PRIVACY NOTICE – PROCESSING OF PERSONAL DATA
Medical Center “Adella Fertility” AD is a healthcare facility specialising in assisted reproduction and reproductive medicine. As the controller of personal data within the meaning of the General Data Protection Regulation (Regulation (EU) 2016/679), we are responsible for the lawful processing of your personal data, including data concerning your health.
This Privacy Notice explains how we process your personal data: what data we collect, why we process it, who we disclose it to, how long we retain it, and what rights you have.
Who is the Data Controller?
The Data Controller is Medical Center “Adella Fertility” AD, UIC 204668999, with registered office at: 15G Tintjava Blvd., 3rd floor, 1113 Sofia, Bulgaria; website: Adella Fertility; telephone: 0700 10 992, +359 877 769 333; email: adellafert@adellaclinic.com, hereinafter referred to as the “Controller”.
Data Protection Officer (DPO)
For questions regarding the processing of your personal data, you may contact the Data Protection Officer:
Email: rakhat.turgnabek@adellaclinic.com
Telephone: +359883305567
Address: Medical Center “Adella Fertility”, 15G Tintjava Blvd., Dianabad, Sofia, Bulgaria.
What Personal Data Do We Process and How Do We Obtain It?
The Controller collects personal data when you register as a patient and throughout the provision of medical services. Some of the data is generated as a result of examinations, tests and medical procedures performed.
As part of donor programmes, data may also be obtained from other healthcare institutions.
Providing personal data that is necessary for diagnosis, the provision of medical services and compliance with legal obligations is mandatory. Failure to provide such data may result in the inability to perform the relevant medical activities or in the refusal to provide a service where this is required by law.
Depending on the service provided, we process the following categories of personal data:
- Identification and contact data: full name, Personal Identification Number (EGN), permanent and current address, telephone number and email address (if provided).
- Identity document data: identity card number, date of issue and issuing authority (collected for certain procedures, such as donor programmes, thawing of oocytes/embryos and embryo transfer, declarations for the destruction of frozen oocytes or embryos, and others).
- Unique identification number: an internal number assigned upon registration at the healthcare facility and used for traceability and medical documentation.
Special Categories of Personal Data
In addition to the above, we process personal data that is subject to enhanced protection:
- Health data and medical history: diagnosis, medical history, laboratory test results, ultrasound and other examination results, records of medical procedures performed, and data concerning pregnancy and childbirth.
- Data concerning the donation of reproductive cells: donor characteristics, blood group, test results and the unique identification number of donated cells.
- Genetic data: genetic screening results, information concerning genetic material with unique identification numbers, as well as data concerning family relationships.
- Infectious disease status data: results of tests for infectious diseases and microbiological examinations, collected prior to assisted reproduction procedures and as part of donor programmes.
- Blood group: collected as part of donor programmes for the purposes of donor selection.
Sources of Data Where We Do Not Obtain It Directly from You
In certain cases, we receive data from other healthcare institutions, laboratories, donor banks and registers, as well as from public authorities where this is provided for by law.
In such cases, we provide you with the information required under Article 14 of the GDPR upon our first contact with you or within one month, unless an expressly provided exemption under the applicable legislation applies.
Legal Bases for Processing Personal Data
We process your personal data on the following legal bases under Articles 6 and 9 of the GDPR:
- Processing is necessary for compliance with a legal obligation to which the Controller is subject, including obligations under the Bulgarian Health Act, the Medical Institutions Act, Ordinance No. N-2 of 2023 on activities related to assisted reproduction, and related secondary legislation. These legal acts require us to maintain records of the activities of a healthcare facility providing assisted reproduction services, as well as the provision, use and storage of human oocytes, sperm and embryos. In cases prescribed by law, we are required to provide your personal data to the competent authorities under the Bulgarian Health Act, including the Executive Agency “Medical Supervision” (Article 6(1)(c) of the GDPR).
- Processing is necessary for the performance of a contract for the provision of medical services to which you are a party, except where special categories of personal data are processed (Article 6(1)(b) of the GDPR).
- Processing is necessary for the purposes of medical diagnosis, the provision of healthcare or treatment, or the management of healthcare services, pursuant to a contract with a healthcare professional. This legal basis applies where the processing is carried out by, or under the responsibility of, a healthcare professional who is subject to an obligation of professional secrecy (Article 9(2)(h) and Article 9(3) of the GDPR).
- Processing is necessary to protect the vital interests of the data subject or of another natural person where the data subject is physically or legally incapable of giving consent, for example, in emergency medical situations (Article 9(2)(c) of the GDPR).
- Processing is necessary for scientific research purposes or statistical purposes, provided that the data is anonymised or pseudonymised. The Controller may use conclusions and results obtained from the methods of assisted reproduction applied for the purposes of compiling statistical data and scientific publications, while ensuring the complete anonymity of patients (Article 9(2)(j) of the GDPR).
