Privacy Policy

  • Home
  • Privacy Policy
Privacy Policy

Privacy Policy

Cito Polyclinic ("we", "our" or "us") is committed to protecting your privacy. This Privacy Policy explains how Cito Polyclinic collects, uses and discloses your personal data.

This Privacy Policy applies to our website and its associated subdomains (collectively, our "Service") together with our Cito Polyclinic application. By accessing or using our service, you confirm that you have read, understood and consented to our collection, storage, use and disclosure of your personal data as described in this Privacy Policy and our Terms of Service.

1 Definitions and key terms

In order to explain matters in this Privacy Policy as clearly as possible, each time any of these terms is referenced, it is strictly defined as:

  • Cookie: a small amount of data generated by a website and stored by your web browser. It is used to identify your browser, provide analytics, and remember information about you such as your language preferences or login details.
  • Company: when this policy refers to “Company”, “we”, “us” or “our”, it refers to Cito Polyclinic, Moliških Hrvata 4, 21000 Split, which is responsible for your data under this Privacy Policy.
  • Country: where Cito Polyclinic or the owners/founders of Cito Polyclinic are located, in this case Croatia.
  • Customer: refers to the company, organisation or person who signs up to use the Cito Polyclinic service to manage relationships with your consumers or service users.
  • Device: any internet-connected device such as a phone, tablet, computer or any other device that can be used to visit Cito Polyclinic and use the services.
  • IP address: every device connected to the Internet is assigned a number known as an Internet Protocol (IP) address. These numbers are usually assigned in geographic blocks. An IP address can often be used to identify the location from which a device connects to the Internet.
  • Staff: refers to those individuals who are employed by Cito Polyclinic or who have a contract to perform a service on behalf of one of the parties.
  • Personal Data: any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person.
  • Service: refers to the service provided by Cito Polyclinic as described in the relative terms (if available) and on this platform.
  • Third-party service: refers to advertisers, contest sponsors, promotional and marketing partners and others who provide our content or whose products or services we think may be of interest to you.
  • Website: the Cito Polyclinic site, which can be accessed via this URL: www.cito.hr
  • You: a person or entity that is registered with Cito Polyclinic to use the Services.

2 What information do we collect?

We collect information from you when you visit our website, register on our site, place an order, subscribe to our newsletter, respond to a survey or fill in a form.

Name / Username
Telephone numbers
E-mail addresses
Postal addresses
Age

3 How do we use the information we collect?

Any of the information we collect from you may be used in one of the following ways:

To personalise your experience (your data helps us to better respond to your individual needs)
To improve our website (we continually strive to improve our website offering based on the information and feedback we receive from you)
To improve customer service (your data helps us to respond more effectively to your customer service requests and support needs)
To process transactions
To administer a contest, promotion, survey or other site feature
To send periodic e-mails

4 When does Cito Polyclinic use third-party end-user data?

Cito Polyclinic will collect end-user data necessary to provide the Cito Polyclinic services to our customers.

End users may voluntarily provide us with information they have made available on social media websites. If you provide us with any such information, we may collect publicly available information from the social media sites you have indicated. You can control how much of your information social media sites make public by visiting these sites and changing your privacy settings.

5 When does Cito Polyclinic use third-party customer data?

We receive some information from third parties when you contact us. For example, when you send us your e-mail address to express interest in becoming a Cito Polyclinic customer, we receive information from a third party that provides Cito Polyclinic with automated fraud-detection services. We also occasionally collect information that is publicly available on social media websites. You can control how much of your information social media sites make public by visiting these sites and changing your privacy settings.

6 Do we share the information we collect with third parties?

We may share the data we collect, both personal and non-personal, with third parties such as advertisers, contest sponsors, promotional and marketing partners and others who provide our content or whose products or services we think may be of interest to you. We may also share it with our current and future affiliated companies and business partners, and if we are involved in a merger, sale of assets or other business reorganisation, we may also share or transfer your personal and non-personal data to our successors in interest.

We may engage trusted third-party service providers to perform functions and provide services for us, such as hosting and maintaining our servers and website, database storage and management, e-mail management, storage marketing, credit card processing, customer service and fulfilment of orders for products and services you may purchase via the website. We are likely to share your personal data, and possibly some non-personal data, with these third parties in order to enable them to perform these services for us and for you.

