For all of us at the Henry Dunant Hospital Center, both management and staff, Quality is the highest value; it is what guides us in our goal of providing safe and comprehensive care in a welcoming environment for our patients and visitors.

All our health care services are patient-centered, so patients trust us for their safety and treatment. To build this relationship of trust, we continually work with consistency and persistence, setting as our priority:

  • to provide high quality services
  • to focus on patient safety and minimize risks, by adopting international best practices to that end
  • to invest in cutting-edge technologies
  • to constantly offer new and innovative services, diagnostic and therapeutic methods
  • to adopt international medical protocols and guidelines
    At the Henry Dunant Hospital Center, we all embrace the vision of providing continuously better and higher quality services to patients and their families, and we feel that this commitment is our high duty.

So, we offer:

  • services with a primary focus on maximum patient safety
  • effective treatments, based on scientific knowledge and guidelines
  • services delivered in a timely manner, as we strive to minimize the time needed to provide them
  • adequate and appropriate services, making the best use of our resources, technology, diagnostic tools and treatment methods
  • patient-centered health services that take into account the patient’s expectations, wishes and needs
    At the Henry Dunant Hospital Center, we apply procedures and protocols based on scientific evidence, with up-to-date and evidence-based knowledge. For us, Quality is not an intangible, but a fully measurable concept, the evaluation of which is done with tangible results, with indicators that assess and certify its degree, while at the same time being the guide for continuous, perpetual improvement. Which continuous improvement is our main objective that runs through the entire range of our operations and activities.

The objective of continuous improvement is achieved by:

  • complying with the applicable laws and regulations which govern our operation
  • strictly complying with the regulatory framework concerning the protection of our patients’ personal data
  • recording and correctly implementing procedures for all our activities
  • establishing control, supervision and feedback mechanisms for all areas of our operation
  • Analyzing measurable results and continuously aiming at improving these results
  • measuring the experience of our patients
  • providing continuous training of all our medical, nursing and administrative staff
  • creating the right working environment for employee development, better performance, evaluation and reward.
    Our tools for all the above are compliance and adherence to the most modern Quality Management Systems, harmonized with international standards:
  • Joint Commission International – Hospital Accreditation Standard
  • ISO 9001 – Quality Management System
  • ELOT EN 15224 – Quality Management System for Health Care
  • Center of Excellence in Hernia Surgery, Surgical Review Corporation
    The monitoring and control of the implementation of the Quality Policy is carried out through the operation of Committees across the entire range of services provided by the Henry Dunant Hospital Center.

To achieve the above, the Management of the Henry Dunant Hospital Center is committed to ensuring that the Quality Policy is understood, implemented, and adhered to at all levels of its organization.

INTRODUCTION

The Henry Dunant Hospital Center (HDHC), in order to fulfill its purpose of providing high quality medical and nursing services, processes personal data of its patients, both simple and sensitive, such as health data, in compliance with both the Code of Medical Ethics and the broader legislative and regulatory framework, including Regulation 679/2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the Regulation), as well as the relevant decisions of the Personal Data Protection Authority (the Authority). In addition, it processes data of its employees, partners, and suppliers and all those who have transactions with it, browse its website, subscribe to its newsletters or training seminars, etc.

THE POLICY

With this Policy, HDHC sets out and discloses the conditions under which it collects, maintains and uses personal data information in paper and/or electronic form, i.e., it acts as a Data Controller (see definition below).

This Privacy Policy also describes how we use, disclose, and protect your personal data, how you can exercise your rights in relation to your personal data, and how you can contact us, and complies with the terms of European Regulation 679/2016 and any other relevant applicable legislation.

The recipients of the data are the subjects themselves, their family members in case of physical incapacity, the persons authorized by them, the social insurance funds insofar as the provision of the data is necessary for insurance coverage, public authorities following a public prosecutor’s decision, and ministries for the purpose of statistical processing, as well as any others expressly described by law.

Finally, with this Personal Data Protection Policy, HDHC assures you of its commitment to keeping the information provided to it confidential and secure, thus ensuring privacy, to maintain a processing record for all its activities, both primary and ancillary to its purposes, to continuously train its staff on data protection, clean office policy, respect for privacy and confidentiality, to adopt policies such as this and the Information Security Policy, to work exclusively with individuals and companies who are equally committed to the principles of personal data protection and who take appropriate measures to protect them and, finally, to process your personal data, whether simple or health-related, with respect and a high sense of responsibility.

