Contact

Kur-ApothekeDrawehnertorstraße 31

29456Hitzacker (Elbe)


05862 96700

Mail: team@kur-apotheke-hitzacker.de

Request video consultation

Drawehnertorstraße 31, 29456 Hitzacker (Elbe)

Drawehnertorstraße 31, 29456 Hitzacker (Elbe)

Öffnungszeiten
Überprüfen...
Öffnungszeiten heute: Überprüfen...

Privacy Policy


 

I. Name and address of the person responsible

The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the member states as well as other data protection provisions is:


Apotheker Ralf Arafa eK

Drawehnertorstr. 31

29456 Hitzacker (Elbe)

Email: team@kur-apotheke-hitzacker.de

Phone: 05862/96700


II. Name and address of the data protection officer

According to Art. 37 GDPR and Section 38 BDSG, there is no obligation to appoint a data protection officer



III. General information on data processing

1. Scope of processing of personal data

We generally only collect and use personal data of our customers/patients, particularly health-related data, to the extent that this is necessary within the scope of our activities as a pharmacy. The collection and use of personal data of our customers/patients generally only takes place on the basis of legal authorization, contracts or with the consent of the customer/patient.

2. Data deletion and storage period

The personal data of the data subject will be deleted or blocked as soon as the purpose for which they were stored no longer applies. Data may also be stored if this has been provided for by the European or national legislator in Union regulations, laws or other provisions to which the controller is subject. Data will also be blocked or deleted if a storage period prescribed by the aforementioned standards expires, unless there is a need to continue storing the data for the conclusion or fulfillment of a contract.


IV. Processing procedures

1. Prescription billing with the statutory health insurance or other cost carriers

If you redeem a prescription from the statutory health insurance (GKV) or another cost carrier with us, our employees collect and process the personal data and health data on your prescription (name, address, date of birth, health insurance company, insurance number, medication, prescribing doctor, in the case of prescriptions for medical devices, the indication/diagnosis). To do so, we transmit the prescription data in analogue form and digital and encrypted form to a data center commissioned by us, which bundles your data and the data of other insured persons in the GKV and other cost carriers and forwards it to the respective statutory health insurance companies or other cost carriers for the purpose of billing the prescription. Our employees and the data center therefore have access to this data.

We have obliged all of our employees and the data center to maintain confidentiality and to maintain data secrecy.

We process your data with the involvement of a data center as part of the prescription billing with the GKV in accordance with §§ 300, 302 SGB V. We delete your data after billing with the GKV or other cost carriers.

In the case of direct billing with private health insurance (PKV), we will bill your health insurance company directly on the basis of contractual agreements with the PKV. Deletion occurs in accordance with Section 147 AO.


2. Customer cards

We offer you a customer card on a voluntary basis. At your request, your name, address, date of birth, telephone number, prescription details, medication plan, medicines, aids, cosmetics, nutritional supplements and similar products you have purchased from us (health data) will be stored on the customer card. The customer card is stored in our pharmacy so that you and our employees have access to your stored data and can add to it. You can revoke your consent to the use of your data as part of our customer card at any time and with effect for the future. In this case, we will delete your data upon receipt of your declaration of revocation. If you have not purchased any medicines or aids from our pharmacy and its premises for more than two years, we will delete your personal data.


3. Medication analysis and medication management

We offer you medication analysis or medication management as a separate service or as part of our customer card. For successful and effective analysis and management, your name, date of birth, address and health-related data (health insurance, insurance number, prescribing doctor, medicines and aids, indications and diagnoses, prescriptions) are processed by our pharmacy staff and stored for a period of 3 years. We process this data on the basis of a contract with you. Only our pharmacy staff has access to this data and we will only pass the data on to your treating doctor or other third parties at your request.


4. Documentation requirements

As part of our pharmaceutical activities, we are subject to legal documentation obligations, which means that we process and store your name, date of birth, address and data relating to health (health insurance, insurance number, prescribing doctor, medicines and aids, indications and diagnoses, prescriptions). This is the case, for example, when preparing prescriptions or dispensing narcotics.

Our employees and, in the event of inspections, the relevant supervisory authority have access to this data.


V. Rights of the data subjects

5. Data transfer or access by third parties

As part of our work as a pharmacy, we also rely on external help such as IT service providers to provide and maintain our hardware and software or other service staff. As part of this integration, our external service providers may also become aware of personal data, which is why we oblige our external service providers to maintain confidentiality and data secrecy and limit their access to personal data to a minimum. Regulatory authorities also regularly inspect pharmacies and have access to personal data and health data.


1. Right to information

The data subject has the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed; where this is the case, he or she has the right to access the personal data and to receive the information specified in Article 15 of the GDPR.


2. Right to rectification

The data subject has the right to obtain from the controller immediately the rectification of inaccurate personal data concerning him or her and, where applicable, the completion of incomplete personal data (Article 16 GDPR).


3. Right to erasure and restriction of processing

The data subject has the right to request that the controller delete personal data concerning him or her immediately if one of the reasons listed in Art. 17 GDPR applies, e.g. if the data is no longer required for the purposes pursued. In the case of statutory documentation or retention obligations, there is no right to deletion until the end of the statutory deadlines.

The data subject has the right to request the controller to restrict processing if one of the conditions listed in Art. 18 GDPR is met, e.g. if the data subject has objected to processing, for the duration of the controller's review.


4. Right to information

If you have asserted your right to rectification, erasure or restriction of processing vis-à-vis the responsible party, this party is obliged to inform all recipients to whom the personal data concerning you were disclosed of said rectification, erasure or restriction of processing, unless doing so should prove impossible or involve disproportionate expenditure.

You have the right to be informed by the controller about these recipients.


5. Objection

The data subject has the right to object at any time to the processing of personal data concerning him or her for reasons related to his or her particular situation. The controller will then no longer process the personal data unless he or she can demonstrate compelling legitimate grounds for the processing which outweigh the interests, rights and freedoms of the data subject, or the processing serves to assert, exercise or defend legal claims (Article 21 GDPR).


6. Right to data portability

You have the right to receive the personal data concerning you that you have made available to the controller in a structured, common and machine-readable format. In addition, you have the right to transmit this data to another controller without hindrance from the controller to whom the personal data was made available, provided that

(1) the processing is based on consent pursuant to Art. 6 (1)(a) GDPR or Art. 9 (2)(a) GDPR or on a contract pursuant to Art. 6 (1)(b) GDPR and

(2) the processing is carried out by automated means.

In exercising this right, you also have the right to have the personal data concerning you transmitted directly from one controller to another, where technically feasible. This must not affect the freedoms and rights of other persons.

The right to data portability does not apply to the processing of personal data necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.


7. Right to revoke the declaration of consent under data protection law

You have the right to revoke your consent to data protection at any time. The revocation of the consent does not affect the legality of the processing carried out on the basis of the consent until the revocation.


8. Right to lodge a complaint with the supervisory authority

Without prejudice to any other administrative or judicial remedy, every data subject has the right to lodge a complaint with a supervisory authority if the data subject considers that the processing of personal data concerning him or her infringes the GDPR (Article 77 GDPR). The data subject may assert this right with a supervisory authority in the Member State of his or her habitual residence, place of work or place of the alleged infringement. In (federal state) the competent supervisory authority is:


Barbara Thiel

The State Commissioner for Data Protection of Lower Saxony

Prinzenstraße 5

30159 Hanover

Phone 0511-120 4500

Fax      0511-120 4599

poststelle@lfd.niedersachsen.de

Share by: