Privacy Policy

I. PRIVACY POLICY AND DATA PROTECTION

Respecting the provisions of current legislation, CMC Medical Devices (hereinafter, also the Website) undertakes to adopt the necessary technical and organizational measures, according to the level of security appropriate to the risk of the data collected.

Laws incorporated in this privacy policy

This privacy policy is adapted to current Spanish and European regulations regarding the protection of personal data on the internet. Specifically, it complies with the following rules:

  • The General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (GDPR).
  • Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights (LOPD-GDD).
  • Royal Decree 1720/2007, of 21 December, approving the Regulations for the development of Organic Law 15/1999, of 13 December, on the Protection of Personal Data (RDLOPD).
  • Law 34/2002, of 11 July, on Information Society Services and Electronic Commerce (LSSI-CE).

Identity of the controller of personal data

Address: Calle Horacio Lengo 18, Cp29006 Málaga

Contact telephone: +34951214054

Contact email: info@cmcmedicaldevices.com

Registry of Personal Data

In compliance with the GDPR and the LOPD-GDD, we inform you that personal data collected by CMC Medical Devices, through the forms extended on its pages, will be incorporated and processed in our files in order to facilitate, expedite, and fulfill the commitments established between CMC Medical Devices and the User or the maintenance of the relationship established in the forms filled out by the latter, or to address a request or query.

Likewise, in accordance with the provisions of the GDPR and the LOPD-GDD, unless the exception provided for in Article 30.5 of the GDPR applies, a record of processing activities is maintained specifying, according to its purposes, the processing activities carried out and the other circumstances established in the GDPR.

Principles applicable to the processing of personal data

User’s personal data processing shall be subject to the following principles set forth in Article 5 of the GDPR and in Articles 4 and following of Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights:

  • Principle of legality, fairness, and transparency: User consent will be required at all times prior to transparently informing them of the purposes for which personal data are collected.
  • Principle of purpose limitation: Personal data will be collected for specified, explicit, and legitimate purposes.
  • Principle of data minimization: The personal data collected will be only those strictly necessary in relation to the purposes for which they are processed.
  • Principle of accuracy: Personal data must be accurate and kept up to date.
  • Principle of storage limitation: Personal data will be kept in a way that allows the identification of the User only for the time necessary for the purposes of its processing.
  • Principle of integrity and confidentiality: Personal data will be processed in a manner that ensures its security and confidentiality.
  • Principle of proactive responsibility: The Controller of processing shall be responsible for ensuring that the above principles are complied with.

Categories of personal data

The categories of data processed at CMC Medical Devices are only identifying data. Under no circumstances are special categories of personal data processed within the meaning of Article 9 of the GDPR.

Legal basis for the processing of personal data

The legal basis for the processing of personal data is consent. CMC Medical Devices is committed to obtaining the express and verifiable consent of the User for the processing of their personal data for one or more specific purposes.

The User shall have the right to withdraw their consent at any time. Withdrawing consent shall be as easy as giving it. As a general rule, withdrawing consent shall not condition the use of the Website.

In cases where the User must or may provide their data through forms to make inquiries, request information, or for reasons related to the content of the Website, they will be informed in case the completion of any of them is mandatory because they are essential for the proper development of the operation carried out.

Purposes of the processing to which the personal data are intended

Personal data are collected and managed by CMC Medical Devices for the purpose of facilitating, expediting, and fulfilling the commitments established between the Website and the User or maintaining the relationship established in the forms filled out by the latter or to address a request or query.

Likewise, data may be used for commercial purposes of personalization, operation, and statistics, and activities inherent in the corporate purpose of CMC Medical Devices, as well as for extracting, storing data, and marketing studies to adapt the Content offered to the User, as well as to improve the quality, operation, and navigation on the Website.

At the time personal data are obtained, the User will be informed about the specific purpose or purposes of the processing to which the personal data will be intended; that is, the use or uses that will be given to the collected information.

Retention periods of personal data

Personal data will only be retained for the minimum time necessary for the purposes of its processing and, in any case, only during the following period: 24 months, or until the User requests their deletion.

At the time personal data are obtained, the User will be informed about the period during which the personal data will be retained or, when that is not possible, the criteria used to determine this period.

Recipients of personal data

The User’s personal data will not be shared with third parties.

In any case, at the time personal data are obtained, the User will be informed about the recipients or categories of recipients of the personal data.

