Data Protection Information for the MEDION Robots, Air and Pet App (as of 27 October 2022)

Thank you for using the MEDION Robots, Air and Pet App. MEDION AG, with its registered office at Am Zehnthof 77, 45307 Essen, Germany (hereinafter "MEDION" or "we"), is the responsible party for the collection, processing and use of your personal data in connection with the MEDION Robots, Air and Pet App (hereinafter "App").

MEDION collects, processes and uses personal data that is either entered by YOU or otherwise created or processed in the course of using the App, the associated end devices or services offered by MEDION in accordance with the applicable data protection laws and informs you below about the data processing carried out by us on the basis of the existing user agreement with you or any other legal basis.

We take the protection of your personal data very seriously and want you to feel secure when using our apps. Protecting your privacy when processing personal data is a central and important concern for MEDION, which we also take into account in all our business processes.

We take care of the protection of your data collected, processed and used by us when you visit the MEDION apps. And we are happy to be your contact for all questions on the subject of MEDION data protection and also take your suggestions on board and see to it that they are dealt with in a very timely manner. The declaration is regularly revised to meet the requirements of legal changes and/or to reflect feature enhancements in the app. We therefore ask you to read it regularly.

1. Principles

Your personal data will be collected, processed and used exclusively in accordance with the statutory provisions and in good faith. As far as possible, we design our business processes in such a way that data protection requirements are already taken into account during the development of products and service offerings and that personal data is anonymised in such a way that the data subject cannot be identified or can no longer be identified if this does not jeopardise the agreed purpose. MEDION uses your personal data for the technical administration of this app, for customer and user administration and marketing in order to inform you about our services and products (specific consumables and spare parts) (see also clause 4.).

2. Sources and data used

Within the scope of our business relationships, we process personal data that we have received directly from you. In addition, we process personal data that we obtain permissibly from publicly accessible sources or that is legitimately transmitted to us by other third parties, insofar as this data is required for the provision of the corresponding services and within the scope of the agreed purpose.

We store your data, the use of our products or the provision of services (maintenance, care and provision of the app as part of the product to enable the full range of functions).

3. Categories of personal data

In connection with the use of the app, the associated end devices or services and functions offered by MEDION (hereinafter "Services"), MEDION collects, processes and uses the following categories of personal data.

User master and usage data

Data that we collect and use in connection with creating a user account (registration) and setting up the app are:

 

Device master data

Data that we collect and use in connection with the connection of your end device (smartphone and/or tablet) with the user account are:

This data is assigned to your user account within the framework of the "Add device" function for each connected end device.

Device usage data

MEDION collects and uses telemetry data in connection with the use of the end device, which can be categorised as follows

 

  1. Basic information
    1. Non-unique unit serial number
    2. Unique unit serial number
    3. Product name
    4. Product name assigned by customer
    5. Firmware versions

 

  1. Information on device activation
    1. Time of activation
    2. Last activity
    3. Time of the last update
    4. Online status

 

  1. Device status information

 

App usage data

MEDION collects and uses the following data in connection with the use of the app:

 

4. Purposes of use

MEDION uses the aforementioned categories of data (listed in section 3):

Your personal data is processed in accordance with the provisions of the European Data Protection Regulation (DS-GVO) and the Federal Data Protection Act and also the state-specific regulations in North Rhine-Westphalia.

Personal data is processed in the context of trade in products and services in the field of consumer electronics. The purposes of the data processing primarily depend on the specific product (e.g. physical or digital) and its application possibilities or also on the order placed with us (e.g. repair). Further details on the data processing purposes can be found in the contract documents, the operating instructions and the terms and conditions or the conditions of use.

