Overview
The protection of your personal data, as well as a transparent and responsible handling of your information, is of great importance to SanMed GmbH.
We process personal data exclusively in compliance with the applicable data protection laws, in particular the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).
This Privacy Policy informs you about the personal data collected and processed by SanMed GmbH in its capacity as data controller, the purposes for which such processing is carried out, and the rights to which you are entitled in connection with the processing of your personal data.
Data Controller
The data controller within the meaning of the General Data Protection Regulation (GDPR) is:
SanMed GmbH
Leesdorfer Hauptstraße 60/3
2500 Baden
Austria
Phone: +43 2252 21628
Email: office@sanmed.at
Processing of Personal Data When Using Our Website
When you use our website, personal data may be processed. The nature, scope, and purpose of such processing depend in particular on the areas of the website you visit and the functions you use.
To ensure a user-friendly, secure, and fully functional website, we may use cookies and similar technologies. Where your consent is required for such processing, your data will only be processed following your prior consent provided through the consent management system implemented on our website.
You may change or withdraw your consent at any time with future effect. The relevant settings can be accessed via the website’s cookie settings.
Technically necessary cookies and similar technologies that are required for the operation and security of the website are used on the basis of our legitimate interests or to provide the services expressly requested by you. These technologies enable essential functions such as page navigation, security settings, language preferences, and the storage of your privacy preferences.
Where services provided by third-party providers are integrated into our website and personal data is transferred to countries outside the European Economic Area (EEA), such transfers are carried out exclusively in accordance with the requirements of the GDPR. Appropriate safeguards, including adequacy decisions issued by the European Commission or Standard Contractual Clauses (SCCs), are implemented to ensure an adequate level of data protection.
Further information regarding the cookies, technologies, and third-party providers used on this website can be found in the following sections of this Privacy Policy.
Processing of Data for the Provision of the Website
Server Log Files
When you visit our website, information is automatically collected by the hosting provider and stored in so-called server log files. This information may include, in particular:
- IP address of the requesting device
- Date and time of access
- Pages and files accessed
- Volume of data transmitted
- Browser type and browser version
- Operating system used
- Referrer URL (previously visited website)
This data is processed for the purposes of ensuring system security, analysing errors, and providing the technical operation of the website.
The legal basis for this processing is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable, and proper provision of our website.
The data is not used to draw conclusions about individual persons and is retained only for as long as necessary to fulfil the purposes described above.
Technically Necessary Cookies
Our website uses only technically necessary cookies that are essential for the secure and proper operation of the website.
These cookies enable fundamental functions such as page navigation, ensuring system security, storing your privacy preferences, and providing the content you request. Without these cookies, the website cannot function properly.
The use of technically necessary cookies is based on our legitimate interest in the secure and functional provision of our online services pursuant to Article 6(1)(f) GDPR and the applicable data protection legislation.
Technically necessary cookies are generally stored only for the duration of your visit or are automatically deleted after the respective period required for their purpose has expired.
You may configure your browser to block or delete cookies. Please note, however, that in this case certain functions of our website may not be available or may only be available to a limited extent.
Links to External Websites
Our website may contain references and links to websites operated by third parties. By clicking on such a link, you leave the area of responsibility of SanMed GmbH.
Please note that the respective operators of the linked websites are solely responsible for the content, functionality, and processing of personal data on their websites. SanMed GmbH has no influence over the compliance of such third parties with applicable data protection laws.
We therefore recommend that you read the privacy policies of the websites you visit before providing personal data or using any additional online services.
Drug Safety and Reporting of Adverse Events
The safety of medicinal products is of the highest priority for SanMed GmbH. If you provide us with information relating to a suspected adverse reaction, a product quality complaint, a medication error, or any other information relevant to drug safety, we process the personal data required for the handling and documentation of such reports.
This may include, in particular, information relating to your identity, health status, use of a medicinal product, reported adverse reactions, and any other information relevant to the assessment of the reported matter.
The provision of such information is voluntary. Please note, however, that incomplete information may hinder or, in individual cases, prevent the proper assessment and processing of a report.
The processing of such data is carried out for the purpose of fulfilling legal obligations relating to drug safety (pharmacovigilance), monitoring the safety of medicinal products, and complying with regulatory reporting and documentation requirements.
The legal basis for this processing includes, in particular, Article 6(1)(c) GDPR (compliance with a legal obligation), Article 9(2)(i) GDPR (reasons of public interest in the area of public health), as well as the relevant provisions of the Austrian Medicines Act and European pharmacovigilance legislation.
The data will be processed exclusively for pharmacovigilance and drug safety purposes and, where required by law, may be disclosed to competent authorities or other authorised entities.
Disclosure of Personal Data to Third Parties
Your personal data will only be disclosed where this is necessary for the performance of our duties and services, required by law, or otherwise permitted under applicable data protection legislation.
To support our business operations, we may engage external service providers, for example in the areas of IT services, hosting, maintenance, or other operational services. Where such service providers process personal data on our behalf, this is carried out exclusively on the basis of a data processing agreement in accordance with Article 28 GDPR. These service providers are required to comply with the applicable data protection laws and may process personal data only in accordance with our instructions.
In addition, personal data will only be transferred to third parties where:
- such disclosure is required by law;
- the disclosure is necessary for the protection of legitimate interests and there are no overriding interests or fundamental rights and freedoms of the data subject requiring protection;
- the disclosure is necessary for the performance of contractual obligations or the implementation of pre-contractual measures; or
- the data subject has given their prior explicit consent.
Any consent provided may be withdrawn at any time with effect for the future.
Personal data will only be disclosed to authorities, courts, or other public bodies to the extent required by applicable legal provisions or pursuant to a lawful administrative or judicial order.
Transfer of Personal Data to Third Countries
Where necessary for the fulfilment of our legal or contractual obligations, or where required in connection with the use of certain service providers, personal data may be transferred to recipients located in countries outside the European Union (EU) or the European Economic Area (EEA).
Any such transfer is carried out exclusively in accordance with the requirements of the GDPR. In particular, we ensure that an adequate level of data protection is maintained, for example through an adequacy decision issued by the European Commission or by implementing appropriate safeguards, such as the European Commission’s Standard Contractual Clauses.
Where, in individual cases, no appropriate safeguards are in place and a transfer is nevertheless necessary, such transfer will be carried out solely on the basis of the applicable derogations provided for under the GDPR or on the basis of your explicit consent, where legally permissible and required.
Further information regarding any transfers of personal data to third countries may be requested at any time using the contact details provided in the section entitled “Data Controller.”
Protection of Personal Data
SanMed GmbH implements appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, unauthorised alteration, or disclosure.
Our security measures are regularly reviewed and adapted in line with technological developments to ensure an appropriate level of protection for the personal data we process.
Data transmitted between your device and our website is transferred via an encrypted connection using recognised security standards (SSL/TLS technology). This protects the transmitted information against access by unauthorised third parties.
You can generally recognise an encrypted connection by the fact that the website address begins with “https://” and your browser indicates that a secure connection has been established.
Despite extensive security measures, please note that complete security of data transmission over the Internet cannot be guaranteed.
Storage and Deletion of Personal Data
We process and store personal data only for as long as necessary to fulfil the respective processing purposes or as required by applicable legal retention obligations.
As soon as the purpose of the processing ceases to apply and no statutory, regulatory, or contractual retention obligation exists, the relevant personal data will be deleted or anonymised.
Where processing is based on your consent and you withdraw such consent, or where you validly object to the processing, the relevant data will be deleted unless another legal basis for continued processing exists.
Where statutory retention or documentation obligations, in particular under corporate, tax, or pharmaceutical legislation, prevent the immediate deletion of personal data, the relevant data will be restricted from further processing for the duration of the applicable retention period and will subsequently be deleted.
Your Rights as a Data Subject
Under the provisions of the General Data Protection Regulation (GDPR), you have various rights regarding the processing of your personal data.
In particular, you have the right to:
- obtain information as to whether and which personal data concerning you is being processed by us (Article 15 GDPR);
- request the rectification of inaccurate personal data and the completion of incomplete personal data (Article 16 GDPR);
- request the erasure of your personal data, provided that the legal requirements for such erasure are met (Article 17 GDPR);
- request the restriction of the processing of your personal data (Article 18 GDPR);
- receive your personal data in a structured, commonly used, and machine-readable format and have that data transmitted to another data controller, where the legal requirements are met (Article 20 GDPR);
- object, on grounds relating to your particular situation, to the processing of your personal data where such processing is based on legitimate interests (Article 21 GDPR);
- withdraw any consent previously given at any time with effect for the future (Article 7(3) GDPR).
The withdrawal of consent shall not affect the lawfulness of any processing carried out on the basis of consent before its withdrawal. To exercise your rights, you may contact us at any time using the contact details provided in the “Data Controller” section.
Right to Lodge a Complaint
If you believe that the processing of your personal data violates applicable data protection laws, you have the right to lodge a complaint with the competent data protection supervisory authority.
In Austria, this is:
Austrian Data Protection Authority (Datenschutzbehörde)
Barichgasse 40-42
1030 Vienna
Austria
Website: www.dsb.gv.at
Changes to this Privacy Policy
We reserve the right to update or amend this Privacy Policy from time to time to ensure compliance with changes in applicable laws, regulatory requirements, or our data processing activities.
The current version of this Privacy Policy is available on our website at all times and shall apply from the date of its publication.
Last updated: October 2026