PROMOȚII
Descoperă promoțiile care îți fac bine!
Privacy Notice Regarding the Processing of Personal Data for the iMed Application
In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“GDPR”), through this Privacy Notice, we, MED LIFE S.A., with our registered office in Bucharest, 365 Calea Griviței, Sector 1, registered with the Bucharest Trade Registry under no. J1996003709402 and having unique registration code (CUI) 8422035 (hereinafter referred to as “MedLife”), acting as data controller, explain below when and why we process your personal data, how we use such data, the circumstances in which we may disclose them to others, and how we store them when you activate and use the iMed Application.
This Privacy Notice supplements MedLife’s general Privacy Policy and applies specifically to the iMed Application.
If you have any questions regarding how we process your personal data or wish to exercise any of the rights described below, you may contact our Data Protection Officer using any of the following methods:
- by post at: 365 Calea Griviței, Sector 1, Bucharest, Romania;
- by email at: sesizari@medlife.ro
What is the iMed Application
The iMed Application is an optional digital functionality available within the MedLife mobile application that allows users to view, in a centralized format, certain data available in their MedLife account and, if they choose, data obtained from connected external devices, as well as an indicative aggregated lifestyle/wellness score and certain descriptive statistical positioning relative to a reference population.
These scores and descriptive statistical positioning do not constitute a medical diagnosis, do not provide recommendations for medical investigations or treatments, and do not classify the user as having or not having a particular medical condition.
Categories of Personal Data Processed
MedLife may process the following categories of personal data, depending on the data available and the consents you have provided: MedLife account identification data; authentication and security data; laboratory test results; medical history data; medical history and anamnesis data; biometric and physiological data; lifestyle data; data relating to physical activity, sleep, or other parameters imported from external devices; genetic data or polygenic risk scores available in your medical record, if you choose to include them; data relating to your use of the Application; technical logs; and records of consents provided or withdrawn.
Sources of Personal Data
The data may be obtained from your MedLife account, from the history of services and results available in the MedLife mobile application, from information provided by you, from external devices connected via API (wearables), and from calculations generated by the Application based on such data.
When you import data from an external device, the provider of the device or associated platform may process your data as an independent data controller in accordance with its own privacy policy.
Categories of Personal Data Processed, Purposes and Legal Bases for Processing
| Personal data processed | Purpose of processing | Legal basis |
| MedLife App Account Credentials, User Identifiers, Settings | Activating the App and linking it to your MedLife account | Art. 6 para. 1 letter (b) of the GDPR - Execution of pre-contractual steps/measures or performance of the contract
|
| Health data, analytics, biometrics, history, lifestyle, PRS, wearable data | Display of aggregate scores, an indicative lifestyle/wellness indicator as well as descriptive statistical positioning scores in relation to a reference population | Art. 6 para. 1 lit. (a) of the GDPR – Your consent
Art. 9 para. 2 lit. (a) GDPR – Your explicit consent to the processing of health status data |
| Date de sănătate și date din wearables (de ex. informații privind activitatea fizică, pașii, somnul, ritmul cardiac, greutatea, caloriile, exercițiile, parametri fiziologici sau alte date disponibile în wearables) agregate temporal | Display data evolution over time | Art. 6 para. 1 lit. (a) of the GDPR – Your consent
Art. 9 para. 2 lit. (a) GDPR – Your explicit consent to the processing of health status data |
| Data from wearables (e.g., information about physical activity, steps, sleep, heart rate, weight, calories, exercise, physiological parameters, or other data available in the wearable), API identifiers, permissions | Importing data from external devices | Art. 6 para. 1 lit. (a) of the GDPR – Your consent
Art. 9 para. 2 lit. (a) GDPR – Your explicit consent to the processing of health status data |
| Genetic data, polygenic risk scores | Inclusion of genetic/PRS data in the form of a score for descriptive statistical positioning in relation to a reference population | Art. 6 para. 1 lit. (a) of the GDPR – Your consent
Art. 9 para. 2 lit. (a) GDPR – Your explicit consent to the processing of health status data |
| Logs, technical identifiers, security events | App Security and Preventing Unauthorized Access | Art. 6 para. 1 letter (f) of the GDPR – The legitimate interest to protect the application or Art. 6 para. 1 lit. (c) of the GDPR – Processing is necessary for the fulfilment of a legal obligation
|
| Consent history, withdrawals, document versions | Evidence of consents and demonstration of compliance | Art. 6 para. 1 letter (f) of the GDPR – The legitimate interest to protect the application or Art. 6 para. 1 lit. (c) of the GDPR – Processing is necessary for the fulfilment of a legal obligation
|
| Identification data, data covered by the application | Resolution of GDPR rights requests | Art. 6 para. 1 lit. (c) of the GDPR – Processing is necessary for the fulfilment of a legal obligation |
| Aggregated, pseudonymised data or, if necessary, personal data | Algorithm improvement, if enabled separately | Art. 6 para. 1 lit. (a) of the GDPR – Your consent
Art. 9 para. 2 lit. (a) GDPR – Your explicit consent to the processing of health status data |
| Aggregated, anonymized/pseudonymized data or, if necessary, personal data | Anonymization or pseudonymization of data and their inclusion in statistics and scientific research studies in the medical field | Art. 6 para. 1 lit. (a) GDPR – Your consent
Art. 9 para. 2 lit. (a) GDPR – Your explicit consent to the processing of health data |
Profiling and Automated Decision-Making
The Application involves profiling within the meaning of the GDPR, as it processes personal data for the purpose of displaying an indicative aggregated lifestyle/wellness score and descriptive statistical positioning relative to a reference population. The scores do not produce legal effects concerning you or similarly significantly affect you, as they do not automatically determine access to services, pricing, appointments, eligibility, diagnosis, or treatment.
