Privacy Policy
Find out how MedTiM collects, uses, and protects your personal data, as well as what rights you have regarding data processing.
Data Controller Information
The personal data controller, within the meaning of the applicable personal data protection regulations, is:
Special Psychiatric Hospital MedTiM
Address: Zemunska 40b, Novi Banovci, Stara Pazova
Company Registration Number: 26000718
Tax Identification Number: 112873388
Email: info@medtim.rs
Phone: +381600595255
(hereinafter: the “Controller”)
Introduction
The Controller pays special attention to the protection of users’ personal data, taking into account the sensitivity of data that may relate to health status.
This Privacy Policy regulates the manner of collection, processing, storage, and protection of personal data of website users, in accordance with the applicable regulations of the Republic of Serbia, namely the Law on Personal Data Protection of the Republic of Serbia (“Official Gazette of the RS”, No. 87/2018), the Decision on the List of Types of Processing Operations for Which a Data Protection Impact Assessment Must Be Carried Out and the Opinion of the Commissioner Must Be Requested (“Official Gazette of the RS”, No. 45/2019), the Decision Amending the Decision on the List of Types of Processing Operations for Which a Data Protection Impact Assessment Must Be Carried Out and the Opinion of the Commissioner for Information of Public Importance and Personal Data Protection Must Be Requested (“Official Gazette of the RS”, No. 112/2020), the Decision Establishing Standard Contractual Clauses (“Official Gazette of the RS”, No. 5/2020), the Rulebook on the Complaint Form (“Official Gazette of the RS”, No. 40/2019), the Rulebook on the Form and Method of Keeping Records of Data Protection Officers (“Official Gazette of the RS”, No. 40/2019), the Rulebook on the Form of Notification of a Personal Data Breach and the Method of Notifying the Commissioner for Information of Public Importance and Personal Data Protection of a Personal Data Breach (“Official Gazette of the RS”, No. 40/2019), the Rulebook on the Form and Method of Keeping Internal Records of Violations of the Law on Personal Data Protection and Measures Taken During Inspection Supervision (“Official Gazette of the RS”, No. 40/2019), and the General Data Protection Regulation (GDPR), where applicable.
By using the website, as well as by submitting data through available forms or other communication channels, you confirm that you are familiar with the content of this Privacy Policy and that you consent to the manner of data processing described herein.
Types of Data Collected
The Controller may collect the following categories of personal data:
Identification and Contact Data
- First and last name
- Email address
- Phone number
Data Provided by the User
- Content of inquiries or messages
- Experiences, comments, and statements
- Documents and files submitted by the user
Technical Data
- IP address
- Device type, operating system, and browser
- Time of access and duration of visit
- Data on pages visited
Special Categories of Data
As part of communication through the website, the user may provide data relating to their health condition.
Such data represents a special category of data within the meaning of applicable regulations and is processed exclusively:
- with the user’s explicit consent
- to the extent necessary to provide a response or service
The Controller does not intentionally collect such data, but only if the user voluntarily provides it.
Method of Data Collection
The Controller collects personal data in the following ways:
- directly from the user, by completing forms on the website
- through communication by email, phone, chat, or social media
- automatically, through technical tools and server logs
- through cookies and analytics tools
Data is collected only to the extent necessary to achieve the purpose of processing. Before collecting all required data, the Controller must ensure and obtain the written consent of the person whose data is being collected, in which all data collected from that person must be clearly and unambiguously defined. Each consent differs depending on the specific data being collected.
Purpose of Data Processing
Personal data is processed for the following purposes:
- responding to user inquiries
- providing requested information and services
- improving the quality of services and website content
- analyzing website use for statistical purposes
- ensuring system security and preventing misuse
The Controller will not use data for purposes that are not in accordance with this Privacy Policy.
