Search
Close this search box.

Privacy

We take great care to ensure that the handling of personal data (hereinafter referred to as data) is transparent. This declaration of data privacy provides information on what data we collect from external data subjects, for what purpose and to whom we pass it on. To ensure a high level of transparency, this privacy policy is regularly reviewed and updated.

1. Services we use

  • Microsoft
  • Abacus ERP
  • Smart-Trials (Greenlight Guru medical)
  • Basec
  • eiam.admin.ch
  • Red Cap
  • Google Ads
  • Google Ads Conversion Tracking
  • Google Analytics
  • Google Tag Manager
  • Google Customer Reviews
  • Google My Business
  • Google Fonts API
  • Google Maps
  • Google Site Kit
  • WordPress
  • Google reCAPTCHA

2. Contact information

For information, correction and deletion of your data or for general matters relating to data privacy, the following contact options are available:

Responsible for data processing:

41medical AG
Tannlimattweg 14
2544 Bettlach, Switzerland

info@41medical.com
+41 32 645 41 41

Data Privacy Representative:

Michael Meyer
dataprivacy@41medical.com
+41 79 731 24 46

3. General principles

3.1 What data do we collect from you and from whom do we receive this data?

First and foremost, we collect and process data that you provide to us or that we need to operate our organization. We may also receive such data about you from third parties. This is always done in accordance with the principle of data minimization. In any case, particularly sensitive data of externally affected persons is processed anonymously. The following categories of data are generally processed:

  • Personal master data (name, address, date of birth, etc.);
  • Contact data (cell phone number, e-mail address, etc.);
  • Financial data (account details);
  • Proof of qualifications (CV, diplomas, certificates, etc.);
  • Online identifiers (cookie identifiers, IP addresses, etc.);
  • Health data (illnesses, injuries, special health characteristics, etc.).

3.2 Under what conditions do we process your data?

We treat your data confidentially and in accordance with the purposes set out in this privacy policy. We pay attention to transparent and proportionate processing.

If, in exceptional cases, we are unable to comply with these principles, data processing may nevertheless be lawful because there is a justification. In particular, the following grounds for justification may apply:

  • Your consent;
  • the fulfillment of a contract or pre-contractual measures;
  • legal requirements;
  • public interest;
  • our legitimate interests, unless your interests prevail.

3.3 In which cases can we pass on your data to third parties?

3.3.1 Principle

We may need to use the services of third parties or affiliated companies and commission them to process your data (so-called processors). The categories of recipients are as follows:

  • Accounting, trust and auditing companies;
  • Consulting companies (legal advice, taxes, etc.);
  • IT service providers (web hosting, support, cloud services, website design, etc.);
  • Payment service providers;
  • providers of tracking, conversion and advertising services.

We ensure that these third parties and our affiliated companies comply with data protection requirements and treat your data confidentially.

We may also be obliged to disclose your data to authorities.

3.3.2 Visiting our social media channels

We may have embedded links to our social media channels on our website. This is visible to you in each case (typically via corresponding icons). If you click on the icons, you will be redirected to our social media channels.

In this case, the social media providers are informed that you have accessed their platform from our website. The social media providers can use the data collected in this way for their own purposes. We would like to point out that we have no knowledge of the content of the transmitted data or its use by the operators.

3.3.3 Transfer abroad

Under certain circumstances, your data may be transferred to companies abroad as part of order processing. These companies are obliged to protect data to the same extent as we are. The transfer may take place worldwide.

If the level of data protection does not correspond to that in Switzerland, we will carry out a prior risk assessment and contractually ensure that the same level of protection is guaranteed as in Switzerland (e.g. by means of the new standard contractual clauses of the EU Commission or other legally prescribed measures). If our risk assessment is negative, we will take additional technical measures to protect your data. You can access the EU Commission’s standard contractual clauses at the following link: https://commission.europa.eu/publications/standard-contractual-clauses-controllers-and-processors-eueea_en

3.4 How long do we store your data?

We only store data for as long as is necessary to fulfill the individual purposes for which the data was collected.

