This Privacy Policy describes the processing of personal data in the Ortopedia Hrubieszów application, an internal workflow tool used for staff availability, surgical planning and coordination of patients being prepared for surgery.
The app is not intended for patients, does not provide medical advice and does not replace the official medical record system. Access is limited to users with an individual account, active authorization and an assigned role.
1. Data Controller
Indywidualna Praktyka Lekarska Albert Chemperek, an individual medical practice, registered address: ul. Piłsudskiego 11, 22-500 Hrubieszów, Polish tax identification number (NIP): 7142008400. No KRS registration applies.
Privacy contact: kontakt@ortohru.pl.
No Data Protection Officer has been appointed. Privacy requests may be sent to the email address above.
2. Data categories
- User data: name, email address, role, account status, linked physician details, availability and activity records, authentication and security information.
- Patient data: name, surname, PESEL national identification number, diagnosis, injury or condition, planned procedure, admission and surgery dates, responsible physician, organizational and medical notes necessary for care coordination.
3. Purposes and legal bases
Patient and health data are processed where necessary for the provision or management of health care, on the basis of Article 6(1)(c) and Article 9(2)(h) GDPR together with applicable Polish health-care law. User account and access data are processed on the basis of Article 6(1)(b), (c) or (f) GDPR, depending on the user’s relationship with the controller and the need to protect the system.
4. Recipients and service providers
- authorized users according to their role;
- LH.pl Sp. z o.o. (lh.pl) for website, public documents and, if configured, domain email hosting in Poland;
- Supabase for authentication, database and backend functions, with the primary project region in Central EU (Frankfurt), Niemcy;
- Apple for iOS app distribution and updates through the App Store;
- other processors or authorities where permitted or required by law.
5. Security
Security measures include individual accounts, role-based access, mandatory multi-factor authentication, encrypted transport, backend encryption of selected patient fields, logging of patient-data access and administrative actions, and backup/recovery mechanisms available under the configured service plans.
6. Retention
- User accounts are retained while authorization remains active, until access is revoked or the account is disabled. Necessary security and accountability records may be retained afterwards.
- Operational patient data are generally retained for the duration of the treatment-planning process and up to 90 days after it ends, unless the data form part of the medical record or are required for an incident investigation.
- Medical-record data are retained for statutory periods under Polish law, generally 20 years from the end of the calendar year of the last entry, subject to legal exceptions.
- Security and audit logs may be retained for up to 6 years; support correspondence for up to 12 months after closure.
7. Rights
Depending on applicable law, individuals may request access, rectification, erasure, restriction, objection or portability, and may lodge a complaint with the Polish supervisory authority. Requests: kontakt@ortohru.pl.
8. Account and data deletion
Instructions are available at Account and data deletion. Uninstalling the app does not delete the account or backend data.
9. No advertising or tracking
The app does not sell personal data, use behavioral advertising or track users across apps or websites for marketing.