Legal Basis for Processing
The processing of personal data is based on the following legal grounds:
- the user’s consent
- the performance of actions at the user’s request prior to entering into a contract or providing a service, where such actions or services must be clearly and unambiguously defined and where consent must be obtained for such data collection
- the legitimate interest of the Controller, including service improvement and system security, as well as the fulfillment of all obligations defined by the regulations specified in Section 2 of this Policy
- compliance with legal obligations in accordance with the regulations specified in Section 2 of this Policy
- In cases where the user provides data relating to their health condition, processing is based on the user’s explicit consent, in accordance with applicable regulations.
Recipients of Data (Subprocessors)
Personal data may be made available to the following categories of recipients, to the extent necessary to achieve the purpose of processing:
- hosting service providers
- providers of IT and security solutions, such as website protection systems
- analytics tools, such as Google Analytics
- social media platforms, such as Facebook and Instagram
- communication tools, such as chat applications
All subprocessors process data in accordance with applicable regulations and on the basis of appropriate contractual obligations.
The forwarding of data to subprocessors requires the clear and unambiguous written consent of the person whose data is being forwarded.
Transfer of Data Abroad
Certain data may be transferred to other countries through the use of third-party services, such as Google and Meta.
Such transfer is carried out in accordance with applicable regulations, with the application of appropriate data protection measures, including standard contractual clauses or other legally prescribed mechanisms.
The transfer of data abroad is carried out in accordance with Articles 63–72 of the Law on Personal Data Protection (“Official Gazette of the RS”, No. 87/2018).
General Principles of Transfer
Any transfer of personal data that is undergoing processing, or that is intended for further processing after being transferred to another country or an international organization, may be carried out only in accordance with the provisions of the Law on Personal Data Protection (“Official Gazette of the RS”, No. 87/2018) (hereinafter: the Law or this Law).
The Controller and the Processor shall act in accordance with the conditions prescribed by Articles 63-72 of the Law, which also include the onward transfer of personal data from another country or international organization to a third country or international organization, with the aim of ensuring an adequate level of protection for natural persons equal to the level guaranteed by this Law.
If processing is carried out by competent authorities for special purposes, the transfer of data that is undergoing processing, or that is intended for further processing after its transfer to another country or international organization, may be carried out only if all of the following conditions are met:
- the transfer is necessary for special purposes;
- the personal data is transferred to a controller in another country or international organization that is a competent authority for performing tasks for special purposes;
- the Government has established a list of countries, parts of their territories, or one or more sectors of specific activities in those countries, and international organizations that ensure an adequate level of personal data protection in accordance with Article 64 of this Law, and the data transfer is made to one of those countries, to part of its territory, to one or more sectors of a specific activity in that country, or to an international organization; or, if this is not the case, appropriate safeguards have been provided in accordance with Article 66 of this Law; or, if such safeguards have not been provided, the provisions on data transfer in special situations under Article 70 of this Law apply;
- in the event of onward transfer of personal data from another country or international organization to a third country or international organization, the competent authority that carried out the first transfer, or another competent authority in the Republic of Serbia, has approved the onward transfer after taking into account all circumstances relevant to the onward transfer, including the seriousness of the criminal offense, the purpose of the first transfer, and the level of personal data protection in the third country or international organization to which the data is further transferred.
Transfer Based on an Adequate Level of Protection
The transfer of personal data to another country, to part of its territory, or to one or more sectors of specific activities in that country, or to an international organization, without prior authorization, may be carried out if it has been determined that such other country, part of its territory, one or more sectors of specific activities in that country, or such international organization ensures an adequate level of personal data protection.
An adequate level of protection is deemed to be ensured in countries and international organizations that are parties to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, as well as in countries, parts of their territories, or one or more sectors of specific activities in those countries or international organizations for which the European Union has determined that they ensure an adequate level of protection.
