Intimfyzio is now ToBe
Personal Data Protection (GDPR)
PERSONAL DATA PROCESSING POLICY
pursuant to Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (hereinafter referred to as the “GDPR”).
Controller(s)
Healthcare providers and providers of non-healthcare services operating within the private healthcare facility ToBe s.r.o., with its registered office at Stromová 7, 831 01 Bratislava, Company ID: 53 509 323, act as joint controllers within the meaning of Article 26 GDPR (hereinafter referred to as the “Controllers”) and process clients’ personal data under the conditions set out below.
Purpose and Legal Basis of Processing
The Controllers process clients’ personal data for the following purposes:
Provision of healthcare, related services (e.g. appointment booking), and maintenance of medical records
Clients’ personal data are processed without the need for the Client’s consent. The legal basis for such processing is compliance with the Controllers’ legal obligations (Article 6(1)(c) GDPR), in particular obligations arising from the following legal regulations:
- Act No. 576/2004 Coll. on Healthcare and Services Related to the Provision of Healthcare;
- Act No. 578/2004 Coll. on Healthcare Providers, Healthcare Professionals and Professional Organisations in Healthcare;
- Act No. 153/2013 Coll. on the National Health Information System.
The provision of personal data for this purpose is required by applicable legislation (legal obligation). If the Client fails to provide the required personal data, the Controller may refuse to provide healthcare services.
Provision of non-healthcare services, related services (e.g. service appointment booking), and maintenance of relevant records and documentation
The legal basis for processing is the performance of a contract and pre-contractual measures (Article 6(1)(b) GDPR), i.e. the fulfilment of the Controllers’ obligations arising from the service agreement concluded between the Controller and the Client.
Where personal data are processed in connection with a concluded contract for tax, accounting, and, where applicable, audit purposes, the legal basis for such processing is compliance with the Controllers’ legal obligations (Article 6(1)(c) GDPR), in particular obligations arising from the following legal regulations:
- Act No. 431/2002 Coll. on Accounting;
- Act No. 222/2004 Coll. on Value Added Tax;
- Act No. 250/2007 Coll. on Consumer Protection.
The provision of personal data necessary for the conclusion and subsequent performance of the contract and/or required by law constitutes a contractual and/or legal requirement. If the Client fails to provide the required personal data, the Service may not be provided.
Where the provision of non-healthcare services involves the processing of special categories of personal data (i.e. sensitive personal data, such as health-related data), the legal basis for such processing is the Client’s consent (Article 6(1)(a) and Article 9(2)(a) GDPR), which the Client provides in writing in advance.
Marketing purposes – sending newsletters
The legal basis for processing is the Client’s consent, which the Client provides either in writing or electronically through the Controllers’ website by subscribing to the newsletter.
No automated decision-making, including profiling, is carried out in connection with the processing of personal data.
Personal Data Retention Period
Personal data are retained for no longer than is necessary to fulfil the purpose for which they are processed.
Personal data processed for the purpose of providing healthcare are retained by the Controllers in accordance with Section 22(2) of Act No. 576/2004 Coll. for a period of 20 years from the date of the last provision of healthcare to the Client.
Personal data processed for the purpose of fulfilling contractual obligations are retained by the Controllers for the duration of the contractual relationship and subsequently only for the period necessary to resolve mutual rights and obligations, including, for example, the exercise of rights arising from liability for defects (complaints).
Personal data processed on the basis of the Client’s consent are retained by the Controllers for the duration of the consent. If the Client wishes to withdraw consent, they may do so at any time by sending a written withdrawal of consent to the Controllers. Consent for marketing purposes may also be withdrawn by clicking the relevant link included in each newsletter.
Following withdrawal of consent, the Controllers shall cease processing the relevant personal data unless another legal basis exists for their continued processing. Withdrawal of consent shall not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
Recipients of Personal Data
The Controllers do not disclose or make Clients’ personal data available to any third parties, except for persons designated by law and processors who ensure the fulfilment of the Controllers’ legal and contractual obligations and who have entered into a personal data processing agreement with the Controllers.
Such persons shall have access only to the personal data necessary for the performance of their agreed activities. They may not use such personal data for any other purpose and are obliged to process the personal data in accordance with applicable legal regulations.
Personal data are not transferred to third countries (i.e. countries outside the European Union) or to international organisations.
Rights of the Data Subject
The Client, as the data subject, has the following rights:
- the right of access to personal data (including the right to receive a copy of personal data) and the right to information regarding the conditions of personal data processing, to the extent provided for in Article 15 GDPR;
- the right to request the rectification or completion of incorrect or incomplete personal data;
- the right to erasure of personal data under the conditions set out in Article 17 GDPR;
- the right to restriction of processing of personal data under the conditions set out in Article 18 GDPR;
- the right to data portability under the conditions set out in Article 20 GDPR.
If the Client believes that the processing of their personal data violates the GDPR, they have the right to lodge a complaint with the supervisory authority, namely the Office for Personal Data Protection of the Slovak Republic, with its registered office at Hraničná 12, 820 07 Bratislava 27, and available at www.dataprotection.gov.sk.
If the Client has any questions or uncertainties regarding the processing of personal data or wishes to exercise their rights as a data subject, they may contact any of the Controllers by e-mail or in writing by sending a letter to the address of the healthcare facility. Current contact details are available on the website www.tobe.sk.
Validity and Updates
These Personal Data Processing Principles are effective from 1 June 2026.
The Controllers regularly review and assess their personal data processing and protection procedures. Therefore, these Personal Data Processing Principles may be updated from time to time. If an update involves material changes, the Controllers shall inform Clients accordingly.
The current version of these Personal Data Processing Principles is always available on the healthcare facility’s website.
