Privacy statement

1. Data protection at a glance

General notices

The following notices provide a simple overview of what happens to your personal data when you visit our website. Personal data are all data with which you can be personally identified. You will find detailed information about data protection in our privacy statement listed under this text.

Data collection on this website

Who is responsible for the data collected on this website?

The website operator processes data on this website. The website operator’s contact data can be found in the Imprint on this website.

How do we collect your personal data?

We collect data that you communicate to us. This may be data that you fill in a contact form, for example.

Other data is collected automatically or after you have given consent by our IT systems when you visit our website. These are mainly technical data (e.g. internet browser, operating system or time of page visit). This data are collected automatically as soon as you enter this website.

What do we use your data for?

We collect some of your data to ensure that we can provide the website without any errors. Other data may be used to analyse the way you use the website.

What are your rights concerning your data?

You have the right to receive information about the origin, recipient and purpose of your stored personal data free of charge at any time. You also have the right to request the correction or deletion of this data. If you have given your consent to data processing, you can revoke this consent for the future at any time. Furthermore, you have the right to demand that we restrict the processing of your personal data under certain circumstances. You also have the right of appeal to the competent supervisory authority.

You can contact us at any time at the address given in the legal notice if you have any further questions about data protection.

Analysis tools and third-party provider tools

Your surfing behaviour on our website can be analysed statistically. This is done primarily with so-called analytics programs.

You will find detailed information on these analytics programs in the following privacy statement.

2. Hosting and Content Delivery Networks (CDN)

External Hosting

This website is hosted by an external service provider (host). The personal data collected on this website is stored on the host’s servers. This may include, but is not limited to, IP addresses, contact requests, meta and communication data, contract data, contact data, names, website visits and other data generated by a website.

The host is used for the purpose of fulfilling contracts with our potential and existing customers (Art. 6(1)(b) GDPR) and in the interest of a secure, fast and efficient provision of our online offer by a professional provider (Art. 6(1)(f) GDPR).

Our host will only process your data to the extent necessary to fulfil its performance obligations and will follow our instructions with regard to this data.

We use the following host:

STRATO AG
Pascalstraße 10
10587 Berlin, Germany

Conclusion of a contract for commissioned data processing

In order to guarantee processing in compliance with data protection law, we have concluded a contract for commissioned data processing with our host.

3. General and mandatory information

Data protection

The operators of this website take the protection of your personal data very seriously. We treat your personal data with confidentiality in compliance with the legal regulations and this privacy statement.

When you use this website, various personal data are collected. Personal data is data with which you can be personally identified. This Data Privacy Policy explains which data we collect and what we use them for. It also explains how and for what purpose this is done.

We would like to emphasise that data transmission over the Internet (e.g. communication by e-mail) may have security gaps. It is not possible to guarantee absolute protection of data against access by third parties.

Note on the data controller

The data controller for data processing on this website is:

GALENpharma GmbH
Wittland 13
D-24109 Kiel

Telefon: 0431 58518-0
E-Mail:

The data controller is the natural or legal person who alone or together with others decides on the purposes and means of processing personal data (e.g. names, e-mail addresses).

Duration of storage

Unless a more specific storage period has been specified within this privacy statement, your personal data will remain with us until the purpose for which it was collected ceases to apply. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted, unless we have other legally permissible reasons for storing your personal data (e.g. tax or commercial law retention periods); in the latter case, the deletion will take place after these reasons have ceased to exist.

Notice on data transfer to the USA

Among other things, tools from companies based in the USA are integrated on our website. When these tools are active, your personal data may be transferred to the US servers of the respective companies. We would like to point out that the USA is not a safe third country in the sense of EU data protection law. US companies are obliged to hand over personal data to security agencies without you as a data subject being able to take legal action against this. It can therefore not be ruled out that US agencies (e.g. intelligence services) process, evaluate and permanently store your data located on US servers for surveillance purposes. We have no influence over these processing activities.

Revocation of your consent to data processing

Many data processing operations are only possible with your express consent. You may revoke any consent you have already given at any time. The legality of the data processing up to the revocation remains unaffected by the revocation.

Right to object to data collection in special cases and to direct advertising (Art. 21 GDPR)

IF DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY STATEMENT. IF YOU FILE AN OBJECTION, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR PROCESSING THAT OUTWEIGH YOUR INTERESTS, RIGHTS AND FREEDOMS, OR IF THE PROCESSING IS FOR THE PURPOSES OF ASSERTING, EXERCISING OR DEFENDING LEGAL RIGHTS/CLAIMS (OBJECTION PURSUANT TO ART. 21(1) GDPR).

WHERE YOUR PERSONAL DATA ARE PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING PURPOSES, WHICH INCLUDES PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21(2) GDPR).

Right of appeal to the competent supervisory authority

In the event of infringements of the GDPR, the data subjects have the right to appeal to a supervisory authority, in particular in the Member State of their habitual residence, workplace or place of presumed infringement. The right of appeal shall be without prejudice to other administrative or judicial remedies.

Right to data transferability

You have the right to have data, which we process automatically based on your consent or in fulfilment of a contract, handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another data controller, this will only take place if it is technically feasible.

SSL or TLS encryption

This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or requests that you send to us as the site operator. You can recognise an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line.

If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Access, Erasure and Rectification

Within the scope of applicable statutory provisions, you have the right to free information about your stored personal data, their source and recipient, and the purpose of data processing and, if necessary, a right to rectification or erasure of these data. You can contact us at any time at the address given in the legal notice if you have any further questions on the subject of personal data.

Right to restriction of processing

You have the right to demand that we restrict the processing of your personal data. To that end, you can contact us at any time at the address given in the legal notice. The right to restrict processing exists in the following cases:

  • If you dispute the accuracy of your personal data stored with us, we usually need time to verify this. For the duration of the verification, you have the right to demand that we restrict the processing of your personal data.
  • If the processing of your personal data has taken/is taking place unlawfully, you can demand the restriction of data processing instead of deletion.
  • If we no longer need your personal data, but you need it for the exercise, defence or assertion of legal claims, you have the right to demand the restriction of the processing of your personal data instead of deletion.
  • If you have filed an objection in accordance with Art. 21(1) GDPR, your interests must be weighed against ours. As long as it is not yet clear whose interests shall prevail, you have the right to demand that the processing of your personal data be restricted.

If you have restricted the processing of your personal data, such data may – apart from its storage – only be processed with your consent or for the purpose of asserting, exercising or defending legal rights or protecting the rights of another natural or legal person or for reasons pertaining to an important public interest of the European Union or a Member State.

Objection to marketing e-mails

Objection is hereby made to the use of contact data published in accordance with legal requirements for the purpose of sending marketing and information material which has not been explicitly requested. The operators of this website explicitly retain the right to take legal action in the event that unsolicited marketing information, such as spam mail, is sent.

4. Data collection on this website

Cookies

Our webpages use so-called cookies. Cookies are small text files and do not cause any damage on your terminal. They are either stored temporarily for the duration of a session (session cookies) or permanently (permanent cookies) on your terminal. Session cookies are automatically deleted at the end of your visit. Permanent cookies remain stored on your terminal until you delete them yourself or until they are automatically deleted by your web browser.

In some cases, cookies from third-party companies may also be stored on your terminal when you visit our site (third-party cookies). These enable us or you to use certain services of the third-party company (e.g. cookies for processing payment services).

Cookies have various functions. Numerous cookies are technically necessary, as certain website functions would not work without them (e.g. the shopping basket function or displaying videos). Other cookies are used to evaluate user behaviour or display advertisements.

Cookies that are required to implement the electronic communication process (necessary cookies) or to provide certain functions that you have requested (functional cookies, e.g. for the shopping basket function) or to optimise the website (e.g. cookies for measuring the web audience) are stored on the basis of Art. 6(1)(f) GDPR, unless another legal basis is given. The website operator has a legitimate interest in the storage of cookies for technically accurate and optimised provision of his services. If consent to the storage of cookies has been requested, the storage of the cookies in question is based exclusively on this consent (Art. 6(1)(a) GDPR); consent may be revoked at any time.

You can customise your browser in such a way that you are informed of the placement of cookies and permit cookies only in individual cases, block the acceptance of cookies for certain cases or generally as well as activate the automatic deletion of cookies when the browser is closed. Deactivating cookies may limit the functionality of this website.

Insofar as cookies are used by third-party companies or for the purposes of analysis, we will inform you separately about this within the framework of this data protection declaration and, if necessary, request your consent.

Server log files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. This is information about the:

  • browser type and browser version
  • operating system used
  • referrer URL
  • host name of the accessing computer
  • the time of the server request
  • IP address

This data is not combined with other data sources.

These data are collected on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in presenting and optimising its website in a manner free of technical errors – for this purpose the server log files must be recorded.

Contact form

If you would like to send any questions to us using this contact form, the information you enter in the form (including any contact data you provide) will be stored by us for the purpose of dealing with your enquiry and any follow-up questions which may arise. We do not disclose these data without your consent.

This data is processed on the basis of Art. 6(1)(b) GDPR if your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of the enquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR), provided that this consent has been requested.

The data entered in the contact form will be held by us until you ask us to erase them, you withdraw your consent to storage or the purpose for which data have been stored no longer applies (e.g., after finally processing your inquiry). Mandatory legal provisions – including but not limited to retention periods – remain unaffected.

Inquiry by e-mail, telephone or fax

If you contact us by e-mail, telephone or fax, your request including all personal data (name, request) will be stored and processed by us for the purpose of processing your request. We do not disclose these data without your consent.

This data is processed on the basis of Art. 6(1)(b) GDPR if your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of the enquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR), provided that this consent has been requested.

The data you sent to us via contact inquiries remain with us, till you ask us to erase them, you withdraw your consent to storage or the purpose for which data have been stored no longer applies (e.g. after successfully handling your request). Mandatory legal provisions – including but not limited to statutory retention periods – remain unaffected.

5. Analysis tools and marketing

Matomo (formerly Piwik)

This website uses the open source web analytics service Matomo. Matomo uses technologies that enable the user to be recognised across pages for the analysis of user behaviour (e.g. cookies or device fingerprinting). The information collected by Matomo about the use of this website is stored on our server. The IP address is anonymised before storage.

With the help of Matomo, we are able to collect and analyse data about the use of our website by website visitors. This enables us to find out, among other things, when which page views were made and from which region they originate. We also collect various log files (e.g. IP address, referrer, browsers and operating systems used) and can measure whether our website visitors perform certain actions (e.g. clicks, purchases).

These analytics tools are used on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the anonymised analysis of user behaviour for the purpose of optimising its web services and its marketing. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR; the consent can be revoked at any time.

Hosting

We host Matomo exclusively on our own servers, thus ensuring that all analysis data remains with us and is not passed on.

Status: November 2020