Privacy Policy
Last amended: 07.05.2026
1. Introduction and applicability of this privacy policy
1.1. This Privacy Policy applies in all cases where Terena (“Centre”) processes the personal data of Data Subjects as the controller for the purpose of providing or offering services. In particular, this Privacy Policy applies where a Patient contacts the Centre to receive services and where the Centre provides its services to a Patient. This Privacy Policy also applies where an individual applies for employment with the Centre or where the Centre actively seeks to recruit a new employee.
1.2. The Centre is a healthcare service provider which, pursuant to the legislation in force in the Republic of Estonia (including the Health Services Organisation Act, the Health Insurance Act, the Medicinal Products Act, and the Statute of the Health Information System), has both the right and the obligation to process personal data necessary for the provision of healthcare services, including special categories of personal data. The Centre has a statutory obligation to protect the privacy of individuals, including Patients.
1.3. This Privacy Policy is effective as of the date stated above. The Centre reserves the right to amend and supplement this Privacy Policy unilaterally. Data Subjects will be notified of any amendments to this Privacy Policy by email or by other appropriate means.
1.4. The protection of the personal data of Data Subjects (including Patients) is of utmost importance to the Centre. Please read this Privacy Policy carefully in order to understand how the Centre processes personal data.
2. Definitions
2.1. For the purposes of this Privacy Policy, the following terms shall have the meanings set out below:
(a) “Centre” – Terena OÜ, registry code 12809632, with its registered address at Linnamäe tee 3, 13912 Tallinn, Estonia.
(b) “GDPR” – Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
(c) “HSOA” – the Health Services Organisation Act.
(d) “Privacy Policy” – this Privacy Policy, which explains the Centre’s rules for the processing of personal data.
(e) “Data Subject” – a natural person whose personal data is processed by the Centre.
(f) “Patient” – a Data Subject to whom the Centre provides healthcare services or who has contacted the Centre for the purpose of receiving healthcare services.
(g) “personal data” – any information relating to an identified or identifiable natural person (Data Subject). In other words, personal data includes any information that enables the identification of a Data Subject, regardless of the form or format in which the information is recorded, such as a person’s name, address, contact details, or personal identification code. Personal data also includes data that is inherently more sensitive in nature, namely special categories of personal data, including, among other things, a person’s health data.
(h) “processing of personal data” – any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation and alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
(i) “controller” – a natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
(j) “processor” – a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.
2.2. Any terms not specifically defined herein shall have the same meaning as set out in the GDPR and other applicable legislation.
3. CONTROLLER
3.1. The controller responsible for the personal data processing activities described in this Privacy Policy is the Centre, i.e. Terena OÜ, unless otherwise specified in this Privacy Policy.
3.2. For any questions relating to this Privacy Policy or the processing of personal data, you may contact the Centre’s Data Protection Officer by sending an enquiry to andmekaitse@terena.ee.
4. PURPOSES OF PROCESSING PERSONAL DATA, CATEGORIES OF PERSONAL DATA, LEGAL BASES, AND RETENTION PERIODS
4.1. The Centre processes personal data only for specified purposes and on the basis of applicable law. Below we provide an overview of the purposes for which the Centre processes personal data (i.e. why personal data is processed). For each purpose, we explain which personal data is processed, the legal basis for the processing in accordance with applicable legislation, and the applicable retention period.
4.2. Preparatory activities prior to the provision of healthcare services or other services provided by the Centre
(a) The Centre processes personal data for the purpose of carrying out activities prior to the provision of healthcare services or other services provided by the Centre. This occurs, for example, when a Patient (or the Patient’s relative or representative) contacts the Centre to receive healthcare services. Such activities may include, for example, appointment booking, preparations for the appointment, and communication relating to the preparation of healthcare services or other services, including sending appointment reminders and other organisational information.
