top of page

​

Privacy Policy and Data Protection 

 

This Privacy Policy is intended to provide site visitors with information on important aspects regarding the data processing within www.suma-medtec.com.  

 

Suma Medtec GmbH (“Suma Medtec”, “Controller”), as the Controller of this site, may process visitors’ data according to applicable law; the following applies to the design, content, and use of this site:

 

Definitions

  • Personal Data; means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

  • Processing: means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

  • Restriction of processing; means the marking of stored personal data with the aim of limiting their processing in the future.

  • Controller: means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

  • Third Party: means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorized to process personal data.

  • Consent: of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

 

Controller

Suma Medtec GmbH

Baumgartnerstrasse 1 Top 16

6330 Kufstein

Austria

Phone: +43 660 281 2463

E-mail: info@suma-medtec.com

Website: www.suma-medtec.com

 

Legal Bases

If you are located in the EU or UK, this section applies to you.

The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process your personal information. As such, we may rely on the following legal bases to process your personal information:

  • Consent. We may process your information if you have given us permission (i.e., consent) to use your personal information for a specific purpose. You can withdraw your consent at any time.

  • Performance of a Contract. We may process your personal information when we believe it is necessary to fulfill our contractual obligations to you, including providing our Services or at your request prior to entering into a contract with you.

  • Legal Obligations. We may process your information where we believe it is necessary for compliance with our legal obligations, such as to cooperate with a law enforcement body or regulatory agency, exercise or defend our legal rights, or disclose your information as evidence in litigation in which we are involved.

  • Vital Interests. We may process your information where we believe it is necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.

In legal terms, we are generally the "data controller" under European data protection laws of the personal information described in this privacy notice, since we determine the means and/or purposes of the data processing we perform. This privacy notice does not apply to the personal information we process as a "data processor" on behalf of our customers. In those situations, the customer that we provide services to and with whom we have entered into a data processing agreement is the "data controller" responsible for your personal information, and we merely process your information on their behalf in accordance with your instructions. If you want to know more about our customers' privacy practices, you should read their privacy policies and direct any questions you have to them.

 

If you are located in Canada, this section applies to you.

We may process your information if you have given us specific permission (i.e., express consent) to use your personal information for a specific purpose, or in situations where your permission can be inferred (i.e., implied consent). You can withdraw your consent at any time.

In some exceptional cases, we may be legally permitted under applicable law to process your information without your consent, including, for example:

  • If collection is clearly in the interests of an individual and consent cannot be obtained in a timely way

  • For investigations and fraud detection and prevention

  • For business transactions provided certain conditions are met

  • If it is contained in a witness statement and the collection is necessary to assess, process, or settle an insurance claim

  • For identifying injured, ill, or deceased persons and communicating with next of kin

  • If we have reasonable grounds to believe an individual has been, is, or may be victim of financial abuse

  • If it is reasonable to expect collection and use with consent would compromise the availability or the accuracy of the information and the collection is reasonable for purposes related to investigating a breach of an agreement or a contravention of the laws of Canada or a province

  • If disclosure is required to comply with a subpoena, warrant, court order, or rules of the court relating to the production of records

  • If it was produced by an individual in the course of their employment, business, or profession and the collection is consistent with the purposes for which the information was produced

  • If the collection is solely for journalistic, artistic, or literary purposes

  • If the information is publicly available and is specified by the regulations

 

If you are located in the United States of America, this section applies to you.

The only personal information that we have collected in the past twelve (12) months are identifiers (for example contact details, such as real name, company, e-mail address) via voluntary submission using our contact form. We will use and retain the collected personal information as needed to provide the Services or until you request its deletion, revoke your consent for its storage, or the purpose of storage is no longer applicable.

We do not intend to disclose your personal information with our service providers, unless explicitly agreed with you beforehand.

We may use your personal information for our own business purposes, such as for undertaking internal research for technological development and demonstration. This is not considered to be "selling" of your personal information.

We do not collect sensitive personal information (such as biometric data, precise geolocation, health data, or racial/ethnic origin) unless explicitly required and provided with informed consent.
We do not “sell” or “share” personal information as defined by applicable US state laws (e.g., CCPA/CPRA).

Suma Medtec GmbH has not disclosed, sold, or shared any personal information to third parties for a business or commercial purpose in the preceding twelve (12) months. Suma Medtec GmbH will not sell or share personal information in the future belonging to website visitors, users, and other consumers.

