Data protection
action medeor pays attention to the protection of your personal data.
action medeor takes the protection of personal data seriously. On this site, we offer all information about data storage and when and how data is processed. Both action medeor and our external service providers ensure compliance with legal regulations by technical and organizational measures.
We are very pleased about your interest in our organization. Data protection is of major importance for the board of action medeor. As a matter of principle, action medeor’s websites can be used without providing any personal data. If a person would like to take up special services from our organization via our website, this might however necessitate processing personal data. We always obtain the data subject’s consent if personal data need to be processed, and if there is no statutory basis for such processing.
Personal data such as a data subject’s name, postal or e-mail address or telephone number are always processed in accordance with the General Data Protection Regulation, and with the country-specific data protection regulations applying to action medeor. Our organization would like to use this Data Protection Statement to inform the public of the nature, extent and purpose of the personal data that we collect, use and process. This Data Protection Statement furthermore informs data subjects of their rights.
As the controller, action medeor has implemented numerous technical and organizational measures in order to ensure optimum protection of the personal data that are processed via this website. Internet-based data transmission may nonetheless as a matter of principle entail gaps in security, so that it is not possible to guarantee complete protection. Each data subject is therefore also free to transmit personal data to us by alternative means, such as the telephone.
Definitions
action medeor’s Data Protection Statement is based on the definitions applied by the European legislature when issuing the General Data Protection Regulation (GDPR). Our Data Protection Policy is to be easy to read and understand, both for the public as well as for our customers and business partners. In order to ensure this, we would like to start by explaining the terms that we have used.
We use the following terms, amongst others, in this Data Protection Statement:
Personal data
Personal data are any information relating to an identified or identifiable natural person (‘data subject’). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Data subject
A data subject is any identified or identifiable natural person whose personal data are processed by the controllers.
Processing
Processing is any operation or set of operations which is performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Restriction of processing
Restriction of processing is the marking of stored personal data with the aim of limiting their processing in the future.
Profiling
Profiling is any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements.
Pseudonymisation
Pseudonymisation is the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.
Controller
The controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
Processor
The processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Recipient
The recipient is a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law are not regarded as recipients.
Third party
A third party is a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorized to process personal data.
Consent
The consent of the data subject is any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
Cookies
action medeor’s websites use cookies. Cookies are text files which are stored on a computer system via a browser.
Large numbers of websites and servers use cookies. Many cookies contain what is referred to as a cookie ID. A cookie ID serves to unambiguously identify the cookie. It consists of a series of characters allowing websites and servers to be traced to a specific browser on which the cookie has been stored. This enables the websites and servers that have been visited to distinguish between the individual browsers of the data subject and other browsers containing different cookies. A specific browser can be recognized and identified using the unambiguous cookie ID.
Using cookies allows action medeor to provide users of this website with more user-friendly services, which would not be possible without using cookies.
Cookies can be used to optimize the information and services on our website to benefit users. As was mentioned above, cookies enable us to recognize our website’s users. This recognition is used to make our website easier to use. The users of a website, which uses cookies, do not for instance need to re-state their login data each time they visit the website because the website does so using a cookie that has been stored on the user’s computer system. A further example is the cookie of a basket in the online shop. The online shop uses a cookie to remember the articles, which a customer has placed in the virtual basket.
The data subject can prevent cookies being created by our website at any time via the browser settings, and thus stop any cookies ever being created. What is more, once cookies have been created, they can be deleted at any time by a browser or other programs. All the common browsers allow this. If the data subject deactivates the creation of cookies in the browser that they are using, this may prevent all the functions of our website being used to the full.
Collecting general data and information
action medeor’s website collects a series of general data and information each time a data subject or an automated system visits the website. These general data and information are stored in the server’s log files. It is possible to record (1) the browser types and versions used, (2) the operating system used by the system accessing the site, (3) the website from which an accessing system reaches our website (“referrer”), (4) the sub-websites on our website which are addressed by a system accessing the site, (5) the date and time of access to the website, (6) an Internet protocol address (IP address), (7) the Internet service-provider of the system accessing our site, and (8) other similar data and information serving the prevention of dangers in the event of attacks on our IT systems.
action medeor does not draw any conclusions regarding the data subject when using these general data and information. This information is in fact needed in order to (1) correctly present the content of our website, (2) optimize the content of our website and advertising for it, (3) guarantee the long-term functionality of our IT systems and of the technology used on our website, as well as (4) provide the criminal prosecution authorities with information needed for prosecution in the event of a cyber attack. These data and information, which are collected on an anonymous basis, are therefore evaluated by action medeor both statistically, as well as with the aim in mind of increasing data protection and data security in our organization in order to ultimately ensure an optimum level of protection for the personal data that we process. The anonymous data contained in the server log files are stored separately from all personal data provided by a data subject.
