Privacy Policy

The purpose of this Privacy Policy is to inform patients, individuals, service users, and other persons (hereinafter referred to as the »individual«) who interact with Juventina Clinic d.o.o., Vilharjev podhod 7, Ljubljana (hereinafter referred to as the »private healthcare provider«) about the purposes and legal bases, as well as the rights of individuals, concerning the processing of personal data that we carry out as a private healthcare provider.

We process personal data in accordance with European legislation, applicable Slovenian legislation on the protection of personal data (Personal Data Protection Act), and specific legislation that provides us with a legal basis for processing personal data in the field of healthcare:
Health Care Data Collection Act (ZZPPZ),
Patient's Rights Act (ZPacP),
Health Activity Act (ZZDej),
Medical Services Act,
Occupational Safety and Health Act (ZVZD-1),
Health Care and Health Insurance Act (ZZVZZ),
Compulsory health insurance regulations,
Mental Health Act (ZDZdr),
Zakon o nalezljivih boleznih (ZNB),
Pharmaceutical Activity Act (ZLD-1),
Law on the Treatment of Infertility and Medically Assisted Reproduction (ZZNPOB),
Blood Supply Act (ZPKrv-1),
Medicinal Products Act (ZZdr-2),
Health Inspection Act (ZZdrI).

Any changes to this document will be published on our website. By using the website, you acknowledge that you are familiar with the entire content of the privacy policy.

Purposes and legal bases for processing personal data
Private healthcare provider collects and processes your personal data on the following legal bases:
processing is necessary to fulfill a legal obligation that applies to the controller;
processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
processing is necessary for the legitimate interests pursued by the controller or by a third party;
the individual to whom the personal data relate has consented to the processing of his personal data for one or more specific purposes;
processing is necessary for the protection of the vital interests of the data subject or another natural person.

For the provision of healthcare services
For the purpose of carrying out healthcare activities, private healthcare providers process patient personal data based on legislation. On these grounds, we process the following patient personal data: social security number, health insurance number, full name, genogram, marital status, education, occupation, permanent address, temporary address, phone number, diagnosis, date of contact, scheduled contacts, doctor's number, therapy, referral, reason for temporary incapacity for work, cause of death, insurance status, reason for treatment, family social history, nursing care plan.

The legal basis for data processing is legislation.

Data is stored for the period prescribed by law. Some data is stored only for a specific period, while some data must be stored permanently.

For the provision of primary healthcare services (prevention)
A private healthcare provider performs primary healthcare services (preventive care) for the purpose of monitoring, evaluating, and planning work within the scope of primary healthcare. Thus, they carry out preventive and other examinations for adults, children aged 0 to 6, schoolchildren and adolescents, women, workers, road users, and athletes.

For the purpose of providing primary healthcare services (prevention), a private healthcare provider processes data from basic health records: personal identification number, health insurance number, first and last name, genogram, marital status, education, occupation, permanent residence address, temporary residence address, phone number, diagnosis, date of contact, planned contacts, doctor's number, therapy, referral, reason for temporary incapacity for work, cause of death, insurance status, reason for treatment, family social history, and nursing care plan. In addition, when performing primary healthcare services, it also processes dynamic entities: contact, event, process (diagnosis of illness - conditions, work performed, referral, referrer for referral, incapacity for work, risk factors for health deterioration), and planned contacts. For the purpose of performing preventive examinations, the following data is processed: data on the results of preventive examinations, data on preventive work performed, and data on other activities in the field of occupational medicine, traffic medicine, and sports medicine (applicable to workers, traffic participants, and athletes).

The legal basis for data processing is legislation.

The retention period for preventive examinations for adults, children aged 0-6 years, school children, and adolescents is 5 years from the patient's death; for women, workers, traffic participants, and athletes, it is 15 years from the examination date.

Ordering Health Services
Patients must be allowed to book appointments electronically, by mail, by phone, and in person at the practice, in accordance with the law.

For the purpose of electronic patient ordering for a health service, the private healthcare provider processes the following data: first name, last name, date of birth, residential address, contact phone number, and ZZZS number.

