of our web pages and subpages, applications, and other services provided by Medyk Läkartjänster AB, which you can access by visiting our “website,” “sales platform” at www.drschirmer.com. This privacy policy does not apply to our current employees or future job applicants.
Third-party websites.
Our platform may contain links to other websites, but this does not mean that we endorse them or have any affiliation with them. We encourage you to review the privacy policies of these websites, as their procedures for collecting, processing, and handling personal data may differ from ours.
1. What is personal data, and what is data processing?
Personal data is any information that can be directly or indirectly attributed to a living natural person. For example, images and audio recordings processed on a computer may constitute personal data, even if they do not contain names. Encrypted data and various types of electronic identifiers (e.g., IP addresses) are personal data if they can be linked to natural persons. The processing of personal data refers to any action taken with respect to personal data. Any action taken on personal data constitutes processing, regardless of whether it is automated or not. Examples of typical processing operations include, among others, collection, recording, organization, structuring, storage, processing, transmission, and erasure.
2. Who is responsible for the personal data we collect?
Medyk Läkartjänster AB, corporate identification number (Org.nr): (559064-8233), is the data controller that processes your personal data in accordance with this privacy policy.
3. Data Protection Officer.
Medyk Läkartjänster AB has appointed a Data Protection Officer whose role is to advise and monitor Medyk Läkartjänster AB’s compliance with the General Data Protection Regulation and other related regulations. The data controller decides how and why your personal data is used and is responsible for ensuring that it is processed correctly. The data processor acts on the instructions of the data controller regarding the processing of your data. These definitions are taken from the General Data Protection Regulation (Regulation (EU) 2016/679) . You may contact the Data Protection Officer if you have any questions regarding the processing of personal data by Medyk Läkartjänster AB, or if you wish to exercise any of your rights related to the processing of personal data. The easiest way to contact the Data Protection Officer is to send an email to gdpr.dr.schirmerclinic@gmail.com.
4. Where—and how—does Medyk Läkartjänster AB collect your personal data?
In connection with your interactions with Medyk Läkartjänster AB, we receive information directly from you. We may also receive information from third parties for the purpose of fraud detection and investigation, including Google ReCAPTCHA. We also automatically generate or collect information from your computer or device when you use our services, such as your IP address, your location, interaction patterns (such as mouse movements and typing rhythm), information about your device and browser specifications, which you use to access Medyk Läkartjänster AB’s content, as well as usage and profiling information, such as your interaction with our platform or marketing emails you receive, or when you use our other services. If you apply for a position at Medyk Läkartjänster AB, we will receive personal data directly from you through your application, resume, cover letter, and information provided during interviews or in forms as part of the recruitment process. Where applicable, we may also receive information from references you have provided or from recruitment agencies (external partners working with Medyk Läkartjänster AB).
5. Consistent medical records.
If you are a patient, we process the information necessary to provide and manage your care, and this information is documented in your medical records as needed. In Medyk Läkartjänster AB’s medical records system, it is important that your contact information is accurate and up to date. Therefore, we collect information about you (name, contact information, medical records, and other information) that you voluntarily provide in order to provide you with the highest level of service in accordance with Medyk Läkartjänster AB’s highest standards. With your consent, Medyk Läkartjänster AB may collect information about you from other healthcare providers and medical service providers. Access via the integrated medical records system requires that we have an active patient relationship with you, in which we assume that the information we collect is relevant to the care we intend to provide you through our services, and that we have obtained your consent first and foremost. For minor patients who cannot give consent on their own, consent is not required to grant access. You have the right to object to the collection of medical records by blocking access to your medical records.
6. Personal Information.
When we refer to “private personal data,” we mean personal data that we do not publish on our website. This may include, among other things,
a). User Account Information: Your password, your username.
b). Contact Information. Your first and last name, email address, or other contact information that you may provide to us from time to time, whether you provide it directly on the www.drschirmer.com website or through various social media platforms, for example.
c). Banking information. Your bank account number or payment card number, if necessary (to charge your bank account), for the purpose of processing payments for e-learning services and/or other services.
d). Call Recording. All incoming and outgoing phone or video calls made by Medyk Läkartjänster AB, or by us, may be recorded for training, quality control, and regulatory compliance purposes. Personal information (such as your first and last name and contact information) disclosed during a phone call may be digitally recorded in order to provide the appropriate services.