PERSONAL DATA AND OTHER DEFINITIONS

The following definitions, as described in the Regulation, will help you to better understand this Policy.

“Personal Data”: any information relating to an identified or identifiable natural person (”data subject”); an identifiable natural person is one whose identity can be established, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, psychological, economic, cultural or social identity of that natural person,

“health-related data”: personal data related to the physical or mental health of a natural person, including the provision of health care services, a including the provision of health care services, which reveal information about his or her health status;

“processing”: “any operation or set of operations performed with or without the aid of automated processes and applied to personal data or set of personal data, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, comparison or interconnection, restriction, erasure or destruction”;

“controller”: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data;

“processor”: the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;

“Consent” of the data subject: any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

DATA CONTROLLER

According to the definition above, the Data Controller shall be the Single Person S.A. by the name “IMITHEA MONOPROSOPI ANONYMI ETAIREIA EKMETALLEFSIS NOSILEFTIKON MONADON KAI IATRIKON DIAGNOSTIKON KENTRON KAI PAROCHIS SYNAFON YPIRESION” (translated in English as “IMITHEA NURSING UNITS AND MEDICAL – DIAGNOSTIC CENTERS OPERATION AND KINDRED SERVICES PROVIDING SINGLE PERSON S.A.”) and the distinctive title “IMITHEA M.A.E.” (translated in English as “IMITHEA Single Person S.A.”), headquartered in Athens, 107, Mesogeion Avenue, Tax registration No 998936357, General Commercial Registry (GEMI) No: 006502201000, Single Person S.A. Reg. No: 59294/001/Β/05/0422, which operates at the above address the “HENRY DUNANT HOSPITAL CENTER” private clinic that provides medical services.

HDHC’s PRINCIPLES OF PERSONAL DATA PROCESSING

As Data Controller, HDHC processes the personal data of its patients, employees, and collaborators as well as the health data of its patients, respecting the principles that, according to the Personal Data Protection Regulation, must govern the processing. So:

(a) collected data are processed lawfully, fairly and in a transparent manner,

(b) data are collected for specified, explicit and legitimate purposes;

(c) the data processed are adequate and relevant to the purposes of the processing;

(d) they are accurate and, where necessary, kept up to date;

(e) data are kept and stored only for as long as required by the legal framework,

(f) all necessary and appropriate technical and organizational measures are taken to ensure their security.

DATA WE PROCESS

(a) Patient data:

Simple Personal Data: first name, surname, date of birth, home address, e-mail address, occupation, ID card number, social security number, social security number (AMKA), tax identification number (AFM), insurance carrier, contact telephone numbers, etc.

Health data: Data relating to the state of health of its patients, as they result from obtaining their medical history, during admission and the course of their hospitalization, from the consents to medical procedures and from the results of diagnostic and clinical tests carried out in the context of the provision of medical services.

(b) Employees/external collaborators: personal and other data (health data e.g., to justify sick leave, data on the children of an employee in order for him to receive benefits, etc.) necessary for the fulfilment of HDHC’s legal obligations towards its employees (salaried and external collaborators) in accordance with the labor and insurance legislation.

(c) Partners/suppliers: the necessary personal data of company representatives and employees are processed for the handling of HDHC’s commercial relations with partner companies (pharmaceutical, biotechnology equipment companies, suppliers, etc.) for its operation, and the fulfilment of its purposes.

(d) Finally, we process the personal data of all those who contact us either to subscribe to our newsletter or to obtain a privileged card, to look for a job by sending us a CV, to contact us through the online form on our website or finally to browse our website by accepting cookies. For all this, HDHC has specific procedures and policies that ensure both that the data it processes are kept secure and only for the period specified by law or its procedures.

RETENTION PERIOD OF YOUR DATA

We inform you that HDHC is obliged to keep your Medical Record in its Medical Records Archive for twenty (20) years (in application of our legal obligation under L. 3418/2005), from each of your hospitalizations as well as from the need to preserve your life, your health and to provide the appropriate treatment. Outpatient data are kept in our Archive for 20 years, while purely accounting-tax records must be kept for 5 years.

The contents of a Medical Record comprise any data related to your health as well as the personal data that you have provided to us for the execution of the contract for the provision of medical services between us.

If the time limits change, we will inform you of any change.
The data we receive through our website to make an appointment are kept secure in our computer system and are integrated in the medical records that we keep in the Archive as above.

