Cabinet de Kinésithérapie Paris Chaligny
EN

Data protection / Privacy policy

1. Purpose of this policy

This policy describes the processing of personal data carried out in connection with the website https://kine-pc.fr/, its protected areas, and the administrative organisation and care of patients by the physiotherapists practising at Cabinet de Kinésithérapie Paris Chaligny.

In particular, it specifies the data that may be processed, the purposes and legal bases of the processing, the recipients of the data, the applicable retention periods and the rights of data subjects.


2. Data controllers

2.1. Website and technical operation

The processing operations relating to the operation, security and technical administration of this website are carried out under the responsibility of:

Tina THIEME, sole trader (EI)
Trading name: Cabinet de Kinésithérapie Paris Chaligny
265 B Rue du Faubourg Saint-Antoine
75011 Paris – France
Tel.: 09 50 53 14 30
Email: contact@kine-pc.fr

2.2. Patient data

Each self-employed physiotherapist practising at the practice is the data controller for the data relating to their own patients, including the data contained in their patient records, the management of their appointments and the accounts they create and manage within the protected areas.

The identity of the relevant therapist is communicated to the patient when the appointment is booked and during their care. Wherever possible, any request concerning a patient’s data should be addressed directly to the relevant therapist.

Tina THIEME is also responsible for the technical operation, administration and security of the protected areas. For accounts created by the other self-employed therapists, her access to the data is limited to what is necessary for these purposes.


3. Data processed, purposes and legal bases

3.1. Website use and security

When the website is accessed, certain technical data may be recorded by the server, including:

  • the IP address;
  • the date and time of the connection;
  • the pages or resources requested;
  • the type of browser and device used;
  • technical information relating to errors or access attempts.

These data are processed to ensure the operation, availability and security of the website, to detect technical errors and to prevent fraudulent or abusive access.

This processing is based on the publisher’s legitimate interest in ensuring the operation and security of her digital services, in accordance with Article 6(1)(f) of the GDPR.

3.2. Contact requests

When a person contacts the practice by telephone or email, the information they provide may be processed in order to respond to their request and, where appropriate, forward it to the relevant therapist.

This information may include the person’s name, the contact details used for the response and the content of the request.

The processing of general enquiries is based on the legitimate interest in responding to requests received. Where a request concerns an appointment or patient care, its processing is also based, depending on its nature, on steps taken at the request of the data subject and on the obligations applicable to healthcare professionals.

Users are advised not to send detailed medical information or documents containing health data by email unless this is necessary and the method of transmission has been agreed with the therapist.

3.3. Patient care and patient records

In the course of their professional activities, physiotherapists may process the data required:

  • to manage appointments;
  • to identify the patient;
  • to assess, monitor and ensure continuity of care;
  • to maintain the patient record;
  • to invoice and electronically transmit details of treatment provided;
  • to comply with the legal, regulatory, accounting and professional obligations of the healthcare professional.

These data may include identity and contact details, administrative information, information relating to social security coverage and the health data required for patient care.

The maintenance of patient records and preparation of the documents required for patient care are based on compliance with the legal obligations applicable to healthcare professionals, in accordance with Article 6(1)(c) of the GDPR.

Appointment management and the organisation of professional activities are based on the legitimate interest of the relevant healthcare professional, in accordance with Article 6(1)(f) of the GDPR.

Health data are processed for the purposes of diagnosis, treatment and the provision of healthcare, in accordance with Article 9(2)(h) of the GDPR. They are processed by healthcare professionals who are subject to professional confidentiality.

3.4. Appointment booking through Doctolib

The website may provide access to an appointment-booking module supplied by Doctolib. This module is not loaded automatically. It is activated only following a deliberate action by the user.

When the module is activated and used, technical data may be transmitted to Doctolib. The information entered to book an appointment is subsequently processed on the Doctolib platform.

Each healthcare professional remains the data controller for data relating to appointment booking and the care of their own patients. Doctolib acts as a data processor for the services it provides to healthcare professionals.

Doctolib may also act as a separate data controller for the creation and management of Doctolib user accounts and for certain processing operations specific to its platform.

For further information: Doctolib Privacy Policy.

3.5. Patient Area

The Patient Area is accessible only to patients who have received a username and temporary password from their therapist.

The following data may be recorded for each account:

  • the patient’s first name and the initial of their surname;
  • a username generated for the account;
  • a secure, non-reversible cryptographic hash of the password;
  • the dates on which the account was created and expires and, where applicable, the date of the last login;
  • the technical information required for authentication and account security.

The Patient Area contains no diagnoses, prescriptions, medical reports or individual treatment programmes. The exercises and documents available form a general library and are not assigned individually through the portal.

These data are processed to manage access to the library, authenticate users and ensure the security of the service. This processing is based on the relevant therapist’s legitimate interest in making these resources available to their patients and controlling access to them.

Each self-employed therapist is responsible for the accounts they create and manage for their own patients. Tina THIEME is responsible for the technical operation, administration and security of the platform.

3.6. External content and services

The website and its protected areas may provide content hosted by external providers, including a Google virtual tour or videos hosted on specialised platforms.

This content is not loaded automatically. It is activated only following a deliberate action by the user, after the user has been informed that a connection will be established with the relevant provider.

When the content is activated, the external provider may receive certain technical data, including the IP address, browser characteristics and information relating to the content viewed. The provider may also use its own cookies or other tracking technologies in accordance with its privacy policy.


4. Cookies and local storage

The website does not use cookies for audience measurement, profiling or advertising.

Strictly necessary cookies may be used to:

  • enable authentication within the protected areas;
  • maintain the user’s session;
  • protect accounts and prevent fraudulent access;
  • retain certain technical choices that are essential to the operation of the service.