If you have a business account on our website www.drschirmer.com, we may also collect the following personal information,
a). Business account information. Your password, your first and last name, and your company information. Your verification information, such as,
b). Your contact information.
c). Photos of documents you have uploaded. Your image, if you contact us, for example, via Google Meet or another similar service.
d). Your age and date of birth.
e). Your bank account information (if you purchase a product or service—or multiple products or services—directly through our website or sales platform).
7. For what purposes and on what legal basis does Medyk Läkartjänster AB process and use your personal data?
We may use your personal data for the following purposes. Personal data may only be processed for specific, explicit, and legitimate purposes. It is not permitted to collect more personal data than is necessary to achieve the purpose. Data may also not be stored longer than necessary or processed in a manner other than that originally intended. We pursue our legitimate business interests, including, but not limited to, operating our website, our sales platform, and providing services to you. When processing your personal data based on a legitimate interest, we will do so only if the processing is relevant, appropriate, and limited to what is necessary for the purpose for which it was collected. Of course, we always ensure that our legitimate interests do not unfairly infringe upon your rights.
To fulfill our agreement with you or your company; if you do not provide us with the information necessary to fulfill our agreement, it may be impossible to do so, which means that we will not be able to provide you with the appropriate services, comply with our legal rights and obligations, communicate on our website and sales platform in accordance with applicable laws, perform tasks in the public interest, and, if necessary, establish, enforce, or defend legal claims.
If you have explicitly consented to our processing of your personal data, for example, by subscribing to our newsletter or registering a purchase and/or online purchases, or by accepting certain cookies on your device, you may withdraw your consent at any time by contacting us (see Section 21, “Contact”). Please note, however, that we may continue to process your data for other purposes based on a different legal basis, as described in our privacy policy. You have the right to object to the way we process your personal data or to request that we restrict such processing. For more information, see Section 16, “Your Rights.”
1. Goal: Primary – overarching.
a). We provide our services to you, including granting you access to your user account on our website or sales platform, or providing you with access to your company’s business account on our website, sales platform. In connection with the above, we may verify your identity to ensure the accuracy of your personal data.
b). We identify you as a registered user when you log in to our sales platform and return to it. We answer your questions and provide customer service. We send you our newsletters and other marketing materials.
c). We personalize your experience on our e-commerce platform, for example, by tailoring content and recommendations based on your interactions with our services. When you complete our surveys, we collect feedback that helps us improve our products and/or services.
d). We manage our operations and services by analyzing data and conducting internal audits to detect potential fraud and bots, in order to ensure the security of our sales platform. For example, on our website and sales platform, we may use Google reCAPTCHA to prevent abuse by automated software (bots).
e). To improve or modify our sales platform, products, and services. We identify and analyze usage trends and assess the effectiveness of our promotional campaigns.
f). To understand customer attitudes toward our products and services, as well as to conduct and develop our business activities with current and target customers of our e-learning services. This includes presentations of third-party products that we do not own and case studies. Staff training and quality control help us improve the quality of our services.
g). Also, to exercise or enforce our own legal rights or obligations in connection with legal claims, or for compliance, regulatory, and auditing purposes, as necessary. For example, we may disclose or retain information when required by law, a court order, or a regulatory authority.
In some cases, with your consent and in accordance with the law, we may also use your personal data to conduct scientific research and analyses in collaboration with Medyk Läkartjänster AB’s partners, such as universities, business partners, and other institutions.
h). If you have a user account, we may also use your personal information to notify you about new products and/or services we offer.
i). We may also use additional information about the processing of your personal data and information about you in other ways, which we will disclose to you at the time of collection. To achieve the above purposes, including, for example, the automatic detection of false or fraudulent content, we may use automated means, including machine learning and artificial intelligence. Automated data processing by Medyk Läkartjänster AB will always be in full compliance with applicable laws.
