Privacy Policy
Please read the rules on how we collect, use, and protect your personal information on our website.
1. General Provisions
The Municipal Non-Profit Enterprise 'Center of Medical Rehabilitation and Palliative Care for Children' of the Zhytomyr Regional Council (hereinafter — the Center) respects the right to privacy and personal data protection of any individual visiting our website. This Privacy Policy is formulated to ensure personal data protection pursuant to the Law of Ukraine 'On Protection of Personal Data' (№ 2297-VI), Ukrainian electronic communications legislation, and additionally benchmarked against best international privacy practices (including the EU General Data Protection Regulation — GDPR) as a voluntary commitment to high data security standards.
2. Categories of Personal Data and Pediatric Health Information
We collect and process the following categories of personal data voluntarily provided by users:
- Contact & Identification Data: Full name of the legal representative (parent, guardian) or applicant, telephone number, email address, city of residence;
- Child (Patient) Details: Child's full name, date of birth, medical referral status, and electronic referral number;
- Special Category Data (Art. 7 of Law № 2297-VI, Art. 9 GDPR): Health details, pediatric rehabilitation needs, and tentative clinical diagnosis.
Legal Basis for Processing Health Data: Processing of pediatric health information is performed strictly upon the explicit informed consent of a parent or legal guardian granted via the web form, exclusively for preliminary rehabilitation planning by the multidisciplinary clinical team under strict medical confidentiality.
3. Automated Technical Telemetry and Anonymization
When browsing the website, technical telemetry is collected automatically via Cloudflare Web Analytics and Google Analytics (browser type, interface language, operating system, session duration, and pages viewed).
Technical IP Anonymization: As IP addresses are recognized identifiers under data privacy legislation, our platform employs technical IP masking. Analytical systems truncate the trailing octet of IP addresses before persistence, preventing individual re-identification.
Full IP addresses logged in Cloudflare edge network logs are processed strictly for cybersecurity operations (DDoS mitigation, bot filtration, intrusion prevention) and are never shared with advertising entities.
4. Purpose of Data Processing and Legal Effect of Form Submission
Personal data is processed exclusively for:
- arranging consultations and appointments for pediatric rehabilitation and palliative care;
- maintaining direct communication with parents and legal guardians;
- processing employment applications and volunteer registrations.
Legal Effect of Form Submission: The voluntary completion and submission of any electronic form on this site with the consent checkbox activated constitutes an explicit manifestation of intent and formal consent to personal data processing under this Policy.
5. Data Protection, Technical Processors, and Cross-Border Transfers
We implement modern administrative, organizational, and cryptographic security safeguards (HTTPS/TLS protocols, role-based access restrictions). The Center guarantees that personal data is never sold, rented, or utilized for commercial or marketing ends.
Technical Infrastructure Providers (Data Processors):
- Cloud Infrastructure & DDoS Defense: Cloudflare Inc. (USA/EU) for secure edge content delivery;
- Operational Notifications: Encrypted Telegram Bot API services and enterprise email systems (Ukr.net, Google Workspace / Gmail) for real-time alerts to Center administrative staff;
- Internal Records & Workflow: Protected Google Workspace spreadsheets and the Center's internal Medical Information System (MIS) with role-based access strictly limited to authorized clinical staff.
Lawfulness of Cross-Border Transfers (Art. 29 of Law № 2297-VI): Technical cloud platforms operate servers located in the European Economic Area (EEA), which provides an adequate level of data protection, as well as the United States. As the US lacks a general statutory adequacy decision under Ukrainian law, cross-border transfers are legitimized through appropriate compensatory safeguards — standard contractual clauses (Standard Contractual Clauses, SCC) pursuant to Article 29(3) of the Law of Ukraine 'On Protection of Personal Data' in combination with robust transport-layer encryption.
6. Cookies and Prior Consent Mechanism
In compliance with Ukrainian legislation on electronic communications and data protection, alongside European standards (ePrivacy Directive):
- Strictly Necessary (Technical) Cookies: Automatically loaded to preserve user interface theme (light/dark mode), language selections, and session security. They do not require prior consent;
- Analytical Cookies: Employed to analyze visit metrics and enhance performance. Loaded strictly following explicit user consent granted via the Cookie Banner.
You may withdraw consent or modify cookie permissions at any time within your browser preferences.
7. Personal Data Retention Periods (Data Retention)
Personal data is retained no longer than necessary to fulfill the legitimate purposes for which it was collected:
- Online Inquiries & Appointment Requests: Processed during the active communication and scheduling timeframe (up to 30 calendar days). General records of incoming inquiries are maintained in official communication logs and email archives for the current reporting year (up to 1 year) for non-profit statistical tracking;
- Patient Medical Records: Upon official admission to rehabilitation or palliative programs, records are transferred into primary medical files retained under mandatory Ministry of Health of Ukraine regulations (from 5 to 25 years depending on the statutory medical record form);
- Employment Resumes & Volunteer Questionnaires: Maintained in the internal candidate pool for up to 6 months;
- Network Security Logs: Retained for up to 90 calendar days for cyber incident auditing.
Upon expiration of statutory retention periods or receipt of a justified consent withdrawal request, records are securely deleted or irreversibly anonymized.
8. Local Cache Storage and Offline Mode (Service Worker)
To guarantee uninterrupted access to emergency contacts (103, 112), bomb shelter routes, and pediatric first-aid guidelines during power outages or network disruptions, this website utilizes Service Worker technology and browser Cache Storage. Only static, public materials from the 'Emergency Clinic Guide' are cached on-device. This system operates completely client-side, does not monitor user actions, transmits zero telemetry, and stores no personal data.
9. User Rights and Supervisory Authority
Under Article 8 of the Law of Ukraine 'On Protection of Personal Data', you have the right to access your personal data, know the sources and purposes of processing, demand rectification or erasure of inaccurate data, and withdraw consent.
Supervisory Authority & Complaints:
If you believe your data protection rights have been violated, you have the statutory right to file a formal complaint with:
- Ukrainian Parliament Commissioner for Human Rights: 01008, Kyiv, 21/8 Instytutska St.; Hotline: 1678 (toll-free across Ukraine) or +38 (044) 299-74-08 (international inquiries); Email: hotline@ombudsman.gov.ua;
- Courts of Law: In accordance with Ukrainian civil and administrative procedural law.
To submit inquiries directly to the Center, contact: info@vitrylazhyttia.com.ua.
10. Policy Modifications
The Center reserves the right to amend this Policy to comply with evolving Ukrainian legislation or technical enhancements. Modifications take effect immediately upon publication on this page with an updated revision date. In case of material changes, an informative banner will be featured on the homepage.
11. Legal Data Controller Details
The Data Controller of this web resource is:
Personal data protection operations are overseen by the Center's designated Data Protection Officer.