Personal Data Protection Policy
Preamble
Synevo Georgia LLC (hereinafter referred to as the “Organization”) protects fundamental human rights and freedoms, including the inviolability of privacy, personal space, and communication, when processing personal data.
The organization, as a provider of medical/healthcare services, carries out patient registration, diagnostics and treatment, laboratory and instrumental studies, medical record management, appointments, billing and insurance document circulation processes, and pays special attention to the protection of patient, employee and partner data, including health (special category) data.
This Policy defines the main measures by which the Organization ensures compliance of personal data processing processes with the Law of Georgia on Personal Data Protection (hereinafter referred to as the “Law”) and protects the legal rights of data subjects.
Article 1. Scope of application
This policy applies to all processes of processing personal data (hereinafter referred to as “Data”) by the Organization, including:
- Patient identification and recording;
- Full service cycle (diagnostics, laboratory/instrumental studies, electronic medical records – EMR);
- Quality management and clinical audit/test control;
- Financial and accounting operations, including billing and processing of insurance scheme/client claims;
- Risk management and fraud prevention (including IT/cybersecurity);
- Use of digital platforms, portals and mobile applications;
- Implementation of video monitoring for security purposes;
- Labor and legal relations management and recruitment;
- On relations with subcontractors.
Article 2. Definition of Terms
The terms used in this policy have the meanings given by law.
Article 3. Principles of data processing
- The organization processes data in accordance with the law, provided that there is a legal basis for data processing, and in compliance with the following principles:
a) Data must be processed lawfully, fairly, transparently and without violating the dignity of the data subject;
b) Data must be collected only for specific, explicit and legitimate purposes and must not be used in a manner incompatible with those purposes;
c) Data must be processed only to the extent necessary to achieve the relevant legitimate aim (“minimisation”);
d) The data must be true, accurate and, if necessary, updated;
e) Data must be stored only for the period necessary to achieve the relevant purposes, or for the period prescribed by law;
f) Appropriate technical and organizational measures must be implemented to protect data against unlawful processing, especially health data.
- The organization ensures that data processing is organized in such a way that it can demonstrate compliance with the above principles.
Article 4. Basic measures to ensure lawfulness of processing
For the processing of data in accordance with Article 3 of this Policy, the Organization:
a) Takes technical and organizational measures appropriate to the threats to ensure data security: role-based access (RBAC), authentication/audit logging, encryption/pseudonymization (if necessary), backup storage, network segmentation; identifies the owner of each information asset and provides access control to prevent unauthorized access to personal and especially health data;
b) Ensures periodic training of employees in data protection, medical confidentiality and information security rules;
c) upon detection of an incident, ensures immediate response, reduction/elimination of damage, recording of the incident in accordance with the established procedure and, as necessary, informing the data subject and/or the supervisory authority;
d) Publicly publishes information on key processing processes in a transparent manner. If necessary, use additional channels to inform patients (banners/leaflets in the clinic, SMS/E-mail notifications);
e) makes internal documents regarding the processing of their data available for employees to be informed;
f) ensures timely and appropriate response to the rights of data subjects;
g) if necessary, conducts a data protection impact assessment (DPIA);
h) Incorporates the principles of "privacy by design/default" in all products, projects and services;
i) maintains records of processing (ROPA) in accordance with the law, including purposes, categories, deadlines and categories of recipients;
j) When interacting with persons authorized to process, acts in accordance with a legal act/written agreement that clearly defines the grounds and purposes of processing, data categories (e.g., name, contact information, medical record extract, payment/insurance details), processing time limits, confidentiality obligations and security measures; complies with the rules established by law when transferring abroad;
l) Implements other appropriate measures, including, if necessary, anonymization of data for statistical/research purposes in accordance with the law.
Article 5. WebresultsOn the platform Used Cookie ფაილები (cookies)
5.1. An “Internet cookie” (also known as a “browser cookie”, “HTTP cookie” or “cookie”) is a small file consisting of letters and numbers and stored on a computer, mobile terminal or other device that a user uses to access the Internet.
Cookies are installed through a request sent by a web server to a browser (e.g. Internet Explorer, Firefox, Chrome). Once installed, cookies have a fixed expiration date and remain “passive” in the sense that they do not contain software, viruses or spyware and do not have access to information on the user’s hard drive where they are installed.
A cookie consists of two parts:
- The name of the cookie; and
- The content or meaning of the cookie.
Technically, only the web server that sent the cookie can re-access it when the user returns to a web page associated with that web server.
When using/visiting the Webresults platform, the following cookies may be stored:
necessary Cookie ფაილები (Necessary cookies) – They are required for the website to function and provide basic functions such as navigation and access to secure areas of the platform. Without these cookies, the platform will not function properly.
5.2. The Webresults platform is used exclusively to offer online access to test results, therefore, the said platform uses only necessary cookies, which allows the organization to maintain the functionality of the platform.
