Privacy Notices
Information on the processing of personal data of persons using Haelan medical services
We process your personal data in your capacity as our patient using the medical services provided by Haelan Medical Centers. The processing is carried out in compliance with the applicable national and European legislation in the field of personal data.
We hereby inform you about the processing of your personal data by the controllers listed below and about your rights related to them, as well as provide you with the information under Art. 13 and Art. 14 of the General Data Protection Regulation.
PERSONAL DATA CONTROLLER DETAILS AND CONTACT DETAILS
Administrator “Haylan - Home for Medical-Social Care” JSC, ID: 207648560
Headquarters and management address: Sofia, 1766, blvd. Ring road № 251 E, fl. 12
Tel.: +359893 02 02 02
Email: care@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care - Medical Center” Ltd., ID: 207312638
Headquarters and management address: Gr. Sofia, ul. Ring Road No. 251 E, ground floor
Tel.: +359893 02 02 02
Email: haelan.care1@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 2 — Medico-Dental Center” Ltd., ID: 201760855
Headquarters and management address: Gr. Sofia, ul. “Business Park Sofia” № 1, building № 2, floor. 1
Tel.: +359892 20 20 40
Email: haelan.care2@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 3 — Medical Center” Ltd., ID: 206470233
Headquarters and management address: Gr. Sofia, Mihail Tenev № 6, building D, ground floor
Tel.: +359893 02 02 02
Email: haelan.care3@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 4 — Medical Center” Ltd., ID: 207710752
Headquarters and management address: Gr. Varna, blvd. “Vladislav Varnenchik” № 267
Tel.: +359887 50 30 60
Email: haelan.care4@haelan.bg
Website: www.haelan.bg
Administrator “Pia Mater” Ltd., ID: 201409799
Headquarters and management address: Gr. Sofia, ul. Racho Petkov Kazandjiyatta № 4-6, office № 2
Tel.: +359884588446
Email: office@piamater.org; classes@piamater.org
Website: www.haelan.bg
Administrator SAT Health AD, EIC 204705650
Headquarters and management address: Sofia, 1766, blvd. Ring road № 251 E, fl. 12
Email: office@sathealth.com
Website: www.sathealth.com
DATA PROTECTION OFFICER AND CONTACT DETAILS:
Mariya Georgieva Nestorova
Bulgaria, Gr. Sofia, Ring Road 251E, floor 12, 1766
Phone: +359882727270
E-mail: dpo@sathealth.com
LEGAL BASIS FOR THE PROCESSING OF YOUR PERSONAL DATA:
The basis for the processing of your personal data may be legal, contractual, consent expressly provided by you or our legitimate interest:
- The legal basis for processing may be the requirements of the Health Act, the Medical Institutions Act, other applicable laws and regulations;
- Contractual grounds are:
- A contract for medical services for you or your child, entered into personally by you, your legal representative or the applicant for the service;
- A contract for integrated medical and social care for you or your child, concluded personally by you, your legal representative or the applicant for the service;
- Requested by you, your legal representative or applicant, medical service and/or examination, and/or on-site consultation, and/or online consultation, and/or home visit for you or your child, by making an appointment by phone, e-mail or through a platform;
- A contract concluded between us and your employer for preventive medical examinations for you;
- Contractual relations between us and the supplementary health insurance fund chosen by your employer for the provision of health services for specialized outpatient medical care, including consultations, medical-diagnostic activities, conducting treatment and performing preventive medical examinations;
- Contractual relations with other legal entities - our contractors for the provision of medical and telemedicine services, in which We work as a processor of personal data;
- Consent to the processing of your data for marketing or other additional purposes, if you have provided it;
- To protect vital interests of you, your child or a relative as data subjects;
- In some cases and subject to applicable law, the basis may be our legitimate interest, for example to analyze, develop and improve services, improve systems and platforms, ensure the quality of services, protect the property and safety of employees, and others.
PURPOSES OF PROCESSING YOUR PERSONAL DATA:
Your personal data is processed for the purpose of providing the services that you have requested and/or used in fulfillment of our legal obligations for specific purposes defined in legal acts and/or in a contract, and/or in other documents, incl. but not limited to:
- identify you as our client (patient) and provide you with the information you are looking for;
- Provide you with the services requested by you/your employer/selected by your employer for supplementary health insurance/Employers for you, your child or a relative;
- You can exercise your rights as a patient;
- Fulfill our statutory and contractual requirements (e.g. tax, social security, statistical, reporting, etc. obligations);
- We maintain your (and/or your child's) health record;
- We serve you on the spot in a medical center, in an office, online, by phone or at the address specified by you;
- We process and collect payments due for the services provided;
- We examine your satisfaction with the services we provide;
- We maintain our websites, online platforms and their security.
With your consent, we process your personal data (and/or your child's data):
- To participate in marketing, statistical and/or other studies, summary analyses and other information programs, projects and/or events concerning your illness and/or health condition;
- To participate in clinical trials;
- To prepare analyses and/or summaries of the data or of a relevant part of it with the aim, but not limited to, ensuring a better quality of services; to provide personalized and attractive offers tailored to your specific interests and needs; to conduct market and competitive analyses that help us better understand customer needs and preferences; improve the public health and the development of more effective methods of treatment and prevention; for the development of new services
- to provide you with information about services at preferential prices and/or new services, current events and activities, sending marketing and advertising newsletters and/or other information bulletins.
- to interact with us by participating in surveys, comments and feedback. This data is valuable for us to understand how to improve our services and better meet your expectations.
Subject to regulatory requirements, in some cases we may process your personal data to protect our legitimate interests, for example when you are subject to video surveillance when visiting our medical centres. In connection with the security requirements that we apply in Haelan medical centers, video surveillance is carried out in common areas - corridors and at the reception (more information can be found inPersonal Data Protection Policypublished on our website).
CATEGORIES OF PERSONAL DATA THAT WE PROCESS:
We only process personal data related to the exercise of your rights as a patient. In particular, we collect and process personal data such as: name, surname, family name, personal identification number, age, gender, contact details — telephone, residential address, e-mail address; health data (illness, diagnosis, data from medical epicrisis and/or other medical records, prescribed treatment, etc.), genetic data (insofar as it is possible to contain in the results of genetic studies assigned to Haelan); data on kinship with other persons; data of children patients; financial information — bank account; data from video surveillance (in the case of that you visit our center).
TERM OF PROCESSING OF YOUR PERSONAL DATA:
We process your data during the relationship we have with you, such as:
- we store your personal data for a period of 5 (five) years after you cease your relationship with us (last provided service, activity or withdrawal of consent) and you have no activity in your account on our platforms for more than 3 (three) years (if you are a registered user on a platform);
- we store audio recordings of telephone conversations with you for 5 (five) years after the end of the year in which the calls were made, after which they are automatically deleted, unless we are required to keep them for a longer period in order to comply with a legal requirement or our legitimate interest;
- we store your personal data related to and/or contained in tax insurance control documents (contracts, invoices, credit and debit notices) for a period of 10 (ten) years, starting from the beginning of the year of the reporting period following the reporting period to which they relate;
- We store the data contained in CCTV recordings for a period of 30 (thirty) days.
We store documents and data for which no special storage period is provided for a period of five years from the cessation of their use.
We will not destroy your data after the expiry of the storage period if a competent government authority has requested it or the data is necessary for the establishment, exercise or defence of legal claims.
We do not store any credit or debit card information. This information is maintained and payments are processed by a third-party payment service provider in accordance with payment card and settlement industry security standards.
SHARING YOUR PERSONAL DATA WITH THIRD PARTIES:
We respect the confidentiality of your data and, as a rule, do not provide it to third parties. As an exception to this rule and subject to applicable legal requirements, we may share your data:
- with state and regulatory authorities in the Republic of Bulgaria (such as: Executive Agency “Medical Supervision”, CPDP, Ministry of Interior, Prosecutor's Office, court, etc.) at their explicit request;
- with your employer, your employer's chosen supplementary health insurance fund or our contractors (where we act as a processor of personal data) — where there is a contractual obligation to share your data with them;
- with companies that provide our technical and operational support for the operation and provision of the services (e.g. laboratories, platform and/or website maintenance, data center, telemedicine service partners, payment services, etc.), carrying out consulting or other activities (e.g. auditing) where it is possible, exceptionally, to have access to your data. In such cases, the disclosure of data shall only take place in the presence of a valid reason and a written agreement with them in order to ensure the necessary level of protection;
- when it is necessary to protect the vital interests of patients (in medical emergencies).
AS SUBJECTS OF PERSONAL DATA, YOU HAVE THE RIGHT TO:
- information on whether we process your personal data;
- access to your personal data processed by us and the right to receive a copy of the personal data processed;
- to know what categories of personal data we collect and the purposes for which we process them;
- information about the recipients of your personal data, where applicable;
- to know for what period your personal data is stored;
- to correct your personal data processed by us where they are inaccurate, to be supplemented when they are incomplete and to be updated when there is a change;
- to request the deletion of your personal data, if there are legal grounds for this and if there is no obligation for us, on the basis of a legal act or a contract concluded by you, for their processing or storage;
- withdraw your consent for your personal data to be processed for direct marketing purposes or for other additional purposes to which you initially consented;
- object to the processing of your personal data, if there are legal grounds for this and if there is no obligation for us, on the basis of a legal act or a concluded contract, for their processing;
- restriction of the processing of your personal data for a certain period of time (for example, for the time necessary to establish the accuracy of your data or for the purposes of establishing or exercising legal claims by you);
- the portability of your data, in a structured, widely used and machine-readable format, where the processing is based on consent or contractual obligation and is carried out in an automated manner;
- a complaint to the Commission for Personal Data Protection (www.cpdp.bg), when you consider that we have violated your rights related to your personal data;
- information about the source of your personal data that you have not provided to us (e.g. if provided to us by a relative).
In order to exercise any of the rights listed above or to receive further information about the processing of your personal data, it is necessary to visit our medical center or request it by e-mail. care@haelan.bg, with a free-text application attached, signed with a qualified electronic signature (QE).
