Intern Privacyverklaring voor de mobiele app „HARTMANN Easy“

Stand: 10 augustus 2026

Wij, N.V. PAUL HARTMANN S.A., hechten het grootste belang aan de bescherming van uw persoonsgegevens. Neem alstublieft de tijd om dit privacybeleid zorgvuldig door te lezen. Dit privacybeleid informeert u overeenkomstig de Algemene Verordening Gegevensbescherming (AVG). Voor een goed begrip is het van cruciaal belang om onze verschillende rollen te kennen:

  1. HARTMANN als verwerkingsverantwoordelijke (voor uw gebruikersgegevens): Wij zijn verwerkingsverantwoordelijke voor uw eigen persoonsgegevens als gebruiker (bijv. uw naam, e-mailadres, wachtwoord voor het gebruikersaccount). Alle paragrafen van deze verklaring (met name C.1-C.4, C.7, D, E, F, G, H) hebben uitsluitend betrekking op deze gegevensverwerking, waarbij wij de verwerkingsverantwoordelijke zijn. Dit geldt uitdrukkelijk ook voor de in paragraaf D beschreven toegang tot uw eindapparaat (artikel 10/2 van de Belgische wet van 30 juli 2018 betreffende de bescherming van natuurlijke personen met betrekking tot de verwerking van persoonsgegevens), die uitsluitend betrekking heeft op uw apparaat als gebruiker (bijv. uw diensts-smartphone).
  2. HARTMANN als verwerker (voor patiëntgegevens): Zodra u in de modules „Care Plan“ of „Wound Documentation “ patiëntgegevens invoert, treedt u of uw instelling op als verwerkingsverantwoordelijke. Wij treden dan uitsluitend op als uw verwerkingsverantwoordelijke die aan uw instructies gebonden is. In de paragrafen C.5 en C.6 wordt op transparante wijze onze rol als verwerkingsverantwoordelijke en de daarmee samenhangende instructies (bijvoorbeeld met betrekking tot anonimisering) beschreven.

Gedetailleerde bepalingen inzake de verwerking in opdracht (met name betreffende uw verplichtingen als verwerkingsverantwoordelijke en onze verplichtingen als verwerker) vindt u in de afzonderlijke „Aanvullende privacyverklaringen“ van de betreffende applicaties en in de verwerkersovereenkomst (DPA) die uw instelling met ons sluit.

A. Algemene informatie en definities

Onder „persoonsgegevens“ wordt volgens de Algemene Verordening Gegevensbescherming (AVG) alle informatie verstaan die betrekking heeft op een geïdentificeerde of identificeerbare natuurlijke persoon. Dit omvat gegevens zoals uw naam, uw e-mailadres of uw gebruikersgedrag.

Wij houden ons strikt aan de geldende voorschriften inzake gegevensbescherming en beschermen uw gegevens door middel van uitgebreide technische en organisatorische maatregelen.

B. Verantwoordelijke en functionaris voor gegevensbescherming

Verantwoordelijk voor de verwerking van uw persoonsgegevens in het kader van de app „HARTMANN Easy“ is N.V. PAUL HARTMANN S.A., Paul Hartmannlaan, 1, 1480 SINT-RENELDE, België, email : info@hartmann.be.

U kunt de functionaris voor gegevensbescherming bereiken via: N.V. PAUL HARTMANN S.A., Avenue Paul Hartmann, 1, 1480 SAINTES, Belgique Email : dataprotection.be@hartmann.info.

Verwerkers: PAUL HARTMANN AG (moedermaatschappij) beheert deze app als centraal technisch platform. Indien u modules gebruikt waarvan de inhoud wordt aangeboden door lokale dochterondernemingen van PAUL HARTMANN (bijvoorbeeld de HARTMANN-onderneming in uw land), verwerkt PAUL HARTMANN AG uw gebruikersgegevens als technische dienstverlener (verwerker) in opdracht van deze dochterondernemingen. Wij blijven echter uw centrale aanspreekpunt voor uw gegevensbeschermingsrechten met betrekking tot het gebruik van de app.

