INFORMATION OF GENERAL INTEREST
Treatment of low risk personal data that we perform in VEST MEDICAL by not including personal data related to ethnic or racial origin, religious or philosophical political ideology, union affiliation, genetic and biometric data, health data, and sexual orientation data of people, as well as any other data processing that entails high risk for the rights and freedoms of people.
In compliance with article 5.1.f of the General Data Protection Regulation (RGPD) which determines the need to establish adequate security guarantees against unauthorized or illegal treatment, against the loss of personal data, destruction or accidental damage We indicate below the technical and organizational measures aimed at ensuring the integrity and confidentiality of personal data followed by our organization.
All personnel with access to personal data must be aware of their obligations in relation to the processing of personal data and will be informed about these obligations. The minimum information that will be known by all the staff will be the following:
DUTY OF CONFIDENTIALITY AND SECRET
The access of unauthorized persons to personal data should be avoided, for this purpose it will be avoided: leaving personal data exposed to third parties (unattended electronic screens, paper documents in areas of public access, supports with personal data, etc.) , this consideration includes the screens that are used to display images of the video surveillance system. When you are absent from the workplace, the screen will be blocked or the session closed.
- Paper documents and electronic media will be stored in a secure place (cupboards or restricted access rooms) 24 hours a day.
- Documents or electronic media (cd, pen drives, hard drives, etc.) will not be discarded with personal data without guaranteeing their destruction.
- Personal data or any personal information will not be communicated to third parties, special attention will be given in not divulging protected personal data during telephone consultations, emails, etc.
- The duty of secrecy and confidentiality persists even when the worker’s employment relationship with the company ends.
RIGHTS OF THE DATA HOLDERS
All workers will be informed about the procedure to deal with the rights of the interested parties, clearly defining the mechanisms by which the rights can be exercised (electronic means, reference to the Delegate of Data Protection if there is one, postal address, etc.). ) taking into account the following:
Upon presentation of their national identity document or passport, the holders of personal data (interested) may exercise their rights of access, rectification, deletion, opposition and portability. The person responsible for the treatment must respond to the interested parties without undue delay.
For the right of access, the interested parties will be given the list of the personal data they have available, together with the purpose for which they were collected, the identity of the recipients of the data, the conservation periods, and the identity of the person responsible. which can request the rectification suppression and opposition to the processing of the data.
For the right of rectification will proceed to modify the data of the interested parties that were inaccurate or incomplete attending to the purposes of the treatment.