Privacy Policy

Data protection is important to us, and we attach great importance to the protection of your data and your privacy. Below, we want to show you which data we process, when, for what purpose, and on what legal basis.

In accordance with our information obligations under the Data Protection Ordinance (DS-GVO), the Federal Data Protection Act (BDSG), and the Telemedia Act (TMG), this should enable you to understand as much as possible how our offered services work and how your personal data is protected.

1. Responsible party

The person responsible for processing personal data under Article 4 No. 7 of the GDPR:

SYMBIONT ITALIA SRL
Via Fatebenefratelli, 20
20121 Milano, Italy
Email: Kontakt
Telephone: +390289659908

Managing Director: Federico Servadio

2. Data protection contact person

If you have questions regarding the processing of your personal data, as well as your rights related to data protection, please contact:

SYMBIONT ITALIA SRL
Ufficio legale e protezione dei dati
Via Fatebenefratelli, 20
20121 Milano, Italy

3. What personal data is

Under Article 4 No. 1 DS-GVO, personal data is any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified directly or indirectly, particularly by association with an identifier such as a name, customer number, location data, online identification, or other characteristics. In the DS-GVO, this is referred to as "data subjects." Further details can be found in Article 4 No. 1 DS-GVO.

4. Data during the visit to this website

4.1 Hosting and log files

When you visit our website, our web server automatically collects data and information from your device's system and stores it in server log files. This data is automatically transmitted by your browser when you access our website:

  • Timestamp of the page request to the web server
  • URL of the web page accessed
  • Type and version of the browser used
  • The operating system transmitted to us by your browser
  • The IP address of the computer is masked, i.e., the last octet is zeroed out.

The purpose of this processing is to make our website accessible from the device you are using and to ensure the best possible presentation by adapting it. Additionally, we use this data to optimize the website and ensure system security. These data are not evaluated for marketing purposes.

The legal basis for the processing is Article 6, paragraph 1, letter f) of the GDPR. We have a legitimate interest in presenting you with a website optimized for your browser and enabling communication between our server and your terminal device. This requires, in particular, the processing of your IP address.

The data is stored for 10 days, and older logs are automatically overwritten.

The recipient of the data is our server host, which works for us under a data processing agreement:

Platform.sh GmbH
Germany

Further information on data protection at Platform.sh is available at https://platform.sh/privacy-policy/.

You have the right to object. You can exercise this right using the contact details provided for our company.

4.2 Content Delivery Network (CDN)

To ensure the best possible delivery of this site, we use the CDN service provided by Fastly. Fastly operates global traffic distribution servers that enable the quick and secure delivery of this website (Content Delivery Network). This service is connected to our web host via DNS. Technically, the flow of information between your browser and our website is routed through the Fastly network. This allows for rapid provisioning of the site and the filtering of harmful traffic through traffic analysis. Fastly uses cookies or other technologies to recognize internet users. No use beyond the described purpose takes place.

The legal basis for processing is Article 6(1)(f) of the DS-GVO. We have a legitimate interest in making our website available as quickly, accurately, and securely as possible.

The recipient of the data is the CDN operator, who works for us under a data processing agreement:

Fastly, Inc
475 Brannan St. #300
San Francisco, CA 94107
USA

Fastly, Inc. is Privacy Shield certified. For more information on Fastly's security and privacy practices, please visit https://www.fastly.com/privacy.

You have the right to object. You can exercise this right using the contact details provided for our company.

4.3 Cookies

Our website uses cookies, which are small text files stored on your device to enhance the usability of a website. These may include functionalities such as saving settings or recognizing a user’s device via a cookie ID. Cookies help us design an online offering that is as user-friendly and tailored as possible for you as a visitor to the website. We use both our own cookies and third-party cookies.