​

Your Rights:

You have rights under certain US state data protection laws. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law. These rights include:

  • Right to know whether or not we are processing your personal data

  • Right to access your personal data

  • Right to correct inaccuracies in your personal data

  • Right to request the deletion of your personal data

  • Right to obtain a copy of the personal data you previously shared with us

  • Right to non-discrimination for exercising your rights

  • Right to opt out of the processing of your personal data if it is used for targeted advertising (or sharing as defined under California’s privacy law), the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects (‘profiling’)

​​

Depending upon the state where you live, you may also have the following rights:

  • Right to access the categories of personal data being processed (as permitted by applicable law, including the privacy law in Minnesota)

  • Right to obtain a list of the categories of third parties to which we have disclosed personal data (as permitted by applicable law, including the privacy law in California, Delaware, and Maryland)

  • Right to obtain a list of specific third parties to which we have disclosed personal data (as permitted by applicable law, including the privacy law in Minnesota and Oregon)

  • Right to review, understand, question, and correct how personal data has been profiled (as permitted by applicable law, including the privacy law in Minnesota)

  • Right to limit use and disclosure of sensitive personal data (as permitted by applicable law, including the privacy law in California)

  • Right to opt out of the collection of sensitive data and personal data collected through the operation of a voice or facial recognition feature (as permitted by applicable law, including the privacy law in Florida)

​​

How to Exercise Your Rights:

To exercise these rights, you can email us at info@suma-medtec.com, or by referring to the contact details at the bottom of this document. We will honor your opt-out preferences if you enact the Global Privacy Control (GPC) opt-out signal on your browser.

Under certain US state data protection laws, you can designate an authorised agent to make a request on your behalf. We may deny a request from an authorised agent that does not submit proof that they have been validly authorised to act on your behalf in accordance with applicable laws.

​

Request Verification:

Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. We will only use personal information provided in your request to verify your identity or authority to make the request. However, if we cannot verify your identity from the information already maintained by us, we may request that you provide additional information for the purposes of verifying your identity and for security or fraud-prevention purposes.

If you submit the request through an authorised agent, we may need to collect additional information to verify your identity before processing your request and the agent will need to provide a written and signed permission from you to submit such request on your behalf.

​

Appeals:

Under certain US state data protection laws, if we decline to take action regarding your request, you may appeal our decision by emailing us at info@suma-medtec.com. We will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If your appeal is denied, you may submit a complaint to your State attorney general.

California Civil Code Section 1798.83, also known as the 'Shine The Light' law, permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to us by using the contact information provided in this Privacy Policy.

​

Your Privacy Rights

In some regions (like the EEA, UK, and Canada), you have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information, (ii) to request rectification or erasure; (iii) to restrict the processing of your personal information; and (iv) if applicable, to data portability; and (v) not be subject to automated decision-making. In certain circumstances, you may also have the right to object to the processing of your personal information. You can make such a request by contacting us via e-mail info@suma-medtec.com. We will consider and act upon any request in accordance with applicable data protection laws. If you are located in the EEA or UK and you believe we are unlawfully processing your personal information, you also have the right to complain to your Member State data protection authority or UK data protection authority. If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.

Withdrawing your consent: If we are relying on your consent to process your personal information, which may be express and/or implied consent depending on the applicable law, you have the right to withdraw your consent at any time. You can withdraw your consent at any time by contacting us via e-mail info@suma-medtec.com.

However, please note that this will not affect the lawfulness of the processing before its withdrawal nor, when applicable law allows, will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent.

 

Data Protection

At Suma Medtec, data protection is a high priority; we do not require personal data to operate this website. However, some personal data, such as name, last name, company, e-mail address, may be collected and processed for the sole purpose of communicating with the site visitors that wish to contact us. The submission of said information is entirely voluntary and will be treated as confidential in accordance with this privacy policy and in the basis of GDPR.

Furthermore, when visiting our website, your IP address may be recorded for the duration of the session for technical reasons (e.g., to connect your computer to the internet), and in accordance with the definition of legitimate interest within the provisions of GDPR, Article 6(1). It is not intended to be processed by Suma Medtec GmbH unless otherwise specified within this Policy.

We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, the usage of our website is at your own risk. You should only access the website within a secure environment.

We do not knowingly collect or process (nor do we intend to collect or process) data from individuals who are considered children under the data protection laws in their country of residence, unless consent is provided by a person holding parental responsibility or another lawful basis applies. Where we become aware that such personal data has been collected from said individual without the necessary consent or legal basis, we will take appropriate steps to erase the data from our records. By using the Services, you represent that you are at least 18 or that you are the parent or guardian of such a minor and consent to such minor dependent’s use of the Services. If you have a reason to believe that we have unlawfully processed a child's personal data, please contact us without delay at info@suma-medtec.com.

 

We adhere to the principles of data minimization and storage limitation, meaning that we only collect the minimum amount of personal data necessary, and retain it no longer than necessary for the purposes stated. Retention periods vary based on applicable legal, contractual, or operational obligations, but we regularly review our data retention practices to ensure compliance.

