Medtronic FocusOn℠ Clinician Website
Privacy Statement
 
General Information
Medtronic hereinafter referred to as “we” or “Medtronic”) is committed to maintaining your trust by protecting your Personal Data. When we use the word “you” or “your”, we mean FocusOn Clinician/Customer.
This Privacy Notice explains how we process your Personal Data on the FocusOn Clinician’s website (hereafter “Site”) to which access is provided to you in light of the FocusOn services (hereafter “Services”).
We are committed to ensuring that your privacy is respected and that your Personal Data is handled in a transparent and lawful way. Any Personal Data you provide will be used only in accordance with this Privacy Notice. We encourage you to read this Privacy Notice carefully.
This Site may contain links to other websites. Some of those websites may be operated by Medtronic, and some may be operated by third parties. We provide any links for your convenience, but we do not review, control, or monitor the privacy practices of websites operated by others. This Privacy Notice does not apply to any other website, even other Medtronic websites. We are not responsible for the performance of websites operated by third parties or for your business dealings with them. Therefore, whenever you leave this Site we recommend that you review each website's privacy practices and make your own conclusions regarding the adequacy of these practices.

Definitions
By “Personal Data” we mean any information relating to an identified or identifiable person; in other words: any information which can lead to knowing who you are (either directly or indirectly).
By “Sensitive Information” we mean Personal Data revealing or relating to your health (such as your device serial number, or the date of an implant), genetic or biometric data, your racial or ethnic origin, religious or philosophical beliefs, sex life or sexual orientation, political opinions or trade union membership.
By “Processing” we mean any operation which is performed on Personal Data, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restrictions, erasure or destruction.
By “Consent” we mean your freely given, specific, informed and unambiguous (not subject to misinterpretation or more than one interpretation) indication of your wishes by which you, by a statement or by a clear affirmative action, signify agreement to the Processing of your Personal Data.
By “Aggregated Data” we mean that data from different sources are combined to observe trends and patterns over a large population/group. By using a large population/group and deriving statistics from it, we minimise identification to unique individuals.

Personal Data Categories

The following Personal Data is processed on the Site:
Clinician data
- Contact and account details:
• First and last name
• Email address
• Phone number
• Hospital name
• Clinic address
• Username and password
• Account status
• Record creation
• Record updates

Health data for delivery of the Services
- Patient health data measured by Medtronic devices registered in CareLink and linked to your FocusOn CareLink account and enrolled in the FocusOn service:
• Implanted device model and serial number
• Remote monitoring solution method, model and serial number (if applicable)
• Patient ID
• Clinic ID
• Episode (ECG/EGM) data
• Diagnostic data
• Patient enrollment
• Date of birth

- Technical device data
• Type of device
• Device serial number
• Device programming records
• Lead details (if applicable)
• Transmission schedule
• Communication status

Purposes and Legal Basis for Processing

Contract
By using this Site, you agree to the terms of this Privacy Notice. Please read our Terms of Use and the Medtronic FocusOn Agreement we have with you or with the organization on whose behalf you are engaged (the “Agreement”) to understand the general rules about your use of this Site and your Personal Data which we process based on the Agreement. Except as written in any other disclaimers, policies, terms of use, other notices on this Site or the Agreement, this Privacy Notice and the Terms of Use are the complete agreement between you and Medtronic with respect to your use of this Site. You may be subject to additional terms that may apply when you access particular services or materials on certain areas of this Site, or by following a link from this Site elsewhere.
We may keep and use Personal Data we collect from you through this Site:
• To provide you with access to this Site via a personal account in the relevant clinic profile;
• To provide and communicate with you regarding the Services, including responding to requests submitted via an online form on the Site to which we may respond to you via email.

Legitimate Interests
When we Process your Personal Data for carefully considered purposes based on the legitimate interests of Medtronic or another party, we do so, based on our assessment that such legitimate interests do not override your data protection rights. We may Process your Personal Data for the following purposes, based on legitimate interests:
• To personalize your access to our Site, for example, by telling you about new features that may be of interest to you;
• To contact you with information that might be of interest to you, including information about products and services of ours and of others (see further Marketing Communications below);
• To analyze survey results on customer satisfaction and user experience, by requesting specific information on your practice generally, your experiences with patients that are enrolled in FocusOn, and your activities on this Site, in order to improve our Site and Services;
• To aggregate Personal Data to a level where you are no longer directly identifiable. Such information is used to create and communicate statistics on the general use of our Site in order to:
o To get a better understanding of how effective our services and products are;
o To identify where our services and products may require improvement;
o To support research and development for innovation and share Aggregated Data with third parties for such research purposes in support of academic research and/or improved services and products.

