Privacy notice

Effective: 20 September 2026

1. The controller

The controller is:

Pulmo Protect Kft.
Registered office: 1044 Budapest, Ezred utca 7. 2. ép. fszt. 4.
Company registration number: 01 09 383163
Tax number: 29205297-2-41
Telephone: +36 70 248 7997
Email: rendelo@innomedic.hu
Represented by: Dr. Horváth Alpár Zsolt, managing director

Pulmo Protect Kft. provides healthcare services under the name Innomedic Health Centre (Innomedic Egészségközpont). Innomedic Health Centre is not a separate legal entity, and is not a separate controller or healthcare provider; Pulmo Protect Kft. is responsible for healthcare and for data processing.

This privacy notice applies to the processing of personal data by Pulmo Protect Kft. in connection with healthcare services provided within Innomedic Health Centre.

Processing is governed in particular by Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and by Hungarian healthcare and health-insurance legislation.

2. Purpose of processing

The Provider processes personal data for the following purposes:

  • identifying the patient;
  • booking and managing appointments;
  • providing healthcare services;
  • medical examinations, diagnostics and treatment;
  • keeping health records;
  • ensuring continuity of care;
  • taking previous health data and findings into account;
  • communication related to care;
  • data reporting to the EESZT as required by law;
  • fulfilling invoicing and accounting obligations;
  • providing documentation needed for health-fund reimbursement;
  • handling complaints, requests and enquiries;
  • fulfilling obligations laid down by law;
  • pursuing the Provider’s legitimate interests and legal claims;
  • processing related to clinical trials, according to the documentation and processing terms of the given study.

3. Legal basis of processing

Depending on the purpose, the legal basis for processing personal data is in particular:

  • Article 6(1)(c) GDPR: compliance with a legal obligation to which the Provider is subject;
  • Article 6(1)(b) GDPR: performance of a contract with the patient, or steps taken in connection with it;
  • Article 6(1)(f) GDPR: the Provider’s legitimate interest, where the conditions for such processing are met;
  • Article 6(1)(a) GDPR: the data subject’s consent, where consent is required for the given processing;
  • for health data, the appropriate legal basis under Article 9 GDPR, in particular processing related to healthcare under Article 9(2)(h) GDPR.

Health data are a special category of data under the GDPR, so in addition to the general rules on personal data, the special rules on health data also apply.

4. Categories of personal data processed

Depending on the care and the processing purpose, the Provider may process in particular the following data:

Identification and contact data

  • name;
  • birth name;
  • place and date of birth;
  • mother’s name;
  • address;
  • telephone number;
  • email address;
  • social security (TAJ) number;
  • identity-document data, where their processing is necessary.

Health data

  • medical history;
  • complaints and symptoms;
  • diagnoses;
  • examination results;
  • laboratory results;
  • imaging results and related documentation;
  • previous findings and discharge summaries;
  • treatments;
  • therapies applied;
  • data on medication;
  • other documentation generated in the course of healthcare.

Data related to appointment booking and communication

  • booked appointment;
  • chosen service or examination;
  • change or cancellation of an appointment;
  • content of the enquiry;
  • data provided during online or telephone communication.

Billing data

Data needed to account for the fee of the service, in particular:

  • name;
  • billing address;
  • tax identifier or tax number, where required by law or by invoicing;
  • service used;
  • billing and payment data.

5. Appointment booking and use of the REMEDI system

Appointments may be booked online or by telephone.

For online booking the Provider uses the REMEDI system provided by Paper Dog (Hungary) Kft. REMEDI is a cloud-based patient-records system operated by Paper Dog (Hungary) Kft.; according to that provider’s own information the system is EESZT-accredited, and it names Paper Dog (Hungary) Kft. as controller.

Data needed to book an appointment and to organise healthcare may be processed in the REMEDI system.

Processing related to the REMEDI service is also governed by the privacy notice of Paper Dog (Hungary) Kft. and by the relevant provisions of the data-processing agreement with the Provider.