In order to obtain information and exercise your rights, you must first identify yourself as our customer and our employees verify your identity. This requirement protects your rights and your personal data.
The information about your personal data that is being processed will be provided to you free of charge, at the latest within one month of receiving your request.
The present information and Personal Data Protection Policymay be updated from time to time, depending on changes in the regulatory framework and/or the activities of Haelan. Their current versions are published on the website www.haelan.bg.
Date of last update: 01\ 2024
Information on the processing of personal data of persons using Haelan social services
We process your personal data, including medical data on your state of health, in your capacity as a user of social services within the meaning of the Social Services Act. The processing is carried out in compliance with the applicable national and European legislation in the field of personal data.
We hereby inform you about the processing of your personal data by the controllers listed below and about your rights related to them, as well as provide you with the information under Art. 13 and Art. 14 of the General Data Protection Regulation.
PERSONAL DATA CONTROLLER DETAILS AND CONTACT DETAILS
Administrator “Heilan” EAD, ID: 207648560
Headquarters and management address: Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Tel.: +359893 02 02 02
Email: care@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care - Medical Center” Ltd., ID: 207312638
Headquarters and management address: Gr. Sofia, 1404, blvd. “Bulgaria” № 51A, fl. 3
Tel.: +359893020202
Email: haelan.care1@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 2 — Medico-Dental Center” Ltd., ID: 201760855
Headquarters and management address: Gr. Sofia, ul. “Business Park Sofia” № 1, building № 2, fl. 1
Tel.: +359892202040
Email: haelan.care2@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 3 — Medical Center” Ltd., ID: 206470233
Headquarters and management address: Gr. Sofia, Mihail Tenev № 6, building D, ground floor
Tel.: +359893020202
Email: haelan.care3@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 4 — Medical Center” Ltd., ID: 207710752
Headquarters and management address: Gr. Varna, blvd. “Vladislav Varnenchik” № 267
Tel.: +359887 50 30 60
Email: haelan.care4@haelan.bg
Website: www.haelan.bg
Administrator “Pia Mater” Ltd., ID: 201409799
Headquarters and management address: Gr. Sofia, ul. Racho Petkov Kazandjiyatta № 4-6, office № 2
Tel.: +359884588446
Email: office@piamater.org; classes@piamater.org
Website: www.haelan.bg; www.piamater.org
Administrator SAT Health AD, EIC 204705650
Headquarters and management address: Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Email: office@sathealth.com
Website: www.sathealth.com
DATA PROTECTION OFFICER AND CONTACT DETAILS:
Mariya Georgieva Nestorova
Bulgaria, Gr. Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Telephone: +359882727270
E-mail: dpo@sathealth.com
LEGAL BASIS FOR THE PROCESSING OF YOUR PERSONAL DATA:
The basis for the processing of your personal data may be legal, contractual, consent expressly provided by you or Our legitimate interest:
o Legal basis for processing are the requirements of the Social Services Act and other legal and regulatory acts applicable to our activity;
o Contractual grounds are:
• A contract for social service or integrated medical-social care concluded with you or your legal representative, guardian or trustee;
• Social service requested by you or your relative, legal representative, guardian or trustee.
o To protect your vital interests as data subjects;
o Consent to the processing of your data for marketing or other additional purposes, if you have provided it;
In some cases and subject to applicable law, the basis may be our legitimate interest, for example to provide and improve the quality of the social services we provide to you, improve the systems and platforms related to these services, protect property, physical and information security, and others.
PURPOSES OF PROCESSING YOUR PERSONAL DATA:
Your personal data is processed for the purpose of providing the social services that you have requested and/or use. The purposes correspond to our legal obligations set out in the Social Services Act and other regulations applicable to our business, in contracts for the provision of social services and/or in other documents, incl. but not limited to:
o Identify you as our customer, as a registered user on our platforms and provide you with the information you are looking for;
o provide you with the social services requested by you or by your legal representative, guardian or trustee;
o You can exercise your rights as a user of a social service;
o Fulfill our statutory and contractual obligations (e.g. tax, social security, statistical, reporting, etc.);
o We maintain your social services user file, which we create and maintain for the purpose of providing social services;
o We serve you on the spot in an office, medical center, online, by phone or at the address specified by you;
o Process and collect payments due for social services provided;
o We examine your satisfaction with the social services we provide;
o For information security purposes on our sites and online platforms.
In the presence of your consent, we process your personal data:
o To participate in marketing, statistical and/or other research, summary analyses and other information programs, projects and/or events concerning your illness and/or health status and social services;
o To prepare analyses and/or summaries of the data or of a relevant part of it with the aim, but not limited to, ensuring a better quality of services; to provide personalized and attractive offers tailored to your specific interests and needs; to conduct market and competitive analyses, which helps us to better understand customer needs and preferences; improve the public health and the development of more effective methods of treatment and prevention; for the development of new services;
o to provide you with information about services at preferential prices and/or new services, current events and activities, sending marketing and advertising newsletters and/or other newsletters.
o to interact with us by participating in surveys, comments and feedback. This data is valuable for us to understand how to improve our services and better meet your expectations.
Subject to regulatory requirements, in some cases we may process your personal data to protect our legitimate interests, for example when you are subject to video surveillance when visiting our medical centres. In connection with the security requirements that we apply in Haelan medical centers, video surveillance is carried out only in the common areas - corridors and at the reception (more information can be found in the Privacy Policy published on our Website).
CATEGORIES OF PERSONAL DATA THAT WE PROCESS:
We only process personal data related to the exercise of your rights as a user of a social service. In particular, we collect and process personal data such as: name, surname, family name, personal identification number, age, gender, data about your state of health, incl. epicrisis, data from laboratory tests, data on treatment performed, etc., data related to the social service provided, contact details — telephone, address of residence, e-mail address; family relationship with other persons or for your legal representatives/guardians or trustees; financial information — bank account; video surveillance data (in case you visit our center).
TERM OF PROCESSING OF YOUR PERSONAL DATA:
We process your data during the relationship we have with you, such as:
o we process and store your personal data for a period of 5 (five) years after you have ceased your relationship with us (last provided service, activity or withdrawal of consent) and you have no activity in your account on our platforms for more than 3 (three) years (if you are a registered user on a platform);
o we store audio recordings of telephone conversations with you for 5 (five) years after the end of the year in which the calls were made, after which they are automatically deleted, unless we are required to keep them for a longer period in order to comply with a legal requirement or our legitimate interest;
o we store your personal data related to and/or contained in tax insurance control documents (contracts, invoices, credit and debit notices) for a period of 10 (ten) years, starting from the beginning of the year of the reporting period following the reporting period to which they relate;
o We store the data contained in CCTV recordings for a period of 30 (thirty) days.
We store documents and data for which no special storage period is provided for a period of five years from the cessation of their use.
We will not destroy your data after the expiry of the storage period if a competent government authority has requested it or the data is necessary for the establishment, exercise or defence of legal claims.
We do not store any credit or debit card information. This information is maintained and payments are processed by a third-party payment service provider in accordance with payment card and settlement industry security standards.
SHARING YOUR PERSONAL DATA WITH THIRD PARTIES:
We respect the confidentiality of your data and, as a rule, do not provide it to third parties. As an exception to this rule and subject to applicable legal requirements, we may share your data:
o with state and regulatory authorities in the Republic of Bulgaria (such as: Agency for the Quality of Social Services, CPDP, Ministry of Interior, Prosecutor's Office, court, etc.) at their explicit request;
o with companies that provide our technical and operational support for the operation and provision of the services (e.g. laboratories, platform and/or website maintenance, data center, home food delivery partners, payment services, etc.), carrying out consulting or other activities (e.g. auditing) where it is possible, exceptionally, to have access to your data. In such cases, the disclosure of data shall only take place in the presence of a valid reason and a written agreement with them in order to ensure the necessary level of protection;
o with medical and health facilities, doctors and other medical personnel when it is necessary to protect your vital interests (in case of medical emergencies).
AS SUBJECTS OF PERSONAL DATA, YOU HAVE THE RIGHT TO:
o information on whether we process your personal data;
o access to your personal data processed by us and the right to receive a copy of the personal data processed;
o to know what categories of personal data we collect and the purposes for which we process them;
o information about the recipients of your personal data, where applicable;
o to know for what period your personal data is stored;
o to correct your personal data processed by us where they are inaccurate, to be supplemented when they are incomplete and to be updated when a change has occurred;
o to request the deletion of your personal data, if there are legal grounds for this and if there is no obligation for us, on the basis of a legal act or a contract concluded by you, for their processing or storage;
o withdraw your consent for your personal data to be processed for direct marketing purposes or for other additional purposes to which you initially consented;
o object to the processing of your personal data, if there are legal grounds for this and if there is no obligation for us, on the basis of a legal act or a concluded contract, for their processing;
o to restrict the processing of your personal data for a certain period of time (for example, for the time necessary to establish the accuracy of your data or for the purposes of establishing or exercising legal claims by you);
o the portability of your data, in a structured, widely used and machine-readable format, where the processing is based on consent or contractual obligation and is carried out in an automated manner;
o a complaint to the Commission for Personal Data Protection (www.cpdp.bg), when you consider that we have violated your rights related to your personal data;
o information about the source of your personal data that you have not provided to us (e.g. if provided to us by your legal representative, guardian or trustee).
In order to exercise any of the rights listed above or to receive additional information about the processing of your personal data, it is necessary to visit our medical center or request it by e-mail care@haelan.bg, with an attached application in free text, signed with a qualified electronic signature (KEP).
In order to obtain information and exercise your rights, you must first identify yourself as our customer and our employees verify your identity. This requirement protects your rights and your personal data.
The information about your personal data that is being processed will be provided to you free of charge, at the latest within one month of receiving your request.
This information and the Privacy Policy may be updated from time to time, depending on changes in the regulations and/or activities of Haelan. Their current versions are published on the website www.haelan.bg.
Date of last update: 04\ 2025
Information on the processing of personal data of persons using training services of the Center for Vocational Training - CPO
We process your personal data in your capacity as a person using training services of the Vocational Training Center-CPO at Haelan. The processing is carried out in compliance with the applicable national and European legislation in the field of personal data.
