Privacy Policy
This is the Privacy Policy for the website of Galatea International.
Thank you for visiting www.galateasurgicalinternational.com (the “Web Site”) and reviewing our Privacy Policy. Your privacy is important to us. This privacy policy sets out how the Web Site uses and protects any information that you give when you use this website. The Web Site is committed to ensuring that your privacy is protected.
This Privacy Policy does not describe information collection practices on other sites, including those linked to or from the Web Site.
We will collect no personal information about you when you visit the Web Site unless you choose to provide that personal information. Personal information is information, or a combination of pieces of information that could reasonably allow you or your household to be identified.
Should we ask you to provide certain information by which you can be identified when using this website, then you can be assured that it will only be used in accordance with this Privacy Policy. The Website may change this policy from time to time by updating this page. You should check this page from time to time to ensure that you are happy with any changes.
Contents
1. Controller
Galatea International is the data controller responsible for the personal information that we collect and process. Our address is:
Tepha, Inc.
99 Hayden Avenue, Suite 360
Lexington, MA 02421
USA
2. Data protection officer
Tepha, Inc.
99 Hayden Avenue, Suite 360
Lexington, MA 02421
USA
If you have any questions concerning the way that we use your personal information, please contact us at: contact-international@galateasurgical.com
3. EU-Representative
Kalms Consulting GmbH
Rheinstraße 45-46
12161 Berlin
Email: dataprotection@kalmsconsulting.com
4. Purpose and legal basis of data processing
We may process personal data to meet our legitimate interests, for example to understand how you use our products and services and to enable us to derive knowledge from that, which allows us to develop new products and services and to assess your job application. When we process personal information to meet our legitimate interests, we put in place robust safeguards to ensure that your privacy is protected and to ensure that our legitimate interests are not overridden by your interests or fundamental rights and freedoms.
On our website, we collect personal data via the contact form. We require this information to understand your needs and provide you with a better service, and in particular for the following reasons:
• Internal record keeping;
• We may use the information to improve our products and services;
• If you have expressly consented, we may periodically send you promotional emails about new products, special offers or other information that we believe may be of interest to you, using the email address you have provided;
• If you have expressly consented, we may also use your information to contact you for market research purposes. We may contact you by email, phone, fax or mail. We may use the information to customize the website according to your interests.
4.1 Transfer of your data to the USA and third countries
Tepha Inc. is an American company. In order for us to contact you, it is necessary that you consent to the transfer of data to the USA or third countries. The European Court of Justice has ruled that the level of data protection in the USA does not meet EU standards. This is justified by the fact that there is a risk that your data may be processed by U.S. authorities, for control and monitoring purposes, possibly without any legal remedy.
It is necessary to obtain your consent to the transfer and processing of your data in the USA and in third countries pursuant to Art. 49 (1) p. 1 lit. a DSGVO. Therefore, when you visit our website, you will be explicitly asked for consent to the transfer before you submit your personal data to us via the contact form.
4.2 Contact Form
4.2.1 Purpose and legal basis of processing
The processing of your personal data is carried out on the legal basis of Article 6(1a) and 1f of the GDPR.
We collect personal data via the contact form on our website, provided that the user actively records it there and transmits it to us. We require this data in order to be able to contact you as a potential customer and to provide you with the necessary information about our product, as well as to send you future product information upon request. In particular, the processing is necessary to carry out pre-contractual measures.
Similarly, it is in our legitimate interests as a medical device manufacturer to inform healthcare professionals as users of our products about our products, as well as to understand how you use our products and services and to enable us to derive insights from this that will enable us to develop new products and services and evaluate your application. When we process personal data to fulfill our legitimate interests, we use robust safeguards to ensure that your privacy is protected and that our legitimate interests are not overridden by your interests or fundamental rights and freedoms.
4.2.2 Personal data collected
We collect the following personal data via our contact form:
• Your full Name
• Company
• Contact information including email address
• City
• Country
• Phone
4.2.3 Processing and transmission
Your personal information collected through the contact form will be shared with recipients in the following categories.
• Our web hosting provider in the USA
• Microsoft Corporation, in the context of processing email data using Office 365.
• The respective local distributor of our product from your country. Your data will only ever be transferred to the local sales partner responsible for your country.
We have concluded corresponding contracts with our local sales partners, which ensure that your data may only be further processed in accordance with the provisions of the GDPR.
4.2.4 Period of Data storage
The collected contact data will be deleted within 30 days after transmission to us. Please note that we may be required by law to collect certain personal information about you, or because of any contractual relationship we have with you. Failure to provide this information may prevent or delay the fulfilment of these obligations. We will inform you at the time your information is collected whether certain data is compulsory and explain the consequences of any failure to provide such data.
4.3 Cookies
On our website we currently do not process cookies that contain any personal data.
5. Your rights as a data subject of data processing
You have, subject to local law, certain rights regarding your personal information. These include the rights to:
• access your personal information;
• rectify the information we hold about you;
• erase your personal information;
• restrict our use of your personal information;
• object to our use of your personal information;
• receive your personal information in a usable electronic format and transmit it to an external party (right to data portability);
• learn more about the sources from which we collect information, the purposes for which we collect and share information, the information we hold, and the categories of parties with whom we share your information;
• exercise rights without fear of being denied goods or services;
• lodge a complaint with your local data protection authority.
We encourage you to contact us to update or correct your information if it changes or if the personal information we hold about you is inaccurate.
We will contact you if we need additional information from you in order to honour your requests.
6. Security
We are committed to ensuring that your information is secure. In order to prevent unauthorized access or disclosure, our host service has put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect online.
7. Links to other websites
Our website may contain links to other websites of interest. However, once you have used these links to leave our site, you should note that we do not have any control over that other website. Therefore, we cannot be responsible for the protection and privacy of any information which you provide whilst visiting such sites and such sites are not governed by this privacy statement. You should exercise caution and look at the privacy statement applicable to the website in question.
8. Changes and updates to this policy
We reserve the right to change the information, services, features and policies at any time. We will post changes to this and any other policies on this website in writing. This policy is effective as of February 2021.