Data protection information for the MEDION Life Plus App (last updated: February 9, 2024)

Thank you for using the MEDION Life Plus App. MEDION AG, with its registered office at Am Zehnthof 77, 45307 Essen, Germany (hereinafter "MEDION" or "we"), is the responsible party for the collection, processing and use of your personal data in connection with the MEDION Life Plus App (hereinafter "App").

MEDION collects, processes and uses personal data that is either entered by YOU or otherwise created or processed in the course of using the App, the associated end devices (such as vacuum robots, video doorbells, smart lighting, etc.) or services offered by MEDION in accordance with the applicable data protection laws and informs you below about the data processing carried out by us on the basis of the existing usage agreement with you or any other legal basis.

We take the protection of your personal data very seriously and want you to feel secure when using our apps. The protection of your privacy when processing personal data is a central and important concern for MEDION, which we also take into account in all our business processes.

We take care of the protection of your data collected, processed and used by us when you visit the MEDION Apps. And we are happy to be your contact for all questions on the subject of MEDION data protection and also take your suggestions on board and see to it that they are dealt with in a very timely manner. The declaration may be updated from time to time. We therefore ask you to read it regularly. The last line of this statement below indicates when it was last updated.

1. Principles

Your personal data will only be collected, processed and used in accordance with the law and in good faith. As far as possible, we design our business processes in such a way that data protection requirements are already taken into account during the development of products and service offerings and that personal data is anonymised in such a way that the data subject cannot be identified or can no longer be identified if this does not jeopardise the agreed purpose. MEDION uses your personal data for the technical administration and further development of this app, for customer, user administration and marketing purposes, to inform you about our services and products and for other precisely defined purposes.

2. Sources and data used

In the course of our business relationships, we process personal data that we have received directly from you. In addition, we process personal data that we permissibly obtain from publicly accessible sources or that is legitimately transmitted to us by other third parties, insofar as this data is necessary for the provision of the corresponding services and within the scope of the agreed purpose.

We store your data which is necessary for the processing of your order, the use of our products or the provision of services, e.g. repairs, and - if selected by you - for the processing of payments. This is personal data such as your address details, date of birth (for transactions with age verification) and data required for certain types of payment. The respective order data (article, quantity, price, etc.) is assigned to your address data. In most cases, MEDION is already legally obliged to collect this data (for example, in the case of age verification in accordance with the German Youth Protection Act or the German Tax Code).

3. Categories of personal data 

In connection with the use of the App, the associated end devices or services and functions offered by MEDION (hereinafter "Services"), MEDION collects, processes and uses the following categories of personal data.

a. User, master and usage data

Data that we collect and use in connection with the creation of a user account (registration) and the setup of the App are:


b. Device master data 

Data that we collect and use in connection with the connection of your terminal device with the user account are:

This data is assigned to your user account as part of the "Add device" function for each connected end device.

To ensure the compatibility of your LIFE PLUS products with your smartphone, our application (MEDION LIFE PLUS) accesses the following functions of your phone in the process:


App-persmissions:

In order to provide you with the functionalities of the app, the app must be able to access various functions and data of your mobile device. To do this, it is technically imperative that you grant the app selected access permissions. Otherwise, the app cannot be used for technical reasons. Before using the app for the first time, we will explicitly inform you of the requested access authorisations. In most cases, these are the following permissions:

Location: This authorisation is required to determine your current location for location-based services. This permission allows your smartphone to access your GPS data, Wi-Fi identifiers and/or Bluetooth, depending on which you have enabled, to determine your location.

Contacts: This authorisation supports the selection of contacts to be informed for the user and provides the option to search for and select the corresponding persons in the contact data. For this to be possible, the app needs the 'Contacts' permission to access the contact data.

Wifi connection information: This permission requires access to the WLAN status in order to be able to automatically inform the user if there is a connection to the Internet and to be able to inform him/her to switch to 'offline' control if the Internet connection is not established or cannot be established, it is necessary to query the status of the network and to be able to search for WLAN connections/home networks.

Push-notifications: Push notifications are messages that are sent from the app to your device and are prioritised there. This app uses push notifications by default if the user has consented to them during app installation or first use. The receipt of push notifications can be deactivated at any time in the settings of the device.

User behaviour: Within the framework of legal regulations, we, or companies commissioned by us, create user profiles under a pseudonym. These can be evaluated for advertising and market research or for the needs-based design of the app. It is not possible to draw any direct conclusions about the user. A linking of the profile data with further information about the user does not take place.

