Privacy Policy

Welcome to the MDSS Consulting website. We appreciate your interest in our company. Protection of the personal data you entrust to us is a priority and we want you to feel safe and secure when you visit our website or use our online offers.

Principles of data processing for our Advisory Services with respect to interested parties
In order to fulfill the information obligation towards you as a party interested in our products per to Art. 12, 13 of the General Data Protection Regulation (GDPR), we subsequently present you our information on data protection.

Who is responsible for data processing?
The responsible entity as per data privacy law is

MDSS Consulting GmbH
Schiffgraben 41
30175 Hannover
Tel: 0511 6262 8638
consulting@mdssco.com

Which data do we process? And for which purposes?
If we have received data from you, we basically process them only for the purposes for which we have collected them.

As a rule, these purposes are:

  • Possible conclusion of a contract (within the services here offered, such as Quality Management, Regulatory Affairs, Clinical Evaluation and PRRC).
  • Internal and external communication
  • Assertion of legal claims and defense in case of legal disputes
  • Information on our products and services (customer surveys included), unless you have objected to the use of your data
  • Invoicing and debiting
  • Statistical evaluation or market analysis
  • Subscription to our newsletter

These data are in general:

  • Your master data (e.g. last name, first name, title, address form)
  • Contact data (e.g. email address, phone number, mobile phone number)
  •  Transaction data (e.g. IBAN, BIC, billing address)
  • Data on your request

And other personal data you may provide to us in the course of our mutual (pre)contractual relation.

Please note that we cannot enumerate all potential data. We do, however, collect only data which you actively provide to us, or which are publicly available.

Data processing for other purposes is considered only if the required legal specifications according to Art. 6 Section 4 of the GDPR apply. In such a case, we will naturally fulfill possible information obligations according to Art. 13 Section 3 of the GDPR and Art. 14 Section 4 of the GDPR.

Which legal provisions is this based on?

  • Data processing for the performance of a contract (Art. 6 Section 1 lit. b of the GDPR)
  •  Data processing based on the consideration of interests (Art. 6 Section 1 lit. f of the GDPR)
  • Data protection for compliance with a legal obligation (Art. 6 Section 1 lit. c of the GDPR)
  • Data processing in order to protect the vital interests of the data subject or of another natural person (Art. 6 Section 1 lit. d of the GDPR)
  • Data processing based on your consent (Art. 6 Section 1 lit. a of the GDPR)

If personal data is processed based on your consent, you have the right to withdraw your consent at any time, with effect for the future. You can send your withdrawal to the attention of our data protection officer mentioned further below.

We base our legitimate interest on communication with contract relevant contact persons, retention of records beyond possible retention times, to provide you a consistent documentation, on claims management. We also use your data for marketing and opinion research purposes, to find out the interests and inquiries in regard to future products and services. If necessary, we process your data also for assertion of our legal claims and in our defense in case of legal disputes. Furthermore, we make use of the option of direct marketing as per Recital 47 of the GDPR, we pursue a legitimate interest in informing our clients about our services via communication channels, if said clients have actively contacted us in this matter.

As the affected person, you have the right to object to the processing of your personal data for these purposes, taking into consideration the provisions of Art. 21 of the GDPR.

How long are the data stored?

We process the data for as long as necessary for the respective purpose.

If legal retention obligations apply – e.g. in commercial law or fiscal law – personal data are stored for the duration of the obligation. Once the retention period has elapsed, we will verify whether the necessity for processing persists. If it no longer applies, the data will be deleted.

To which recipients do we disclose data?

In principle, we disclose your personal data to third parties (referred to as recipients) only if it is required for the performance of the mutual contract with you, if disclosure is permitted based on a consideration of interests as per Art. 6 Section 1 lit. f of the GDPR, if we are obliged to disclose them, or if you have given your consent.

Such recipients are for example connected companies – including laboratories –, which provide support with fulfilling the contract, as well as external certification bodies (trade supervision or others, depending on the certification country) which receive data for registration in accordance with the legal provisions.

Within the scope of the requirements of the fiscal and commercial law, we may also disclose data to consultants such as tax consultants, banks or other tax authorities.

Third persons in our case do not include service providers and affiliated companies obliged to adhere to our requirements on data protection. For this purpose, we have concluded data processing contracts, and we ensure thereby that you can exercise your rights towards them as well. Such entities are e.g. IT service providers or software system companies for IT applications (e.g. external IT administrators, ERP system producers etc.) and qualified service providers in the area of document destruction.

Information on the provision of personal data

In order to process your inquiries, we are dependent on your information. When processing your inquiries, the processing of the personal data of the data subjects relates to a corresponding contractual relationship or to legal regulations. You do not necessarily have to provide us with data that is not required by a legal regulation and you can object to the processing. When collecting the data, we will draw your attention to which data is required.

Recruitment data

By submitting your application for a job at our company, your personal data, which may include your name, contact details, resume, cover letter, and other information relevant to your application will be processed for this purpose only. This processing is necessary in order to take steps at the request of the data subject prior to entering into a contract, as outlined in Article 6(1)(b) of the General Data Protection Regulation (GDPR). Your data will be stored securely for a period of 6 months for recruitment purposes. After this period, your data will be deleted unless you have given separate consent for further processing.

