Processing of your personal data
Episurf Medical AB, Reg. No. 556767-0541 and its group companies, Karlavägen 60, SE-114 49 Stockholm, Sweden (the “Company” or “we”) takes all necessary measures to make sure that personal data concerning our patients, our external partners, visitors of our website and other persons whose personal data may be subject to processing by the Company is being processed by us in a lawfully, fairly and transparent manner.
The Company is committed to protecting your personal data and it is important to the Company to ensure that your personal data is being processed in a secure way. We comply with all applicable laws and rules that exist to protect the privacy of individuals, including the Swedish Personal Data Act (1998:204), the Swedish Act on Electronic Communication (2003:389) and such other laws or regulation that implements the EU Data Protection Directive 95/46/EC, the Electronic Communications Directive 2002/58/EC and the EU General Data Protection Regulation 2016/679 (GDPR) and any changes to, amendments to or regulations that replace such laws and regulations. We use appropriate technical and organizational measures with respect to the amount and sensitivity of personal data.
For information on the collection, handling and storage of information obtained through cookies, see the “Cookies” section below.
What personal data do we collect and where from?
If you are a potential patient to receive any of the Company’s products, surgeon who use products by the Company, subscribe to the Company’s press releases, contact us through the Company’s website or otherwise use our services, you may provide information to us that is considered personal data under applicable data protection laws.
The types of personal data that we collect may, depending on the context, include:
We may collect your personal data from the following sources:
Why do we process your personal data?
If you are a potential patient to receive any of the Company’s products, we process your personal information in order to evaluate whether our products can help you. As a result, we process your personal data for the purpose of carrying out the study and/or evaluate your injury.
The Company will only collect data that is necessary in order to develop and manufacture the Episealer implant and its accompanying surgical instruments. All of the Company’s employees are trained to handle patient sensitive information in line with the Company’s patient confidentiality policy as summarised says:
Medical images received by the Company are anonymised upon receipt and replaced with a unique identifier assigned to every case. The identifier is used throughout the Company’s processes, and only the operating surgeon has the ability to link the identifier to the actual patient identity. Sensitive data is stored on a dedicated secure place with restricted and controlled access, using modern encryption standards.
In addition to processing your personal data in connection with patient follow-up to meet our regulatory responsibilities and evaluation of your injury, the Company may use your personal data for other purposes, based on other legal grounds, as set out below.
In the event that a service that we provide requires your consent, we will always explicitly ask you to give your consent to such a service and to the processing of your personal data in such a case. For example, we will ask for your consent if you would like to subscribe to any of the Company’s press releases.
Retention of personal data
The Company takes all reasonable steps to ensure that your personal data is processed and stored securely. Your personal data will never be stored longer than permitted by applicable law or longer than necessary to fulfil the above stated purposes. Your personal data will be processed by us during the following time periods.
Transfer of personal data
The type of transfers mentioned above may only be carried out to companies within the EU or EEA (i.e. all EU members states and Iceland, Norway and Lichtenstein).
Withdrawal of consent
You have the rights to request information about what personal data concerning you that we are processing and how it is being used by contacting us in writing (see contact details below). You are also entitled to request correction of incorrect, incomplete or ambiguous personal data concerning you by contacting us. For the protection or your privacy and your personal data, we may require that you identify yourself in connection with our assistance.
In accordance with applicable data protection laws, you also have the right to request that your personal data be erased or that the processing of your personal data be restricted. In certain situations, you also have the right to object to the processing of your personal data and request that your personal data be transmitted in an electronic format.
You may file a complaint with the Swedish Data Protection Authority (sw. Datainspektionen) if you believe that the Company’s processing of your personal data is not carried out in accordance with applicable laws.
The Company uses so-called cookies on our websites. A cookie is a small text file sent from a website to your web browser. The cookie cannot identify you personally, but only the web browser that is installed on your computer and the web browser you use when visiting the webpage. Consequently, different cookies are saved on different computers, should you use different computers when visiting our website. Cookies do not carry viruses and cannot destroy any other information stored on your computer.
Cookies are usually categorized based on their origin and based on whether they are stored in your web browser or not. Cookies can either be sent to you from the website you visit (i.e. first-party cookie) or from another organisation that delivers services to the current website, such as an analysts and statistical company (i.e. third-party cookies). Cookies can also be divided into session cookies and permanent cookies. A session cookie is sent to your computer so that the webpages can function properly during your visit and is not stored on your computer but is erased when you close down you web browser. The function of a session cookie is for example that it is activated when you return to a previously visited part of the website and thus facilitates your navigation on the website. A permanent cookie, on the other hand, is stored in your web browser and thus allows a web page to recognize your computer’s IP address even if you turn of your computer or log out between visits.
The company uses both session cookies and permanent cookies on our website.
If the changes concern processing of personal data that we carry out based on your consent, we will give you the opportunity to once again give your consent to the processing on the new terms.
Episurf Medical AB
SE-114 49 Stockholm
Phone +46 (0) 8 612 00 20