Personal data of minors

Respecting the provisions of Articles 8 of the GDPR and 7 of Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights, only those over 14 years of age may give their consent for the processing of their personal data in a lawful manner by CMC Medical Devices. If the User is under 14 years of age, the consent of their parents or guardians will be required for the processing, and this will only be considered lawful to the extent that they have authorized it.

Secrecy and security of personal data

CMC Medical Devices undertakes to adopt the necessary technical and organizational measures, according to the level of security appropriate to the risk of the data collected, to ensure the security of personal data and to prevent their destruction, loss, or accidental or unlawful alteration of personal data transmitted, stored, or processed in any other way, or unauthorized communication or access to such data.

The Website has an SSL (Secure Socket Layer) certificate, which ensures that personal data are transmitted securely and confidentially, as the transmission of data between the server and the User, and in feedback, is fully encrypted.

However, since CMC Medical Devices cannot guarantee the impregnability of the internet or the absence of hackers or others who fraudulently access personal data, the Controller of processing undertakes to inform the User without undue delay when a personal data security breach is likely to result in a high risk to the rights and freedoms of natural persons. In accordance with Article 4 of the GDPR, a personal data breach is understood as any breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or processed in any other way.

Personal data will be treated as confidential by the Controller of processing, who undertakes to inform and ensure, by means of a legal or contractual obligation, that confidentiality is respected by its employees, associates, and any person to whom it makes the information accessible.

Rights derived from the processing of personal data

The User has and may, therefore, exercise against the

Controller of processing the following rights recognized in the GDPR:

  • Right of access: The User has the right to obtain from the Controller of processing confirmation as to whether or not personal data concerning them are being processed, as well as detailed information regarding certain aspects of the processing being carried out.
  • Right to rectification: The User has the right to obtain the rectification of inaccurate personal data concerning them or to have incomplete personal data completed.
  • Right to erasure (“right to be forgotten”): The User has the right to obtain from the Controller of processing the erasure of personal data concerning them when the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed.
  • Right to restriction of processing: The User has the right to obtain from the Controller of processing restriction of processing where one of the following applies: the accuracy of the personal data is contested by the User, the processing is unlawful and the User opposes the erasure of the personal data, the Controller of processing no longer needs the personal data for the purposes of the processing, but they are required by the User for the establishment, exercise or defense of legal claims, and when the User has objected to processing.
  • Right to data portability: The User has the right to receive the personal data concerning them, which they have provided to a Controller of processing, in a structured, commonly used and machine-readable format and have the right to transmit those data to another Controller of processing without hindrance from the Controller to which the personal data have been provided.
  • Right to object: The User has the right to object at any time, on grounds relating to their particular situation, to processing of personal data concerning them.
  • Right not to be subject to a decision based solely on automated processing, including profiling: The User has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.

Therefore, the User may exercise their rights by sending a specific request, along with a copy of their national identity document or equivalent identification document, to the following addresses:

  • Postal address: CMC Medical Devices, Calle Horacio Lengo 18, Cp29006 Málaga
  • Email: info@cmcmedicaldevices.com

Similarly, the User may, if they wish, unsubscribe from any of the subscription services provided by clicking on the unsubscribe section of all emails sent by CMC Medical Devices.

Likewise, the User may contact the Data Protection Officer of CMC Medical Devices, by writing to the email address provided for this purpose.

Links to third-party websites

The Website may contain links or hyperlinks to other sites and internet content that are not operated, controlled, maintained, or owned by CMC Medical Devices. Therefore, the Controller of processing does not assume any responsibility for the content of such websites or the connection possibilities or results obtained through these links.

These links are provided exclusively to inform the User about the existence of other sources of information on a specific topic, and the inclusion of a link does not imply approval of the linked site by the Controller of processing.

The User accesses such websites at their own risk and under the terms and conditions governing them.

Acceptance and changes in this privacy policy

It is necessary that the User has read and agrees with the conditions on the protection of personal data contained in this Privacy Policy, as well as that they accept the processing of their personal data so that the Controller of processing can proceed to process them in the manner, during the periods, and for the purposes indicated. The use of the Website will imply acceptance of the Privacy Policy of the Website.

CMC Medical Devices reserves the right to modify its Privacy Policy, according to its own criteria, or motivated by a legislative, jurisprudential, or doctrinal change of the Spanish Data Protection Agency.

Changes or updates to this Privacy Policy will be explicitly notified to the User.

This Privacy Policy was updated on 13/12/2022 to adapt to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (GDPR).