We hereby inform you about the processing of your personal data by the controllers listed below and about your rights related to them, as well as provide you with the information under Art. 13 and Art. 14 of the General Data Protection Regulation.
PERSONAL DATA CONTROLLER DETAILS AND CONTACT DETAILS
Administrator “Heilan” EAD, ID: 207648560
Headquarters and management address: Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Tel.: +359893 02 02 02
Email: care@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care - Medical Center” Ltd., ID: 207312638
Headquarters and management address: Gr. Sofia, 1404, blvd. “Bulgaria” № 51A, fl. 3
Tel.: +359893020202
Email: haelan.care1@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 2 — Medico-Dental Center” Ltd., ID: 201760855
Headquarters and management address: Gr. Sofia, ul. “Business Park Sofia” № 1, building № 2, fl. 1
Tel.: +359892202040
Email: haelan.care2@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 3 — Medical Center” Ltd., ID: 206470233
Headquarters and management address: Gr. Sofia, Mihail Tenev № 6, building D, ground floor
Tel.: +359893020202
Email: haelan.care3@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 4 — Medical Center” Ltd., ID: 207710752
Headquarters and management address: Gr. Varna, blvd. “Vladislav Varnenchik” № 267
Tel.: +359887 50 30 60
Email: haelan.care4@haelan.bg
Website: www.haelan.bg
Administrator “Pia Mater” Ltd., ID: 201409799
Headquarters and management address: Gr. Sofia, ul. Racho Petkov Kazandjiyatta № 4-6, office № 2
Tel.: +359884588446
Email: office@piamater.org; classes@piamater.org
Website: www.haelan.bg; www.piamater.org
Administrator SAT Health AD, EIC 204705650
Headquarters and management address: Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Email: office@sathealth.com
Website: www.sathealth.com
DATA PROTECTION OFFICER AND CONTACT DETAILS:
Mariya Georgieva Nestorova
Bulgaria, Gr. Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Telephone: +359882727270
E-mail: dpo@sathealth.com
LEGAL BASIS FOR THE PROCESSING OF YOUR PERSONAL DATA:
The basis for the processing of your personal data may be legal, your consent or our legitimate interest:
o Legal basis for processing are the requirements of the Law on Vocational Education and Training, Ordinance No. 2 of June 22, 2018 on the documents for vocational training of persons over 16 years of age, Regulations on the activities of the National Agency for Vocational Education and Training (NAPOO) and other legal and regulatory acts applicable to our activity;
o Consent provided by you through the professional training requested by you;
o In some cases and subject to applicable law, the basis may be our legitimate interest, for example, to improve training services, improve systems and platforms related to the training service provided, protect property, physical, information and network security, on and on the occasion of the training provided and the like.
PURPOSES OF PROCESSING YOUR PERSONAL DATA:
Your personal data is processed for the purpose of providing the training services requested by you, in fulfillment of our legal obligations for specific purposes specified in the legal acts and/or in a contract, and/or in other documents, incl. but not limited to:
o Identify you as our customer and provide you with the information you are looking for;
o Provide you with the training services requested by you;
o We register you as a trainee on the NAPOO platform;
o to provide the NAPOO with the medical documents required under the applicable regulations, certifying your state of health;
o We issue you a certificate of professional qualification (after successfully passed the exam);
o You can exercise your rights as a trainee;
o Fulfill our regulatory obligations (e.g. tax, social security, statistical, reporting, etc.);
o We keep your file as a trainee with us;
o We serve you on the spot in the office, online or by phone;
o We process and collect payments due for the services provided;
o We examine your satisfaction with the services we provide;
o Provide you with information about new services, promotions or advertising campaigns and activities;
o For the purposes of security of the online platforms used, in and on the occasion of the provided training service.
CATEGORIES OF PERSONAL DATA THAT WE PROCESS:
We only process personal data related to the exercise of your rights as a user of a training service from our CPO. In particular, we collect and process personal data such as: name, surname, family name, personal identification number, date of birth, gender, nationality, residential address, contact details — telephone and e-mail address; financial information — bank account; education data; health data (from a medical certificate required by NAPOO when registering a student).
TERM OF PROCESSING OF YOUR PERSONAL DATA:
We process your data during the relationship we have with you, such as:
o we process and store your personal data for a period of 5 (five) years after you have terminated the relationship with us (last service provided);
o We process and store your data contained in the “Registration Book for issued documents for completed degree and for acquired professional qualifications” for a period of 50 years from the issuance of the vocational training certificate;
o we store audio recordings of telephone conversations with you — 5 (five) years after the end of the year in which the calls were made, after which they are automatically deleted, unless we are required to keep them for a longer period in order to comply with a legal requirement or our legitimate interest;
o We store your personal data related to and/or contained in tax insurance control documents (contracts, invoices, credit and debit notices) for a period of 10 (ten) years, starting from the beginning of the year of the reporting period following the reporting period to which they relate.
We store documents and data for which no special storage period is provided for a period of five years from the cessation of their use.
We will not destroy your data after the expiry of the storage period if a competent government authority has requested it or the data is necessary for the establishment, exercise or defence of legal claims.
PROVIDING YOUR PERSONAL DATA TO THIRD PARTIES:
We respect the confidentiality of your data and, as a rule, do not provide it to third parties. As an exception to this rule and subject to applicable legal requirements, we may share your data:
o with state and regulatory authorities in the Republic of Bulgaria (such as: National Agency for Vocational Education and Training, CPDP, Ministry of Interior, Prosecutor's Office, court, etc.) at their explicit request or when we are legally obliged;
o with companies that provide our technical and operational support for the activities and provision of the services (e.g. platform maintenance, and/or website maintenance, data center, payment services, etc.), consulting or other activities (e.g. auditing) where it is possible, exceptionally, to have access to your data. In these cases, the disclosure of data takes place only in the presence of a valid reason and a written agreement with them in order to ensure the necessary level of protection.
AS SUBJECTS OF PERSONAL DATA, YOU HAVE THE RIGHT TO:
o information on whether we process your personal data;
o access to your personal data processed by us and the right to receive a copy of the personal data processed;
o to know what categories of personal data we collect and the purposes for which we process them;
o information about the recipients of your personal data, where applicable;
o to know for what period your personal data is stored;
o to correct your personal data processed by us where they are inaccurate, to be supplemented when they are incomplete and to be updated when a change has occurred;
o to request the deletion of your personal data, if there are legal grounds for this and if there is no obligation for us, on the basis of a legal act or a contract concluded by you, for their processing or storage;
o withdraw your consent for your personal data to be processed for direct marketing purposes or for other additional purposes to which you initially consented;
o object to the processing of your personal data, if there are legal grounds for this and if there is no obligation for us, on the basis of a legal act or a concluded contract, for their processing;
o to restrict the processing of your personal data for a certain period of time (for example, for the time necessary to establish the accuracy of your data or for the purposes of establishing or exercising legal claims by you);
o the portability of your data, in a structured, widely used and machine-readable format, where the processing is based on consent or contractual obligation and is carried out in an automated manner;
o a complaint to the Commission for Personal Data Protection (www.cpdp.bg), when you consider that we have violated your rights related to your personal data;
o information about the source of your personal data that you have not provided to us.
In order to exercise any of the rights listed above or to receive additional information about the processing of your personal data, it is necessary to visit our medical center or request it by e-mail care@haelan.bg, with an attached application in free text, signed with a qualified electronic signature (KEP).
In order to obtain information and exercise your rights, you must first identify yourself as our customer and our employees verify your identity. This requirement protects your rights and your personal data.
The information about your personal data that is being processed will be provided to you free of charge, at the latest within one month of receiving your request.
This information and the Privacy Policy may be updated from time to time, depending on changes in the regulations and/or activities of Haelan. Their current versions are published on the website www.haelan.bg.
Date of last update: 04\ 2025
Information on the processing of personal data of persons included in the Patient Assistance Program (PSP)
We process your personal data in your capacity as a patient included in the Patient Assistance Program (PSP), treated with medicines with limited prescription (e.g. Article 78, item 2 of the WHO).
The processing is carried out in compliance with the applicable national and European legislation in the field of personal data.
We hereby inform you about the processing of your personal data by the SAT Health Group and Haelan (the controllers referred to below), and about your rights related to them, as well as provide you with the information under Art. 13 and Art. 14 of the General Data Protection Regulation.
PERSONAL DATA CONTROLLER DETAILS AND CONTACT DETAILS
Administrator “Heilan” EAD, ID: 207648560
Headquarters and management address: Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Tel.: +359893 02 02 02
Email: care@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care - Medical Center” Ltd., ID: 207312638
Headquarters and management address: Gr. Sofia, 1404, blvd. “Bulgaria” № 51A, fl. 3
Tel.: +359893020202
Email: haelan.care1@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 2 — Medico-Dental Center” Ltd., ID: 201760855
Headquarters and management address: Gr. Sofia, ul. “Business Park Sofia” № 1, building № 2, fl. 1
Tel.: +359892202040
Email: haelan.care2@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 3 — Medical Center” Ltd., ID: 206470233
Headquarters and management address: Gr. Sofia, Mihail Tenev № 6, building D, ground floor
Tel.: +359893020202
Email: haelan.care3@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 4 — Medical Center” Ltd., ID: 207710752
Headquarters and management address: Gr. Varna, blvd. “Vladislav Varnenchik” № 267
Tel.: +359887 50 30 60
Email: haelan.care4@haelan.bg
Website: www.haelan.bg
Administrator “Pia Mater” Ltd., ID: 201409799
Headquarters and management address: Gr. Sofia, ul. Racho Petkov Kazandjiyatta № 4-6, office № 2
Tel.: +359884588446
Email: office@piamater.org; classes@piamater.org
Website: www.haelan.bg; www.piamater.org
Administrator SAT Health AD, EIC 204705650
Headquarters and management address: Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Email: office@sathealth.com
Website: www.sathealth.com
DATA PROTECTION OFFICER AND CONTACT DETAILS:
Mariya Georgieva Nestorova
Bulgaria, Gr. Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Telephone: +359882727270
E-mail: dpo@sathealth.com
LEGAL BASIS FOR THE PROCESSING OF YOUR PERSONAL DATA:
The basis for the processing of your personal data may be legal, contractual, consent expressly provided by you or our legitimate interest:
o Legal basis for processing may be the requirements of the Health Act and other applicable laws and regulations;
o Contractual grounds are:
• A contract concluded between SAT Health and another legal entity — Client of a specific Patient Assistance Program (PSP), when SAT Health acts as a personal data administrator;
• A contract concluded between SAT Health and another legal entity — Client of a specific Patient Assistance Program (PSP), when SAT Health acts as a processor of personal data;
o Consent to the processing of your data for the purposes of participation in the CSP, for marketing or other additional purposes, if you have provided it;
o To protect vital interests of you or your child patient in the PSP as data subjects;
In some cases and subject to applicable law, the basis may be our legitimate interest, for example to analyze, develop and improve services, improve systems and platforms, ensure the quality of services, protect the property and safety of employees, and others.