Where do we process data?

We process your personal data exclusively in data processing centers within the European Union (IONOS in Germany), thus the Data Protection Regulation applies at all times.

Manufacturers of the products may, however, be located outside the European Union. The data transfer is subject to Art. 49 Section 1 of the GDPR as an individual case.

Principles of data processing when using „Zoom“ for online meetings and phone conferences

In order to fulfill our information obligations per Art. 12, 13 of the General Data Protection Regulation (GDPR) towards our clients, participants of webinars and our employees, we would like to present our information on data protection:

Purpose of Data Processing

We use the “Zoom” online tool to hold phone conferences, online meetings, video conferences, and webinars (hereinafter referred to as “online meetings”).

Legal Basis for Data Processing

For the processing of data of MDSS GmbH employees, the legal basis for data processing is § 26 of the Federal Data Protection Act and Art. 6 Section 1 lit. f) of the GDPR. Our interest in these cases is the effective realization of “online meetings”.

With respect to our clients and participants of webinars, the legal basis for data processing when holding “online meetings” is Art. 6 Section 1 lit. b) of the GDPR, as they are held within the scope of the contractual relationship.

In case that no contract is in place, the legal basis is Art. 6 Section 1 lit. f). Here, too, our interest is the effective realization of “online meetings”.

Types of Data Being Processed:

User Information:

First name, last name, phone number (optional), email address, password (when “single sign-on” is not used), profile picture (optional), Department (optional)

Meeting Meta Data:

Subject, Description (optional), participant IP address, device/hardware information

For Recordings (optional):

MP4 file of all video, audio and presentation recordings, M4A file of all audio recordings, text file of all online meeting chats

For Telephone Dial-In:

Information on incoming and outgoing phone number, country, start and end time.  Further connection information, such as the IP address of the device, may be stored.

How long is data stored?

We process the data for as long as it is required for the respective purpose. Of course you can request information on stored personal data concerning you at any time (see below), and, if there is no necessity for further retention, request erasure of your data or restriction of processing.

To which recipients are data transferred?

If data from “online meetings” are not intended for transfer, we generally do not make them available to further recipients.

As a service provider, “Zoom” is necessarily informed of the above mentioned data, to the extent to which it is intended within the scope of our processing contract with “Zoom”.

Data Processing Outside the European Union

The servers of the service provider “Zoom” are located in the U.S., therefore, data is processed in the U.S. (a third country). For this reason we have concluded a processing contract (as described above), which reflects the requirements of Art. 28 of the GDPR.

An adequate level of data protection is guaranteed by conclusion of the so-called EU standard contractual clauses. Furthermore, “Zoom” also offers information on data protection https://zoom.us/docs/de-de/privacy-and-legal.html.

Cookies used on our Website

When you enter our website, we set a cookie that is necessary for the well functioning of our website. You can configurate which cookies should be allowed on our banner. The following cookies are being used in our website:

Cookie-ID

Retention Period

Function

sbjs_migrations

Session

Statistics/Marketing

sbjs_current

Session

Statistics/Marketing

sbjs_first

Session

Statistics/Marketing

sbjs_session

30 minutes

Statistics/Marketing

sbjs_current_add

Session

Statistics/Marketing

sbjs_first_add

Session

Statistics/Marketing

sbjs_udata

Session

Statistics/Marketing

pll_language

1 year

Essential

request_a_quote_user_coockie

Session

Functional

Google Fonts

This site uses so-called Google Fonts, which are provided by Google, for the uniform display of fonts. The Google Fonts are installed locally. A connection to Google’s servers does not take place.

For more information about Google Fonts, please visit https://developers.google.com/fonts/faq and read Google’s privacy policy.

Font Awesome

This site uses Font Awesome for the uniform display of fonts. Font Awesome is installed locally. A connection to servers of Fonticons, Inc. does not take place.
For more information about Font Awesome, please see the Font Awesome privacy policy at: https://fontawesome.com/privacy

Your rights as “data subject”

You have the right to obtain information on the personal data processed by us, as per Art. 15 GDPR. If a request for information is not submitted in writing, please understand that we may request documentation proving your identity.

Furthermore, you have the right of rectification, erasure or restriction of processing, whenever legally permitted according to Art. 16, 17 and 18 of the GDPR.

An automated individual decision-making as per Art. 22 of the GDPR does not apply.

Furthermore, you have the right of objection to processing within the scope of the legal provisions. The same applies to the right of data portability. In particular, you have the right of objection according to Art. 21 Section 1 and 2 of the GDPR against processing of your data in connection with Art. 6 Section 1 lit. f of the GDPR. You can file the objection informally to the attention of our data protection officer at the following addresses:

Our data protection officer:

We have designated an external data protection officer for our company. You can reach him/her at the following contact:
E-Mail: privacy@mdssar.com

Right of appeal

You have the right to complain about the processing of your personal data by our company to a supervisory authority in charge of data protection.

Amendments to this Data Protection Policy

This document will be updated regularly as necessary. The current version can be found on our website.