(b) The personal data processed for this purpose includes the following:
i.The Patient’s first name and surname, date of birth, personal identification code, permanent residential address (and, where necessary, registered residential address), telephone number and, where available, email address; depending on the Patient’s age, the name of the educational institution, school or employer; and, for employed Patients, the name of the employer and job title.
ii. The reason why the Patient wishes to attend an appointment and receive healthcare services, which may also include health data.
iii.The Patient’s sex and information relating to the identification of the Patient; information relating to the appointment booking, including the place, time and purpose of the appointment; any other information disclosed by the Patient; and information relating to health insurance.
iv. Where a parent, guardian or other representative registers their child or a person under guardianship (or another represented person) as a Patient, the contact details of the parent, guardian or other representative (including name, address and telephone number), personal identification code, and relationship to the Patient.
v. Where communication with the Data Subject takes place by telephone, the telephone call may be recorded.
(c) The legal basis for the processing of personal data where the Centre processes personal data for the purpose of carrying out activities prior to the provision of healthcare services is Section 4¹(1) and Section 4¹(1¹)(1) of the Health Services Organisation Act (planning the provision of healthcare services). Where a Patient contacts the Centre to receive a service other than a healthcare service, the legal basis for processing is the Patient’s request within the meaning of Article 6(1)(b) of the GDPR. The personal data of the Patient’s parent, guardian (or other representative) is processed for the purpose of complying with the Centre’s legal obligation pursuant to Article 6(1)(c) of the GDPR.
(d) The retention periods for personal data are as follows:
i. Where services are not provided to the Patient (for example, where an appointment is booked but the Patient does not attend), the Centre retains the personal data for up to one (1) year after the last contact with the Patient.
ii. As a healthcare service provider, the Centre retains information system log files for five (5) years (Conditions and Procedure for the Documentation of Healthcare Services, Section 31(2)).
iii. Data collected for the conclusion of a healthcare services agreement with the Patient, where a longer retention period is not required by applicable law, is generally retained for as long as necessary for the performance of the agreement during its validity and for up to five (5) years following termination of the agreement.
iv. Telephone call recordings are retained for thirty (30) days.
4.3. Provision of healthcare services or other services and the performance of activities necessary for such provision
(a) The Centre also processes personal data for the purpose of providing healthcare services or other services and carrying out activities necessary for such provision. This may include activities such as diagnosing and treating the Patient’s illness or injury and communicating with the Patient in connection with the provision of healthcare services. It may also include providing information relating to the Patient to the Patient’s designated contact person or, where the Patient is a child or a person under guardianship, providing such information to the parent or guardian.
(b) The personal data processed for this purpose includes the following:
i. All of the personal data referred to above that is processed for the purpose of carrying out activities prior to the provision of healthcare services or other services provided by the Centre (see Section 4.2(b) above), including relevant health data relating to the Patient (including information regarding the Patient’s health condition, previous illnesses, current treatment, clinical data, laboratory test results and diagnoses). The categories of health data processed in each individual case depend on the healthcare service provided.
ii. The Patient’s designated contact person’s name, telephone number, residential address, personal identification code, relationship to the Patient, and email address.
iii. The Patient’s payment details or, where payment for the Patient’s healthcare services is made by another person, that person’s payment details.
iv. Where the Patient has been referred to the Centre by another healthcare service provider, the name and professional registration number of the healthcare professional employed by that provider.
(c) The legal basis for processing personal data where the Centre processes personal data for the provision of healthcare services and the performance of activities necessary for such provision is Section 4¹(1) of the Health Services Organisation Act. Where the Centre provides the Patient with services other than healthcare services, the legal basis is the agreement concluded between the Patient and the Centre pursuant to Article 6(1)(b) of the GDPR. Where the Centre processes the personal data of the Patient’s parent, guardian (or other representative), the legal basis is compliance with the Centre’s legal obligation pursuant to Article 6(1)(c) of the GDPR. Where payment for the services is made by a person other than the Patient, the Centre processes the relevant payment data on the basis of its legitimate interest pursuant to Article 6(1)(f) of the GDPR. The Centre’s legitimate interest is to receive payment for the services provided and to process the payer’s personal data for that purpose.
