<p>We will use the personal data collected about you for the specific purposes as detailed below.</p>
<p>Please note that in some cases, you have no choice but to provide your personal data to us when you make use of our products or services. In other cases, however, the provision of your personal data is voluntary. This can still mean that if you choose not to provide your personal data it might not be possible for us to provide you the products and/or services you request. We will inform you in the appropriate places, whether online or offline, if the provision of your personal data is mandatory in a particular scenario and what the consequences are if you do not provide your personal data.</p>
<p>The purposes and the legal basis for processing your personal data are the following:</p>
<h6 class="header-6">To follow the on-boarding process for customers</h6>
<p>We process your personal data when you request to register you as a Customer, which gives you the possibility to issue orders. The data we collect and process for this purpose includes your first name, last name, email address, and information about your organization/company. We process this information with the purpose of registering you as a Customer. We will retain your personal data for this purpose for as long as you have an active commercial relation with us, unless we are legally required and/or permitted to retain your personal data for a period thereafter.</p>
<p>We process your personal data for this purpose on the basis of article 6.1 (b) GDPR (performance of a contract, including pre-contractual measures) and, as the case may be, on the basis of article 6.1(c) (compliance with a legal obligation) or 6.1 (f) GDPR (our legitimate interest of considering and managing new business relationships).</p>
<p>For more information about your statutory rights, please refer to section 7 of this privacy statement.</p>
<h6 class="header-6">To create your Medline user account</h6>
<p>We process your personal data when you request the creation of a Medline user account via our Medline website, our customer service or your account manager, which you can use to consult invoices and historical purchases you made and issue your order via our e-commerce platform. The data we collect and process for this purpose includes your first name, last name, email address, and information about your organization/company. We process this information with the purpose of creating your user account. We will retain your personal data for this purpose in accordance with the retention period described in section 6 of this privacy statement.</p>
<p>We process your personal data for this purpose on the basis of article 6.1(a) GDPR (your consent) or 6.1(b) GDPR (performance of a contract, including pre-contractual measures).</p>
<p>For more information about your statutory rights, please refer to section 7 of this privacy statement.</p>
<h6 class="header-6">To manage our business relationship with you</h6>
<p>We process your personal data when you interact with us as a current or prospective supplier or customer or other business contact, via email, telephone, our website and e-commerce platform, and offline. The personal data we process for this purpose includes your name, contact details, information about your organization/company and your function, and other information that is exchanged in the context of our business relationship. We process this information for the purpose of managing product orders, supplies, deliveries, and after sales services, as applicable. We will retain your personal data for this purpose in accordance with the retention period described in section 6 of this privacy statement.</p>
<p>We process your personal data for this purpose on the basis of article 6.1 (b) GDPR (performance of a contract, including pre-contractual measures) and, as the case may be, on the basis of article 6.1(c) (compliance with a legal obligation) or 6.1 (f) GDPR (our legitimate interest of managing our business relationships).</p>
<p>For more information about your statutory rights, please refer to section 7 of this privacy statement.</p>
<h6 class="header-6">To send you marketing and other related communications</h6>
<p>We process your personal data when you subscribe to receive marketing or related communications, which includes relevant news, articles, whitepapers, event invitations, and updates on Medline and its products. The data we collect and process for these purposes includes your name, contact details, job title, which part of the world you are in, information about your organization/company and its healthcare focus. We process this information for the purpose of sending you our marketing and/or related communications as per your request. We will retain your personal data for this purpose for as long as you have an active subscription to receive our marketing or related communications, unless we are legally required and/or permitted to retain your personal data for a period thereafter. Please refer to section 6 of this privacy statement on Medline’s approach to retaining your personal data.</p>
<p>We process your personal data for this purpose on the basis of article 6.1 (a) GDPR (your consent). If you are an existing customer we may process your personal data for this purpose on the basis of article 6.1 (f) GDPR (our legitimate interest of executing marketing activities).</p>
<p>You may withdraw your consent and unsubscribe to receiving marketing or related communications at any time. You can unsubscribe anytime using the link at the bottom of any email you receive from us.</p>