PURPOSES OF PROCESSING YOUR PERSONAL DATA:
Your personal data is processed for the purposes of participating in the CSP and providing the services that you have requested and/or use in fulfillment of our legal or contractual obligations for specific purposes defined in legal acts and/or in a contract, and/or in other documents, incl. but not limited to:
o Identify you as a patient in the PSP and provide you with the information you are looking for;
o provide for you or your child patient in the PSP assistance and assistance in your participation in administrative procedures before expert medical committees, NSOs and other bodies competent to carry out examination and examination of medical documents related to his/her illness;
o provide for you or your child patient in the PSC the additional medical supervision and specific care services requested by you in the home, including one-time manipulations or a series of such manipulations, long-term care, training in taking medications or adherence to a certain treatment regimen and/or lifestyle, and consultations by medical and non-medical persons competent to carry out medical and non-medical services;
o You can exercise your rights as a patient;
o Fulfill our regulatory and contractual requirements (e.g. tax, social security, statistical, reporting, etc. obligations);
o We maintain your (and/or your child's) health record;
o We serve you on site at Healan Medical Center, in an office, online, by phone or at the address you specify;
o We examine your satisfaction with the services we provide;
o We maintain our sites, online platforms and their security.
With your consent, we process your personal data (and/or your child's data):
o to prepare analyses and/or summaries of the data or of a relevant part thereof;
to organise and manage commercial and scientific activities carried out by us or with our participation, such as participation in marketing research, clinical trials or other information programmes, projects and/or events related to your/your child's illness;
o to advertise and evaluate the products and services provided and/or presented by us (for example, sending marketing newsletters or conducting marketing research);
o to receive newsletters containing information that we believe may be useful to you in view of your health/the condition of your child.
Subject to regulatory requirements, in some cases we may process your personal data to protect our legitimate interests, for example when you are subject to video surveillance when visiting our Haelan medical centres. In connection with the security requirements that we apply in Haelan medical centers, video surveillance is carried out in common areas - corridors and at the reception (more information can be found in the Privacy Policy published on www.haelan.bg).
CATEGORIES OF PERSONAL DATA THAT WE PROCESS:
We only process personal data related to the exercise of your rights as a patient participant in the CSR. In particular, we collect and process personal data such as: name, surname, family name, personal identification number, contact details - permanent address and/ or address for correspondence, telephone, e-mail; health data (illness, diagnosis, data from medical epicrisis and/or other medical records, laboratory and other medical tests, prescribed treatment), genetic data (as far as possible to be contained in the results of genetic studies necessary for PSC); data on kinship with other persons (when the patient in the PSC is a child); data of child patients; data from video surveillance (in case you visit the Haelan Medical Center).
TERM OF PROCESSING OF YOUR PERSONAL DATA:
We process your data during the relationship we have with you, such as:
o we store your personal data for a period of 5 (five) years after you terminate the relationship with us (exit from the PSU, termination of the PSU or withdrawal of consent) or for a period specified by the programme sponsor when we act as a processor of personal data;
o we store audio recordings of telephone conversations with you — 5 (five) years after the end of the year in which the calls were made, after which they are automatically deleted, unless we are required to keep them for a longer period in order to comply with a legal requirement or our legitimate interest;
o we store your personal data related to and/or contained in tax insurance control documents (contracts, invoices, credit and debit notices) for a period of 10 (ten) years, starting from the beginning of the year of the reporting period following the reporting period to which they relate;
o We store the data contained in CCTV recordings for a period of 30 (thirty) days.
We store documents and data for which no special storage period is provided for a period of five years from the cessation of their use.
We will not destroy your data after the expiry of the storage period if a competent government authority has requested it or the data is necessary for the establishment, exercise or defence of legal claims.
SHARING YOUR PERSONAL DATA WITH THIRD PARTIES:
We respect the confidentiality of your data and, as a rule, do not provide it to third parties. As an exception to this rule and subject to applicable legal requirements, we may share your data:
o with state and regulatory authorities in the Republic of Bulgaria (such as: CPDP, Ministry of Interior, Prosecutor's Office, court, etc.) at their explicit request;
o with the Client of the specific patient program in which you participate — where there is a contractual obligation to share your data with them;
o with independent medical and diagnostic laboratories, when your laboratory tests are carried out in them as a patient in the PSC;
o with companies that provide our technical and operational support for the operation and provision of the services (e.g. platform maintenance, data center, etc.), carrying out consulting or other activities (e.g. auditing) where it is possible, exceptionally, to have access to your data. In such cases, the disclosure of data shall only take place in the presence of a valid reason and a written agreement with them in order to ensure the necessary level of protection;
o when it is necessary to protect the vital interests of patients (in medical emergencies).
AS SUBJECTS OF PERSONAL DATA, YOU HAVE THE RIGHT TO:
o information on whether we process your personal data;
o access to your personal data processed by us and the right to receive a copy of the personal data processed;
o to know what categories of personal data we collect and the purposes for which we process them;
o information about the recipients of your personal data, where applicable;
o to know for what period your personal data is stored;
o to correct your personal data processed by us where they are inaccurate, to be supplemented when they are incomplete and to be updated when a change has occurred;
o to request the deletion of your personal data, if there are legal grounds for this and if there is no obligation for us, on the basis of a legal act or a contract concluded by you, for their processing or storage;
o withdraw your consent for your personal data to be processed for direct marketing purposes or for other additional purposes to which you initially consented;
o object to the processing of your personal data, if there are legal grounds for this and if there is no obligation for us, on the basis of a legal act or a concluded contract, for their processing;
o to restrict the processing of your personal data for a certain period of time (for example, for the time necessary to establish the accuracy of your data or for the purposes of establishing or exercising legal claims by you);
o the portability of your data, in a structured, widely used and machine-readable format, where the processing is based on consent or contractual obligation and is carried out in an automated manner;
o a complaint to the Commission for Personal Data Protection (www.cpdp.bg), when you consider that we have violated your rights related to your personal data;
o information about the source of your personal data that you have not provided to us.
In order to exercise any of the rights listed above or to receive additional information about the processing of your personal data, it is necessary to visit our medical center, our office or to request this by e-mail care@haelan.bg, with an attached application in free text, signed with a qualified electronic signature (KEP).
To obtain information and exercise your rights, you must first identify yourself as our patient and our staff verify your identity. This requirement protects your rights and your personal data.
The information about your personal data that is being processed will be provided to you free of charge, at the latest within one month of receiving your request.
In the event that you are a patient under the PSP, for which we act as a processor of personal data, your request will be forwarded for execution to the relevant Contracting Company, administrator of your personal data.
This information and the Privacy Policy may be updated from time to time, depending on changes in the regulations and/or activities of the SAT Health and Haelan group. Their current versions are published on the website www.haelan.bg.
Date of last update: 04\ 2025
Information and access to personal data of persons - representatives of patients (parents, guardians, trustees, proxies, applicants for medical and social services) and contact persons voluntarily appointed by a Haelan client (in short “Representatives”)
With this document, we inform you about the processing of your personal data by Haelan companies (the controllers referred to below, “Haelan” for short) and about your rights related to them, as well as provide you with the information under Art. 13 and Art. 14 of the General Data Protection Regulation.
PERSONAL DATA CONTROLLER DETAILS AND CONTACT DETAILS
Administrator “Heilan” EAD, ID: 207648560
Headquarters and management address: Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Tel.: +359893 02 02 02
Email: care@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care - Medical Center” Ltd., ID: 207312638
Headquarters and management address: Gr. Sofia, 1404, blvd. “Bulgaria” № 51A, fl. 3
Tel.: +359893020202
Email: haelan.care1@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 2 — Medico-Dental Center” Ltd., ID: 201760855
Headquarters and management address: Gr. Sofia, ul. “Business Park Sofia” № 1, building № 2, fl. 1
Tel.: +359892202040
Email: haelan.care2@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 3 — Medical Center” Ltd., ID: 206470233
Headquarters and management address: Gr. Sofia, Mihail Tenev № 6, building D, ground floor
Tel.: +359893020202
Email: haelan.care3@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 4 — Medical Center” Ltd., ID: 207710752
Headquarters and management address: Gr. Varna, blvd. “Vladislav Varnenchik” № 267
Tel.: +359887 50 30 60
Email: haelan.care4@haelan.bg
Website: www.haelan.bg
Administrator “Pia Mater” Ltd., ID: 201409799
Headquarters and management address: Gr. Sofia, ul. Racho Petkov Kazandjiyatta № 4-6, office № 2
Tel.: +359884588446
Email: office@piamater.org; classes@piamater.org
Website: www.haelan.bg; www.piamater.org
Administrator SAT Health AD, EIC 204705650
Headquarters and management address: Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Email: office@sathealth.com
Website: www.sathealth.com
DATA PROTECTION OFFICER AND CONTACT DETAILS:
Mariya Georgieva Nestorova
Bulgaria, Gr. Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Telephone: +359882727270
E-mail: dpo@sathealth.com
LEGAL BASIS FOR THE PROCESSING OF YOUR PERSONAL DATA:
Haelan processes your personal data on the following grounds:
o The Health Act, the Social Services Act, the Medical Facilities Act, other applicable laws and regulations;
o A contract or a medical and/or social service requested by you, and/or integrated medico-social care, and/or examination, and/or on-site consultation, and/or online consultation, and/or home visit for your child or relative (in your capacity as a parent, guardian, trustee, proxy or applicant for medical or social services);
o A contract or a medical and/or social service requested by your relative, and/or examination, and/or on-site consultation, and/or online consultation, and/or home visit for which you are listed as a contact person;
o To protect the vital interests of your child, guardian or relative as data subjects;
o Consent to the processing of your data for marketing or other additional purposes, if you have provided it;
o Legitimate interests - analysis, development and improvement of services, improvement of systems and platforms, ensuring the quality of services, protection of property and security of employees and others.