You have the option to configure the settings for these cookies at any time. This includes limiting cookie settings in your browser, disabling them entirely, or setting cookies to be automatically deleted when the browser window is closed. Additionally, you can adjust cookie settings via the pop-up window at the bottom of the page. We distinguish between the following categories of cookies:

  • Technically Necessary Cookies: These are required for the proper functioning of the website. We use them in accordance with Article 6(1)(c) DS-GVO.
  • Analytics Cookies: These measure the reach of our offering and serve to optimize it in accordance with Article 6(1)(a) DS-GVO.
  • Marketing Cookies (currently not implemented): These allow us to promote our services through interest-based advertising. This option requires approval and is implemented in accordance with Article 6(1)(a) DS-GVO.

5. Our services on this page

5.1 Contact form

A contact form is available on our website. You can use this form to contact us electronically. If you contact us through this form, the data entered in the input fields will be processed by us and include the following information:

  • Salutation
  • First and Last Name
  • Company Affiliation (if applicable)
  • Contact Information (phone, email)
  • Customer Category
  • Information entered under “Message”

When the form is submitted, the IP address (see "Log Files") and the time of submission are also saved.

Mandatory and voluntary information is treated equally by us. Mandatory data is required to contact you and process your request.

The purpose of processing personal data in the context of mandatory and voluntary information is to process the contact request and to be able to contact you. The legal basis for processing the personal data you provide as part of the contact is Article 6(1)(b) DS-GVO.

The collection of additional personal data during submission serves to prevent misuse of our contact form. The legal basis for this is our legitimate interest under Article 6(1)(f) DS-GVO in preventing misuse of the contact form or being able to document a fact.

The data will be deleted as soon as it is no longer necessary for the purpose for which it was collected.

The recipient of the data is our mail host, which works for us within the framework of a data processing agreement.

5.2 How to contact us

You have the option to contact us via mail, phone, fax, or email. Depending on the data you provide when you contact us, we will get back to you via phone, fax, or email, call you back, or write to you.

  • Mail: If you contact us by mail, we may process your address details (e.g., surname, first name, street, city, postal code), the date and time of receipt of the mail, as well as the data contained in your letter.
  • Phone: If you contact us by phone, we will process your phone number and, if necessary, your name, email address, the time of the call, and the details of your inquiry.
  • Fax: If you contact us via fax, the fax number or sender identification and the data contained in the fax will be processed.
  • Email: When contacting us via email, your email address, the time of the email, and the data from the message text (and any attachments) will be processed.

The purpose of processing the above data is to handle your inquiry and to contact you in order to respond to your request.

The legal basis for processing the personal data described here is Article 6(1)(f) DS-GVO. It is in our legitimate interest to offer you the possibility to contact us at any time and to respond to your questions.

Personal data will be processed for as long as necessary to fulfill the purpose of your contact request and will be received or processed by the following companies:

Mail Host (Microsoft Azure)

After you send us the contact form or your email, it will be received and processed by our mail host. This host works for us under a data processing agreement.

Microsoft Ireland Operations Limited
Ireland

For more information on Microsoft's privacy policy, click the following link: Microsoft Privacy Policy.

Customer Relationship Management ("CRM") HubSpot

We use HubSpot CRM as an interface between office staff and sales to address our customers' concerns as efficiently and effectively as possible. Requests sent via email or the contact form are processed by HubSpot and responded to by our staff. They work for us under a data processing agreement.

HubSpot Ireland Limited
Ireland

For more information about HubSpot's privacy policy, follow this link: HubSpot Privacy Policy.

Sales Partners

Depending on the type and content of your inquiry, we reserve the right to forward your request to our sales partners. Such forwarding of your data is based on "disclosure by transmission" under Article 6(1)(a) DS-GVO, of which you will be informed when submitting the contact form on the website:

Johnson Health Tech. GmbH
Germany

Information on data protection obligations at "Johnson Health Tech. GmbH" can be found at: Johnson Health Tech Privacy Policy.

You have the right to object to the processing and forwarding of your data. You can assert this right by using the contact details provided for our company or when your data is forwarded to our sales partners due to "disclosure by transmission."

6. Integrated services on this website

6.1 Google services

This website uses various services provided by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

By integrating Google services, Google may collect and process information, which may include personal data. It cannot be excluded that Google might transfer this information to servers in third countries.

