Therapies and health programs, tailored to your needs
From assessment to recovery – complete support at every step of your therapy
Not sure which therapy you need?
Our physiatrist examinations and ultrasound diagnostics provide clear insights and a customized treatment plan tailored specifically to your condition.
Looking for comprehensive rehabilitation with accommodation?
Discover our thoughtfully curated packages that combine advanced therapies with comfortable accommodation – designed for full recovery and renewed mobility.
Know your condition and need targeted therapy?
Whether you're dealing with back pain, shoulder issues, calcifications or heel spurs, we offer precise solutions – from spinal decompression to advanced, pain-free shockwave therapy.
Interested in a therapy package without an overnight stay?
Our day packages include specialist consultations and therapies – ideal for local and regional patients seeking comprehensive care without accommodation.
Privacy Policy
Lječilište Bizovačke toplice
Sunčana 39, 31222 Bizovac
OIB (Personal Identification Number): 24179309084
E-mail: ljeciliste@bizovacke-toplice.hr
Telephone: 00385 31 685 189
Last updated: 6 July 2026
This Privacy Policy explains how Lječilište Bizovačke toplice collects, uses, stores and protects the personal data of users of the website ljeciliste-bizovacke.hr, persons who submit enquiries, book appointments, pay for services or contact us by e-mail or telephone through the website, as well as persons who visit the Institution’s premises.
Because Lječilište Bizovačke toplice provides healthcare and medical services, some of the data we process may constitute health data. Such data are specially protected personal data. We process them only where necessary to handle your enquiry, book an appointment, provide a healthcare service, carry out the required administration, collect payment, comply with legal obligations or protect persons and property.
We have written this policy in clear language so that you understand what data we process, why we process them, who may have access to them and what rights you have.
The personal data controller is:
Lječilište Bizovačke toplice
Sunčana 39
31222 Bizovac
OIB (Personal Identification Number): 24179309084
E-mail: ljeciliste@bizovacke-toplice.hr
Telephone: 00385 31 685 191
Lječilište Bizovačke toplice is an independent legal entity operating as an institution.
For questions relating to personal data protection, you may contact us at:
Data protection e-mail: bolnica@bizovacke-toplice.hr
By post: Lječilište Bizovačke toplice, Sunčana 39, 31222 Bizovac, marked “Personal Data Protection”
Depending on how you use the website or our services, we may process the following categories of data:
Basic identification data, such as your first and last name.
Contact details, such as your e-mail address, telephone number and address, where required for service administration or invoicing.
Appointment booking data, including the selected medical service, the date and time of the appointment, the selected service provider where applicable, the booking status and communications relating to the booking.
Data that you enter yourself in a contact form, booking form or free-text field. We particularly note that the booking form contains a field in which you may freely enter information that you consider relevant. In that field, you may state symptoms, a diagnosis, treatment, test results or other health information. Please do not enter more health data in free-text fields than is necessary to handle the enquiry, book the appointment or prepare for the provision of the service.
Data concerning the healthcare service you have selected. Because specifically named medical services can be booked on the website, the selection of a service itself may indicate a health condition, health-related interest or reason for your visit.
Payment data, including the data required to process an online payment, the transaction status, amount, payment date and the data required to issue an invoice. We do not process payment card data directly on our website; payments are made through the CorvusPay payment system.
Data relating to HZZO patients, including enquiries, approvals for inpatient rehabilitation and medical documentation submitted by the user through a form or another communication channel. Where necessary, such data may be transferred to the hospital information system for patient administration and processing.
Technical data concerning use of the website, such as the IP address, device type, browser type, approximate location at country or regional level, time of visit, pages visited, traffic source and the manner in which the website is used.
Data collected through cookies and similar technologies, depending on your consent settings.
Video surveillance recordings if you enter areas marked as being under video surveillance.
We enable online booking of medical services on the website through the SimplyBook.me system.
The following medical services can be booked online: physiatrist examination, diagnostic ultrasound, PRP, intra-articular injections, spinal decompression, pain-free shockwave therapy, robotic neurorehabilitation, Vacumed therapy, Schroth therapy, medical massage, acupuncture, DNS therapy, Bowen/Emmett therapy, lymphatic drainage and hydrotherapy exercises.
