Santé Services S.A., as operator of the medlogistics.lu website, takes particular care to protect the privacy of its customers.
You will find below the Information Notice allowing you to be informed of the data processing carried out within the framework of this e-commerce site in accordance with article 13 of the GDPR.
Santé Services S.A. has a Data Protection Policy available upon request via the contact information available in point 13 of this information notice.
This information has been updated as of June 2020.
Santé Services S.A. is responsible for the data processing which are carried out within the framework of the management and organization of this e-commerce site.
The Robert Schuman Hospital Foundation is the sole shareholder of Santé Service S.A., a company providing services in the health sector.
However, Santé Services S.A. is a legally independent company specialized in the provision of catering services in the health sector.
The data is collected directly from the concerned Person (yourself).
The collection is carried out when you complete the online forms on the e-commerce website of the MedLogistic platform.
The personal data collected on the e-commerce site of the MedLogistic platform are hosted by EDITUS.
The Data Centers are located in Luxembourg.
The categories of data concerned are identification data such as:
- your name,
- your first name,
- date of birth.
- your company
- professional number
- complete postal address.
- e-mail address,
- Phone number.
Your personal data is processed by Santé Services via the MedLogistic platform for the following purposes:
- creation and management of the customer account,
- management of order baskets,
- delivery of orders,
- processing of contact requests via the online form,
- transmission and management of the newsletter when subscribing to the newsletter.
No further processing of your data is planned at the moment. However, it is possible that statistics may be produced at a later date.
If this is the case, the present mentions will be updated.
These data processing operations have several legal bases.
In accordance with article 6-1-a of the GDPR, the processing is based on the collection of your consent to the implementation of the processing in view of the fact that you wish to make a purchase on the MedLogistic platform.
The processing is necessary for the purposes of the legitimate interests pursued by the Data Controller. The legitimate interest of Santé Services S.A. is to manage and deliver a supply of goods (article 6-1-f of the GDPR).
You are obliged to provide your personal data. In the event that you refuse, you will not be able to acquire the goods offered by the platform.
The recipients of the collected data are both internal and external to Santé Services S.A:
Internal Recipients :
- Supply Chain Manager, Santé Services S.A
- Director, Santé Services S.A
- Supply Chain Referent, Santé Services S.A.
- Coordinator Manager, Health Services S.A.
- Accounting, Santé Services S.A
- Data Protection Officer, Santé Services S.A.
- Warehouseman and warehouse Manager, Post Logistics
- Post Logistics for the delivery of orders
- the company Editus for the management and hosting of the MedLogistic platform
- The Control Authorities in case of audits or controls.
Within the framework of the management of the MedLogistic e-commerce site, no data transfer outside the European Union is foreseen.
However, if this were to change, you would be informed prior to the transfer and the Robert Schuman Hospitals Foundation undertakes to only transmit the data to third countries in which an adequacy decision has been issued by the Commission or, in the case of transfers referred to in Articles 46 or 47, or in Article 49-1-2 of the GDPR, a country with appropriate or adapted guarantees.
An automated individual decision, such as profiling, is any form of automated processing of personal data consisting in using such data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict elements concerning the work performance, economic situation, health, personal preferences, interests, reliability, behavior, location or movements of that natural person (Article 4-4 of the GDPR).
Santé Services S.A. does not perform automated individual decisions.
The data collected as part of this data processing will be kept for 5 years from the delivery of the service.
Concerning the newsletter, your data will be kept until you make the request for cancellation.
The data may be destroyed if you expressly request this in accordance with your rights set out in point 12 of this notice.
In accordance with articles 15 to 22 of the GDPR, you have rights over your personal data.
You have the right to ask Santé Services S.A.:
a) access to your personal data,
b) the correction or deletion of these in the event of erroneous or inaccurate data,
c) a limitation of the data processing under validation of certain criteria,
d) to oppose the processing for legitimate reasons,
e) the portability of your data under validation of certain criteria,
f) not to be subject to automated individual decisions.
If you wish to obtain more information or to assert your rights above, you may contact the Data Protection Officer of Santé Services S.A. via the following means:
By post :
A l’attention du DPO de Santé Services S.A
Gestion des droits des personnes
9, rue Edouard Steichen
In order to process your request, you may be asked for identification document to verify your legitimacy.
If you exercise your right of access or rectification, the data relating to the identification documents will be kept for a period of one year. In case of exercise of the right of opposition, these data will be archived for the period of three years.
If you wish to file a data protection complaint, you can contact the DPO of Santé Services S.A., using the information in point 13 above.
You may also file a complaint with a Control Authority in the event of a dispute, if the concerned dispute has not been resolved by Santé Services S.A., in accordance with the Complaint Management Procedure.
In Luxembourg, you may file a complaint with the National Commission for Data Protection via their website.