The Privacy Shield certification indicates that Google is committed to complying with the EU-US Privacy Shield Framework and the Swiss-US Privacy Shield Framework. This applies to the collection, use, and storage of personal data from EU Member States and Switzerland. Google, including Google LLC and its wholly-owned subsidiaries in the United States, has declared through certification that it will adhere to the Privacy Shield Principles.

We cannot influence what data Google collects, processes, and stores. Google states that it processes, among others, the following information (including personal data):

  • Log data, particularly the IP address
  • Location information
  • Unique application numbers
  • Cookies and similar technologies

If you are logged into your Google account, Google may add the processed information to your account and treat it as personal data. This depends on your account settings. See specifically: https://www.google.de/policies/privacy/partners

You can prevent the direct addition of such information by logging out of your Google account or changing your account settings. You can also modify your cookie settings (delete cookies, block cookies, etc.). For more information and instructions, refer to the "Cookies" section.

Google Ads (formerly AdWords)

This website utilizes Google Ads (formerly AdWords) and, as part of Google AdWords, conversion tracking, an online advertising service provided by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Ads and Google Conversion Tracking is an analysis service by Google. When you click on an ad placed by Google, a so-called "cookie" (a text file) is stored on your device. This enables an analysis of the pages you visit on our website. This information (including your IP address) is transmitted to a Google server and stored there, potentially on servers in the United States or third countries. After 30 days, these cookies lose their validity. Within this period, Google and we can recognize when you have clicked on one of our ads and have been redirected to our website. Since every website visitor receives an individual cookie, cookies can be traced through page views of AdWords customers. However, you can restrict this possibility by modifying your cookie policy. Please refer to the "Cookies" section for more information.

The legal basis for the processing of personal data described here is Article 6(1)(a) DSGVO.

You have the right to object. You can exercise this right by using the contact information provided for our company.

Google Analytics

We use Google Analytics on our website, a web analytics service provided by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics uses cookies that enable an analysis of the use of visited websites. Google Analytics may also use "web beacons" (invisible graphics). These web beacons allow the evaluation of information such as visitor traffic on websites. The information generated by cookies and web beacons about the use of our website (including the user's IP address) is transmitted to a Google server and stored there. This server may be located in the United States or other third countries and may also be transmitted to other contractual partners of Google in accordance with Google's SLA.

Google processes the following types of data:

  • Online identifiers (including cookie identifiers)
  • IP address
  • Device ID

Detailed information about the processed data is available at https://www.google.com/intl/de/policies/privacy/#infocollect.

We use Google Analytics only with IP anonymization enabled ("anonymous IP"). Consequently, your IP address will be truncated by Google within the member states of the European Union or in other states that are part of the European Economic Area Agreement. The transfer and shortening of the IP address only occur in exceptional cases on a Google server in the USA.

Furthermore, we have entered into a contract with Google for the use of Google Analytics for order processing (Article 28 DS-GVO). Google processes the data on our behalf to evaluate the use of our website, compile reports on our site’s activities, and provide related services. Google may transfer this information to third parties if required by law or if such third parties process the data on behalf of Google.

Integrating Google Analytics allows us to analyze user behavior on our website, which helps us improve our offerings in a targeted manner. The legal basis for the processing of personal data described here is Article 6(1)(a) DSGVO. Within the scope of order processing, Google is authorized to employ subcontractors. The list of these subcontractors is available at https://privacy.google.com/businesses/subprocessors/. The data processed is retained as long as necessary for the described purpose or as required by law.

You have the right to object. You can exercise this right by using the contact information provided for our company.

Providing personal data is not required by law or contract and is not necessary for concluding a contract. You are also not obligated to provide personal data. However, failure to provide such data may mean that you are unable to use our website or may not be able to use it fully.