2. Objective: Priority – Key (Provision of medical services).
As a provider of aesthetic medicine services (by definition: “Aesthetic medicine is a branch of medicine focused on improving a patient’s appearance and well-being through non-invasive or minimally invasive procedures”) and, including post-treatment healthcare, Medyk Läkartjänster AB processes your personal data, for example, to provide medical advice and consultations. The processing of personal data in healthcare requires explicit legal authorization. As a provider of the aforementioned services, Medyk Läkartjänster AB is subject, among other things, to the Patient Data Act (2008:355, “PDL”) and the regulations and general guidelines of the National Board of Health and Welfare (HSLF-FS 2016:40) regarding record-keeping and the processing of personal data in healthcare. Patient data may be processed (and accessed exclusively) only by personnel who need it to perform their duties as part of Medyk Läkartjänster AB’s operations, where, within the scope of our services, patient data is processed for the following purposes:
a). Maintaining medical records and other documentation necessary for your care.
b). The collection of images and data in medical technology systems (e.g., X-ray images, magnetic resonance imaging (MRI) images, and computed tomography (CT) images).
c). Administrative tasks related to your care (e.g., sending notifications and processing payments).
d). Preparing documentation required by law, regulations, or other legal acts.
e). Systematic and continuous development and quality assurance in the services we provide.
f). Administration, planning, monitoring, evaluation, and oversight of activities.
g). Compiling statistics on health, medical care, and post-operative care.
Legal basis: We process data regarding your care and treatment pursuant to Article 6(1)(e) of the GDPR (processing is necessary for the performance of a task carried out in the public interest). In the case of privately funded and insurance-covered healthcare, personal data is processed pursuant to Article 6(1)(c) of the GDPR (processing is necessary for compliance with a legal obligation).
The processing of sensitive personal data, such as health data, takes place when it is necessary for the provision of health care (Article 9(2)(h) of the GDPR).
Categories of personal data, such as first and last name, home address, phone number, email address, gender, age, identification data, social security number, health information, images (e.g., X-rays and ultrasound images), and payment information. Retention period. Medical records must be retained for at least ten years from the date of the last entry (Chapter 3, § 17 of the Swedish Medical Records Act). Data regarding payments for medical care is retained for the period required by the Accounting Act, i.e., seven years. Personal data processed for other purposes mentioned above (quality improvement, administration, monitoring, etc.) is processed only for as long as necessary to achieve the specific purpose.
3. Purpose: Reporting to national quality registries.
Medyk Läkartjänster AB reports specific patient data to national quality registries. National quality registries collect personal data for the purpose of systematic and continuous improvement and quality assurance in healthcare, as well as to enable comparisons within the healthcare system at the national or regional level. Legal basis: The processing of personal data is necessary for the performance of a task carried out in the public interest (Article 6(1)(e) of the GDPR). The specific legal basis is set forth in Chapter 7 of the Swedish Personal Data Act.
4. Categories of personal data. Health-related data.
Participation in quality registries is voluntary. You always have the option to decline participation in quality registries without it affecting the quality of care you receive. Contact the facility you visited if you have questions about quality registries or if you do not want your data to be included in national quality registries.
5. Purpose: Research.
Medyk Läkartjänster AB occasionally processes patient data as part of ethically approved research studies. Legal basis: The processing of personal data is necessary for the performance of a task carried out in the public interest (Article 6(1)(e) of the GDPR). The processing of sensitive personal data, such as health data, is necessary for scientific or historical research purposes (Article 9(2)(j) of the GDPR).
For the processing of personal data for research purposes to be permitted, it must be authorized under the Act (2003:460) on the Ethical Review of Research Involving Human Subjects (the Ethical Review Act). The personal data being processed must be necessary to achieve the specific purpose, i.e., the specific research study. Categories of personal data: The categories of data specified in the approved ethics application, such as health data and identity data.
Retention period: As long as the processing of personal data is necessary to conduct a specific study. The retention period must be specified in the information provided to study participants and must be consistent with the approved ethics application.
6. Purpose: Administrative matters related to the proper operation of the company or other organizational issues.
7. Purpose: To assist you in using Medyk Läkartjänster AB’s communication services, appointment scheduling services, etc.
