Privacy Policy
1. Definitions
The following capitalized terms shall have the following meanings:
| Personal Data | Means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name and surname, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person. |
| GDPR | Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). |
| Service | The website available at the address www.medmentis.pl. |
| Psychotherapeutic Session | A meeting between the Entitled Person and a psychotherapist scheduled via the Service, aimed at conducting a psychological consultation or a psychotherapeutic process. |
| Entitled Person | A natural person indicated by the User at the time of booking, entitled to use the Psychotherapeutic Session. The Entitled Person may be: (a) the User; (b) a person for whom the User is a statutory representative, legal guardian, or a person authorized to act on their behalf. |
| User | A natural person with full legal capacity, using the Service, in particular for the purpose of browsing information available on the Service, making a Booking, or Requesting Contact. |
2. Processing of Personal Data
2.1 The Controller of the Personal Data of Users and Entitled Persons within the meaning of the GDPR regulations is Wiktoria Urbanik, conducting business under the name MedMentis Wiktoria Urbanik, address: Stanisława Lema 24/67, 31-571 Kraków, NIP: 6751826838 (“Controller”).
2.2 The Controller processes the User’s Personal Data in the following scope:
2.2.1. for purposes necessary for the legitimate interests pursued by the Controller, in particular ensuring the proper functioning of the Service, the ability to navigate the Service and use its basic functions, as well as establishing, exercising, or defending against potential claims based on Art. 6(1)(f) of the GDPR;
2.2.2. for purposes necessary to adapt the operation of the Service to the User’s preferences based on Art. 6(1)(a) of the GDPR;
2.2.3. for purposes necessary to perform the agreement for the provision of electronic services based on Art. 6(1)(b) of the GDPR;
2.2.4. for purposes necessary for the legitimate interests pursued by the Controller, in particular providing contact before concluding an agreement for the provision of psychotherapeutic services, as well as establishing, exercising, or defending against potential claims based on Art. 6(1)(f) of the GDPR.
2.2 The Controller processes the Entitled Person’s Personal Data in the following scope:
2.3.1 for purposes necessary to perform the agreement for the provision of psychotherapeutic services or to take steps at the request of the data subject prior to entering into an agreement based on Art. 6(1)(b) of the GDPR;
2.3.2 for purposes necessary to comply with legal obligations incumbent on the Controller, in particular those resulting from tax law and accounting regulations based on Art. 6(1)(c) of the GDPR;
2.3.3 for purposes necessary for the legitimate interests pursued by the Controller, in particular providing contact before concluding an agreement for the provision of psychotherapeutic services and during the term of the agreement, as well as establishing, exercising, or defending against potential claims based on Art. 6(1)(f) of the GDPR.
2.4 For matters related to the protection of Personal Data, you can contact the following address: kontakt@medmentis.pl.
2.5 The recipients of Personal Data may be – only in cases where it is necessary and to the extent required – entities cooperating with the Controller in terms of services provided to the Controller and supporting current processes, in particular entities providing IT, accounting, and legal services.
2.6 Personal Data will not be transferred by the Controller outside the European Economic Area, to third countries, or international organizations.
2.7 If the processing of data is necessary for the performance of an agreement to which you are a party, or to take action at your request prior to entering into an agreement, your Personal Data will be processed for the duration of the agreement, and after that period for the limitation period of potential claims resulting from generally applicable law.
2.8 If the processing is necessary to fulfill a legal obligation incumbent on the Controller, your Personal Data will be processed for the period of time resulting from generally applicable law.
2.9 If the processing is necessary for the purposes of the legitimate interests pursued by the Controller, your Personal Data will be processed for a period no longer than is necessary for the purposes for which the data are processed or until an objection is raised to the processing of Personal Data in the scope of processing for these purposes, for reasons related to your particular situation, unless the Controller demonstrates the existence of valid legitimate grounds for processing that override your interests, rights, and freedoms, or grounds for establishing, exercising, or defending claims.
