ICU Medical, Inc. (“ICU Medical”) with its corporate headquarters at 951 Calle Amanecer, San Clemente, CA 92673, California, USA (email: email@example.com) and its affiliates take your right to privacy seriously and are committed to protecting the confidentiality of your personal information. This Website Privacy Notice (the “Notice”) provides information as to how we maintain the privacy of personal information submitted on our website (the “Site”), as well as the methods by which we maintain the security of our site. This Notice covers all personal information processed by us which means information that (either in isolation or in combination with other information) enables you to be identified directly or indirectly. In accordance with the EU General Data Protection Regulation ("GDPR"), ICU Medical is the controller of your personal information.
Visitors to the Site can access the Site's home page, and browse some areas of the Site, without disclosing any personal information. The Site will collect information provided to us by your browser, including the website you came from (known as the referring URL), the type of browser you use, the time and date of access, and other information that does not personally identify you. In addition, the Site may also automatically collect information about you, such as your IP address and domain name. We may also explicitly and with your consent request data from you (e.g. for printing requests).
We may use aggregate data about visitors to our Site for product and service development and improvement and for market analysis. We may provide information from our Site in aggregate form, with identifying information removed, to third parties. For the purposes of the GDPR, processing of personal information is necessary for our legitimate interests to maintain and develop our Site and to market, provide and improve our products and services.
Your personal information may be shared with third parties in certain circumstances: ICU Medical's group: We may share your personal information among our group of companies in order to conduct the activities described in this Notice. Our service providers: We use third parties to perform services on our behalf or to assist us the activities described in this Notice such as infrastructure and IT service providers and external auditors and advisers. We will only provide our service providers with personal information which is necessary for them to perform their services, and we require them not to use your information for any other purpose. Third parties permitted by law: We reserve the right to disclose your personal information as required by law, when disclosure may be necessary to comply with a regulatory requirement, judicial proceeding, court order, or legal process served on us, or to protect the safety, rights or property of our customers, the public or ICU Medical and its affiliates. We may also disclose your personal information to our business partners for printing and shipping documentation manuals. Third parties connected with business transfers: We may transfer your personal information to third parties in connection with a reorganisation, restructuring, merger, acquisition or transfer of assets, provided that the receiving party agrees to treat your personal information in a manner consistent with this Notice. We will not sell your personal information to third parties.
Information collected through this Site will be transferred to the U.S., which may not have an adequate data protection standard compared to the jurisdiction of your residence (e.g. the EU). For the purposes of the GDPR, we either request your consent into the transfer or we have put in place appropriate safeguards for personal information, including, where relevant, by entering into EU standard contractual clauses (or equivalent measures) with the party outside the EU (available here: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/model-contracts-transfer-personal-data-third-countries_en).
If provided, we process your personal information on the basis of consent (Article 6 (1) a) GDPR). Otherwise, we base our processing on legitimate interests as defined in Sections 4 and 5 of this Notice (Article 6 (1)f)GDPR).
We use current technical security measures to safeguard your personal information from unauthorized access or disclosure and require our business partners to follow the same standards if personal information is disclosed to them.
We will only store your personal information in accordance with storage periods as required or permitted by applicable laws and regulations (e.g. statutory periods of limitation).
The Site is not intended for persons under 16 years of age and we do not knowingly solicit or collect personal information from or about children. Our products are intended for use by providers of healthcare, and we do not knowingly market our products or services to children.
We support your personal information rights. Please contact firstname.lastname@example.org to request further information and to access, rectify, erase (‘right to be forgotten’), restrict or object to processing regarding your personal information. However, without processing your personal information, we may not be able to provide and ship printed documentation manuals. Where we have sought your consent to process your personal information, you may withdraw that consent. However, withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.
You may object to the processing of your personal information where based on legitimate interests. Unless your objection is directed solely against direct marketing by us, you have to justify that you are in a special situation, which makes the processing of your personal information based on legitimate interests unacceptable for you.
We may continue processing your personal information even after withdrawal of consent or objection if the processing is lawful according to other applicable laws and regulations as there may be. However, please take into account that without processing your personal information, we may not be able to provide and ship printed documentation manuals. You also have the right to lodge a complaint with the local data protection authority if you believe that we have not complied with applicable data protection laws. A list of local data protection authorities in European countries is available here: http://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm
Changes may be made to this Notice from time to time. Any changes will be effective immediately upon the posting of the revised Notice.
Issue date: November 22, 2018