Data Privacy Statement
We, the MIM Medizinische Instrumente & Monitoring GmbH (hereinafter "we" or MIM") are pleased about your interest in our company.
We take the protection of your personal data and their confidential treatment very seriously. The processing of your personal data takes place exclusively within the framework of the legal provisions of the data protection law of the European Union, in particular the General Data Protection Regulation (hereinafter "GDPR") and further applicable regulations.
1. Name and contact details of the controller
This data privacy statement shall apply to data processing activities by the following controller:
MIM Medizinische Instrumente & Monitoring GmbH,
Brandshofer Deich 68, 20539 Hamburg
Phone: 0049 40 36807680;
2. Subject matter of data protection
The subject matter of data protection is personal data". This means any information relating to an identified or identifiable natural person (‘data subject’). These include e.g. information such as name, postal address, e-mail address or telephone number.
Specific information on the personal data processed by us can be found below in detail in the data processing operations listed.
3. Collection and storage of personal data as well as the nature and purpose of their processing
a. When visiting the website
When calling our website, the browser used on your end device will automatically send information to the server of our website. This information is temporarily stored in a so-called log file. The following information is recorded without any action on your end and stored until automated erasure after seven days:
- internet protocol address of the requesting computer
- date and time of the access
- name and URL of the file retrieved
- website from which the access takes place (referrer URL)
- website that is called via our website
- browser used and, if applicable, the operating system of your computer and the name of your access provider
The data mentioned are processed by us for the following purposes:
- ensuring smooth establishment of the website’s connection
- ensuring comfortable use of our website
- evaluation of system safety and stability, as well as
- other administrative purposes
The legal basis for data processing activities shall be Article 6(1)(1)(f) GDPR. Our legitimate interests follow from the purposes listed above for data collection. In no case shall we use any collected data for the purpose of drawing conclusions about your person.
b. When using our contact form and email contact
If there are any questions, we offer the option of contacting us using a form provided on the website. A valid email address must be indicated there, so that we will know where the query comes from and to answer such. Further information can be provided freely.
Alternatively, contact via the provided email address is possible. In such a case, your personal data transmitted in the email will be stored.
Data processing activities for the purpose of contacting is according to Article 6(1)(f) GDPR. If the contact is targeted at conclusion of a contract, Article 6(1)(b) GDPR shall be an additional legal basis for processing.
The personal data collected by us shall be erased automatically after completion of the request submitted by you.
4. Passing on data
We shall only pass on your personal data to third parties (recipients) if we are entitled to do so under the provisions of data protection law. Below we inform you about the circumstances in which this may be the case: We can pass on your personal data to third parties (recipients), if:
- you have explicitly given consent to such for one or more specific purposes (Article 6(1)(1)(a) GDPR);
- processing is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract (Article 6(1)(1)(b) GDPR);
- processing is necessary for compliance with a legal obligation to which the we are subject (Article 6(1)(1)(c) GDPR);
- processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of personal data (Article 6(1)(1)(f) GDPR).
Furthermore, we work together with service providers, so-called processors, to whom we transfer your personal data and who process your data for us on our behalf and in accordance with our instructions in compliance with Art. 28 GDPR. These service providers have been carefully selected and commissioned by us, are bound by our instructions and are regularly inspected. Specifically, please find below a list of our service providers:
- Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
- Domainhost: united-domains AG, Gautinger Straße 10, 82319 Starnberg (Deutschland), Kontakt zum Datenschutzbeauftragter: firstname.lastname@example.org
- Webhost: Neue Medien Münnich, Hauptstrasse 68, 02742 Friedersdorf (Deutschland), Kontakt zum Datenschutzbeauftrager: email@example.com
The cookie is used to store information that results from the respective context of the specifically used end device. However, this shall not mean that we directly gain knowledge of your identity this way.
Furthermore, we also use temporary cookies to optimise user friendliness, which are stored on your end device for a certain specified period. When you visit our website again in order to use our services, it will be automatically recognised that you have visited us before and which input and settings you have made so that you will not have to enter them again. These cookies are deleted automatically at the end of each browser session.
The data processed by cookies are required for the purpose of maintaining our legitimate interests and those of third parties according to Article 6(1)(1)(f) GDPR.
Most browsers accept cookies automatically. You may, however, configure your browser so that no cookies will be stored on your computer or that you will always be informed before a new cookie is set up. Complete deactivation of cookies may, however, render you unable to use all functions of our website.
6. Analysis tools
The tracking measures listed below and used by us are performed based on Article 6(1)(1)(f) GDPR. With the tracking measures used, we want to ensure demand-oriented design and continuous optimisation of our website. On the other hand, we use tracking measures in order to statistically record use of our website and to evaluate it for the purpose of optimising our offer to you. These interests are to be viewed as justified within the meaning of the above rule.
The respective purposes of the data processing activities and data categories can be taken from the corresponding tracking tool in this section.
