Privacy Policy
1. Introduction
Welcome to Medimond (“we”, “us”, or “our”). We are committed to protecting your personal information and your right to privacy. This Privacy Policy applies to all information collected through our website (medimind.com), and/or any related services, sales, marketing or events (we refer to them collectively in this privacy policy as the “Services”).
When you visit our website and use our services, you trust us with your personal information. We take your privacy very seriously. In this privacy policy, we seek to explain to you in the clearest way possible what information we collect, how we use it and what rights you have in relation to it. We hope you take some time to read through it carefully, as it is important. If there are any terms in this privacy policy that you do not agree with, please discontinue use of our Sites and our services.
This privacy policy is compliant with the General Data Protection Regulation (GDPR).
2. Who is the Data Controller?
The data controller for the processing of personal data is:
Medimond
Based in the Netherlands
Website: medimind.com
For any privacy-related questions or to exercise your rights, please contact us through our contact page on our website.
3. What Personal Data We Collect and Why
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and services, when you participate in activities on the Services or otherwise when you contact us.
The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make and the products and features you use. The personal information we collect can include the following:
Identity DataExamples: First name, last name, username or similar identifier.
Purpose: To create and manage your account, and to personalize your experience.
Contact DataExamples: Billing address, delivery address, email address and telephone numbers.
Purpose: To process and deliver your orders, and to communicate with you.
Financial DataExamples: Payment card details.
Purpose: To process payments for your orders. We do not store your full payment card details.
Transaction DataExamples: Details about payments to and from you and other details of products and services you have purchased from us.
Purpose: To keep a record of your transactions with us.
Technical DataExamples: Internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website.
Purpose: To ensure the security of our website, to improve our website and services, and for analytics.
Usage DataExamples: Information about how you use our website, products and services.
Purpose: To understand how our customers use our website and to improve our services.
Marketing and Communications DataExamples: Your preferences in receiving marketing from us and our third parties and your communication preferences.
Purpose: To send you marketing communications that you have consented to receive.
4. Legal Basis for Processing Your Data
We process your personal data on the following legal bases:
- Consent: We may process your data if you have given us specific consent to use your personal information for a specific purpose (e.g., for marketing communications). You can withdraw your consent at any time.
- Performance of a contract: We may process your personal data when it is necessary for the performance of a contract to which you are a party or in order to take steps at your request before entering into such a contract (e.g., to process and deliver your order).
- Legitimate interests: We may process your data when it is reasonably necessary to achieve our legitimate business interests, provided that your interests and fundamental rights do not override those interests.
- Legal obligations: We may disclose your information where we are legally required to do so in order to comply with applicable law, governmental requests, a judicial proceeding, court order, or legal process.
5. Data Storage and Retention
We will only keep your personal information for as long as it is necessary for the purposes set out in this privacy policy, unless a longer retention period is required or permitted by law (such as tax, accounting or other legal requirements). When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
6. Data Sharing and Third Parties
We may share your data with third-party vendors, service providers, contractors or agents who perform services for us or on our behalf and require access to such information to do that work. Examples include: payment processing, data analysis, email delivery, hosting services, customer service and marketing efforts. We have contracts in place with our data processors. This means that they cannot do anything with your personal information unless we have instructed them to do it. They will not share your personal information with any organisation apart from us. They will hold it securely and retain it for the period we instruct.
7. International Data Transfers
Your information may be transferred to — and maintained on — computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction. If we transfer your personal data out of the EEA, we will ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
- We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission.
- Where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe.
8. Your Data Protection Rights
Under GDPR, you have the following rights:
- The right to access – You have the right to request copies of your personal data.
- The right to rectification – You have the right to request that we correct any information you believe is inaccurate. You also have the right to request that we complete the information you believe is incomplete.
- The right to erasure – You have the right to request that we erase your personal data, under certain conditions.
- The right to restrict processing – You have the right to request that we restrict the processing of your personal data, under certain conditions.
- The right to object to processing – You have the right to object to our processing of your personal data, under certain conditions.
- The right to data portability – You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.
If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us through our contact page.
You also have the right to lodge a complaint with a supervisory authority. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) is the supervisory authority in the Netherlands.
9. Data Security
We have implemented appropriate technical and organizational security measures designed to protect the security of any personal information we process. However, please also remember that we cannot guarantee that the internet itself is 100% secure. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. You should only access the services within a secure environment.
10. Cookies and Tracking Technologies
We use cookies and similar tracking technologies (like web beacons and pixels) to access or store information. Specific information about how we use such technologies and how you can refuse certain cookies is set out in our Cookie Policy.
11. Changes to This Privacy Policy
We may update this privacy policy from time to time. The updated version will be indicated by an updated “Last Updated” date and the updated version will be effective as soon as it is accessible. We encourage you to review this privacy policy frequently to be informed of how we are protecting your information.
12. Contact Us
If you have questions or comments about this policy, you may contact us through our contact page on our website: medimind.com/contact.
References
[1] 10 steps to comply with the GDPR in the Netherlands | Business.gov.nl
[2] 10 Must-Have Elements of Every GDPR-Compliant Privacy Policy | Piwik PRO