Depending on the chosen service ordering, in certain cases, the private healthcare provider also processes the following data: scanned certificate of e-referral or work order issuance, e-referral number (for referrals) or work order number (for orders), level of urgency (for referrals), diagnosis/description of medical condition (for orders and referrals). For the purpose of appointment scheduling: reason for visit; for the purpose of vaccination scheduling: information on whether the individual has recovered from Covid and whether they have indicated they are a chronic patient. For the purpose of sick leave certificate ordering: start and end date of sick leave, information on whether the sick leave is for full or part-time employment.

The legal bases for data processing are legislation and patient consent.

Personal data is stored for 5 years in accordance with the law.

For the execution of the contract
In cases where an individual enters into a contract with a private healthcare provider, the contract serves as the legal basis for processing personal data. Personal data may thus be processed for the conclusion and execution of the contract, such as the provision of a paid service, the sale of goods and services, participation in various programs, etc. If the individual does not provide their personal data, the private healthcare provider cannot enter into the contract, nor can they provide the service or deliver goods or other products in accordance with the concluded contract, as they lack the necessary data for its execution. On this basis, we process only and exclusively those personal data that are necessary for the conclusion and proper execution of contractual obligations.

For the purpose of issuing an invoice, we process personal data: first and last name, self-payer's address, and the type of service rendered.

The legal basis for data processing in the case of a self-pay service is a contract concluded in accordance with Article 9(h) of the General Data Protection Regulation.

The retention period is until the contract's purpose is fulfilled or for up to 6 years after the contract termination, except in cases where a dispute arises between an individual and a private healthcare provider regarding the contract. In such a case, the private healthcare provider retains the data for an additional 10 years after the court decision, arbitration, or court settlement becomes legally binding, or, if no court proceedings took place, for 6 years from the date of the amicable dispute resolution.

For the purpose of informing individuals by email
A private healthcare provider can, based on the performance of its legitimate activities, inform clients, customers, and service users about its services, events, training, offers, and other content via their email address. An individual may at any time request the cessation of such communication and the processing of personal data, and may opt-out of receiving messages through the unsubscribe link in the received message, or by submitting a request via email or regular mail to the private healthcare provider's address.

The legal bases for data processing are legitimate interest and consent.

The data will be processed until withdrawal of receipt of messages, or until withdrawal of consent, or until fulfillment of the purpose of processing. Withdrawal of consent does not affect the lawfulness of processing based on consent prior to its withdrawal.

To prevent abuse
Based on legitimate interest, we process personal data when it is strictly necessary to prevent abuse. Based on legitimate interest, we process personal data after the termination of a contractual relationship, during the period when legal claims can be asserted under the contract.

Processing based on consent
If a private healthcare provider does not have a legal basis demonstrated through law, contractual obligation, legitimate interest, or protection of an individual's life, they may ask the individual for consent. Thus, they can process certain personal data of the individual for the following purposes, provided the individual gives consent:
Residential and email address: for notification and communication purposes;
photographs, video recordings, and other content relating to an individual (e.g., posting pictures of individuals on the website of a private healthcare provider): for the purpose of documenting activities and informing the public about the work and events of the private healthcare provider;
other purposes for which the individual consents.

If an individual gives consent for the processing of personal data and at some point no longer wishes to do so, they may request the cessation of personal data processing by submitting a request via email or regular mail to the address. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. Upon receipt of withdrawal or deletion request, data will be deleted within a maximum of 15 days. A private healthcare provider may also delete this data before withdrawal when the purpose of personal data processing has been achieved or if required by law.

Exceptionally, a private healthcare provider may refuse a deletion request for reasons under the General Data Protection Regulation: exercising the right to freedom of expression and information, compliance with a legal obligation to process, reasons of public interest relating to public health, purposes of archiving in the public interest, scientific or historical research purposes, or statistical purposes, or for the establishment, exercise or defense of legal claims.

