General
- Who is responsible for processing your data?
- OPENHEALTHCARE S.L. (hereinafter opensalud).
- Postal address
- Avda. República Argentina 25 9th floor, 41011 Seville, Spain.
- [email protected]
- DPO
- GRUPO INGERTEC — [email protected]
In order to browse the website, you must be a registered user and accept the privacy rules detailed below. By registering, you agree that opensalud will store and process the personal data you provide us with in accordance with the privacy policy.
The legal basis for processing your data is the data subject’s consent.
Data is processed for the following purposes:
- Carrying out medical consultations and managing appointments and services that are the subject of the platform’s activity.
- Carrying out statistical and historical studies by opensalud. Any reports generated will always be aggregated and anonymised.
- Sending communications of interest to users regarding how the platform works (usage tips, improvements introduced, etc.).
- Sending electronic communications the user has previously subscribed to, in compliance with Spanish Law 34/2002, of 11 July, on Information Society Services and Electronic Commerce (LSSICE).
We may send you communications related to the provision of the service, such as appointment reminders, notices or service quality information necessary for the correct functioning of your account. These communications are not commercial in nature and are essential for managing the service requested.
We will only send promotional or non-essential communications when we have your prior consent. At any time, you may exercise your rights to object, erase or withdraw consent regarding these non-essential communications, following the instructions included in each message or by contacting us through the channels indicated in this Policy.
All users who establish any form of communication, whether through the forms on the website or through alternative means, should be aware that their data may be collected for processing by this platform.
Opensalud processes data confidentially and adopts appropriate technical and organisational measures to guarantee a level of security appropriate to the processing, in compliance with applicable Data Protection regulations. Openhealth holds ISO 27001 certification.
However, no system can guarantee absolute invulnerability; therefore, opensalud assumes no liability for damages arising from alterations that third parties may cause to the user’s computer systems, electronic documents or files.
How long is the data retained for?
The personal data provided will be retained for as long as the user remains active on the platform (has not requested to unsubscribe) and for the periods necessary to comply with legal obligations regarding the safekeeping of clinical and administrative information.
Data collected to respond to your request, query or enquiry about our products and services will be retained indefinitely until, where applicable, you inform us of your wish to have it deleted.
Data sharing and international transfers
Any data collected by opensalud will under no circumstances be shared with third-party companies, except for the exceptions set out below:
- Where the portal has previously requested it from the data subject and the data subject has expressed their agreement, whether that request is individual or general in nature. In any case, opensalud will never share any data for advertising purposes.
- When they relate to the exceptions provided for under applicable regulations.
- Through contracts with third-party companies, for analytics services, for purely statistical and service-improvement purposes and never for advertising.
- To healthcare professionals and centres registered on the platform for the purpose of arranging and carrying out medical appointments, for a period of one year from the last explicit consent, whether given by requesting an appointment or authorising a professional. For these purposes, registered professionals and centres that access patient data on the platform assume, where applicable, the obligations set out under the applicable data protection regulations, bearing full responsibility in the event of non-compliance with such regulations. Under those regulations, professionals and centres accept the relationship as data processor with respect to the personal data that registered users provide to opensalud for the purposes of making appointments and consultations, always maintaining the level of protection required for such specially protected data.
- To companies used to support the correct functioning of the platform (cloud) and collaborators.
- In the case of telemedicine services for businesses, to generate aggregated reports on platform usage by their employees. These aggregated reports will be anonymous and will only contain the following information: total number of users, total number of services used and main reasons for consultation. The data is aggregated by sex and age range.
Obligations of the professional or centre regarding information extracted from the platform
In relation to any information extracted from the platform, through legally permitted means, the professional or centre must be aware that health data is classified as highly sensitive information requiring a high level of security, and must accordingly be processed in accordance with the guidelines set out in Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (GDPR), Spanish Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights, and other applicable regulations on the protection of personal data and information security. Access to or downloading of such information is only permitted to the extent authorised under applicable regulations.
Under no circumstances may the extracted information be stored on the hard drive of (local) devices. If the information is printed on paper, it must be kept under the custody of the person responsible for it at all times, and stored under lock and key when not in use.
Likewise, external mobile devices, such as USB drives, smartphones, laptops, etc., must not be used to store or transfer the information. Under no circumstances shall external email be used to send or receive this type of information. Furthermore, regardless of the medium on which it is held, the extracted information must be reliably erased or destroyed once it is no longer needed for the purposes for which it was extracted.
The professional or centre must use the personal data being processed, or that they collect for inclusion, only for the purpose covered by the contract. Under no circumstances may they use the data for their own purposes. Should the data processor use the data for purposes other than those stipulated, disclose it, or use it in breach of the conditions of this document, they will be considered responsible for the file for all purposes, being personally liable for any infringements committed.
The professional or centre will not disclose the data to unauthorised third parties, unless they have the express written authorisation of the data controller, in legally permissible cases. For these purposes, data communications between companies belonging to each party’s group shall be deemed authorised, for the purpose of meeting the obligations and rights arising from the performance of the contract. They must also maintain the duty of confidentiality regarding personal data to which they have had access under the contract, even after its purpose has ended, being answerable to the data controller in the event of non-compliance, without prejudice to any liability that may arise before the Spanish Data Protection Agency or the data subject.
The professional or centre must implement the security measures applicable in accordance with the risk assessments that, where applicable, the data controller must carry out.
We do not carry out international transfers.
Data quality
The website informs users of the obligation to correctly update the data provided and processed in the file called Users. Such data must be adequate, relevant, current, accurate and truthful, with opensalud excluded from all negative consequences arising from any inaccuracies therein.
Users are also informed that they may not register and/or provide third-party data on their behalf through the stipulated means of communication, unless there is legally established representation. In the case of minors, express proof of such status may be required.
Rights
Rights of access, objection, rectification and erasure of data, deletion and portability.
Anyone has the right to obtain information about whether opensalud is processing their personal data.
Legitimately entitled individuals have the right to access their personal data, to request the rectification of inaccurate data or, where applicable, to request its deletion when, among other reasons, the data is no longer necessary for the purposes for which it was collected.
Where circumstances so require, data subjects may request the restriction of the processing of their data, in which case we will only retain it for the establishment, exercise or defence of claims.
When we need to obtain information from you, we will always request your express consent through the means made available for this purpose.
These rights must be exercised by contacting opensalud, either at the postal address indicated above, or at the email address provided for this purpose ([email protected]), without prejudice to the use of any other legally valid means that allows the requirements for doing so to be met.
The content requirements for exercising these rights are:
- Full name of the data subject.
- Purpose of the request.
- Address for notifications, date and signature of the applicant.
- Supporting documents for the request made, where these are considered appropriate or necessary.
Spanish Data Protection Agency
The AEPD is responsible for ensuring compliance with privacy and data protection laws and for guaranteeing the security and privacy of your data in general, and especially on the Internet.
If you feel that your rights regarding the protection of your personal data have been violated, especially when you have not obtained satisfaction in exercising your rights, you may file a complaint with the competent Data Protection Supervisory Authority through its website: www.agpd.es.
Useful links
If you want to know more about the Internet and your privacy, opensalud recommends you visit the following links:
- Internet Security Office: www.osi.es
- Spanish Data Protection Agency: www.agpd.es