Google Tag Manager

We use Google Tag Manager on our website. Google Tag Manager is a service provided by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Tag Manager allows us to integrate various codes and services on our website in an orderly and simplified manner. Google Tag Manager implements or separates tags. Google may process information (including personal data). It cannot be ruled out that this information is transferred to a server in the United States or third countries. In particular, the following personal data are processed by Google Tag Manager:

  • Online identifiers (including cookie identifiers)
  • IP address

Detailed information about the integration of Google Tag Manager is available at the following link: https://www.google.de/tagmanager/use-policy.html

Additionally, we have entered into a contract with Google for the use of Google Tag Manager for order processing (Article 28 DS-GVO). Google processes data on our behalf to trigger embedded tags and display services on our website. Google may also transfer this information to third parties if required by law or if such third parties process this information on behalf of Google.

If you have disabled individual tracking services, the deactivation will remain effective for all tracking tags implemented via Google Tag Manager. This can be done through the opt-out option for cookies or third-party tools.

By integrating Google Tag Manager, we aim for a simplified and clear integration of various services. Additionally, integrating Google Tag Manager optimizes the loading times of these services.

The legal basis for the processing of personal data described here is Article 6(1)(a) DSGVO.

The processed data are retained as long as necessary for the intended purpose or as required by law.

You have the right to object. You can exercise this right using the contact information provided for our company.

Providing personal data is not required by law or contract and is not necessary for the conclusion of a contract. You are also not obligated to provide personal data. However, failure to provide this data may mean that you are unable to use our website or may not be able to use it fully.

Use of YouTube

We use YouTube videos and plugins on our website. YouTube is a service provided by YouTube LLC ("YouTube"), 901 Cherry Ave., San Bruno, CA 94066, USA. YouTube LLC is a subsidiary of Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

YouTube is integrated into our website by embedding the service through "iFrames". When this iFrame is loaded, YouTube or Google may collect and process information (including personal data). It cannot be ruled out that YouTube or Google may transfer the information to a server in a third country.

By integrating YouTube, we aim to present various videos on our website so you can watch them directly on our site.

The legal basis for the processing of personal data described here is Article 6(1)(f) DSGVO. Our legitimate interest lies in the benefits YouTube provides through its platform. By embedding external videos via YouTube, we reduce the load on our servers and increase loading speeds by automatically providing different playback qualities. Additionally, YouTube and Google have a legitimate interest in the data (personal) collected to improve their services.

Providing personal data is not required by law or contract and is not necessary for the conclusion of a contract. You are also not obligated to provide personal data. However, failure to provide such data may mean that you are unable to use our website or may not be able to use it fully.

6.2 Facebook services

We use various Facebook services on our website. "Facebook" is operated by Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.

Facebook Pixel

Through Google Tag Manager, we have installed Facebook Pixels on the website. This is retrieved from a Facebook server when a page is accessed, recording the visit to the page. This allows us to use "Facebook Custom Audience." According to information provided by Facebook, the following data may be recorded (including personal data):

  • Browser information
  • Websites visited
  • Hash ID of the Facebook user on the website

For more information on Facebook Pixels, visit: https://www.facebook.com/business/help/651294705016616.

Custom Audience

The marketing tool is a targeting option that uses the integrated Facebook Pixel to match data from visitors to our website with users on Facebook. This allows us to target groups of visitors with advertisements on the Facebook platform. Additionally, this service helps reduce waste in marketing efforts.

For more information about Facebook Custom Audiences, visit the following links:

Facebook Conversions

This service enables easier communication through Facebook chat and is integrated with "Hubspot CRM." For further details, please refer to the "Contact Us" section.

In the case of services used by Facebook, it cannot be excluded that Facebook may transfer the information to a server in the United States or another third country.

The Privacy Shield certification indicates that Facebook, Inc. is committed to complying with the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework. This applies to the collection, use, and storage of personal data from EU member states and Switzerland. Facebook, Inc. has declared, through certification, its compliance with the Privacy Shield Principles.