<p>Please note that Medline reserves the right to communicate with you about important matters relating to its products, services or purchases you have made (e.g. product recalls, warranty or service related issues). It is not possible to withdraw your consent or unsubscribe from receiving such transactional or product-generated emails sent in connection with your use of our products and services.</p>
<p>For more information about your statutory rights, please refer to section 7 of this privacy statement.</p>
<h6 class="header-6">To optimize and improve our communication with you</h6>
<p>We process your personal data to monitor and scoring your interactions with our email marketing communications, your purchase history, and other interactions that you may have with us to better understand your needs as a customer and improve our communication with you. The personal data we process for this purpose includes your name, contact details, information about your organization/company and information about your interactions with Medline. To the extent possible, we will process aggregated data (i.e. data that cannot identify you or be linked to you, such as statistical data), pseudonymised or anonymised data, rather than personal data that allows us to directly identify you. We process this information for the purpose of better understanding our customers' needs and preferences in order to improve our communication with you and to offer you relevant product information. The use of monitoring and lead scoring techniques are not fully automated process and they will under no circumstances have legal or other significant consequences for you. We will retain your personal data for this purpose in accordance with the retention period described in section 6 of this privacy statement.</p>
<p>We process your personal data for this purpose on the basis of article 6.1 (f) GDPR (our legitimate interest of optimizing and improving our products and services).</p>
<p>For more information about your statutory rights, please refer to section 7 of this privacy statement.</p>
<h6 class="header-6">To optimize and improve our website(s)</h6>
<p>When you visit our website(s), we also collect data about you by using cookies and similar techniques. For more information about cookies, the way we use them and how to delete cookies, you can read our Cookies Statement.</p>
<h6 class="header-6">To optimize and improve our website(s)</h6>
<p>We process your personal data when you contact us via our online contact form, via email, telephone, fax, social media or regular mail. The personal data we process for this purpose depends on how and why you contact us, but will always include your name, contact details and information relating to your question or request. We process this information for the purpose of contacting you and responding to your question or request. We will retain your personal data for this purpose in accordance with the retention period described in section 6of this privacy statement.</p>
<p>We process your personal data for this purpose on the basis of article 6.1 (a) GDPR (your consent) or, as the case may be, on the basis of article 6.1 (b) GDPR (performance of a contract, including pre-contractual measures) or, where we are legally obliged to respond to your queries, on the basis of article 6.1 (c) (compliance with legal obligation).</p>
<p>For more information about your statutory rights, please refer to section 7 of this privacy statement.</p>
<h6 class="header-6">To invite you for a Medline webinar or event and to register your attendance</h6>
<p>We process your personal data when you register for and attend to an (online) Medline webinar or event via our online registration form or via email, as the case may be. The personal data we process for this purpose includes your first name, last name, email address, job title, your country and/or you’re your city/region where you work, and information about your organization/company. We process this information for the purpose of inviting you for our webinar or event, for communicating with you about the webinar or the event, for registering your attendance, and for evaluation of the webinar or event. If you are an existing customer we will retain your personal data for as long as our commercial relationship lasts. If you just signed up for one of our webinars, we will retain your personal data for as long as it is necessary to conduct the webinar. In this case, your personal data will be deleted after the webinar if you did not consent for other purposes.</p>
<p>In case of an offline event, we may – subject to your consent - take photographs or have photographs taken at the event and/or ask if you have any diet restrictions (whereby your response may include health related data), which we shall only process for the purpose of offering you alternative dietary options at our event.</p>
<p>We process your personal data for this purpose on the basis of article 6.1 (b) GDPR (performance of a contract, including pre-contractual measures) and, where required, on the basis of article 6.1 (a) GDPR (your consent). We process your diet (health) related information on the basis of article 9.2 (a) GDPR (explicit consent).</p>
<p>For more information about your statutory rights, please refer to section 7 of this privacy statement.</p>
<h6 class="header-6">To register your visit to a Medline facility and to secure our premises</h6>
<p>We process your personal data when you visit one of our Medline facilities as a guest. The data we process includes your name, contact details, and information about your organization/company, which we process for the purpose of visitor registration for security reasons. We will retain your personal data for this purpose for as long as 3 months, unless we are legally required and/or permitted to retain your personal data for a period thereafter.</p>
