Information on personal data processing

Introductory Provisions

The company RehaGym, s.r.o., ID No. 17248434, with its registered office at V jehličí 2121/8, Prague 4 - Krč (hereinafter referred to as the "controller") processes as a controller personal data of its clients, i.e. persons using services provided at the RehaGym Centre (hereinafter referred to as "data subjects") in connection with its business activities - operation of the RehaGym Centre at V Jehličí 2121/8, Prague 4 - Krč.

With the exception of selected personal data of clients who use the additional service "visual tracking of the set exercise plan", and whose personal data are transferred for processing with their consent to the operator of the OnForm fitness application, OnForm, Inc., with its registered office at 1998 Pleasant Glen Lane, Bellvue, CO 80512, USA, the administrator does not transfer any personal data to a third country (i.e. a country outside the European Union),  or any international organization.

When processing personal data by the controller, no decision-making is made that would be based exclusively on automated processing, including profiling.

Rights of data subjects

Data subjects have the following rights towards the controller:

  • Right to access their personal data (i.e. the right to request information about the processing of personal data)
  • Right to correction or completion of their personal data (i.e. the right to request the correction of inaccurate personal data or the right to request completion of incomplete personal data)
  • Right to erasure – the so-called right to be forgotten (i.e. the right to request the erasure of personal data concerning the relevant data subject, if the data are processed unlawfully, if they are no longer necessary or if the data subject has objected to the processing and there are no prevailing legitimate reasons of the controller for the processing)
  • Right to restriction of processing (i.e. the right to request the controller to restrict the processing of the personal data of the relevant data subject only to their storage, if the processing is unlawful, is no longer necessary, or if the data subject disputes the accuracy of the data or if the data subject has objected to the processing)
  • Right to object to processing (i.e. the right of the data subject to object, on grounds relating to his or her particular situation, to the processing of his or her personal data based on a legitimate interest, unless the controller demonstrates legitimate grounds for the processing overriding the interest of the data subject or for the establishment, exercise or defence of legal claims)

These rights may be exercised electronically by e-mail to the address "info@rehagym.cz" or in writing by letter delivered to the address of the RehaGym centre V jehličí 2121/8, Prague 4 - Krč. Since the processing of personal data is not fully automated, data subjects do not have the right to portability of personal data (the so-called right to portability).

If the data subject believes that the processing of his/her personal data is defective in any way, he/she has the right to contact the statutory body of the controller at any time with his/her complaint or has the right to file a complaint with the supervisory authority, which is the Office for Personal Data Protection (more at www.uoou.cz).

Purpose and legal basis of processing

The purpose of the processing of personal data is:

  • proper provision of services within the operation of the RehaGym Centre, i.e. in particular in the field of fitness, nutritional counselling, psychological counselling and diagnostics and the provision of health and related services in the areas of rehabilitation and physical medicine, physiotherapy and ergotherapy, as well as the application and enforcement of rights and obligations related thereto,
  • fulfilment of the statutory obligations of the controller, in particular in the area of keeping medical records (pursuant to Section 53 of Act No. 372/2011 Coll., on health services and the conditions of their provision) and in the area of providing health services arising from the relevant legal regulations,
  • marketing and promotion of the RehaGym centre and the services provided in this centre,
  • protection of the property of the controller and third parties, ensuring the safety of persons within the operation of the RehaGym centre, prevention of emergencies and obtaining data for dealing with possible insurance claims, offences or other unlawful conduct in relation to the operation of the RehaGym centre.

The specific purposes of processing for individual groups of data subjects are listed in the table that forms Annex No. 1 to this information.

The legal basis for the processing of personal data is:

  • processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
  • processing is necessary for compliance with a legal obligation to which the controller is subject;
  • processing is necessary for the purposes of the legitimate interests of the controller or a third party; or
  • processing is based on the consent given by the data subject.

In the case of personal data concerning health, the legal basis for processing is:

  • processing is necessary for the purposes of preventive medicine, medical diagnosis and/or the provision of health services;
  • processing is necessary for the establishment, exercise or defence of legal claims.

Details are given in the table attached as Annex No. 1 to this information.

If the processing is based on consent granted by the data subject, the data subject may withdraw this consent at any time, in whole or in part, by sending a written notice to the controller at info@rehagym.cz or to the address RehaGym, s.r.o., V jehličí 2121/8, Prague 4 – Krč. In such a case, the controller shall immediately terminate the processing of the relevant personal data, unless there is another legal basis for their processing.

Scope of processed data

In accordance with the principle of minimization of personal data, the scope of personal data processing is derived from the specific purpose of processing. The scope of processed personal data depending on the individual purposes of processing is specified in the table that forms Annex No. 1 to this information. 

Recipients of personal data

Personal data contained in medical records may only be made available under the conditions set out in the Health Services Act.

Data of data subjects may be transferred in connection with the performance of the statutory or contractual obligations of the controller to the following recipients:

  • auditors, tax or legal advisors of the controller (to the extent necessary when providing services to the controller),
  • persons cooperating with the controller or persons through whom the controller provides services within the operation of the RehaGym Centre (to the extent necessary for the provision of the relevant service),
  • insurance companies or insurance intermediaries of the controller in connection with the settlement of insurance claims,
  • Police of the Czech Republic, tax administration bodies or other public administration bodies of the Czech Republic (within the exercise of their competence or in connection with its exercise).

The following processors may be entrusted by the controller with the processing of personal data of data subjects:

  • persons cooperating with the controller, or persons through whom the controller provides services within the operation of the RehaGym Centre (to the extent necessary for the provision of the relevant service),
  • suppliers of database, reservation or other information systems or applications used by the controller,
  • providers of accounting services and related reporting,
  • Data storage service providers,
  • archiving service providers.

Period of storage of personal data

Personal data of data subjects are generally processed for the duration of the contractual relationship between the controller and the data subject and also for the period when any claims related to the services provided may be asserted or enforced.

Personal data incorporated into documents for which longer archiving periods are prescribed by special legal regulations are stored for such longer archiving periods.

Specific information on the period of storage (processing) of personal data is given in the table that forms Annex No. 1 to this information.

Request to provide personal data

To the extent that the processing of personal data is necessary for the fulfilment of the legal obligation of the controller, or for the preparation, conclusion and performance (including enforcement) of a contract on the basis of which the services of the RehaGym centre are provided to the client, the provision of personal data of the data subject is a statutory or contractual requirement. If the personal data is not provided in such a case, the relevant contractual relationship cannot be established, or the services of the controller cannot be used.