PURPOSES OF PROCESSING YOUR PERSONAL DATA:
We process your personal data in fulfillment of our legal obligations for specific purposes defined in legal acts and/or in a contract, in your capacity as:
o a parent, guardian, guardian, medical or social service applicant or custodian of a person using Haelan's services;
o contact person voluntarily indicated by our client.
We process your personal data in order to:
o We identify you as a person from the circle mentioned above (“Representatives” for short);
o you can exercise your rights as a person from the circle of those mentioned above;
o comply with our legal and contractual requirements (e.g. tax, insurance, statistical, reporting, etc. obligations);
o process and collect payments due for the services provided;
o We maintain our sites, online platforms and their security.
In the presence of your consent, we process your personal data:
o To participate in marketing, statistical and/or other surveys, aggregate analyses and other information programs, projects and/or events in order to improve the quality of our services and provide personalized offers;
o To prepare analyses and/or summaries of data or a relevant part of them with the aim, but not limited to, ensuring a better quality of services; providing personalized and attractive offers tailored to your specific interests and needs; improving public health and developing more effective methods of treatment and prevention; to develop new services;
o To provide you with information about services at preferential prices and/or new services and activities, campaigns and events, sending marketing and advertising newsletters and/or other newsletters.
Subject to regulatory requirements, in some cases we may process your personal data to protect our legitimate interests, for example when you are subject to video surveillance when visiting our medical centres. In connection with the security requirements that we apply in Haelan medical centers, video surveillance is carried out in corridors and at the reception (more information can be found in the Privacy Policy published on our Website).
TERM OF PROCESSING OF YOUR PERSONAL DATA:
In the event that you fall into the category of persons “Representatives”, we:
o we process and store your personal data for a period of 5 (five) years after our relationship with your parent/relative ceases (last provided service, activity) and you have no activity in your account on our platforms for more than 3 (three) years (if you are a registered user on a platform);
o we process and store your personal data for a period of 5 (five) years after you withdraw your consent for marketing or other additional purposes, if you initially provided it;
o we store audio recordings of telephone conversations with you — 5 (five) years after the end of the year in which the calls were made, after which they are automatically deleted, unless we are required to keep them for a longer period in order to comply with a legal requirement or our legitimate interest;
o we store your personal data related to and/or contained in tax insurance control documents (contracts, invoices, credit and debit notices) for a period of 10 (ten) years, starting from the beginning of the year following that during which the payment of the corresponding obligation is due;
o We store the data contained in CCTV recordings for a period of 30 (thirty) days.
We store documents and data for which no special storage period is provided for a period of five years from the cessation of their use.
We do not destroy personal data and documents if they are necessary to establish, exercise or defend legal claims or when there is a need to present the documents to a government authority.
We do not store any credit or debit card information. This information is maintained and payments are processed by a third-party payment service provider in accordance with payment card and settlement industry security standards.
CATEGORIES OF PERSONAL DATA THAT WE PROCESS:
Only personal data related to the exercise of your rights as a person falling into the category of “Representatives”, complying with the requirements of European and national legislation, such as: names, contact details — telephone and e-mail address; data on kinship with other natural persons - our patients or users of a social service; financial information - bank account; data from video surveillance (in case you visit our center).
PROVIDING YOUR PERSONAL DATA TO THIRD PARTIES:
We do not provide your personal data to third parties unless:
o there is a legal obligation to provide data to a public authority (for example, the Executive Agency for Medical Supervision, the Agency for the Quality of Social Services and others);
o is necessary in connection with our technical and operational support of the activity and provision of services (e.g. laboratories, platform maintenance, data center, telemedicine service partners, payment services, etc.), consulting activities or services (e.g. audit) where it is possible, exceptionally, for service providers to access your data. In such cases, the disclosure of data shall only take place in the presence of a valid reason and a written agreement with the service providers in order to ensure the necessary level of protection;
o it is necessary to protect the vital interests of patients (in medical emergencies).
AS SUBJECTS OF PERSONAL DATA, YOU HAVE THE RIGHT TO:
o information on whether Haelan processes your personal data;
o access to your personal data processed by Haelan and the right to receive information about your personal data that is being processed;
o to know what categories of personal data we collect and the purposes for which we process them;
o information about the recipients of your personal data, where applicable;
o to know for what period your personal data is stored;
o to correct your personal data processed by Haelan where they are inaccurate, to be supplemented when they are incomplete and to be updated when there is a change;
o withdraw your consent for your personal data to be processed for direct marketing purposes or for other additional purposes to which you initially consented;
o request the deletion of your personal data, if there are legal grounds for this and if Haelan does not have an obligation, on the basis of a legal act or a contract concluded by you, for their processing or storage;
o object to the processing of your personal data, if there are legal grounds for this and if Haelan does not have an obligation, on the basis of a legal act or a contract, for their processing;
o the portability of your data, in a structured, widely used and machine-readable format, where the processing is based on consent or contractual obligation and is carried out in an automated manner;
o a complaint to the Commission for Personal Data Protection when you consider that we have violated your rights related to your personal data (www.cpdp.bg);
o information about the source of your personal data that you have not provided to us (e.g. if you are listed as a contact person).
In order to obtain information and exercise any of these rights, it is necessary that you first identify yourself and our employees verify your identity. This requirement protects your rights and your personal data.
The information about your personal data that is being processed will be provided to you free of charge, at the latest within one month of receiving your request.
In the event that you have submitted a request for the exercise of rights, we will provide you with information about the actions we have taken at your request without delay, but at the latest within one month of receiving your request. If necessary, this period may be extended by a further two months, taking into account the complexity and number of requests received. In this case, we will inform you of the extension and the reasons for it within one month of receiving your request.
To exercise any of the rights listed above, it is necessary to visit our medical center or request it by e-mail care@haelan.bg with an attached application in free text signed with a qualified electronic signature (KEP).
If you wish to receive further information about the processing of your personal data, you can contact us at the contacts indicated above.
This information may be updated from time to time, depending on changes in Haelan's regulations and/or activities. The current version is published on the website www.haelan.bg.
Date of last update: 04\ 2025
Information on the processing of personal data of persons, representatives of legal entities with whom Haelan enters into business relationships
We process your personal data in your capacity as a representative, owner, ultimate beneficial owner or contact person of a legal entity with whom we enter into a business relationship. The processing is carried out in compliance with the applicable national and European legislation in the field of personal data.
We hereby inform you about the processing of your personal data by the controllers listed below and about your rights related to them, as well as provide you with the information under Art. 13 and Art. 14 of the General Data Protection Regulation.
PERSONAL DATA CONTROLLER DETAILS AND CONTACT DETAILS
Administrator “Heilan” EAD, ID: 207648560
Headquarters and management address: Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Tel.: +359893 02 02 02
Email: care@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care - Medical Center” Ltd., ID: 207312638
Headquarters and management address: Gr. Sofia, 1404, blvd. “Bulgaria” № 51A, fl. 3
Tel.: +359893020202
Email: haelan.care1@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 2 — Medico-Dental Center” Ltd., ID: 201760855
Headquarters and management address: Gr. Sofia, ul. “Business Park Sofia” № 1, building № 2, fl. 1
Tel.: +359892202040
Email: haelan.care2@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 3 — Medical Center” Ltd., ID: 206470233
Headquarters and management address: Gr. Sofia, Mihail Tenev № 6, building D, ground floor
Tel.: +359893020202
Email: haelan.care3@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 4 — Medical Center” Ltd., ID: 207710752
Headquarters and management address: Gr. Varna, blvd. “Vladislav Varnenchik” № 267
Tel.: +359887 50 30 60
Email: haelan.care4@haelan.bg
Website: www.haelan.bg
Administrator “Pia Mater” Ltd., ID: 201409799
Headquarters and management address: Gr. Sofia, ul. Racho Petkov Kazandjiyatta № 4-6, office № 2
Tel.: +359884588446
Email: office@piamater.org; classes@piamater.org
Website: www.haelan.bg; www.piamater.org
Administrator SAT Health AD, EIC 204705650
Headquarters and management address: Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Email: office@sathealth.com
Website: www.sathealth.com
DATA PROTECTION OFFICER AND CONTACT DETAILS:
Mariya Georgieva Nestorova
Bulgaria, Gr. Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Telephone: +359882727270
E-mail: dpo@sathealth.com
PURPOSES AND LEGAL BASIS FOR PROCESSING YOUR PERSONAL DATA:
The basis for the processing of your personal data is the contract concluded with the legal entity, as well as the applicable legislation (incl. The Law on Obligations and Contracts, the Commercial Law, the Law on Measures against Money Laundering (AML), the Law on Measures against the Financing of Terrorism (CFT) and other applicable legal acts).
Your personal data is processed only for the purposes of your identification, for the purposes specified in the contract, including for its preparation, conclusion and execution, for making payments on the basis of the contract.
CATEGORIES OF PERSONAL DATA THAT WE PROCESS:
We only process your personal data that is necessary to identify you as the representative, owner, ultimate beneficial owner, or contact person of the legal entities with whom we enter into contracts and any other forms of agreements. In particular, we collect and process personal data such as: name, surname, surname, contact data such as e-mail, telephone and address. We do not process a special category of personal data.