7 Do we share the information we collect with third parties?

We may share portions of our log file data, including IP addresses, for analytical purposes with third parties such as web analytics partners, application developers and ad networks. If your IP address is shared, it may be used to estimate the general location and other technologies such as connection speed, whether you have visited the website in a shared location and the type of device used to visit the website. They may collect information about our advertising and what you see on the site, and then provide auditing, research and reporting for us and our advertisers. We may also disclose personal and non-personal information about you to government or law-enforcement officials or private parties as we, in our sole discretion, deem necessary or appropriate to respond to claims, legal process (including subpoenas) to protect our rights and interests or those of third parties, the safety of the public or any person, to prevent or stop any illegal, unethical or legally actionable activity, or otherwise to comply with applicable court orders, laws, rules and regulations.

8 Where and when is information collected from customers and end users?

Cito Polyclinic will collect personal data that you provide to us. We may also receive personal data about you from third parties as described above.

9 How do we use your e-mail address?

By submitting your e-mail address on this website, you consent to receiving e-mails from us. You can cancel your participation in any of these e-mail lists at any time by clicking on the opt-out link or other unsubscribe option included in the relevant e-mail. We send e-mails only to people who have authorised us to contact them, either directly or through a third party. We do not send unsolicited commercial e-mail because we hate spam as much as you do. By submitting your e-mail address you also agree to allow us to use your e-mail address for audience targeting on websites such as Facebook, where we display customised advertising to specific people who have opted in to receive communications from us. E-mail addresses submitted only through the order processing page will be used solely for the purpose of sending information and updates relating to your order. However, if you have provided us with the same e-mail address by another means, we may use it for any of the purposes set out in this Policy. Note: If at any time you wish to unsubscribe from receiving future e-mails, we include detailed unsubscribe instructions at the bottom of every e-mail.

10 How long do we keep your data?

We keep your information only so long as we need it to provide Cito Polyclinic to you and fulfil the purposes described in this policy. This is also the case for anyone with whom we share your information and who carries out services on our behalf. When we no longer need to use your information and there is no need for us to keep it to comply with our legal or regulatory obligations, we will either remove it from our systems or depersonalise it so that we cannot identify you.

11 How Do We Protect Your Information?

We implement a variety of security measures to maintain the safety of your personal data when you place an order or enter, submit or access your personal data. We offer the use of a secure server. All supplied sensitive/credit information is transmitted via Secure Socket Layer (SSL) technology and then encrypted into our payment gateway providers' database so that it may only be accessed by those authorised with special access rights to such systems, and who are required to keep the information confidential. After a transaction, your private information (credit card, social security numbers, financial details, etc.) is never kept on file. However, we cannot ensure or warrant the absolute security of any information you transmit to Cito Polyclinic or guarantee that your information on the service will not be accessed, disclosed, altered or destroyed by a breach of any of our physical, technical or managerial safeguards.

12 Can my data be transferred to other countries?

Cito Polyclinic is established in Croatia. Information collected via our website, through direct interaction with you or through the use of our support services may, from time to time, be transferred to our offices or staff, or to third parties, located anywhere in the world, and may be viewed and hosted anywhere in the world, including in countries that may not have generally applicable laws regulating the use and transfer of such data. To the fullest extent permitted by applicable law, by using any of the above, you voluntarily consent to the cross-border transfer and hosting of such information.

13 Is data collected via the Cito Polyclinic service secure?

We take precautions to protect the security of your data. We have physical, electronic and managerial procedures in place to safeguard, prevent unauthorised access to, maintain the security of, and ensure the correct use of your data. However, neither people nor security systems are infallible, including encryption systems. In addition, people may commit intentional crimes, make mistakes or fail to follow policy. Therefore, while we make reasonable efforts to protect your personal data, we cannot guarantee its absolute security. If applicable law imposes any non-disclaimable duty to protect your personal data, you agree that intentional misconduct will be the standard used to measure our compliance with that duty.

14 Can I update or correct my data?

The rights you have to request updates or corrections to data Cito Polyclinic collects depend on your relationship with Cito Polyclinic. Staff may update or correct their data as detailed in our company's internal employment policies.

Customers have the right to request restrictions on certain uses and disclosures of personal data as follows. You may contact us in order to (1) update or correct your personal data, (2) change your preferences regarding communications and other information you receive from us, or (3) delete personal data held about you in our system (subject to the following paragraph), by cancelling your account. Such updates, corrections, changes and deletions will have no effect on other data we maintain or information we have provided to third parties in accordance with this Privacy Policy prior to such update, correction, change or deletion. To protect your privacy and security, we may take reasonable steps (such as requesting a unique password) to verify your identity before granting you access to your profile or making corrections. You are responsible for maintaining the secrecy of your unique password and account information at all times.