Log data: This authorisation enables the automatic storage of log data, such as the information that your browser sends when you visit a website or that your mobile app sends when you use it. This log data may include your IP address, the address of the websites visited, browser type and settings, the date and time of your request and cookies. Cookies are small text files that become from the mobile device every time you visit a MEDION website. MEDION uses cookies to track the preferences of users and to be able to optimally design the website accordingly. Cookies help MEDION to identify particularly popular areas of our website. This enables us to better tailor the content of our Internet pages to the needs of users and to improve our Internet offering. Cookies can be used to determine whether your computer has already connected to our Internet pages. The cookies can identify your computer but cannot establish a link to your person.

Device information: In addition to log data, MEDION may also collect information about the device on which the app is used. This includes device type, operating system used, device settings, unique device identifiers and crash data. Whether some or all of this information is collected depends on the type of device used and its settings. This allows error messages and system crashes to be analysed in order to improve future operation. Personal data is not required or collected for this purpose.

Social Media: If you connect to this APP via third-party social media sites (such as Facebook or Twitter or Instagram or Google+), you agree to the permissions stored there under your personal account. MEDION will not have access to your personal data stored there.

c. Device usage data

The functional status of the device is recorded and a log of the device operation is written in order to localise problems and to be able to remedy them in a more targeted manner. The maps created by robotic vacuum cleaners are encrypted and stored locally on the device and in the app in the smartphone device memory.

d. App-usage data

App usage data is data from your interaction with the app, such as app functionalities used, click behaviour in relation to app controls, on/off switch settings, and app fault reports. See also section 9.

4. Purposes of use

MEDION uses the aforementioned categories of data:


The processing of personal data is carried out in the context of trading with products and services in the field of consumer electronics. The purposes of the data processing primarily depend on the specific product (e.g. physical or digital) and its application possibilities or also on the order placed with us (e.g. repair). Further details on the data processing purposes can be found in the contract documents, the operating instructions and the terms and conditions or the conditions of use.

5. Customer account

In order to provide you with the greatest possible convenience when shopping, we offer you the permanent storage of your personal data in a password-protected MEDION customer account for online offers and selected apps from MEDION. Once you have set up this customer account, you do not need to enter your personal data again for the ordering process or app use. If you already have an account for an online offer at MEDION, the master data stored there will be transferred to your MEDION customer account. From then on, your MEDION customer account can be used to place orders in MEDION's online offers and to use selected MEDION apps without having to register separately or provide detailed user data again. In addition, you can view and change certain data stored about you in your customer account in the web shop at any time and, for example, permanently save items for a later purchase.

In addition to the data requested when placing an order, you must enter a password of your choice to set up a customer account. This is used together with your e-mail address to access your MEDION customer account. The legal basis for this is Article 6 (1) b) DS-GVO, i.e. you provide us with the data on the basis of the contractual relationship between you and us. Your data will be passed on to the operator of the respective offer for the purpose of processing purchase contracts or other services that have been commissioned via the offers included by MEDION. The latter receives the data required for the provision of the service ordered in each case, i.e. verification of the log-in data (e-mail address, password, telephone number if applicable). We generally exclude any further disclosure of this data to third parties.

If you request the deletion of the MEDION customer account, your data will be deleted accordingly. The processing and storage of data is also the responsibility of the respective operator of the service used, who uses the data required to provide the service ordered for this purpose and then archives it in accordance with the statutory retention periods.

6. Customer service

Personal data that you provide to us when filling out contact forms, by telephone, by e-mail or via social media will of course be treated confidentially. We use your data exclusively for the purpose of processing your enquiry. The legal basis for data processing is Article 6(1) f) or Article 6(1) b) DS-GVO. Our and your concurrent (legitimate) interest in this data processing results from the aim of answering your enquiries, solving any problems that may exist and thus maintaining and promoting your satisfaction as a customer or user of our website.

If you participate in one of our customer surveys, this is done on a purely voluntary basis. In these anonymous surveys, no information is stored that allows conclusions to be drawn about the participants in the surveys. Only the date and time of your participation are stored. Any personal information you provide while responding to our survey will be considered voluntarily given and will be stored in accordance with the DS-GVO. Please refrain from mentioning names or similar in the free text fields that would allow conclusions to be drawn about you or other persons.

In the event that a declaration of consent is submitted as part of a customer survey, Article 6 (1) a) DS-GVO is the legal basis for the data processing based on the consent. If you have given your consent in the context of a customer survey, you have the option of revoking this consent at any time with effect for the future. In these cases, more details are regulated in the special data protection principles of the respective customer survey.

Exceptionally, data is processed on our behalf by order processors from the customer service sector. These are carefully selected in each case, are also audited by us and are contractually obligated in accordance with Article 28 DS-GVO. To the extent necessary to process your request, the data you provide may be passed on to MEDION companies.

