Privacy Policy
Your privacy and health information security are our top priorities
Last Updated: February 17, 2026
Table of Contents
1. Introduction
Fuller ABC ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal and health information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or interact with our chiropractic practice located in Rijeka, Croatia.
As a healthcare provider, we comply with the European Union's General Data Protection Regulation (GDPR), Croatian data protection laws, and healthcare privacy regulations. This policy applies to all patients, website visitors, and individuals who interact with our services.
By using our website or services, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.
2. Data Controller
The data controller responsible for your personal information is:
Fuller ABC
Verdijeva ul. 6/I
51000 Rijeka, Croatia
Phone: +385 91 544 6181
Email: info@fuller-abc.com
For any questions or concerns about this Privacy Policy or how we handle your data, please contact us using the information above.
3. Information We Collect
3.1 Personal Information
We collect the following types of personal information:
- Identity Information: Name, date of birth, gender, identification documents (when required)
- Contact Information: Email address, phone number, postal address
- Health Information: Health history, current health conditions, symptoms, treatment records, chiropractic assessment data, X-ray images, treatment notes
- Appointment Information: Appointment dates, times, preferences, attendance history
- Payment Information: Billing address, payment method details (processed securely through third-party providers)
- Emergency Contact Information: Names and phone numbers of emergency contacts
3.2 Automatically Collected Information
When you visit our website, we automatically collect:
- Technical Data: IP address, browser type, operating system, device information
- Usage Data: Pages visited, time spent on pages, links clicked, referring website
- Cookies and Tracking Technologies: See our Cookie Policy section below
3.3 Information from Third Parties
We may receive information from:
- Other healthcare providers (with your consent)
- Insurance companies (for billing purposes)
- Referring physicians or specialists
4. How We Use Your Information
We use your personal information for the following purposes:
4.1 Healthcare Services (Legal Basis: Legitimate Interest & Consent)
- Providing Advanced Biostructural Correction™ treatments
- Assessing, diagnosing, and treating health conditions
- Maintaining accurate health records
- Coordinating care with other healthcare providers
- Emergency health situations
4.2 Appointment Management (Legal Basis: Contract)
- Scheduling and managing appointments
- Sending appointment reminders and confirmations
- Managing cancellations and rescheduling
- Maintaining appointment history
4.3 Billing and Administration (Legal Basis: Contract & Legal Obligation)
- Processing payments and managing billing
- Insurance claims processing
- Financial record-keeping
- Tax compliance
4.4 Communication (Legal Basis: Consent)
- Responding to inquiries and support requests
- Sending health tips and wellness information (with consent)
- Practice updates and announcements
- Patient satisfaction surveys
4.5 Website Improvement (Legal Basis: Legitimate Interest)
- Analyzing website usage and performance
- Improving user experience
- Technical support and troubleshooting
5. Legal Basis for Processing (GDPR)
Under GDPR, we process your personal data based on the following legal grounds:
- Consent: You have given explicit consent for processing your health information for specific purposes
- Contract: Processing is necessary to fulfill our contract with you (providing healthcare services)
- Legal Obligation: Processing is required to comply with Croatian and EU healthcare regulations
- Legitimate Interest: Processing is necessary for our legitimate business interests (practice management, fraud prevention)
- Vital Interest: Processing is necessary to protect life or physical integrity in emergency situations
6. How We Share Your Information
We do not sell or rent your personal information. We may share your information with:
6.1 Healthcare Providers
- Referring physicians and specialists (with your consent)
- Other chiropractors or healthcare professionals involved in your care
- Emergency medical services (when necessary)
6.2 Service Providers
- Payment processors (for billing)
- IT service providers (website hosting, data storage)
- Appointment scheduling platforms
- Email service providers (for communications)
All service providers are contractually bound to protect your data and use it only as instructed.
6.3 Legal Requirements
We may disclose information when required by law:
- Court orders or legal proceedings
- Regulatory authorities (Croatian Health Ministry, AZOP)
- Law enforcement (when legally obligated)
- Public health authorities
6.4 International Transfers
Some of our service providers may be located outside the European Economic Area (EEA). When we transfer data internationally, we ensure appropriate safeguards are in place through:
- EU Standard Contractual Clauses
- Privacy Shield certification (where applicable)
- Adequacy decisions by the European Commission
8. Data Security
We implement comprehensive security measures to protect your information:
8.1 Technical Safeguards
- SSL/TLS encryption for data transmission
- Encrypted databases and secure servers
- Regular security audits and updates
- Firewall protection and intrusion detection
- Secure password policies
8.2 Organizational Safeguards
- Staff training on data protection and GDPR compliance
- Access controls (role-based permissions)
- Confidentiality agreements with all staff
- Regular privacy impact assessments
- Data breach response procedures
8.3 Physical Safeguards
- Secure facility access controls
- Locked filing cabinets for paper records
- Secure disposal of physical documents
While we implement industry-standard security measures, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security but continuously work to protect your information.
9. Data Retention
We retain your information for as long as necessary to fulfill the purposes outlined in this policy:
- Health Records: Retained for 15 years after the last treatment (Croatian healthcare regulations)
- Billing Records: Retained for 10 years (tax and accounting requirements)
- Appointment Records: Retained for 5 years
- Marketing Consent: Until consent is withdrawn
- Website Analytics: Anonymized after 26 months
After the retention period expires, we securely delete or anonymize your information. You may request earlier deletion subject to legal and regulatory requirements.
10. Your Rights Under GDPR
Under GDPR and Croatian data protection law, you have the following rights:
10.1 Right to Access
Request a copy of your personal information we hold
10.2 Right to Rectification
Correct inaccurate or incomplete information
10.3 Right to Erasure ("Right to be Forgotten")
Request deletion of your personal data (subject to legal retention requirements)
10.4 Right to Restrict Processing
Limit how we use your information
10.5 Right to Data Portability
Receive your data in a structured, commonly used format
10.6 Right to Object
Object to processing based on legitimate interests or direct marketing
10.7 Right to Withdraw Consent
Withdraw consent at any time (without affecting lawfulness of prior processing)
10.8 Right to Lodge a Complaint
File a complaint with the Croatian Personal Data Protection Agency (AZOP)
Exercising Your Rights
To exercise any of these rights, please contact us at info@fuller-abc.com or +385 91 544 6181. We will respond to your request within 30 days as required by GDPR.
11. Children's Privacy
We provide chiropractic services to patients of all ages, including children. When treating minors (under 18 years old), we obtain consent from parents or legal guardians.
For children under 16, parental consent is required before we collect or process their personal data. We take extra care to protect children's information and only collect data necessary for treatment.
Parents have the right to access, correct, or delete their child's information at any time.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:
- Posting the updated policy on our website
- Updating the "Last Updated" date
- Sending email notifications for significant changes (if required by law)
Your continued use of our services after changes are posted constitutes acceptance of the updated policy. We encourage you to review this policy periodically.
13. Contact Information
For questions, concerns, or requests regarding this Privacy Policy or your personal data:
Fuller ABC - Data Protection Officer
Address: Verdijeva ul. 6/I, 51000 Rijeka, Croatia
Phone: +385 91 544 6181
Email: info@fuller-abc.com
Website: fuller-abc.com
Supervisory Authority
You have the right to lodge a complaint with:
Croatian Personal Data Protection Agency (AZOP)
Address: Selska cesta 136, 10000 Zagreb, Croatia
Phone: +385 1 4609 000
Email: azop@azop.hr
Website: azop.hr