For the purposes of its activity as a clinic for dental medicine and as an
entrepreneur AIPPDP Nurident EOOD (Ambulatory for Individual Practice for Primary
(Outpatient) Medical Care Nurident Solely-owned Limited Liability Company) processes
personal data of individuals in strict compliance with Regulation (EU) 2016/679, the
Personal Data Protection Act and the normative acts in the sphere of healthcare.
The following definitions are used in this Policy:
“personal data” – any information or set of information that identifies you or could be
used for your identification;
“health data” – personal data related to the physical and mental health of the
individual. These data are protected considering of their sensitive nature and are
processed by medical professionals bound by a professional secrecy obligation;
“data controller” – is the person determining the purposes for which and the manner in
which personal data is processed;
“data processor” – is the person processing personal data on behalf of the controller.
The Privacy policy provides information about:
 Who the data controller is
 The personal data of which natural persons are processed by the company
 For what purposes and on legal grounds the personal data are processed
 The terms for storing personal data
 The preventive measures for the protection of personal data
 The rights of the data subjects and the means for their exercising
1. Personal data controller
The personal data controller is AIDPDP Nurident EOOD (Ambulatory for Individual
Practice for Primary (Outpatient) Medical Care Nurident Solely-owned Limited Liability
Company), with UIC (Unified Identification Code): 201728658, having its principal office
and address of management: city of Sofia, Lozenets municipal district, Lozenets
residential district, 52 Zlatovrah Street, Tel. +359 887 770 703.

2. Natural persons whose personal data are processed by the company
AIDPDP Nurident EOOD Ambulatory for Individual Practice for Primary (Outpatient)
Medical Care Nurident Solely-owned Limited Liability Company)”processes the personal
data of the following natural persons:
– Patients, and where necessary – their relatives;
– Personnel – current and former employees of the company, applicants and
trainees;
– Visitors of the dental clinic;
– Contractors or potential contractors of the company and their employees;
* The Listed groups of individuals may or may not be citizens of EU member
countries.
3. Categories of processed personal data
– physical identity: names, PIN, address, passport data (except copies under the
Personal Documents of Bulgarian Citizens Act), place of birth, telephone;
– social identity: education, occupational history;
– family identity: marital status, relatives;
– economical identity: accounts for transfer of salaries;
– health status: card for preliminary medical examination, information from sick
leaves, expert decisions TEMC, conclusion about the suitability of the employee
to perform the respective position from the servicing OMS;
4. Purposes of the processing
The company processes personal data for the following purposes:
– nationality of the individual (these personal data are collected in order to verify
the person's legal right to work);
– education of the individual (type of education, place, number and date of issuing
of the diploma). The data are necessary to comply with statutory requirements for
employment or termination of the employment for certain positions by the
individuals, as well as for other purposes related to human resources
management, such as employees’ participation in further training/qualification
and professional development programs;

– providing dental services – diagnostics, treatment, clinical studies, etc.;
– execution of a legal obligations of the company;
– fulfilment of the requirements of the labour and social legislation concerning the
employees;
– ensuring the security of patients, employees and property through video
surveillance, access control;
– other legitimate purposes such as accounting services, maintenance and security
of the company's web site and IT systems, protection of the legal interests of the
company, including through legal cases;

5. Legal grounds for processing
The company processes personal data under the following legal grounds:
– provision of dental services
– for the purposes of the occupational medicine, for assessing the employee's
capacity to work, for medical diagnosis, for the provision of care and treatment
– in case of data subject consent for one or more specific purposes
– when receiving CVs, motivation letters, recommendations of future
employees
– conclusion and execution of contracts
6. Transfer of personal data to third parties
The personal data of the natural persons listed in clause 2 are transferred to the
following third parties:
– competent public authorities in order to comply with legal requirements;
– accounting companies;
– occupational medicine services;
– external IT company;
In all these cases, AIPPDP Nurident EOOD (Ambulatory for Individual Practice for
Primary (Outpatient) Medical Care Nurident Solely-owned Limited Liability Company)
takes the necessary measures to protect the rights and the interests of the data

subjects, such as assuming explicit contractual obligations from the personal data
processors to ensure the security of the personal data and their confidentiality.
7. Terms for storing personal data
The personal data of applicants for employment in the company who have not been
approved for appointment will be stored for a period of 2 years from the end of the
calendar year in which the application is submitted.
The video surveillance records are kept for 60 days, according to the Private Security
Act.
The personal data of patents are stored in health files for a period of 50 years.
The personal data of employees are stored for a period of 50 years.
The personal data of contractors are stored for a period of 11 years.
8. Measures for the protection of personal data
– access control on the territory of the clinic;
– limited access to the company's system with a personal password;
– video surveillance on the territory of the company;
– storing the documentation in a locked cabinet;
– locking the premises when leaving the workplace;
9. Data subjects' rights
All natural persons whose data is processed by AIPPDP Nurident EOOD (Ambulatory
for Individual Practice for Primary (Outpatient) Medical Care Nurident Solely-owned
Limited Liability Company) have the following rights:
– access to their personal data including to have a copy of them;
– right of rectification if the personal data is inaccurate or incomplete;
– right of erasure of the personal data;
– right for restriction of the processing – if there is a legal dispute between the
company and the individual – until its resolving or for establishing, exercising or
defending legal claims;

– right of portability of personal data concerning the data subject, which the data
subject has provided to the company, in a structured, widely used and machine
readable format;
– right to object – at any time and on grounds relating to the particular situation of
the individual provided that there are no compelling legal grounds for the
processing that take precedence over the interests, rights and freedoms of the
data subject, or during a legal case;
In accordance with the Data Protection Act, the above rights may be exercised by
submitting a written application to: city of Sofia, Lozenets municipal district, Lozenets
residential district, 52 Zlatovrah Street. Applications may also be filed electronically
under the Electronic Document and Electronic Certification Services Act. The
application is submitted personally by the data subject or by a person expressly
authorized by him/her with a power of attorney certified by a notary and a copy thereof
is submitted together with the application.
10. Supervisory authority
According to the Personal Data Protection Act and the General Regulation for Data
Protection, any individual who considers his/her right to data protection breached may
lodge a complaint at the Personal Data Protection Commission at: 1592 Sofia, 2
Professor Tsvetan Lazarov Blvd, website www.cpdp.bg