After the mandatory data retention period has expired, HDHC shall destroy the data following the instructions of the Authority and its own procedures and protocols, in accordance with the applicable regulatory framework and JCI accreditation.

TRANSFER OF PERSONAL DATA TO THIRD PARTIES

HDHC may transfer (by electronic and natural means), in performance of a legal obligation your personal and sensitive personal data concerning your hospitalization to your insurance company and its Auditors, to cover and reimburse you for your medical expenses, in combination with your health coverage.

HDHC may also transfer (by electronic and natural means), in performance of a legal obligation your personal and sensitive personal data concerning your hospitalization to your insurance company and its Auditors, to cover and reimburse you for your medical expenses, in combination with your health coverage.

HDHC’s financial services (Inpatient Accounting Office, Outpatients Accounting Office, Laboratory Cashier’s Office, Submission Department, Central Accounting Office) are required to process your simple personal data (referring physician) or limited health data (for instance: type of surgery, type of diagnostic test) in order to issue the legal document for the payment of the medical services we provide to you and to satisfy our legitimate business interest and our legal tax obligation.

Finally, to pursue our legal claims we may transfer limited personal data to legal firms with whom we work or to individual lawyers/associates of ours.

SECURITY OF PERSONAL DATA

HDHC uses the appropriate technical and organizational protection measures to ensure that the personal data you entrust to us is secure, whether stored in physical form or electronically.

When HDHC assigns to a third party as processor (including our service providers) to collect or process personal data on our behalf, such processor is carefully selected based on its know-how, reliability and available resources as well as based on the technical and organizational security measures it takes to secure the processing, according to the specifications set by the General Regulation of Data Protection.

RIGHTS OF NATURAL PERSONS WITH REGARD TO THEIR PERSONAL DATA

You have the following rights in relation to your personal data:

Right to revoke your consent: as the case may be, you have the right to revoke your consent at any time without prejudice to the lawfulness of any processing carried out with your consent prior to its revocation.

Right to access, rectification, and erasure: you have the right to request access to any of your personal data that we may hold, to request that any inaccurate data about you be rectified and, in certain cases, to request the erasure of your personal data. You may request the deletion of your health data because, by law, we are obliged to keep it for 20 years.

Right of data portability: under certain conditions, you have the right get the personal data you have provided to us in a structured, widely used and machine-readable format as well as to request that we transfer it to another controller where technically feasible. For example, you can contact us to send a Medical Record or diagnostic tests to another clinic or hospital by any available means.

Right to restrict processing: you have the right to restrict our processing of your personal data if:

you question the accuracy of such personal data until we have taken the necessary steps to correct or verify its accuracy;
you think such processing is illegal, but you do not want us to erase the data;
we no longer need your personal data for processing purposes, but you need same data to establish, pursue or defend legal claims; or

you have objected to the processing for reasons of legitimate interest (see below), pending verification as to whether we have compelling legitimate grounds to continue the processing.

Where personal data is subject to such restrictions, we will process it solely with your consent or for the establishment, exercise, or defense of legal claims.

Right to object to processing: as long as the conditions set by law are met, you have the right to object to the processing of your personal data. If you object to it, we will have to discontinue the processing, unless we can demonstrate compelling legitimate grounds for processing which override your interests, rights and freedoms or where we need to process the data for the establishment, exercise or defense of legal claims.

If you consider that the processing of your personal data violates the applicable law, you have the right to file a complaint to:

Hellenic Authority for the Protection of Personal Data,
1-3 Kifissias Avenue, 115 23, Athens, Greece
Telephone: +30-210 6475600
Fax: +30-210 6475628
E-mail: contact@dpa.gr

THE DATA PROTECTION OFFICER

For more information regarding the exercise of your rights or for any question regarding the processing of your personal data, please contact our Data Protection Officer we have appointed in accordance with the Regulation at dpo@dunant.gr and we will respond to your request within the applicable time frames.

The Data Protection Officer will respond to your request without delay, and in any case within one (1) month of receiving it. However, if the request is complex, he will inform you within the month of the necessity to extend the time to respond by a further (2) two months, within which he will reply.

CHANGES TO THE PERSONAL DATA PROTECTION POLICY

We regularly review this Policy and reserve the right to review and make changes to it to include any changes to our business activities, to the legal requirements and how we process your personal data.

