Privacy Policy
Last updated: 20.01.2026
§1. General provisions
1. The controller of personal data provided via the website www.health4you.eu is Instytut Medycyny Innowacyjnej with its registered office in Kraków, address: Zablocie 25 lok 4, 30-701 Kraków, Poland, VAT ID (NIP): 6793103375, REGON: [To be completed], hereinafter referred to as the "Controller".
2. Data protection contact: dane.osobowe@health4you.eu.
3. The Service collects personal data voluntarily, except in situations specified in §2.
4. Data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), the Polish Personal Data Protection Act and the Act on Provision of Electronic Services.
§2. Scope and purpose of data processing
1. For users browsing the Service (without registration):
We process data in the form of cookies and similar technologies to ensure proper operation of the Service, analyse traffic and tailor marketing content (§3).
2. For users registering in the Service:
Processing purposes: Enabling access to restricted content (e.g. detailed materials on the PVHC model), account management, communication for informational and marketing purposes of the Controller, and potential preparation of a cooperation/licensing offer.
Data categories: email address, first and last name, institution/company name, job title, phone number (optional), activity history in the Service (access to materials, downloads).
Legal basis: Art. 6(1)(b) GDPR (performance of an electronic service contract – account access) and Art. 6(1)(f) GDPR (legitimate interest of the Controller in direct marketing of its own services).
3. For users submitting commercial enquiries:
Processing purposes: Preparing an offer, contact regarding cooperation, analysis of client needs, preparation of a cooperation proposal (licence/franchise).
Data categories: first and last name, email address, phone number (optional), company/institution name, job title, description of business needs, IP address, browser user agent.
Legal basis: Art. 6(1)(b) GDPR (preparation for entering into a contract – commercial offer) and Art. 6(1)(f) GDPR (legitimate interest of the Controller in developing business activity).
Retention period: Data from commercial enquiries is stored for 5 years from the date of submission or until consent is withdrawn (in the case of marketing consent). After this period, data is anonymised or deleted.
4. For users contacting us regarding cooperation:
Data voluntarily provided in the contact form or correspondence (including CV) is processed for the purpose of initiating and conducting discussions on potential cooperation, franchise or licence, on the basis of Art. 6(1)(b) GDPR (preparation for entering into a contract).
5. For NDA (Non-Disclosure Agreement) signatories:
Data processing is carried out on the basis of a separate, detailed information clause attached to the Non-Disclosure Agreement (NDA).
§3. Cookies
1. The Service uses cookies for the following purposes:
- Essential: ensuring proper website operation (e.g. login).
- Analytics/Performance: we do not currently use analytics tools (e.g. Google Analytics). If we introduce them in the future, we will inform users and request consent.
- Functional: remembering user settings.
- Marketing/Targeting: displaying personalised advertising content (e.g. via LinkedIn/Facebook pixel).
2. The first visit to the Service involves displaying a cookie management banner, where the user can express preferences. These can be changed at any time in cookie settings or via the browser.
3. Detailed information about cookies is available in the Cookie Policy.
§4. Data recipients and transfers outside the EU
1. Data may be entrusted to processors (IT service providers, analytics and marketing tool providers) on the basis of data processing agreements.
2. Data from analytics tools (Google) may be transferred to the USA based on appropriate legal mechanisms (Standard Contractual Clauses). Details: Google Privacy Policy.
3. Data is not transferred to other recipients unless required by law.
§5. Data retention period
- User account data is stored for as long as the account exists. The user may delete it at any time.
- Contact form data – for the period necessary to handle the enquiry, no longer than 3 years.
- Commercial enquiry (RFP) data – for 5 years from the date of submission, enabling tax settlements and potential claims.
- Data related to potential cooperation (after expressing interest) – for the limitation period for claims (usually 3 years), unless the user consents to longer marketing.
- Cookies are stored according to their lifecycle (session or persistent), no longer than 24 months.
§6. User rights
You have the right to: access data, rectification, erasure, restriction of processing, objection (in particular to direct marketing), data portability, and to lodge a complaint with the President of the Personal Data Protection Office (UODO).
§7. Final provisions
The Policy may be amended. Registered users will be notified of material changes by email.