When you book an appointment through the website, SimplyBook.me may process your first and last name, contact details, selected service, appointment time, notes you enter yourself and other data required to organise and carry out the booking.
After a booking has been made, the name of the selected service is visible in the appointment schedule within SimplyBook.me. The patient and the Institution receive an appointment confirmation by e-mail containing the name of the selected service and the appointment time.
Because the name of the selected service may indicate a health condition or health-related interest, we treat such data as particularly sensitive. We use them only to process the booking, organise the appointment, communicate with you, prepare for and provide the service, and carry out the required administration.
The website may contain contact forms for different types of enquiries. You may also contact us by e-mail or telephone.
Depending on the type of enquiry, your data may be processed by the sales department, administration, the head nurse or other authorised persons at the Institution. If you are a private patient, the enquiry is generally handled by the sales department. If you are an HZZO patient, the enquiry may be handled by administration or the head nurse.
If HZZO patients submit HZZO approval or other documentation required for processing through a form or another communication channel, those data may be entered into the hospital information system for further patient administration and processing.
We use data from contact forms to respond to your enquiry, communicate with you, organise your visit, administer the service and, where applicable, process HZZO documentation.
The booking form contains a free-text field. You may use this field to enter information that you consider important for the booking or provision of the service. This may include, for example, symptoms, diagnoses, treatments, test results, limitations, special needs or other information that you wish to share with the Institution.
Please enter only the data required to understand your enquiry or prepare for the service you wish to book. If test results, detailed diagnoses or extensive medical documentation are not necessary to process the booking, we recommend that you do not enter them in the free-text field.
We use the data you enter in this field only to handle your enquiry, book an appointment, prepare for the provision of the service and carry out the required internal administration.
We use the CorvusPay payment system as our online payment gateway.
When you pay for a service online, the payment is processed through the secure CorvusPay payment system. The Institution does not store your credit or debit card data on its website.
For payment collection and invoicing purposes, we may process data such as your first and last name, contact details, service name, amount, payment date, transaction status and the data required to issue an invoice.
The specific name of a medical service may appear on the invoice and payment confirmation. Such information may indicate the healthcare service you selected, so we process it with particular care and solely for payment collection, invoicing, accounting, fiscal obligations and evidence of the service provided or payment made.
The website and the online booking system are separate from the Institution’s hospital information system.
The Institution uses a hospital information system in which patient data and medical records are stored and retained in accordance with the regulations governing healthcare activities, the keeping of medical records, accounting and other legal obligations.
Where necessary, data received through a web form, e-mail, telephone or online booking may be used for further patient processing in the hospital information system. This may apply in particular to HZZO patients who submit HZZO approvals or other documentation required for admission and processing.
More detailed rules governing the processing of patient data and medical records are set out in the Institution’s internal privacy policy and other applicable healthcare rules.
We may use analytics and advertising tools on the website, including:
Google Tag Manager, Google Analytics, Google Ads and Meta Ads.
These tools are used to measure website traffic, understand how the website is used, measure advertising performance and improve the user experience.
Analytics and advertising tools are used solely in accordance with your consent settings for cookies and similar technologies. If you do not consent to analytics or marketing cookies, these tools will not be used to their full extent. In certain cases, technical cookieless signals may be sent as part of the consent management system, without identifying cookies and without data that would reveal your health condition.
Data that may indicate a user’s health condition, including the selected medical service, appointment time, patient notes, reason for the visit, symptoms, diagnosis, treatment or test results, are not used for advertising profiling and are not sent to advertising platforms as parameters for creating audiences or personalising advertisements.
We do not send first name, last name, e-mail address, telephone number, hashed e-mail address, hashed telephone number, the contents of patient notes, appointment time, the name of the selected medical service, diagnosis, test results or other health data to advertising or analytics tools.
Conversions may be tracked only as neutral events, without sending the name of the medical service or other health-related details.