You should be aware that it is not technologically possible to remove every record of the data you have provided to us from our system. The need to back up our systems to protect data from inadvertent loss means that a copy of your data may exist in a non-erasable form that will be difficult or impossible for us to locate. Promptly upon receipt of your request, all personal data stored in the databases we actively use and other readily searchable media will be updated, corrected, changed or deleted, as appropriate, as soon as and to the extent reasonably and technically feasible.

If you are an end user and wish to update, delete or receive any information we hold about you, you can do so by contacting the organisation of which you are a customer.

15 Staff

If you are a Cito Polyclinic employee or an applicant, we collect the information you voluntarily provide. We use the information collected for human-resources purposes in order to administer benefits to employees and to screen candidates.

You may contact us in order to (1) update or correct your data, (2) change your preferences in relation to communications and other information you receive from us, or (3) receive a record of the information we hold about you. Such updates, corrections, changes and deletions will have no effect on other data we maintain or information we have provided to third parties in accordance with this Privacy Policy prior to such update, correction, change or deletion.

16 Sale of business

We reserve the right to transfer data to a third party in the event of a sale, merger or other transfer of all or substantially all of the assets of Cito Polyclinic or any of its corporate affiliates (as defined herein), or that portion of Cito Polyclinic or any of its corporate affiliates to which the service relates, or in the event that we discontinue our business or file or have filed against us a petition in bankruptcy, reorganisation or similar proceedings, provided that the third party agrees to abide by the terms of this Privacy Policy.

17 Affiliates

We may disclose information (including personal data) about you to our corporate affiliates. For the purposes of this Privacy Policy, “Affiliate” means any person or entity that directly or indirectly controls, is controlled by Cito Polyclinic or is under common control with Cito Polyclinic, whether by ownership or otherwise. Any information relating to you that we provide to our corporate affiliates will be treated by those corporate affiliates in accordance with the terms of this Privacy Policy.

18 Governing law

This Privacy Policy is governed by the laws of Croatia, irrespective of conflict-of-laws provisions. You consent to the exclusive jurisdiction of the courts in connection with any action or dispute arising between the parties under or in connection with this Privacy Policy, except for those individuals who may have rights to bring claims under the Privacy Shield or the Swiss-US framework.

The laws of Croatia, excluding conflict-of-laws rules, govern this Agreement and your use of the website. Your use of the website may also be subject to other local, state, national or international laws.

By using Cito Polyclinic or by contacting us directly, you acknowledge that you accept this Privacy Policy. If you do not agree with this Privacy Policy, you should not engage with our websites or use our services. Continued use of the website, direct engagement with us, or following the posting of changes to this Privacy Policy that do not significantly affect the use or disclosure of your personal data, will mean that you accept those changes.

19 Your consent

We have updated our Privacy Policy in order to provide you with full transparency about what is set up when you visit our site and how it is used. By using our website, registering an account or making a purchase, you hereby agree to our Privacy Policy and consent to its terms.

20 Links to other websites

These Terms and Conditions apply only to the Services. The Services may contain links to other websites that Cito Polyclinic does not operate or control. We are not responsible for the content, accuracy or opinions expressed on such websites, and we do not investigate, monitor or check the accuracy or completeness of such sites. Please note that our Terms and Conditions no longer apply when you use a link to navigate from the Services to another website. Your browsing and interaction on any other website, including those linked from our platform, is subject to the rules and policies of that website. Such third parties may use their own cookies or other methods to collect data about you.

21 Cookies

Cito Polyclinic uses "cookies" to identify areas of our website that you have visited. A cookie is a small piece of data that your web browser stores on your computer or mobile device. We use cookies to enhance the performance and functionality of our website, but they are not essential to its use. However, without these cookies, certain features such as videos may become unavailable or you may have to enter your login details every time you visit the website because we would not be able to remember that you had previously logged in. Most web browsers can be set to disable the use of cookies. However, if you disable cookies, you may not be able to access functionality on our website correctly or at all. We never place personal data in cookies.

22 Blocking and disabling cookies and similar technologies

Wherever you are located, you may also set your browser to block cookies and similar technologies, but this action may block our essential cookies and prevent our website from functioning correctly, and you may not be able to fully use all of its features and services. You should also be aware that you may also lose some saved data (e.g. saved login details, site preferences) if you block cookies in your browser. Different browsers offer you different controls. Disabling a cookie or category of cookies does not delete the cookie from your browser; you will need to do that yourself from your browser. You should visit your browser's help menu for further information.

23 Remarketing services

We use remarketing services. What is remarketing? In digital marketing, remarketing (or retargeting) is the practice of serving advertisements online to people who have already visited your website. It allows your company to appear to "follow" people across the internet by serving advertisements on the websites and platforms they use most often.

