


These Regulations apply to the processing of personal data carried out by the Service Provider.
The personal data processed by the Service Provider comply with the GDPR and the applicable laws on the right to informational self-determination and freedom of information.
Under no circumstances does the Service Provider process personal data that fall into a special category or qualify as special data. The Service Provider also does not obtain or request personal data from persons who are not entitled to provide them.
The scope of these Regulations does not cover the processing of data relating to legal persons, nor the processing of data on the basis of which the data subject cannot be identified.
The Service Provider provides information relating to these Regulations and their interpretation electronically, in response to requests sent to its official email address.
Principles of data processingThe Service Provider pays particular attention to protecting the personal data of anyone who comes into contact with it, as well as to the accuracy and confidential nature of such data. It acts proactively to ensure that personal data made available to it are processed only for specified purposes, in line with the principle of storage limitation, and only on an appropriate legal basis, and that the personal data it processes are not disclosed to third parties without an appropriate legal basis.
With these objectives in mind, the Service Provider does everything possible to ensure that the principles relating to the processing of the personal data concerned are fully and without limitation applied throughout the entire data-processing operation, in all cases:
a. Principle of lawfulness, fairness and transparency: personal data must be processed lawfully and fairly, and in a transparent manner for the data subject.
b. Principle of purpose limitation: personal data must be collected for specified, explicit and legitimate purposes, and must not be processed in a manner that is incompatible with those purposes.
c. Principle of data minimisation: personal data must be adequate, relevant and limited to what is necessary in relation to the purposes of the processing.
d. Principle of accuracy: personal data must be accurate and, where necessary, kept up to date. Every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes of the processing, are erased or rectified without delay.
e. Principle of storage limitation: personal data must be stored in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. Personal data may be stored for longer periods only where the personal data will be processed for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes.
f. Principle of integrity and confidentiality: personal data must be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
g. Principle of accountability: the controller is responsible for, and must be able to demonstrate, compliance with the stated principles.
Updating and availability of the Regulations; becoming familiar with and accepting themThe Service Provider reserves the right to amend these Regulations unilaterally, even without the separate express consent of the data subjects.
Accordingly, the Service Provider undertakes to publish the current version of the Regulations at all times and, at the same time, to make previous versions of the Regulations available on its website, so that the data subjects whose personal data it processes always have accurate information about the Service Provider’s data-processing activities and the rules applicable to them.
By providing personal data to the Service Provider, the data subject declares that they have read the version of these Regulations in force at the time the data are provided and expressly accept its provisions.
Data-processing operations, their source and legal basis, the scope of the processed data, the duration of processing, and the persons authorised to process data.Data-processing operations
When carrying out technical tasks related to data-processing operations, the Service Provider, where an appropriate legal basis exists, records and processes the data, forwards them further only to the narrowest extent possible, and, at the request of the data subject (where legally justified), restricts and deletes personal data previously provided.
Method of processing
Personal data are stored and processed using IT tools, on a computer.
Legal basis for processing
The legal basis for processing personal data is governed by the rules on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, as well as on repeal.
In the course of concluding and performing contracts aimed at establishing customer relationships, the Service Provider records and processes personal data voluntarily provided to it in order to fulfil its statutory and contractual obligations, on the basis of the data subject’s consent.
During communication between data subjects and the Service Provider, including newsletter subscription, email communication and social media posts, data subjects may also make their personal data available to the Service Provider on the basis of voluntarily given consent.
If the data subject withdraws their consent to the processing of personal data, but the Service Provider can justifiably rely on a different legal basis defined by law instead of consent, the Service Provider may switch to the legal basis supporting the processing of the personal data even without the data subject’s consent.
Categories of data affected by processing
The categories of personal data provided to the Service Provider by data subjects include the full range of personal data provided by customers and by persons establishing electronic communication with the Service Provider, and in particular include the following:
In the course of customer contact: correspondence and permanent address, personal identification document number, email address, telephone number.
When completing participant contracts and documents required for application: full name, place and date of birth, mother’s name, correspondence and permanent address, number of the personal identification document and the official document proving address, educational and professional qualifications, a copy of the document proving the highest qualification, tax identification number, citizenship, email address, telephone number.
During electronic communication: the name and email address of the person communicating, newsletter subscription status. When operating the Service Provider’s social media page: communication with visitors to the page; visitors can send comments and messages to the Service Provider, or ask about the Service Provider’s upcoming courses. The Service Provider may answer questions and comments and may send a reply message where necessary.