(d) The retention periods for personal data are as follows:
i. Data collected for the conclusion of a healthcare services agreement with the Patient, where a longer retention period is not required by applicable law, is generally retained for as long as necessary for the performance of the agreement during its validity and for up to five (5) years following termination of the agreement.
ii. Data evidencing the provision of outpatient and inpatient healthcare services is generally retained for thirty (30) years from the confirmation of the healthcare service data relating to the Patient (Section 42(4) of the Health Services Organisation Act). By way of exception, the following healthcare documentation is retained as follows (Section 42(5) of the Health Services Organisation Act): (i) student health records for five (5) years after graduation from or departure from school, as well as ambulance records, referral letters and referral responses for five (5) years after confirmation of the data; (ii) death notices and notices of the cause of death for ten (10) years after confirmation of the data; (iii) tissue samples containing health data collected for pathological examination during a person’s lifetime for as long as required for the provision of healthcare services, but no longer than thirty (30) years after confirmation of the data; (iv) autopsy reports for thirty (30) years after confirmation of the data; and (v) blood records, transfusion protocols and post-transfusion reaction protocols for thirty (30) years after the person’s death.
iii. As a healthcare service provider, the Centre retains information system log files for five (5) years (Conditions and Procedure for the Documentation of Healthcare Services, Section 31(2)).
4.4. Disclosure of medical records
(a) The Centre also processes personal data for the purpose of disclosing medical records. This may include activities such as providing medical records to the Patient, the Patient’s legal representative, a person authorised by the Patient, or a person who is entitled under applicable law to receive medical information.
(b) The personal data processed for this purpose includes the following:
i. The Patient’s personal data and health data contained in the relevant medical record.
ii. The recipient’s personal data, including contact details (such as email address), personal identification code, identification document details, residential address, relationship to the Patient, and the legal basis for receiving the medical records.
(c) The legal basis for processing personal data is either the Patient’s consent (Article 9(2)(a) of the GDPR), the provision of healthcare services pursuant to Section 4¹(1) of the Health Services Organisation Act, or compliance with the Centre’s legal obligation pursuant to Article 6(1)(c) of the GDPR.
(d) Personal data is retained for this purpose for as long as necessary to fulfil the relevant processing purpose or, where processing is based on consent, until the consent is withdrawn.
4.5. Handling and responding to requests for explanation, memoranda, requests for information, or proposals
(a) The Centre also processes personal data where it receives, handles and/or responds to requests for explanation, memoranda, requests for information, or proposals, and carries out various processing activities in connection therewith.
(b) For this purpose, the Centre may process the relevant personal data of the person submitting and sending such document (request for explanation, memorandum, request for information, or proposal), including contact details and any personal data contained in the relevant document.
(c) The legal basis for the processing of personal data is the performance of the Centre’s legal obligation pursuant to Article 6(1)(c) of the GDPR.
(d) Personal data is retained for this purpose for as long as necessary to fulfil the purpose for which it is processed.
4.6. Ensuring the quality of healthcare services
(a) The Centre also processes personal data for the purpose of ensuring the quality of healthcare services. This may include activities such as conducting patient satisfaction surveys (including requesting feedback) and handling and responding to complaints.
(b) For this purpose, the Centre may process the Patient’s personal data, relevant health data, and, where a complaint has been submitted, personal data relating to the complaint.
(c) The legal basis for the processing of personal data is ensuring the quality of healthcare services pursuant to Section 4¹(11)(2) of the Health Services Organisation Act.
(d) Feedback collected for the purpose of assessing Patient satisfaction is retained by the Centre for five (5) years from the date the feedback is received.
4.7. Recruitment of job applicants and assessment of candidates’ suitability for employment
(a) The Centre also processes personal data for the purpose of recruiting candidates for employment with the Centre and assessing their suitability for employment. This may include activities necessary for identifying potential candidates (for example, searching for suitable candidates through recruitment service providers) and assessing their suitability for employment (for example, communicating with candidates).