24 Children's privacy

We do not address anyone under the age of 13. We do not knowingly collect personal data from anyone under the age of 13. If you are a parent or guardian and you become aware that your child has provided us with personal data, please contact us. If we become aware that we have collected personal data from anyone under the age of 13 without verification of parental consent, we take steps to remove that data from our servers.

25 Changes to our privacy policy

We may change our service and policies, and we may need to make changes to this Privacy Policy so that it accurately reflects our service and policies. Unless otherwise required by law, we will notify you (for example, through our service) before we make changes to this Privacy Policy and give you the opportunity to review them before they take effect. Then, if you continue to use the Service, you will be bound by the updated Privacy Policy. If you do not wish to consent to this or any updated Privacy Policy, you may delete your account.

26 Third-party services

We may display, include or make available third-party content (including data, information, applications and other product services) or provide links to third-party websites or services (“Third-Party Services”).

You acknowledge and agree that Cito Polyclinic shall not be responsible for any Third-Party Services, including their accuracy, completeness, timeliness, validity, copyright compliance, legality, decency, quality or any other aspect. Cito Polyclinic does not assume and shall have no liability or responsibility to you or any other person or entity for any Third-Party Services.

Third-Party Services and links thereto are provided solely as a convenience to you and you access and use them entirely at your own risk and subject to the terms and conditions of such third parties.

27 Tracking technologies

Google Maps API: The Google Maps API is a robust tool that can be used to create a custom map, a searchable map, check-in features, display synced live location data, plan routes or create a mashup, just to name a few.
The Google Maps API may collect information from you and from your device for security purposes.
Google Maps API collects information that is held in accordance with its Privacy Policy
We use cookies to enhance the performance and functionality of our $platform, but they are not essential to its use. However, without these cookies, certain features such as videos may become unavailable or you may have to enter your login details every time you visit the $platform because we would not be able to remember that you had previously logged in.

28 Information about the General Data Protection Regulation (GDPR)

We may collect and use information from you if you are in the European Economic Area (EEA), and in this section of our privacy policy we will explain how and why this data is collected and how we keep this data protected from replication or misuse.

29 What is the GDPR?

The GDPR is an EU-wide privacy and data protection law that regulates how companies protect EU residents' data and enhances the control that EU residents have over their personal data.

The GDPR is relevant to all global companies, not just companies based in the EU and EU residents. Our customers' data is important regardless of where they are located, which is why we have implemented GDPR controls as our baseline standard for all our operations around the world.

30 What is personal data?

Any data that relates to an identifiable or identified person. The GDPR covers a broad spectrum of information that can be used alone or in combination with other information to identify a person. Personal data goes beyond a person's name or e-mail address. Some examples include financial information, political opinions, genetic data, biometric data, IP addresses, physical address, sexual orientation and ethnicity.

The data protection principles include requirements such as:

Personal data collected must be processed in a fair, lawful and transparent manner and should only be used in a way that a person would reasonably expect.
Personal data should only be collected for the purpose of fulfilling a specific purpose and should only be used for that purpose.
Organisations must state why they need the personal data when they collect it.
Personal data must not be kept for longer than is necessary to fulfil its purpose.
People covered by the GDPR have the right to access their own personal data. They can also request a copy of their data and updates to, erasure, restriction or transfer of their data to another organisation.

31 Why is the GDPR important?

The GDPR adds some new requirements regarding how companies should protect the personal data of individuals that they collect and process. It also raises the stakes for compliance by increasing enforcement and imposing higher fines for breach. Beyond these facts, it is simply the right thing to do. At Cito Polyclinic, we firmly believe that the privacy of your data is very important, and we already have strong security and privacy protection practices in place that go beyond the requirements of this new regulation.

32 Rights of the individual — data access, transfer and erasure

We are committed to helping our customers meet the GDPR's data subject rights requirements. Cito Polyclinic processes or stores all personal data with fully vetted, DPA-compliant providers. We retain all conversations and personal data for up to 6 years unless your account is deleted. In such a case, we dispose of all data in accordance with our Terms of Service and Privacy Policy, but we will not keep it for longer than 60 days.

We recognise that if you work with EU customers, you must enable them to access, update, retrieve and remove personal data. We have you covered! From the very beginning we have been set up as self-service and we have always given you access to your data and your customers' data. Our customer support team is here to answer any questions you have about working with the API.

33 Contact us

Do not hesitate to contact us if you have any questions.
Via Email: poliklinika@cito.hr