The REMEDI provider is:

Paper Dog (Hungary) Kft.
Registered office: 8200 Veszprém, Szabadság tér 12.
Company registration number: 19-09-517339
Tax number: 25005703-2-19
Email: info@remedi.hu

According to the data published on the provider’s website, the REMEDI data protection officer is:

Vókó Péter
Email: peter@remedi.hu

When using the REMEDI system, the Provider processes and transfers only the data necessary to provide the service.

6. Health records and the EESZT

The Provider processes and retains health records generated during care in accordance with the applicable healthcare legislation.

For health data and documentation, the Provider reports to the EESZT in accordance with the legislation in force.

Processing in the EESZT is governed by separate legislation on the operation of the EESZT and on the processing of health data. The EESZT has its own privacy notice.

7. Retention period of health records

The Provider processes health records for the retention periods laid down in the applicable legislation.

As a general rule, health records must be retained for at least 30 years, and the discharge summary for at least 50 years, according to the applicable legislation.

If another law requires a longer retention period for a given data item, the Provider processes the data for that longer period.

8. Clinical trials

The Provider may also take part in clinical trials and research-and-development projects.

Processing related to clinical trials takes place on the basis of the study protocol, the agreements with the study sponsor or commissioner, and the applicable legislation.

A separate privacy notice and patient information sheet related to the given study may also apply to the processing of data of persons taking part in a clinical trial.

Documentation and data related to clinical trials must be retained for the period specified in the applicable legislation or in the contract and protocol of the study. Depending on the applicable rules, this period may also exceed the general retention period of patient-care documentation.

9. Online card payment – Elavon / Novopayment

The fee for the service may be settled after the service has been used, by the payment methods provided by the Provider.

Payment may be made in particular:

  • in cash;
  • by bank card;
  • by online bank-card payment.

It is not possible to pay the service fee in advance online.

The Elavon payment service related to online card payment is provided in Hungary by Novopayment Kft.

Novopayment Kft.
Registered office: 1034 Budapest, Tímár utca 20. IV. emelet
Tax number: 26118853-2-41
Company registration number: 01-09-302898
Telephone / Call Centre: +36 1 490 0234

During online card payment, data needed to carry out the payment transaction are processed through the payment-service system.

The Provider does not learn or process the patient’s full bank-card data.

According to Novopayment’s own privacy notice, Novopayment Kft. also performs independent controller functions in processing related to the payment service. The individual processing operations and the role of the controllers depend on the specific payment service and on the applicable contractual and statutory provisions.

The data processed by the payment provider and their retention are also governed by the data-protection and service rules of Novopayment Kft. and Elavon.

10. Invoicing

The Provider issues an invoice for the consideration of the services in accordance with the accounting and tax legislation in force.

To carry out invoicing, the Provider uses an electronic invoicing service.

Processing of personal data needed for invoicing is based on compliance with a legal obligation.

In the course of invoicing, in particular the name, billing address, tax identifier or tax number, the name of the service, invoice data and payment-related information may be processed.

Billing data are retained in accordance with the applicable accounting and tax legislation.

11. Health-fund reimbursement

At the patient’s request, the Provider may provide the documents and data needed for health-fund reimbursement in accordance with the applicable legislation and the rules of the given health fund.

The given health fund may be an independent controller in respect of the processing it carries out. The scope of data processed by the health fund, and the purpose and duration of processing, are governed by that health fund’s own privacy notice.

The Provider transfers or makes available only the data necessary for reimbursement.

Health data may be transferred only where an appropriate legal basis exists and only to the extent necessary.

12. Telephone and email communication

The Provider may communicate with the patient by telephone or email, among other things for:

  • arranging an appointment;
  • changing or cancelling an appointment;
  • information related to the service;
  • communication necessary for patient care;
  • handling complaints and requests;
  • other administration related to the provision of healthcare.

Health documents and other personal data sent by the patient by email or other electronic means are processed by the Provider to the extent necessary to provide healthcare.

13. Handling of complaints and requests

In order to investigate complaints, requests and enquiries, the Provider processes the personal data needed to submit, investigate and answer the complaint or enquiry.

Investigation of the complaint and information to the patient take place in accordance with the applicable legislation.

After investigating the complaint, the Provider gives the patient a written reply within no more than 30 working days, unless a different deadline is set by law.

14. Patients’ rights representative

In order to exercise their rights related to healthcare, the patient may also turn to a patients’ rights representative.