(b) For this purpose, the Centre may process the personal data of a job applicant (or an individual who may become a job applicant), including information disclosed by the individual, such as their name, email address, telephone number, address, curriculum vitae (CV), education, work experience, skills, qualifications, as well as other information available from public sources.
(c) The legal bases for the processing of personal data are as follows:
i. Where an individual independently applies for employment with the Centre – processing is necessary in order to take steps at the request of the data subject prior to entering into a contract pursuant to Article 6(1)(b) of the GDPR.
ii. Where the Centre actively searches for a new potential employee – processing is based on the Centre’s legitimate interest pursuant to Article 6(1)(f) of the GDPR. The Centre’s legitimate interest is to recruit new employees.
iii. Where an individual is not employed but their personal data is retained for longer than one (1) year after the end of the recruitment process, such retention takes place only on the basis of the individual’s consent pursuant to Article 6(1)(a) of the GDPR. The need to retain such data for one (1) year arises from Section 25 of the Equal Treatment Act, which establishes the limitation period for submitting a corresponding claim.
(d) The retention periods for personal data are as follows:
i. Personal data collected about a job applicant or an individual actively approached by the Centre for the purpose of assessing their suitability for employment is deleted one (1) year after the end of the recruitment process if no employment contract or other agreement is concluded with that individual.
ii. Alternatively, where the individual’s consent has been obtained for a longer retention period, the personal data will be retained until the consent is withdrawn (but in any event for no longer than three (3) years).
4.8.Compliance with the Centre’s legal obligations under applicable law
(a) The Centre also processes personal data for the purpose of complying with its legal obligations under applicable law. This may include any processing activities necessary to fulfil the relevant statutory obligation, such as compliance with accounting obligations, as well as obligations arising under the Health Services Organisation Act that apply to the Centre as a healthcare service provider.
(b) For this purpose, the Centre may process any personal data necessary to fulfil the relevant legal obligation imposed on the Centre. In particular, this may include the personal data of the Patient, the Patient’s designated contact person, parent or guardian, or the representative or contact person of a legal entity providing services or supplying goods to the Centre.
(c) Where the Centre processes personal data for the purpose of complying with its legal obligations under applicable law and the obligation relates to the provision of healthcare services, the legal basis for the processing is Section 4¹(1) of the Health Services Organisation Act or another relevant provision of healthcare legislation governing the specific obligation. In all other cases, the legal basis for the processing is Article 6(1)(c) of the GDPR.
(d) Personal data contained in accounting documents is retained for seven (7) years from the end of the relevant financial year. In all other cases, personal data is retained for as long as necessary to fulfil the purpose for which it is processed, unless a different retention period is prescribed by law.
4.9. Exercise of the Centre’s rights under applicable law
(a) The Centre also processes personal data for the purpose of exercising its rights under applicable law. This may include any processing activities necessary for the establishment, exercise, or protection of such rights. The specific processing activities are determined on a case-by-case basis in accordance with the legal right exercised by the Centre.
(b) For this purpose, the Centre may process any personal data necessary in connection with the legal right being exercised. In particular, this may include the personal data of the Patient, the Patient’s designated contact person, parent or guardian, or the representative or contact person of a legal entity providing services or supplying goods to the Centre.
(c) Where the Centre processes special categories of personal data for the establishment, exercise, or defence of legal claims, the legal basis for the processing is Article 9(2)(f) of the GDPR. In all other cases where the Centre processes personal data (including personal data that does not constitute special categories of personal data) for the purpose of exercising its rights under applicable law, the legal basis is the Centre’s legitimate interest pursuant to Article 6(1)(f) of the GDPR. The Centre’s legitimate interest is to protect and exercise its rights at its own discretion.
(d) Personal data processed for this purpose is retained for as long as necessary to fulfil the purpose for which it is processed, unless a different retention period is prescribed by law or by this Privacy Policy.
