You can print this document by using the normal functionality of your Internet service program (= browser: there mostly “file” > “print”).
1. Responsible controller
2. General information on processing personal information
We process your personal data in compliance with the data protection laws of the Federal Republic of Germany and the European General Data Protection Regulation. In no case will we forward your personal data to third parties for advertising or marketing purposes without your consent.
As an international company, we work together with external service providers. To the extent that processed information contains personal content, corresponding contractual agreements and organizational measures have been enacted according to applicable law which ensure the security of your information. Our external service providers are bound by our instructions and are monitored regularly. Our employees are trained to handle personal data and have committed in writing to comply with data protection regulations.
As a general rule, our website can be used without providing personal data. Insofar as personal data (name, address or email addresses, for example) are collected, this is always on a voluntary basis whenever possible.
We draw your attention to the fact that data transmission via the Internet (e.g. when communicating by e-mail) may involve gaps in security. We attempt to protect your data from unauthorized access by third parties by means of precautions such as pseudonymization, data economy, observing deletion periods and in consideration of the current state of the art technology. Despite these protective measures, however, we cannot completely rule out unlawful processing by third parties.
3. Data processing in the case of access from the Internet
When you visit our website, our web servers save each access temporarily to a log file. The following information is captured and processed until automated deletion:
- Anonymized IP address of the computer requesting the information
- Date and time of access
- Time zone difference to Greenwich Mean Time (GMT)
- Access status/http status code
- Volume of data transferred in each case
- Operating system and its interface
- Identification data of the browser and operating system used
- Language and version of browser software
- Name and URL of the data retrieved, content of request
- Report of whether the retrieval was successful
- Website from which the access takes place
- Name of your Internet service provider
When this website is used purely for informational purposes, Aesculap Suhl GmbH collects only those personal data that are necessary in technical terms in order to display the website and enable the use thereof (establishment of a connection), for system security and stability, for the technical administration of the network structure and to optimize the website. The legal basis for this is a legitimate interest on the part of Aesculap Suhl GmbH (Article 6(1)(f) GDPR).
You may object to this data processing. Insofar as you object to the use of this data, we hereby inform you that our services may only be usable to limited degree.
This personal information is not processed beyond the cases indicated above, unless you explicitly consent to further processing. (For further information, please see this Data Privacy Statement under the following point, “Consent”).
4. Purpose of data processing
In accordance with the principle of data avoidance and data economy set out in the General Data Protection Regulation, we only process personal information on our website when it is either required for your desired purpose, we are obligated to do so due to legal regulations or contracts, if we have a legitimate interest and/or if you voluntarily provide the information to us.
When entering personal or business information (e.g. email address, name, address), the disclosure of your information is performed on an explicitly voluntary basis.
We process your contact and business-related information based on statutory regulations in connection with existing or pending business relationships. In addition, with your input, you declare your consent for the information entered to be processed for the purpose designated by you. We process your provided information only as long as required for the intended purpose and delete it after fulfilling the purpose or after expiration of the respective storage periods. Processing does not occur for any other purpose. Insofar as you object to the processing of this data, we hereby inform you that our services may only be usable to limited degree. To provide you with comprehensive offerings, your data are transferred and used within the B. Braun Group (for information on the B. Braun Group, click here.)
The following are possible ways we may use the information:
Due to statutory regulations:
- Execution of our General Terms and Conditions
- Management of our business
- Protection from or identification of possible fraudulent transactions
Based on contractual purposes:
- Payment processing for purchases and other services
- Processing your application documents
Based on our legitimate interest:
- Determining the effectiveness of our advertising
- Developing new products and services
- Analyzing the use of our products, services and websites
- Knowledge of how you reached our website
Your personal data are processed solely on the basis of statutory permission or your consent (Article 6(1)(a) GDPR). Your consent to processing can be revoked at any time with effect for the future. Your consent to the processing of your personal data may be required in various cases:
- Sending of samples, bonuses, products and information
- Signing up for prize competitions, programs or offers at your request
- Delivery of other services which we have offered to you
- Surveys on our websites
- Development and provision of advertising tailored to your interests
- Making contact via the contact form
6. Term of storage
Your data are stored by Aesculap Suhl GmbH only as long as they are required for certain purposes. Consequently, your data are erased by Aesculap Suhl GmbH if and when:
- the relevant legal basis for the processing of your data no longer exists,
- the purpose of processing of your data no longer exists,
- you withdraw your consent to the processing of your data,
- a legal obligation makes it necessary to erase them, or
- you have objected to the processing of your personal data,
unless storage periods stipulated by law apply. For example, the German Fiscal Code (AO) and Commercial Code (HGB) provide for certain storage periods. Aesculap Suhl GmbH cannot erase your data on a final basis until these periods have elapsed.