Purposes and Legal Bases for Processing Your Personal Data
The circumstances in which we collect and process your personal data, the purposes for which we process it, and the legal bases for such processing are as follows:
|
Activity |
Category of Personal Data |
Legal Basis |
|
Provision of medical diagnosis, treatment and assisted reproduction procedures |
|
Processing is necessary for the purposes of medical diagnosis, the provision of healthcare or treatment, or the management of healthcare services, pursuant to a contract with a healthcare professional. This legal basis applies where the processing is carried out by, or under the responsibility of, a healthcare professional who is subject to an obligation of professional secrecy (Article 9(2)(h) and Article 9(3) of the GDPR). Processing is necessary for the performance of a contract for the provision of medical services to which you are a party, except with regard to data that constitutes special categories of personal data (Article 6(1)(b) of the GDPR). Compliance with a legal obligation applicable to the Controller (Article 6(1)(c) of the GDPR). |
|
Creation and maintenance of patient records and medical documentation. Maintenance of the “Patients” Register. |
|
Compliance with a legal obligation applicable to the Controller (Article 6(1)(c) of the GDPR). Processing is necessary for the purposes of medical diagnosis, the provision of healthcare, or the management of healthcare services (Article 9(2)(h) of the GDPR). |
|
Maintenance of the register under Article 132(1) of the Bulgarian Health Act. |
|
Compliance with a legal obligation applicable to the Controller (Article 6(1)(c) of the GDPR). Processing is necessary for the purposes of medical diagnosis, the provision of healthcare, or the management of healthcare services (Article 9(2)(h) of the GDPR). |
|
Fulfilment of traceability obligations for oocytes, sperm and embryos from donor to recipient. |
|
Compliance with a legal obligation applicable to the Controller (Article 6(1)(c) of the GDPR). Processing is necessary for the purposes of medical diagnosis, the provision of healthcare, or the management of healthcare services (Article 9(2)(h) of the GDPR). |
|
Provision of information to competent authorities (Executive Agency “Medical Supervision”, Ministry of Health, etc.) in accordance with applicable legal requirements. |
|
Compliance with a legal obligation applicable to the Controller (Article 6(1)(c) of the GDPR). Processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of medical devices or medicinal products (Article 9(2)(i) of the GDPR). |
|
Reporting serious adverse reactions and serious incidents to the Executive Agency “Medical Supervision”. |
|
Compliance with a legal obligation applicable to the Controller (Article 6(1)(c) of the GDPR). Processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety (Article 9(2)(i) of the GDPR). |
|
Blocking, withdrawal and destruction of oocytes, sperm and embryos. |
· Данни за идентификация и данни за контакт · Данни по документ за самоличност · Уникален идентификационен номер · Данни за дарителство |
Спазване на законово задължение, приложимо спрямо Администратора (чл. 6, пар. 1, б. „в” от ОРЗД). Обработването е необходимо за целите на медицинската диагноза, осигуряването на здравни грижи или управлението на здравни услуги (чл. 9, пар. 2, б. „з“ от ОРЗД). |
|
Obtaining informed consent for medical procedures. |
|
Compliance with a legal obligation applicable to the Controller (Article 6(1)(c) of the GDPR). Processing is necessary for the purposes of medical diagnosis, the provision of healthcare, or the management of healthcare services (Article 9(2)(h) of the GDPR). |
|
Ensuring the quality and safety of medical activities. |
|
Compliance with a legal obligation applicable to the Controller (Article 6(1)(c) of the GDPR). Processing is necessary for the purposes of medical diagnosis, the provision of healthcare, or the management of healthcare services (Article 9(2)(h) of the GDPR). |
|
Protecting the vital interests of the data subject or another natural person where the data subject is physically or legally incapable of giving consent. |
|
Protecting the vital interests of the data subject or another natural person where the data subject is physically or legally incapable of giving consent (Article 9(2)(c) of the GDPR). |
|
Scientific research or statistical purposes, provided that the data is irreversibly anonymised. |
|
Processing is necessary for the purposes of scientific research, is proportionate to the objective pursued, respects the essence of the right to data protection, and provides for appropriate and specific measures to safeguard the fundamental rights and interests of the data subject (Article 9(2)(j) of the GDPR and Article 28(1)(6) of the Bulgarian Health Act). |
We will not use your personal data for marketing purposes.
Who Do We Share Your Personal Data With?
Your personal data may be disclosed to the following categories of recipients only where this is necessary to comply with a legal obligation, protect your health, or where you have provided your consent:
- Executive Agency “Medical Supervision” — for the monthly submission of data pursuant to Article 44 of Ordinance No. N-2; for the annual reporting of activities performed (by 31 January) pursuant to Article 66; for reporting serious adverse reactions and incidents (within 7 days) pursuant to Articles 63–64; and for the annual reporting of blocked, withdrawn and destroyed gametes/zygotes pursuant to Article 68(3) of Ordinance No. N-2.
- Other healthcare institutions when providing or receiving reproductive cells or zygotes.