Whenever we take those actions, we will notify you through our website or upon your arrival at HDHC.

In any case, we encourage you to check this Policy from time to time for possible changes so that you are informed in time.

  1. Data Processors
    The data processor is the Imithea Medical Group, comprised of:
    • the company by the name “IMITHEA SINGLE MEMBER SOCIETE ANONYME EXPLOITING NURSING UNITS AND MEDICAL- DIAGNOSTIC CENTERS AND RELATED SERVICES PROVIDING” and distinctive title: “IMITHEA SINGLE MEMBER S.A.”, headquartered in Athens, 107, Mesogeion Avenue, Tax registration No 998936357, General Commercial Registry (GEMI) No: 006502201000, S.A.
    • the company by the name “NextHealth S.A.” and distinctive title: “NextHealth”, headquartered in Athens, Mesogeion Avenue 109-111, Tax registration No. 802842446,
    • the company by the name “MEDICAL SUPPLIES & SERVICES SINGLE MEMBER PRIVATE COMPANY» and distinctive title: “MEDISS SMPC”, headquartered in Athens, Mesogeion Avenue 109-111, Tax registration No. 801411255,

  2. Purpose and legal justification of data processing
    The purpose of the Imithea Medical Group is to provide private healthcare services to its clients and to fulfill its purpose, it processes personal data. The Company has a legal obligation to protect the equipment necessary for its operation, its information systems and networks, and anything else that must be included in this purpose. Thus, it operates on a 24-hour basis and throughout the year, a closed circuit video surveillance system, in accordance with the principles of legality, necessity, proportionality and data minimization, as provided for in the GDPR, but also in Directive 1/2011 of the Personal Data Protection Authority (the Authority) and in all relevant opinions and instructions of the Authority.

  3. Processing security and protection
    • Video surveillance is limited, as far as possible, to the areas absolutely necessary for its purposes.
    • The cameras focus on goods and infrastructures critical to the operation of the Company.
    • No further processing is carried out on the data collected.
    • The closed circuit is not used for the surveillance or monitoring of employees in their workplaces, nor for the evaluation of the behavior and efficiency of personnel.
    • The circuit does not receive images from external public spaces, sidewalks or entrances of neighboring buildings.
    • The circuit does not receive images from areas where there are increased expectations for the privacy of individuals (toilet areas and lobbies, changing rooms, etc.).
    • The cameras have a fixed viewing angle and do not have a rotation mechanism.
    • They record exclusively images and not sound.
    • The circuit is autonomous and is not connected to the internet, nor to the Company’s central network (secure communication circuit), and the monitoring screens are located in a special secure area.
    • Access to video surveillance data is strictly limited to a small number of authorized and specially trained operators, while access to the area is via access control and a special security lock. There is a fire extinguishing system in the Control Unit.
    • Authorized personnel ensure:
    ▪ the security of the videotaped material,
    ▪ the control of access to the Control, storage and processing Unit,
    ▪ the operation of the projection screens and software,
    ▪ the continuous training of personnel on personal data protection issues and compliance with personal data protection procedures,
    ▪ the information of natural persons/data subjects before they enter the range of the video surveillance system by posting clearly visible information signs, which indicate the controller, the purpose and the method of communication of interested parties for the exercise of their rights.

  4. Data transfers to third parties
    The data of the video footage is not disclosed or transmitted to third parties. An exception is the transmission/communication of the data in the following cases: a) to the competent judicial, prosecutorial and police authorities when it includes data necessary for the investigation of a criminal act, which concerns persons or goods of the controller, b) to the competent judicial, prosecutorial and police authorities, when they lawfully request data in the exercise of their duties, and c) to the victim or perpetrator of a criminal act, when it concerns data that may constitute evidence for the commission of the act.

  5. Storage Period
    Each recorder has its own internal storage space and automatically deletes the stored data every 15 days, in accordance with the Authority’s instructions, except for the exceptions expressly provided for by the Directive, namely in the event of an incident against goods or persons of Imithea Medical Group, the files are kept separately for 30 days and in the event of an incident against goods or persons of a third party, the storage time of the video surveillance material is extended to 3 months.

  6. Data subjects’ rights
    Individuals/data subjects may exercise the rights provided for in the GDPR by sending an email to dpofficer@imitheamg.gr. Requests to exercise rights are reviewed and responded to within the deadline set by the GDPR.


