Rights of data subjects

 

We implement data processing as follows:

As an employer, for staff matters.

As an Insurance Institution, for the service of our members and visitors.

As obligated to comply with any requirement of the legal framework in which we operate.

 

Your rights under European and Greek Personal Data protection legislation are:

Right to Information

There must be a clear reason why DOCTUM must collect or use your personal data. Thus, you have at any given time the right to obtain information about your personal data, the way we process them and where we have them stored, always in compliance with the current regulation and free of any charge. A summary of this information will usually be provided to you when we collect your personal information, but in any case, you can also receive detailed information from our website.

Right of Access

Personal Data Regulation gives you the right to request, view and receive a copy of any personal information we hold about you. However, in order to respond to your request, we may need additional information (i.e. to identify the subject and to make sure that the personal data is not sent to the wrong person). Where possible, you will be able to access the information we hold through the account. We will arrange to respond to any relevant request within a period of one month, unless for objective reasons we may need more time, in this case we will inform you. Please refer to our website in the relevant section to select the appropriate form. 

Right to Rectification

You can ask from us the correction – update of your personal data in case they are inaccurate or incomplete. If we have passed the information on to others, we will take steps to notify them and take the necessary corrective action. If we find that the information does not need to be changed, we will contact you within one month to explain our decision.

Right to Erasure

We strive to ensure that the data we receive will not be retained and will not be processed for longer than necessary. However, since you have the right to request the deletion of your personal data, DOCTUM will delete them immediately. This will happen particularly in the following cases: 

  • They are no longer necessary for the purpose for which they were originally collected
  • You agreed to the collection and editing initially and later changed your mind
  • We have stated that we will use them to serve our own “legitimate interests”, which have now disappeared and there is no other reason to retain your data
  • You have sound reason to believe that we used your data illegally
  • You have a well-documented opinion that we have an obligation by the law to stop processing and stop holding your data
  • The data refers to a minor for whom there is no legal possibility for the processing of their data

However, in some cases where applicable legal obligations (i.e. tax) require mandatory data retention, data deletion may be prohibited. In these cases, we will explain why we cannot delete your personal data and for how long. While we can also refuse to delete data if there is no clear reason or if the request was excessive.

If we have passed the information on to others, we will take steps to notify them so they will take the necessary corrective action.

We will arrange to respond to any relevant request within a period of one month, unless for objective reasons we may need more time, in which case we will inform you. Please refer to our website in the relevant section to select the appropriate form. But if we have any objections, we will explain our decision to you.

Please note that if we comply with a request, we may still be required to retain some information such as that you made the request and that we have responded. We may also need to retain some data such as contact details in a log protocol so that we do not communicate for advertising purposes in the future. 

Right to Restriction of Processing

You have the right to request the restriction of processing of your personal data from Doctum and DOCTUM will immediately proceed to the limitation of the processing of these, at least, in order to consider your request, to limit, correct or stop the processing of data. If this is not possible, we will explain why we cannot restrict the processing of Personal Data.

Right to Data Portability

For the processing of personal data for which we use computer systems, either by contract or with your consent, you have the right to request that we provide you with these in one of the most widely used forms of reading, for example in an XML file.

Right to Object

You have the right to object to the processing of the Personal Data which we carry out:

  • for the fulfillment of a task assigned to us and performed in the public interest
  • because processing is necessary for the purposes of legitimate interests
  • for advertising / marketing purposes
  • for scientific or historical research and statistics

We will not be able to respond to your request if:

  • there is an imperative and legal reason which prevails
  • there is an urgent need to establish, exercise or support legal claims

We will contact you within a month to explain our decision.

 

Automated individual decision-making, including profiling

As a processor https://doctum.gr/en/home/ has the right to utilize technology in order to make decisions that have a significant impact on subjects in very specific cases and under certain conditions. In particular, we may use technology for automated decision-making and profiling when:

  • is necessary for the conclusion or execution of a contract between DOCTUM and you
  • is based on your explicit consent
  • allowed by European or Greek legislation

In any case, the specific technology will have been implemented having taken the appropriate measures to protect the rights, freedoms and legal interests of the data subject, providing the appropriate information, i.e. what information we use, for what purpose and the effects. You can ask us to reconsider the decision with human participation.

 

How you can exercise your rights

After being informed from our website, you can fill in the contact form https://doctum.gr/en/contact/

To exercise any of your rights you can:

Contact the department of DOCTUM which is deemed supervisory. Information about the infrastructure of the Company and the contact details can be found here

Alternatively, send an e-mail to the Data Protection Officer Mr. Dimitrios Lioulias of DOCTUM, at info@doctum.gr

In any case, for exercising your rights you can submit a request by applying to the Greek DPA, located at 1-3 Kifissias Avenue, PC 115 23, Athens, tel.: + 30-210 6475600, Fax: + 30-2106475628, www.dpa.gr