C. Verwerking van uw persoonsgegevens bij gebruik van de app

De omvang en de aard van de gegevensverwerking zijn afhankelijk van de manier waarop u onze app gebruikt. Om de transparantie op mobiele apparaten te vergroten, volgt deze verklaring de aanbevolen zogenoemde ‘meerlagige aanpak („Layered Approach“), waarbij u door de kopjes te selecteren naar de voor u relevante paragrafen kunt navigeren.

1. Het downloaden van de app uit een app-store

Al bij het bezoeken van onze app-pagina in de betreffende app-store (bijv. Apple App Store of Google Play Store) en bij het downloaden van de app wordt bepaalde informatie verwerkt door de exploitant van de app-store. Dit omvat gedetailleerde statistische gegevens voor het meten van het bereik (zoals bijvoorbeeld bezoeken aan de productpagina, vertoningen, bezoekers van de vermelding in de store en eerste downloads op een nieuw apparaat), evenals persoonsgegevens zoals uw gebruikersnaam, uw e-mailadres, het klantnummer van uw account, het tijdstip van de download en, indien van toepassing, betalingsgegevens.

Wij hebben geen invloed op deze gegevensverzameling en -verwerking; deze valt uitsluitend onder de verantwoordelijkheid van de betreffende app-store-exploitant (Apple of Google), die hierbij optreedt als zelfstandige verwerkingsverantwoordelijke in de zin van de wetgeving inzake gegevensbescherming. Wij ontvangen van de store-exploitanten uitsluitend geaggregeerde, geanonimiseerde statistische analyses over het bereik en de prestaties van onze app, waaruit wij geen conclusies over uw persoon kunnen trekken. Raadpleeg voor meer informatie over de gegevensverwerking in de stores de privacyverklaringen van Apple of Google.

2. Technisch noodzakelijke gegevensverwerking bij het opstarten van de app

Bij elk gebruik van de app verwerken wij om technische redenen automatisch gegevens die uw eindapparaat naar onze servers verzendt. Deze gegevens zijn absoluut noodzakelijk om de stabiliteit, lokalisatie en veiligheid van de app te waarborgen.

  • IP-adres
  • Datum en tijdstip van de verzoek
  • Apparaat-ID (bijv. IMEI, IMSI)
  • Naam van uw mobiele apparaat
  • Besturingssysteem en de versie daarvan
  • Taal en versie van de app

De rechtsgrondslag voor deze verwerking is ons gerechtvaardigd belang bij het aanbieden van een goed functionerende en veilige app overeenkomstig art. 6, lid 1, zin 1, onder f) van de AVG.

Om de IT-beveiliging te waarborgen, cyberaanvallen af te weren (bijv. brute-force-aanvallen op gebruikersaccounts) en technische fouten op te lossen (debugging), verzamelen we bovendien aan de serverzijde beveiligingsrelevante loggegevens, zoals met name mislukte registratie- en inlogpogingen (Failed Registrations) in onze modules. Deze gegevensverwerking is absoluut noodzakelijk voor het handhaven van de systeemintegriteit en de vertrouwelijkheid van uw gegevens. Zij is gebaseerd op ons gerechtvaardigd belang bij het waarborgen van de netwerk- en informatiebeveiliging overeenkomstig artikel 6, lid 1, zin 1, onder f), van de AVG in combinatie met de uitzonderingsbepaling van artikel 10/2 van de Belgische wet van 30 juli 2018 betreffende de bescherming van natuurlijke personen met betrekking tot de verwerking van persoonsgegevens.

