TITOLARE TRATTAMENTO DEI DATI
Home / Data controller
INFORMATION TO BE PROVIDED TO THE INTERESTED PARTY
(ex art. 13 EU Regulation 2016/679)
Dear Interested Party,
Below we provide you with some information that you need to bring to your attention, not only to comply with legal obligations, but also because transparency and fairness towards interested parties is a fundamental part of our activity.
The Data Controller of your personal data is the Società Generale di Mutuo Soccorso Basis Assistance (hereinafter also “MUTUA BASIS ASSISTANCE”), responsible towards you of the legitimate and correct use of your personal data and who you can contact for any information or request at the following addresses:
Data Controller: MUTUA BASIS ASSISTANCE Headquarters: Via di Santa Cornelia, 9 – 00060 Rome RM, IT Contacts and contact details: Telephone +39 06 90198060 PEC mbamutua@legalmail.it
The MUTUA BASIS ASSISTANCE company has appointed a Personal Data Protection Officer (“Data Protection Officer or DPO”) Contacts and contact details: Email dpo@mbamutua.it
The MUTUA BASIS ASSISTANCE company has appointed: Data Controller HEALTH ASSISTANCE SOCIETÀ COOPERATIVA (hereinafter Centrale Salute) Headquarters: Via Santa Cornelia, 9 – 00060 Rome RM, IT Contacts and contact details: Telephone +39 06 9019801 PEC healthassistance@legalmail.it
The HEALTH ASSISTANCE SOCIETÀ COOPERATIVA company has appointed a Personal Data Protection Officer (“Data Protection Officer or DPO”) Contacts and contact details: Email dpo@healthassistance.it
The Data Controller (pursuant to art. 28, par. 1 of EU Regulation 2016/679) operates on behalf of the Data Controller for all activities connected to the Health Centre.
In accordance with the art. 26 of the Application Regulation of the Statute of the MUTUA BASIS ASSISTANCE Company (Documentation required for the provision of healthcare services, requests for direct and/or indirect reimbursement and compensation) your personal data are collected and processed for the purposes set out below together with the legal basis of reference.
Below we provide you with some information that you need to bring to your attention, not only to comply with legal obligations, but also because transparency and fairness towards interested parties is a fundamental part of our activity.
The Data Controller of your personal data is the Società Generale di Mutuo Soccorso Basis Assistance (hereinafter also “MUTUA BASIS ASSISTANCE”), responsible towards you of the legitimate and correct use of your personal data and who you can contact for any information or request at the following addresses:
Data Controller: MUTUA BASIS ASSISTANCE Headquarters: Via di Santa Cornelia, 9 – 00060 Rome RM, IT Contacts and contact details: Telephone +39 06 90198060 PEC mbamutua@legalmail.it
The MUTUA BASIS ASSISTANCE company has appointed a Personal Data Protection Officer (“Data Protection Officer or DPO”) Contacts and contact details: Email dpo@mbamutua.it
The MUTUA BASIS ASSISTANCE company has appointed: Data Controller HEALTH ASSISTANCE SOCIETÀ COOPERATIVA (hereinafter Centrale Salute) Headquarters: Via Santa Cornelia, 9 – 00060 Rome RM, IT Contacts and contact details: Telephone +39 06 9019801 PEC healthassistance@legalmail.it
The HEALTH ASSISTANCE SOCIETÀ COOPERATIVA company has appointed a Personal Data Protection Officer (“Data Protection Officer or DPO”) Contacts and contact details: Email dpo@healthassistance.it
The Data Controller (pursuant to art. 28, par. 1 of EU Regulation 2016/679) operates on behalf of the Data Controller for all activities connected to the Health Centre.
In accordance with the art. 26 of the Application Regulation of the Statute of the MUTUA BASIS ASSISTANCE Company (Documentation required for the provision of healthcare services, requests for direct and/or indirect reimbursement and compensation) your personal data are collected and processed for the purposes set out below together with the legal basis of reference.
Purpose | Data processed | Legal Basis |
---|---|---|
In particular, evaluate the requests for reimbursement of expenses presented by the Member and arrange for the related reimbursement, as required by the chosen Health Plan (indirect health services), authorize the provision of direct health services. Example of performance:
Acquisition of health documentation, also through the use of means of contact such as telephone/fax or internet (Web portal; sms; mms; e-mail), ordinary mail, short manuals directly at the Operations Centre. |
Name, address or other personally identifiable information; m/f sex; racial origins; ethnic origins; health cards; state of health: current pathologies, previous pathologies, ongoing therapies; (among these: health documentation, medical records, medical prescriptions, reports, exclusively relating to the request for reimbursement of health expenses presented by the Member or the request for the provision of services directly): genetic data; contact details (telephone/fax number; email; etc.); data referring to the patient's family members, data of minors. | Member State law (GDPR 2016/679, art. 6, par. 1 letter a) |
2. Account management; litigation management | Name, address or other personally identifiable information; m/f sex; health cards; contact details (telephone/fax number; email; etc.); data referring to the patient's family members, data of minors. | Member State regulation (GDPR 2016/679 art. 6, par. 1 letter b) |
Your data may be used in an anonymized and aggregated form for statistical purposes.
Your data may be sent to the recipients or categories of recipients listed below:
Categories of recipients to whom the data can be communicated: For the execution of the requested services and the fulfillment of legal obligations, MUTUA BASIS ASSISTANCE may communicate your personal data to the following categories of subjects:
The updated list of data controllers is available at the MUTUA BASIS ASSISTANCE headquarters, and can be found through a specific request made via PEC at the address mbamutua@legalmail.it.