Furthermore, it may be necessary for us to pass on extracts of your enquiry to contractual partners (e.g. suppliers in the case of product-specific enquiries) in order to process your enquiry. In these cases, the enquiry is anonymised beforehand so that the third party cannot establish any reference to you. If it is necessary to pass on your personal data in individual cases, we will inform you of this beforehand and obtain your consent.

The results of our customer surveys are only used for internal evaluations. We will not pass on personal data to third parties unless you have given your express consent to do so.

7. Transfer or forwarding of your data to third parties

MEDION works with various service providers to provide the app and the services offered via it. Insofar as MEDION has obligated these service providers to process data strictly in accordance with instructions, data processing by these service providers does not require your consent. Service providers we use as processors:

Service providers for hosting services
Service providers for programming services
We will only transfer your data to other recipients if this is necessary to fulfil a contract with you or between you and the third party provider, if we or the recipient has a legitimate interest in the transfer of your data or if you have given your consent to the transfer. These recipients include the service providers mentioned above. In addition, data may be transferred to other recipients where we are required to do so by law or by enforceable governmental or court order.

The other recipients of your data include, in particular, service providers whose offers and services (third-party services) MEDION mediates within the scope of the app or enables access to such services.

Data is transferred to bodies in countries outside the European Union (so-called third countries) insofar as it is necessary for the execution of your orders, it is required by law or you have given us your consent. MEDION does not transfer any personal data to third countries or international organisations. However, MEDION uses service providers for certain orders (see above), which also use service providers that may have their registered office, parent company or data centres in a third country. According to Art. 45 DS-GVO, the transfer is permitted if the European Commission has decided that an adequate level of protection exists in a third country. If such a decision has not been made, MEDION or the service provider may only transfer personal data to a third country or to an international organisation if appropriate safeguards are provided (e.g. standard data protection clauses adopted by the Commission or the supervisory authority in a specific procedure) and enforceable rights and effective remedies are available. MEDION has agreed contracts with these service providers on so-called commissioned processing, which regulate that bases for data protection are always concluded with their contractual partners in compliance with the European level of data protection.

8. Standard storage periods

MEDION processes and stores your personal data as long as this is necessary for the fulfilment of our contractual and legal obligations. If the data is no longer required for the fulfilment of contractual or legal obligations, it is regularly deleted, unless its further processing for a limited period is necessary for the following purposes: preservation of evidence within the framework of the statutory limitation provisions.

According to §§ 195 ff. of the German Civil Code (BGB), these limitation periods can be up to 30 years, with the regular limitation period being 3 years. Furthermore, this includes the fulfilment of retention obligations under commercial and tax law according to the German Commercial Code (HGB) or the German Fiscal Code (AO).

The retention and documentation periods specified in the aforementioned laws range from 2 to 10 years.

Subject to deviating legal requirements, the following standard storage periods apply:

  1. Single sign-in: If a deletion of the central login is intended, an email must be sent to datenschutz@medion.com. According to BDSG §39, MEDION is obliged to keep data for up to ten years. For this reason, only a reservation for deletion is possible.
  2. User master data: see 1.
  3. Device master data: Cancellation of the assignment to the user account with removal of the home appliance from the user account.
  4. Device usage data: storage in personal form for a period of one year. Afterwards, the data is deleted.
  5. App usage data: Storage in pseudonymous form and provision in personalised form for services/messages provided via the app, insofar as the function "Allow tracking of usage data" is activated for seven days. A randomly selected part is stored in pseudonymous form for up to one year.

 

9. Recording of app usage

The app offers the possibility to collect app usage data (see 1.4. above).

Insofar as the function "Allow tracking of usage data" is activated, app usage data is sent to and stored on servers of the named providers located in the EU. The app usage data enables an analysis of your use of the app and the provision of notifications for services provided via the app (see 3 d. above). IP anonymisation has been activated for this app, so that the IP address you use is shortened beforehand. On behalf of MEDION, the service provider for programming services will use this information on our behalf to evaluate your use of the app, generate error reports and compile reports on app activities for MEDION. The IP address and other personal data transmitted by your mobile device as part of the aforementioned services will not be merged with any other data held by MEDION without your separate consent without any other service provider mentioned in clause 7.

You can control the collection of app usage data (including your IP address) by the aforementioned services as well as the processing of this data by the aforementioned services by activating or deactivating the function "Allow tracking of usage data". The following data is collected:


As a matter of principle, we do not use fully automated decision-making pursuant to Art. 22 DS-GVO to establish and implement the business relationship. Should we use these procedures in individual cases, we will inform you about this separately if this is required by law. We sometimes process your data automatically with the aim of evaluating certain personal aspects (profiling).

We use profiling, for example, to provide you with targeted information about products and services or we use evaluation tools. These enable needs-based communication and advertising, including market and opinion research.

