Data Treatment Policy
Data Treatment Policy
Andrade Cirugía Plástica S.A.S., identified with the NIT (Tax ID) 9014298551, with its main office located at Cra. 11D # 119-21, Bogotá, Colombia, as the responsible party for personal data, will process personal data in accordance with the principles and duties defined in Law 1581 of 2012 and other applicable and complementary regulations, which are aligned with international best practices.
The collection, storage, use, circulation, and deletion of personal data by Andrade Cirugía Plástica S.A.S. will be carried out for the following general purposes:
Conducting necessary actions for the development of the institution’s corporate purpose.
Providing healthcare services to patients and their families.
Communicating with stakeholders about health services, academic and business events, publications, and advertising related to health.
Complying with legal obligations involving personal data of stakeholders.
Fulfilling obligations arising from existing contractual relationships with stakeholders.
Proactively understanding the needs of stakeholders to innovate in service delivery.
Informing and inviting stakeholders to marketing campaigns, service promotions, academic and institutional events, and loyalty programs.
Obtaining relevant information from data analysis and combinations for decision-making in service delivery.
Managing procedures (requests, complaints, claims).
Complying with Colombian labor laws or orders issued by competent Colombian authorities.
Ensuring the safety of patients, visitors, employees, and the general public within the facilities.
Ensuring the quality and safety of care.
Informing about changes in the Data Treatment Policy.
Specific purposes of personal data treatment by Andrade Cirugía Plástica S.A.S. include, but are not limited to:
Patients:
Registration and creation of medical records, diagnostics, medical authorizations, self-care programs, service provision, patient follow-up, appointment scheduling, service billing, administrative activities, requests, collections, generating alerts, healthcare services, and medical consultations.
Contacting patients and/or users via phone, in-person, or electronic means (chat, email, phone).
Notifying about changes or improvements in services and related advertising.
Creating databases for service provision, scientific and academic research, service development, telemedicine, remote activities (promotion, prevention, diagnosis, treatment, or rehabilitation using information and communication technologies).
Conducting satisfaction surveys and evaluating the quality of products and/or services.
Archiving, updating systems, and protecting and safeguarding information and databases.
Using images in photographs or other audiovisual media (physical, digital, or virtual) for service and/or product promotion.
Other purposes required for fulfilling the institution’s objectives, in compliance with the law.
Employees:
Recruitment, selection, hiring, contract execution, and termination.
Training, educational processes, safety studies for selected candidates, payroll management, disability management, affiliation, health prevention and management activities, follow-up interviews, medical diagnostics, work-related accident or illness disabilities, occupational environmental measurements.
Managing cultural, sports, health prevention, and promotion activities.
Photography, execution, verification, and recording of internal procedures.
Participation in institutional induction or re-induction programs.
Archiving, updating systems, and protecting and safeguarding information and databases.
Historical, scientific, or statistical purposes.
All activities required to be fulfilled by Andrade Cirugía Plástica S.A.S. as an employer.
Suppliers and/or Third Parties:
Managing contracts with individuals for service provision.
Evaluating contractor skills, managing invoices for payments, and verifying service delivery.
Creating and updating supplier, creditor, and payer records.
Generating and submitting income and withholding certificates.
Accounting for supplier invoices, withholdings, and communications about informational campaigns.
Managing inquiries, complaints, claims, and procedures.
Visitor registration, academic and scientific research development.
Filing complaints, reports, or denunciations to competent authorities.
Security:
Video surveillance, security, and access control to buildings for the safety of individuals, assets, and facilities.
Other purposes required for fulfilling the institution’s objectives, in compliance with the law.
Sensitive Personal Data:
In general, Andrade Cirugía Plástica S.A.S. processes sensitive personal data when required for fulfilling its role as a healthcare provider, provided that:
The data subject has given explicit consent, except when such consent is not required by law or due to the nature of their relationship with Andrade Cirugía Plástica S.A.S.
The treatment is necessary to safeguard the vital interest of the data subject, who is physically or legally incapacitated. In such cases, legal representatives or support persons must grant authorization.
The treatment is necessary for the recognition, exercise, or defense of a right in a judicial process.
The treatment has historical, statistical, or scientific purposes. In this case, measures must be taken to suppress the identity of the data subjects.
Rights of Children and Adolescents:
In general, Andrade Cirugía Plástica S.A.S. may process personal data of children with prior authorization from their legal representatives or if the data is of a public nature. In all cases, the treatment will respect the best interests of children and adolescents and ensure the protection of their fundamental rights.
Data Treatment by Third Parties:
To fulfill its purposes, Andrade Cirugía Plástica S.A.S. may contract third-party services for its stakeholders. In such cases, the necessary information, including personal data, will be transferred to these third parties under privacy clauses that guarantee the protection of the data subjects’ privacy, proper service delivery, and compliance with legal and constitutional obligations.
Rights of Data Subjects:
Any individual whose personal data is processed by Andrade Cirugía Plástica S.A.S. has the right to:
Access their data free of charge.
Know, update, and rectify their information if it is partial, inaccurate, incomplete, fragmented, misleading, or prohibited.
Be informed about the use of their personal data.
Request proof of authorization, except when such authorization is not required by law.
File complaints with the Superintendence of Industry and Commerce (SIC) for violations of applicable regulations.
Revoke authorization and/or request data deletion, provided there is no legal or contractual obligation preventing it.
Exercise of Rights:
To exercise their rights, data subjects or those with a legitimate interest may contact the Compliance Office via email at servicio@ernestoandrade.com or by mail to Cra. 11D # 129-21, 2nd Floor, Bogotá D.C., Colombia. The following information must be provided:
Full name of the data subject and/or representative.
Identification type and number.
Contact details (physical and/or email address, phone number).
Reason(s) for the request and a brief description of the right being exercised.
Signature (if applicable).
Supporting documents (if applicable).
Copy of the data subject’s and/or representative’s ID.
Validity and Updates:
This Data Treatment Policy is effective as of August 17, 2021, and can be consulted on the official website: www.ernestoandrade.com.
Andrade Cirugía Plástica S.A.S. reserves the right to update this policy as necessary to comply with legal requirements and best practices in data protection.