Effective date: June 1, 2020
COMMITMENT TO PRIVACY.
CVRx, Inc. (“CVRx”, “Company”, “we”, or “us”) is committed to respecting and protecting your privacy.
THE PERSONAL INFORMATION CVRx COLLECTS.
The list below details the categories of Personal Information that we collect and have collected over the past 12 months:
- Contact data: such as name, title, address, phone number, mailing address, and email.
- Other identifiers: such as device ID or serial number, various types of personal health information (e.g., health insurance information, medical information, and the like), online identifiers, and other similar identifiers.
- Communication data submitted by you: such as questions and feedback.
- Demographic data: such as language, age, and gender.
- Marketing preferences: such as e-mail subscription and frequency preferences.
- Site data used to facilitate the use of the Website: such as login and technical data.
- Other data: such as product use and application data, IP address, the browser you are using, your location and other geographic data, the website you came from and the website you visit after leaving, pages viewed on the Website, links clicked on the Website, and time spend on a particular page of the Website or the Website as a whole.
How CVRx May collect personal INFORMATION.
CVRx collects Personal Information about you from the following categories of sources, including, but not limited to:
- Directly from you: We may collect Personal Information that you provide directly to CVRx from sources, such as this Website, telephone, email, or online interfaces.
- Automated data: We may collect Personal Information through automated technologies (e.g., cookies). We use these technologies to collect information about your equipment, browsing actions, and other patterns, and information about your computer and internet connection (e.g., IP address, operating system, and browser type).
Legal basis for processing
We collect, handle, process, use and disclose your Personal Information only where we have a legal basis for doing so under applicable laws. The legal basis depends on how you use our Site and how we use your Personal Information. Our “legal bases” for processing your Personal Information are as follows:
- Consent: In some cases, CVRx will only process your Personal Information after you have provided consent. For example, by signing up for newsletters and requesting to be contacted. Note: CVRx likely has a different legal basis for processing your information so that consent is not needed (e.g., legitimate interest). If the use of the date you are providing is not readily apparent at point of collection, we will provide additional information at that time regarding how we collect your Personal Information and the purpose(s) and use of your Personal Information.
- Performance of a contract: CVRx processes your Personal Information in order to fulfill our obligations to you under contract to deliver goods and services to you. For example, we will process your Personal Information in order to provide you with the products and services you have requested from us.
- Legitimate interest: CVRx may process your Personal Information as necessary for our legitimate interests which include, but are not limited to, facilitating communication between us and you; to help improve our online interfaces; to promote our business by using email or other contact information to communicate with you; to safeguard our IT infrastructure (e.g., for detection and prevention of fraud and other crimes); and to develop or enhance our products and services. CVRx’s legitimate interests are balanced against your rights and freedoms. We will not process your Personal Information if our processing of your Personal information is outweighed by your rights and freedoms.
- As required by law: CVRx may process your Personal Information when we are required or permitted to do so by law in order to comply with government inspection, audits, and other valid requests from government or other authorities; to respond to legal process; or to protect our rights and property.
CVRx will only use your Personal Information for the purposes for which it was collected, unless we reasonably consider that there is a need to use it for another reason and that reason is compatible with the original purpose, we have your consent, or are otherwise required or permitted by law.
If your Personal Information is needed for unrelated purposes, we will attempt to notify you and explain the legal basis which allows us to do so.
OUR COMMERCIAL OR BUSINESS PURPOSES FOR COLLECTING Personal INFORMATION.
CVRx may keep and use Personal Information collected from you through this Website for the following uses:
- To provide you with access to this Website.
- To respond to your requests.
- To personalize your access to our Website.
- To develop records (including records of your Personal Information).
- To contact you with pertinent information about products, clinical trials, or important safety information, and about products and services of ours and of others.
- For analytical purposes and to research, develop, and improve programs, products, services, and content.
- To remove your personal identifiers. Once we have de-identified information, it is considered non-personal information and we may treat it like other non-personal information.