4.10. Promotion of the Centre
(a) The Centre may also process personal data for the purpose of promoting the Centre, but only where the Data Subject has given prior consent. In such cases, the Centre may create and publish promotional materials (for example, a photograph of a Centre employee) or request feedback from a client of the Centre for publication, for example, on the Centre’s website.
(b) For this purpose, the Centre may process the Data Subject’s name, position, location, the service provided, photograph, and other personal data in accordance with the individual’s consent.
(c) The legal basis for the processing is the Data Subject’s consent (Article 6(1)(a) of the GDPR).
(d) Personal data is processed until the consent is withdrawn.
4.11 Contacting Patients for marketing purposes
(a) The Centre may also process certain personal data in order to contact Patients for marketing purposes and to offer the provision of healthcare services.
(b) The personal data that may be processed for this purpose includes the Patient’s contact details (telephone number and email address), name, and personal identification code.
(c) The legal basis for the processing of personal data is the Patient’s prior consent (Article 6(1)(a) or Article 9(2)(a) of the GDPR). The Patient has the right to withdraw their consent at any time, either by contacting the Centre using the email address provided in this Privacy Policy or by clicking the relevant unsubscribe option included in the marketing communication.
(d) Marketing communications will be sent to the Patient until the Patient withdraws their consent.
4.12. Analysis of website usage
(a) The Centre may process certain personal data for the purpose of analysing visits to and use of the Centre’s website.
(b) The personal data that may be processed for this purpose consists of data collected through analytical cookies relating to the use of and visits to the website, i.e. website usage data (such as actions performed on the website). The Centre does not process health data for this purpose under any circumstances. Further information about cookies is provided in Section 7 of this Privacy Policy.
(c) The legal basis for the processing of personal data is the Centre’s legitimate interest pursuant to Article 6(1)(f) of the GDPR. The Centre’s legitimate interest is to analyse the use of and visits to its website.
(d) Personal data processed for this purpose is retained for a maximum period of three (3) years from the date of collection.
4.13. Display of personalised advertisements
(a) The Centre may process certain personal data for the purpose of displaying advertisements for the Centre to individuals who have visited the Centre’s website when they subsequently visit other websites.
(b) The personal data that may be processed for this purpose consists of data collected through marketing cookies relating to the individual’s website browsing history, i.e. data concerning the use of the Centre’s website (such as actions performed on the website) as well as the individual’s browsing history on other websites. The Centre does not process health data for this purpose under any circumstances. Further information about cookies is provided in Section 7 of this Privacy Policy.
(c) The legal basis for the processing of personal data is the website visitor’s consent pursuant to Article 6(1)(a) of the GDPR. The website visitor has the right to withdraw their consent at any time.
(d) Personal data processed for this purpose is retained for a maximum period of three (3) months from the individual’s most recent visit to the Centre’s website or until the individual withdraws their consent, whichever occurs first.
5. Sources of personal data and disclosure of personal data
5.1 The Centre obtains the Patient’s personal data both directly from the Patient and from third-party sources. Such third-party sources may include, in particular, the Patient’s representative (such as a parent or guardian), the Health Information System, another healthcare service provider, the Health Insurance Fund, the Prescription Centre, the Medical Imaging Repository (Pildipank), or another health-related information technology system. The Centre obtains the personal data of job applicants both from the applicants themselves and from public third-party sources (such as the internet). The Centre may also obtain the personal data of other Data Subjects either directly from the Data Subject or from a third-party source.
5.2 As a general rule, the disclosure of personal data to the Centre is voluntary. However, for example, if a Patient or the Patient’s representative chooses not to provide the required personal data, it will not be possible to book and/or use the services provided by the Centre. Likewise, if a job applicant chooses not to provide their personal data, they will not be able to apply for employment with the Centre.
6. Transfer of personal data
6.1. Pursuant to Section 768 of the Law of Obligations Act, the Centre, as a healthcare service provider, and all persons involved in the provision of healthcare services are obliged to maintain the confidentiality of any information concerning the Patient’s identity and state of health that becomes known to them in the course of providing healthcare services or performing their professional duties.
