Privacy policy
In accordance with Regulation (EU) 2016/679 of the European Parliament and of the European Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter “GDPR”), as well as Organic Law 3/2018 of 5 December (hereinafter “LOPDGDD”) and Law 41/2002 of 14 November, the basic law regulating patient autonomy and rights and obligations in relation to clinical information and documentation (hereinafter “LAP”), we hereby inform you of the following:
1.– Who is the Data Controller and how can they be contacted?
Identification details:
Name of the data controller: Blarsi Estética, S.L.
Tax ID number: B75372961
Address: Calle Ganduxer, 72, ground floor, door 1, Barcelona (08021) Email: info@blarsi.com
We would like to inform you that the data we collect will be processed in accordance with the provisions of the GDPR, the LOPDGDD and the LAP.
2.– What personal data do we process?
The personal data we process are:
Identification and contact details of patients or their representatives: including names, surnames, national identity card number, telephone number, email address, signature, image/photograph, mutual insurance company number;
Personal data: marital status, date and place of birth, age, sex, nationality, language.
Health, genetic or biometric data included in your medical records or provided to us directly or by the healthcare centre, such as, for example, family and personal health history and medical tests, personal characteristics, social circumstances relevant to the service;
Transactional and financial data (payments, deposits, transfers, debits, bank account number)
Browsing and connection data: if you access our Website (cookies, IP address, connection time, etc.)
The data usually comes from the data subject themselves (hereinafter “Data Subject or Patient”) or, where applicable, from their legal representative and, exceptionally, from healthcare centres and/or healthcare personnel.
3.- For what purposes do we process your personal data? The operations envisaged for processing are:
Provision of cosmetic medicine services, beauty treatments and wellness therapies: in these cases, they will be treated as examples and are not exhaustive, in order to provide you with the appropriate care and service by our medical professionals or beauticians; Management of medical records; Responding to your queries or any incidents or complaints; Management and reminders of appointments; Management of your participation in the various prize draws that are organised; Managing payment for our services; Any other procedure related to the provision of the service and execution of the contract.
Handling requests for information, complaints, suggestions, claims, exercising data protection rights, etc.: in these cases, your data will be processed for the purpose of managing and processing the request, by any means, including telephone and/or electronic communications.
Compliance with legal obligations: it may be necessary to process personal data in order to comply with the relevant legal requirements. Specifically, to comply with legislation on data protection, taxation, health, etc.
Sending of commercial communications: we may send commercial information related to our services by any electronic or physical means. In the event that you are not our customer and you have contacted us by a particular means, we will only send commercial information if you have given your express consent by ticking the corresponding box. Visiting the website does not imply that you have to provide personal data, unless you wish to receive further information, make an enquiry or request an appointment.
Whether you are a customer or not, you may unsubscribe at any time and request that we do not send you commercial information by contacting us by email.
Marketing with website publication, social media and promotional material featuring images of the patient and their treatment: we may use images of your treatment, including before and after images, on our social media platforms, website and promotional material. The image will be published without showing more information than necessary.
You may revoke your consent at any time by contacting us via email.
Improving navigation on our website and social media. Through the use of cookies, which are duly reported in the banner and in the cookie policy.
What is the legal basis for processing your data?
PURPOSE
Provision of cosmetic medicine services, beauty treatments and wellness therapies
LEGAL BASIS
The processing will be based on the performance of a contract to which the data subject is party. The explicit consent given at the time of providing us with your personal data through the forms provided at our centre.
PURPOSE
Dealing with requests for information, complaints, suggestions, claims, and the exercise of data protection rights
LEGAL BASIS
When your query relates to requests for information, complaints, suggestions or claims related to our services, the processing will be based on the legitimate interest in providing you with adequate service and resolving the queries raised. When your query relates to the exercise of your rights, the processing will be based on compliance with a legal obligation applicable to the joint controllers.
PURPOSE
Compliance with legal obligations
LEGAL BASIS
The processing will be based on compliance with an applicable legal obligation.
PURPOSE
Sending out commercial communications
LEGAL BASIS
The processing will be based on legitimate interest when sent to customers. Such communications are covered by Article 21.2 of Law 34/2002, of 11 July, on information society services and electronic commerce. The processing will be based on express consent when you are not yet a customer and you contact us electronically (website, email or telephone).