The Government may determine that a country, part of its territory, field of activity or legal regulation, or an international organization does not ensure an adequate level of protection, except in the case of parties to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, taking into account:
- the principle of the rule of law and respect for human rights and fundamental freedoms, applicable legislation, including regulations in the areas of public security, defense, national security, criminal law, and access by public authorities to personal data, as well as the application of such regulations, rules on personal data protection and professional rules in this field, namely the implementation of personal data protection measures, including rules on the onward transfer of personal data to third countries or international organizations, as applied in the practice of courts and other public authorities in the other country or international organization, as well as the effectiveness of exercising the rights of the data subject, in particular the effectiveness of administrative and judicial procedures for protecting the rights of persons whose data is being transferred;
- the existence and effectiveness of the work of a supervisory authority for personal data protection in the other country, or of a supervisory authority competent to supervise an international organization in this field, with the authority to ensure the application of personal data protection rules, initiate personal data protection procedures in the event of non-compliance, assist and advise data subjects in exercising their rights, and cooperate with supervisory authorities of other countries;
- the international obligations undertaken by the other country or international organization, or other obligations arising from legally binding international treaties or other legal instruments, as well as from membership in multilateral or regional organizations, particularly with regard to personal data protection.
An adequate level of protection is also deemed to be ensured if an international agreement on the transfer of personal data has been concluded with another country or international organization.
In the procedure for concluding an international agreement on the transfer of personal data, the fulfillment of the above-mentioned conditions shall be specifically established.
The Government monitors the state of personal data protection in other countries, in parts of their territories, or in one or more sectors of specific activities in those countries or in international organizations, based on available collected information and information collected from international organizations that is relevant for reviewing the existence of an adequate level of protection.
The list of countries, parts of their territories, or one or more sectors of specific activities in those countries, and international organizations in which an adequate level of protection is deemed to be ensured, or for which the Government has determined that they do not ensure an adequate level of protection, shall be published in the “Official Gazette of the Republic of Serbia”.
Transfer with the Application of Appropriate Safeguards
The Controller or Processor may transfer personal data to another country, to part of its territory, or to one or more sectors of specific activities in that country, or to an international organization for which the above-mentioned list of countries has not established the existence of an adequate level of protection, only if the Controller or Processor has provided appropriate safeguards for such data and if the data subject is ensured the enforceability of their rights and effective legal protection.
Appropriate safeguards may be provided without special authorization from the Commissioner by means of:
- a legally binding instrument concluded between public authorities;
- standard contractual clauses prepared by the Commissioner in accordance with Article 4 of the Law, which fully regulate the legal relationship between the Controller and the Processor;
- binding corporate rules, in accordance with the Law;
- an approved code of conduct in accordance with the Law, together with the binding and enforceable application of appropriate safeguards, including the protection of the rights of the data subject, by the Controller or Processor in another country or international organization;
- issued certificates in accordance with the Law, together with undertaken obligations to apply appropriate safeguards, including the protection of the rights of the data subject, by the Controller or Processor in another country or international organization.
Appropriate safeguards may also be provided on the basis of special authorization from the Commissioner by means of:
- contractual provisions between the Controller or Processor and the Controller, Processor, or recipient in another country or international organization;
- provisions included in an agreement between public authorities that ensure effective and enforceable protection of the rights of the data subject.
The Commissioner shall issue authorization within 60 days from the date of submission of the request for authorization.
Transfer with the application of appropriate safeguards does not apply to the transfer of data processed by competent authorities for special purposes.
Transfer of Data Processed by Competent Authorities for Special Purposes, with the Application of Appropriate Safeguards
If processing is carried out by competent authorities for special purposes, the transfer of personal data to another country, to part of its territory, or to one or more sectors of specific activities in that country, or to an international organization for which the list of countries has not established the existence of an adequate level of protection, is permitted in one of the following cases:
- if appropriate personal data protection safeguards are provided for in a legally binding instrument;
- if the Controller has assessed all circumstances relating to the transfer of personal data and has determined that appropriate personal data protection safeguards exist.
The Controller is obliged to notify the Commissioner of any transfer carried out with the application of appropriate safeguards.
The Controller is obliged to document any transfer carried out with the application of appropriate safeguards and to make the transfer documentation available to the Commissioner upon request.
The documentation on the transfer with the application of appropriate safeguards contains information on the date and time of the transfer, the competent authority receiving the data, the reasons for the transfer, and the data that was transferred.
