Personal data protection
This page is a review draft of data flows on the new website, not the hospital’s approved privacy notice. It cannot be published as the final policy until the institution completes and approves the controller’s full identity, processing conditions, recipients, transfer countries and retention periods.
Translation draft · Not yet approved by the hospital.
Before sharing your information
This page is a review draft of data flows on the new website, not the hospital’s approved privacy notice. It cannot be published as the final policy until the institution completes and approves the controller’s full identity, processing conditions, recipients, transfer countries and retention periods.
Appointments and patient portal
Information required for appointments and account actions is sent through the server to the hospital’s Medisoft system for the action you select. A personal transaction request is not created until the relevant step is submitted. If the provider response is uncertain, the system does not automatically send a new booking request.
Do not enter passwords or verification codes in feedback, survey or application fields. Patient portal information is personal; sign out on shared devices. Health results are accessible only with an authorised session and the relevant module enabled.
Feedback, surveys and incident reports
Surveys do not ask for names or contact details. In feedback and incident reports, you provide contact details separately if you request a response. Do not enter patient or staff names, identity numbers, diagnoses or other people’s health information in free-text fields.
Applications and enquiries
Job and doctor applications record education, experience and necessary contact details; supplier applications record company and proposal details; check-up enquiries record the selected package, name and phone number. Do not send identity documents, bank information or medical reports.
Optional CV files are not available for staff download until security checks are complete. The relevant team follows applications in the administration panel; the current form workflow sends no automatic email or SMS.
Access and retention
Panel access is limited by role: human resources sees applications, quality sees surveys and incidents, patient relations sees feedback and check-up enquiries, and procurement sees supplier applications. Administrator access is defined separately.
Retention and deletion periods must be determined by an institution-approved policy for each form type. The application’s technical cleanup tool does not itself establish a legal retention period; backups and legal obligations require separate consideration.
Your rights and contact channel
For information about your personal data, corrections and other requests subject to applicable legal conditions, ask the hospital’s authorised unit how to apply. The general feedback form does not replace an identity-verified data subject request; do not upload identity documents to it.
