The respect of privacy is a serious concern to which we pay special attention when processing and using personal data. We therefore attribute great importance to the protection of your personal data. Insofar as personal data is collected (e.g. your name, address or other contact details), it is processed and used exclusively in accordance with applicable data protection regulations.
In the following we would like to inform you about the processing of personal data when using this website. Personal data are all data that identify you, e.g. name, address, e-mail addresses, user behavior.
1. Controller & Data Protection Officer
Responsible Controller for the collection, processing and use of your personal data in the context of the GDPR is: “PHOENIX Pharma” EOOD, 199A, Okolovrasten pat, Str. 1700 Sofia, Bulgaria, tel: +359 2 9658 100 fax: +359 2 9658 172.
You can reach our data protection officer at firstname.lastname@example.org.
2. Data Collection during the visit of the website
(1) When using the website for information purposes only, i.e. if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server. If you wish to view our website, we collect the following data, which is technically necessary for us to display our website to you and to ensure its stability:
- IP address
- date and time of the request
- Time zone difference to Greenwich Mean Time (GMT)
- Content of the request (specific page)
- Access status/HTTP status code
- amount of transferred data
- Referrer URL
- Browser Type
- Operating system and its interface
- Language and version of the browser software
(2) In addition to the aforementioned data, cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your hard disk in the browser you use and through which certain information flows to the instituion that sets the cookie. Cookies cannot run programs or transmit viruses to your computer. They serve to make the Internet offer more user-friendly and effective overall.
- This website uses the following types of cookies, the scope and functioning of which are explained below:
Transient cookies (see b)
Persistent cookies (see c).
- Transient cookies are automatically deleted when you close your browser. This includes in particular the session cookies. These store a so-called session ID, with which different requests of your browser can be assigned to the common session. This will allow your computer to be recognized when you return to our website. Session cookies are deleted when you log out or close your browser.
- Persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie. You can delete cookies at any time in the security settings of your browser.
- You can configure your browser settings according to your wishes and, for example, refuse the acceptance of third party cookies or all cookies. Please note that you may not be able to use all functions of this website.
- We use HTML5 storage objects that are stored on your mobile device. These objects store the required data independently of your browser and do not have an automatic expiry date. You can prevent the use of HTML5 storage objects by using private mode in your browser. We also recommend that you regularly delete your cookies and browser history manually.
(4) The legal basis for data processing in accordance with the above paragraphs is Art 6 (1) lit. f) GDPR. Our interests in data processing are in particular to enable the use of the website by ensuring the stability of its operation and the security of the website. Unless specifically stated, we only store personal data for as long as is necessary to fulfil the purposes pursued.
(5) If we make use of contracted service providers for individual functions of our offer or would like to use your data for advertising purposes, we will inform you in detail about the respective processes below. We also specify the defined criteria for the storage period.
3. E-Mail Contact
If you contact us (e.g. via contact form or e-mail), we store your details for processing the enquiry and for any follow-up questions. We delete the data arising in this context after the storage is no longer necessary, or limit the processing if statutory retention obligations exist. We only store and use further personal data if you give your consent or if this is legally permissible without special consent.
(1) By actively giving your consent you can subscribe to our newsletter, with which we inform you about our current interesting offers and services. The advertised goods and services are named in the declaration of consent.
(2) We use the double opt-in procedure to subscribe to our newsletter. This means that after your registration we will send you an e-mail to the specified e-mail address in which we ask you to confirm that you would like the newsletter to be sent. In addition, we store your IP addresses and the time of registration and confirmation. The purpose of the procedure is to be able to prove your registration and, if necessary, to clarify a possible misuse of your personal data.
(3) The only mandatory information for sending the newsletter is your e-mail address. The indication of further, separately marked data is voluntary and is used to be able to address you personally. After your confirmation we will save your e-mail address for the purpose of sending you the newsletter. The legal basis is Art. 6 (1) lit. a GDPR.
(4) You can revoke your consent to the sending of the newsletter at any time and cancel the newsletter. You can declare your revocation by clicking on the link provided in every newsletter e-mail.
(5) We point out to you that we evaluate your user behaviour when sending the newsletter. For this analysis, the e-mails sent contain so-called web beacons or tracking pixels, which represent single-pixel image files stored on our website. For the evaluations we link the data mentioned in § 3 and the web beacons with your e-mail address and an individual ID.
5. Further functions and offers of our website
(1) In some cases, we use external service providers/contract processors to process your data. These have been carefully selected and commissioned by us, are bound by our instructions and are regularly checked.
(2) Furthermore, we may pass on your personal data to third parties if we offer participation in promotions, competitions, conclusion of contracts or similar services together with partners. You will receive more detailed information when you provide your personal data.
(3) If our service providers or partners are based in a country outside the European Economic Area (EEA), we will inform you of the consequences of this circumstance in the description of the offer.
- On behalf of us Google will use this information for the purpose of analyzing your use of the website, compiling reports on website activity and providing us with other services relating to website activity and internet usage.
- Google will not associate the IP address transmitted by your browser with any other data held by Google. Google may also transfer this information to third parties where required to do so by law, or where such third parties process this information on Google’s behalf.
- At any time you may delete cookies placed on your computer by calling up the relevant menu item in your internet browser or deleting the cookies on your hard drive. For details, see the Help menu of your internet browser.
- Further information is available at http://tools.google.com/dlpage/gaoptout?hl=en. We want to point out that the code “_anonymizeIp();” has been added to Google Analytics on the website to guarantee the anonymous collection of IP addresses (so-called IP masking).
Google Web Fonts
Google Fonts are used to improve the visual presentation of various information on this website. The web fonts are transferred to the cache of the browser when the page is called up so that they can be used for display. If your browser does not support Google Web Fonts or does not allow access, the text will be displayed in a default font.
Data submitted in connection with the page visit is sent to resource-specific domains such as fonts.googleapis.com or fonts.gstatic.com. They are not associated with data that may be collected or used in connection with the parallel use of authenticated Google services.
You can set your browser so that the fonts are not loaded from Google servers (e.g. by installing add-ons like NoScript or Ghostery for Firefox.) If your browser does not support Google Fonts or if you block access to the Google servers, the text will be displayed in the system’s default font.
This website uses plug-ins from the American company Vimeo, LLC, 555 West 18th Street, New York, New York 10011, USA. As a consequence, log information may be transmitted from our website to Vimeo. Vimeo’s server in the United States thus automatically stores information (“log data”), such as the information that your browser sends to a website when you visit, or the information that your mobile app sends when you use it. This log data may contain your IP address, the address of the website you visited that uses Vimeo features, the browser type and settings, the date and time of your request, information about your use of Vimeo, and cookies.
On our website social plugins (“plugins”) are used by social networks.
In order to increase the protection of your data when visiting our website, the plugins are not unrestricted, but only integrated into the page using an HTML link (so-called “Shariff solution” from c’t). This integration ensures that no connection is established with the servers of the provider of the respective social network when a page of our website containing such plug-ins is called up. Click on one of the buttons, a new window of your browser opens and calls up the page of the respective service provider, on which you can (if necessary after entering your login data) e.g. press the Share button.
The purpose and scope of data collection and the further processing and use of the data by the providers on their pages as well as your relevant rights and setting options for the protection of your privacy can be found in the data protection information of the following providers:
XING AG (Dammtorstr. 30 – 20354 Hamburg – Germany)
LinkedIn Corporation (2029 Stierlin Court – Mountain View – CA 94043 – USA)
facebook Inc. (1601 p. California Ave, Palo Alto, CA 94304, USA)
Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043 USA)
Twitter Inc. (795 Folsom St., Suite 600, San Francisco, CA 94107, USA)
7. Your Data Privacy Rights
We gladly want to you inform you regarding your rights according to the general data protection regulation:
Right of Access
You have the right to request confirmation whether data concerning you are being processed and to request information regarding these data according to Art. 15 GDPR
Right to rectification
In accordance with Article 16 of the GDPR, you have the right to request the completion or correction of inaccurate data concerning you.
Right to erasure
In accordance with Art. 17 GDPR, you have the right to demand that relevant data may be deleted in case there are no legal obligations preventing the deletion.
Right to restriction of processing
You may demand a restriction of the processing in accordance with Art. 18
Right of data portability
You have the right to request to receive the data provided to us in accordance with Art. 20 GDPR and additionally to request its transmission to other processors
Right to object
You may object to the future processing according to Art. 21 GDPR at any time.
Right to revocation
You have the right to revoke consent anytime according to Art. 7 Par. 3 GDPR valid for the future.
Right to notify the supervisory authority
In accordance with Art. 77 GDPR you have the right to file a complaint with the competent supervisory authority.
8. Reporting System
The PHOENIX group, i.e. the PHOENIX Pharmahandel GmbH & Co KG as well as its affiliated companies according to §§ 15ff AktG, has established a web based reporting system which is designed to enable employees, business partners, customers and third parties an easy system by which to report data incidents or concerns. These reports are taken seriously and are reviewed and actioned regularly and are used to improve the protection of personal data.
You can access this reporting tool at any time via:
In order to explain the background to the reporting system in more detail, we have also answered a number of frequently asked questions below:
When should I report an incident?
PHOENIX group has an obligation to notify the supervisory authority within 72 hours of becoming aware of an incident, due to this, all incidents must be reported without delay via the online reporting tool.
What data incidents should be reported and how?
All personal data incidents are to be reported to the Data Protection team via the online reporting tool.
What is a data protection incident?
Data Protection incidents are any event which has, or could have, resulted in the accidental or deliberate loss of personal data (electronic or paper) or destruction of data, or unauthorised access to data (e.g. loss or theft of laptop, smartphone, paper record, prescriptions).
What happens after I submit a report?
The Data Protection team will review the incident report and will contact you for further information or, where necessary, will assist you with the post incident actions.
9. General Comments
We retain the right to change our data privacy statement. This may be necessary as a result of technical developments. We therefore ask you to consult the data privacy statement from time to time and to apply the current version.
If you have do have any further questions or concerns regarding you personal data, please contact the designated data protection officer.
Date of last review and update: May 2018