​

Contact Information

As mentioned above, personal data may be voluntarily submitted by visitors of this website. This information is submitted through a form, and it requires a contact Name, Last Name, e-mail address and Message to us. These fields are required as a means of identifying the user and being able to contact them to address their inquiry. Company field is optional. By submitting your contact information through the website’s Contact form, visitor is giving explicit consent to Suma Medtec to store it.

This website provides other means for contacting Suma Medtec for visitors who do not want to use the website’s form as the first point of contact.

Suma Medtec will store this information only for the purpose of answering your inquiry and any follow-ups, and until you request its deletion, revoke your consent for its storage, or the purpose of storage is no longer applicable.

You have the right to request your data to be deleted from our system, please send us an e-mail to: info@suma-medtec.com.

 

Cookies and similar technologies

Cookies are small pieces of data stored on a site visitor's browser. They are typically used to keep track of the settings users have selected and actions they have taken on a site. Some of these cookies may remain stored on your device until you delete them. Deactivating cookies could restrict the full functionality of our website. This website uses cookies and similar technologies to personalize content, analyze traffic, and enhance user experience. By using our website, you consent to our use of cookies, unless you opt out. You can change your cookie preferences at any time by adjusting your browser settings or by accessing the cookie banner settings displayed when visiting the site. We use the following categories of cookies:

  • Essential cookies: necessary for website functionality.

  • Analytics cookies: help us understand how users interact with our site.

  • Functional cookies: enhance user experience.

​

More information can be found here: Wix Help Center - Cookies and your website at Wix

 

Legitimate Interest

In accordance with GDPR Article 6(1) on Lawfulness of processing of information, the data which is subject to collection and for which the website visitors give consent to, are processed for the legitimate interest of carrying out our businesses, providing our customers and internal employees the best experience.

 

Website Host

Suma Medtec has created the content of its site and designed on Wix.com Ltd., an Israeli software company which provides cloud-based web development services.

 

SSL Encryption

Suma Medtec uses SSL encryption (Secure Sockets Layer) allowing visitors to view our site over an HTTPS connection. This can be confirmed by checking the lock icon in your browser, located on the left site to the website’s address bar.

 

Supported browsers for desktop devices:

Supported browsers for mobile devices:

 

Older browsers may not support the high security standards required by SSL certificates. For more information, please visit Wix Help Center - SSL and HTTPS.

 

Third Party Plugins

Suma Medtec uses third party plugins, which are available within the website and direct the visitors to external links.  The responsibility for the content on the external links of these third party providers is entirely with the Controllers of those linked pages. Should one of the linked pages contain questionable or illegal content, please notify us, in which case the link will be deleted immediately.

 

LinkedIn Plugin

A LinkedIn plugin is used to direct visitors to Suma Medtec’s LinkedIn professional page. When a visitor clicks on the plugin, a direct connection between your browser and LinkedIn servers will be established. The LinkedIn network is provided by LinkedIn Corporation, Headquartered in 1000 West Maude Avenue, Sunnyvale, California, United States.

Privacy Policy: LinkedIn Legal - Privacy Policy

Cookies Policy: LinkedIn Legal - Cookie Policy

Google Maps

Our website uses Google Maps as the service to mainly indicate our company’s location. It may also be necessary to store a visitor’s IP address in order to use all functions of Google Maps. Google Maps is a web mapping product developed at Google, Headquartered in 1600 Amphitheatre Parkway in Mountain View, California, United States.

Privacy Policy: Google Policies - Privacy

Google Use of Cookies: Google Policies - Cookies

 

Google Analytics

Suma Medtec’s website has Google Analytics integrated. This tool is used by us to better understand the use of our site, and it provides us with a (non-personal data) summary of number of visitors, site sessions, and page views. The use of this feature offered by the Wix and Google is not intended to collect visitor’s personal data, it is use with the legitimate interest to evaluate the use of this website and improve its functionality.

Google Analytics uses cookies, see Cookies section of this policy for details.

Further details on Google Analytics: https://www.google.com/analytics

To opt out of being tracked by Google Analytics across all websites, visit this link: http://tools.google.com/dlpage/gaoptout.

 

Controls for do-not-track features

Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Policy.

​

Changes to this Policy

Suma Medtec actively monitors applicable regulations pertaining to Privacy and Data Protection. This website and policy may be updated for continuous compliance to the latest applicable regulations and as such, Suma Medtec reserves the rights to update without prior notice.

 

About the content of this website

All content has been created by Suma Medtec GmbH based on its acquired expertise and industry knowledge.

Photos credits: Suma Medtec GmbH or Shutterstock stock photos purchased through Wix.com. All rights reserved.

Use of any of the content within this website is only allowed with written permission by Suma Medtec GmbH.

 

Questions and comments 

If you would like to access, correct, amend, or delete any personal data we have about you, please contact us: 

​

Suma Medtec GmbH 

Baumgartnerstrasse 1 Top 16

6330 Kufstein

Austria

 

 

Last update: June 2025. 

​

bottom of page