- National Health Insurance Fund (NHIF) — in relation to activities covered by the NHIF.
- Personal data processors (e.g. accounting firms, IT service providers, laboratories) that process data on behalf of the Controller under a data processing agreement in accordance with Article 28 of the GDPR.
- Other healthcare institutions where oocytes or embryos have been cryopreserved, when the patient wishes to transfer the cryopreserved material to our medical centre or vice versa.
- Other public authorities where disclosure is required by law.
Transfers of Data Outside the European Union/European Economic Area
Your data is not transferred to third countries or international organisations outside the European Union/European Economic Area.
Should such a transfer become necessary in the future, it will only take place where appropriate safeguards are in place in accordance with Chapter V of the GDPR (e.g. Standard Contractual Clauses, an adequacy decision or your explicit consent). You will be informed in advance of any such transfer.
Prohibition on Disclosure of Identity Data of Anonymous Donors and Recipients
The disclosure of information that may identify anonymous donors or recipients is prohibited. Information concerning the identity of donors and recipients constitutes official confidential information.
Automated Decision-Making and Profiling
The Controller does not use your personal data for automated decision-making based on computer algorithms that replace human judgement, including through profiling.
How Long Do We Retain Your Personal Data?
The retention periods are determined in accordance with applicable legal requirements:
- 30 years for information contained in the register of assisted reproduction activities, but not less than 10 years after the expiry of the storage period or use of the material.
- In the case of cryopreservation — for the entire period during which the material is stored and for no less than 10 years after the end of the storage period.
- Other medical documentation is retained in accordance with the Bulgarian Health Act.
- Informed consent forms are retained as part of the patient record for the period required by law.
Once the data is no longer required to be retained, it is securely destroyed.
How Do We Protect Your Personal Data?
We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss or alteration, including:
- Restricted access to personal data — access is limited to authorised employees only.
- Secure medical information system with passwords, encryption and access logging.
- Paper patient records are stored in premises with restricted access.
- Employees are required to treat all information as confidential.
What Are Your Rights as a Data Subject?
Under Articles 15–22 of the GDPR, you have the following rights:
Right of access — to obtain confirmation as to whether we process your personal data and to receive a copy of such data.
Right to rectification — to request the correction of inaccurate or incomplete personal data.
Right to erasure — under certain conditions, insofar as this does not conflict with our legal obligations to retain medical documentation.
Right to restriction of processing — under certain circumstances, to request that the processing of your personal data be restricted.
Right to object — to object to the processing of your personal data where the legal basis is legitimate interest (where applicable), including profiling based on such legitimate interest.
Right to data portability — to receive your personal data in a structured format and to transmit it to another data controller.
Right to withdraw consent — where processing is based on your consent, you may withdraw your consent at any time, without affecting the lawfulness of processing carried out before its withdrawal.
Right to lodge a complaint — with the Commission for Personal Data Protection: 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria; telephone: +359 2 915 3518; cpdp.bg.
You also have the right to an effective judicial remedy where you consider that your rights under the GDPR have been infringed, including against a decision of the supervisory authority.
How Can You Exercise Your Rights?
To exercise your rights, please submit a written request to the Controller or the Data Protection Officer (DPO) using one of the following methods:
- In person at the Controller’s address;
- By email to: turganbek@adellaclinic.com;
- By registered mail to: 15G Tintjava Blvd., 1st floor, 1113 Sofia, Bulgaria.
We will process your request without undue delay and, in any event, no later than one month after receiving it. Where necessary, this period may be extended by up to two additional months. In such cases, we will inform you of the reasons for the delay.
To exercise any of the rights listed above, please submit a written request using the designated form and send it through one of the communication channels specified above. We will also accept requests submitted without using the form provided by us. However, in order to be processed, the request must meet the minimum legal requirements and be submitted in writing, containing:
- Name, address, Personal Identification Number (EGN), Personal Number of a Foreigner (LNCh), or another equivalent identifier, or the unique identification number assigned by the Controller in connection with the services provided;
- A description of the request;
- The preferred form for receiving information when exercising the rights under Articles 15–22 of the GDPR;
- Signature, date of submission and correspondence address;
- Where the request is submitted by an authorised representative, the relevant power of attorney must also be attached.
Questions?
For questions and additional information regarding the processing of your personal data under this Privacy Notice and your rights as a data subject, you may contact us using the Controller’s contact details provided at the beginning of this Privacy Notice.
Changes to this Privacy Notice
This Privacy Notice was adopted by the Controller on 25 August 2026.
The Controller reserves the right to update this document in the event of changes in applicable legislation or the reorganisation of medical activities.
For non-material (administrative) changes: The updated version will be made available on the website and at the Controller’s reception. Non-material changes may include, for example, changes to the Controller’s contact details or to the contact details of the appointed Data Protection Officer (DPO).
For material changes: You will be notified in writing, including electronically. Where the changes affect activities that are carried out on the basis of your explicit consent, they will not take effect with regard to you until you have expressly confirmed them.
***