Advertising tags are not activated on the booking confirmation or payment confirmation page.
The website may use advertising tools such as Google Ads and Meta Ads.
Given the nature of healthcare and medical services, the Institution does not use data that may indicate a health condition, selected medical service or reason for the visit for advertising profiling.
Where remarketing is used, it is limited to general and non-sensitive parts of the website. Remarketing audiences are not created on the basis of visits to pages relating to individual medical services, the booking of a particular medical service, payment, booking confirmation, payment confirmation or data entered in forms.
We may use Microsoft Clarity on the website to understand how the website is used, identify technical problems and improve the user experience. Microsoft Clarity may provide heatmaps and anonymised recordings of user interactions.
Microsoft Clarity is used only with your consent.
Microsoft Clarity is not used, or is disabled, on pages and at stages involving booking, payment, booking confirmation, payment confirmation or the entry of sensitive data. Content masking is also applied so that personal data, data entered in forms, medical data, selected services, contact details or payment data are not recorded.
Despite the technical safeguards in place, the Institution seeks to avoid using session-recording tools on parts of the website where there is a greater risk that health data or other sensitive data may be processed.
Video surveillance is used on the Institution’s premises to protect persons and property, ensure the security of the premises, control access and prevent unauthorised activity.
A notice at the entrance states that the premises are under video surveillance.
Cameras are located at the entrance to the inpatient section of the Institution, at the entrance to the outpatient section, in the corridor connecting the inpatient and outpatient buildings, by the safe at reception, and outside the entrances to the hospital building and the outpatient building.
Video surveillance recordings are retained for 40 days, unless a longer retention period is required in a particular case for proceedings by competent authorities, the protection of rights, evidentiary purposes or another justified reason provided for by law.
Access to the recordings is limited to authorised persons. Under the current organisational arrangements, access is granted to the director of Lječilište Bizovačke toplice and the director of Izvor upravljanje, the founder of Lječilište Bizovačke toplice, in accordance with their assigned powers and the purpose of protecting persons and property.
The recordings are not used for purposes other than those for which the video surveillance system was installed, unless this is necessary to comply with the law or a request from a competent authority.
Access to personal data is limited to authorised persons who need the data to perform their work.
Depending on their role and need, SimplyBook.me data may be accessed by the admissions desk, reception, physiotherapists, sales staff, physicians and the director.
Data from contact forms may be accessed by persons responsible for the relevant type of enquiry, such as sales staff, administration or the head nurse.
Patient data in the hospital information system may be accessed by authorised persons in accordance with healthcare rules and the Institution’s internal rules.
Data from the video surveillance system may be accessed only by specifically authorised persons.
In certain cases, we use external service providers that may process personal data on our behalf or within the scope of their own legal role.
These include:
SimplyBook.me, for online bookings and appointment schedule management.
CorvusPay, for online payment processing.
Zeraxo d.o.o., as the provider responsible for the development, maintenance and technical administration of the website.
Ružičasta breskvica d.o.o., as the provider responsible for implementing Google Tag Manager, analytics and advertising tags, and the technical configuration of measurement.
Google, for Google Analytics, Google Ads and related tools.
Meta, for Meta Ads and related advertising tools.
Microsoft, for Microsoft Clarity where activated with the user’s consent.
Providers of hosting, e-mail services, IT support, accounting, fiscalisation, system maintenance and other services necessary for the Institution’s operations.
Where external service providers process personal data on our behalf, appropriate agreements have been concluded with them or appropriate data processing terms are used. Such providers may process data only on our instructions, in accordance with the relevant agreement and applicable personal data protection legislation.
Where possible, the Institution seeks to use service providers and settings that enable data to be processed within the European Union or the European Economic Area.
For SimplyBook.me, we use the activated EU hosting option and the applicable data processing terms.
In the case of global service providers such as Google, Meta and Microsoft, data may in certain circumstances be processed or accessed outside the European Economic Area. In such cases, appropriate safeguards provided for under personal data protection legislation are applied, such as standard contractual clauses, adequacy decisions or other valid mechanisms.