<p>We also use camera security/CCTV at our locations for security reasons, which may capture your presence at our Medline facilities. We will retain CCTV footage for as long as 4 weeks, unless we are legally required and/or permitted to retain your personal data for a period thereafter.</p>
<p>We process your personal data for these purposes on the basis of article 6.1 (f) GDPR (our legitimate interests of protecting our premises).</p>
<p>For more information about your statutory rights, please refer to section 7 of this privacy statement.</p>
<h6 class="header-6">To comply with our legal obligations</h6>
<p>We process your personal data when this is necessary for us to comply with our legal obligations or is otherwise necessary in view of our legitimate interests, which may include the prevention and detection of fraud and other criminal activities, protecting the rights, safety and property, of Medline, you, and/or others, satisfying Medline’s audit requirements, the resolution of disputes and disputed payment transactions, the establishment, exercise or defence of legal claims, protecting information security or the retention and disclosure of information as required by applicable legislation and/or public authorities.</p>
<p>We process your personal data for these purposes on the basis of article 6.1 (c) GDPR) (compliance with our legal obligation) and article 6.1 (f) GDPR (our legitimate interest of protecting our business), as applicable.</p>
<p>For more information about your statutory rights, please refer to section 7 of this privacy statement.</p>
<h6 class="header-6">To comply with our Materiovigilance obligations</h6>
<p>For this purpose Medline International France SAS will be the data controller, which will process your personal data to manage the adverse health event that you reported to us. If you report to us an adverse health event with one of our products that you are not exposed to, we remind you that Medline does not need to process any personal data related to the patient or the person affected by the event. In the case that patient data is included in the report, we inform you that Medline has processes in place to anonymize or delete such personal data.</p>
<p>Medline will process your personal data to enable the prevention, monitoring, evaluation and management of adverse health events that the use of our products may produce. Medline will collect, analyse, document and store your personal data to conduct the necessary investigation about the event. As a part of the investigation, we may need to use your personal data to contact you.</p>
<p>Medline will process the contact details, included but not limited to first name, last name, email address, and phone number, of the person that reports the adverse health event to us.</p>
<p>We process your personal data only if such processing is justified by a legal obligation and in accordance with the data protection regulations. Therefore, we will only process your personal data if the processing is necessary to comply with our legal obligations relating to the safety of medical devices.</p>
<p>Medline will share your personal data with the following recipients and for the following purposes:</p>
<ul>
<li>Medline International Germany GmBH for support in the management of the adverse health event reports as part of the Quality Assurance function that manage the adverse health event reports in Medline.</li>
<li>British Standard Institution (BSI) as Medline’s external auditor for the ISO quality certification. BSI is an organization based in the UK and therefore we inform you that Medline is conducting an International Transfer with your personal data. The UK has an adequacy decision made by the European Commission ensuring that the level of protection of your personal data is equivalent to the level of protection established by the GDPR.</li>
</ul>
<p>We will keep your personal data for the necessary period to perform our investigation about the reported adverse health event. Once the investigation is closed we will store your personal data for a period of 10 years as required by law. During these 10 years, your personal data will be blocked and only accessible to the relevant functions that may access and process your personal data to comply with a legal obligation or for the defence of legal claims. After this period, we will delete your personal data.</p>
<p>For this purpose you can exercise the following rights:</p>
<ul>
<li>the right of access / information;</li>
<li>the right to obtain the restriction of the processing of your personal data;</li>
<li>the right to rectification by requesting corrections/amendments if inaccurate or incomplete personal data has been processed;</li>
</ul>
<p>Please, be informed that under this processing activity you do not have the right to object to processing your personal data, to delete your personal data or to request the portability of your personal data because the processing activity is based on the compliance of a legal obligation.</p>
<h6 class="header-6">Special categories of data</h6>
<p>We do not ask for, collect or process any special categories of data about you, except in specific circumstances as described in this privacy statement. Special categories of personal data are often referred to as ‘sensitive’ personal data and include information relating to racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health or sexual life. In cases where you accidently or voluntarily provide such information and we do not have a legal basis to process this information, we will delete this information without undue delay.</p>