    6.1. Right to be informed
    Data subjects entering the range of the video surveillance system are informed by clearly visible signs in visible places. The signs inform that the area is monitored by closed circuit video surveillance, the details of the Data Controller, the purpose of the processing and the way in which interested parties can obtain more information and exercise their rights. Data subjects receive additional information through this document, which is posted on the Imithea Medical Group website as well as in visible places on its premises.


    6.2. Right to access
    Data subjects entering the premises of Imithea Medical Group have the right to access the video surveillance system data that concerns them, by submitting a relevant request, which must include the date and exact time they were within the range of the system’s cameras, the specific area, as well as a recent good quality photograph.


    6.3. Right to objection and/or erasure
    Data subjects have the right to object to the processing of their image by the video surveillance system and to request the deletion of their data. However, the exercise of this right (objection or deletion) does not entail the immediate deletion of data or the modification of the processing but is subject to a review of its legality.


    6.4. Right to restriction of the processing
    Data subjects have the right to request the restriction of processing, such as for example not to delete data concerning them that they consider necessary for the establishment, exercise or support of legal claims.

  7. Right to submit a complaint
    In case the subjects consider that the processing of data concerning them violates Regulation 2016/679, they have the right to appeal to the competent supervisory authority and file a complaint. The competent supervisory authority for Greece is the Personal Data Protection Authority and the contact details are: 1-3 Kifissias, P.C. 115 23 – Athens, https://www.dpa.gr/, tel. 210-64.75.600

Thank you very much for your interest in collaborating with the IMITHEA MEDICAL GROUP.

In compliance with the General Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data (hereinafter referred to as the “GDPR”) and Law 4624/2019, the IMITHEA MEDICAL GROUP provides prospective employees or those candidates who proceed to an interview with this information regarding the processing of their personal data.

Data Controller

Each company of the IMITHEA MEDICAL GROUP is a Data Controller of your personal data:

  • the company by the name “IMITHEA SINGLE MEMBER SOCIETE ANONYME EXPLOITING NURSING UNITS AND MEDICAL- DIAGNOSTIC CENTERS AND RELATED SERVICES PROVIDING” and distinctive title: “IMITHEA SINGLE MEMBER S.A.”, headquartered in Athens, 107, Mesogeion Avenue, Tax registration No 998936357, General Commercial Registry (GEMI) No: 006502201000, S.A. which operates at the above address the private clinic under the name “Private Clinic Henry Dunant Hospital Center”,
  • the company by the name “GENERAL CLINIC OF DODECANESE SINGLE MEMBER SOCIETE ANONYME” and distinctive title: “GENERAL CLINIC OF RHODES”, headquartered in Rhodes in the Municipal Community of Koskinou – Municipal Unit of Kallithea, Postal Code 85150, Tax registration No 099658646,
  • the company by the name “NextHealth S.A.” and distinctive title: “NextHealth”, headquartered in Athens, Mesogeion Avenue 109-111, Tax registration No. 802842446, which operates the clinics “GENERAL CLINIC OF THESSALONIKI”, headquartered in Thessaloniki, 11 Maria Kallas street and 2 Gravias Street, “Kyanous Stavros”, headquartered in Thessaloniki, 1 Viziis street, and “GENERAL CLINIC OF KOZANI”, headquartered in Kozani, 4 M. Dimtsa Street,
  • the company by the name “GENESIS IDIOTIKI GENIKI MAIEFTIKI GYNAIKOLOGIKI KLINIKI S.A.” and distinctive title: “GENESIS S.A.”, headquartered in Pilaia Thessalonikis, end of 17th November Street, Tax registration No 094539724,
  • the company by the name “AROGI – KENTRO IATRIKIS APOTHERAPIAS KAI APOKATASTASIS SOCIETE ANONYME” and distinctive title: “AROGI THESSALONIKIS S.A.”, headquartered in Pilaia Thessalonikis, end of 17th November Street, Tax registration No. 099770726,
  •  the company by the name “MEDICAL SUPPLIES & SERVICES SINGLE MEMBER PRIVATE COMPANY» and distinctive title: “MEDISS SMPC”, headquartered in Athens, Mesogeion Avenue 109-111, Tax registration No. 801411255,

(collectively the “IMITHEA MEDICAL GROUP”). 

Data Processor:

  • The company by the name of “Workable Software Single Member Private Company”, with the distinctive title “WORKABLE” headquartered in Athens, 95-97 Leoforos Kifissias 15125 Marousi, Greece.