Duration of processing
The Service Provider processes personal data handled on the basis of the data subject’s consent until that consent is withdrawn; if consent is not withdrawn, it generally processes the data for 5 years after the relationship with the data subject ends. The data subject may withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Data that are necessary for the performance of a contract in which one party is the data subject and the other is the Service Provider, and data whose processing is necessary for compliance with a legal obligation applicable to the Service Provider, are retained for the period specified by the sector-specific rules applicable to the relevant documents, regardless of the data subject’s consent.
Service Provider details
HumanMED Training Ltd.
Company registration number: 01-10-141208
Tax number: 29028036-2-41
Adult training registration number: B/2021/001206
Persons authorised to process data
The rights and obligations of the processor in connection with the processing of personal data are determined, within the framework of the specific laws relating to data processing, by the Service Provider as controller.
The Service Provider enables all of its employees, as processors, to carry out technical tasks related to data-processing operations.
The Service Provider, as controller, is responsible for the lawfulness of processing. The processor’s authorisations relating to processing are set out in these Regulations and may not be exceeded under any circumstances. The processor may process personal data that come to its knowledge solely in accordance with the instructions of the Service Provider as controller and the guidance of these Regulations; it may not process data for its own purposes. The processor must store and retain personal data in accordance with the controller’s instructions and, where the appropriate legal basis ceases to exist, delete them, and, where the data subject submits a well-founded request to that effect, restrict them.
Data transferAs a general rule, the Service Provider does not transfer the personal data made available to it to third parties without the data subject’s written consent or without an appropriate legal basis, except where necessary to comply with a legal obligation.
By way of derogation from the above general rule, in order to comply with its legal obligations, the Service Provider transfers, each month, to its accountant the invoices issued to students participating in courses and to its customers, which contain the student’s or customer’s name and address.
In exceptional cases, upon request by a court, prosecutor’s office, investigative authority, misdemeanour authority or administrative authority, or upon request by other bodies authorised by law, the Service Provider is obliged to provide information, disclose data, and/or make documents available. In such cases, the Service Provider will disclose to the requesting body only as much personal data, and only to the extent, as is strictly necessary to achieve the purpose of the request.
Sending newslettersNewsletter subscription forms part of automated data processing. Newsletters are sent out automatically by the system used by the Service Provider, according to pre-set rules, to subscribers, based on the consent and data provided by the data subject subscribing to the newsletter.
The data subject may unsubscribe from newsletters at any time, free of charge, without restriction and without giving reasons, by following the instructions in the newsletter and using the link on the website that appears after clicking.
Personal data processed without a legal basisThe Service Provider is committed to ensuring that any personal data for which the legal basis for processing has ceased, or which have been made available to it unlawfully, are deleted.
The Service Provider asks the data subjects whose personal data it processes to notify it without delay if the data subject becomes aware that a third party has unlawfully made the data subject’s personal data available to the Service Provider, or if the personal data of a child under 16 have come into the Service Provider’s possession without parental consent.
Data security measuresThe Service Provider implements appropriate security measures to ensure that personal data in its possession are not, under any circumstances, disclosed, erased, lost or destroyed.
In order to enforce the requirements of these data security measures, the Service Provider has created the IT environment used for processing personal data in such a way that it meets the following conditions:
a. The IT system is capable of restricting access to the processed data, meaning the data are protected from unauthorised third parties.
b. During automated processing of personal data, all changes to the data are recorded with the time of modification indicated, in order to prevent unauthorised data entry, prevent unauthorised persons from using data-processing systems, prevent use via data transmission equipment, and ensure verifiability and traceability of information relating to data entry and data transfer.
c. Error reports are generated for errors arising during automated processing, and erroneous data are deleted.
d. In order to protect data against accidental destruction and damage, and against becoming inaccessible due to changes in the technology used, and to ensure they can be restored in the event of an outage, backup copies of the data are made.
The Service Provider’s IT system provides the expected level of protection during the processing of personal data and is protected against computer-related offences. The operator ensures security through password protection, firewalls, and server security procedures.
Personal data breachA personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data transmitted, stored or otherwise processed.
If the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall inform the data subject of the personal data breach without undue delay. The information provided to the data subject must describe the nature of the personal data breach clearly and in plain language.
The data subject’s rights and remediesThe data subject may request from the controller:
a. information about the processing of their personal data,
b. rectification of their personal data where there is an error, and
c. erasure or restriction of their personal data.
The data subject may also object to the processing of their personal data.
The Service Provider is obliged to provide clear information, generally in writing, on the fulfilment of the request within a reasonable time from receipt of the request, but no later than within 25 days.