GDPR Information Obligation
The Data Protection Officer at Uzdrowisko Busko-Zdrój S.A. is Mr. Tomasz Paprocki, email: iod@ubz.pl
Who is the controller of my personal data?
The controller of your personal data processed for the purpose of providing healthcare services is “Uzdrowisko Busko-Zdrój” Spółka Akcyjna, headquartered in Busko-Zdrój at Rzewuskiego 1.
Who can I contact regarding the processing of my personal data?
For all matters concerning the processing of your personal data by “Uzdrowisko Busko-Zdrój” S.A., you can contact our Data Protection Officer at: iod@ubz.pl
or by posT:
Data Protection Officer
“Uzdrowisko Busko-Zdrój” S.A.
Rzewuskiego 1, 28-100 Busko-Zdrój
What personal data are processed by “Uzdrowisko Busko-Zdrój” S.A.?
First, we need to register you for the provision of healthcare services.
To do this, we need the following data:
- first name and last name
- PESEL number
- sex
- date of birth (if no PESEL number is available)
- residential address
- first and last name, and contact details of the person authorised to receive information about your health status
These data are essential for the provision of healthcare services.
We also kindly request your phone number to facilitate contact when necessary.
While providing care, we create your medical records, which include all information related to your treatment process – especially data regarding your health status and epidemiological history. We collect this information only when necessary for the provision of healthcare services.
What is the purpose of processing my personal data?
We process your personal data as a medical entity, and the purpose of this processing is the provision of healthcare services and the management of healthcare systems and services.
Legal basis: (Full names of legal acts are listed at the end of this document.)
To confirm your identity before providing services – especially during registration, at reception desks, and in doctors’ offices.
We are legally obliged to maintain and store medical documentation. We fulfil your rights – e.g., we collect and store your authorisations to share your medical information.
We may contact you using the provided phone number or email address to confirm or cancel appointments, remind you of appointments, instruct you on preparation for procedures, or inform you about test results.
Providing appropriate care and improving service quality are our priorities – therefore, during or after the service, we may send you brief surveys asking for feedback. As a business entity, we have the right to pursue claims and may process your data in this regard.
We keep accounting books and meet tax obligations – e.g., by issuing invoices, which may require us to process your personal data.
Who do we share your personal data with?
As a healthcare entity, we ensure the confidentiality of your data. Due to the need to maintain appropriate organization, such as in terms of IT infrastructure or day-to-day matters related to our operations as “Uzdrowisko Busko-Zdrój” S.A., as well as to fulfill your rights as a patient, your personal data may be disclosed to the following categories of recipients:
- other healthcare providers cooperating with “Uzdrowisko Busko-Zdrój” S.A. to ensure continuity and availability of care (within our own or partner facilities)
- service providers supplying technical and organisational solutions (especially IT providers, diagnostic equipment suppliers, courier and postal companies)
- legal and advisory service providers (e.g., law firms, debt collection agencies)
- payers covering the cost of provided healthcare services
Are my data transferred outside the European Union?
Since we use external service providers (e.g., for diagnostic equipment maintenance), your personal data may be transferred outside the EU. In such cases, we ensure data transfers are governed by agreements between “Uzdrowisko Busko-Zdrój” S.A. and the given entity, including standard data protection clauses adopted by the European Commission.
How long are my data processed?
If you are our patient and medical documentation has been created, we are required to store it for at least 20 years from the date of the last entry.
Subject to this period, if the data have been processed by us for the purpose of pursuing claims (e.g., in debt collection proceedings), we will process the data for this purpose for the duration of the limitation period, as provided for under the Civil Code. All data processed for accounting purposes and tax-related reasons are retained for a period of 5 years, counted from the end of the calendar year in which the tax obligation arose. After the expiry of the aforementioned periods, your data are either deleted or anonymized.
Is providing data mandatory?
Using our services is entirely voluntary. However, as a medical provider, we are legally required to maintain medical records, including confirming patient identity.
Failure to provide necessary data may result in refusal to register or provide services.
Also, due to tax and accounting regulations, we may not be able to issue invoices or receipts without personal data.
Providing your phone number or email address is optional – not providing it will not affect your access to services but will prevent us from sending you appointment confirmations.
Am I required to provide my personal data?
Using our services is entirely voluntary. However, as a healthcare provider, “Uzdrowisko Busko-Zdrój” S.A. is legally obligated to maintain medical records in accordance with the applicable laws, including verifying the identity of the patient using their personal data. In such cases, failure to provide the required data may result in the refusal to book an appointment or provide healthcare services.
We are also legally required to process your data for accounting and tax purposes—failure to provide such data may, for example, prevent us from issuing an invoice or a receipt in your name. If you choose to provide us with your telephone number or email address, it is entirely voluntary—failure to do so will not result in denial of healthcare services, but you will not receive appointment confirmations from us.
What are my rights?
As the controller of your personal data, we ensure that you have the right to access your data. You may also request that your data be rectified, deleted, or that its processing be restricted. You also have the right to object to the processing of your data by “Uzdrowisko Busko-Zdrój” S.A., as well as the right to transfer your data to another data controller.
If “Uzdrowisko Busko-Zdrój” S.A. processes your personal data based on your consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of the processing carried out on the basis of your consent before its withdrawal.
If you wish to exercise any of these rights, please contact us personally at the headquarters of “Uzdrowisko Busko-Zdrój” S.A., by email using the address provided on our website, or in writing to our registered office address. You may also visit the reception desk at “Uzdrowisko Busko-Zdrój” S.A.
Please note that you also have the right to lodge a complaint with the supervisory authority responsible for overseeing compliance with data protection regulations.
Legal Acts Cited in This Notice
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC;
- Patient Rights Act – Act of 6 November 2008 on Patient Rights and the Patient Rights Ombudsman;
- Regulation of the Minister of Health – Regulation of the Minister of Health of 9 November 2015 on the types, scope, and templates of medical documentation and the method of its processing;
- Act of 15 April 2011 on Medical Activity;
- Act of 28 April 2011 on the Information System in Healthcare.
The Data Protection Officer at “Uzdrowisko Busko-Zdrój” S.A. is Mr Tomasz Paprocki, email: iod@ubz.pl
Information Clause on the Processing of Personal Data for Marketing Purposes
Who is the controller of my data?
The controller of your personal data processed for the marketing purposes indicated in the Statement is “Uzdrowisko Busko-Zdrój” Spółka Akcyjna, with its registered office in Busko-Zdrój, at ul. Rzewuskiego 1.
Who can I contact regarding the processing of my personal data?
For all matters related to the processing of your personal data by “Uzdrowisko Busko-Zdrój” S.A., you may contact our Data Protection Officer at the following email address: iod@ubz.pl or by post: Data Protection Officer “Uzdrowisko Busko-Zdrój” S.A., ul. Rzewuskiego 1, 28-100 Busko-Zdrój
What personal data is processed by Uzdrowisko Busko-Zdrój S.A.?
The personal data you provided in the Statement will be processed for the marketing purposes of “Uzdrowisko Busko-Zdrój” S.A. as specified in that Statement.
What is the purpose of processing my personal data?
The purpose of this processing is the direct marketing of “Uzdrowisko Busko-Zdrój” S.A.’s own products and services, within the scope specified in the Statement.
Legal basis
Your personal data are processed based on and within the scope of the written consent you have given — Article 6(1)(a) of the GDPR.
To whom are my personal data disclosed?
We ensure the confidentiality of your data. Due to the necessity of maintaining proper organization, e.g., in terms of IT infrastructure or ongoing matters related to our activities as “Uzdrowisko Busko-Zdrój” S.A., as well as for the exercise of your rights, your personal data may be disclosed to the following categories of recipients:
- service providers supplying technical and organizational solutions enabling us to manage our organization (in particular, providers of IT services);
- external entities in cases provided for by law.
Are my data transferred outside the European Union?
Your personal data will not be transferred outside the territory of the European Union.
How long will my personal data be processed?
The data subject has the right to withdraw consent at any time. We process your personal data for the purposes specified in the Statement until the consent is withdrawn. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Is providing my data mandatory?
In cases where data processing is based on the consent of the data subject, providing your personal data to the controller is voluntary.
What rights do I have?
As the controller of your data, we provide you with the right to access your personal data, and you may also request rectification, deletion, or restriction of its processing.
You also have the right to object to the processing of your data by “Uzdrowisko Busko-Zdrój” S.A., as well as the right to data portability to another data controller.
If “Uzdrowisko Busko-Zdrój” S.A. processes your personal data based on your consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal.
If you wish to exercise any of these rights, please contact us personally at the headquarters of “Uzdrowisko Busko-Zdrój” S.A., via the email address provided on our website, or in writing at our registered office address.
Please also be informed that you have the right to lodge a complaint with the supervisory authority responsible for data protection — the Personal Data Protection Office (Urząd Ochrony Danych Osobowych), located at ul. Stawki 2, 00-193 Warsaw.
Automated processing, including profiling
Your personal data will not be processed in an automated manner (including profiling) that could produce legal effects concerning you or similarly significantly affect your situation.
Transfer of personal data to third countries or international organizations
Your personal data will not be transferred outside the European Economic Area or to international organizations.