Registration on our website
The data subject is able to register on the controller’s website, thereby providing personal data. What personal data are transmitted to the controller emerges from the respective form that is used for registration. The personal data that are input by the data subject are only collected and stored by the controller for its own purposes and for internal use. The controller can have them passed on to one or several processors, such as a parcel service-provider, who is also to only use the personal data for internal purposes attributed to the controller.
Registration on the controller’s website also causes the IP address issued by the data subject’s Internet service-provider (ISP), as well as the date and the time of registration, to be stored. These data are stored because this is the only way to prevent our services being misused, and these data make it possible to detect criminal offences where necessary. This necessitates the storage of these data as security for the controller. These data are not passed on to third parties as a matter of principle unless this is required by law or they are passed on for the purpose of criminal prosecution.
Registration by the data subject, voluntarily providing personal data, helps the controller to offer the data subject content or services which, given their nature, can only be offered to registered users. Registered users are free to change the personal data provided on registration at any time, or to have them completely erased from the data held by the controller.
The controller provides any data subject with information, on request at any time, as to what personal data are stored regarding him or her. The controller also corrects or erases personal data, on request or notification by the data subject, unless obliged to store them by law. A data protection officer named in this Data Protection Statement, and all the employees of the controller, are available to the data subject as contact persons in this context.
Subscription to our newsletter
On our website, users will be given the opportunity to subscribe to our e-mail newsletter. The input mask used for this purpose provides information on the personal data that will be transmitted to the controller when the newsletter is ordered.
action medeor regularly informs partners about our activities via our newsletter. The newsletter can only be received by the data subject if (1) the data subject has a valid e-mail address and (2) the data subject subscribes to the newsletter. For legal reasons, a confirmation e-mail will be sent to the e-mail address entered by the data subject after the subscription, using the double-opt-in procedure. This confirmation e-mail is used to check whether the owner of the e-mail address as the data subject authorized the receipt of the newsletter.
When subscribing to our newsletter, we also store the IP address issued by the data subject’s Internet service-provider (ISP) at the time of subscription, as well as the date and time of subscription. This data is stored in order to be able to detect the (possible) misuse of a data subject’s e-mail address at a later date and therefore serves as legal safeguard for the controller.
The personal data collected in the context of registering for the newsletter will only be used to send our newsletter. Additionally, the recipients could be informed via e-mail if necessary for the operation of the newsletter tool or registration (this could occur in case of changes to the newsletter offer or changes in the technical conditions). There will be no transfer of the personal data collected as part of the newsletter service to third parties. The subscription to our newsletter may be cancelled by the data subject at any time. The consent to the storage of personal data that the data subject has given us for the newsletter dispatch can be revoked at any time. There is a corresponding link in each newsletter, which can be used to unsubscribe to our newsletter. It is also possible to communicate this to the controller via e-mail.
Newsletter tracking
The newsletters of action medeor contain so-called web beacons. A web beacon is a miniature graphic, which is embedded in such e-mails sent in html format to enable log file recording and log file analysis. This allows a statistical analysis of the success or failure of online marketing campaigns. With the embedded web beacon, action medeor can detect if and when an e-mail was opened by the data subject and which links in the e-mail have been opened by the data subject.
We store and evaluate this information provided by the web beacon to optimize the delivery of our newsletter and to better adapt the content of future newsletter to the interest of the data subject. We do not transfer this personal data to third parties. The data subject can revoke its consent given during the double-opt-in procedure at any time. After revocation, this personal data will be deleted by the controller. If you unsubscribe from receiving our newsletter, action medeor automatically interprets this as a revocation.
Contact available via our website
On the basis of statutory provisions, action medeor’s website contains information enabling our organization to be contacted quickly by electronic means, as well as direct communication with ourselves, including a general e-mail address. If a data subject contacts the controller by e-mail or via a contact form, the personal data provided by the data subject are automatically stored. These personal data voluntarily provided to the controller by a data subject are stored for the purpose of processing or for contacting the data subject. These personal data are not forwarded to third parties.
Routine deletion and blocking of personal data
The controller only processes and stores the data subject’s personal data for the time required to achieve the purpose of storage, or where provided for by the European legislature or another legislature in laws or regulations to which the controller is subject.
Should the purpose of the storage cease to apply, or should a storage period prescribed by the European legislature or another competent legislature expire, the personal data are routinely blocked or erased in accordance with the statutory provisions.