Occasionally, our patients need to contact us regarding matters related to Medyk Läkartjänster AB’s communication services, appointment scheduling, and similar issues. Legal basis: If a given service is related to healthcare, Medyk Läkartjänster AB processes personal data based on our right to process personal data in connection with the administration of your care as a patient, in accordance with the Personal Data Protection Act (PDL) and within the legal basis for the provision of healthcare (Article 6(1)(e)/6(c) supported by Article 9(2)(h) of the GDPR). The processing of personal data may also take place in other cases if required by law (Article 6(1)(c) of the GDPR, compliance with a legal obligation).
8. Purpose: The contact form on the Medyk Läkartjänster AB website.
On our website, a sales platform, patients may in the future be able to contact certain other facilities or websites owned by Medyk Läkartjänster AB through forms or “external links” that lead directly to those sites. When you submit your information to us via these forms, your personal data will be processed by employees of Medyk Läkartjänster AB. Legal basis. We process data regarding your care and treatment (appointment requests, etc.) under the legal basis for healthcare. For publicly funded healthcare, the legal basis is Article 6(1)(e) of the GDPR (processing is necessary for the performance of a task carried out in the public interest), and for privately funded and insurance-covered healthcare, it is Article 6(1)(c) of the GDPR (processing is necessary for compliance with a legal obligation).
Categories of personal data: Identity data (first and last name), contact information, and, in some cases, user data. There is a risk that some of the information you provide—even if you do not disclose diagnoses, medications, or other information directly related to health—may be considered health information, i.e., sensitive personal data. Medyk Läkartjänster AB recommends that communication regarding sensitive personal data take place directly with our employees and/or persons authorized by us. Your personal data will be stored in encrypted form on our website for the maximum period specified by law.
9. Purpose: Recruitment.
Medyk Läkartjänster AB processes the personal data of job seekers for the purpose of managing recruitment processes, evaluating applications, communicating with candidates, conducting interviews, and, if necessary, obtaining references. The processing of personal data is necessary to take steps at the request of the data subject prior to entering into a potential employment contract (Article 6(1)(b) of the GDPR) and, where applicable, following a balancing of interests against a legitimate interest. Medyk Läkartjänster AB, in connection with the administration and conduct of recruitment (Article 6(1)(f) of the GDPR). If Medyk Läkartjänster AB requests and retains application documents for future recruitment purposes after the recruitment process has ended, this is done solely with consent (Article 6(1)(a) of the GDPR), unless otherwise required by law. Categories of personal data: First and last name, contact information, information contained in the resume and cover letter, information about education, work experience, qualifications, references, and other information that the candidate provides as part of the recruitment process.
Retention period: Job seekers’ personal data is retained for the duration of the recruitment process and thereafter for as long as necessary to complete the process, pursue claims, or fulfill applicable legal obligations. If data is retained for future recruitment purposes, this is permitted only for the period for which the job seeker has given consent or in accordance with other legal requirements.
10. Purpose: To fulfill legal obligations.
Medyk Läkartjänster AB may process your personal data to comply with legal requirements, rulings, or decisions by authorities, such as in the context of oversight conducted by the Swedish Health and Social Care Inspectorate (IVO) or the National Board of Health and Welfare. We store and process your personal data to the extent necessary to fulfill our legal obligations and the requirements set forth in Swedish law, such as the Accounting Act (1999:1078). Legal basis: The processing of personal data is necessary for compliance with a legal obligation (Article 6(1)(c) of the GDPR). Categories of personal data: first and last name, home address, phone number, email address, gender, age, identity data, social security number, health information, images (e.g., X-rays, magnetic resonance imaging (MRI) scans, computed tomography (CT) scans), and payment information.