The Commissioner approves binding corporate rules if such rules jointly meet the following conditions:
- they are legally binding, apply to, and are enforced by every member of the multinational company or group of undertakings, including their employees;
- they expressly ensure the exercise of the rights of data subjects in relation to the processing of their data;
- they meet the requirements relating to binding corporate rules.
The binding corporate rules must specify at least the following:
- the structure and contact details of the multinational company or group of undertakings, as well as of each of its members;
- the transfer or groups of transfers of personal data, including the types of personal data, the types of processing operations and their purpose, the categories of data subjects, and the name of the country to which the data is transferred;
- the binding nature of the binding corporate rules, both within the multinational company or group of undertakings and outside them;
- the application of the general principles of personal data protection, in particular purpose limitation, data minimization, storage limitation, data integrity, ongoing data protection measures, the legal basis for processing, the processing of special categories of personal data, security measures, and the conditions for the onward transfer of personal data to other persons or bodies that are not bound by the binding corporate rules;
- the rights of data subjects in relation to processing and the ways of exercising those rights, including rights related to automated individual decision-making and profiling referred to in Article 38 of this Law, the right to lodge a complaint with the Commissioner or to file a lawsuit before a court in accordance with Articles 82 and 84 of this Law, as well as the right to compensation for damage caused by a breach of the binding corporate rules;
- acceptance of responsibility by the controller or processor with residence, temporary residence, or registered seat in the territory of the Republic of Serbia for a breach of these rules committed by another member of the group that does not have residence, temporary residence, or registered seat in the territory of the Republic of Serbia, unless the controller or processor proves that the other member of the group is not responsible for the event that caused the damage;
- the manner in which information on the binding corporate rules is provided to the data subject, especially information referred to in items 4 to 6 above, together with the other information referred to in Articles 23 and 24 of this Law;
- the powers of the Data Protection Officer, appointed in accordance with Article 58 of this Law, or of any other person authorized to supervise the application of the binding corporate rules within the multinational company or group of undertakings, including supervision of training and decision-making on complaints within the multinational company or group;
- the procedure applied in relation to complaints;
- the mechanism for verifying compliance with the binding corporate rules within the multinational company or group of undertakings. This mechanism includes personal data protection audits and corrective measures for the protection of the rights of data subjects. The results of the verification must be communicated to the person referred to in item 8 above, as well as to the management body of the multinational company or group of undertakings, and must also be made available to the Commissioner upon request;
- the manner of reporting and keeping records of changes to the binding corporate rules and the manner of notifying the Commissioner of such changes;
- the manner of cooperation with the Commissioner in order to ensure the application of the binding corporate rules by each individual member of the multinational company or group of undertakings, in particular the manner in which the results of the verification referred to in item 10 above are made available to the Commissioner;
- the manner of informing the Commissioner of legal obligations applicable to a member of the multinational company or group of undertakings in another country, which could have a significant adverse effect on the guarantees provided by the binding corporate rules;
- appropriate personal data protection training for persons who have permanent or regular access to personal data.
The Commissioner may further regulate the manner of exchange of information between controllers, processors, and the Commissioner in the application of the above-mentioned binding corporate rules.
If the conditions referred to in this paragraph are met, the Commissioner shall approve the binding corporate rules within 60 days from the date of submission of the request for their approval.
The provisions of paragraph 8.5 do not apply to the transfer of data processed by competent authorities for special purposes.
Transfer or Disclosure of Personal Data Based on a Decision of an Authority of Another Country
Decisions of a court or administrative authority of another country requiring the Controller or Processor to transfer or disclose personal data may be recognized or enforced in the Republic of Serbia only if they are based on an international agreement, such as an agreement on international legal assistance concluded between the Republic of Serbia and that other country. This does not affect the application of other grounds for transfer in accordance with the provisions of this chapter of the Law. The above provisions do not apply to the transfer of data processed by competent authorities for special purposes.