2.10 Providing Personal Data is voluntary, but necessary to conclude an agreement with the Controller.
2.11 The data subject has the right to access their Personal Data, rectify it, delete it, limit processing, transfer Personal Data – in the scope of data processing for purposes necessary to perform the agreement and in an automated manner – and the right to object to the processing of Personal Data – in the scope of data processing for purposes resulting from legitimate interests pursued by the Controller, unless the Controller demonstrates the existence of valid legitimate grounds for processing that override the interests, rights, and freedoms of the data subject, or grounds for establishing, exercising, or defending claims.
2.12 The data subject also has the right to lodge a complaint with the supervisory authority for the protection of Personal Data – the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
3. Cookies
3.1 The Service uses cookies (i.e., small text files sent to the User’s device, identifying them in a way necessary to simplify or cancel a given operation) in order to collect information related to the User’s use of the Service.
3.2 The Service uses the following types of cookies based on the purpose of their use:
3.2.1 necessary cookies (system) – they are used to ensure the proper operation of the Service, the ability to navigate the Service, and the use of basic functions. They are necessary for the Service to function and cannot be disabled, as disabling them would prevent it from working;
3.2.2 functional cookies – they are used to remember settings selected by the User and choices made within the Service.
3.3 Types of cookies based on the storage period:
3.3.1 session cookies – they are stored on the User’s device and remain there until the end of the given browser session. The saved information is then permanently deleted from the device memory;
3.3.2 persistent cookies – they are stored on the User’s device for the time specified in the cookie parameters or until they are deleted by the User. Ending a given browser session or turning off the device does not delete them from the User’s device.
3.4 Types of cookies based on origin:
3.4.1 first-party cookies – set by the Service’s web servers;
3.4.2 third-party cookies – set by the web servers of sites other than the Service.
3.5 Information, including Personal Data, obtained in connection with the use of cookies in the Service, is processed by the Controller.
3.6 Cookies are used in the Service based on the User’s consent expressed by selecting the appropriate option while using the Service or by appropriately configuring the User’s browser settings. Granting consent for the use of cookies in the Service is voluntary.
3.7 Before granting consent for the use of cookies, the User is informed about the purposes of using cookies and about the possibility of changing cookie settings at any time.
3.8 The User may withdraw previously granted consent for the use of cookies and change cookie settings at any time, as well as delete cookies from the User’s device memory.
3.9 Furthermore, the User may at any time change the settings regarding cookies used in the Service in the web browser settings. Detailed information on the possibility and methods of changing cookie settings in the most popular web browsers can be found at the following addresses:
- Google Chrome https://support.google.com/chrome/answer/95647?hl=pl;
- Firefox https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer;
- Internet Explorer https://support.microsoft.com/en-us/topic/delete-and-manage-cookies-168dab11-0753-043d-7c16-ede5947fc64d;
- Opera https://help.opera.com/en/latest/web-preferences/#cookies;
- Safari https://support.apple.com/en-us/guide/safari/sfri11471/mac.
4. Use of Google Maps
4.1 The Service uses the function of embedding maps provided by Google Maps.
4.2 In order to display the map, it is necessary to establish a connection with Google servers. In connection with this, Google may obtain access to User data, in particular:
1. IP address,
2. information about the device and browser,
3. technical data regarding the visit to the site.
4.3 This data may also be processed by Google for its own purposes, in accordance with Google’s privacy policy: https://policies.google.com/privacy.
4.4 Please note that user data may be transferred outside the European Economic Area, in particular to the United States of America.
4.5 Google Maps are activated in the Service only after obtaining the User’s consent.
List of Cookies
| Tracker name | Provider | Category | Domain |
|---|---|---|---|
| pll_language | medmentis.pl | Preferences | medmentis.pl |
| CookieConsent | medmentis.pl | Necessary | medmentis.pl |
| wpEmojiSettingsSupports | medmentis.pl | Necessary | medmentis.pl |