We are obliged by law to store contract and product-related data for a longer period of time. In particular, we must store business communications, concluded contracts and accounting documents for up to 10 years, and product-related data must be stored for up to 30 years in accordance with the product life cycle. If we no longer need such data from you to provide our services, the data will be blocked and we will only process it in accordance with official requirements.

Data that we store when you visit our website is stored for twelve months, except analysis and tracking data, which may be stored longer.

3.5 How do we protect your data?

We will store your data securely and have taken all appropriate technical and organizational measures to protect your data from loss, unauthorized access, misuse or alteration.

Our contractual partners and employees who have access to your data are obliged to comply with data privacy regulations. In some cases it will be necessary for us to pass on your inquiries to companies affiliated with us. Your data will also be treated confidentially in these cases.

Within our website, we use the SSL (Secure Socket Layer) method in conjunction with the highest level of encryption supported by your browser.

3.6 What rights do you have?

In principle, you have the right to information, correction and deletion of data stored about you at any time. You also have the right to withdraw your consent at any time. Please send your request together with proof of identity to the data privacy representative named in section “Contact information”.

The processing of your request is subject to the statutory processing period of 30 days. However, we may extend this period due to a high volume of requests, for legal or technical reasons or because we require more detailed information from you. You will be informed of the extension in good time, at least in text form.

The following circumstances must be taken into account when processing such requests:

  • We may restrict or refuse to provide information or data if this conflicts with our legal obligations, our own legitimate interests, public interests or the interests of a third party.
  • When withdrawing consent, it should be noted that this does not affect data processing that has already taken place under the consent.
  • Requests for the erasure or rectification of data may be rejected if we are required by law to retain the data for a longer period or to retain it unchanged, or if your request conflicts with a corresponding justification in accordance with section ”Under what conditions do we process your data?”.
  • Under certain circumstances, the exercise of your rights may conflict with contractual provisions and have corresponding effects on the performance of the contract (e.g. premature termination of the contract and/or cost consequences).

3.6.1 Tegal recourse

If you are affected by the processing of personal data, you have the right to enforce your rights in court or to file a complaint with the competent supervisory authority. The competent supervisory authority in Switzerland is the Federal Data Protection and Information Commissioner: https://www.edoeb.admin.ch/edoeb/en/home.html

4. Individual data processing operations

4.1 Microsoft

What data do we receive and how do we use it?

As part of our business activities, we store and analyze qualification certificates of persons commissioned for auditing or involved in development. In addition, anonymized health data of persons may be stored and processed during market surveillance activities, in the event of unintentional incidents (complaints) or generally to improve the products. This data is required to ensure the safety and performance of the products.

Why are we allowed to process this data?

This data is processed on a legal basis. We are legally obliged to check and document the qualifications of external contributors and must ensure the safety and performance of the products at all times.

4.2 Abacus (ERP system)

What data do we receive and how do we use it?

As a partner, customer or service provider, we store and process your personal master data, contact data and financial data for order processing.

Why are we allowed to process this data?

You give us your consent to process this data when you place an order or accept an order by submitting your data. In addition, we have a legitimate interest in order processing and a legal requirement regarding the traceability of delivered products and for accounting and tax purposes.

4.3 Clinical data

What data do we receive and how do we use it?

As part of clinical studies, we store and analyze anonymized health data (clinical data) of persons who participate or have participated in clinical studies on the basis of consent. This data is used to provide evidence of the safety and performance of a product.

Why are we allowed to process this data?

The collection of clinical data is based on legal requirements. In addition, each study participant has given a declaration of consent.

4.4 Website

What data do we receive and how do we use it?