Transfer of Data in Special Situations
If the transfer of personal data is not carried out in accordance with Articles 64, 65, and 67 of this Law, such data may be transferred to another country or international organization only in one of the following cases:
- the data subject has explicitly consented to the proposed transfer, after being informed of the possible risks related to the transfer due to the absence of an adequacy decision and appropriate safeguards;
- the transfer is necessary for the performance of a contract between the data subject and the Controller, or for the implementation of pre-contractual measures taken at the request of the data subject;
- the transfer is necessary for the conclusion or performance of a contract concluded in the interest of the data subject between the Controller and another natural or legal person;
- the transfer is necessary for the establishment of an important public interest prescribed by the law of the Republic of Serbia, provided that the transfer of certain types of personal data is not restricted by this Law;
- the transfer is necessary for the submission, exercise, or defense of a legal claim;
- the transfer is necessary to protect the vital interests of the data subject or another natural person, if the data subject is physically or legally unable to give consent;
- the transfer concerns certain personal data contained in a public register, which are available to the public or to any person who can prove a legitimate interest, but only to the extent that the conditions prescribed by law for access in that specific case are fulfilled.
If the transfer cannot be carried out in accordance with paragraph 8.7 of this Policy and Articles 64, 65, and 67 of this Law, personal data may be transferred to another country or international organization only if all of the following conditions are met:
- the data transfer is not repetitive;
- the data of a limited number of natural persons is transferred;
- the transfer is necessary for the purpose of pursuing the legitimate interest of the Controller, which overrides the interests, rights, or freedoms of the data subject;
- the Controller has ensured the application of appropriate personal data protection measures based on a prior assessment of all circumstances related to the transfer of such data.
The Controller or Processor is obliged to provide evidence of the assessment carried out and of the application of appropriate safeguards in the records of processing activities referred to in Article 47 of this Law.
The Controller is obliged to notify the Commissioner of the data transfer carried out in accordance with paragraph 8.7.
The Controller is obliged to provide the data subject, in addition to the information referred to in Articles 23 and 24 of this Law, with the information referred to in paragraph 8.7, including information on which legitimate interest of the Controller is pursued by such transfer.
The transfer of data may not relate to all personal data or to entire categories of personal data from the register.
If data from a register that is available only to a person with a legitimate interest is transferred, the transfer may be carried out only at the request of that person or if that person is the recipient of the data.
The provisions of this paragraph do not apply to the activities of public authorities in the exercise of their powers.
The provisions of this paragraph do not apply to the transfer of data processed by competent authorities for special purposes.
Special Situations of Transfer of Data Processed by Competent Authorities for Special Purposes
Transfer of Personal Data in Special Cases
If the transfer of personal data processed by competent authorities for special purposes is not carried out in accordance with Articles 64 and 66 of this Law, such data may be transferred to another country or international organization only if such transfer is necessary in one of the following cases:
- for the purpose of protecting the vital interests of the data subject or another natural person;
- for the purpose of protecting the legitimate interests of the data subject, if provided for by law;
- for the purpose of preventing an immediate and serious threat to the public security of the Republic of Serbia or another country;
- in an individual case, where processing for special purposes is concerned;
- in an individual case, for the purpose of submitting, exercising, or defending a legal claim, if that purpose is directly related to the special purposes.
The transfer of personal data may not be carried out if the competent authority carrying out the transfer determines that the interest of protecting the fundamental rights and freedoms of the data subject overrides the public interest.
The competent authority is obliged to document the transfer carried out on the basis of this paragraph and to make such documentation available to the Commissioner upon request.
The documentation on the transfer referred to in this paragraph contains information on the date and time of the transfer, the competent authority receiving the data, the reasons for the transfer, and the data that was transferred.
