Privacy policy

Privacy Policy for sexreassignmentsurgery.eu

Effective date: 1 April 2023 (with later editorial updates)

1) General information

The data controller is Timeless Chirurgia Plastyczna sp. z o.o., based in Warsaw, Poland (hereinafter: “TIMELESS”).

This Policy explains how we process and protect personal data (including health data) of individuals:

  • who browse the website sexreassignmentsurgery.eu (the “Website”), and
  • who use Services offered by TIMELESS, including patients and persons authorised by patients to receive information about their health and/or access medical records.

We process data in compliance with applicable law, including the GDPR (Regulation (EU) 2016/679) and the Polish Act of 18 July 2002 on the provision of services by electronic means.

Before using the Services, please read this Policy.

2) Controller and contact

Controller: TIMELESS Chirurgia Plastyczna sp. z o.o., ul. Gen. Romana Abrahama 18/322, 03-982 Warsaw, Poland.

Data Protection Officer (DPO):
e-mail: iod@timeless.com.pl
postal address: as above (please add “Data Protection Officer” on the envelope).

3) Data collection principles

  • Some features (e.g., contact forms) require you to provide data. Providing data is voluntary, but necessary to perform the requested action/service.
  • You may browse the Website without logging in. Cookies are used as described in our Cookies Policy.

4) Purposes and legal bases of processing

We process personal data for the following purposes:

a) Provision of Website Services – delivering content and handling forms.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract/terms of use).

b) Provision of healthcare services – prevention, diagnosis, treatment, healthcare; includes data of persons authorised by the patient.
Legal basis: Art. 6(1)(b) and (c) GDPR (contract and legal obligation) and Art. 9(2)(h) GDPR, in connection with the Polish Act on Patients’ Rights and the Patient Ombudsman (Arts. 24 and 29).

c) Protection of vital interests – in urgent situations.
Legal basis: Art. 6(1)(d) GDPR and Art. 9(2)(c) GDPR.

d) Analytics/own marketing and service improvement – measurements, statistics, optimisation of the Website.
Legal basis: Art. 6(1)(f) GDPR (legitimate interests of TIMELESS).

e) Security and continuity of IT systems – information security and IT administration.
Legal basis: Art. 6(1)(f) GDPR.

f) Handling queries, complaints and claims – contacting users, clarifications, corrective actions.
Legal basis depends on the case: Art. 6(1)(b)/(c)/(f) GDPR.

g) Establishment, exercise or defence of legal claims.
Legal basis: Art. 6(1)(f) GDPR; for special categories of data (e.g., health data) Art. 9(2)(f) GDPR.

5) Data recipients

Personal data may be disclosed to:

  • authorised employees and contractors of TIMELESS,
  • service providers (e.g., hosting, IT, software, email) under data-processing agreements,
  • healthcare providers cooperating to deliver medical services (where necessary),
  • public authorities only where required by law.

6) Your rights

You have the right to:

  • access your data,
  • rectify your data,
  • withdraw consent (where processing is based on consent),
  • erase data (where applicable),
  • restrict processing,
  • data portability (where applicable),
  • object to processing (including to analytics/own marketing based on Art. 6(1)(f) GDPR).

To exercise your rights, contact: iod@timeless.com.pl.
You also have the right to lodge a complaint with the President of the Polish Personal Data Protection Office (PUODO).

7) Sources of data

In some cases, data may come from someone other than you—for example, from your legal representative or a person authorised by you.

8) Data retention

We keep personal data for as long as necessary to fulfil the purposes of processing, in particular:

  • for the duration of the contract/provision of services, and thereafter for the period required by law or for the establishment/exercise/defence of claims;
  • for compliance with legal duties – for the period set by law;
  • for processing based on consent – until consent is withdrawn;
  • otherwise – for the period necessary to pursue the legitimate interests of TIMELESS.

9) Cookies

The Website uses cookies and similar technologies for purposes described in our separate Cookies Policy (e.g., functionality, statistics, security). Details are provided in the “Cookies Policy” available on sexreassignmentsurgery.eu.

10) Data security

We apply appropriate technical and organisational measures proportionate to risk, including access control, selected encryption of channels, role-based permissions, and oversight of processors.

11) Transfers outside the EEA

As a rule, we do not transfer data outside the European Economic Area (EEA). If such a transfer occurs (e.g., within certain IT services), it will take place in compliance with the GDPR, using appropriate safeguards (e.g., Standard Contractual Clauses).

12) Changes to this Policy

We may update this Policy, for example due to legal changes or new Website features. The current version is always available on the Website.

13) Contact

Questions regarding this Policy or our processing of personal data:
iod@timeless.com.pl or by post to Timeless Chirurgia Plastyczna sp. z o.o., ul. Gen. Romana Abrahama 18/322, 03-982 Warsaw, Poland.