TERM OF PROCESSING OF YOUR PERSONAL DATA:
We process your data during the course of the business relationship with the legal entity you represent or are indicated as a contact person. We store:
o concluded service contracts and related documents, in paper and/or electronic form, for the entire period of their validity and 5 years after their termination;
o Your personal data related to and/or contained in tax insurance control documents (contracts, invoices, credit and debit notices) for a period of 10 (ten) years, starting from the beginning of the year of the reporting period following the reporting period to which they relate;
o Audio recordings of telephone conversations with you — 5 (five) years after the end of the year in which the calls were made, after which they are automatically deleted, unless we are required to keep them for a longer period in order to comply with a legal requirement or our legitimate interest.
We will not destroy your data after the expiry of the storage period if a competent government authority has requested it or the data is necessary for the establishment, exercise or defence of legal claims.
SHARING YOUR PERSONAL DATA WITH THIRD PARTIES:
We respect the confidentiality of your data and, as a rule, do not provide it to third parties. As an exception to this rule and subject to applicable legal requirements, we may provide your data to:
o state and regulatory authorities in the Republic of Bulgaria (such as: NRA, NSA, CPDP, Ministry of Interior, Prosecutor's Office, court, etc.) at their explicit request;
o commercial banks (for the purpose of payment of amounts due under the concluded contract);
o companies providing Our technical and operational support (e.g. platform and website maintenance, data center, etc.), consulting or other activities (e.g. auditing) where it is possible, exceptionally, to have access to your data. In these cases, the disclosure of data takes place only in the presence of a valid reason and a written agreement with them in order to ensure the necessary level of protection.
AS SUBJECTS OF PERSONAL DATA, YOU HAVE THE RIGHT TO:
o information about and access to your personal data processed by Haelan;
o to know what categories of personal data we collect and the purposes for which we process them;
o information about the recipients of your personal data, where applicable;
o to know for what period your personal data is stored;
o to correct your personal data processed by us where they are inaccurate, to be supplemented when they are incomplete and to be updated when a change has occurred;
o to request that your personal data be deleted, in the presence of legal grounds for this and if there is no obligation for us, on the basis of a legal act or a contract concluded by you, for their processing or storage;
o withdraw your consent for your personal data to be processed for direct marketing purposes or for other additional purposes to which you initially consented;
o to object to the processing of your personal data, if there are legal grounds for this and if there is no obligation for Us, on the basis of a legal act or a concluded contract, for their processing;
o to restrict the processing of your personal data for a certain period of time (for example, for the time necessary to establish the accuracy of your data or for the purposes of establishing or exercising legal claims by you);
o the portability of your data, in a structured, widely used and machine-readable format, where the processing is based on consent or contractual obligation and is carried out in an automated manner;
o a complaint to the Commission for Personal Data Protection (www.cpdp.bg), when you consider that we have violated your rights related to your personal data;
o Information about the source of your personal data that you have not provided to us (e.g. if it is provided to us by a company, if we have accessed it through public sources of information such as trade registers, etc.).
In order to exercise any of the rights listed above or to receive additional information about the processing of your personal data, it is necessary to visit our head office, our medical center or to request this by e-mail care@haelan.bg, with an attached application in free text, signed with a qualified electronic signature (KEP).
In order to obtain information and exercise your rights, it is necessary that you first identify yourself and our employees verify your identity. This requirement protects your rights and your personal data.
The information about your personal data that is being processed will be provided to you free of charge, at the latest within one month of receiving your request.
This information and the Privacy Policy may be updated from time to time, depending on changes in the regulations and/or activities of Haelan. Their current versions are published on the website www.haelan.bg.
Date of last update: 04\ 2025
Information on the processing of personal data of SAT Health and Haelan employees
The processing of your personal data as employees of SAT Health and Haelan is carried out in compliance with the applicable national and European legislation in the field of personal data.
We hereby inform you about the processing of your personal data by the controllers listed below and about your rights related to them, as well as provide you with the information under Art. 13 and Art. 14 of the General Data Protection Regulation.
PERSONAL DATA CONTROLLER DETAILS AND CONTACT DETAILS
Administrator “Heilan” EAD, ID: 207648560
Headquarters and management address: Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Tel.: +359893 02 02 02
Email: care@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care - Medical Center” Ltd., ID: 207312638
Headquarters and management address: Gr. Sofia, 1404, blvd. “Bulgaria” № 51A, fl. 3
Tel.: +359893020202
Email: haelan.care1@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 2 — Medico-Dental Center” Ltd., ID: 201760855
Headquarters and management address: Gr. Sofia, ul. “Business Park Sofia” № 1, building № 2, fl. 1
Tel.: +359892202040
Email: haelan.care2@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 3 — Medical Center” Ltd., ID: 206470233
Headquarters and management address: Gr. Sofia, Mihail Tenev № 6, building D, ground floor
Tel.: +359893020202
Email: haelan.care3@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 4 — Medical Center” Ltd., ID: 207710752
Headquarters and management address: Gr. Varna, blvd. “Vladislav Varnenchik” № 267
Tel.: +359887 50 30 60
Email: haelan.care4@haelan.bg
Website: www.haelan.bg
Administrator “Pia Mater” Ltd., ID: 201409799
Headquarters and management address: Gr. Sofia, ul. Racho Petkov Kazandjiyatta № 4-6, office № 2
Tel.: +359884588446
Email: office@piamater.org; classes@piamater.org
Website: www.haelan.bg; www.piamater.org
Administrator SAT Health AD, EIC 204705650
Headquarters and management address: Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Email: office@sathealth.com
Website: www.sathealth.com
DATA PROTECTION OFFICER AND CONTACT DETAILS:
Mariya Georgieva Nestorova
Bulgaria, Gr. Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Telephone: +359882727270
E-mail: dpo@sathealth.com
PURPOSES AND LEGAL BASIS FOR PROCESSING YOUR PERSONAL DATA:
The basis for the processing of your personal data may be legal, contractual, consent expressly provided by you or our legitimate interest:
o The legal basis for processing may be the requirements of the Labor Code (TC), the Social Security Code (CSD), the Personal Income Tax Act (ZDDFL), the Tax and Insurance Procedure Code (DOPC), the Accounting Act (ZH), the Health and Health Care Act occupational safety (OSH) and other applicable legal acts;
o Contractual basis is the contract concluded with you (employment contract, management contract);
o Consent to the processing of your data and the data of your relatives and children for additional purposes (such as for additional social benefits, etc.) ;
In some cases and subject to applicable law, the basis may be our legitimate interest.
Your personal data is processed for the purposes of the employment relationship with you and is not further processed in a manner incompatible with these purposes. These include:
o drafting, conclusion and execution of the contract;
o payment of remuneration and preparation and storage of documents certifying its payment, as well as for the purpose of reimbursement of representative expenses incurred by you;
o Preparation and storage of your employment record;
o exercise of your social security and employment rights;
o preparing official income statements for tax purposes (or at your request for other purposes, such as before social or credit institutions);
o trainings and tests to establish your level of competence;
o an overall assessment of your performance as an employee;
o Survey of your satisfaction as an employee, incl. in outgoing interviews;
o the provision of additional health and social benefits (where applicable, including supplementary health and pension insurance, life insurance, medical liability, food vouchers, sports cards, etc.);
o the fulfillment of our obligations as your employer by virtue of CT, CSR, OSZBUT and other normative acts.
Subject to regulatory requirements, in some cases we may process your personal data to protect our legitimate interests, for example, when you are subject to video surveillance in our medical centers or photos and videos with your image are used for the purposes of corporate marketing and advertising events, public events, publications, presentations and other materials that are displayed or made available to the public. including when covering events or news in corporate profiles created in various social networks.
In connection with the security requirements that we apply in Haelan medical centers, video surveillance is carried out only in common areas - corridors and reception (more information can be found in Pro08 - Procedure for processing and protection of video surveillance data in Haelan medical centers).
CATEGORIES OF PERSONAL DATA THAT WE PROCESS:
We process your personal data for the purposes of concluding and performing an employment contract with you, as an employer and on the basis of labor, social security and tax legislation. In particular, we collect and process the following personal data:
o data from an identity document such as name, surname, surname; personal identification number (or personal identification number); age; gender; nationality; photo;
o contact details such as: personal e-mail, telephone and address;
o data and documents about your educational degree and acquired qualifications (incl. data on school, vocational, higher education, number and date of diploma, specialty,
o data from certificates held by you;
o data on work and social security experience (including acquired professional experience in a given field and/or in a given position);
Information contained in recommendations from your previous employers;
o data from your profile on the social network Linkedin;
Photos and videos with your image for the purposes of corporate marketing and advertising events, public events, publications, presentations and other materials that are displayed or made available to the public;
o video surveillance data in the common areas of our medical centers;
o data from your work email and other data about your activity through company devices, for the purposes of information security and the prevention of abuse;
o details of a driving licence held by you (where such a licence is required for the relevant position);
o data on your state of health related to your appointment to work (such as a medical certificate for starting work or certificates from medical authorities in case you have reduced working capacity); as well as data relating to the exercise of your rights under the Labour Code, such as rights in the event of temporary or permanent incapacity for work, carrying out preventive work medical examinations, etc., related to the performance of our duties as an employer, incl. to create healthy and safe working conditions;
o criminal records, where a legal act requires the verification of a criminal record;
o bank account details (for payment of remuneration under a contract);
o data about your relatives (spouse, children), only insofar as they are related to your right to leave and exercise your other employment and social security rights, as well as in cases where we provide you with additional social benefits (e.g. supplementary health insurance or sports cards of your family members);
o data about you and your relatives for the purposes of measures to prevent conflicts of interest (such as positions held in commercial companies, ownership of shares in such companies, etc.), in cases where it is necessary to declare this information.
It is important to know that, as our employees, we do not require you to provide us with data about your racial or ethnic origin, political views, religious or philosophical beliefs or membership in trade union organizations, nor do we process genetic data and biometric data, data on sex life or sexual orientation.
TERM OF PROCESSING OF YOUR PERSONAL DATA:
We process your data during the employment relationship by storing:
o data on your employment contract, employment and insurance experience and documents for paid remuneration, for a period not less than 50 years after its termination on the basis of the applicable legislation (TC, DOPC, etc.) ;
o all documents from the employment record that relate to the financial statements and orders for business trips, for a period of not less than 10 years on the basis of the applicable legislation (Accounting Act, etc.) ;
o the rest of your data for a period not exceeding 5 years from the termination of our relationship with you as our employee;
o the data of your family members in connection with the provided additional social services for sport — until the withdrawal of the consent to the processing of the data for these purposes and the termination of the use of the service;
o the data of your family members in connection with the provided additional social services for health insurance — for a period of 1 year;
o Your personal data related to and/or contained in tax insurance control documents (contracts, invoices, credit and debit notices) for a period of 10 (ten) years, starting from the beginning of the year of the reporting period following the reporting period to which they relate;
o Audio recordings of telephone calls made by you through the corporate telephone exchange — 5 (five) years after the end of the year in which the calls were made, after which they are automatically deleted, unless we are required to retain them for a longer period in order to comply with a legal requirement or our legitimate interest.
o the data contained in CCTV recordings for a period of 30 (thirty) days.
We will not destroy your data after the expiry of the storage period only if a competent governmental authority has requested it or the data is necessary for the establishment, exercise or defence of legal claims.
SHARING YOUR PERSONAL DATA WITH THIRD PARTIES:
We respect the confidentiality of your data and, as a rule, do not provide it to third parties. As an exception to this rule and subject to applicable legal requirements, we may provide your data to:
o state and regulatory authorities in the Republic of Bulgaria (such as: NRA, NSA, CPDP, Ministry of Interior, Prosecutor's Office, court, etc.) at their explicit request;
o legal entities, executive and local authorities and advisory bodies, for the purpose of demonstrating corporate capacity when applying for contracts, financing projects or competitions, including public ones;
o specialized companies with whom we work on the basis of a written agreement, whereby they undertake to comply with the legislation in the field of personal data and to ensure an adequate level of data protection, such as:
• specialized recruitment companies;
• commercial banks (for the purpose of paying your remuneration) and financial companies (for example Payhawk and others);
• insurance companies, when we provide you with additional health insurance and medical liability insurance;
• providers of services for sports activities and relaxation activities;
• travel agencies, hotels and other organizations organizing accommodation, travel and activities in connection with business trips, company events and team buildings;
• companies providing our technical and operational support (e.g. platform maintenance, data center, etc.), consulting or other activities (e.g. auditing), providers of accounting, legal services, occupational health and safety services, medical and specialty insurance and others where it is possible, exceptionally, to have access to your data.
AS SUBJECTS OF PERSONAL DATA, YOU HAVE THE RIGHT TO:
o information on whether we process your personal data;
o access to your personal data processed by us and the right to receive a copy of the personal data processed;
o to know what categories of personal data we collect and the purposes for which we process them;
o information about the recipients of your personal data, where applicable;
o to know for what period your personal data is stored;
o to correct your personal data processed by us, where they are inaccurate, to be supplemented, if they are incomplete or in the event of a change, to be updated;
o to request that your personal data be deleted if there are legal grounds for this and if there is no obligation for us, on the basis of a legal act or a contract concluded by you, for their processing or storage;
o withdraw your consent for your personal data to be processed for additional purposes for which you initially consented;
o object to the processing of your personal data, if there are legal grounds for this and if there is no obligation for us, on the basis of a legal act or a concluded contract, for their processing;
o to restrict the processing of your personal data for a certain period of time (for example, for the time necessary to establish the accuracy of your data or for the purposes of establishing or exercising legal claims by you);
o the portability of your data, in a structured, widely used and machine-readable format, where the processing is based on consent or contractual obligation and is carried out in an automated manner;
o a complaint to the Commission for Personal Data Protection (www.cpdp.bg), when you consider that we have violated your rights related to your personal data;
o information about the source of your personal data that you have not provided to us.
In order to exercise any of the rights listed above, it is necessary to request this to the Human Resources Manager by e-mail, with a copy to the CEO/manager of the company of the SAT Health or Haelan group in which you work.
The information about your personal data that is being processed will be provided to you free of charge, at the latest within one month of receiving your request.
This information may be updated periodically, subject to changes in the regulations and/or activities of SAT Health and Haelan. Their current versions are published on an internally shared directory.
Date of last update: 04\ 2025
Information on the processing of personal data of persons applying for a job at Haelan
Applying for a job at Haelan and your participation in a selection procedure are related to the processing of your personal data. The processing is carried out in compliance with the applicable national and European legislation in the field of personal data.
We hereby inform you about the processing of your personal data by the controllers listed below and about your rights related to them, as well as provide you with the information under Art. 13 and Art. 14 of the General Data Protection Regulation.
By applying for a job at Haelan, you confirm that you have read and understand this information and that you wish the following personal data controllers to collect and process your personal data for the evaluation of your application for the purpose of concluding an employment contract. You provide your personal data voluntarily and insofar as you consider it necessary.
PERSONAL DATA CONTROLLER DETAILS AND CONTACT DETAILS
Administrator “Heilan” EAD, ID: 207648560
Headquarters and management address: Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Tel.: +359893 02 02 02
Email: care@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care - Medical Center” Ltd., ID: 207312638
Headquarters and management address: Gr. Sofia, 1404, blvd. “Bulgaria” № 51A, fl. 3
Tel.: +359893020202
Email: haelan.care1@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 2 — Medico-Dental Center” Ltd., ID: 201760855
Headquarters and management address: Gr. Sofia, ul. “Business Park Sofia” № 1, building № 2, fl. 1
Tel.: +359892202040
Email: haelan.care2@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 3 — Medical Center” Ltd., ID: 206470233
Headquarters and management address: Gr. Sofia, Mihail Tenev № 6, building D, ground floor
Tel.: +359893020202
Email: haelan.care3@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 4 — Medical Center” Ltd., ID: 207710752
Headquarters and management address: Gr. Varna, blvd. “Vladislav Varnenchik” № 267
Tel.: +359887 50 30 60
Email: haelan.care4@haelan.bg
Website: www.haelan.bg
Administrator “Pia Mater” Ltd., ID: 201409799
Headquarters and management address: Gr. Sofia, ul. Racho Petkov Kazandjiyatta № 4-6, office № 2
Tel.: +359884588446
Email: office@piamater.org; classes@piamater.org
Website: www.haelan.bg; www.piamater.org
Administrator SAT Health AD, EIC 204705650
Headquarters and management address: Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Email: office@sathealth.com
Website: www.sathealth.com
DATA PROTECTION OFFICER AND CONTACT DETAILS:
Mariya Georgieva Nestorova
Bulgaria, Gr. Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Telephone: +359882727270
E-mail: dpo@sathealth.com
PURPOSES AND LEGAL BASIS FOR PROCESSING YOUR PERSONAL DATA:
The basis for the processing of your personal data may be legal, contractual (including pre-contractual - steps to conclude a contract), your explicit consent or Our legitimate interest:
o Legal basis for processing may be the requirements of the Labor Code, the Social Security Code, the Personal Income Tax Act and other normative acts;
o A contractual (pre-contractual) basis is when the processing is necessary to take steps at your request before entering into a contract;
o Your consent is the basis for processing your data where you have expressly expressed it (for example in the application procedure for a job with us);
In some cases and subject to applicable law, the basis may be Our legitimate interest.
Your personal data are processed only for the purposes of selecting and concluding a contract with you and are not further processed in a manner incompatible with these purposes:
o carrying out the selection, incl. establishing the availability of the requirements for the position;
o collection of the necessary data and documents for the appointment of an employment contract;
o conclusion and execution of an employment contract.
Subject to regulatory requirements, in some cases we may process your personal data to protect our legitimate interests, for example when you are subject to video surveillance when visiting our medical centres. In connection with the security requirements that we apply in Haelan medical centers, video surveillance is carried out in common areas - corridors and reception (more information can be found in the Privacy Policy published on Our Website).
CATEGORIES OF PERSONAL DATA THAT WE PROCESS:
We only process personal data of job applicants that are relevant to the selection process and the requirements for the position. These include, for example, your contact details necessary to communicate with you; data on your education and qualifications, professional experience and skills; data necessary for the purposes of concluding the contract with you, such as name, address, etc.
In particular, we collect and process the following personal data:
o first names: first name, surname, surname;
o EGN (or LNCH); age; gender;
o nationality;
o photo;
o contact details such as: e-mail, telephone and address;
o data and documents about your educational degree and acquired qualifications (including data on school, vocational, higher education, number and date of diploma, specialty, certificates held by you, etc.);
o data on work and social security experience (including acquired professional experience in a given field and/or in a given position);
Information contained in recommendations from your previous employers;
o data from your profile on the social network LinkedIn;
o data from a videoconference held in the selection process (if one was held with you);
o cookies and other data about your activity on Our website (if you have applied for a position through our website);
o Video surveillance data in the common areas of our medical centers, when the interview with you was conducted in our medical centers.
o details of a driving licence held by you (where such a licence is required for the relevant position);
o data on your state of health related to your appointment to work, such as a medical certificate for starting work, or certificates from medical authorities in case you have reduced working capacity.
o criminal records, where a legal act requires the verification of a criminal record.
It is important to know that in the selection process We do not require you to provide us with data on your racial or ethnic origin, political views, religious or philosophical beliefs or membership in trade union organizations, nor do we process genetic data and biometric data, data on sex life or sexual orientation.
TERM OF PROCESSING OF YOUR PERSONAL DATA:
We process your data in the selection process and if we enter into a contract with you, your data will continue to be processed by us, but already in your capacity as our employee, on the basis of the concluded contract and the legislation applicable to the relevant labor and civil legal relations, incl. in compliance with the deadlines provided therein.
If we do not enter into a contract with you, your data is stored for the purpose of participating in a new selection procedure for up to 6 months after the end of the selection process (appointment of the selected candidate to the position or termination of the procedure without selection).
If you have provided us with originals or copies of documents, we will return or destroy these documents, in case you are not approved for appointment, after the end of the selection procedure.
We store the data contained in CCTV recordings for a period of 30 (thirty) days.
We will not destroy your data after the expiry of the storage period only if a competent governmental authority has requested it or the data is necessary for the establishment, exercise or defence of legal claims.
SHARING YOUR PERSONAL DATA WITH THIRD PARTIES:
We respect the confidentiality of your data and, as a rule, do not provide it to third parties. As an exception to this rule and subject to applicable legal requirements, we may provide your data to:
o state and regulatory authorities in the Republic of Bulgaria (such as: NRA, NSA, CPDP, Ministry of Interior, Prosecutor's Office, court, etc.) at their explicit request;
o operators providing postal and courier services, only at your request, in the event that you wish us to send you documents or other correspondence; In this case, we will share with them your address data and data on your identification as recipient, within the scope necessary for the purposes of sending and delivering the shipment.
o specialized recruitment and recruitment companies, when we work with them, on our behalf and on the basis of a written agreement whereby they undertake to comply with the legislation in the field of personal data and to ensure an adequate level of data protection.
AS SUBJECTS OF PERSONAL DATA, YOU HAVE THE RIGHT TO:
o information on whether we process your personal data;
o access to your personal data processed by us and the right to receive a copy of the personal data processed;
o to know what categories of personal data we collect and the purposes for which we process them;
o information about the recipients of your personal data, where applicable;
o to know for what period your personal data is stored;
o to correct your personal data processed by us where they are inaccurate, to be supplemented when they are incomplete and to be updated when a change has occurred;
o to request the deletion of your personal data, if there are legal grounds for this and if there is no obligation for us, on the basis of a legal act or a contract concluded by you, for their processing or storage;
o withdraw your consent for your personal data to be processed for direct marketing purposes or for other additional purposes to which you initially consented;
o object to the processing of your personal data, if there are legal grounds for this and if there is no obligation for us, on the basis of a legal act or a concluded contract, for their processing;
o to restrict the processing of your personal data for a certain period of time (for example, for the time necessary to establish the accuracy of your data or for the purposes of establishing or exercising legal claims by you);
o the portability of your data, in a structured, widely used and machine-readable format, where the processing is based on consent or contractual obligation and is carried out in an automated manner;
o a complaint to the Commission for Personal Data Protection (www.cpdp.bg), when you consider that we have violated your rights related to your personal data;
o information about the source of your personal data that you have not provided to us (e.g. if provided to us by a recruitment company and others).
To exercise any of the rights listed above, it is necessary to visit our medical center or request it by e-mail care@sathealth.com with an attached application in free text, signed with a qualified electronic signature (KEP).
In order to obtain information and exercise your rights, it is necessary that you first identify yourself and our employees verify your identity. This requirement protects your rights and your personal data.
The information about your personal data that is being processed will be provided to you free of charge, at the latest within one month of receiving your request.
This information and the Privacy Policy may be updated from time to time, depending on changes in the regulations and/or activities of Haelan. Their current versions are published on the website www.haelan.bg.
Date of last update: 04\ 2025
Information and access to personal data of persons working for Haelan in non-employment relationships as subjects of personal data
With this document, we inform you about the processing of your personal data by Haelan companies (the controllers referred to below, “Haelan” for short) and about your rights related to them, as well as provide you with the information under Art. 13 and Art. 14 of the General Data Protection Regulation...
PERSONAL DATA CONTROLLER DETAILS AND CONTACT DETAILS
Administrator “Heilan” EAD, ID: 207648560
Headquarters and management address: Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Tel.: +359893 02 02 02
Email: care@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care - Medical Center” Ltd., ID: 207312638
Headquarters and management address: Gr. Sofia, 1404, blvd. “Bulgaria” № 51A, fl. 3
Tel.: +359893020202
Email: haelan.care1@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 2 — Medico-Dental Center” Ltd., ID: 201760855
Headquarters and management address: Gr. Sofia, ul. “Business Park Sofia” № 1, building № 2, fl. 1
Tel.: +359892202040
Email: haelan.care2@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 3 — Medical Center” Ltd., ID: 206470233
Headquarters and management address: Gr. Sofia, Mihail Tenev № 6, building D, ground floor
Tel.: +359893020202
Email: haelan.care3@haelan.bg
Website: www.haelan.bg
Administrator “Haylan Care 4 — Medical Center” Ltd., ID: 207710752
Headquarters and management address: Gr. Varna, blvd. “Vladislav Varnenchik” № 267
Tel.: +359887 50 30 60
Email: haelan.care4@haelan.bg
Website: www.haelan.bg
Administrator “Pia Mater” Ltd., ID: 201409799
Headquarters and management address: Gr. Sofia, ul. Racho Petkov Kazandjiyatta № 4-6, office № 2
Tel.: +359884588446
Email: office@piamater.org; classes@piamater.org
Website: www.haelan.bg; www.piamater.org
Administrator SAT Health AD, EIC 204705650
Headquarters and management address: Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Email: office@sathealth.com
Website: www.sathealth.com
DATA PROTECTION OFFICER AND CONTACT DETAILS:
Mariya Georgieva Nestorova
Bulgaria, Gr. Sofia, 1766, ul. “Racho-Petkov Kazandjiyatta” № 4-6, office № 2
Telephone: +359882727270
E-mail: dpo@sathealth.com
PURPOSES AND LEGAL BASIS FOR PROCESSING YOUR PERSONAL DATA:
Haelan processes your personal data, in your capacity as a person working in non-employment relations with Haelan, in connection with the activity of concluding and executing assignment contracts (civil contracts), on the basis of:
o The Social Security Code, the Health Insurance Code and applicable civil, commercial and tax legislation, as well as all other laws and regulations applicable to Haelan's activities;
o A civil contract signed between you and Haelan.
We process your personal data only for the specific purposes specified in the legal acts mentioned above and/or in civil contracts and/or in other documents, including, but not limited to, the purposes of:
o the conclusion of the contract and your identification as a party to it;
o completing and storing the contract and the documents attached to it, certifying compliance with the legal requirements;
o payment of the remuneration under the contract;
o fulfillment of rights and obligations under the contract;
o for internal company satisfaction surveys, surveys, exit interviews, etc.
Subject to regulatory requirements, in some cases we may process your personal data to protect our legitimate interests, for example when you are subject to video surveillance when visiting our medical centres. In connection with the security requirements that we apply in Haelan medical centers, video surveillance is carried out in corridors and at the reception (more information can be found in the Privacy Policy published on Our Website).
CATEGORIES OF PERSONAL DATA THAT WE PROCESS:
We process only your personal data that are related to the legal relationship under the civil contract, complying with the requirements of European and national legislation. We do not process special categories of personal data, with the exception of data on reduced working capacity, if you provide it to us in connection with taxation.
TERM OF PROCESSING OF YOUR PERSONAL DATA:
We store:
o the civil contract and related documents and data - throughout the term of the contract and 5 years after its termination;
o the documents certifying the remuneration paid to you, in paper and/or electronic form - 50 years after the termination of the civil contract.
o we store audio recordings of telephone conversations with you — 5 (five) years after the end of the year in which the calls were made, after which they are automatically deleted, unless we are required to keep them for a longer period in order to comply with a legal requirement or our legitimate interest;
o We store the data contained in CCTV recordings for a period of 30 (thirty) days.
We do not destroy personal data and documents if they are necessary to establish, exercise or defend legal claims or when there is a need to present the documents to a government authority.
PROVIDING YOUR PERSONAL DATA TO THIRD PARTIES:
We do not provide your personal data to third parties unless:
o this is not requested by you;
o this is necessary in view of the legal relationship under the contract (such as the commercial bank you specify, when we pay you remuneration, etc.) ;
o there is a legal obligation for Haelan to provide your data to the National Revenue Agency, the National Insurance Institute or any other authority;
o is necessary in connection with our technical and operational support of the activity and provision of the services (e.g. platform maintenance, data centre, etc.), consultancy activities or services (e.g. audit) where it is possible, exceptionally, for service providers to have access to your data. In these cases, the disclosure of data takes place only in the presence of a valid reason and a written agreement with the service providers in order to ensure the necessary level of protection.
AS SUBJECTS OF PERSONAL DATA, YOU HAVE THE RIGHT TO:
o information about and access to your personal data processed by Haelan;
o to know what categories of personal data we collect and the purposes for which we process them;
o information about the recipients of your personal data;
o to know for what period your personal data is stored;
o to correct your personal data processed by Haelan where they are inaccurate, to be supplemented when they are incomplete and to be updated when there is a change;
o request the deletion of your personal data, if there are legal grounds for this and if Haelan does not have an obligation, on the basis of a legal act or a contract concluded by you, for their processing or storage;
o object to the processing of your personal data, if there are legal grounds for this and if Haelan does not have an obligation, on the basis of a legal act or a contract, for their processing;
o withdraw your consent for your personal data to be processed for direct marketing purposes or for other additional purposes to which you initially consented;
o the portability of your data, in a structured, widely used and machine-readable format, where the processing is based on consent or contractual obligation and is carried out in an automated manner;
o a complaint to the Commission for Personal Data Protection when you consider that we have violated your rights related to your personal data (www.cpdp.bg);
o information about the source of your personal data that you have not provided to us (where applicable).
In order to obtain information and exercise any of these rights, it is necessary that you first identify yourself and our employees verify your identity. This requirement protects your rights and your personal data.
The information about your personal data that is being processed will be provided to you free of charge, at the latest within one month of receiving your request.
In the event that you have submitted a request for the exercise of rights, we will provide you with information about the actions we have taken at your request without delay, but at the latest within one month of receiving your request. If necessary, this period may be extended by a further two months, taking into account the complexity and number of requests received. In this case, we will inform you of the extension and the reasons for it within one month of receiving your request.
In order to exercise any of the rights listed above, it is necessary to visit our medical center or request this by e-mail with an attached application in free text signed with a qualified electronic signature (KEP).
If you wish to receive further information about the processing of your personal data, you can contact us at the contacts indicated above.
This information may be updated from time to time, depending on changes in Haelan's regulations and/or activities. The current version is published on the website www.haelan.bg.
Date of last update: 04\ 2025