You can find the Privacy Shield certification entry at the following link: https://www.privacyshield.gov/list

Information on how Facebook, Inc. complies can be found at: https://de-de.facebook.com/about/privacyshield

The legal basis for the processing of personal data described here is Article 6, paragraph 1, letter a) DSGVO. Regarding the retention period of information, Facebook states that data will be retained as long as necessary to provide users or others with products and services.

For more information and contact details, follow the link: https://de-de.facebook.com/about/privacy/ and at the following addresses:

If you live in the United States or Canada:

Facebook, Inc.
1601 Willow Road
Menlo Park, CA 94025

If you live in the rest of the world:

Facebook Ireland Ltd.
4 Grand Canal Square
Grand Canal Harbour, Dublin 2
Ireland

Privacy Policy for our Facebook fan page insights

Facebook Ireland Ltd ("Facebook") provides us, as the operator of the Facebook fan page, with the so-called "Facebook Insights" ("Insights"). Insights are various statistics that provide us with information about the usage of our Facebook fan page. Detailed information is available at https://www.facebook.com/business/a/page/page-insights.

For the compilation of these statistics, various information provided by you (including personal data) is processed by Facebook. Personal data is processed by Facebook and by us as joint controllers pursuant to Article 26 DSGVO. Below we provide the key information of the agreement concluded between Facebook and us (https://www.facebook.com/legal/terms/page_controller_addendum) under Article 26 DS-GVO.

Information on the agreement concluded between Facebook and us as joint controllers

I. Designation of Joint Controllers

Joint controller for the processing

Facebook Ireland Ltd
4 Grand Canal Square
Dublin 2
Ireland

and

schwa-medico, Medizinische Apparate, Vertriebsgesellschaft mbH
Wetzlarer Str. 41-43
35630 Ehringshausen
Germany

Phone: +49 6443 8333 - 0
Fax: +49 6443 8333 - 119
E-mail: info@schwa-medico.de

II. Responsibility in relation to the processing of Insights data

Facebook has assumed primary responsibility (fulfillment of all obligations under the DS-GVO) for the processing of data. This specifically includes:

  • Facebook assumes the necessary information obligations (e.g., Article 13 DSGVO).
  • The rights of the data subjects can be asserted directly against Facebook (e.g., the right to information or deletion, objection to data processing, or revocation of consent granted; see also the section "V. Rights of Data Subjects").
  • Ensuring the technical and organizational measures for data processing.

Facebook provides comprehensive information on data processing at www.facebook.com (Article 13 DS-GVO). To give you an overview of the essential information, we also refer to the content provided by Facebook as part of this data protection notice.

Notwithstanding Facebook's agreed-upon primary responsibility, you may of course also assert your rights under the DSGVO directly against us. We will immediately forward such requests to Facebook using a form available for this purpose.

1. Legal Basis for Processing

The legal bases and purposes for Facebook's processing can be found at https://www.facebook.com/about/privacy/legal_bases and https://de-de.facebook.com/policy.php. Our legal basis for processing Insights data is our legitimate interest pursuant to Article 6, Paragraph 1, Letter f) DSGVO. We have a legitimate interest in being able to track user behavior on our Facebook fan page. Specifically, this allows us to measure the reach and effectiveness of our campaigns, posts, and other activities through prepared statistics. This enables us to continuously optimize our website and services in line with demand. This also constitutes the purpose of the processing for us.

2. Data Processing on a Facebook Fan Page

Facebook may process the following data in particular:

  • User interaction (click behavior, messages, "likes," video views, page visits, etc.)
  • Cookies
  • Demographic characteristics (age, gender, federal state, etc.)
  • IP address
  • System and device information (e.g., browser type, operating system, etc.)

The exact processing of your data when visiting our Facebook fan page depends on whether you have a Facebook account:

  • If you have a Facebook account, Facebook may permanently link the data to your account to learn more about you.
  • If you do not have a Facebook account, Facebook may still store your data. This can be done through the use of cookies, which are typically small text files stored on your device. These text files contain various pieces of information that can be read later. This enables Facebook to store and process information about you even if you do not have a Facebook account. More detailed information about Facebook's cookies is available at https://de-de.facebook.com/policies/cookies/.

