MEDTRONIC PRIVACY STATEMENT - DATA CAPTURE VIA SOCIAL MEDIA CHANNELS

   

Medtronic (hereinafter referred to as “we”) are committed to maintaining your trust by protecting your Personal Information. This Privacy Notice explains how we process your personal information collected via your sign up on Social Media channels, using our Marketing Automation platform and Customer Relationship Management systems.

We are committed to ensuring that your privacy is respected and that your Personal Information is handled in a transparent and lawful way. Any Personal Information you provide will only be used in accordance with this Privacy Statement. We encourage you to read this Privacy Statement carefully.

We recognize that data privacy is an ongoing responsibility and therefore in case of any material changes to our privacy practices or policies we will revise this Privacy Notice. Any significant update to this Privacy Notice will be brought to your attention either via an email or other electronic notification to you, or by posting a notice on our website or appropriate social media channel. This Privacy Statement was last revised on July 4th, 2019.

WHAT IS PERSONAL INFORMATION?

“Personal Information”, (also known as “Personal Data” or “Personally Identifiable Information”) is any information relating to an identified or identifiable person; in other words: any information which can lead to knowing who you are (either directly or indirectly). Your name, address, phone number and social media username or profile are examples of Personal Information. 

PROCESSING OF PERSONAL INFORMATION 

When we process your Personal Information we will ensure that we have an appropriate legal basis, and will get your consent first if necessary. More information on the Personal Information that we process, and the legal basis we rely on, is set out below:

Consent 

Your consent is optional and can be withdrawn at any time in the same way as it was given, or by contacting us as detailed in the Your Rights section below. You may also at any time, free of charge and without having to provide any justification, opt-out of any direct marketing campaigns and request to no longer receive any promotional material by using the opt-out option in any relevant communication you receive. If any changes to this notice impact the terms under which you provided your consent, we will notify you and provide you with the option to withdraw or renew your consent.
Medtronic may process your Personal Information to the extent you have provided consent, in the following situations:

  • Processing Activity
  • Marketing Initiatives based on sign up on social media channels (e.g. via LinkedIn): Medtronic will send you product related information that is relevant to you (marketing).
  • Purpose
  • To contact you with information on Medtronic Products, Services and Solutions. 
  • Categories of Personal Information (Data Elements processed)
  • Name, Contact details (email,phone number,address (Country only) mobile phone number, job role, company
  • Logic, Significance & Consequences
  • Once you sign up (by clicking the relevant box or similar) you provide your consent for Medtronic to use the relevant personal information to send you relevant information
  • Legal Basis 
  • Your consent
  • Which data subject rights may apply?
  • Applicable data protection laws may provide the following rights for individuals: Access, Rectification, Erasure, Data Portability, Withdraw Consent

Security

We are committed to protect the security and confidentiality of Personal Information. To prevent accidental or unlawful destruction, loss, alteration, unauthorized access or disclosure of, the Personal Information, we use appropriate technical and organizational measures to safeguard and secure the “Personal Information” we process.
We will inform you and/or the relevant supervisory authorities without undue delay should an unauthorized disclosure of the Personal Information require such a notification.

Disclosure of Your Personal Information

We may disclose your Personal Information as we believe to be necessary or appropriate to protect the health and safety of you or another person, our physical and online operations, and the property, rights, and privacy of our affiliates, you or others.
We only disclose your Personal Information to our Medtronic affiliates or third-party providers or vendors for the purposes identified above. In such cases, the third-party providers or vendors are obligated to use the Personal Information in accordance with the binding agreements that we have with them. The agreements include data processing clauses to ensure that your Personal Information is handled in accordance with applicable data protection laws and regulations.
All third-party providers or vendors involved in data processing have the obligation to meet the requirements of applicable data protection laws and regulations and to comply with Medtronic's privacy, data protection, and security policies and standards.

Categories of Third Parties

Processing Activity Purpose Categories of Personal Information ( Data Elements disclosed) Category of Recipient

Hosting of personal data in Customer Relationship Management System

To allow Medtronic to manage your personal information appropriately and enable fulfilment of other data processing purposes set out in this privacy statement.

Name, Location, Occupation, Contact details (e.g. work email, address, phone and or/or FAX number, mobile phone number)

Customer Relationship Management System provider. e.g Salesforce

Marketing Automation

To enable effective transmission of marketing communications by Medtronic.

Email address, plus additional identifiers if necessary for specific purposes
 

Marketing Automation provider. e.g. Eloqua

Please note that subject to applicable laws, we may disclose your personal information if we believe we are required to do so to comply with any law, regulation, court order, legal or government request. In the unlikely event that all or part of our business is acquired by a third party, your information may be transferred to the new corporate owner insofar as relevant to the business in question and subject to appropriate safeguards being in place. We may need to transfer your Personal Information to Regulatory Authorities in order to comply with our legal obligations.

International Transfer of Personal Information  

When we transfer your Personal Information to other Medtronic affiliates or to a third party in another country, we will ensure that adequate safeguards are in place in accordance with applicable laws.

Where we transfer Personal Information internationally we will ensure a level of protection for Personal Information that is adequate according to applicable laws and regulations. For transfers of your Personal Information we will ensure that approved legal mechanisms are in place.  For more details or to request a copy please Contact Us at rs.globalprivacyoffice@medtronic.com.

 

Retention 

We will not store your Personal Information for longer than is necessary for the purpose for which we have identified.
The criteria we use to determine our retention periods include: the duration of your relationship with Medtronic, the period during which we need to be able to demonstrate compliance with legal requirements, and the period of time for which we need to protect our legal position (e.g. in case of litigation or an investigation).
For more information on how long your Personal Information is stored please send your request to the contact details below .
 

Your Personal Rights and How to Contact Medtronic 

Your Rights
Please see the description of the processing of personal information above where the applicable data subject rights are listed.
In accordance with applicable laws, you may have the right to:

  • Access: Request access to the Personal Information which we hold concerning you.
  • Rectify, Erase, Restrict: Request that your Personal Information be rectified, erased or that our use of your Personal Information be restricted.
  • Object: based on your particular situation, you may object to our use of your Personal Information on legitimate interest grounds.
  • Data Portability: If we are providing an automated service to you (based on contract or your consent) you can also request a copy of your Personal Information in a structured, commonly used and machine-readable format.
  • Withdraw Consent: Where Personal Information is processed on the basis of your consent, you may withdraw your consent at any time.

Note: This does not affect the lawfulness of our use of your Personal Information before you withdrew your consent. Also, aggregated data which we have already complied will not be affected, even after you withdraw your consent, as there are no technical means available to isolate or identify data elements to exclude.

To exercise any of these rights, please contact us at rs.globaldataprivacyoffice@medtronic.com or by post at:

Medtronic International Trading Sàrl  (Data Controller)
Attn: Legal: Data Subject Request
Re: marketing consent / CRM / Sf.com
Case postale
Route du Molliau 31
CH-1131 Tolochenaz
Switzerland

Please note that in accordance with applicable laws, we may ask you to provide some proof of identity before we can process your request.

If you are not satisfied with our handling of your request, you may also wish to exercise your right to file a complaint with a supervisory authority.