 

5. Customer account

A MEDION customer account is required to use the app. You can create this conveniently via the app. If you already have a MEDION customer account - which you can create via the MEDION webshop, for example - you can use it to log in to the app. In order to provide you with the greatest possible convenience when shopping, we offer you the permanent storage of your personal data in a password-protected MEDION customer account for online offers and selected apps from MEDION. After setting up this customer account, you do not need to enter your personal data again for 30 days in order to use the app.  If you already have an account for an online offer at MEDION, the master data stored there will be transferred to your MEDION customer account. From now on, your MEDION customer account can be used to place orders in MEDION's online offers and to use selected MEDION apps without having to register separately or enter detailed user data again. In addition, you can view and change certain data stored about you in your customer account in the web shop at any time and, for example, permanently save items for a later purchase.

In addition to the data requested when placing an order, you must enter a password of your choice to set up a customer account. This is used together with your e-mail address to access your MEDION customer account. The legal basis for this is Article 6 (1) b) DS-GVO, i.e. you provide us with the data on the basis of the contractual relationship between you and us. Your data will be passed on to the operator of the respective offer for the purpose of processing purchase contracts or other services ordered via the offers included by MEDION (see clause 6 for details). The operator receives the data required for the provision of the service ordered, i.e. verification of the log-in data (e-mail address, password, etc.). We generally exclude any further disclosure of this data to third parties.

If you request the deletion of the MEDION customer account - this option is available in the profile settings of the app - your data will be deleted accordingly. The processing and storage of data is also the responsibility of the respective operator of the service used, who uses the data required to provide the service ordered for this purpose and then archives it in accordance with the statutory retention periods.

6. Customer service

Personal data that you provide to us when filling out contact forms, by telephone, by e-mail or via social media is, of course, treated confidentially. We use your data exclusively for the purpose of processing your enquiry. The legal basis for data processing is Article 6(1) f) or Article 6(1) b) DS-GVO. Our and your concurrent (legitimate) interest in this data processing results from the goal of answering your enquiries, solving any problems that may exist and thus maintaining and promoting your satisfaction as a customer or user of our website.

If you participate in one of our customer surveys, this is done on a purely voluntary basis. In these anonymous surveys, no information is stored that allows conclusions to be drawn about the participants of the surveys. Only the date and time of your participation are stored. Any personal information you provide while responding to our survey will be considered voluntarily given and will be stored in accordance with the DS-GVO. Please refrain from mentioning names or similar in the free text fields that would allow conclusions to be drawn about you or other persons.

In the event that a declaration of consent is given as part of a customer survey, Article 6 (1) a) DS-GVO is the legal basis for the data processing based on the consent. If you have given your consent in the context of a customer survey, you have the option of revoking this consent at any time with effect for the future. In these cases, more details are regulated in the specific data protection principles of the respective customer survey.

Exceptionally, data is processed on our behalf by order processors from the area of customer service. These are carefully selected in each case and are also audited by us and contractually obligated in accordance with Article 28 DS-GVO. To the extent necessary to process your request, the data you provide may be passed on to MEDION companies.

Furthermore, it may be necessary for us to pass on extracts of your enquiry to contractual partners (e.g. suppliers in the case of product-specific enquiries) in order to process your enquiry. In these cases, the enquiry is anonymised beforehand so that the third party cannot establish any reference to you. If it is necessary to pass on your personal data in individual cases, we will inform you of this in advance and obtain your consent.

The results of our customer surveys are only used for internal evaluations. We do not pass on personal data to third parties unless you have expressly consented to this.

7. Transmission or disclosure of your data to third parties

MEDION works with various service providers to provide the app and the services offered via it. Insofar as MEDION has obliged these service providers to process data strictly in accordance with instructions, data processing by these service providers does not require your consent. Service providers that we use as processors:

- Service provider for hosting services- Service provider for programming services

We only transfer your data to other recipients if this is necessary to fulfil a contract with you or between you and the third-party provider, we or the recipient have a legitimate interest in the transfer of your data or your consent to the transfer has been given. These recipients include the service providers mentioned above. In addition, data may be transferred to other recipients where we are required to do so by law or by enforceable governmental or court order.

Other recipients of your data include, in particular, service providers whose offers and services (third-party services) MEDION mediates within the scope of the app or enables access to such services.