6.2. The Centre does not transfer personal data to third parties unless such transfer is authorised by law or is necessary for the provision of services.
6.3. The Centre may transfer personal data to processors authorised under applicable law who provide services necessary for the Centre’s provision of services to Patients and for the administration of the Centre’s day-to-day operations. All such processors ensure a level of protection for personal data as required by the GDPR and other applicable data protection legislation. As a general rule, personal data is not transferred outside the European Economic Area. However, should such a transfer exceptionally occur, appropriate safeguards in accordance with the GDPR will be implemented appropriate safeguards in accordance with the GDPR will be implemented to ensure a level of protection for personal data equivalent to that required under the GDPR. Such safeguards may include, for example, a data processing agreement concluded with the processor based on the European Commission’s approved Standard Contractual Clauses for the protection of personal data.
6.4. Within the framework described above, the Centre may transfer personal data to its IT partners (including various server hosting providers, IT support service providers, telecommunications service providers, and other information technology service providers), marketing partners, accounting service providers, payment service providers, and other service providers.
6.5. For example, the Centre uses an IT system called Heda in its day-to-day operations, which enables the management of the healthcare services provided by the Centre and the storage of data within the system, including health data. Heda also assists the Centre in complying with its statutory obligation to retain health data. Accordingly, the Centre makes personal data, including Patients’ health data, accessible to Gennet Laboratories AS (located in Estonia), which administers the Heda system and acts as the processor in respect of such personal data.
6.6. In addition, the Centre may transfer personal data to the Estonian Health Image Bank Foundation (SA Eesti Tervishoiu Pildipank), primarily diagnostic imaging data relating to the Patient (including ultrasound, X-ray, CT, and MRI images). As a healthcare service provider, the Centre is legally required to retain diagnostic images created in the course of providing healthcare services for thirty (30) years, and the Image Bank provides image archiving and display services to enable the Centre to comply with this obligation. With respect to the personal data transferred by the Centre to the Image Bank, the Centre acts as the controller and the Image Bank acts as the processor.
6.7. The Centre may also transfer personal data to companies providing laboratory or diagnostic analysis services. In such cases, the Centre transfers the relevant data (for example, a laboratory sample) to the service provider and receives the test results in return. Such transfer of personal data is necessary to enable the Centre to provide healthcare services to the Patient. In these cases, the relevant service provider acts as the processor. For example, the Centre currently uses service providers such as SYNLAB Eesti OÜ, OÜ Antegenes, and Natera, Inc.. The latter is located in the United States, and transfers of personal data are subject to the European Commission’s approved Standard Contractual Clauses in order to ensure the secure processing of personal data.
6.8. In addition, the Centre’s reception staff uses an IT system called Salesforce in its day-to-day operations to manage the Centre’s customer service and marketing activities and to store data within the system, including consents, customer emails, feedback, and appointment booking information. Salesforce is located in the United States; however, transfers of personal data are subject to the European Commission’s approved Standard Contractual Clauses to ensure the secure processing of personal data.
6.9. The Centre may also transfer personal data to its call centre service provider where the Centre uses call centre software for managing appointment bookings through its reception. The call centre is currently operated by Aurora Innovation AB, which is located in Sweden. As a general rule, health data is not made accessible to this service provider.
6.10. The Centre may also transfer personal data to providers of accounting software services, currently Merit Tarkvara AS, and to its banking service provider, currently AS LHV Pank. As a general rule, the Centre does not transfer health data to these service providers.
6.11. When providing healthcare services, the Centre transfers personal data (including health data) to the Health Information System, as this is a statutory obligation of the Centre as a healthcare service provider. The Health Information System is a central national database through which healthcare service providers, such as physicians and nurses, are able to exchange information and access health data submitted by other healthcare professionals concerning a Patient. The joint controllers of the Health Information System are the Ministry of Social Affairs and the Health Insurance Fund (Tervisekassa), while the processors are the Health and Welfare Information Systems Centre (TEHIK), the Estonian Health Image Bank Foundation (SA Eesti Tervishoiu Pildipank), and the Social Insurance Board. Further information is available on the Health Portal website at https://www.terviseportaal.ee/ or by email at abi@tehik.ee or by telephone at +372 7 943 943.