In the context of using Insights, we only receive anonymous statistics from Facebook about the use of our fan page. We can only see how many users performed certain interactions but not which specific user performed a given action. The Insights data statistics do not allow us to draw conclusions about any individual.

3. Diritti degli interessati

Rights of Data Subjects

  • Right to information (Article 15 DS-GVO)
  • Right to rectification (Article 16 DS-GVO)
  • Right to objection (Article 21 DS-GVO)
  • Right to erasure (Article 17 DS-GVO)
  • Right to restrict processing (Article 18 f. DS-GVO)
  • Right to data portability (Article 20 DS-GVO)

You have the right to revoke your consent at any time with effect for the future, without affecting the lawfulness of the processing carried out based on the consent before its revocation.

You can assert these rights directly against Facebook or us (see section "II. Responsibility in relation to Insights data processing"). If you wish to assert your rights against us, please contact us at datenschutz@schwa-medico.de and describe your specific concern as precisely as possible.

You have the right to object to the processing of cookies. You can exercise this right, for example, as follows:

  • In your browser settings, you can restrict or completely prevent the placement of cookies. You can also arrange for cookies to be automatically deleted when the browser window is closed. For more information or instructions on how to proceed, please refer to the "Cookies" section.

  • You can also adjust your settings for the use of cookies at https://de-de.facebook.com/policies/cookies/. Here you will find, under the sections "If you have a Facebook account (Facebook account available)" and "Public (no Facebook account available)" information on how you can object to processing with Facebook.

You can determine the storage period of cookies via your browser by displaying the cookies (usually by clicking on the "i" next to the address bar, e.g., in Firefox or Google Chrome).

7. General notes on the provision of data

The provision of personal data is not required by law or contract and is not necessary for the conclusion of a contract. The user is also not obliged to provide personal data. However, failure to provide data may result in the inability to use our offer or only being able to use it in a limited form.

8. Social networks and external links

In addition to this website, we also maintain presences on various social media platforms, which you can access via the corresponding buttons on our website. If you visit such a presence, personal data may be transmitted to the social network provider.

We would like to point out that the information (including personal data) may be transferred to a server in a third country and that the data may therefore be processed outside the European Union. US providers certified under the Privacy Shield have committed to complying with EU data protection standards. Further information is available at https://www.privacyshield.gov/Program-Overview.

Additionally, it is possible that, in addition to storing the data you enter in this social media, further information may also be processed by the social network provider. This includes, for example, key data about your computer system from which you are visiting (IP address, type of processor used, browser version, and plugins used). If, during the visit to such a website, you are logged in with a user account of the respective network, the corresponding page may associate this visit with your account.

For the purposes, scope, and further processing of your data, as well as your rights in this regard, please refer to the respective provisions of the responsible party.

We would also like to point out that our website contains additional links to external third-party websites, over which we have no influence on the data processing of these third-party websites.

9. Data security

We protect our website and all other related systems with technical and organizational measures against the loss, destruction, access, modification, or distribution of your data by unauthorized persons. However, despite regular checks, complete protection against all risks is not possible.

10. Revocation

You have the right to revoke your consent at any time with future effect, without affecting the legality of the processing carried out based on the consent until revocation.

11. Rights of data subjects

In principle, you have the following rights:

  • Right to information (Art. 15 DSGVO)
  • Right to rectification (Art. 16 DSGVO)
  • Right to object (Art. 21 DSGVO)
  • Right to erasure (Art. 17 DSGVO)
  • Right to restriction of processing (Art. 18 et seq. DSGVO)
  • Right to data portability (Art. 20 DSGVO)

For such requests, please contact datenschutz@schwa-medico.de. Please note that for such requests, we must ensure that the person concerned is indeed the data subject.

You also have the right to appeal to a data protection supervisory authority, without prejudice to any other administrative or judicial remedy.

Automated decision-making ("profiling") does not take place on our website.


Via Fatebenefratelli, 20/20121 Milano, Italy

Date: November 2020 / The German version applies.