Transfer of Data Processed by Competent Authorities for Special Purposes to a Recipient in Another Country
By way of exception from Article 63, paragraph 2, item 2 of this Law, and regardless of the application of an international agreement, a competent authority processing data for special purposes may directly transfer personal data to a recipient in another country only if the other provisions of this Law have been complied with and if all of the following conditions are met:
- the transfer is necessary for the exercise of the legal authority of the competent authority carrying out the transfer for special purposes;
- the competent authority carrying out the transfer has determined that the interest of protecting the fundamental rights or freedoms of the data subject does not override the public interest for the protection of which the data transfer is necessary;
- the competent authority carrying out the transfer considers that transfer to the competent authority in another country for special purposes would be ineffective or would not correspond to the achievement of those purposes, particularly if the transfer cannot be carried out in time;
- the competent authority in the other country has been informed of the transfer without undue delay, unless such notification would be ineffective or would not correspond to the achievement of the purpose;
- the competent authority carrying out the transfer has informed the recipient in the other country of the purposes of data processing, as well as that the processing may be carried out only for those purposes, only by the recipient, and only if such processing is necessary.
An international agreement, within the meaning of this Policy and the Law, is any agreement concluded between the Republic of Serbia and one or more other countries that regulates cooperation in criminal matters or police cooperation.
The competent authority carrying out the transfer is obliged to notify the Commissioner of the transfer carried out on the basis of paragraph 1 of this section.
The competent authority is obliged to document the transfer carried out on the basis of paragraph 1 of this section and to make such documentation available to the Commissioner upon request.
The documentation on the transfer referred to in this section contains information on the date and time of the transfer, the recipient of the data, the reasons for the transfer, and the personal data that was transferred.
Data Retention Period
Personal data is stored only for as long as necessary to achieve the purpose for which it was collected, unless a longer retention period is prescribed by law.
The usual retention periods are:
- data submitted through contact forms: up to 10 years or until a deletion request is submitted
- email communication: up to 1 year
- data for sending notifications/newsletters: until consent is withdrawn
After the expiry of the stated periods, the data is deleted or anonymized, except in cases where there is a legal obligation to retain it further.
Rights of Data Subjects
The data subject has the right to:
- request access to their data
- request correction of inaccurate or incomplete data
- request deletion of data (“right to be forgotten”)
- request restriction of processing
- object to data processing
- withdraw previously given consent at any time
A request to exercise these rights may be submitted via email: info@medtim.rs
The user also has the right to file a complaint with the competent authority for personal data protection.
Data Security
The Controller applies appropriate technical and organizational measures for the protection of personal data in order to prevent unauthorized access, loss, misuse, or unauthorized alteration of data.
Protection measures include, among others:
- use of SSL encryption
- data access control
- protection of server infrastructure
- use of security add-ons and abuse detection systems
The Controller applies appropriate technical and organizational measures for the protection of personal data in situations where data must be provided to third parties, such as courts, public prosecutors’ offices, and state authorities, upon their requests. These measures include anonymization of data that was not requested but is included in the requested documents, as well as minimization of the delivery of requested data in order to achieve the purpose for which the data was requested.
Cookies
The website uses cookies to ensure proper website operation, analyze usage, and improve the user experience.
By using the website, the user consents to the use of cookies.
Detailed information about cookies is available in the separate Cookie Policy.
Changes to the Privacy Policy
The Controller reserves the right to amend this Privacy Policy at any time.
All changes will be published on this page and shall enter into force on the date of publication.
Any use of future amendments to the Privacy Policy requires the additional consent of the user.
Contact
For any questions regarding the processing of personal data, you may contact us at:
Email: info@medtim.rs
Phone: +381600595255
Disclaimer
The content published on the website is for informational purposes only and does not constitute a substitute for a professional medical examination, diagnosis, or therapy.
The Controller does not guarantee the completeness, accuracy, or timeliness of the information published on the website and shall not be liable for any damage resulting from its use.
The user uses the information from the website at their own responsibility.
External Links
The website may contain links to other websites that are not under the control of the Controller.
The Controller is not responsible for the content, accuracy, or privacy policies of those websites.
User Content
Content submitted by users through the website, such as comments, experiences, statements, and similar materials, represents the personal opinion of the user.
The Controller does not guarantee the accuracy, completeness, or applicability of such information.
Published content does not represent a guarantee of results and cannot be considered medical advice.
Final Provisions
This Privacy Policy applies from the date of its publication on the website.
By using the website, the user confirms that they are familiar with its content and accepts it in full.




