Information on Personal Data Processing during the Provision of Medical Services

Within the medical services provided by CRISTAL PALACE a.s., reg. no.: 45359172, registered address: Mariánské lázně, Hlavní třída 61/66, 353 01 (hereinafter referred to as “Controller”), or by its partners, special categories of personal data are or may be processed as well. The following personal data are processed during the provision of the medical services:

Personal dataCategoryPurpose of processingTime of storingCategories of entities authorised to view the dataProcessing title
Name and surname: Personal dataStatutory obligations, identification for the time of storing medical documents**employees in charge and partners within the provision of medical services*legal obligation, necessity for the performance of services
Date and place of birthPersonal dataStatutory obligations, identificationfor the time of storing medical documentsemployees in charge and partners within the provision of medical services legal obligation, necessity for the performance of services
Address and permanent address Personal dataStatutory obligation, identification, delivery of documentsfor the time of storing medical documentsemployees in charge and partners within the provision of medical services legal obligation, necessity for the performance of services
sexpersonal datalegal obligations, identification for the time of storing medical documentsemployees in charge and partners within the provision of medical serviceslegal obligation, necessity for the performance of services
birth identification numberpersonal datalegal obligations, identificationfor the time of storing medical documentsemployees in charge and partners within the provision of medical serviceslegal obligation, necessity for the performance of services
citizenshippersonal datalegal obligations, identification for the time of storing medical documentsemployees in charge and partners within the provision of medical serviceslegal obligation, necessity for the performance of services
number of proof of identitypersonal datastatutory obligations, identificationfor the time of storing medical documentsemployees in charge and partners within the provision of medical serviceslegal obligation, necessity for the performance of services
email addresspersonal datacommunicationfor the time of storing email (up to 10 years)employees in charge and partners within the provision of medical servicesif an email is received, the reply is also sent by email
telephone number personal datacommunicationnot storedemployees in charge and partners within the provision of medical servicesIf contact is made by telephone, the request is dealt with by telephone.
images recorded during the provision of medical servicesspecial categories of personal data pursuant to Article 9 of the GDPR***provision of medical servicesfor the time of storing medical documentsemployees in charge and partners within the provision of medical servicesnecessity for the performance of services
signaturespecial categories of personal data pursuant to Article 9 of the GDPRlegal obligations, communication, provision of medical servicesfor the time of storing medical documentsemployees in charge and partners within the provision of medical serviceslegal obligation, necessity for the performance of services
genetic dataspecial categories of personal data pursuant to Article 9 of the GDPRprovision of medical servicesfor the time of storing medical documentsemployees in charge and partners within the provision of medical servicesnecessity for the performance of services
biometric dataspecial categories of personal data pursuant to Article 9 of the GDPRprovision of medical servicesfor the time of storing medical documentsemployees in charge and partners within the provision of medical servicesnecessity for the performance of services
information about the state of healthspecial categories of personal data pursuant to Article 9 of the GDPRprovision of medical servicesfor the time of storing medical documentsemployees in charge and partners within the provision of medical servicesnecessity for the performance of services
information about sexual lifespecial categories of personal data pursuant to Article 9 of the GDPRprovision of medical servicesfor the time of storing medical documentsemployees in charge and partners within the provision of medical servicesnecessity for the performance of services
Camera recordingsspecial categories of personal data pursuant to Article 9 of the GDPRProtection of life, health and property3 daysemployee in charge or a partner in the area of securityprotection of interests
sampled tissue / bodily fluidspecial categories of personal data pursuant to Article 9 of the GDPRprovision of medical servicesfor the time of storing medical documents / duration of consentemployees in charge and partners within the provision of medical servicesnecessity for the performance of services / consent (judged according to the situation)
bank account numberpersonal datalegal obligations, payments up to 15 yearsemployee in charge or business partnerlegal obligation, contract performance
bank card numberpersonal datalegal obligations, paymentsup to 10 days (tax document, accounting records)employee in charge or business partnerlegal obligation, contract performance
information about the insurance company, insured person’s numberpersonal datalegal obligations, provision of medical servicesfor the time of storing medical documentsemployees in charge and partners within the provision of medical serviceslegal obligation, contract performance


We hereby inform you that under the conditions provided for by legislation you have the right to:

Contact information of the person authorised by the Controller in the area of personal data protection: osobni-udaje@cimex.cz

We hereby inform you that you have the right:

  • to ask for confirmation as to whether or not personal data concerning you are being processed, and, where that
  • is the case, access to the personal data.
  • to have inaccurate data concerning you rectified.
  • to have inaccurate data concerning you deleted.
  • to the restriction of processing of the personal data concerning you.
  • to receive the personal data concerning you in a structured (electronic or printed) format and to transmit those data to another controller.
  • to withdraw your consent to personal data processing at any time.


We also inform you that you have the right to object to the processing of the personal data concerning you and lodge a complaint with the Office for Personal Data Protection at any time.

Contact forms for exercising the data subject’s rights: http://kontakt.cimex.cz/ Personal data may be processed manually or in an automated way. The personal data shall not be transferred outside the Czech Republic.

Where the reason for processing is not marked as “consent,” the aforementioned data must be processed by the data controller in order to achieve the objective of the relevant legal transaction, and therefore, if such personal data are not provided, the legal transaction cannot be performed.

Where the reason for processing is marked as “consent,” you have the right not to provide the aforementioned data without affecting the possibility of performance based on the legal transaction for which you have been asked to give consent to personal data processing.

If you have given and/or give the Controller consent to processing your personal data for marketing purposes, you may be sent commercial communication or other marketing materials at the Controller’s discretion.

Personal data belonging to a special category under Article 9 of the GDPR are processed by or under the responsibility of a professional subject to the obligation of professional secrecy under EU or Member State law or rules established by national competent bodies or by another person also subject to an obligation of secrecy under Union or Member State law or rules established by national competent bodies.

This notice applies to the provision of medical services. Notice of the processing of personal data by the Controller within the provision of accommodation and other services is available at reception.

* Especially health insurance companies and other medical services providers (if necessary as part of providing the patient with medical services, e.g. for subsequent treatment)
** According to the Ministry of Health Regulation no. 98/2012, on medical documents, or according to legislation replacing this Regulation. “GDPR” means the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).