Privacy statement

General Data Protection Regulation
The General Data Protection Regulation (GDPR) took effect on 25 May 2018. This means that the same privacy law is valid for the entire European Union (EU) as of this date. The Personal Data Protection Act will hence no longer be valid. The goal of this law is to guarantee your privacy and provide protection from unwanted and unlawful infringement of the law.

The GDPR helps bring about the following, among other things:
• strengthening and expansion of privacy rights;
• more responsibilities for organizations;
• uniform authorizations for all European privacy regulators.

Scope
This privacy statement applies to all personal data that are processed by NordMedica.

Origin
NordMedica receives direct information from you when you choose to use our products and services, call or email us or directly give us information in other ways.

Personal data that we process
NordMedica processes your personal data because you use our services and/or because you have provided these data to us yourself.
Below is an overview of the data that we process, depending on your statement:

Personal data:

• initials;
• gender;
• date of birth;
• IP address;
• location information;
• data about your activities on our website;
• data about your browsing behavior at affiliated websites of NordMedica;
• internet browser and device type; and
• other personal data that you actively provide, e.g. in correspondence or over the phone.

Special personal data
• medical data

Our website and/or service does not have the intention of collecting data about website visitors who are younger than 16 years of age, unless they have permission from a parent or guardian. However, we cannot check whether a visitor is older than 16 years of age. We therefore advise parents to monitor their children’s online activities, in order to prevent data being collected about children without parental consent. If you are convinced that we have collected personal data about a minor without such consent, contact us at dataprotection@euroceptpharma.com.

Security
NordMedica takes the protection of your data seriously and takes suitable measures to prevent misuse, loss or unauthorized access, unwanted disclosure and unauthorized modification. If you believe that your data are not properly secured or there are indications of misuse, contact our Data Protection Officer at dataprotection@euroceptpharma.com.

Processing objectives
NordMedica processes your personal data for the following objectives:
• answering your questions and/or comments about our services and products;
• offering our services at the request of you or your healthcare provider;
• administration of our websites.

Automated decision-making
NordMedica does not use automated processing for matters that can have (significant) consequences for people. This concerns decisions that are made by computer programs or systems, without any human intervention (e.g. a NordMedica employee).

Retention period
NordMedica saves personal data for the duration necessary for achieving its objectives, unless a longer retention period is required or permitted by law.

Use of personal data by third parties
NordMedica will not sell your data to third parties and will only provide the data if this is necessary, within the scope of the concluded service provision contract, for rendering the service provision to you or to comply with a legal obligation. We conclude a processor agreement with all companies that process your data in order to ensure the same level of security and confidentiality of your data. NordMedica remains responsible for these processing activities.

Cookies, or similar technologies, that we use
A cookie is a small text file that is saved on your computer, tablet or smartphone when you first visit this website. NordMedica only uses technical, functional and analytical cookies that do not encroach on your privacy. The cookies that we use are necessary for the technical functioning of the website and your ease of use. They ensure that the website works properly and remember your preferred settings, for example. We can also optimize our website with cookies. You can unsubscribe from cookies by configuring your Internet browser so that it no longer saves cookies. You can also delete all the information that was previously stored using your browser’s settings.

Right to view, correct, delete or transfer data
You have the right to view your personal data or have these corrected or deleted. You also have the right to revoke the consent you have already given for the data processing or object to the processing of your personal data by NordMedica, and you have the right to transfer these data. This means that you can submit a request to us to send you the personal data that we have about you.

You can send your request for viewing, correction, deletion or transfer of your personal data or request to revoke your consent or your objection to the processing of your personal data to dataprotection@euroceptpharma.com.

Possibility of asking questions and/or lodging complaints
NordMedica wishes to point out that you have the possibility of lodging a complaint with the Data Protection Officer. You can do this by email at dataprotection@euroceptpharma.com or by post to NordMedica, Attn. Data Protection Officer, Trapgans 5, 1244 RL, Ankeveen.

How we secure personal data
NordMedica takes the protection of your data seriously and takes suitable measures to prevent misuse, loss or unauthorized access, unwanted disclosure and unauthorized modification. If you believe that your data are not properly secured or there are indications of misuse, contact our Data Protection Officer at dataprotection@euroceptpharma.com.

Data Protection Officer
NordMedica’ Data Protection Officer can be reached at dataprotection@euroceptpharma.com.

Version 1.0
15 May 2018