Privacy notice

Last updated: TODO, set on the day this goes live.

Needs your input, and a legal review This notice covers only what this website does. It is drafted to be substantively complete, but three fields marked TODO need your particulars, and given that the company processes health data in its products we recommend a lawyer reads it before launch. This notice deliberately says nothing about the ePA or patient data, because this website neither collects nor processes any. Do not extend it to cover the products without advice.

1. Controller

The controller responsible for data processing on this website is:

TODO: company legal name and registered address, exactly as given in the Imprint.

Email: Alexander.vanheijningen@pulseready-medsystems.com

2. Data protection officer

TODO: assess and then state one of two things. A Datenschutzbeauftragter is mandatory under § 38 BDSG once at least 20 people are permanently engaged in automated processing, and under Art. 37 GDPR where core activities involve large-scale processing of health data. If no officer is required, say so here explicitly rather than leaving this section out.

3. Contact form

What we collect

When you use the form on our contact page we receive the first name, last name, email address, organisation, job title where you give one, the subject you select, and the content of your message.

Why, and on what legal basis

  • To answer your enquiry. Where your message concerns a possible pilot, demo or contract, the basis is Art. 6 (1) (b) GDPR, steps taken at your request prior to entering into a contract. Otherwise the basis is our legitimate interest in responding to enquiries addressed to us, Art. 6 (1) (f) GDPR.
  • Your consent to the handling described here, given by ticking the box on the form, Art. 6 (1) (a) GDPR. You may withdraw that consent at any time with effect for the future, by writing to the address above. Withdrawal does not affect the lawfulness of processing carried out before it.

How long we keep it

We keep your message and the details submitted with it for as long as needed to deal with your enquiry and for any follow-up, and delete it thereafter, unless statutory retention periods require otherwise. Where an enquiry leads to a contract, the relevant records are retained under the applicable commercial and tax retention periods.

Is it required

Providing this data is neither legally nor contractually required. The fields marked with an asterisk are the ones we need in order to reply usefully. If you would rather not use the form, you can email any of us directly using the addresses on the contact page.

4. Hosting and form processing

TODO: confirm the host before launch and correct this section if it changes. As planned, the site is hosted by Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA, which also receives and stores contact form submissions on our behalf as a processor under Art. 28 GDPR.

This involves a transfer of personal data to the United States. That transfer is safeguarded by the European Commission's Standard Contractual Clauses concluded with the processor. You may request a copy of those safeguards from us using the contact details above.

When you visit this site, the host automatically records technical data that your browser transmits: IP address, date and time of the request, the page requested, referrer, browser and operating system. This is necessary to deliver the site and to keep it secure and stable, and rests on our legitimate interest under Art. 6 (1) (f) GDPR.

5. Cookies, analytics and tracking

This website sets no cookies, runs no analytics, and embeds no tracking pixels, advertising tags or social media plugins. Nothing here profiles you or follows you across sites. This is why the site shows no cookie banner: there is nothing to consent to.

6. Fonts and third-party content

The Archivo typeface is served from our own servers. No request is made to Google Fonts or any other third-party host when you load this site, and no data about your visit reaches such a service.

7. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15)
  • have inaccurate data corrected (Art. 16)
  • have your data erased (Art. 17)
  • restrict processing (Art. 18)
  • receive your data in a portable format (Art. 20)
  • object to processing based on legitimate interest (Art. 21)
  • withdraw consent at any time with effect for the future (Art. 7 (3))

To exercise any of these, write to the contact address above. We will respond within one month.

8. Right to lodge a complaint

You have the right to complain to a supervisory authority, in particular in the member state of your habitual residence, place of work or the place of the alleged infringement (Art. 77 GDPR).

TODO: name the competent Landesdatenschutzbehörde for the company's registered seat, with its address and website.

9. SSL/TLS encryption

This site uses TLS encryption for all connections. You can recognise an encrypted connection by the "https://" prefix and the padlock in your browser's address bar.

10. Changes to this notice

We update this notice when the site changes in a way that affects it. The date at the top always shows the current version.