WHAT KIND OF PERSONAL DATA DO WE PROCESS?

The personal data we collect and process (e.g. access, storage, registration, deletion) are your identification details (e.g. name, date of birth) and your contact details (e.g. address, telephone number, email address), information regarding your professional and academic life and experience, as well as any other information you have included in your CV. We receive this personal data from you via your email, by completing the relevant submission form on our website or through the websites of job search companies with which we collaborate. If you are invited to proceed to an interview with one of our representatives, we may also collect data that will arise during your interview, but also during any assessments that our representative will carry out, who will meet with you to conduct the interview.

During the assessment of your candidacy, we may ask you to video your answers to selected assessment questions and submit the video to the job search platform (Workable) with which we collaborate. This data is processed by authorized employees of the Human Resources Department solely for the purposes of assessing your candidacy and is stored exclusively on the servers of the job search platform for 2 years in accordance with the Group’s personal data retention policy.

The processing of this data takes place by authorized employees of the Human Resources Department and the individual relevant departments (depending on your specialty) of the Group, in compliance with all necessary technical and organizational measures that have been taken for the security, confidentiality and ensuring the integrity and availability of the data that is processed and with the exclusive purpose of evaluating your qualifications for the position or positions for which you are interested or for another potential position within the Group or within one of the companies or clinics of the Group, provided that you have declared when submitting your application that you wish to be informed about other potential positions within the Group, as well as to have your CV available to the other clinics or companies of the Group, for the purposes of staffing them with appropriate personnel.

WHAT ARE THE PURPOSES AND LEGAL BASES OF THE PROCESSING OF YOUR DATA?

The purposes and legal bases of the processing of your personal data by each company of the Group are as follows:

(a) The satisfaction of the legitimate interest of each company of the Group, for the appropriate and comprehensive evaluation and final selection of the candidate to fill the respective positions.

(b) Your consent in relation to the expression of interest in cooperation.

HOW LONG DO WE KEEP YOUR DATA?

If you are not hired, we will keep your personal data for a period of two (2) years, for evaluation in future job positions that may interest you. After this period, your data will be permanently deleted, in a secure and unrecoverable manner. If you are hired, we will keep your data for as long as required by applicable law. We keep your personal data in a physical and/or electronic file, and we take strict technical and organizational security measures to protect your data from unlawful processing, accidental or unlawful destruction, accidental loss, alteration, prohibited dissemination or access, and any other form of unlawful processing, as well as to prevent access to them by unauthorized persons, in accordance with the provisions of applicable law.

WHO ARE THE RECIPIENTS OF YOUR DATA?

The recipients of your data are the employees of the Human Resources Department and the individual relevant departments of the Group and the employees/executives of the Group who are responsible for the screening and evaluation of the submitted CVs, and companies collaborating with the Group that operate job search websites, if you have submitted an application through them, who comply with the necessary measures to protect your personal data. If, when submitting your application, you declare that you wish your CV to be available for other positions in companies of the IMITHEA MEDICAL GROUP, your personal data may be transferred to these companies, within the framework of the legitimate interest of the Group to meet staffing needs and in particular for the purposes of evaluating and maintaining a relevant file of candidate employees. We do not transfer your personal data to third countries outside the EU.

WHAT RIGHTS DO YOU HAVE REGARDING THE PROCESSING OF YOUR DATA AND HOW CAN YOU EXERCISE THEM?

You have the right to access the personal data we hold about you at any time. Furthermore, you have the right to information, to withdraw your consent, to request the correction of your personal data, as well as to exercise the right to erasure, the right to restriction of processing, the right to data portability and the right to object to the processing thereof, by submitting a relevant request to the relevant Data Protection Officer:

• for Private Clinic Henry Dunant Hospital Center, please contact dpo@dunant.gr

• for the other companies of the Group, please contact dpofficer@imitheamg.gr

Finally, you have the right to file a complaint with the Greek Data Protection Authority (www.dpa.gr), in the event of a breach of your personal data.

UPDATE OR MODIFICATION OF THIS NOTICE.

We reserve the right to unilaterally modify or update or revise this privacy notice at any time, without prior notice to you, in order to comply with applicable EU and national legislation on the protection of personal data. That is, we may publish more specific terms regarding the collection and processing of personal data, which will supplement this notice and form an integral part thereof.

Last updated: July 2026