These cookies are essential to the requested service and do not require prior consent. Blocking them may prevent users from logging in or may interfere with the normal operation of the protected areas.

External services that may use their own cookies or tracking technologies are not loaded until the user deliberately activates them. Users may continue browsing without activating these services.


5. Recipients and service providers

The data are accessible only to persons who require them in the course of their duties and within the limits of their access permissions.

Depending on the nature of the processing, recipients may include:

  • the therapist responsible for the patient’s care;
  • healthcare professionals involved in ensuring continuity of care, where disclosure is authorised or necessary;
  • statutory or supplementary health insurance organisations, within the limits laid down by applicable regulations;
  • Tina THIEME, only where her involvement is necessary for the technical administration or security of the protected areas;
  • technical service providers acting on behalf of the data controller, within the limits of the services entrusted to them;
  • authorities or organisations legally authorised to receive certain information.

The website and its protected areas are hosted by:

IONOS SARL
7, place de la Gare – BP 70109
57200 Sarreguemines – France
Website: www.ionos.fr

Personal data are not sold, rented or used for marketing purposes.


6. Retention periods

Data are retained only for as long as necessary for the purpose for which they were collected, subject to legal obligations or the periods necessary for the establishment, exercise or defence of legal claims.

  • Patient records: the data may be retained for twenty years from the date of the most recent care provided, comprising five years in the active database followed by fifteen years in archived form on a separate medium, subject to the specific periods applicable to certain documents or circumstances.
  • Requests received by telephone or email: these are retained for the time required to process them. Where they are necessary for patient care, they may be incorporated into the patient record and retained for the period applicable to that record.
  • Technical data and website logs: these are retained only for the period strictly necessary to ensure the security of the service, diagnose incidents and comply with the hosting provider’s obligations.
  • Patient Area: an account is normally created for a period of six months. It is automatically deactivated on its expiry date. Unless extended by the relevant therapist, the account and its associated data are automatically and permanently deleted 30 days after that date. Patients may also request early deletion or delete their account using the relevant feature.
  • Records of failed login attempts: where such records are kept, they are limited to the information necessary to protect the service and are deleted or automatically anonymised within 24 hours at the latest.
  • Session cookies: these expire at the end of the session or after the period strictly necessary for authentication and account security.

7. Security and confidentiality

Technical and organisational measures are implemented to protect data against loss, alteration, disclosure or unauthorised access.

These measures include:

  • the use of an encrypted HTTPS connection;
  • individual access protected by a username and password;
  • mandatory replacement of the temporary password upon first login;
  • the storage of passwords in the form of non-reversible cryptographic hashes;
  • the restriction of access rights according to operational requirements;
  • session protection and the monitoring of login attempts;
  • the regular maintenance and updating of technical services.

Despite the precautions implemented, no computer system can guarantee absolute security. In the event of an incident that may result in a risk to the rights and freedoms of data subjects, the measures required by applicable regulations will be implemented.


8. Transfers of data outside the European Economic Area

Activating an external service or external content may result in data being processed by the relevant provider, including, depending on the provider, outside the European Economic Area.

Such processing is carried out under the responsibility of the external provider and in accordance with its own privacy policy and the safeguards it implements for any international transfers.

Users may continue to use the website without activating this external content.


9. Rights of data subjects

Under the conditions laid down by the GDPR and depending on the legal basis of the relevant processing, every person has, in particular:

  • the right to access their personal data;
  • the right to have inaccurate or incomplete data rectified;
  • the right to restriction of processing;
  • the right to erasure, where the legal requirements are met;
  • the right to object to processing based on legitimate interests, on grounds relating to their particular situation;
  • the right to data portability, where this right applies;
  • the right to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before its withdrawal.

Certain rights may be restricted by the healthcare professional’s legal obligations. In particular, patients cannot object as a matter of principle to the mandatory maintenance of their patient record or obtain the erasure of data that must continue to be retained in order to comply with a legal obligation or defend legal claims.

Requests concerning patient records, appointments or an account created by a therapist should be addressed primarily to the relevant therapist.

Requests concerning the operation of the website, its technical administration or the security of the protected areas may be addressed to:

Tina THIEME
Email: contact@kine-pc.fr
Address: 265 B Rue du Faubourg Saint-Antoine, 75011 Paris – France

If a request is sent to the practice without identifying the relevant therapist, it will be forwarded to the healthcare professional responsible for the corresponding processing.

Proof of identity may be requested where there is reasonable doubt concerning the identity of the person making the request. A response will be provided within the period prescribed by applicable regulations, normally within one month of receipt of a complete request.


10. Complaints to the CNIL

Any person who considers, after contacting the relevant data controller, that their rights have not been respected may submit a complaint to:

Commission nationale de l’informatique et des libertés – CNIL
3 Place de Fontenoy – TSA 80715
75334 Paris Cedex 07
Website: www.cnil.fr


11. Automated decision-making

The data processed through the website and its protected areas are not subject to any solely automated decision-making or profiling that produces legal effects or similarly significantly affects data subjects.


12. Changes to this policy

This policy may be amended to reflect legal, regulatory, technical or functional developments affecting the services provided.

The date of the most recent update is shown in the footer. The version published online is the version currently in effect.


Book an appointment on:
Doctolib.fr


Telephone:
09 50 53 14 30

Email:
contact@kine-pc.fr

Address:
265 Rue du Faubourg Saint-Antoine
75011 Paris FR

Legal information:
Legal notice
Data protection / Privacy policy

Website last updated:


Opening hours last updated: