Skip to main content
Poradnia Lekarza Rodzinnego Mariola Karolak-Tomczuk

Privacy Policy

Description of how personal data is processed for individuals using the website, contact forms, Facebook profile, and other communication channels of NZOZ Poradnia Lekarza Rodzinnego Mariola Karolak‑Tomczuk Sp. z o.o.

1. Personal Data Controller

In accordance with the General Data Protection Regulation (GDPR), the controller of your personal data is NZOZ Poradnia Lekarza Rodzinnego Mariola Karolak‑Tomczuk Sp. z o.o.

(hereinafter: "the Controller"). The Controller is responsible for the security of the provided personal data and its processing in accordance with the law, in particular GDPR and Polish specific laws (including the Act on Patient Rights and the Ombudsman for Patient Rights, the Act on Medicinal Activity, and the Act on the Information System in Healthcare).

2. Data Protection Officer

The Controller has appointed a Data Protection Officer (DPO) who can be contacted on all matters regarding the processing of personal data and the exercise of rights related to data processing:

3. Channels of Communication with the Controller

3.1. Phone contact

Via phone number 61 898 77 77 (registration open Mon-Fri 8:00-18:00). During the conversation, data necessary to handle the request is collected: name and surname, phone number, PESEL (in case of making an appointment through NFZ), and description of the case.

3.2. E-mail contact

At the addresses: ekamkt@gmail.com or lekarzmkt@gmail.com. By sending a message, you provide data such as your e-mail address, name and surname (if provided), and the content of the message.

3.3. Messenger / Facebook contact

The Controller maintains a profile on the social network Facebook (facebook.com/doktorkarolaktomczuk) and responds to messages in Messenger. By contacting us via Messenger, you agree to the data being governed by the regulations and privacy policy of Meta Platforms Ireland Limited, which acts as an independent data controller (facebook.com/privacy/policy).

The Controller receives access to: name and surname (public profile), profile picture, message content, dates and times of messaging, and other data voluntarily provided in the message content.

3.4. Contact form on the website

The Controller's website contains a contact form through which you can send an inquiry. Data entered into the form (name, e-mail, phone, message content) is transferred directly to the Controller.

3.5. Personal contact

A personal visit to the Controller's office at ul. Świt 34/36 lok. E1, 60‑376 Poznań - registration is open Mon-Fri 8:00-18:00.

4. Purposes and Legal Bases for Data Processing

4.1. Handling contact inquiries

We use your data to the extent necessary to handle inquiries and fulfill the request, including maintaining communication and providing answers.

Legal basis: Art. 6 para. 1 lit. f GDPR - legitimate interest of the Controller consisting in maintaining communication with persons interested in our services.

4.2. Special categories of data (health data)

In the event of providing special categories of data (e.g., information about health status, symptoms, treatment), you declare that you consent to their use for the purpose of properly processing the inquiry and fulfilling the request.

Legal basis: Art. 9 para. 2 lit. a GDPR - consent.

NOTICE: We recommend NOT transmitting detailed medical information (diagnoses, test results, treatment) in messages sent via Messenger, e-mail, or the contact form. To discuss health matters, we invite you to direct telephone or personal contact.

4.3. Provision of medical services

In case of using our medical services (registration as a patient, doctor's visit, examinations), data is processed on the basis of:

  • Art. 6 para. 1 lit. c GDPR - fulfillment of a legal obligation (in particular, the Act on Patient Rights and the Ombudsman for Patient Rights, and the Act on Medicinal Activity),
  • Art. 9 para. 2 lit. h GDPR - processing necessary for the purposes of preventive health, medical diagnosis, provision of healthcare, and management of health systems and services.

4.4. Fulfillment of legal obligations

Processing data for purposes related to legal requirements, including transfer of data to NFZ (National Health Fund), supervisory authorities, and law enforcement agencies.

Legal basis: Art. 6 para. 1 lit. c GDPR.

4.5. Marketing and post-visit communication

If separate consent is provided, your contact details may be used for:

  • sending reminders about upcoming visits (SMS, e-mail),
  • sending feedback requests after a visit,
  • informing about new services or organizational changes.

Consent is voluntary, independent, and may be withdrawn at any time. Legal basis: Art. 6 para. 1 lit. a GDPR - consent.

4.6. Exclusion of automated decision-making

Your data will not be used for decision-making based solely on automated processing of personal data, including profiling as defined in Art. 22 GDPR.

Providing data is voluntary but necessary to achieve the aforementioned purposes. Refusal may result in the inability to provide an answer, process a request, or provide medical services.

5. Data Retention Period

  • Data provided during contact (phone, e-mail, Messenger, form) - for the period necessary to provide an answer and resolve the matter, but no longer than 12 months after the last communication.
  • Data based on consent (e.g., marketing messages, feedback requests) - until the consent is withdrawn.
  • Patient medical records - generally 20 years from the date of the last entry in the medical records, according to the Act on Patient Rights and the Ombudsman for Patient Rights.
  • Accounting and tax documentation - 5 years from the end of the year in which the tax obligation arose.
  • Data regarding objections and withdrawal of consent - until the statute of limitations expires.

