Having regard to the principles of lawful, fair and transparent use of personal data, to the right to privacy of Service Users in collecting, using, preserving and protecting the personal data of Service Users and in accordance with the Law on Personal Data Protection (“Official gazette of RS”, no. 97/08, 104/2009 - other law, 68/2012 –decision of the CC and 107/2012) and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 On The Protection Of Natural Persons with regard to the Processing of Personal Data and on the Free Movement of such Data, and Repealing Directive 95/46/EC (General Data Protection Regulation) the director of the Specialized Gynaecological Hospital “Genesis” Novi Sad with the seat in Novi Sad, 4 Uroš Predić Street (hereinafter reffered to as: Genesis) pursuant to art. 7.10, item 7 of Articles of Incorporation of Specialized Gynaecological Hospital “Genesis” Novi Sad, on the July 24th 2018 adopts the following:Having regard to the principles of lawful, fair and transparent use of personal data, to the right to privacy of Service Users in collecting, using, preserving and protecting the personal data of Service Users and in accordance with the Law on Personal Data Protection (“Official gazette of RS”, no. 97/08, 104/2009 - other law, 68/2012 –decision of the CC and 107/2012) and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 On The Protection Of Natural Persons with regard to the Processing of Personal Data and on the Free Movement of such Data, and Repealing Directive 95/46/EC (General Data Protection Regulation) the director of the Specialized Gynaecological Hospital “Genesis” Novi Sad with the seat in Novi Sad, 4 Uroš Predić Street (hereinafter reffered to as: Genesis) pursuant to art. 7.10, item 7 of Articles of Incorporation of Specialized Gynaecological Hospital “Genesis” Novi Sad, on the July 24th 2018 adopts the following:
RULEBOOK ON PROTECTION OF PERSONAL DATA OF SERVICE USERS
Article 1
Scope
This Rulebook is applied to all personal data of Service Users which Genesis collects through any form of communication. The provisions of this Rulebook shall apply to any automated processing, as well as to processing incorporated in non-automated data files.
Article 2
Obligation to collect personal data and the use of personal data
Providing personal data is based on a consent, but it is a necessary requirement for Genesis to provide its services to Service Users.
Genesis shall use the personal data of Service Users only in ways that are compatible with the purpose for which they were collected or for which Genesis has been authorized by the Service User in accordance with the law, other regulations, and EU standards.
Genesis uses collected personal data solely in order to provide its services. Personal data is used to keep records of Service Users having regard to their right to privacy.
Personal data can also be used to provide information about news related to Genesis and Genesis offers to Service Users.
Genesis may provide collected personal data to the competent state authorities on their demand in accordance with the law, other regulations and EU standards.Genesis cannot provide nor sell collected personal data to third parties without prior written consent of the Service User with the exception stipulated in paragraph 5 of this article.
Article 3
Consent of the Service User
Genesis collects and processes personal data of Services Users solely on the basis of their written consent. Prior to the provision of services, the Service User signs the Statement on the Acceptance of the Use and Processing of Personal Data in the manner and for the purpose determined by this Rulebook.
Article 4
Types of personal data
Genesis collects and processes following types of personal data from Service Users:
1) First name2) Last name3) Date of birth4) Gender5) Unique personal identification number or other personal number if the Service User is a foreign citizen6) Address7) Phone number8) E-mail address9) The IP address of each individual access to the website https://genesis.rs/ including cookie data
Article 5
Data Protection Officer Genesis shall appoint the Data Protection Officer within a period of 3 days from the adoption of this Rulebook by a special decision.
When signing a Statement on the Acceptance of the Use and Processing of Personal Data, the Service User is informed of the identity of the Data Protection Officer and how to contact him.
Data Protection Officer is responsible for ensuring that the personal data of the Service User are used in accordance with this Rulebook, the law and the applicable EU standards.
Data Protection Officer also performs other duties determined by this Rulebook.
Article 6
Addressing the Data Protection Officer
The Service User addresses the Data Protection Officer in order to realise all the rights stipulated by this Rulebook, the Law on Personal Data Protection and the applicable EU standards.
Addressing is done directly, by mail or by e-mail. The Data Protection Officer shall have a personal e-mail address which will be displayed on the website https://genesis.rs/ and of which Service Users will be informed when signing the Statement on the Acceptance of the Use and Processing of Personal Data.
Article 7
Data Security
Genesis applies security measures and reasonable precautionary measures to prevent loss, misuse, and unauthorized access to personal data of Service Users.
In case of data security breach, the Data Protection Officer informs the Commissioner for Information of Public Importance and Personal Data Protection without delay and takes other necessary measures to minimize the security breach and further protection of personal data.
Article 8
Withdrawal of Consent and the Right to Erasure
The Service User has the right to withdraw his consent for the use and processing of personal data at any time without affecting the legality of processing prior to withdrawal.
Consent shall be withdrawn in writing via the Data Protection Officer.
The Service User is entitled to have his personal data erased from the Genesis record upon his request. The request shall be submitted in writing via Data Protection Officer.
Article 9
Right to rectification
The Service User has the right that the personal data which he provided are accurate and complete.
The Service User has the right that the personal data which he provided are to be rectified without delay if they are inaccurate. The Service User has the right that the personal data which he provided are to be updated if they are incomplete. The Service User who wants his personal data to be rectified or updated addresses the Data Protection Officer who without delay rectifies or updates collected data.
Article 10
Newsletter Subscription
A person who applies to receive information from Genesis (Newsletter) on the website https://genesis.rs/ accepts that his e-mail, IP address and other personal data will be used for the purpose of informing about news related to Genesis and relevant offers.
When applying to the Newsletter, the person is given the opportunity to decide if he accepts that his e-mail, IP address and other personal data will be used as described in paragraph 1 of this article.
The person referred to in paragraph 1 of this article shall enjoy all the rights prescribed by this Rulebook.
Rules that govern Newsletter apply accordingly to contacting Genesis through the contact form on the website.
Article 11
Right to Protection
Service User has the right to address the Commissioner for Information of Public Importance and Personal Data Protection if he believes that his personal data is not used in accordance with the Law on Personal Data Protection and this Rulebook.
Article 12
Final Provisions
All matters not explictly regulated by this Rulebook are governed by the regulations of the Republic of Serbia and the applicable EU standards regarding the personal data protection.
The Rulebook will be available on the website of Genesis from the day of its adoption. A copy of this Rulebook shall be provided to the Service User when signing the Statement on the Acceptance of the Use and Processing of Personal Data.
This Rulebook shall enter into force on the day of its adoption.
In Novi Sad, July 24th 2018
For Specialized Gynaecological Hospital “Genesis” Novi Sad,director: