en | de

Privacy policy

for Medela's File Sharing solution

 

Protecting your privacy is important to us. We therefore wish to make the following information available to you.

1. Name and contact details of entity responsible for data processing (data controller): 
Medela AG
Lättichstrasse 4b
6340 Baar
Switzerland
privacy@medela.com

2. Legal basis and purpose
Your personal data is processed on the basis of your freely given consent.

Medela uses a file sharing solution ("fileshare") to globally exchange files securely, especially large documents, with internal and mainly external recipients. This means an external recipient has to share limited personal data in order to create an account and to up-/download files from fileshare.

Any personal data collected by fileshare is processed exclusively for the purposes mentioned above. It is not processed automatically nor analyzed with regard to personal aspects (profiling).

3. We process the following categories of your personal data:

  • Contact details (first name, last name, email address)
  • Your internal contact at Medela
  • Password
  • Any personal contained in the files you share with us

4. Recipients or categories of recipients
In order to operate fielshare, the company MASSIVE ART Web Services GmbH (Gütlestrasse 7a, 6850 Dornbirn, Austria) and its subcontractor Hetzner Online GmbH (Gunzenhausen, Germany) are given access to your personal data. Medela has entered into a contract with this service provider to ensure that your personal data is adequately protected. The service provider may not pass on your personal data to unauthorised third parties or use it for any other purpose than instructed by Medela.

Some Medela affiliates (Medela USA, Medela Germany and Medela China) will have access to your personal data, as they may sub-process your personal data on behalf of the Global IT of Medela AG.

Beside the above-mentioned recipients, Medela employees may disclose personal data to third parties for other purposes, which may be covered by other privacy notices. However, according to Medela’s Global Policy on Data Protection, Medela employees have to keep personal data confidential and can only disclose personal data to third parties if this is expressly required (legitimate purpose) or permitted by applicable laws and regulations.   

5. Location and duration of storage of your personal data
Your personal data will be stored on servers in Germany of Hetzner Online GmbH and may be accessed out of Austria by MASSIVE ART Web Services GmbH. Any shared files will be deleted after thirty (30) days. Accounts will be deleted after ninety (90) days of inactivity and fully removed from archive after an additional one-hundred-eighty (180) days from the archive. 

6. Transmission to a non-Swiss/EU/EEA jurisdiction
Some Medela affiliates are located in countries outside of Switzerland and the EU/EEA that do not provide for the same level of data protection as in your country of residence. Medela has entered into an agreement with these Medela affiliates to ensure that all necessary measures are taken to protect your personal data in accordance with applicable requirements.

7. Technical and organizational security measures
Every IT person at Medela accessing your personal data needs to get an administrator account, for which an internal approval process needs to be followed. Medela has also limited the number of people at the service provider who have access to your personal data. Moreover, during the registration process the internal Medela contact person has to approve the request before the external person can use fileshare. In addition, the external person can then only exchange files with this specific Medela employee and can’t misuse fileshare for exchanging documents with others. 

8. Your data protection rights

Right to access personal data: You have the right to request and receive information on the personal data collected on you or processed or, where applicable, shared with third parties, as part of operating fileshare.

Right to rectification: You have the right to have any inaccurate personal data corrected.

Right to erasure ("right to be forgotten"): You have the right to have your personal data deleted – for example, if your personal information is no longer required for the original purpose it was collected – subject to statutory retention obligations.

Right to restrict data processing: You have the right to request the restriction of the processing of your personal data, for example if the processing is unlawful or the accuracy of your personal data is contested.

Right to data portability: You have the right to receive a copy of the personal data you have provided when using fileshare. You can request to have your personal data transmitted to you or, where technically feasible, to another data controller of your choice.

Right to object: You have the right to object to having your personal data processed for certain purposes or to withdraw your consent to such processing.

Please note that in exceptional cases, your right to exercise the above rights may not be guaranteed due to statutory or regulatory requirements.

If you would like to exercise any of the above rights, please send your request to Medela AG, Data Protection Officer, Lättichstrasse 4b, 6340 Baar, Switzerland, or email our data protection officer at privacy@medela.com.

To file an official complaint, please contact the data protection authority in your jurisdiction (in Switzerland: Federal Data Protection and Information Commissioner / Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB).

9. Changes to this Privacy Policy for Medela's File Sharing Solution

We reserve the right to make changes to this Privacy Policy for Medela's File Sharing Solution at any time with effect for the future. The then current version of this Privacy Policy for Medela's File Sharing Solution will be made available on the fileshare website. While we do not intend to make changes to this Policy very often, it is always a good idea to double check our most current Policy statement from time to time that you are aware of the data we collect, process and share.

 

Last modified in June 2020