For the purpose of demand-oriented design and continuous optimisation of our websites, we use Google Analytics, a web analysis service of Google Inc. (https://www.google.de/intl/de/about/) (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; hereinafter: “Google”). In this context, pseudonymised user profiles are compiled and cookies are used (see section 5). The information generated by the cookie regarding your use of this website, such as
- browser type/version,
- operating system used,
- referrer URL (the website visited before),
- host name of the accessing computer (internet protocol address),
- time of the server query,
are transferred to servers of Google in the USA and stored there within the context of the agreement on contract data processing that we have entered into with Google. The information is used in order to evaluate use of the website in order to compile reports on the website activities and in order to provide further services connected to use of the website and use of the internet for the purpose of market research and demand-oriented design of these internet websites. This information may also be transferred to third parties if this is required by law or as far as third parties process these personal data based on a contract. In no case will your internet protocol address be combined with any other data of Google. The internet protocol addresses are rendered anonymous so that they cannot be assigned (IP masking). Sessions and campaigns shall be ended after the end of a specific period of time. By default, sessions shall be ended after 30 minutes without any activity, and campaigns after six months. The time limit for campaigns may be up to two years.
You may prevent installation of the cookies by making the corresponding settings in your browser software; however, note that you may be unable to fully use all functions of the website in such a case.
You may furthermore prevent recording of the data generated by the cookie and referring to your use of the website (including your internet protocol address) and processing of these personal data by Google by downloading and installing a browser add-on (https://tools.google.com/dlpage/gaoptout?hl=de).
For more information on data protection related to Google Analytics, see the Google Analytics Help (https://support.google.com/analytics/answer/6004245?hl=de).
7. Social Media
We use links to the social networks Facebook, Twitter, and GooglePlus on our website. The buttons are simple HTML links. No personal data from you will be transmitted in the scope of this. Instead of your internet protocol address, only our server address will be transmitted to Facebook, Google and Twitter. You will only be directly connected to Facebook, Google, or Twitter if you take action. Before this, the social networks cannot record any personal data on you. As long as you do not click the link in order to share contents, you will remain invisible to the networks. When you click the link, the obligation to provide information on data collection and processing is no longer with us, but with the provider of the social network.
8. Google Webfonts
Our site uses the map service Openstreetmap. This service is provided by the Openstreetmap Foundation 132 Maney Hill Road, Sutton Coldfield, West Midlands, B72 1JU, United Kingdom. Information regarding the use of our website – including your IP address – is transferred to and saved on a server of the Openstreetmap Foundation in Great Britain.
10. Rights of the data subject
You have the right:
- to demand information in accordance with Article 15 GDPR regarding the processing of your personal data by us. In particular, you may request information on the purposes of the processing, the categories of personal data, the categories of recipient to whom your data have been or are disclosed, the envisaged storage period, the existence of the right to rectification, erasure, restriction of processing or objection, the right to lodge a complaint, the source of your data to the extent that these were not collected at our site, and the existence of automated decision-making, including profiling and any meaningful information on its details;
- in accordance with Article 16 GDPR, obtain the rectification of any inaccurate personal data stored by us or completion of such data without undue delay;
- in accordance with Article 17 GDPR, obtain the erasure of your personal data stored by us, to the extent that processing is not required for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the establishment, exercise or defence of legal claims;
- in accordance with Article 18 GDPR, obtain the restriction of processing of your personal data, to the extent that the accuracy of the data is contested by you, processing is unlawful, but you oppose erasure and we no longer need the personal data, but you still require them for the establishment, exercise or defence of legal claims or you have objected to processing pursuant to Article 21 GDPR;
- in accordance with Article 20 GDPR, demand to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format or to demand transmission to another controller;
- in accordance with Article 7(3) GDPR, to withdraw your consent once given to us towards us at any time. This has the consequence that we may no longer continue the data processing activities that were based on this consent in future and
- in accordance with Article 77 GDPR, lodge a complaint with a supervisory authority. Usually, you may contact the supervisory authority at your habitual residence or place of work or our registered office for this.
11. Right to object
As far as your personal data are processed based on legitimate interests in accordance with Article 6(1)(1)(f) GDPR, you have the right to object to processing of your personal data in accordance with Article 21 GDPR, to the extent that there are grounds relating to your particular situation or the objection is targeted against direct marketing. In the latter case, you have a general right to object that will be implemented by us without any indication of a particular situation.
If you want to exercise your withdrawal right or right to object, simply send us an email to firstname.lastname@example.org
12. Further information
In accordance with Art. 13 para. 2 lit. e GDPR we would like to inform you about the following:
The provision of personal data is neither a statutory nor contractual requirement, nor a requirement necessary to enter into a contract. You are not obliged to provide the personal data. There are no consequences resulting from failure to provide such data.
In accordance with Art. 13 para. 2 lit. f GDPR we would like to inform you about the following:
We do not process your personal data for the purpose of automated decision-making.
13. Data security
Within the website visit, we use the common SSL procedure (Secure Socket Layer) in conjunction with the respective highest encryption level your browser supports. This usually is 256-bit encryption. If your browser does not support 256-bit encryption, we will use 128-bit v3 technology instead. Whether an individual website of our internet offer is transmitted encrypted or not is evident by the closed display of the key or lock symbol in the lower status bar of your browser.
Apart from this, we use appropriate technical and organisational security measures in order to protect your data from accidental or wilful manipulation, partial or complete loss, destruction or unauthorised access by third parties. Our security measures will be improved continually according to the technological developments.
14. Topicality and changes of this data privacy statement
This data privacy statement is currently valid as of 25 May 2018.
Further development of our website and offers through it or changed statutory or authority specifications may require changes to this data privacy statement. You may call and print the respective current data privacy statement at any time on the website at http://www.mim-germany.com/data-protection.