In addition to this information, to guarantee that your data is processed as correctly and transparently as possible, you must be aware of the fact that:
Duration of treatment The duration of the processing is determined as follows: the personal data of the interested party will be kept for the time periods as indicated pursuant to art. 13, paragraph 2 of Regulation (EU) 2016/679. In particular: for the purpose of Provision of health benefits for the entire duration of the contract and as long as there are obligations and obligations connected to the execution of the same and, in any case, for a period of no less than 10 years from the last provision or service provided, unless the need for further conservation arises, to allow the owner to defend his rights; for other purposes until deemed necessary for the provision of the services requested and will subsequently be cancelled. In all cases, personal data will be kept for a time necessary and not exceeding the achievement of the purposes described in the information, for the fulfillment of legal obligations within the limits established by law.
Treatment methods Personal data will be processed electronically or electronically and also on paper. As part of the processing, methods of organisation, comparison or processing of personal data may be envisaged to possibly be addressed to the recipients mentioned above. Furthermore, every person involved in the organization and administrative management of the Data Controller will be committed to respecting the rights, fundamental freedoms and dignity of the interested parties, as well as observing the same rules of secrecy to which healthcare personnel (doctors, nurses, etc.). Transfer of personal data to countries not belonging to the European Union We inform you that your personal data will not be transferred to non-EU countries.
Your rights Pursuant to articles. from 15 to 22 of the Regulation, we inform you regarding the obligations that the Data Controller has towards you.
To exercise these rights, you may contact at any time the Personal Data Protection Officer at MUTUA BASIS ASSISTANCE, with headquarters in Via di Santa Cornelia, 9 – 00060 Formello (RM), IT – reachable at dpo@mbamutua.it
Your data may be sent to the recipients or categories of recipients listed below:
Categories of recipients to whom the data can be communicated: For the execution of the requested services and the fulfillment of legal obligations, MUTUA BASIS ASSISTANCE may communicate your personal data to the following categories of subjects:
- healthcare bodies, medical and paramedical personnel (e.g. healthcare facilities affiliated for the issue of authorization to carry out healthcare services directly, professional doctorsaffiliated), also as of sub managers of the Health Center (Processing Manager)
- companies and businesses, consultants and freelancers in single or associated form, couriers and post offices, for example subjects engaged in the provision of services directly or indirectly (such as legal services, shipping, archives, IT services, institutes of credit), entities to improve the quality and quantity of the services offered, also as sub-managers of the Health Center (Processing Manager)
- subjects delegated directly by the interested party
- to public and private entities who can access your data pursuant to legal or regulatory provisions, within the limits established by such regulations.
The updated list of data controllers is available at the MUTUA BASIS ASSISTANCE headquarters, and can be found through a specific request made via PEC at the address mbamutua@legalmail.it.
In addition to this information, to guarantee that your data is processed as correctly and transparently as possible, you must be aware of the fact that:
Duration of treatment The duration of the processing is determined as follows: the personal data of the interested party will be kept for the time periods as indicated pursuant to art. 13, paragraph 2 of Regulation (EU) 2016/679. In particular: for the purpose of Provision of health benefits for the entire duration of the contract and as long as there are obligations and obligations connected to the execution of the same and, in any case, for a period of no less than 10 years from the last provision or service provided, unless the need for further conservation arises, to allow the owner to defend his rights; for other purposes until deemed necessary for the provision of the services requested and will subsequently be cancelled. In all cases, personal data will be kept for a time necessary and not exceeding the achievement of the purposes described in the information, for the fulfillment of legal obligations within the limits established by law.
Treatment methods Personal data will be processed electronically or electronically and also on paper. As part of the processing, methods of organisation, comparison or processing of personal data may be envisaged to possibly be addressed to the recipients mentioned above. Furthermore, every person involved in the organization and administrative management of the Data Controller will be committed to respecting the rights, fundamental freedoms and dignity of the interested parties, as well as observing the same rules of secrecy to which healthcare personnel (doctors, nurses, etc.). Transfer of personal data to countries not belonging to the European Union We inform you that your personal data will not be transferred to non-EU countries.
Your rights Pursuant to articles. from 15 to 22 of the Regulation, we inform you regarding the obligations that the Data Controller has towards you.
- You have the right to ask the Data Controller to access your personal data, to rectify or delete them, to integrate the data or to limit the processing that concerns you or to oppose their processing, in the cases provided for;
- You have the right to lodge a complaint with the Supervisory Authority (Privacy Guarantor) where you believe that your data have been processed illegitimately, which can be reached on the website garanteprivacy.it;
- You have the right to object at any time to the processing of your personal data (Right of opposition) carried out for the pursuit of a legitimate interest of the Data Controller, provided that there are no legitimate reasons for proceeding with the processing which prevail over the interests, rights and freedoms of the interested party or for the assessment, exercise or defense of a right in court;
- You can exercise the right to object for institutional information and promotion purposes at any time, by making a specific request via PEC to the address mbamutua@legalmail.it.
- The exercise of rights is not subject to any formal constraints and you will be provided with written feedback within 30 days (unless you specifically request oral feedback);
To exercise these rights, you may contact at any time the Personal Data Protection Officer at MUTUA BASIS ASSISTANCE, with headquarters in Via di Santa Cornelia, 9 – 00060 Formello (RM), IT – reachable at dpo@mbamutua.it