11. Who may have access to your personal data; Types of third parties that may access your personal data.
Your personal data at Medyk Läkartjänster AB is and will always be carefully protected (see Section 3, “Data Protection Officer”). Your personal data may only be disclosed in justified cases that are essential to the proper functioning of Medyk Läkartjänster AB’s internal departments; however, it may also be disclosed to other entities listed below. You can find information on how to opt out of certain types of processing (see Section 16, “Your Rights”).
a). Service providers we use (e.g., IT services, support, communications, and marketing).
b). IT security service providers, when required by law or to protect our services and rights. We may also share your data with third parties in connection with the investigation and enforcement of our rights before government authorities (prosecutor, court).
c). To third parties, so that we may pursue available remedies or limit any damages we may incur, in order to protect our rights, privacy, security, or property, and/or our intellectual property rights relating to, for example, e-learning courses and licenses.
d). When it becomes necessary to initiate legal proceedings.
e). IT service providers that systematically index web content to display it in search results or use it to train artificial intelligence models.
f). Advisors and potential buyers in connection with the sale or integration of a company.
g). Government agencies (e.g., the police, the Swedish Tax Agency), when required by law or in the event of a suspected crime. Cooperation with regulatory agencies, law enforcement agencies, and government authorities in connection with investigations or case management.
h). Certain employees of Medyk Läkartjänster AB will have access to your data to facilitate the activities through which we tailor our range of products and services specifically for you. In this case, access is limited to employees who have a legitimate business need for the information.
i). To third parties, so that we can detect, investigate, prevent, or take action regarding suspected or actual prohibited activities, including, but not limited to, fraud and misuse of our website and sales platform.
j). In justified cases, to partners of apps and platforms such as GOOGLE, YouTube, FACEBOOK, INSTAGRAM, TikTok—may be shared, provided this is related to the performance of tasks within the framework of sales-oriented e-learning courses on our website or on the sales platform owned by Medyk Läkartjänster AB.
Most of these entities are data processors and may process data only in accordance with our instructions and agreements. Responsibility for the further processing of data by independent data controllers rests with them.
Some of these data processors and third-party service providers will be located in countries other than the one where you live and may have different or less stringent data protection standards. However, subject to the local laws in those countries, we will ensure the necessary safeguards are in place to protect your data, regardless of location. We do this by combining appropriate technical, organizational, and administrative security measures and by implementing the necessary legal agreements to confirm these requirements. For example, we will transfer personal data of users from Europe outside the European Economic Area only if a transfer mechanism approved by the European Commission has been implemented.
12. How we protect the security of your personal data.
The security of your personal data is our top priority. At Medyk Läkartjänster AB, we implement a variety of organizational, technical, and administrative measures to protect your personal data within our organization, and we regularly conduct internal audits of our system to identify security vulnerabilities. The security team for our website and sales platform conducts vulnerability scans to detect vulnerabilities in Medyk Läkartjänster AB’s code. These scans are performed regularly to identify and address potential vulnerabilities.
13. Professional confidentiality.
The staff of Medyk Läkartjänster AB, (all employees, including medical staff such as doctors, consultants, etc.), are subject to statutory confidentiality obligations within the framework of healthcare activities in accordance with Chapter 6, Sections 12–14 and 16 of the Patient Safety Act (Patient Safety Act). This means that staff may not disclose, without authorization, information about patients that they have learned in the course of performing their duties at Medyk Läkartjänster AB. This applies to both information about patients’ health and other personal circumstances. For personal data other than patient data, access is restricted to individuals who need this information to perform their duties, and personal data is protected by appropriate technical and organizational security measures.
14. Where does Medyk Läkartjänster AB process your personal data?
Medyk Läkartjänster AB processes personal data primarily within the EU/EEA. When using IT service providers—for example, for operational and support services—we strive, to the extent possible, to ensure that these providers and any subcontractors store and process personal data exclusively within the EU/EEA. In exceptional cases, personal data may be transferred to countries outside the EU/EEA, for example, when we need to use the services of a provider that employs its own data processors (so-called subprocessors) located outside the EU/EEA or processes data in a country outside the EU/EEA. Any such transfer of personal data must be carried out in accordance with applicable law and without infringing upon your rights.
When transferring data to a country outside the EU/EEA (including the United States and the United Kingdom in the case of companies that are not part of the EU-US/UK Privacy Shield framework), compliance with the law is ensured primarily through the use of the European Commission’s standard contractual clauses for data transfers to third countries, as well as through additional technical and organizational security measures that ensure a high level of protection equivalent to that offered in the EU/EEA. On July 10, 2023, the European Commission issued a decision recognizing an adequate level of data protection with respect to the United States. The European Commission’s decision means that data transfers to organizations covered by the EU-U.S. Data Protection Framework may generally take place without the need for additional safeguards, such as the use of standard contractual clauses pursuant to Article 46 of the GDPR. Article 46 – Transfers subject to appropriate safeguards.
