Privacy Policy
MIGZ — Minimally Invasive Gynaecology Zadar · Last updated: January 2025 · Version 1.0
Data Controller
The data controller responsible for your personal data is MIGZ — Minimally Invasive Gynaecology Zadar, Croatia. For all data-related enquiries, contact hello@migz.eu.
This Privacy Policy explains how we collect, use, store and protect your personal data when you visit migz.eu, register for a course or examination session, or communicate with us. It applies in accordance with the General Data Protection Regulation (GDPR) and Croatian data protection law.
What We Collect
We collect only the personal data necessary to process your registration, issue an invoice and communicate with you about your course.
- Identity — your first name and last name.
- Contact — email address and phone number.
- Professional — institution or hospital, medical specialty and experience level.
- Billing — company or institution name, OIB (tax ID), billing address and country.
- Payment — payment confirmation and transaction reference. Card details are processed through the Teya payment gateway and are never collected or stored by MIGZ.
- Technical — IP address, browser type and pages visited, collected automatically via standard web server logs and cookies.
Why We Collect Your Data
We use your personal data for the following purposes:
- Course registration and administration — to confirm your spot, send confirmation emails, and manage your participation.
- Invoicing and tax compliance — to generate and send the required R1 fiscal invoice and fulfil our obligations under Croatian tax law.
- ESGE certification processing — to submit assessment results to ESGE and facilitate the issuance of your GESEA/ESGE certificate.
- Communication — to contact you about your registration, course dates, changes or cancellations.
- Payment processing — to complete your payment transaction through the Teya payment gateway.
- Website improvement — to understand how visitors use our website and improve the experience.
We do not use your personal data for automated decision-making or profiling.
Legal Basis for Processing
We process your data on the following legal bases under GDPR Article 6:
- Performance of a contract (Art. 6(1)(b)) — course registration and administration, ESGE certification processing, and payment processing through Teya.
- Legal obligation (Art. 6(1)(c)) — invoicing and tax compliance under Croatian law.
- Consent (Art. 6(1)(a)) — marketing communications, where you have explicitly opted in.
- Legitimate interest (Art. 6(1)(f)) — website analytics to improve our service.
Third Parties & Data Sharing
We do not sell or rent your personal data to any third party. We share data only where strictly necessary.
Payment Data Processing (Teya)
When paying on migz.eu for a course or service by credit or debit card, we ask the participant for the information required to initiate the payment process.
When paying through the Teya payment gateway, our contractual partner and data processor, your data is shared with Teya. Your personal data as a participant (for example, your full name, address and card details) is temporarily stored within the Teya system, which processes it in accordance with the highest standards for protecting and safeguarding confidential data (PCI DSS certification).
The participant initiates payment by selecting Pay and reserve my place. MIGZ does not at any time have access to, collect or store personal data entered for card processing and payment, such as the card number or CVV.
ESGE — European Society for Gynaecological Endoscopy
To process your certification, we share your name, assessment results and relevant professional details with ESGE. This is necessary to issue your GESEA/ESGE certificate. ESGE is an independent organisation and processes your data according to their own privacy policy.
Croatian tax authorities
We may be required to share certain data (primarily invoicing and transaction data) with the Croatian tax authority (Porezna uprava) in fulfilment of our legal obligations.
We do not share your data with marketing platforms, social media companies, data brokers or any other third parties not listed above.
Data Retention
We retain your personal data for as long as necessary to fulfil the purposes for which it was collected, and in compliance with applicable legal requirements.
- Invoice and billing data — 11 years, as required by Croatian tax law.
- Registration and course records — 5 years after the course date.
- Certification records — 10 years, or as required by ESGE.
- Email communications — 3 years after the last contact.
- Website analytics — 26 months, in anonymised form.
After the applicable retention period, your data is securely deleted or anonymised.
Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of access — you may request a copy of the personal data we hold about you.
- Right to rectification — you may request correction of inaccurate or incomplete data.
- Right to erasure — you may request deletion of your data, subject to our legal retention obligations.
- Right to restriction — you may request that we limit how we process your data in certain circumstances.
- Right to data portability — you may request your data in a structured, machine-readable format.
- Right to object — you may object to processing based on legitimate interest.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at hello@migz.eu. We will respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP) at azop.hr.
Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction or alteration.
- HTTPS encryption on all pages of migz.eu.
- Payment data processed through Teya in accordance with PCI DSS security standards.
- Access to personal data restricted to authorised personnel only.
- Regular review of data handling procedures.
No method of data transmission over the internet is completely secure. While we take every reasonable precaution, we cannot guarantee absolute security.
Minors
MIGZ courses and services are intended exclusively for qualified medical professionals. We do not knowingly collect personal data from anyone under the age of 18. If you believe a minor has submitted personal data through our website, please contact us at hello@migz.eu and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices or legal requirements. The date of the most recent revision is shown at the top of this page. For significant changes, we will notify registered participants by email where practical.
Continued use of migz.eu after a revised Privacy Policy has been published constitutes acceptance of the updated policy.
Contact
For any questions, requests or concerns about this Privacy Policy or how we handle your data, contact us by email at hello@migz.eu or visit migz.eu. We are based in Zadar, Croatia.
You also have the right to contact the Croatian supervisory authority for data protection — AZOP (Agencija za zaštitu osobnih podataka) — at azop.hr.
We are committed to handling your data responsibly. If you have any concerns, contact us directly and we will do our best to resolve them promptly.