Privacy Policy
Here we describe how Novokliniken processes and protects your personal data when you visit our website, contact us, book a consultation, or receive care and treatment from us.
About this privacy policy
Your privacy is important to us. Here we explain how Kosmetisk Kirurgi & Cosmetic Surgery LL Medical AB, which operates Novokliniken, processes personal data when you visit our website, contact us, book a consultation, or receive care and treatment with us.
1. Data controller
Kosmetisk Kirurgi & Cosmetic Surgery LL Medical AB, corporate registration number 556302-2937, is the data controller for the processing of personal data described here.
Address: Barnarpsgatan 19, 553 16 Jönköping
Phone: 010-500 61 00
Email: info@novokliniken.se
2. What personal data we process
The data we process depends on how you contact us and which services you use. This may include, among other things:
name, phone number, email address, and personal identity number
information about the requested treatment and information you provide in a free-text message
booking details, visit history, and communication with the clinic
medical details required for assessment, care, treatment, and follow-up
medical records and photographs taken before or after a treatment
payment, invoicing, and financing details
technical information about your visit to the website, such as IP address, device, web browser, cookie identifiers, and how the website is used.
Health data is sensitive personal data and is subject to special protection. Do not provide more medical information in the website's standard contact fields than is necessary for us to handle your inquiry.
3. Why we process the data
Contact and inquiries
We process your contact details and the content of your message to answer questions, provide information, and follow up on your inquiry. The processing is based on our legitimate interest in communicating with individuals who contact us and, when applicable, on steps taken at your request prior to entering into a contract.
Booking and administration
We process data to book, reschedule, and cancel consultations and treatments, send confirmations and reminders, and administer payments and invoices. The processing is carried out to fulfill contracts, take steps prior to contracts, and comply with legal obligations.
Care, treatment, and record-keeping
When we provide health and medical care, we process the data needed for medical assessment, treatment, follow-up, patient safety, and medical record-keeping. The processing is carried out to comply with legal obligations and to provide health and medical care. Sensitive personal data is processed in accordance with applicable exemptions in the General Data Protection Regulation and Swedish healthcare legislation, including the Patient Data Act.
Payment, accounting, and legal claims
We process the data needed for payment, invoicing, financing, accounting, and to establish, exercise, or defend legal claims. The processing is based on contracts, legal obligations, and legitimate interest.
Website, advertising, and analytics
If you consent to non-essential cookies, we can measure the performance of advertising via Google Ads and Meta, as well as analyze how the website's features are used. Data about your care, your medical record content, or what you write in forms is not used for personalized advertising.
4. Booking and medical records systems
The website's booking form is integrated with Metodika. Data you provide in the form may therefore be sent directly to the clinic's booking and medical records system. When you book, you may receive an automated confirmation via SMS.
5. Photographs
Photographs may be taken before or after a treatment for medical record-keeping, medical documentation, and follow-up. If images are to be used in marketing, a separate and explicit consent is obtained. Such consent is voluntary and does not affect your ability to receive care or treatment.
6. Who may access the data
Only individuals who need the data for their work are allowed access to it. We may also share or grant access to personal data to suppliers who assist us with, for example, booking and medical records, website and IT operations, communication, payment, invoicing, financing, accounting, analysis, and advertising.
Suppliers processing data on our behalf may only do so in accordance with our instructions and subject to requirements for appropriate security. We may also disclose data to authorities, other healthcare providers, or insurance companies when required by law, necessary for your care, or otherwise legally supported.
Google and Meta may process technical information for their own purposes when their services are used and you have provided relevant consent. More information can be found in each supplier's privacy information.
7. Transfer outside the EU and EEA
Some external suppliers may process personal data outside the EU and EEA. When such a transfer occurs, it must be supported by the General Data Protection Regulation, for example, through an adequacy decision or the EU Commission's standard contractual clauses together with supplementary safety measures when necessary.
8. How long the data is stored
We store personal data for as long as it is needed for the purpose for which it was collected, and thereafter for as long as required by law or to handle legal claims.
Patient records are stored in accordance with the Patient Data Act and other applicable healthcare legislation.
Accounting records are stored for the period required by the Swedish Accounting Act.
General inquiries that do not lead to care or treatment are deleted or anonymized when they are no longer needed.
Cookie data is stored in accordance with the storage periods shown in the website's cookie settings.
Data processed on the basis of consent is processed until consent is withdrawn or the purpose ceases, unless we must retain it for some other legal reason.
9. How we protect the data
We use technical and organizational security measures adapted to the sensitivity of the data and the risks of the processing. This includes, among other things, authorization control, secure systems, procedures for access, and protection of information during transfer and storage.
10. Your rights
Depending on the circumstances, you have the right to request access to your personal data, have incorrect data corrected, request deletion or restriction, object to certain processing, and obtain certain data in a structured and machine-readable format. When processing is based on consent, you can withdraw your consent at any time.
These rights are not absolute. Requirements such as medical record-keeping and accounting may mean that certain data cannot be deleted.
Contact us at info@novokliniken.se if you wish to exercise a right. We may need to verify your identity before disclosing information.
11. Complaints
If you believe that we are processing your personal data incorrectly, please feel free to contact us so that we can investigate the matter. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection, IMY. Contact details can be found at imy.se.
12. Changes
We may update this privacy policy when our processing, our services, or applicable regulations change. The latest version is always available on the website, and the date of the last update is specified at the top.