Global Privacy/Data Protection Notice
Due to the nature of its global business, KMT Medical Incorporated and its subsidiaries around the world, including the entity identified in the section Contact Information below (such entity referred to as “KMT Medical”, "we", "our" and "us"), may collect and use your personal information.
The General Data Protection Regulation (EU) 2016/679 (GDPR) is a regulation in EU law on data protection and privacy. The GDPR applies to Personal Data about any identified or identifiable natural person in the European Economic Area (EEA), regardless of nationality or place of residence.
This section describes your rights in relation to the Personal Data of natural persons covered by the EU GDPR, and explains how to exercise them.
If you have any questions, comments, or concerns about or in connection with this Global Privacy/Data Protection Notice, please contact us by using one of the following methods:
Attn: Legal & Compliance Department
KMT Medical Incorporated
17755 US HWY 19 N., Suite 201
Clearwater, FL 33764
United States of America
By phone: +1-727-900-7247
By Toll Free: 1-888-611-5104
By email (for general inquiries): email@example.com
By email (for privacy related inquiries): firstname.lastname@example.org
The KMT Medical Website presents the company’s mission and values. The Website provides useful information to the users about the KMT group of companies.
KMT Medical collects and processes information relating to users of the Website, including cookies that are necessary for the functionality of the Website and to help ensure a positive user experience.
We may collect personal information to determine your suitability for the position you are applying for as part of the application process based on the application provided by you through forms provided in sections of this Website and/or in other contexts, such as by participating in a career fair or responding to a job advertisement.
We also collect your personal information for this purpose from our various recruitment agencies with whom we partner to fill employment positions.
Your decision to provide us with any personal information in this context is voluntarily; however, if you do not provide certain information, we may not be able to process your application or other requests you may have with respect to your potential employment with KMT Medical.
The information you provide to us will be used to contact you to provide you information about job positions and market news about KMT and in the event you apply for a position, to process your application.
When applying for a position, you will have the opportunity to specify whether you want the information you provide to be shared with KMT recruiters worldwide, only KMT recruiters in your country of residence, or only KMT recruiters managing the specific positions to which you apply.
Data collected and processed are those contained in resumes and covering letters sent by candidates, mainly their surname, first name, date of birth, contact details and previous professional experience.
Such data are processed by KMT solely for the purpose of recruitment, which constitutes a legitimate interest for KMT within the meaning of Article 6(f) of the GDPR. The data is kept for a reasonable period, not more than necessary for the purpose of recruiting.
KMT Medical may directly or indirectly collect information relating to the health and medical professionals that provide care to patients. This data is necessary for KMT Medical to carry out various tasks, including: regular monitoring of patient compliance; alerting physicians in the event of anomalies; recalling patient information; coordination with the medical team supporting the end-user/customer. This data is also processed for the purpose of direct marketing such as sending news related to KMT and its activity.
Data that may be collected includes:
First and last name
Hospital name, city/location of practice and/or postal code
Specialty of the healthcare professional
Professional identification number, if any
These data are not collected directly from the health professionals concerned. Consequently, the health professional concerned are informed of the processing implemented for the purposes of drawing up the "prescriber form" and sending news as soon as the first written exchange between KMT and the health professional takes place. On this occasion, he or she is invited to consent to the data processing operations set out above, pursuant to Articles 6(a) and 7 of the GDPR.
These data are kept for as long as necessary to achieve the purposes of the processing, while complying with applicable legal and regulatory limits.
Data that may be collected includes:
Customer/end-user's first and last name
Date of Birth
Healthcare identification number
Health insurance program information
Identity and contact details of primary care provider and other relevant specialists, including but limited to ostomy nurse, specialized nurse, gastroenterologist, urologist
If the person does not have legal capacity, the surname and first name of his or her representative
KMT Medical and its affiliates may also collect and process data containing direct or indirect information on the end-user customer health, such as:
Health products that are prescribed, ordered, and/or that KMT is in charge of delivering; or
Usage of such health products (colostomy, ileostomy, urostomy, self-sheathing, penile sheath, wound healing).