6. Withdrawal of Consent

You have the right to withdraw your consent to the processing of personal data at any time regarding data processed on its basis. If you exercise this right, we will stop processing such data and it will be deleted (unless its retention is required by other legal provisions). Withdrawal of consent does not affect the lawfulness of data use during the period when the consent was valid.

Consent can be withdrawn via contact: by phone (61 898 77 77), by e-mail (lekarzmkt@gmail.com or rodo@jamano.pl) or in person at the Clinic's office.

7. Rights of the Data Subject

You may request from us:

  • access to personal data (information about processed data and a copy of the data),
  • rectification of data (if they are incorrect or incomplete),
  • data portability (in cases specified in GDPR),
  • erasure of data (the right to be forgotten) - under the conditions specified in GDPR),
  • restriction of personal data processing,
  • objection to data processing - in case of processing based on legitimate interest (Art. 6 para. 1 lit. f GDPR).

You also have the right to lodge a complaint with the President of the Personal Data Protection Office (uodo.gov.pl) if you believe that the processing of your data violates the law.

Regardless of the rights arising from GDPR, as patients you have rights provided for in the Act on Patient Rights and the Ombudsman for Patient Rights. Regarding patient rights, you can contact the Patient Rights Ombudsman (gov.pl/web/rpp).

8. Data Recipients

While maintaining all security guarantees, we may transfer your data (other than persons authorized by the Controller) to other entities, including:

  • entities authorized to receive it by law (e.g., NFZ, supervisory authorities, courts),
  • entities processing it on our behalf - IT system providers (e.g., Kamsoft S.A. - KS‑SOMED system for medical record management),
  • website hosting service providers,
  • analytical service providers for the website (e.g., Google LLC within Google Analytics, if active),
  • social platform operators (Meta Platforms Ireland Limited, if contact occurs via Facebook/Messenger),
  • medical platform operators (DocPlanner Sp. z o.o. - if we use the ZnanyLekarz profile),
  • payment service operators (in case of settlements for commercial services),
  • other data controllers (e.g., law firms, consulting entities, DPO).

9. Transfer of Data Outside the European Economic Area

Some of the entities to which we entrust data processing (e.g., Meta Platforms, Google) have an office or process data outside the European Economic Area (EEA), particularly in the United States. Data transfer takes place on the basis of:

  • EU‑US Data Privacy Framework - for entities certified within the program,
  • standard contractual clauses approved by the European Commission (Art. 46 para. 2 lit. c GDPR),
  • other mechanisms required by GDPR.

You can obtain a copy of the applied security measures by contacting the Data Protection Officer (rodo@jamano.pl).

10. Cookies and Similar Technologies

10.1. What are cookies

Cookies are small text files sent by a website to the user's device (computer, tablet, smartphone) and stored in their browser. These files allow the user's device to be recognized and display the page according to their preferences.

10.2. Types of cookies used

  • Necessary cookies - ensure the correct functioning of the site (e.g., contact form operation, user session). These cookies are always active.
  • Analytical cookies - used to collect information about how the site is used, which helps us improve its operation (e.g., Google Analytics). Require your consent.
  • Marketing cookies - used to personalize displayed content and advertisements (e.g., Meta Pixel). Require your consent.

10.3. Cookie Management

Upon first visit to the site, a cookie banner appears, allowing you to grant consent for individual categories of cookies. You can also:

  • manage cookie settings in your web browser (each browser allows blocking, deleting, or configuring them),
  • withdraw consent for analytical and marketing cookies at any time by reopening the cookie banner on our site.

Restricting the use of cookies may affect some of the website's functionalities.

11. Social Media Profiles

The Controller maintains profiles on the following social networks and services:

  • Facebook: facebook.com/doktorkarolaktomczuk
  • Google Business Profile - profile in Google search engine and on Google Maps,
  • ZnanyLekarz - profile of dr Mariola Karolak‑Tomczuk.

Communication in these channels is also governed by the rules and privacy policies of the platforms, which are independent data controllers:

Statistical data regarding interactions on our profiles (reach, reactions, clicks) are collectively processed by the Controller to analyze communication effectiveness.

12. Data Security

The Controller applies appropriate technical and organizational measures to ensure the protection of processed personal data, in particular:

  • encryption of communication with the website (HTTPS/SSL protocol),
  • access control to medical records in accordance with the law on patient rights,
  • training of staff in the field of personal data protection,
  • procedures for responding to data security incidents,
  • regular security audits of IT systems.

The Controller complies with the requirements arising from GDPR, the law on the information system in healthcare, and - to the extent applicable - the NIS2 directive (Directive 2022/2555, implemented in Poland from April 3, 2026).

13. Additional information for persons whose data was transferred during contact

If your data was obtained during contact with the Controller (e.g., through a message sent by a third party on your behalf, upon recommendation of another patient), the Controller will process it to the extent necessary to handle the request and fulfill the inquiry, including maintaining communication and providing answers. You have the right to contact the Controller with a request for access to your data, its rectification, erasure, or restriction of processing, as well as an objection to processing.

14. Contact regarding personal data protection

15. Changes to the Privacy Policy

The Controller reserves the right to make changes to this Privacy Policy, particularly in the event of changes in legislation, implementation of new services, or technologies. We will inform you of any significant changes by publishing the updated version on our website. We recommend regularly reviewing the content of the Privacy Policy.

Document version: 1.0. Last update date: May 2026.

CallRxMessage