In the absence of a decision pursuant to Article 45(3), the controller or processor may transfer personal data to a third country or an international organization only if they provide appropriate safeguards and provided that enforceable rights of data subjects and effective legal remedies are in place.
1. The appropriate safeguards referred to in paragraph 1 may be ensured—without the need to obtain special authorization from the supervisory authority—by means of,
(a) a legally binding and enforceable instrument between public authorities or entities;
(b) binding corporate rules in accordance with Article 47,
(c) the standard data protection clauses adopted by the Commission in accordance with the examination procedure referred to in Article 93( 2,
(d) standard data protection clauses adopted by the supervisory authority and approved by the Commission in accordance with the examination procedure referred to in Article 93(2),
(e) an approved code of conduct pursuant to Article 40, together with binding and enforceable obligations on the controller or processor in a third country to apply appropriate safeguards, including with respect to the rights of data subjects, and/or,
(f) an approved certification mechanism in accordance with Article 42, together with binding and enforceable commitments by the controller or processor in the third country to apply appropriate safeguards, including with respect to the rights of data subjects.
2. Subject to obtaining authorization from the competent supervisory authority, the appropriate safeguards referred to in paragraph 1 may also be ensured, in particular, by means of,
(a) contractual clauses between the controller or processor and the controller, processor, or recipient of personal data in a third country or international organization, or,
(b) the provisions of administrative arrangements between public authorities or entities that provide for enforceable and effective rights for data subjects.
3. In the cases referred to in paragraph 3 of this article, the supervisory authority shall apply the consistency mechanism referred to in Article 63.
Authorizations issued by a Member State or a supervisory authority pursuant to Article 26(2) of Directive 95/46/EC shall remain in force until they are amended, replaced, or repealed, as necessary, by that authority. Decisions adopted by the Commission pursuant to Article 26(4) of Directive 95/46/EC shall remain in force until they are amended, replaced, or repealed, as necessary, by a Commission decision adopted in accordance with paragraph 2.
If an adequate level of data protection is not established, the controller or processor should implement measures to compensate for the lack of data protection in the third country, thereby providing the data subject with appropriate safeguards. Such appropriate safeguards may consist of binding corporate rules, standard data protection clauses adopted by the Commission, standard data protection clauses adopted by a supervisory authority, or contractual clauses approved by a supervisory authority. These safeguards should ensure that data protection requirements and the rights of data subjects are respected to the same extent as in the case of intra-Union processing, including ensuring the availability of enforceable rights of the data subject and effective legal remedies — including the right to effective administrative or judicial remedies and to claim compensation — within the Union or in a third country. These should relate, in particular, to compliance with the general principles governing the processing of personal data and the principles of data protection by design and data protection by default. Public authorities or bodies may also transfer data to public authorities or bodies in third countries or to international organizations with analogous obligations or functions, including on the basis of provisions that should be included in administrative arrangements, such as memoranda of understanding, and that should provide for enforceable and effective rights for data subjects. If safeguards are contained in non-legally binding administrative arrangements, authorization must be obtained from the competent supervisory authority.
The fact that a controller or processor may use standard data protection clauses adopted by the Commission or a supervisory authority should not prevent the controller or processor from incorporating those standard data protection clauses into a broader agreement, such as an agreement between that processor and another processor, nor should it prevent them from adding other clauses or additional safeguards, provided that they do not directly or indirectly conflict with the standard contractual clauses adopted by the Commission or a supervisory authority, nor do they infringe upon the fundamental rights or freedoms of data subjects. Controllers and processors should be encouraged to provide for additional safeguards through contractual commitments that supplement the standard contractual clauses.