Such data is necessary for KMT to carry out its services, which, in some jurisdictions, is required by law.
Processing of certain data by KMT Medical and/or its affiliates may be based on your consent, which you provide by completing and submitting your consent declaration. Your granting of consent is strictly voluntary.
Pursuant to Art. 6 of the GDPR, KMT relies on the consent of the end-user customer and the performance of the contract for the following processing of data:
Patient information (e.g., presentation of products that can meet the patient's needs with their advantages, disadvantages, costs and possible levels of coverage by insurance organizations, demonstration of the functioning of the devices, guarantee conditions and the usual lifespan);
Reminders for the conditions of use of the equipment;
Delivery of the equipment and consumables necessary for product use and, if necessary, delivery to the person's place of residence;
Establishing a file containing all the elements allowing the follow-up of the patient and the material and service delivered;
The setting up, if necessary, of a follow-up by a nurse or member of the KMT Medical team (e.g., to demonstrate utilization of the product or educate on usage);
Follow up by the KMT’s customer service team (product preference and recommendation);
If necessary, regular monitoring of compliance by the nursing team and, with a view to alerting the attending physician in the event of anomalies;
If necessary, to correct use of the equipment, the possible recall of information, in coordination with the medical team and the medical auxiliaries in charge of the person.
Such processing will be carried out in compliance with the prescription and in accordance with the rules established by the local Healthcare system and Healthcare professional to benefit from the Third-Party Payer.
The absence, incompleteness or inaccuracy of this information is likely to hinder the proper performance of its mission by KMT.
End-user customer data may also processed by KMT Medical for purposes of sending information such as:
Direct marketing such as relevant information on products and services, promotions products and news (including newsletter);
Invitations to events;
Provide information, in pseudonymized form, to healthcare institutions requesting it related to the duration of services rendered by KMT, the products delivered and the identity of the prescribers;
Performance of the video consultation service “Easy Consult” offered to KMT's customers;
Usage of the KMT’s websites including local website from KMT subsidiaries including but not limited to “Navigator” by KMT Medical.
Such processing is carried out based on the express customer’s consent.
KMT Medical aims to ensure that the data it collects is updated throughout processing so that it is not obsolete.
Transfers of Your Personal Data
KMT Medical defines the access and confidentiality rules applicable to the personal data collected and processed. Only duly authorized recipients may access, within the framework of an access management policy, the personal data collected which is necessary for their activity.
The data collected and processed by KMT are not intended to be transferred or sold to third parties.
We may transfer your Personal Data to the following recipients for the purposes of:
Keeping you informed about KMT Medical’s products or services you may be interested in;
Participating in KMT Medical’s feedback programs, such as surveys, product or service evaluations, and/or clinical trial activities;
To other entities within the KMT Medical Incorporated group of companies. Such entities may be located in another country for which the European Commission has not issued a decision that this country ensures an adequate level of data protection, namely: the United States or the locations of non-EEA KMT Medical group companies. We may transfer your personal data to these recipients for the legitimate interests of KMT Medical (pursuant to Art. 6 (1) (f) GDPR) to facilitate global operations in connection with the systems and services that the KMT Medical group of companies share, such as access to network servers, IT systems, and interdepartmental staff. A list of such companies can be found here: https://www.kmtmedical.com/business-units
To third-party service providers who process data on KMT Medical’s behalf as necessary for the provision of products and services, including IT service providers, such as salesforce.com and SAP, for the purpose of administering the software on which KMT Medical systems and network operate, noting that our third party service providers and partners are contractually obligated to process such data on behalf of KMT Medical under appropriate instructions as necessary for the respective processing purposes and to appropriately protect your personal data. They may not otherwise process or share your personal data, except as permitted by law;
To governmental authorities, courts, external advisors, and similar third parties as required or permitted by applicable law if we have reason to believe that disclosing personal data is necessary to identify, contact, or bring legal action against someone who may be causing fraud or injury to or interference with (either intentionally or unintentionally) our rights or property, other Website users or anyone else who could be harmed by such activities. We also disclose personal data in response to a subpoena, warrant or other court or administrative order, or when we believe in good faith that a law, regulation, subpoena, warrant or other court or administrative order requires – or authorizes us to do so – or to respond to an emergency situation. The legal basis for such data transfers are our legitimate interests identified above (pursuant to Art. 6 (1) (f) GDPR) and to comply with legal obligations (pursuant to Art. 6 (1) (c) GDPR).