Where profiling involves genetic, biometric, or health data, MedLife applies the additional safeguards provided for under Article 3 of Law No. 190/2018, with such processing being carried out exclusively on the basis of your explicit consent and subject to specific technical and organizational measures designed to protect your rights and freedoms.
You will not be subject, solely as a result of using the dashboard, to a decision based exclusively on automated processing that produces legal effects concerning you or similarly significantly affects you.
Recipients of Personal Data
Personal data may be accessed by authorized MedLife personnel only to the extent necessary for the administration, security, and functional support of the Application. Personal data may also be processed by technical service providers, hosting providers, developers, security service providers, support providers, and other partners acting, as applicable, as data processors or independent data controllers. Where such partners act as data processors, the processing is carried out pursuant to data processing agreements concluded in accordance with Article 28 of the GDPR, which require appropriate safeguards for the confidentiality and security of personal data.
Data from external devices are imported based on the permissions you have granted. MedLife does not ordinarily transmit the score back to the device provider unless such transmission is expressly described and authorized.
International Data Transfers
As a general rule, we will not transfer your personal data outside the European Economic Area (EEA). In exceptional circumstances, and only where necessary, any transfer of your personal data outside the EEA will be carried out only with appropriate safeguards in place in accordance with Articles 44–49 of the GDPR (for example, Standard Contractual Clauses) and with appropriate notice provided to you.
Please note that, if you choose to connect an external device (wearable), the provider of that device or the associated platform may be established outside the EEA (for example, in the United States of America) and may process your personal data as an independent data controller, in accordance with its own privacy policy and international data transfer mechanisms, over which MedLife has no control.
How Long We Retain Your Personal Data
The data used for the Application are retained for as long as the functionality remains active. Following deactivation of the Application or withdrawal of consent, data specific to the Application will be retained for a maximum period of 30 days, as necessary to complete the technical deactivation process and cease the relevant processing activities.
By way of exception, the following will be retained: (i) records of consents given and withdrawn, for the period during which MedLife may be held liable and, in any event, for the general limitation period of three years; (ii) technical and security logs, for a maximum period of 12 months; and (iii) data required to comply with specific legal obligations, for the period prescribed by applicable law. Health data and genetic data will be deleted or anonymized upon expiry of the applicable retention periods.
Following deactivation of the Application or withdrawal of consent, MedLife will cease calculating scores and statistical positioning and will delete or anonymize data specific to the Application, except for data that must be retained for other lawful purposes.
Your Rights
Unless otherwise provided by law, you have the following rights in relation to your personal data:
(i) the right of access to your personal data – the right to obtain confirmation from us as to whether we process your personal data and, where this is the case, the right to access such data and obtain information about the processing;
(ii) the right to request rectification of your personal data – the right to request, without undue delay, the correction of inaccurate personal data or the completion of incomplete personal data;
(iii) the right to request erasure of your personal data where you consider that the personal data are no longer necessary for the purposes for which they were collected or processed and there is no other legal basis for the processing, where they have been unlawfully processed by us, or where the data must be erased in order to comply with a legal obligation;
(iv) the right to request restriction of processing where: (a) you contest the accuracy of the data; (b) the processing is unlawful and you oppose the erasure of the data and request restriction of their processing instead; (c) the data are no longer necessary for the processing carried out by the Company, but you require them for the establishment, exercise or defence of legal claims; or (d) you object to processing carried out by us on the basis of our legitimate interests;
(v) the right to object to the processing of personal data based on the Company’s legitimate interests – unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or that the processing is necessary for the establishment, exercise or defence of legal claims;
(vi) the right to data portability – the right to receive the personal data you have provided to the Company in a structured, commonly used and machine-readable format, as well as the right to transmit those data to another data controller;
(vii) the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, except where we have duly obtained your consent for such processing;
(viii) the right to withdraw your consent at any time in relation to processing activities based on consent, without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal;
(ix) the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal), at 28–30 General Gheorghe Magheru Blvd., Sector 1, postal code 010336, Bucharest, telephone: 0318 059 211, via www.dataprotection.ro, regarding the processing of your personal data.
Data Security
MedLife implements appropriate technical and organizational measures, including access controls, encryption, logging, segmentation, monitoring, security testing, and internal incident management procedures. The level of these measures is tailored to the high level of risk associated with the processing of health and genetic data.
The processing of your health data is carried out in compliance with medical professional secrecy and patient data confidentiality requirements, in accordance with Law No. 46/2003 on Patients’ Rights and Law No. 95/2006 on Healthcare Reform.
Given the large-scale processing of special categories of personal data, MedLife has carried out a Data Protection Impact Assessment (DPIA) in accordance with Article 35 of the GDPR.