Data protection rules regarding the use of Google Analytics (with anonymisation function)
The controller has integrated the Google Analytics component (with anonymization function) on this website. Google Analytics is a web analytics service. Web analytics consist of gathering, collecting and evaluating data regarding the conduct of visitors to websites. Amongst other things, a web analytics service collects data regarding from which website a data subject came to a website (“referrers”), which sub-pages of the website were accessed, or how often, and for what period a sub-page was viewed. Web analytics are largely used to optimize a website and for a cost-benefit analysis of Internet advertising.
The Google Analytics component is operated by Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.
The controller uses the "_gat._anonymizeIp" feature for web analytics via Google Analytics. Google uses this feature to truncate and anonymize the IP address of the data subject’s Internet connection if access to our websites comes from a Member State of the European Union or from another Contracting State of the Treaty on the European Economic Area.
The purpose of the Google Analytics component is to analyze the flow of visitors to our website. Amongst other things, Google uses the data and information obtained in order to evaluate the use of our website, to compile online reports for us illustrating activities on our websites, and to provide other services linked to the use of our website.
Google Analytics places a cookie on the data subject’s IT system. We explained above what cookies are. Google places cookies to enable an analysis of how our site is used. Every time one of the individual pages of this website which is operated by the controller is visited on which a Google Analytics component was integrated, the respective Google Analytics component automatically causes the browser on the data subject’s IT system to send data to Google for online analysis. As part of this technical process, Google obtains personal data, such as the data subject’s IP address, enabling Google amongst other things to ascertain visitors’ origin and clicks, and thus to enable commissions to be charged.
The cookie is used to store personal information, such as the access time, the location from which access was made, and the frequency of the visits to our website by the data subject. When visiting our websites, these personal data, including the IP address of the Internet connection used by the data subject, are transmitted to Google in the United States of America. These personal data are stored by Google in the United States of America. Google may pass these personal data collected via the technical process on to third parties.
As explained above, the data subject can prevent our website from placing cookies at any time by selecting the appropriate setting on the browser used, thus permanently objecting to cookies being placed. This browser setting would also prevent Google placing a cookie on the data subject’s IT system. A cookie that Google Analytics has already placed can also be erased at any time using the browser or other programs.
The data subject can also object to and prevent the data created by Google Analytics related to the use of this website and the processing of these data being stored by Google. In order to do so, the data subject must download and install a browser add-on by following the link tools.google.com/dlpage/gaoptout. This browser add-on informs Google Analytics via JavaScript that no data or information may be transmitted to Google Analytics regarding visits to websites. Google regards the installation of the browser add-on as constituting an objection. If the data subject’s IT system is erased, formatted or re-installed at a later date, the data subject will need to re-install the browser add-on to deactivate Google Analytics. If the browser add-on is uninstalled or deactivated by the data subject or another person within his or her area of responsibility, the browser add-on can be re-installed or re-activated.
Further information and Google’s valid Privacy Policy can be downloaded at https://policies.google.com/privacy?hl=en&gl=en and https://www.google.com/analytics/terms/us.html . Google Analytics is explained in greater detail at this link https://www.google.com/intl/en_en/analytics/#?modal_active=none.
Statutory or contractual provisions for the preparation of the personal data; necessity for the conclusion of a contract; obligation incumbent on the data subject to provide the personal data; possible consequences of non-provision
We would like to inform you below that the provision of personal data is stipulated by law in some cases (e.g. fiscal regulations), or may emerge from contractual provisions (e.g. information regarding the contracting partner). It may be necessary at times in order to conclude a contract for a data subject to provide us with personal data, which we then need to process. The data subject is for instance obliged to provide us with personal data if our organization concludes a contract with him or her. Not providing the personal data would make it impossible to conclude the contract with the data subject. Before data are provided by the data subject, the data subject must approach our data protection officer. Our data protection officer informs data subjects in individual cases whether the personal data must be provided for legal or contractual reasons, or if they are needed in order to conclude the contract, whether there is an obligation to provide the personal data, and what would be the consequences of failing to provide the personal data.
Existence of automated decision-making
As a responsible organization, we do not use automated decision-making or profiling.
Photos of employees
We point out that photos of employees are legally protected according to § 22 German KUG (right regarding the own picture). In particular, download, manipulation, publication or duplication of photos are not allowed. Any violation of the right regarding the own picture may result in claims for omission or compensation.
Update of the data protection statement
If it will be necessary, action medeor will update the security and data protection measures. In this case, the data protection statement will be adjusted accordingly. Please note the current version of our data protection statement.
Questions and comments
For questions, suggestions, and comments regarding data protection please contact us via e-mail: info@medeor.de