This does not apply to data whose erasure would involve disproportionate effort. In cases like these, Aesculap Suhl GmbH is deemed to have a legitimate interest within the meaning of Article 6(1)(f) GDPR in storing your data.
7. Automated decision-making
As a basic principle, we do not use any fully automated decision-making pursuant to Article 22 GDPR to establish and implement the business relationship. Should we utilize these methods in individual cases, we will notify you thereof separately where required by law.
We use automated methods to process your data in part, with the objective of evaluating certain personal aspects (profiling). We use profiling to provide products that may interest you on a targeted basis, for example.
8. Obligation to provide personal data
Within the scope of our business relationship, you are required to provide the personal data that are necessary in order to commence and implement the relevant business relationship and fulfill the contractual obligations associated with it or that we are required by law to collect. Without these data, we will typically not be able to enter into the business relationship with you and fulfill the obligations that arise from it.
The website of Aesculap Suhl GmbH may contain links to third-party websites over whose content Aesculap Suhl GmbH has no influence. After you click a link, you leave the sphere of responsibility of Aesculap Suhl GmbH. Processing of data thereafter no longer takes place within the sphere of influence of Aesculap Suhl GmbH.
10. Protection of minors
Children and people under the age of 18 normally do not transmit personal data to us without the consent of their parents or legal guardians. We do not request personal data from children and we affirm that we do not collect personal data from children, nor do we use it in any way or disclose it to third parties without authorization.
11. Transmission of data via the Internet
The Internet is a globally open platform. Due to the Internet's inherent mode of operation and the systemic risks involved, any data transmissions are made at your own risk. For your security we exclusively offer our services via the encrypted transmission channel.
Our websites also use so-called "cookies." Cookies are small text files that are stored on your computer and that your browser saves. They do not cause damage to your computer and do not contain viruses. They serve to make our offering more user-friendly, effective and secure. Some cookies (so-called "functional cookies," e.g. for language settings and order processes) are those that are required in order to guarantee the essential functions of the website. Without them, the website cannot be used as intended.
The majority of the cookies used by us are so-called “session cookies“. They will be deleted automatically after the end of your visit. Other cookies remain stored on your terminal device until you delete these. These cookies enable us to recognize your browser again on the next visit.
There are two different types of cookies:
- Transient cookies: Most of the cookies we use are “transient cookies,” especially “session cookies.” These cookies are automatically deleted after the end of your visit. They enable us to recognize your browser when you return to our website within the same session.
- Persistent cookies: Other cookies known as “persistent cookies” are automatically erased from your device only after a predetermined period (which varies according to the type of cookie).
13. Security Measures
We have taken extensive precautions to protect the security of your data. The data transmitted to us that you have entered e.g. in HTML websites (contact forms) are transmitted in an encrypted form (SSL – Secure Socket Layer) via the public data network to Aesculap Suhl GmbH, where they are saved and processed.
This website uses an SSL encryption for reasons of security and for the protection of the transmission of confidential contents, such as for example the inquiries that you send us as the website operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.
If the SSL encryption is activated the data, which you transmit to us, cannot be read by third parties.
14. Forwarding of data to third parties
Your personal data will not be forwarded to third parties, unless you have granted us your corresponding prior consent. Excluded from this provision is the forwarding to service partners, such as for example parcel service provider or freight forwarders, if the transmission is necessary for the order processing or delivery of the goods.
The logistics service providers receive the data that are required for the delivery for use at their own responsibility. We accordingly restrict this to sending the data that are necessary for the delivery.
