Privacy Policy

Data Controller

LaevaCare ApS is the data controller responsible for processing the personal data we collect about our customers and individuals who submit information through our online forms.

LaevaCare ApS

Haugesundsvej 5, 8200 Aarhus N, Denmark

CVR no.: 46106229

If you have any questions about how we process your personal data, please contact us at: kontakt@laevacare.dk

 

Background

We process your personal data in accordance with applicable data protection legislation, including the EU General Data Protection Regulation (GDPR).

Personal data means any information relating to an identified or identifiable physical person. This includes any information that can directly or indirectly identify an individual. Learn more about personal data. 

 

How We Process Your Personal Data

We process your personal data for the following purposes:

 

When You Visit Our Website

When you visit our website, we use cookies to ensure that the website functions properly. You can read more about this in our Cookie Policy.

 

Communication with Potential Customers

If you contact us with questions about our products or services, you may do so through:

  • Email
  • Telephone

We process the personal data you provide so that we can respond to your enquiry and communicate with you.

Typically, we process: name, email address, telephone number.

Our legal basis for processing this information is Article 6 (1) (f) GDPR (legitimate interests).

We retain correspondence only for as long as necessary to determine whether you wish to use our products or services.

In exceptional circumstances, we may retain your personal data for a longer period where necessary.

 

Customers

We process personal data relating to our customers to ensure that we can deliver our products and services correctly.

This may include:

  • Name
  • Address
  • Purchased products or services
  • Special agreements
  • Payment information
  • Other information necessary to fulfil our contractual obligations

Our legal basis is Article 6 (1) (b) GDPR (performance of a contract).

As a manufacturer of medical devices, we are also subject to documentation and traceability requirements under the EU Medical Device Regulation (MDR). We therefore process and retain personal data where necessary to comply with these legal obligations.

Our legal basis for this processing is Article 6 (1) (c) GDPR (legal obligation).

We retain personal data only for as long as necessary for the purposes for which it was collected, including compliance with applicable legal obligations.

 

Newsletter

You can subscribe voluntarily to our newsletter and unsubscribe at any time.

The purpose of our newsletter is to send:

  • Company updates
  • New content published on our website
  • Information about our products and services

We will only send newsletters if you have given your explicit consent.

Our legal basis is Article 6 (1) (a) GDPR (consent).

We process your personal data for as long as you remain subscribed. If you unsubscribe, we will stop sending newsletters immediately. If we have not sent you any newsletters for one year, your consent will automatically expire.

Following your withdrawal of consent to our newsletter, we retain documentation of your consent for two years in order to comply with Danish consumer protection legislation concerning electronic marketing.

 

Accounting Records

We are legally required to retain accounting records in accordance with the Danish Bookkeeping Act.

These records may include:

  • Name
  • Address
  • Invoice details
  • Descriptions of purchased products or services

Our legal basis is Article 6 (1) (c) GDPR (legal obligation).

Accounting records are retained for a minimum of five years after the end of the relevant financial year.

 

Other Data Processors

We work with external suppliers and business partners who process personal data on our behalf.

These may include providers of:

  • IT systems
  • Website hosting
  • Cloud services
  • Payment solutions
  • Email marketing
  • Customer relationship management (CRM)
  • Analytics
  • Marketing services

We require all data processors to implement appropriate technical and organisational measures to protect your personal data.

Where required, we enter into Data Processing Agreements with our processors in accordance with Article 28 GDPR.

 

Disclosure of Personal Data

We do not sell your personal data.

We may disclose personal data where necessary to our data processors, where required by law, or where you have given your consent.

 

Profiling and Automated Decision-Making

We do not carry out profiling or make automated decisions that produce legal or similarly significant effects concerning you.

 

International Data Transfers

As a general rule, we use data processors located within the EU/EEA or processors that store personal data within the EU/EEA.

In certain cases, we use service providers located outside the EU/EEA, including in the United States and Canada, for example in connection with Microsoft services, social media platforms, email marketing providers and our webshop platform.

Where personal data is transferred outside the EU/EEA, we ensure that appropriate safeguards are in place in accordance with applicable data protection legislation.

 

Information Security

We have implemented appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

We regularly assess the risks associated with our processing activities and continuously review our security measures.

We also ensure that our employees are familiar with applicable data protection legislation and our internal procedures for handling personal data.

 

Your Rights

Under the GDPR, you have a number of rights regarding our processing of your personal data.

If you wish to exercise any of these rights, please contact us.

 

Right of Access

You have the right to obtain confirmation of whether we process your personal data and, where applicable, access to that data.

 

Right to Rectification

You have the right to have inaccurate personal data corrected.

 

Right to Erasure

In certain circumstances, you have the right to have your personal data erased before our normal retention period expires.

 

Right to Restriction of Processing

In certain circumstances, you have the right to request restriction of the processing of your personal data.

 

Right to Object

You have the right to object to our processing of your personal data where permitted by law.

You also have the right to object to processing for direct marketing purposes.

 

Right to Data Portability

Where applicable, you have the right to receive your personal data in a structured, commonly used and machine-readable format and to have those data transferred to another data controller.

You can read more about your rights on the website of The Danish Data Protection Agency (Datatilsynet): www.datatilsynet.dk

 

Withdrawal of Consent

Where our processing is based on your consent, you may withdraw your consent at any time.

Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.

 

Complaints

If you are dissatisfied with how we process your personal data, you have the right to lodge a complaint with The Danish Data Protection Agency (Datatilsynet).

More information is available at: www.datatilsynet.dk