 

10. Data security

In order to protect your data from manipulation, loss and unauthorised access by third parties, we use technical and organisational measures. These measures include the use of encryption technology, certificates, the use of a firewall on the MEDION Device Cloud and password protection of the MEDION App. We continuously review and improve our security measures in line with technological progress.

11. Scope of the information on data protection

This information on data protection applies to the services offered by MEDION via the App. Insofar as additional functions, benefits or services are offered by MEDION within the app, special information on data protection will be provided for these, insofar as their use is subject to special data protection regulations.

However, this information on data protection does not apply to third-party services, even if MEDION App arranges the use of or access to these third-party services within the scope of the App (for third-party services, see also the Terms of Use). In this case, the respective data protection provisions of the service provider apply to the use of these third-party services.

In the event of onward transmission to another service provider, MEDION shall make reasonable and appropriate efforts to identify the fact of onward transmission (e.g. when embedding the content of the service provider within the app through inline frames), insofar as the onward transmission is not obvious. Obviousness is given, for example, if the MEDION App is exited via a link and the app or website is opened.

If you are a user within the scope of the GDPR, please note that the use of third-party services may result in your personal data being processed in countries outside the scope of the GDPR. In this regard, please refer to the data protection information of the respective third-party service provider.

12. Changes to the information on data protection

In the course of the further development of the app - among other things due to the implementation of new technologies or the introduction of new services - it may become necessary to adapt this information on data protection. MEDION reserves the right to amend or supplement this information as required. MEDION will always store the current version of the information on data protection in the app so that you can inform yourself about the current version of the information at any time.

13. Rights and contact information 

If, despite our efforts to ensure that the data is correct and up to date, incorrect information about you has been stored, MEDION will correct this at your request. If you have given MEDION your consent to the collection, processing and use of your personal data, you may revoke this consent at any time with effect for the future. You can exercise the revocation by using the contact options mentioned in the app. Your personal data will be deleted if you revoke your consent to the storage, if knowledge of the personal data is no longer required to fulfil the purpose pursued with the storage or if the storage is inadmissible for other legal reasons. Please take into account that for technical or organisational reasons there may be an overlap between your revocation and the use of your data, e.g. in the context of a newsletter that has already been sent. Data that is required for billing and accounting purposes or is subject to the legal obligation to retain data is not affected by this.

If you have any questions about data protection or wish to exercise your rights under data protection law to revoke consent, obtain information, correct, delete or block data, please contact us at datenschutz@medion.com.

14. Supplementary information in accordance with the GDPR

a) Legal basis for data processing 

We base the following data processing on:

b) Your rights

In addition to section 13, you have the following rights. To exercise your rights, please use the contact details provided at the end of this information on data protection.

Informationen über Ihr Widerspruchsrecht nach Art. 21 Datenschutz-Grundverordnung (DS-GVO) Information about your right to object in accordance with Art. 21 of the General Data Protection Regulation (GDPR)

You may withdraw your consent to the processing of personal data at any time by contacting MEDION. This also applies to the revocation of declarations of consent given to us before the applicability of the General Data Protection Regulation (GDPR), i.e. before 25.05.2018. Please note that the revocation is only effective for the future. Processing that took place before the revocation is not affected.

Individual right of objection

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Article 6(1)(e) DS-GVO (data processing in the public interest); this also applies to profiling based on this provision within the meaning of Article 4(4) DS-GVO. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.

Insofar as we base the processing of your personal data on the balance of interests, you may object to the processing. This is the case if the processing is not necessary, in particular, for the performance of a contract with you, which is shown by us in each case in the following description of the functions. When exercising such an objection, we ask you to explain the reasons why we should not process your personal data as we have done.

In the event of your justified objection, we will examine the merits of the case and either discontinue or adapt the data processing or show you our compelling legitimate grounds on the basis of which we must continue the processing.

Right to object to processing of data for direct marketing purposes In individual cases, we process your personal data to carry out direct marketing. You have the right to object at any time to the processing of personal data concerning you for the purposes of such advertising; this also applies to profiling insofar as it is related to such direct advertising. If you object to processing for direct marketing purposes, we will no longer process your personal data for these purposes.

The objection can be made form-free and should preferably be addressed to: MEDION AG, Data Protection, Am Zehnthof 77, 45307 Essen, Germany.

15. Responsible office

The responsible body is MEDION AG Am Zehnthof 77, 45307 Essen, Germany.

You can also reach the company data protection department and the company data protection officer via the e-mail address

datenschutz@medion.com

MEDION AG Management Board: Gerd Brachmann (Chairman),
Christian Eigen (Deputy Chairman)
Chairman of the Supervisory Board of MEDION AG: Dr. Rudolf Stützle
Registered Office of the Company: Essen AG Essen HRB 132 74