Privacy policy

I. GENERAL INFORMATION ON DATA PROCESSING

A. Purpose of the privacy policy

The protection of our customers' privacy is very important to Samarit Medical AG (hereinafter referred to as "SAMARIT", "we" or "us").

This privacy policy explains the nature, scope and purpose of the processing of personal data by us. This is not an exhaustive description; other data protection declarations, general terms and conditions or similar documents may regulate specific matters.

B. Legal basis

The legal basis for our data processing is specifically Art. 5-9 FADP ("Terms and principles") and Art. 5-11 GDPR ("Principles"). However, whether and to what extent these laws are applicable depends on the individual case.

C. Processed personal data

Personal data refers to all information that relates to a specific or identifiable person and can identify that person personally.

The personal data we process includes sensitive personal data within the meaning of the FADP/DSGVO. Particularly sensitive personal data will only be processed in individual cases and after a corresponding declaration of consent.

D. Contact

If you have any questions about this privacy policy or data protection, please contact:

Samarit Medical AG
Gewerbestrasse 12
CH-8132 Egg b. Zürich

Phone +41 44 918 10 11
Mail: info(at)samarit.com

E. Changes

We regularly review our privacy policy and will update it if necessary. The current version will be published on our website.

II. PROCESSING OF PERSONAL DATA

A. Purpose of data processing

We use the personal data we collect primarily to manage our business relationship, in particular to conclude and process contracts with our customers, business partners, suppliers, etc.
We also process personal data in order to comply with our legal obligations in Switzerland and abroad.
In addition, we process personal data of you and other persons, insofar as this is permitted and we deem it appropriate, also for the following purposes in which we have a legitimate interest corresponding to the purpose:

  • to improve our range of services
  • for advertising and marketing purposes
  • to analyze and evaluate website activities
  • for the prevention and investigation of possible criminal offenses
  • for the protection of legal claims and for defense in legal disputes or official proceedings
  • for the performance of internal investigations
  • for internal administrative purposes
  • to monitor and improve system security
  • for video surveillance to safeguard domiciliary rights and other measures for IT, building and facility security and the protection of our employees

B. Transfer of personal data to third parties

We only pass on your personal data if there is a legal obligation to do so, if this is necessary to enforce our rights, in particular to enforce claims arising from the contractual relationship or to achieve the stated purposes.

The third parties to whom we pass on personal data include in particular:

  • Companies of the SAMARIT Group (including Group companies outside the EEA, a list of the relevant companies is available at the following link: Distributors)
  • Service providers, in particular providers of IT services, hosting and support, logistics service providers, providers of CRM systems
  • Customers, partners, suppliers, insurance companies and other business partners
  • Industry organizations, associations and other bodies
  • Media agencies, the public, including visitors to websites and social media
  • Domestic and foreign authorities and offices, courts, arbitration tribunals
  • Counterparties in connection with legal proceedings

If we involve third parties in the performance of contracts, they will only receive your personal data to the extent that the transfer is necessary for the corresponding service.

In the event that a SAMARIT company or part of it is to be transferred to a third party or integrated into another company, your data may be passed on to our and external consultants.

C. Disclosure of personal data abroad

Data processing servers may be located and processors may be based abroad. Within the scope of our business activities and the purposes in accordance with (Art. II A), we also disclose data to third parties abroad to the extent permitted and deemed appropriate, either because they process it for us or because they wish to use it for their own purposes.

If the level of data protection in a country does not correspond to that in Switzerland or the EU, we contractually ensure that the protection of personal data corresponds to that in Switzerland or the EU at all times.

D. Personal data of third parties

If you transmit personal data from third parties to us, we would like to ask you to ensure that you are authorized to do so, that the data subjects are informed about the transmission and that they are aware of this privacy policy and that the data you transmit is correct.

E. Credit assessment and combating abuse

We reserve the right to check payment transactions in order to prevent fraud and other misuse in connection with payments, particularly in the case of "purchase on account". Internal and external sources of information are used for this purpose.

F. Duration of storage of personal data

We process and store your personal data for as long as is necessary for the fulfillment of our contractual and legal obligations or otherwise for the purposes pursued with the processing, i.e., for example, for the duration of the entire business relationship and beyond in accordance with the statutory retention and documentation obligations. It is possible that personal data may be retained for the period in which claims can be asserted against our company and insofar as we are otherwise legally obliged to do so or legitimate business interests require this (e.g. for evidence and documentation purposes). As soon as your personal data is no longer required for the above-mentioned purposes, it will be deleted or anonymized as a matter of principle and as far as possible.

G. Data security

We take appropriate technical and organizational security precautions to protect your personal data from unauthorized access and misuse, such as IT and network security solutions, access controls and restrictions, encryption of data carriers and transmissions (SSL), pseudonymization and controls.

III. USE CASES

A. Server log files

When our website is accessed, our system (web server) automatically collects technical information from the accessing computer. These are:

  • Browser type and browser version
  • Operating system used
  • Referrer URL (previously visited page)
  • Host name of the accessing computer
  • Date and time of the server request
  • IP address
  • Name of the page/file retrieved
  • Amount of data transferred

This data cannot be directly assigned to specific persons. This data is not merged with other data sources. However, we reserve the right to check this data retrospectively if concrete indications of unlawful use become known.

B. Tracking pixel

We may use tracking pixels on our website. Tracking pixels are also known as web beacons. Tracking pixels - including those from third parties whose services we use - are small, usually invisible images that are automatically retrieved when you visit our website. Tracking pixels can be used to collect the same information as server log files.

C. Use of cookies

Cookies are data that are stored by our websites on the user's end device via the browser. On the one hand, the cookies we use serve to increase and improve the user-friendliness of our websites. On the other hand, cookies help to collect statistical data on website usage and to use the data obtained for analysis and advertising purposes.
Some cookies are automatically deleted from your end device as soon as the browser is closed (so-called session cookies). Other cookies are stored for a certain period of time, which does not exceed 2 years (persistent cookies). In addition, we may also use so-called third-party cookies, which are managed by third parties in order to offer certain services.
You can influence the use of cookies. Most browsers have an option to restrict or completely prevent the storage of cookies. However, we would like to point out that the use and in particular the ease of use are restricted without cookies. Furthermore, users can adjust the cookies when visiting the websites via the relevant notice.

D. Success and reach measurement

Our notifications and messages may contain web links or tracking pixels that record whether an individual message has been opened and which web links have been clicked on. Such web links and tracking pixels can also record the use of notifications and messages on a personal basis.

We require this statistical recording of usage to measure success and reach in order to be able to offer notifications and messages in an effective, user-friendly, permanent, secure and reliable manner based on the needs and reading habits of the recipients.

E. Contact forms

Depending on the background of the digital contact, various personal data is requested in the form. Personal details such as title, first name, surname, email address and the nature of your request must be provided for the purpose of contacting you and addressing you personally.

This contact data is stored by us for the purpose of processing the inquiry and in the event of follow-up questions. The data entered in the forms is therefore processed exclusively on the basis of your consent.

F. E-Mail

You have the option of contacting us by e-mail. If you contact us by e-mail, personal data such as e-mail address, content, subject, date and contact details provided by you (e.g. name, telephone number, address) will be processed.

Your details will be stored by us for the purpose of processing the inquiry and in the event of follow-up questions. Pre-contractual measures or our legitimate interests in processing the request serve as justification.

We would like to point out that e-mails can be read or changed without authorization or notice during transmission.

G. Digital customer / user account

1. Purpose

The data is collected for the purpose of providing the customer with password-protected direct access to the basic data stored by us. The customer can view his completed and open orders or manage or change his personal data.

2. Personal data collected for the creation and operation of the account

When a customer account is opened, the following personal data is requested:

  • Salutation
  • Surname and first name
  • Postal address
  • Date of birth
  • Telephone number
  • E-mail address
  • Password

We use the so-called double opt-in procedure for the opening, after registration we will send you a notification e-mail. You can confirm the opening by activating a corresponding link.

----> To process orders, you can also enter the following additional information in your profile: <----

  • Preferred payment method
  • Delivery address other than the billing address

If you do not enter certain information in your customer account, individual functions or processes may not be available to you.

We are entitled to process the data provided by you when using the customer account in order to fulfil the resulting contractual obligations and to operate the customer account.

3. Electronic communication / Marketing

For this purpose, we process your personal data collected during registration and use of the customer account for marketing and analysis activities.

By opening a customer account, you authorise us to send you information, recommendations, offers or services that are suitable for you. This is done by means of non-analogue communication such as e-mail. If you do not wish to receive this communication, you can delete your customer account at any time or revoke your consent in your customer account.

4. Cancellation of the customer account

You can delete your customer account at any time and without giving reasons. Your customer account can then no longer be used or reactivated.

If you delete your customer account, we will permanently delete or anonymise the personal data contained in the account. This is subject to SAMARIT's legal and operational retention obligations/reasons.

H. Shopping in the online shop

If you wish to place orders in the online shop on this website, we require the following data to process the contract:

  • Surname and first name
  • E-Mail address
  • Billing address (and delivery address if different)
  • Payment details (depending on the payment method selected)
  • Login data, i.e. e-mail address and password (for registered customers)

Unless otherwise stated in this privacy policy or unless you have given your separate consent, we will only use the aforementioned data to process the contract, namely to process your orders, deliver the ordered products and ensure correct payment.

I. Newsletter

On request, we will keep you up to date with relevant developments and offers from us. We use the so-called double opt-in procedure to register for our newsletter: If you order our newsletter on the website, e.g. by ticking a confirmation box, we will send you a notification e-mail. You can confirm the order by activating a corresponding link. If you no longer wish to receive a newsletter from us at a later date, you can unsubscribe at any time free of charge, for example via the "Unsubscribe" link in the newsletter.

We process your data in connection with the newsletter in order to send you news about and in connection with us. In addition, we also process and use the e-mail address entered to send you personalised offers in connection with the newsletter.

If we send you advertising from us as an existing customer, you can object to this at any time, which will put you on a blacklist against further advertising mailings.

We work together with external service providers to send the newsletter.

1. Newsletter dispatch via Brevo

We use the services of Brevo (formerly Sendinblue) to send newsletters. The provider is Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany.

Brevo (formerly Sendinblue) is a service that can be used to organise and analyse the sending of newsletters, among other things. If you enter data for the purpose of subscribing to the newsletter (e.g. e-mail address), this data is stored on the Brevo (formerly Sendiblue) servers in Europe.

Brevo (formerly Sendinblue) is ISO 27001:2013 certified. Further information can be found in the privacy policy of Brevo (formerly Sendinblue): https://www.brevo.com/en/legal/privacypolicy/ and in the data security declaration: https://www.brevo.com/en/security/

2. Conclusion of a data processing agreement

We have concluded a so-called "Data Processing Agreement" with Brevo (formerly Sendinblue), in which we oblige Brevo (formerly Sendinblue) to protect the personal data of our customers and not to pass it on to third parties.

J. Online job applications

The application data you send us will be collected and processed electronically by us for the purpose of handling the application process. If your application is followed by the conclusion of an employment contract, we may store your submitted data in your personnel file for the purpose of the usual organisational and administrative process in compliance with the relevant legal regulations.

If your job application is rejected, we will ask you whether you wish the data to be deleted. If you do not wish your data to be deleted, we will store your data in our database of prospective candidates. You can exercise your right of cancellation at any time. This does not apply if longer storage is necessary due to legal requirements.

K. Analysis tools and advertising

1. Google analytics

Our website uses Google Analytics, a service provided by Google Ireland Ltd, Google Building Gordon House, Barrow St, Dublin 4, Ireland and Google LLC, 1600 Am-phitheatre Parkway Mountain View, CA 94043, USA; both together "Google", whereby Google Ireland Ltd. is responsible for the processing of personal data.

Google Analytics uses so-called "cookies". These are text files that are stored on your computer and enable your use of the website to be analysed. The information generated by the cookie about your use of this website is usually transferred to a Google server in the USA and stored there.

We have activated the IP anonymisation function on this website. This means that your IP address will be truncated by Google within member states of the European Union or in other signatory states to the Agreement on the European Economic Area before being transmitted to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there.

Google uses the data collected on our behalf so that we can get an idea of the visits and user behaviour on our website. This enables us to improve our services and website content and design.

You can prevent the storage of cookies by adjusting the settings in your browser accordingly (see our information on cookies). You can deactivate Google Analytics by downloading and installing the Google browser add-on.

2. Google tag manager

We use the Google Tag Manager on our website. This collects data about user behaviour on our website and forwards it to our analysis tools. Google Tag Manager does not have access to the data, it only collects the data. As the Google Tag Manager does not process any personal data per se, please refer to the information on the respective tracking services and the Google Tag Manager terms of use. Usage guidelines: https://marketingplatform.google.com/intl/en/about/analytics/tag-manager/use-policy/.

L. Social media plug-ins and tools

1. Facebook plug-ins (Like button)

Our website uses the functions of the Facebook network. The provider is Facebook Inc, 1 Hacker Way, Menlo Park, California 94025, USA.

Each time one of our pages containing Facebook functions is accessed, a connection to Facebook servers is established. Facebook is informed that you have visited our website with your IP address. If you click on the Facebook "Like" button and are logged into your Facebook account, Facebook is able to assign your visit to our website to you and your user account. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by Facebook. Further information on this can be found in Facebook's privacy policy at https://www.facebook.com/privacy/policy/.

If you do not want Facebook to be able to associate your visit to our pages with your Facebook user account, please log out of your Facebook user account.

4. LinkedIn

We use the functions of the social network LinkedIn Corporation, 1000 West Maude Avenue Sunnyvale, California 94085, USA, installed on our website.  

Each time one of our pages containing LinkedIn functions is accessed, a connection to LinkedIn servers is established. LinkedIn is informed that you have visited our website with your IP address. If you click on the LinkedIn "Recommend" button and are logged into your LinkedIn account, LinkedIn is able to associate your visit to our website with you and your user account. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by LinkedIn.

Further information on this can be found in LinkedIn's privacy policy at: https://www.linkedin.com/legal/privacy-policy

6. Instagram

We use the plug-in of the social network Instagram on our website, which is offered by Meta Platforms, Inc., 1601 Willow Road Menlo Park, CA 94025, USA.

If you are logged into your Instagram account, you can link the content of our pages to your Instagram profile by clicking on the Instagram button. This allows Instagram to associate your visit to our pages with your user account. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by Instagram.

Further information on this can be found in Instagram's privacy policy: https://instagram.com/about/legal/privacy/.

3. YouTube

We use the plug-ins of the Google-operated YouTube site on our website. The operator of the pages is YouTube, LLC, 901 Cherry Ave, San Bruno, CA 94066, USA.
When you visit one of our pages equipped with a YouTube plug-in, a connection to the YouTube servers is established. The YouTube server is informed which of our pages you have visited.

If you are logged into your YouTube account, you enable YouTube to assign your surfing behaviour directly to your personal profile. You can prevent this by logging out of your YouTube account.

Further information on the handling of user data can be found in YouTube's privacy policy at: https://policies.google.com/privacy.

9. Google Maps

We use the API of the map service Google Maps on our website. The provider is Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

To use the functions of Google Maps, it is necessary to store your IP address. This information is usually transmitted to a Google server in the USA and stored there. We have no influence on this data transfer.

The use of Google Maps is in the interest of an appealing presentation of our online offers and to make it easy to find the places we have indicated on the website.
You can find more information on the handling of user data in Google's privacy policy: https://policies.google.com/privacy.

10. Other third-party software

Other third-party software or tools such as the remarketing or "similar target groups" function from Google Inc. are not used, including Google Adwords conversion tracking and Google AdSense. We also do not use any social media plug-ins such as Instagram, XING or X (Twitter).

IV. YOUR RIGHTS

A. Right of enquiry

You can request information about the data we have stored about you at any time. You also have the right to receive your data in a commonly used file format if we process your data automatically and if you have given your consent to the processing of this data or if you have disclosed data in connection with the conclusion or fulfilment of a contract.
We may restrict or refuse to provide information or data if this conflicts with our legal obligations, our own legitimate interests, public interests or the interests of a third party.
Your request for information should be sent to the above contact address together with proof of identity. From the second request for information within 12 months, we may charge a fee to cover the costs. (in accordance with Art. 19 para. 2 GDPR maximum CHF 300)

B. Right to rectification and restriction

You have the option of correcting incorrect personal data, completing incomplete data and restricting the processing of your data at any time.

C. Right to cancellation and objection

You have the option to request the erasure of your personal data at any time ("right to be forgotten") and to object to the processing of your data with effect for the future.

Your rights may be restricted, in particular if the exercise of your right conflicts with our legal or contractual obligations, if we can invoke an overriding interest or if the rights of third parties would be infringed.

D. Legal process

If you are affected by the processing of personal data, you have the right to enforce your rights in court or to file a complaint with the competent supervisory authority. The competent supervisory authority in Switzerland is the Federal Data Protection and Information Commissioner: https://www.edoeb.admin.ch.

Only the German version is binding for a legal assessment of the translations.