...

Information on the Processing of Personal Data (GDPR)

1. Data Controller

1.1 The controllers of personal data are:

Mgr. Jiří Hájek

IČO: 22122745

Mgr. Zdislava Tučková

IČO: 22122664

Bc. Martin Vávra

IČO: 22337920

Business location: Pekařská 635/6, 158 00 Praha 5-Jinonice (hereinafter referred to as the “Controller”).

1.2 Contact Information for the Data Controller:

E-mail: info@enterfyzio.cz

Phone: +420 777 303 430; +420 797 970 264

Web: www.enterfyzio.cz

2. Personal Data Processed

2.1 The controller processes the following personal data:

    • First Name and Last Name
    • Address
    • Phone number
    • Email address
    • Date of Birth
    • Health-related data associated with the services provided
    • Payment Information
    • Identification and contact information (first name, last name, academic title, phone number, email address)
    • Billing and Payment Information (payment method and date, payment via a payment gateway)

3. Purpose of the Processing of Personal Data

3.1 Personal data is processed for the following purposes:

    • Provision of Physical Therapy Services
    • Order and Reservation Management
    • Billing and Bookkeeping
    • Communication with Clients
    • Compliance with Legal Obligations
    • Marketing activities (only with the client's express consent)
    • Conclusion and Performance of the Contract
    • Processing of special categories of personal data necessary for the provision of health care
    • Protection of the Data Controller's Legitimate Interests
    • Sending Commercial Communications

4. Legal Basis for the Processing of Personal Data

4.1 The legal bases for the processing of personal data are:

    • Performance of the Contract Between the Administrator and the Client
    • Compliance with the Controller’s Legal Obligations
    • The Data Controller’s legitimate interest in improving the services it provides and communicating with clients
    • Consent of the Data Subject (for Marketing Purposes)

5. Recipients of Personal Data

5.1 Personal data may be disclosed to the following categories of recipients:

    • Employees and Associates of the Administrator
    • Personal data processors (e.g., IT service providers, accounting services)
    • Public administration bodies when required by law

5.2 The controller may transfer personal data to third countries (e.g., the United States) only if the processing of personal data is carried out in accordance with European security standards and legal regulations.

6. Retention Period for Personal Data

6.1 Personal data is retained for as long as is strictly necessary to fulfill the purpose of its processing, but no longer than the period specified by applicable laws.

6.2 Retention Period for Personal Data:

    • Conclusion and performance of the contract: for the period necessary to fulfill the contract
    • Compliance with legal obligations: for the period specified by applicable laws and regulations
    • Compliance with legal obligations: for the period specified by applicable laws and regulations
    • Sending marketing communications: until consent is revoked

7. Rights of Data Subjects

7.1 Data subjects have the following rights:

    • Right of Access to Personal Data
    • The Right to Correct Inaccurate or Incomplete Information
    • The Right to Erasure of Personal Data (the “Right to Be Forgotten”)
    • The Right to Restrict the Processing of Personal Data
    • Right to Data Portability
    • The Right to Object to the Processing of Personal Data
    • The right to withdraw consent to the processing of personal data (if the processing is based on consent)

7.2 Data subjects may exercise these rights by using the Controller’s contact information provided in section 1.2.

8. Filing Complaints

8.1 Data subjects have the right to lodge a complaint with the supervisory authority, which is the Office for Personal Data Protection (ÚOOÚ), if they believe that the processing of their personal data violates the GDPR.

9. Zabezpečení osobních údajů

9.1 The controller shall take all appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, and other unlawful processing.

9.2 Security measures include:

    • Implementation and Enforcement of Internal Personal Data Protection Policies
    • Antivirus Software and Firewalls
    • Encryption
    • Personal Data Access Control and Authorization Information
    • Backup
    • Physical Security Measures

10. Final Provisions

10.1 This information regarding the processing of personal data takes effect on the date of its publication on the Controller’s website.

10.2 The Administrator reserves the right to update this information at any time. The current version will always be published on the Administrator’s website.

In Prague, March 20, 2025

Mgr. Jiří Hájek

IČO: 22122745

Mgr. Zdislava Tučková

IČO: 22122664

Bc. Martin Vávra

IČO: 22337920

Business location: Pekařská 635/6, 158 00 Praha 5-Jinonice

Phone:+420 777 303 430; +420 797 970 264

Email: info@enterfyzio.cz

Web: www.enterfyzio.cz

 

Scroll to Top
Seraphinite AcceleratorOptimized by Seraphinite Accelerator
Turns on site high speed to be attractive for people and search engines.