In addition, other service providers are involved in the work for the initiation and processing of the contracts, such as for example IT service providers or the hosting service provider for the website. These companies operate for Aesculap Suhl GmbH within the framework of a so-called order processing and may only use the personal data according to our instructions.
Aesculap Suhl GmbH has obligated these service providers to the General Data Protection Regulation as per contract and monitors these companies.
Further excluded is the transmission of data for the order processing or delivery of the goods or services or the transmission and use for bookkeeping and settlement purposes within the B. Braun Group. For the forwarding of the data these can be saved (cf. Point 10) in the cloud application salesforce.com, Inc. The Landmark @ One Market Street, Suite 300, San Francisco, CA 94105, USA (“Salesforce”). In addition, no transmission will take place to third parties without your consent.
In all of these cases the transmission will be carried out in line with the applicable national and European data protection provisions; the scope of the transmitted data is only limited to the necessary minimum in this case.
We have concluded a contract with Adobe for the contract data processing and implement the strict stipulations of the German data protection authorities in full when using Adobe Analytics.
16. Social media
Aesculap Suhl GmbH maintains its own sites on various social networks in order to enable dialogue with interested users or clients and be able to inform these groups about the Aesculap Suhl GmbH product portfolio. Aesculap Suhl GmbH does not process any user data in social networks itself, and can only analyze and use the data that have been anonymized by Facebook, for example. In the process, user data may be transferred to countries outside the European Union. It should, however, be pointed out that U.S. companies that have Privacy Shield certification ensure European levels of data protection. In addition, the user data collected are processed for marketing purposes, for example to define target groups and then display advertising materials to these groups on a targeted basis on the relevant social media platform. To make this possible, the social network/the relevant provider of the social network frequently stores cookies that contain the users’ online behavior, interests and similar. Use profiles on the relevant platforms can also contain data that are stored irrespective of the device. The legal basis for this kind of data processing is the legitimate interest of Aesculap Suhl GmbH in functional, stable communication with users via the respective online presence.
The social media providers may request your consent to the relevant data processing. In this case, the legal basis for the data processing would be that specific consent.
As the data subject affected by the data processing, you can assert various rights with respect to the controller. Please note, however, that as a basic principle, exercising these rights as a data subject makes the most sense if you do so directly with the platform provider. As a general rule, only the platform providers have direct access to the data that are processed, and they are the only ones that can take appropriate measures. Naturally, we are happy to hear from you if you have any further questions about this.
To provide you with as much relevant information as possible regarding the processing of data on social networks, we would also like to refer you to the data protection and privacy statements of the individual platform providers:
17. Your rights as an data subject
We provide an online shop on our website. To handle your order, we need your personal data to implement the contract:
You have the right to the following at any time:
- free information on the personal data concerning you that are stored, the origin and recipients thereof and the purpose of data processing, and
- restriction of processing of data,
- erasure of these data,
- receipt of your information in a structured, commonly used and machine-readable format (right to data portability),
- withdrawal of your consent to the processing of your personal data,
- filing of a complaint with the supervisory authority with jurisdiction
Objection to the processing of your data based on legitimate interests
You also have the right to object to the processing of your personal data at any time if this is done by Aesculap Suhl GmbH based on a legitimate interest (pursuant to Art. 6(1)(f) GDPR). As a result, the processing of your data will be halted unless Aesculap Suhl GmbH can show that there are statutory provisions concerning this or that it has grounds to continue processing the data based on legitimate interests. This is the case, for example, if data are still required in order to be able to assert legal claims where applicable.
Objection to processing for direct marketing purposes
You can object to the processing of your personal data for purposes of advertising and data analysis at any time (“advertising objection”).
On this point and for further questions concerning personal data, you can contact us here or using the contact information under point 18, “Your contacts for data privacy matters.” Upon request, we will inform you in writing if and which personal information we process about you, in accordance with applicable law.
18. Your contacts for data privacy matters
If you have questions regarding the processing of your personal information, you can contact our data privacy officer and his/her team directly. They are also available for information requests, inquiries or complaints:
Aesculap Suhl GmbH
If you wish to exercise your right to lodge a complaint with the supervisory authority with jurisdiction, please contact the following address:
Data Protection Commissioner for the State of Thüringen
19. Accessibility of the data privacy policies
Status April 2019