Privacy Statement


Introduction

The purpose of this Privacy Statement is to provide transparency regarding privacy and the processing of personal data. Our goal is to prove that Sensapharm d.o.o. takes care of personal data in accordance with applicable law, such as the General Data Protection Regulation (GDPR).

Sensapharm d.o.o. processes personal data of the following categories of persons (also called data subjects):

  • Customers;
  • Suppliers;
  • Users of the website and web store;
  • Website visitors;
  • Visitors;
  • Employees and applicants not covered by this Privacy Statement

Data processing

  1. Customers

What kind of personal data do we process?
Sensapharm d.o.o. supplies a variety of customer groups, including wholesalers, pharmacies, specialty stores, cosmetic salons, wellness centers, individuals. We process certain types of personal information of our clients’ commercial representatives.

Sensapharm d.o.o. processes the following types of customer data:
• Name
• Contact information (e-mail address, telephone number)
• Function

What is the purpose of data processing?
Senspharm d.o.o. processes personal customer data for the following purposes:
• providing our customers with an appropriate order processing system
• providing our customers with the best possible service

What is the legal basis for processing?
Legal obligation
We have a legal obligation to process certain types of personal data under applicable pharmaceutical laws and regulations, such as GMP and GDP standards. We only collect basic information (names, phone numbers and email addresses) which we use mainly to process orders received and respond to your inquiries.

Contract
We also need to process personal data when concluding sales contracts with our customers.

What is the retention period?
Sensapharm d.o.o. retains personal data in accordance with the applicable legal retention period or as necessary for the purpose of processing.

  1. Suppliers

What kind of personal data do we process?
Sensapharm d.o.o. processes the following personal data of the supplier:
• Name
• Contact information (e-mail address, telephone number)
• Function

What is the purpose of processing?
Sensapharm d.o.o. processes the personal data of the supplier for the following purposes:
• guaranteeing proper handling during the procurement process
• compliance with the contractual obligation.

What is the legal basis for processing?
Contract
Sensapharm d.o.o. personal data needs to be processed in order to fulfill a contractual obligation to suppliers.

What is the retention period?
Sensapharm d.o.o. retains personal data in accordance with the applicable legal retention period or as necessary for the purpose of processing.

  1. Website and webshop users

What kind of personal data do we process?
Sensapharm d.o.o. processes the following types of personal data of registered users of the website:
• Name
• E-mail address
• Function
• Interest in the newsletter
• Behavior via the Internet on our website

What is the purpose of processing?
Sensapharm d.o.o. processes the personal data of website users for the purpose of retaining user accounts and delivering the requested service (eg web store service). We may also contact customers through surveys to provide feedback on our services to provide them with the best online experience.

What is the legal basis for processing?
Consent
Sensapharm d.o.o. will request written consent from the data subject where applicable, in order to process personal data through the website.

Legitimate interest
Sensapharm d.o.o. may also have a legitimate interest in the processing of personal data for the purpose of direct marketing. In doing so, we will always strive to balance our legitimate interest with that of the data subject. We will take care of the rights of the data subject and inform them of the possibility of objecting to the processing in an easily accessible format.

What is the retention period?
Sensapharm d.o.o. retains personal data in accordance with the applicable legal retention period or as necessary for the purpose of processing.

  1. Website visitors

What kind of personal data do we process?
Sensapharm d.o.o. processes the following types of website visitor data:
• Behavior via the Internet on our website

What is the purpose of processing?
Sensapharm d.o.o. handles the „online“ behavior of website visitors for the purpose of maintaining and improving the website.

What is the legal basis for the processing of personal data?
Legitimate interest
Sensapharm d.o.o. has a legitimate interest in the processing of personal data for marketing and communication purposes. In doing so, we will always strive to balance our legitimate interest with that of the data subject. We will take care of the rights of the data subject and inform them of the possibility of objecting to the processing in an easily accessible format.

What is the retention period?
Sensapharm d.o.o. retains personal data in accordance with the applicable legal retention period or as necessary for the purpose of processing.

  1. Visitors

What kind of personal data do we process?
Sensapharm d.o.o. processes the following types of visitor data to our facilities:
• Name
• Contact information
• Video surveillance.

What is the purpose of processing?
Sensapharm d.o.o. processes visitors’ personal data for the following purposes:
• ensuring safety and quality within our production facilities
• identification of individuals in case of misconduct.

What is the legal basis for processing?
Legal obligation
Sensapharm d.o.o. has a legal obligation to register visitors to our production and distribution facility, according to GMP and HACCP guidelines.

Consent
We will always notify our visitors of the secure recording of videos and request their written consent to authorize the processing of the videos.

What is the retention period?
Sensapharm d.o.o. retains personal data in accordance with the applicable legal retention period or as necessary for the purpose of processing.

Data transfer

1. Who has access to personal data?

Sensapharm d.o.o. uses external data processing services for a range of ancillary activities.

We use only external personal data processing services that provides sufficient guarantees of appropriate technical and organizational security measures. In the event that personal data is processed by an external processor, there is always a processing agreement.

2. To whom else do we disclose personal information?

Under certain circumstances Sensapharm d.o.o. discloses personal information to other recipients as well. This only happens when the data subject has a legitimate expectation from Sensapharm d.o.o. to do so. Examples include legal obligations to disclose personal data to public authorities.

3. What is our role in controlling access to personal data?

When Sensapharm d.o.o. processes personal data as part of sales contracts with our customers, we do not process personal data on behalf of our customers. We process personal data on our own behalf as data controllers. This means that we have our own responsibility to comply with applicable privacy laws and regulations when processing our customers’ personal information. As a consequence, there is no need for a processing contract between Sensapharm d.o.o. and its customers. Users can expect Sensapharm d.o.o. processes all personal data with the highest level of caution and secure our systems with appropriate measures to protect their privacy.

Data subject rights

1. Right of access

Each data subject has the right to access personal data provided by Sensapharm d.o.o. processed. Upon request, we will provide you with a copy of the information about your personal data that we process. We intend to process this request within 15 days of receipt, but we may extend this period to 60 days in complex cases, in which case we will notify you of the reasons for the delay. Sensapharm d.o.o. reserves the right to charge a reasonable fee in the event of an excessive request.

2. Right of correction

You can request that your personal information be corrected if the information is incorrect. Sensapharm d.o.o. intends to process the request within 15 days of receipt, but may extend this period to 60 days (once) in complex situations in which case we will notify you of the reasons for the delay. If applicable, we will notify recipients of personal information about any corrections.

3. Right of deletion

You have the right to ask Sensapharm d.o.o. to delete your personal data if one of the following circumstances applies:

• the purpose of processing no longer exists;
• you have withdrawn your consent;
• you have an objection to the processing;
• processing is illegal;
• there is a legal obligation to delete your personal data.

Sensapharm d.o.o. reserves the right to limit the right to deletion in the following cases:

• Sensapharm d.o.o. has a legal obligation to process your personal data;
• processing is necessary for the establishment, exercise or defense of legal claims;
• processing is needed to ensure high standards of our raw materials;
• the request for deletion is manifestly unfounded or excessive.

Sensapharm d.o.o. intends to comply with your request within 15 days of receipt. We may extend this period to 60 days in complex situations, in which case we will inform the data subject of the reasons for the delay. In the event that your request for deletion is denied, we will notify you in a timely manner of the reasons for the decision and your rights in this matter.

4. The right to limited data processing

You may request a restriction on the processing of your personal data in the following circumstances:

• your personal data is incorrect;
• you objected to the processing and Sensapharm d.o.o. considers whether the legitimate interests
   of Sensapharm d.o.o. have outweighed yours;
• processing is illegal;
• Sensapharm d.o.o. you no longer need your personal information, but you do need the information to determine, enforce, or defend a legal claim.

Sensapharm d.o.o. will notify you in a timely manner of the method to be used to restrict the processing of your personal data. Sensapharm d.o.o. may reject your request if it is manifestly unfounded or excessive. Sensapharm d.o.o. intends to process the request within 15 days of receipt. We may extend this period to 60 days in complex situations and will always inform you of the reasons for the delay or refusal and your rights in that matter.

5. The right to transfer personal data

In certain circumstances, you have the right to transfer data, which means that you have the right to obtain and reuse your personal data in various services. It also indicates that your personal data must be provided in an easily accessible format, which allows you to move / copy / transfer personal data from one IT environment to another. This must be done in a safe way.

The right to data portability is valid only in the following circumstances:

• personal data to Sensapharm d.o.o. are provided by an individual;
• processing is based on the consent of individuals or for the performance of contracts;
• processing is done automatically.

We intend to act on your request within 15 days of receipt. We may extend this period to 60 days in complex situations and will always inform you of the reasons for the delay and your rights in this matter.

6. Right to object

You may object to the processing of your personal data for reasons relating to your situation and if one of the following circumstances applies:

• processing is based on the legitimate interests of Sensapharm d.o.o.;
• Sensapharm d.o.o. processes your personal data for the purpose of direct marketing.

Sensapharm d.o.o. is not obliged to comply with the right of objection, if the processing does not relate to direct marketing and if:

• Sensapharm d.o.o. has a legitimate interest that goes beyond your interests;
• Sensapharm d.o.o. must process your personal information to determine, enforce or defend a legal
   claim.

Cookies

Sensapharm d.o.o. is committed to protecting your privacy and developing the technology that gives you the most powerful and secure online experience. Sensapharm d.o.o. uses cookies to improve the usability of the website.
 

What are cookies?

Cookies are small text files. When you visit Sensapharm d.o.o.’s website, these small text files are temporarily stored on your computer. Cookies are used to track website visitor settings and improve their user experience. For example, cookies provide insight into the websites they have visited and how visitors move from one website to another. Cookies also measure how many people visit a website and how long they stay on that page. With this information Sensapharm d.o.o. optimizes the website.

Are the cookies safe?

Cookies are safe. It does not store any personal data or other sensitive data related to individuals. In addition, it is not possible to track personal information via cookies or send spam or any other unsolicited email.

How do I change my cookie settings?

In your browser settings, you can specify how websites should process cookies on your computer. For example, you can define your settings as follows:

• request notification if the website wishes to place a cookie;
• refuse third-party cookies;
• delete cookies.

Contact information

For any additional information, questions and / or complaints about this Privacy Statement or the processing of personal data at Sensapharm d.o.o., please contact the Head of Personal Data Processing at the contact details below:

Davor Sipic
Vladimira Filakovca 3
10 000 Zagreb
Croatia
e-mail: sensapharm@sensapharm.hr