Client Portal — Data Processing Notice

Version 1.0 · effective 21 September 2026

This notice has been prepared in Polish and English. In the event of any discrepancy, the Polish version prevails.

Controller. Healthcare Poland Foundation, seated in Warsaw, KRS 0001066269. Contact on data protection matters: global@healthcarepoland.pl.

Source of your data. Directly from you — from the access request form, from correspondence and from your use of the Portal.

Purposes and legal bases

PurposeLegal basisRetention period
Examination of an access requestArticle 6(1)(b) GDPR — steps prior to entering into a contract3 years from examination of the request
Maintaining the Account and providing the serviceArticle 6(1)(b) GDPRduration of the agreement
Verification of authorisation and risk assessmentArticle 6(1)(f) GDPR — protection of the Foundation’s resources3 years from completion of verification
Security, access logs, abuse detectionArticle 6(1)(f) GDPR12 months
Analyses, statistics, research and service developmentArticle 6(1)(f) GDPR, with safeguards under Article 89(1)until anonymisation, no longer than 3 years
Handling complaintsArticle 6(1)(b) and (c) GDPR3 years from conclusion of proceedings
Establishment, exercise and defence of claimsArticle 6(1)(f) GDPRuntil limitation, and in the event of a dispute — until its final conclusion
Compliance with legal obligationsArticle 6(1)(c) GDPRperiod required by law

How we process your data

We process your data manually, by machine, in an automated manner and using artificial intelligence systems — within the scope set out in § 8 of the Client Portal Terms of Use.

We do not take decisions concerning you based solely on automated processing which would produce legal effects concerning you or similarly significantly affect you. Decisions on granting, restricting and withdrawing access are taken by an authorised member of the Foundation’s staff, who may change the outcome of an automated tool.

We do not use your data to train, fine-tune or evaluate artificial intelligence models. Content generated or materially processed by such systems is marked as such.

Recipients

Providers of hosting and system maintenance, e-mail providers, providers of analytics and artificial intelligence tools, providers of legal and accounting services, and public authorities to the extent required by law. Each processes data under a data processing agreement or as a separate controller.

Transfers outside the European Economic Area

A transfer may take place solely on the basis of a European Commission adequacy decision or standard contractual clauses, following a transfer impact assessment. A copy of the safeguards is available upon request sent to our contact address.

Your rights

You have the right of access to your data, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interest — on the terms set out in Articles 15–22 GDPR.

You also have the right to lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland), and with the supervisory authority in your country of habitual residence or place of work.

Whether providing data is obligatory

Providing data is voluntary but necessary in order to examine an access request and maintain an Account. Failure to provide it makes use of the Portal impossible.

Third-party data

The Portal is not intended for the transfer of third-party personal data, in particular health data. Providing such data without a separate data processing agreement constitutes a breach of the Terms; we delete such data immediately upon detection.