Consent
We may also process your Personal Data for other purposes for which you have specifically given Consent. Such purposes may include:
• Where Consent is required to send you communications regarding products or services that may be of interest (see further Marketing Communications below);
• In case we need to process any sensitive Personal Data (such as health data) in connection with the Site, we will only do so on the basis of your explicit Consent.
Marketing Communications: to the extent that we send you communications regarding products and services that we believe may be of interest to you, we will only do so on the basis of legitimate interests or your Consent, in accordance with applicable laws. You may at any time opt-out of receiving such communications via the opt-out mechanism included in the relevant communication, or by Contacting Us as set out below.

Legal Rights and Obligations
We may also process your Personal Data on the basis of our legal right or obligation do so in order to:
• To track and manage compliance approvals and violations;
• In the event of a legal claim: for the establishment, exercise or defense of a legal claim.

Disclosure of Your Personal Data
We may disclose your Personal Data as we believe to be necessary or appropriate to protect the health and safety of you or another person, our physical and online operations, and the property, rights, and privacy of our affiliates, you or others.
In the ordinary course of business, we will share certain Personal Data with third parties that we hire to perform services or functions on our behalf. In all cases in which we share your Personal Data with a third party, we will not authorize them to keep, disclose or use your Personal Data with others except for the purpose of providing the services we ask them to provide. We only disclose your Personal Data to our Medtronic affiliates or third parties for the purposes identified above.
Third parties are obligated to use the Personal Data in accordance with the binding agreements that we have with them. The agreements include data processing clauses to ensure that your Personal Data is handled in accordance with applicable data protection laws and regulations, and with Medtronic’s privacy, data protection and security policies and standards.
We will not sell, distribute or lease your Personal Data to third parties unless we have your Consent or are required by law to do so. In the unlikely event that all or part of our business is acquired by a third party, your Personal Data may be transferred to the new corporate owner insofar as relevant to the business in question and subject to appropriate safeguards being in place.
We may also need to transfer your Personal Data to regulatory authorities in order to comply with our legal obligations. 

International Transfer of Personal Data
When we transfer your Personal Data to other Medtronic affiliates or to a third party in another country, we will ensure that adequate safeguards are in place in accordance with applicable laws and regulations.
Where we transfer Personal Information internationally, we will ensure a level of protection for Personal Information that is adequate according to applicable laws and regulations, and approved legal mechanisms are in place, such as European Commission approved standard contractual clauses. For more details or to request a copy please Contact Us at privacyeurope@medtronic.com.

Security
We are committed to protect the security and confidentiality of your Personal Data. To prevent accidental or unlawful destruction, loss, alteration, unauthorized access or disclosure of your Personal Data, we use appropriate technical and organizational measures to safeguard and secure the Personal Data we process. You should keep in mind that no internet transmission is ever 100% secure or error-free. In particular, email sent to this Site may not be secure and you should therefore take special care in deciding what information you send to us via email.
We will inform you and/or the relevant supervisory authorities without undue delay should an unauthorized disclosure of your Personal Data require such a notification.

Retention
Your Personal Data will only be retained by Medtronic for so long as necessary and relevant to fulfil the purposes set out herein.
For more information on how long your Personal Data is stored please contact us via rs.privacyeurope@medtronic.com.

Your Rights
In accordance with applicable laws, you may have the right to:
• Request access to the Personal Data which we hold concerning you.
• Request rectification, erasure or restriction of the Processing of your Personal Data (including deletion of your Learning Management account).
• Object, based on your particular situation, to any use or Processing of your Personal Data which we have based on our legitimate interests.
• Request your Personal Data in a structured, commonly used and machine-readable format (data portability).
• If we use your Personal Data based on your Consent, you can withdraw your Consent at any time and discontinue the relevant data Processing activities. Note that this does not affect the lawfulness of Processing based on Consent before your withdrawal.

Please note that we may keep using Aggregated Data (statistics, trends), even after you request deletion of your Personal Data or withdraw your Consent, as there may be no technical means available to isolate or identify the data elements to exclude.

To exercise any of these rights, please contact us at rs.datasubjectrightrequest@medtronic.com. Please note that in accordance with applicable laws, we may ask you to provide some proof of identity before we can process your request.
If you are not satisfied with our handling of your request, you may also wish to exercise your right to file a complaint with a supervisory authority.

Contact Us
The Site is provided by the Medtronic entity identified in the Contract or other documentation provided in connection with the Services. Please note that the Services are provided through a contractual agreement with your institution or employer, who are also responsible for the Processing of your Personal Data in connection with the Services, in which case your institution or employer should be your first point of contact in that regard. Medtronic’s EMEA Headquarters is located at
Medtronic International Trading Sárl
Route du Molliau 31
CH - 1131 Tolochenaz
Email: rs.privacyeurope@medtronic.com

Data Protection Officer
rs.europeandpo@medtronic.com
Medtronic B.V.
ATTN: Data Protection Officer
Earl Bakkenstraat 10
6422 PJ Heerlen
The Netherlands

This Privacy Notice is published/was last updated on July 16, 2020
We recognise that data protection is an ongoing responsibility, so we will update this Privacy Notice in case we undertake new Personal Data practices or adopt new privacy policies.