PURPOSE
Marketing by publishing images of the patient and their treatment on the website, social media, and promotional material.
LEGAL BASIS
The processing will be based on your express consent by ticking the corresponding box and signing the contract authorising the processing and publication of your image for this particular marketing purpose.
PURPOSE
Enhanced browsing on our website and social media
LEGAL BASIS
The processing will be based on legitimate interest in the case of cookies that are necessary and on express consent for all others.
How long do we keep your data?
In general, your data will only be kept for the time that is strictly necessary for the purpose for which it was collected, as set out below:
The provision of cosmetic medicine services, beauty treatments and wellness therapies: these will be kept for the appropriate period of time in each case (in accordance with medical and legal criteria), and for a minimum of ten years from the date of completion of each treatment, unless regional and/or specific regulations establish a minimum retention period longer than that indicated, in which case the provisions of the applicable regulations will be followed. Once the contractual relationship has ended, the data controller will keep your data duly blocked and pseudonymised for the duration of the aforementioned periods.
Dealing with requests for information, complaints, suggestions, claims, and the exercise of data protection rights: for the time needed to deal with your request and, in any event, for the time established by law.
Compliance with legal obligations: for the period stipulated in the applicable legislation in each case.
Sending of commercial communications: these will be kept until the interested party revokes their consent and/or exercises their rights of opposition and/or deletion.
Marketing by publishing images of the patient and their treatment on the website, social media and promotional material: these will be kept until the data subject revokes their consent and/or exercises their rights of objection and/or removal.
Enhancing browsing on our website and social media: these will be retained for as long as the data subject does not revoke their consent to their processing by deleting cookies and for the period of time established by law, with a minimum duration of three years.
Once the above periods have elapsed, your personal data will be blocked and will only be available at the request of judges and courts, the Public Prosecutor’s Office or the competent public administrations for the number of years required to comply with legal obligations. Once this period has elapsed, your data will be completely deleted.
Who do we share your data with?
In order to fulfil the purposes indicated above, your data may be processed by third parties who will be contractually obliged to comply with their legal obligations as data processors, and to maintain the confidentiality and secrecy of the information.
These third parties are:
Insurance companies and mutual societies, for the proper performance of the contractual and/or care relationship with the patient and the billing of services provided, where applicable.
Financial institutions, in the event that the service or transaction requested by the patient is subject to payment, for the proper performance of the contractual relationship and the management of collections and payments.
Medical or beauty therapy staff who are not part of the permanent staff but who provide services at our centre.
Providers of physical security services, archiving, storage or digitisation of information, document destruction, legal advisory services, IT services and advertising services.
Suppliers of medical equipment, for the proper performance of the contractual and/or care relationship with the patient or based on the data subject’s vital interest.
Public Administrations, Judges, Courts, Security Forces and Corps, in the event of legal obligation.
All information provided to us will be treated confidentially and in strict compliance with the requisite security obligations to prevent access by unauthorised third parties.
The data we collect about you is stored within the European Economic Area (‘EEA’) and we do not make international transfers.
What measures do we implement?
In accordance with current regulations on personal data protection, we are in compliance with all provisions of the GDPR and LOPDGDD regulations, as well as LAP for the processing of personal data, and manifestly with the principles described in Article 5 of the GDPR, whereby they are processed in a lawful, fair and transparent manner in relation to the data subject and are appropriate, relevant and limited to what is necessary in relation to the purposes for which they are collected and processed.
We have implemented the appropriate technical and organisational policies to apply the security measures established by the regulations in order to protect the rights and freedoms of data subjects.
What are your rights?
The rights to which you are entitled are:
Right to withdraw consent at any time.
The right to access, rectify, transfer and delete your data, and to restrict or object to its processing.
Exercising your rights is free of charge and can be done in person by filling out the appropriate forms at our centre, by post to Calle Ganduxer, 72, ground floor, door 1, Barcelona (08021) or by email to info@blarsi.com.
You also have the right to lodge a complaint with the supervisory authority (https://www.aepd.es) if you are of the opinion that the processing does not comply with current regulations. Our Privacy Policy is subject to change on a periodic basis.
Appointment or Information Request
Please let us know your inquiry or, if you prefer, book an appointment now.