15. How long does Medyk Läkartjänster AB retain your personal data?
We retain your data only for as long as necessary or as required by law. This depends on the reason for collecting it and whether we have a valid legal basis for doing so (e.g., to fulfill a contract between us, provide a requested service, comply with legal requirements, or pursue our legitimate interests). Once we no longer have a legitimate reason to retain your data, we will delete it or anonymize it to prevent you from being identified. We handle data differently depending on the purpose of its use, but you may delete your personal data or ask us to do so at any time (see Section 16, “Your Rights”). The personal data you provide is stored for as long as you have an account on Medyk Läkartjänster AB’s sales platform, or for as long as necessary to provide you with our services. If you delete your account on the Medyk Läkartjänster AB platform, we will retain certain information that is required by law or in which we have a legitimate interest. Reasons why we may retain certain data for a longer period include, among others, security, preventing fraud and abuse on the platform, complying with legal or regulatory requirements, and protecting our legitimate business interests. For patients, medical records must be retained for at least ten years from the date of the last entry made in the records.
For other categories of data subjects, such as job seekers, the retention periods specified for the relevant purposes apply. We minimize retention periods to the greatest extent possible.
16. Your rights as a registered user regarding the processing and storage of your personal data by Medyk Läkartjänster AB.
You have a number of rights regarding our processing of your personal data. These rights vary depending on the legal basis for the processing of personal data and the type of data being processed. This means that certain rights, such as the right to erasure, apply only to specific types of personal data and under certain conditions. In addition, specific regulations apply to patient data, including the Patient Data Protection Act. These rights may be limited, for example, if fulfilling your request would result in the disclosure of another person’s personal data, or if you ask us to delete information that we are required to retain by law or in pursuit of an overriding legitimate interest. You always have the right to obtain confirmation as to whether Medyk Läkartjänster AB is processing your personal data, and if so, to access that personal data as well as other information regarding it. We have included all necessary and important information in our “Privacy Policy,” where you can review the content in part or in full, including information regarding all of your rights.
Please indicate which right you wish to exercise. If your request contains sensitive personal data (e.g., information about your health), we recommend that you contact us by mail or phone. Your right to rectification. You have the right to request that Medyk Läkartjänster AB correct any inaccurate information. You also have the right to have missing personal data supplemented if it is relevant to the purpose of processing the personal data. Special provisions apply to information contained in medical records, including the Patient Data Protection Act.
Right to erasure. You have the right to contact Medyk Läkartjänster AB and request that your data be deleted. Data may only be deleted under specific circumstances. Under the Patient Data Act, medical records may be destroyed only after the IVO has reviewed a request for their destruction. (IVO—Inspektionen för vård och omsorg). The Swedish Health and Social Care Inspectorate.
Right to restrict processing. In certain cases, you have the right to request that the processing of your personal data be restricted. Restriction means marking the data in such a way that it may be processed in the future only for specific, limited purposes. The right to restrict processing applies, among other things, when you believe that the data we process about you is inaccurate and you have requested that it be corrected. In such cases, you may request that the processing of your data be restricted until its accuracy has been verified. You have the right to object. You have the right to object to our processing of your personal data. This right applies to personal data processed for the performance of a task carried out in the public interest or for purposes based on a legitimate interest.
You have the right to data portability. In some cases, you have the right to receive the personal data you have provided to Medyk Läkartjänster AB, in a structured, commonly used, machine-readable format, which you can then provide to another data controller (the so-called right to data portability). The right to data portability applies to personal data collected with your consent or for the purpose of fulfilling a contract. This right does not apply to personal data processed by Medyk Läkartjänster AB for the purposes of healthcare and other medical services.
You have the right to access your medical records. If you want to access your medical records, you can contact the clinic where you were treated and request a copy. Unless there are legal obstacles, you have the right to access your medical records as soon as possible.
In some cases, employees of Medyk Läkartjänster AB are not authorized, for organizational reasons, to access medical records belonging to other facilities, so if you have visited several different clinics, you may need to contact each one to obtain a copy of your medical records.
You have the right to obtain extracts from the registry. You have the right to receive information about what access has been granted to your medical records (so-called registry extracts).
You have the right to withdraw your consent. If we process your personal data based on your consent, you have the right to withdraw it at any time. This means that we must stop the ongoing processing of your personal data, but it does not affect the processing we have already carried out (prior to the withdrawal of your consent).