Data is only transferred to countries outside the European Union (so-called third countries) if this is necessary to execute your orders, if it is required by law or if you have given us your consent. MEDION does not transmit any personal data to third countries or international organisations. However, MEDION uses service providers for certain orders (see above), who in turn use service providers that may have their registered office, parent company or data centres in a third country. According to Art. 45 DS-GVO, the transfer is permitted if the European Commission has decided that an adequate level of protection exists in a third country. If such a decision has not been made, MEDION or the service provider may only transfer personal data to a third country or to an international organisation if appropriate safeguards are provided (e.g. standard data protection clauses adopted by the Commission or the supervisory authority in a specific procedure) and enforceable rights and effective remedies are available. MEDION has agreed contracts with these service providers on so-called commissioned processing, which regulate that bases for data protection are always concluded with their contractual partners in compliance with the European level of data protection.

8. Retention periods

MEDION processes and stores your personal data for as long as is necessary for the fulfilment of our contractual and legal obligations. If the data is no longer required for the fulfilment of contractual or legal obligations, it is regularly deleted, unless its temporary further processing is necessary for the following purposes: preservation of evidence within the framework of the statutory limitation provisions.

According to §§ 195 ff. of the German Civil Code (BGB), these limitation periods can be up to 30 years, with the regular limitation period being 3 years. Furthermore, this includes the fulfilment of retention obligations under commercial and tax law according to the German Commercial Code (HGB) or the German Fiscal Code (AO).

The periods for retention or documentation specified in the laws listed above range from 2 to 10 years.

Subject to deviating statutory provisions, the following standard storage periods shall apply:

  1. Single sign-in: If deletion of the central login is intended, an e-mail must be sent to datenschutz@medion.com . Alternatively, the account can be deleted from the app via an onward link. Link: https://privacyportal.onetrust.com/webform/3c884b5f-db83-4077-91c8-fbfdaaba21fe/faddd8cd-62c3-4867-82ab-740bc4d7743eNach BDSG §39 MEDION is obliged to a data retention period of up to ten years. For this reason, it is only possible to make a note for deletion.
  2. User master data: see a
  3. Appliance master data: Unassignment to the user account with removal of the home appliance from the user account.
  4. Device usage data: Storage in personal form for a period of one year. After that, the data is deleted.

9. Data security

We use technical and organisational measures to protect your data from manipulation, loss and unauthorised access by third parties, for example. These measures include the use of encryption technology, certificates, the use of a firewall on the MEDION Device Cloud and password protection of the MEDION app. We continuously review and improve our security measures in line with technological progress.

10 Scope of the information on data protection

This information on data protection applies exclusively to the services offered by MEDION via the App. Insofar as additional functions, benefits or services are offered by MEDION within the app, special information on data protection will be provided for these, insofar as their use is subject to special data protection regulations.

However, this information on data protection does not apply to third-party services (in the context of the app, this concerns Amazon Alexa and Google Assistant - please refer to the data protection declarations of the respective providers), even if MEDION App arranges the use of or access to these third-party services in the context of the app (for third-party services, please also refer to the terms of use). In this case, the respective data protection provisions of the service provider apply to the use of these third-party services.

In the event of onward transfer to another service provider, MEDION shall make reasonable and appropriate efforts to identify the fact of onward transfer (e.g. when embedding the content of the service provider within the app through inline frames), insofar as the onward transfer is not obvious. Obviousness is given, for example, if a link is used to leave the MEDION App and a separate app or website is opened.

If you are a user within the scope of the GDPR, please note that the use of third-party services may result in your personal data being processed in countries outside the scope of the GDPR. Please refer to the data protection information of the respective third-party service provider.

11. Amendment of the information on data protection

In the course of further development of the app - including due to the implementation of new technologies or the introduction of new services - it may become necessary to adapt this information on data protection. MEDION reserves the right to change or supplement this information as necessary. MEDION will always store the current version of the information on data protection in the app so that you can inform yourself about the current version of the information at any time. You will be informed on the app side when new data protection provisions are published. If you do not agree to the updated version of the privacy policy, you will be automatically logged out and will only be able to use the app again after you have given your consent (query after a new login).