When you visit www.41medical.com, certain data is automatically stored on our servers or on servers of services and products that we have purchased and/or installed for system administration, statistical, backup or tracking purposes. These are:

  • the name of your internet service provider;
  • your IP address (under certain circumstances);
  • the version of your browser software;
  • the operating system of the computer used to access the URL;
  • the date and time of access;
  • the website from which you visit the URL;
  • the search terms you used to find the URL.

Why are we allowed to process this data?

This data cannot be assigned to a specific person and is not merged with other data sources. The log files are stored in order to guarantee the functionality of the website and to ensure the security of our information technology systems. This is our legitimate interest.

4.4.1 Google Ads

We use the Google Ads service on our website, an online advertising service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter “Google”). Google Ads enables us to place advertisements in Google search results and in the Google advertising network.

4.4.2 Google Ads Conversion Tracking

We use the online advertising program “Google Ads” on our website and, in this context, conversion tracking (visit action evaluation). Google Ads Conversion Tracking is an analysis service provided by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; “Google”). When you click on an ad placed by Google, a conversion tracking cookie is set on your device. These cookies have a limited validity, do not contain any personal data and are therefore not used for personal identification. If you visit certain pages of our website and the cookie has not yet expired, Google and we can recognize that you have clicked on the ad and have been redirected to this page.

The information collected using the conversion cookie is used to generate conversion statistics. This tells us the total number of users who clicked on one of our ads and were redirected to a page with a conversion tracking tag. However, we do not receive any information with which users can be personally identified. You can prevent the storage of cookies by selecting the appropriate technical settings in your browser software. However, we would like to point out that in this case you may not be able to use all functions of this website to their full extent. You will then not be included in the conversion tracking statistics. You can also deactivate personalized advertising for you in the Google advertising settings. You can find instructions on how to do this at: https://support.google.com/My-Ad-Center-Help/answer/12155764.

4.4.3 Google Analytics

We use Google Analytics on our website, a web analytics service provided by Google LLC (1600 Amphitheater Parkway, Mountain View, CA 94043, USA; “Google”). Google Analytics uses “cookies”, which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of the website will generally be transmitted to and stored by Google on servers in the United States. However, if IP anonymization is activated on this website, your IP address will be shortened by Google beforehand within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.

Google will use this information on behalf of the operator of this website for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. You can prevent the storage of cookies by selecting the appropriate settings on your browser software; however, please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plug-in available at the following link:  https://tools.google.com/dlpage/gaoptout.

4.4.4 Google Tag Manager

To manage website tags via an interface, we use Google Tag Manager, a service provided by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; “Google”). The Google Tag Manager itself (which implements the tags) is a cookie-less domain and does not process any personal data. The service triggers other tags, which in turn may collect data. Google Tag Manager does not access this data. If deactivation has been carried out at domain or cookie level, this remains in place for all tracking tags that are implemented with Google Tag Manager. By using Google Tag Manager, scripts (so-called tags) can be automatically activated on our website and data can be transmitted from your browser to Google. This data may include information about your IP address, the browser you are using, the subpages of our website you have visited and other interactions during your visit to our website.

4.4.5 Google Customer Reviews

We use the Google Customer Reviews service on our website, offered by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; “Google”). Google Customer Reviews enables our customers to provide feedback on their shopping experience with us and helps us to improve our service quality and customer experience. After making a purchase on our website, you may be invited to take part in a Google Customer Reviews survey. If you choose to participate, Google will provide you with a survey in which you can rate your experience with us. The information you provide will be processed and aggregated by Google to give us an overall picture of customer satisfaction.

When you use Google Customer Reviews, data, including your IP address, the date and time of the survey and your reviews, are transmitted to Google and stored on Google servers. These servers may be located in the USA or other countries. If you do not wish to participate in Google Customer Reviews, you can simply ignore or decline the invitation to the survey. For more information about Google’s data collection and privacy practices in relation to Google Customer Reviews, please see Google’s privacy policy at https://www.google.de/intl/de/policies/privacy/ and the specific information on Google Customer Reviews.