Data that may indicate a health condition, selected medical service, reason for the visit, patient notes, appointment time, test results, diagnoses or treatments are not sent to advertising platforms for profiling, remarketing or ad personalisation.
We process personal data only where an appropriate legal basis exists.
Where we process data to respond to an enquiry, book an appointment, communicate before providing a service or organise a visit, the legal basis may be taking steps at your request before entering into a contract or performing a contract.
Where we process data to provide a healthcare service, keep medical records, administer patients or process HZZO documentation, the legal basis may be the provision of healthcare, compliance with a legal obligation of the Institution or another applicable basis under the regulations governing healthcare activities.
Where we process data for invoicing, fiscalisation, accounting and compliance with tax legislation, the legal basis is compliance with legal obligations.
Where we process data through analytics and marketing cookies, the legal basis is your explicit consent.
Where we process data through video surveillance to protect persons and property, the legal basis is the Institution’s legitimate interest in protecting the safety of persons, property and premises, while respecting the rights and freedoms of persons present in areas under video surveillance.
Where we process data for the technical security of the website, prevention of misuse and system maintenance, the legal basis may be the legitimate interest in ensuring system security and proper operation.
We retain personal data only for as long as necessary for the purpose for which they were collected, unless legislation requires us to retain them for longer.
Contact enquiries are retained for: 12 months.
Private bookings in the SimplyBook.me system are retained for: for as long as we need the data to manage bookings, provide the service, communicate with the user, handle administration, and comply with legal obligations.
Data relating to HZZO patients and submitted HZZO documentation are retained in accordance with the Institution’s rules, the regulations governing healthcare activities and the retention periods applicable to medical records: data on inpatients are retained permanently, while data on outpatients are retained for 10 years.
Payment data and invoices are retained in accordance with accounting, tax and fiscal legislation: 11 years.
Marketing consents are retained until consent is withdrawn or until a reasonable period has elapsed since the user’s last activity.
Analytics data are retained in accordance with the settings of the relevant tool, for up to 14 months.
Microsoft Clarity recordings, where used, are retained in accordance with the tool settings and only with consent.
Video surveillance recordings are retained for 40 days, unless a longer period is required in a particular case for evidentiary purposes, proceedings by competent authorities, the protection of rights or another legally permitted purpose.
After the retention periods expire, the data are erased, anonymised or archived where a legal obligation or another justified reason for continued retention exists.
The Institution implements technical, organisational and administrative measures to protect personal data against unauthorised access, loss, misuse, alteration or unauthorised disclosure.
Protective measures include restricting access to data according to job role, using authorised user accounts, technical system protection, contractual obligations imposed on external service providers, access control and internal procedures for handling personal data.
We pay particular attention to data that may indicate a health condition, selected medical service or reason for a visit.
Your rights
In accordance with personal data protection legislation, you have the right to request:
access to your personal data,
rectification of inaccurate or incomplete data,
erasure of personal data where the conditions for erasure are met,
restriction of processing,
the right to object to processing where the processing is based on legitimate interests,
data portability where applicable,
withdrawal of consent where the processing is based on consent,
where you withdraw consent to analytics or marketing cookies, this does not affect the lawfulness of processing based on consent before its withdrawal.
To exercise your rights, you may contact us at:
E-mail: ljeciliste@bizovacke-toplice.hr
By post: Lječilište Bizovačke toplice, Sunčana 39, 31222 Bizovac
To protect your data, we may request additional information to verify your identity before acting on your request. We process requests within the statutory time limit and within a reasonable scope. If that scope affects our ordinary operations, we may charge an administrative fee.
Right to lodge a complaint
If you believe that your rights relating to personal data have been infringed, you have the right to lodge a complaint with the supervisory authority:
Croatian Personal Data Protection Agency
Selska cesta 136
10000 Zagreb
Website: www.azop.hr
Before lodging a complaint, you may contact us so that we can attempt to resolve your request or concern.
We may update this Privacy Policy from time to time, for example due to changes in legislation, changes to our services, the introduction of new website functions or changes of service providers.
The updated version will be published on this website together with the date of the latest update.