GDPR
In this Personal Data Protection Policy (“Policy”), we bring together the main points relating to the processing of your personal data, which we carry out in accordance with the rules of the General Data Protection Regulation (Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016 – “GDPR”), thereby ensuring that we provide you with information in a concise, transparent, intelligible and easily accessible way.
Date: 21 December 2024 (Last update)
Data Controller
The company MOTA & AMARAL – PRESTAÇÕES SERVIÇOS ODONTOLÓGICOS LDA, NIPC 506114406, headquartered at Av.ª Maria Lamas, nº 6, Loja Esq.ª, 6-A, Serra das Minas 2635, Rio de Mouro, is responsible for the collection and processing of your personal data.
Categories of Data, Means of Collection and Purposes
We collect and process the following categories of personal data. This personal data is collected directly from you, or via telephone, e-mail or the website, for the purposes set out below:
Categories of personal data:
Means of Collecting Personal Data:
Purposes of Collection:
Purposes and Legal Grounds for Processing
We collect and process your personal data for the following purposes and on the following legal grounds:
Provision of healthcare
Where processing concerns health-related data, it will be based on your need for preventive medicine, appointment scheduling, exam scheduling, medical diagnosis, provision of care, health treatments and exams, electronic prescription of medications and complementary exams, and for billing the services provided.
Management of the Patient relationship
Based on the performance of the healthcare service contract entered into, or the performance of pre-contractual steps at your request (e.g., when booking an appointment or clinical procedure, providing doctors’ exam results, billing, or filling out the contact form on the website).
Management of health services and other support activities
Based on the need for processing to pursue the legitimate interests of the Data Controller or of third parties, to comply with a legal obligation to which the Data Controller is subject, and for the purposes of managing health systems and services. Additionally, processing may also be carried out based on your need to establish, exercise or defend a right in legal proceedings.
Cookies and Browsing Data
Our website may use cookies and similar technologies to ensure its proper functioning and, where applicable, for traffic and performance analysis purposes.
We distinguish between:
Cookies that are not strictly necessary are only installed after your explicit consent, given through the cookie banner shown on your first visit to the site. You may change or withdraw your consent at any time through the site’s cookie settings or your browser’s settings.
Personnel Authorized to Access Your Data
Our access control system ensures that only doctors and healthcare professionals involved in providing your healthcare, and bound by professional confidentiality obligations, access this data.
In cases where this is not so — when your health data and other special categories of data are accessed by staff not bound by professional confidentiality obligations — we ensure that such staff take on appropriate confidentiality obligations, and that they only process your data under the responsibility and supervision of a professional bound by a duty of confidentiality.
Cases in which administrative staff have access to your health data and other special categories of data include processing data for billing the healthcare services provided to you, for scheduling appointments and clinical procedures, or for managing your information requests or complaints.
Data Retention Periods
The retention period for your personal data varies according to the purpose for which it is processed.
The personal data collected is retained only for the period strictly necessary to fulfill the purposes underlying its processing. However, in certain cases there may be legal obligations binding us that require us to retain your personal data for a longer period. Specifically, health-related data is retained in accordance with the legislation applicable to health record archiving, with the exception of: i) data necessary for the electronic prescription of medications, which is retained under Portaria (Ordinance) No. 224/2015, of 27 July; and ii) data necessary for billing services provided, which will be retained for a period of 10 years.
Data Recipients
We may transmit your personal data to
We do not transmit your personal data to any marketing companies, data-selling companies, or entities with similar purposes.
Use of Images, Videos and Testimonials for Communication Purposes
In cases where we intend to use your photographs, videos or testimonials for communication and marketing purposes (namely on our website or on our social media), such processing always depends on your prior, free, specific and informed consent, given through a dedicated document, separate from consent for the provision of healthcare.
That specific consent clearly identifies the purpose, the means of disclosure, the duration of the authorization, and your right to revoke it at any time, without prejudice to the lawfulness of processing carried out based on consent previously given. You may request the removal of content already published through the contact indicated in this Policy.
Your Rights
As a data subject, you may at any time request access to the personal data concerning you, as well as its rectification, erasure, restriction, portability (if applicable), or you may object to its processing.
If you believe that the way we process your data does not comply with the law, you have the option — without prejudice to any other administrative or judicial remedy — to file a complaint with the Comissão Nacional de Proteção de Dados (National Data Protection Commission).
CONTACTOS
For any questions or suggestions regarding this Policy or the practice of personal data processing, please contact us by e-mail at falecom@smilecare.pt.