Information leaflet
The Fondation des Hôpitaux Robert Schuman (hereinafter referred to as “the foundation”, ” we” or “us “) attaches great importance to respecting your privacy and protecting any of your personal data it collects. The purpose of this leaflet is to inform customers of the use made of personal data collected by the GesondheetsZentrum as part of its screening and preventive medicine activities.
Data processing manager
The Fondation des Hôpitaux Robert Schuman, established and having its registered office at 44 Rue d’Anvers L-1130 Luxembourg, as owner of the GesondheetsZentrum, is responsible for data processing.
Data protection officer
A Data Protection Officer (“DPO”) has been appointed by the Foundation and can be contacted for any questions relating to the processing of personal data:
- by e-mail to dpo@fhrs.lu
- or by post: Fondation des hôpitaux Robert Schuman – For the attention of the Data Protection Officer, 44 Rue d’Anvers, L-1130
Purposes and legal bases of processing
The Foundation collects and processes personal data for the following purposes:
Purpose of processing | Legal basis |
---|---|
Managing registrations for health check-ups | Legitimate interest of the foundation to ensure the proper organisation its activities (Article 6(1)(f) GDPR). |
Appointment management, customer orientation and identification | |
Organising and carrying out medical examinations | Processing necessary for the purposes of preventive medicine and medical diagnosis (Article 9(2)(h) GDPR). |
Monitoring and managing exam results | |
Evaluating test results and making medical recommendations where appropriate | |
Communication of examination results | |
Keeping customer files | Compliance with legal obligations relating to the maintenance of medical data (article 6(1)(c) GDPR). |
Invoicing management | Fulfilling the contract with customers (article 6(1)(b) GDPR) / management of the FHRS’s tax and accounting obligations (article 6(1)(c) GDPR). |
Preparation of activity reports and statistics | Legitimate interest of the foundation to assess and ensure the proper that its activities are operating correctly (Article 6(1)(f) GDPR). |
Categories of data collected
In compliance with the law, we only collect the personal data necessary to achieve the purposes for which they are intended. In addition to the information you provide, we may collect or generate other information we need to manage your health check properly. These data are:
- your identification data (surname, first name, national identification number, date of birth);
- your contact details (telephone number, postal address, email address);
- your personal characteristics (gender, weight, height, languages spoken);
- your employment details, if applicable (employer);
- your drinking habits and risk behaviours;
- data relating to your state of health (data concerning your psychological and physical health, pathologies, ailments, family history, medical treatment, etc.).
Data recipient
Your data will be treated confidentially by GesondheetsZentrum employees and will only be shared with third parties where this is necessary and in accordance with the law. These third parties may include:
- Subcontractors who assist us in managing health check-ups (e.g. laboratory services).
- The competent authorities, if required by law.
- Our service providers, particularly in the context of IT outsourcing.
- Our customers’ GPs.
- Data retention periods
Data is kept for as long as is necessary to achieve the purposes for which it was collected, and for a minimum of 10 years from the end of treatment.
Your rights
In compliance with the law, you have the following rights:
- The right to information. We hope this leaflet has answered any questions you may have.
- The right to access your data free of charge.
- The right to rectify your data if it is incorrect or obsolete.
- The right to withdraw your consent at any time.
- The right to lodge a complaint with the French National Commission for Data Protection (CNPD) if you consider that your data is not being processed in accordance with the law.
In some cases and under the conditions laid down by law, you also benefit from the following rights:
- The right to request the deletion of your data.
- The right to request that the processing of your data be restricted.
- The right to object to the processing of your data on legitimate grounds.
To this end, you can unsubscribe from our newsletters at any time by using the unsubscribe link in each newsletter.
- The right to portability of the data you have provided to us (i.e. the right to receive your personal data on a machine-readable medium), insofar as this is technically possible.
Contact
If you have any questions about how your data is processed or if you wish to exercise your rights, please contact the DPO for the Fondation des Hôpitaux Robert Schuman:
- By email: dpo@fhrs.lu
- By post:
Fondation des Hôpitaux Robert Schuman – For the attention of the Data Protection Officer
44 Rue d’Anvers, L-1130 Luxembourg
In order to comply as closely as possible with current regulations, we undertake to update this information notice whenever necessary.