In all cases, we limit the personal data which is provided to these third parties to only that which is necessary and as otherwise restricted by application of the GDPR and other relevant local law. Some of the recipients of your personal data will be located or have relevant operations outside of your country and the EEA, where the data protection laws may provide a different level of protection compared to the laws in your jurisdiction and with regard to which an adequacy decision by the European Commission does not exist. By way of entering into appropriate data transfer agreements based on Standard Contractual Clauses (2010/87/EU and/or 2004/915/EC) as referred to in Art. 46 (5) GDPR or other adequate means, which may be requested via the contact details below, we will implement appropriate measures to ensure that all other recipients located outside the EEA will provide an adequate level of data protection and that appropriate technical and organizational security measures are in place to protect your personal data against accidental or unlawful destruction, accidental loss or alteration, unauthorized disclosure or access, and against all other unlawful forms of processing.
Your personal data is stored by KMT Medical and/or our service providers to the extent necessary for the performance of our obligations and for the time necessary to achieve the purposes for which the personal data is collected, in accordance with applicable data protection laws and our robust internal data retention schedules.
When KMT Medical/its affiliates no longer need to process your personal data, we will delete it from our systems and/or records and/or take steps to properly anonymize it so that you can no longer be identified from it, unless we need to keep your personal data to comply with legal or regulatory obligations to which KMT Medical is subject.
KMT ensures the security of information systems and the confidentiality of personal data collected.
KMT shall determine and implement the technical and organizational means necessary to protect the personal data processed, to prevent any access by unauthorized third parties and to prevent any loss, alteration or disclosure of data.
Under the GDPR, you have the following statutory rights which you can exercise vis-à-vis KMT Medical, subject to the conditions set forth in applicable law.
Right of access: Pursuant to Art. 15 GDPR, you have the right to obtain from us confirmation as to whether or not personal data concerning you is being processed, and, where that is the case, to request access to the Personal Data. You have the right to obtain a copy of the Personal Data undergoing processing.
Right to rectification: Pursuant to Art. 16 GDPR, you have the right to obtain from us the rectification of inaccurate personal data concerning you. Depending on the purposes of the processing, you have the right to have incomplete Personal Data completed.
Right to erasure (right to be forgotten): Pursuant to Art. 17 GDPR, you have the right to ask us to erase your personal data.
Right to restriction of processing: Pursuant to Art. 18 GDPR, you have the right to restrict our processing your personal data in certain circumstances.
Right to data portability: Pursuant to Art. 20 GDPR, you have the right to receive the personal data concerning you which you have provided to us in a structured, commonly used and machine-readable format and you have the right to transmit those personal data to another entity without hindrance from us.
Right to object: Pursuant to Art. 21 GDPR, you have the right to object, on grounds relating to your particular situation, or where personal data are processed for direct marketing purposes at any time to the processing of your personal data by us and we can be required to no longer process your personal data. Note that such a right to object may not exist, in particular, if the processing of your personal data is necessary to take steps prior to entering into a contract or to perform a contract already concluded.
To exercise any of the above rights, please contact us at the contact information listed.
In case of complaints, you also have the right to lodge a complaint with the competent supervisory authority, in particular in the Member State of your habitual residence or alleged infringement of the applicable data protection law.
This Global Privacy/Data Protection Notice was last updated on 15 April 2021.
KMT Medical Incorporated reserves the right to update this notice at any time. Your continued use of our website, mobile app, products and services constitutes your acceptance of these changes.
© 2021 KMT Medical Incorporated.
The KMT Medical Logo is a trademark of KMT Medical Incorporated.
All other trademarks and copyrights are the property of their respective owners.