17. If you have any concerns or wish to file a complaint, exercise your rights.
If you have any questions or would like to file a complaint, please know that at Medyk Läkartjänster AB, we make every effort to process your personal data in the safest way possible and in accordance with applicable laws. If you have any questions regarding our processing of personal data or the content of this privacy policy, please contact us at gdpr.dr.schirmerclinic@gmail.com or by phone. If you are not satisfied with how Medyk Läkartjänster AB processes your personal data, or if you believe that Medyk Läkartjänster AB is not complying with legal requirements, please let us know. You also always have the right to file a complaint with the Swedish Data Protection Authority.
(https://www.imy.se IMY). To exercise your rights, please contact the Data Protection Officer at Medyk Läkartjänster AB. gdpr.dr.schirmerclinic@gmail.com.
Any disputes related to a purchase or purchases and the use of our website, the www.drschirmer.com platform, will be resolved primarily through negotiations between the parties. If no agreement is reached, you have the right to submit your case to the Swedish Complaints Board (www.arn.se ARN) or another appropriate dispute resolution organization.
18. Does Medyk Läkartjänster AB use cookies?
Medyk Läkartjänster AB uses cookies and similar technologies to facilitate the delivery, optimization, personalization, and analysis of our services, as well as for advertising purposes. We use a combination of cookies and other technologies, such as pixels and tracking codes, to collect information for use in accordance with the purposes set forth in this policy. Medyk Läkartjänster AB uses cookies to improve your experience on our website, www.drschirmer.com, measure website traffic, and support the marketing of our services. A cookie is a small amount of data, usually marked with a unique identifier (pixel). This data contains information about your visit to the website and is stored in your browser. When your browser reconnects to the same website, it sends a copy of this information. Medyk Läkartjänster AB may store cookies on your device only when it is absolutely necessary for you to use this website. For all other purposes (e.g., marketing), your consent is required. Cookies on our website and sales platform may be set by us, by third parties with whom we collaborate, or by independent third parties, such as advertisers.
What are pixels? Pixels are small, transparent image files on a website or in an email. We use them to understand how you use our services, including our marketing emails.
What are tracking codes? Tracking codes are snippets of code placed on a webpage that are used to measure factors such as visits and interactions. We use tracking codes to learn more about how you use our services, what ads you see, and, in general, how you use our platform.
For more information and details about the types of cookies and similar technologies we use, please see our “Cookie Policy” . By reading our “Cookie Policy,” you’ll learn how we handle cookies when you visit the website www.drschirmer.com, the purposes for which we use them, and how long we store them. There, you can also view and change your settings and withdraw your consent to the processing of your cookies by Medyk Läkartjänster AB.
19. Information for and about minors—children under the age of eighteen (18). Legal basis: Chapter 9, Section 1, of the Parental Code (Föräldrabalk (1949:381)).
Our platform is not intended for children under the age of 18, and we do not knowingly collect personal information from such children. If you learn that a child under the age of 18 has provided us with their personal information, please contact us using the contact information provided below.
20. Possible changes to the Privacy Policy of Medyk Läkartjänster AB.
This policy may be updated from time to time. Laws, regulations, and industry standards are subject to change, which may require us to make such updates, or we may make changes to our services or operations. Changes will be posted on this page, and we encourage you to review our Privacy Policy to stay informed. If we make changes that significantly affect your privacy rights, we will notify you separately, for example, by email or through our website or sales platform. Your continued use of our website, sales platform, or services after the publication or sending of a notice regarding changes to the Privacy Policy will constitute your acceptance of and consent to our updated Privacy Policy.
21. Contact Us. Information and contact details for Medyk Läkartjänster AB.
We strive to ensure that this information (all information communicated on our e-commerce platform’s website) is as clear and transparent as possible. However, if you still have questions about how we process your personal data, wish to exercise your rights under our Privacy Policy, or would like to speak with us about any matter, you can always contact us.
| Responsible Entity: Parent Company: |
|---|
| Medyk Läkartjänster AB. Bankgatan 15A, 223 52 Lund, Sweden. Website and sales platform: www.drschirmer.com, Phone: +46 76 579 38 56 |
| Original VAT Number SE559064823301. Registration number of the business, company, or corporation. Org. No.: (559064-8233). VAT: SE559064823301 / VAT OSS. |