6.12. When providing healthcare services, the Centre also transfers personal data (including health data) to the Prescription Centre (Retseptikeskus), as this is likewise a statutory obligation of the Centre as a healthcare service provider. The controller of the Prescription Centre is the Health Insurance Fund (Tervisekassa). The Health Insurance Fund can be contacted by email at info@tervisekassa.ee or by telephone at +372 669 6630.
6.13. The Centre may also transfer personal data (including the medical certificate and the data contained therein) to the Estonian Transport Administration (Transpordiamet) where the Patient wishes to apply for a driving licence. In such cases, the controller of the relevant database is the Estonian Transport Administration. The Estonian Transport Administration can be contacted by email at info@transpordiamet.ee.
6.14. The Centre may also transfer personal data (including health data) to the relevant insurer, as the Centre, in its capacity as a healthcare service provider, is required upon the insurer’s request to provide personal data or grant access to such data where the personal data is necessary for the performance or enforcement of an insurance contract or for the assertion of recourse claims.
6.15. In addition, the Centre may transfer personal data to other persons or authorities where it is required to do so under applicable law.
7. Cookies
7.1. The Centre’s website uses cookies. Cookies are small text files that are stored in a user’s web browser or device when visiting a website. Cookies may be so-called first-party cookies, which are directly associated with the website, as well as third-party cookies, which are managed by third-party service providers.
7.2. The Centre uses the following cookies:
(a) Analytical cookies – cookies used for analysing website visits and usage (for example, how many users visit the website, how the website is used, how users arrive at the website, etc.). For this purpose, the Centre uses the following Google Analytics cookies: _ga (retained for 1 year, 1 month and 4 days), _gid (retained for 1 day), gat_gtag_UA* (retained for one minute), and ga* (retained for 1 year, 1 month and 4 days).
(b) Marketing cookies – cookies used to display personalised advertisements to website visitors, which collect information about the user’s browsing history on the Centre’s website and thereby enable the display of the Centre’s advertisements on Facebook or other websites. For this purpose, the Centre uses the following cookie: _fbp (retained for three months).
7.3. The website visitor has the right to refuse the use of cookies by not giving consent or by withdrawing consent, or by selecting the appropriate settings in their web browser and deleting cookies already stored on their device.
7.4. Cookies can be disabled by following the instructions in the web browser’s “help” or “support” function. Further information on how cookies work or how to disable cookies can also be found at www.allaboutcookies.org.
8. Rights related to the processing of personal data
8.1. The Data Subject (including the Patient) has the right at any time to contact the Centre by writing to the email address andmekaitse@terena.ee or by visiting the Centre’s reception in order to:
(a) request access to the personal data concerning the Data Subject, i.e. to obtain information about the personal data that the Centre has processed and collected regarding the Data Subject;
(b) request the rectification of personal data;
(c) request the erasure of personal data;
(d) restrict the processing of personal data;
(e) object to the processing of personal data;
(f) request the portability of personal data;
(g) request that no decision is taken regarding the Data Subject based solely on automated processing;
(h) withdraw consent given for the processing of personal data; and
(i) lodge a complaint regarding the processing of personal data.
8.2. The Data Subject also has the right to lodge a complaint with the Data Protection Inspectorate (Tatari 39, 10134 Tallinn; email: info@aki.ee).
8.3. In accordance with applicable law, the Centre may have the right to refuse to comply with the Data Subject’s request or to comply with it only in part, in which case the Centre will provide an explanation to the Data Subject.
8.4. The Data Subject’s request must be digitally signed, or if submitted in person at the Centre, the Data Subject must allow their identity to be verified using an identity document. If data is provided by email, it will be sent only in encrypted form. For security reasons, data is not disclosed by telephone.