- To protect someone’s health, safety, or welfare.
- To protect our rights or property.
- To comply with a law or regulation, court order or other legal process, such as preventing, detecting and investigating security incidents and potentially illegal or prohibited activities.
How CVRx May use non-personal information.
Non-personal information is information that has been aggregated, de-identified or anonymized and therefore can no longer be used to identify you or be tied to you. CVRx may use such aggregated, de-identified or anonymized data and share it with third parties for our lawful business purposes, including to analyze, build and improve the Website and promote our business, provided that we will not share such data in a manner that could identify you.
Sharing personal information with THIRD PARTIES.
Your Personal Information may be shared with a physician or other healthcare provider, if you request to be put in contact with a physician or other healthcare provider, if you are seeking information about a clinical trial, if you are seeking more information about whether a product or service may be right for you, or if you or someone else’s safety or wellbeing is in question.
We also share your Personal Information with marketing analytics providers (e.g. Google Analytics) to manage our marketing and advertising activities; advertising service providers to provide you with targeted advertisements; and analytics and search engine providers that assist us in the improvement and optimization of our Website. Visit Google’s webpage to learn more about how Google uses information from sites or apps that use their services.
In the event that we sell or buy any business or assets, in which case we may disclose your Personal Information to the prospective seller or buyer of such business or assets; or if we, or substantially all of our assets, are acquired by a third party, in which case Personal Information held by us about you may be one of the transferred assets.
We may be required by law to share your Personal Information with a third party, including government and/or law enforcement agencies, in response to a warrant, subpoena, court order, law or regulation. In addition, we may decide to cooperate with government or law enforcement authorities to investigate and prosecute harmful or allegedly illegal activities.
We may also share your Personal Information in ways we believe are consistent with FDA and other governmental guidance, directions, regulations, and laws (e.g., HIPAA), where applicable.
STORING AND PROTECTING YOUR PERSONAL INFORMATION.
We may store, collect, transfer and process your Personal Information in a country other than you country of residence. These countries are the United States and the European Union. The data protection and other laws of countries to which your information may be transferred may be different in your country. By submitting your Personal Information, you agree to any transfer, storing or processing.
CVRx has put in place technical and organizational safeguards to protect the confidentiality, integrity, and availability of your Personal Data. We seek to protect your Personal Data against unauthorized access, use or disclosure, by using appropriate security technologies and procedures, such as encryption and access controls and limitations, based on the type of Personal Information and how we are processing that data.
CVRx takes precautions to protect your information from loss, misuse or unauthorized access or disclosure. However, no data transmission over the internet is certain to be secure and we cannot guarantee its security. You should also help protect your data by appropriately limiting access to your computer or device and browser. If you are uncertain or have any concerns about how information volunteered by you will be kept, used or disclosed, do not volunteer that information.
This Website is not targeted to children under the age of 16 and CVRx does not knowingly collect or solicit Personal Information about such children. If we discover that a child has provided us with Personal Information online through this Website, we will take delete this information as quickly as possible. If you believe we may have received Personal Information from a child under the age of 16, please contact us immediately at firstname.lastname@example.org.
You may revoke your consent for the receipt of communication that we send to you at any time by using the “unsubscribe” functionality included in our emails to you or by contacting us directly at email@example.com.
You should note that his will not affect all communications from us, for example, we are legally required to provide notices such as notification of a data breach in which case you should expect to receive a notification via email. It is important that the Personal Information we hold about you is accurate and current. Please keep let us know if your Personal Information changes.
You may make a request to access, correct, or delete your Personal Information or otherwise object to our processing of such Personal Information by contacting us directly. We will respond to reasonable requests in accordance with applicable law and subject to legal and contractual restrictions. We will not discriminate against you for exercising these rights.
There may be times where we cannot grant you access to the Personal Information we hold. For example, if such disclosure would interfere with the privacy of others or if it would result in a breach of confidentiality. We will provide written explanation for our refusal to grant access.