4.4.6 Google My Business

On our website we use functions of Google My Business, a service of Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; “Google”). Google My Business enables companies to manage their presence on Google, including Google Search and Google Maps, and to interact with customers. By visiting our website or interacting with our Google My Business entry, such as leaving reviews or asking questions, data, in particular your IP address and the content of your interactions, is transmitted to Google and stored on Google servers. These servers may be located in the USA or other countries. Google uses this information to provide Google My Business services, to facilitate user interactions with companies and to provide us with reports and analyses about the interactions and performance of our company entry.

4.4.7 Google Fonts API

On our website we use the Google Fonts API, a service of Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; “Google”), to integrate fonts. By integrating these fonts, your browser will establish a connection to Google’s servers when you visit our website in order to download and correctly display the fonts. Through this connection, data, in particular your IP address and information about the browser you are using, may be transmitted to Google and stored on Google’s servers. These servers may be located in the USA or other countries. If you wish to prevent the transfer of data as part of the Google Fonts API, you can block access to the domain fonts.googleapis.com in your browser settings. Please note that in this case our website may not be displayed correctly.

4.4.8 Google Maps

On our website we use Google Maps, a map service provided by Google LLC (1600 Amphitheatre Park-way, Mountain View, CA 94043, USA; “Google”). Google Maps enables us to integrate interactive maps directly into the website and allows you to conveniently use the map function, for example to search for a location or to plan your journey. When you visit the website, Google receives the information that you have accessed the corresponding subpage of our website. In addition, further data, in particular your IP address, is transmitted to Google and stored on Google servers. These servers may be located in the USA or other countries. This occurs regardless of whether Google provides a user account through which you are logged in or whether no user account exists. Google stores your data as usage profiles and uses them for the purposes of advertising, market research and/or the needs-based design of its website. Such an evaluation is carried out in particular (even for users who are not logged in) to provide needs-based advertising. You have the right to object to the creation of these user profiles, whereby you must contact Google to exercise this right.

4.4.9 Google Site Kit

We use the “Google Site Kit” plugin, which is provided by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; “Google”), to manage and analyze our website. Google Site Kit enables us to integrate various Google services, such as Google Analytics, Google Search Console, Google AdSense and others, directly into our WordPress website and to manage them centrally. By using Google Site Kit, various data, including your IP address, information about the browser you are using, the subpages of our website you visit and other interactions during your website visit, are transmitted to Google and stored on Google servers. These servers may be located in the USA or other countries. Google uses this information to provide us with detailed reports and analyses of website traffic, the performance of our website, visitor interactions and other relevant metrics.

4.4.10 WordPress

Our website is based on the WordPress platform, a content management system developed by Automat-tic Inc, 60 29th Street #343, San Francisco, CA 94110, USA. WordPress enables us to create, manage and publish content. When you use our website, which is based on WordPress, various data, including your IP address, date and time of access and information about the browser you are using, may be collected and stored. This data is mainly used for administrative purposes and to ensure the smooth operation of the website. Some WordPress functions, such as comments or contact forms, may collect additional personal data when you use them.

4.4.11 Google reCaptcha

We use the reCAPTCHA service provided by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; “Google”) to protect against unwanted requests via the Internet form on our website. The query is used to distinguish whether the input is made by a human or abusively by automated, machine processing. As part of the query, information such as your IP address or the behavior when filling out the form may be transmitted to Google. For this purpose, your input is transmitted to Google and processed there. By using re-CAPTCHA, you consent to the recognition you have provided being incorporated into the digitization of old works. However, if IP anonymization is activated on this website, your IP address will be shortened by Google beforehand within member states of the European Union or in other contracting states of the Agreement on the European Economic Area.

Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. Google will use this information on behalf of the operator of this website to evaluate your use of this service. The IP address transmitted by your browser as part of reCAPTCHA will not be merged with other Google data.

Menu