Processing is necessary to protect the vital interests of the individual
A private healthcare provider may process the personal data of an individual to whom it relates if it is necessary to protect their vital interests. In urgent cases, a private healthcare provider may search for an individual's personal data, verify if that person exists in their database, review their medical history, prescribed medications and products, or contact the individual or their relatives, for which the private healthcare provider does not need the individual's consent. The above applies only when it is urgently necessary to protect the individual's vital interests.
Personal data users, data export, and automated decision-making
Data users include contractual processors we hire to perform certain personal data processing activities for us. We primarily cooperate with: infrastructure maintainers, information system maintainers, e-mail service providers and software/cloud service providers, social media and online advertising providers (Facebook, Instagram, etc.). You have the right to request information about which (external) users your and your child's personal data have been disclosed to.

Information on the transfer of personal data to a third country
We do not transfer personal data to third countries (countries outside the EU member states, Iceland, Norway, and Liechtenstein) and international organizations, except in cases of using social networks, where data may be exported to the USA. In such cases, relationships with contractual processors from the USA are regulated based on standard contractual clauses adopted by the European Commission and/or binding corporate rules approved by the EU.

We do not perform automated decision-making or profiling.
Cookies (if you use them and do not have them regulated in another document)
Our website uses so-called cookies, which are important for providing web services. They are used to store data about the status of individual web pages, to help collect statistics on users and website traffic, etc. The website uses essential cookies that are loaded immediately. For all other cookies, we require your consent, which you can change at any time. You can delete cookies that your browser has stored.

Our website uses the following cookies:

Data security and data accuracy
The private healthcare provider takes care of information security and infrastructure security (premises and application system software). Our information systems are protected by, among other things, antivirus programs and a firewall. We have implemented appropriate organizational and technical security measures designed to protect personal data from accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, and from other unlawful and unauthorized forms of processing. In the event of the transfer of special categories of personal data, we transfer them in encrypted form and protected by a password.

The individual is solely responsible for securely transmitting their personal information and ensuring that the transmitted data is accurate and authentic.
Patient Rights
The Patient Rights Act defines the rights that a patient has as a user of health services from all healthcare providers, as well as the procedures for asserting these rights when they are violated. The Act also defines the duties associated with these rights that a patient has.

The patient rights stipulated by the Patients' Rights Act, in conjunction with data protection, are: the right to access health records; the right to privacy and personal data protection; the right to address violations of patient rights; and the right to free assistance in exercising patient rights.

A patient who believes their rights have been violated during a healthcare process has the option to request appropriate treatment. If an individual wishes to exercise any of the aforementioned rights, they can send a request via email or regular mail to the address of the private healthcare provider.
Individual's rights regarding the processing of their personal data
The individual to whom personal data relates has the right to request access to personal data and the rectification or erasure of personal data or restriction of processing concerning them, as well as the right to object to processing and the right to data portability. The individual's request shall be handled in accordance with the provisions of the General Regulation.

You can exercise all the stated rights and submit all inquiries by sending a request to our address. We will respond to your request without undue delay, at the latest within one month of receiving it. This period may be extended by a maximum of two additional months, taking into account the complexity and number of requests. You will be informed about this, along with the reasons for the delay. Exercising your rights is free of charge; however, we may charge a reasonable fee if the request is manifestly unfounded or excessive, particularly if it is repetitive. In such a case, we may also refuse the request. In this case, we will inform you of the reasons for refusal and your right to lodge a complaint with a supervisory authority. In case of doubt about your identity, we may request additional information from you, which we need to establish your identity.

You can exercise your right to lodge a complaint with the supervisory authority at: Information Commissioner of the Republic of Slovenia, at the address Dunajska 22, 1000 Ljubljana (email: gp.ip@ip-rs.si, website: www.ip-rs.si).

The privacy policy is valid from 11.20.2024.

Installment payments
Parking near the clinic
Accessible public transport
Access for people with reduced mobility
TITLE
Vilharjeva Cesta 7,
Ljubljana, Slovenia
Social networks

How to get to us?

SUBSCRIBE TO E-NEWSLETTER

You can unsubscribe at any time. For more details, see our Privacy policy.

© 2026 Juventina Clinic · ALL RIGHTS RESERVED