Below are the essential cookies used by the organization to ensure the functioning of the platform:
- "RequestVerificationToken_L1NJTEFCLzQuMi9HRS9UQi9TeW5ldm9XZWI1" cookie - This cookie is used for authentication and security; it is an anti-forgery token used by NET to protect against CSRF (Cross-Site Request Forgery) attacks. It is automatically set by the framework and must be present 100% of the time; otherwise, forms will not work.
- "AspxAutoDetectCookieSupport" cookie - This cookie is used for compatibility; it does not contain sensitive data. This cookie is created by .NET to determine whether the user's browser accepts cookies. In practice: it sends a test cookie to check whether support is active.
- “AspNet.ApplicationCookie” cookies – This cookie is used for authentication. It is the main authentication cookie in the NET Identity system. After logging in (authorization), the server generates this cookie, which contains a token and confirms that the user has been authorized. It is very important – without it, the user will not be able to log in to the platform.
- "ASP.NET_SessionId" cookies - This cookie identifies the current session ID. The server uses it to remember: the user's status, the steps they have taken, and temporary information.
- "userType" cookie - This cookie is also a necessary cookie and identifies the type of user. Values can include: PAT, FFSPAT, COMD, DOC, etc. It is used to determine what should appear in the user interface (UI) and what permissions this user needs.
- “isDoctorClient” cookies – Identifies the type of doctor account (whether he is an administrator or not) and is also a necessary cookie. Based on this data, the user is granted access to specific features of the platform.
Article 6. Enforcement
- To ensure the measures provided for in Article 4 of this Policy, the organization prepares additional written documents (internal rules, incident response plan, retention period matrix, etc.) and takes appropriate measures.
- In order to identify risks in the organization and coordinate appropriate measures:
a) Personal Data Protection Officer – monitors compliance of data processing processes with the law and this Policy, makes recommendations and participates in DPIA and incident management;
b) Owners of information assets – ensure compliance with law and policy of the assets containing data in their possession;
c) Medical Service/Clinical Managers – are responsible for the accuracy of medical records, limiting access on a “need-to-know” basis, and protecting medical confidentiality.
Article 7. Review
This policy will be reviewed at least once a year and, if necessary, amended in accordance with the organization's technological, operational or legal environment, including by updating the accompanying documents/procedures.
Appendix 1
Consent to the processing of personal data
By consenting to the processing of this personal data, the provision of medical services, the provision of high quality services as well as quality improvement, fulfillment of contractual and statutory obligations, you, as a patient, confirm your prior consent to the Company and entitle it to the following:
The company will process information about the patient's personal, including health, treatment. By signing this document, the company is empowered to: process the personal information about the patient and / or his / her treatment and / or representative for services in the company, including the use of software (automatic and / or semi-automatic processing) as his / her immediate employees / med. Through staff, as well as invited persons and also through its contractors, including contractors who are directly or indirectly involved in providing services to the patient or any part of it and / or receiving quality services (eg patient insurance company, etc.). However, this must be done in accordance with the requirements of the current legislation to the extent and within the scope required to provide the service, without obtaining any additional consent.
Data processing includes any activity performed by the Company, including data collection, extraction, access, photography, video surveillance and / or audio monitoring, organizing, grouping, interconnecting, storing, modifying, restoring, retrieving, using, blocking, deleting, or destroying , The disclosure of data through its transmission, publicity, dissemination or otherwise accessible. The data will be processed by the Company only for the purpose for which it was collected and / or provided by law.
The transfer of personal information of the patient to third parties (except the above-mentioned persons), in particular, the state, regulatory bodies, sponsors of the service or part of it, law enforcement agencies, etc., will be carried out in accordance with the law. Such information may be transmitted even in cases not expressly provided for by law, in order to protect legitimate interests, due to reasonable need and / or the essence of the request;
During the use of the Company's services, as well as after its termination, the Company will continue to process the patient's personal information for the purposes specified for the purposes of the medical services and / or required by regulatory bodies and / or provided by law.
You also consent to the processing of your personal data for direct marketing purposes within the limits and in the manner permitted by law.
You acknowledge that you have received complete and exhaustive information about your rights under Georgian law, including the fact that, at your request, the data processor is obliged to correct, update, add, block, delete or destroy data if it is incomplete, inaccurate, Not updated, or if their collection and processing was carried out against the law.
For any issues related to the protection of personal data in "Synevo Georgia" Ltd. you can contact us at the following E-mail address: info@synevo.ge
Consent Online Medical Services (Telemedicine)At the reception
I, the undersigned (or electronically by clicking the button below), consent to receive a medical consultation remotely, using the online platform Zoom, and understand the following:
- I am aware that a lab administrator may be present at the beginning of the session to ensure the technical integrity of the video connection. I am authorized to request that the administrator leave the session immediately after the technical integrity is completed in order to protect the confidentiality of my conversation with the doctor.
- I understand that Zoom is a third-party platform. Although the company takes every precaution to ensure security, communicating over the internet carries minimal cyber risks.
- I agree to have my health documentation (tests, prescriptions) discussed during a video call (via screen sharing or verbally).
- I am informed that the consultation will not be recorded (no audio/video recording will be made) by the laboratory unless my prior written consent is given.