12. Rights and contact information

If, despite our efforts to ensure that the data is correct and up to date, incorrect information about you is stored, MEDION will correct this at your request. If you have given MEDION your consent to the collection, processing and use of your personal data, you may revoke this consent at any time with effect for the future. You can exercise the revocation by using the contact options mentioned in the app. Your personal data will be deleted if you revoke your consent to the storage, if knowledge of the personal data is no longer required to fulfil the purpose pursued with the storage or if the storage is inadmissible for other legal reasons. Please take into account that for technical or organisational reasons there may be an overlap between your revocation and the use of your data, e.g. in the context of a newsletter that has already been sent. Data that is required for billing and accounting purposes or is subject to the legal obligation to retain data is not affected by this.

If you have any questions about data protection or wish to exercise your rights under data protection law to withdraw consent, obtain information, correct, delete or block data, please contact us at datenschutz@medion.com.

13 Supplementary information under the GDPR

a) Legal basis for data processing

The following data processing is based on:

 

b) Your rights

 

c) Disclosure of personal data to recipients outside the EEA

If necessary for the provision of the functionalities of the app as well as the services offered via the app, MEDION also discloses personal data to recipients that are based outside the EEA in so-called third countries. In this case, MEDION ensures prior to the transfer that either an adequate level of data protection exists at the recipient (e.g. based on an adequacy decision of the EU Commission for the respective country or the agreement of so-called EU standard contractual clauses of the European Union with the recipient) or your consent to the transfer has been obtained.

You can obtain from MEDION an overview of the recipients in third countries and a copy of the specifically agreed arrangements for ensuring the appropriate level of data protection. To do this, use the contact details provided at the end of this information on data protection. Please also refer to section 7 for the transfer of personal data when using third-party services.

 

14. Information about your right to object in accordance with Art. 21 of the General Data Protection Regulation (GDPR)

You can revoke your consent to the processing of personal data at any time by contacting MEDION. This also applies to the revocation of declarations of consent that were given to us before the applicability of the General Data Protection Regulation (GDPR), i.e. before 25 May 2018. Please note that the revocation is only effective for the future. Processing that took place before the revocation is not affected.

Right to object on a case-by-case basis

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6 (1) (e) DS-GVO (data processing in the public interest); this also applies to profiling based on this provision within the meaning of Art. 4 No. 4 DS-GVO. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.

Insofar as we base the processing of your personal data on the balance of interests, you can object to the processing. This is the case if the processing is in particular not necessary for the performance of a contract with you, which is shown by us in each case in the following description of the functions. When exercising such an objection, we ask you to explain the reasons why we should not process your personal data as we have done.

In the event of your justified objection, we will examine the merits of the case and either discontinue or adapt the data processing or show you our compelling legitimate grounds on the basis of which we must continue the processing.

Right to object to the processing of data for direct marketing purposes In individual cases, we process your personal data for the purpose of direct marketing. You have the right to object at any time to the processing of personal data concerning you for the purposes of such advertising; this also applies to profiling insofar as it is associated with such direct advertising. If you object to processing for direct marketing purposes, we will no longer process your personal data for these purposes.

The objection can be made form-free and should preferably be addressed to: MEDION AG, Data Protection, Am Zehnthof 77, 45307 Essen, Germany

15 Responsible body

The responsible party is MEDION AG Am Zehnthof 77, 45307 Essen, Germany.

You can also reach the company data protection and the company data protection officer via the e-mail address

datenschutz@medion.com

Management Board of MEDION AG: Gerd Brachmann (Chairman),
Christian Eigen (Deputy Chairman)
Chairman of the Supervisory Board of
MEDION AG: Dr. Rudolf Stützle
Registered office of the Company: Essen AG Essen HRB 132 74