Patients’ rights representative:
Szécsiné Fazekas Márta
Telephone: +36 20 489 9506
Email: marta.szecsine@ijsz.bm.gov.hu

Contact details of the Integrated Legal Protection Service:

IJSZ green number: +36 80 620 055

The patients’ rights representative provides assistance in patients’-rights questions related to healthcare, and may take part in settling complaints and rights violations.

15. Camera system

A camera system may operate at the Provider’s premises for security purposes.

The detailed rules of camera processing, the purpose and legal basis of processing, the rights of data subjects and the retention period of recordings are set out in a separate Camera privacy notice.

16. Cookies and use of the website

The Provider’s website may use technically necessary cookies and – with the data subject’s consent – other cookies as well.

The detailed rules of cookie use and the purpose of each cookie are set out in a separate Cookie notice.

17. Data transfers

The Provider transfers personal data only where an appropriate legal basis exists.

A transfer may take place in particular in the following cases:

  • data reporting to the EESZT as required by law;
  • to another healthcare provider, where this is necessary for healthcare and a legal basis exists;
  • to an authority, court or other body entitled by law;
  • in the framework of data reporting required by law;
  • to a health fund, to the extent necessary for reimbursement;
  • to the sponsor of a clinical trial or another entitled organisation taking part in the study, according to the rules of the given study;
  • to processors used to provide the service, to the extent necessary.

The Provider strives not to transfer personal data outside the European Economic Area. If such a transfer nevertheless takes place, it may only take place with the appropriate safeguards specified by the GDPR.

18. Processors and contributing service providers

The Provider may also use external service providers to provide healthcare and related administrative tasks.

These include in particular:

  • IT and hosting providers;
  • the provider of the appointment-booking and patient-records system;
  • the electronic invoicing provider;
  • providers carrying out IT maintenance;
  • legal, accounting and other professional service providers, where their use involves data processing.

Processors may process personal data on the Provider’s instructions, in accordance with the requirements of the GDPR.

Whether a given provider acts as controller or processor must always be determined on the basis of the given service, the contractual relationship and the applicable legislation.

19. Rights of data subjects

The patient is entitled to:

  • request information about the processing of their personal data;
  • request access to the personal data processed;
  • request rectification of inaccurate personal data;
  • request erasure of their personal data in the cases specified by law;
  • request restriction of processing in the cases specified by law;
  • object to processing in the cases specified by law;
  • withdraw consent at any time, where processing is based on consent;
  • exercise the right to data portability in the cases specified by law.

The exercise of data-subject rights does not affect data whose processing or retention is required by law.

In particular, in the case of health records erasure of the data may not necessarily be requested if their retention is required by law.

The data subject may submit their request to the Provider at the following contact details:

Email:rendelo@innomedic.hu
Telephone: +36 70 248 7997
Postal address: 1044 Budapest, Ezred utca 7. 2. ép. fszt. 4.

20. Lodging a complaint with the supervisory authority

If the patient considers that the processing of their personal data infringes the GDPR or the applicable data-protection legislation, they may lodge a complaint with the supervisory authority.

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9–11.
Postal address: 1363 Budapest, Pf. 9.
Telephone: +36 (1) 391 1400
Email: ugyfelszolgalat@naih.hu

The NAIH’s current contact details are also available on the Authority’s website.

The data subject is also entitled to go to court if they consider that they have suffered a rights violation in the processing of their personal data.

21. Automated decision-making and profiling

The Provider does not apply automated decision-making or profiling in relation to the patient’s personal data that would produce legal effects concerning the data subject or similarly significantly affect them.

22. Data security

The Provider applies appropriate technical and organisational measures to protect personal data in particular against unauthorised access, alteration, loss, destruction or unauthorised transfer.

The Provider determines data-security measures having regard to the nature of the processing, the sensitivity of the data and the possible risks.

23. Amendment of the privacy notice

The Provider reserves the right to amend this privacy notice, in particular in the event of a change in legislation, a change in processing processes or the introduction of a new service.

The privacy notice in force at any given time is available on the Provider’s website.

Effective date: 20 September 2026

Controller: Pulmo Protect Kft.
Innomedic Health Centre