3. Registratie en beheer van uw gebruikersaccount

Voor het gebruik van de app is het aanmaken van een gebruikersaccount vereist. Afhankelijk van of u al bij ons als contactpersoon geregistreerd staat, onderscheiden we twee registratiemethoden. De verwerking van de daarbij verzamelde gegevens dient voor het aanmaken en beheren van uw account, uw authenticatie en het mogelijk maken van het gebruik van de app. De rechtsgrondslag voor deze verwerking is de uitvoering van de gebruiksovereenkomst overeenkomstig artikel 6, lid 1, zin 1, onder b) van de AVG.

Afhankelijk van de registratiemethode worden de volgende gegevens verwerkt:

  1. Gastregistratie (voor nieuwe gebruikers): Bij de registratie als nieuwe gebruiker vragen wij u om de volgende verplichte gegevens: uw aanspreektitel, uw voor- en achternaam (voor eenduidige identificatie en accountbeheer), uw e-mailadres (als uniek identificatienummer, voor communicatie en het inloggen), uw land (voor landspecifieke inhoud/regelgeving), de naam van uw instelling, uw postcode en uw branche (telkens voor toewijzing aan de contractpartner en voor B2B-verificatie). Optioneel kunt u uw beroep (professie) opgeven. Eveneens optioneel is het opgeven van uw HCP/AHPRA/NPI-nummer. De rechtsgrondslag voor de verplichte gegevens is art. 6, lid 1, onder b) AVG; voor landspecifieke verplichte gegevens kan de rechtsgrondslag bovendien voortvloeien uit art. 6, lid 1, onder c) of f) AVG.
  2. Registratie van contactpersonen (voor bestaande contactpersonen): Als u al in ons CRM-systeem bent geregistreerd, vragen wij bij de registratie de volgende verplichte gegevens: uw HARTMANN CRM-ID (om deze aan het bestaande klantenaccount te koppelen), uw voor- en achternaam (voor vergelijking en verificatie), uw e-mailadres (als unieke identificatie, voor communicatie en het inloggen), uw aanspreektitel (om u persoonlijk aan te spreken) en uw beroep (ter verificatie van de beroepsgroep). De rechtsgrondslag voor deze verwerking is eveneens art. 6, lid 1, onder b) AVG.

    Als u al een gebruikersaccount hebt voor het HARTMANN-zorgbeheer, kunt u deze gebruiken om in te loggen in de app. In dat geval worden de gegevens die nodig zijn voor verificatie en koppeling (met name naam, e-mailadres en klantnummer) tussen de systemen uitgewisseld.

4. Gegevensverwerking voor het genereren van leads (modules „Inco Guide“ & „Wound Guide“)

Bij de registratie voor de gratis modules „Inco Guide“ en „Wound Guide“ heeft u de mogelijkheid om ons uw vrijwillige toestemming te geven om uw contactgegevens (voornaam, achternaam, e-mailadres, functietitel) voor marketingdoeleinden te gebruiken. Deze toestemming is afzonderlijk en vrijwillig. Het gebruik van de modules is niet afhankelijk van het verlenen van toestemming. De toestemming omvat: - De overdracht van uw gegevens naar ons CRM-systeem (Salesforce) voor het beheer van contacten met geïnteresseerden. - Het per e-mail contact met u opnemen met informatie over onze producten, diensten en evenementen. Om er zeker van te zijn dat u de e-mails daadwerkelijk wilt ontvangen, maken we gebruik van de double-opt-in-procedure: na uw toestemming ontvangt u een e-mail met een bevestigingslink. Pas nadat u op deze link hebt geklikt, wordt u toegevoegd aan onze mailinglijst. U kunt uw toestemming te allen tijde en zonder opgave van redenen voor de toekomst intrekken, bijvoorbeeld via de afmeldlink in elke e-mail of via uw accountinstellingen in de app. De intrekking heeft geen invloed op de rechtmatigheid van de verwerking die tot dan toe heeft plaatsgevonden. De rechtsgrondslag is uw uitdrukkelijke toestemming overeenkomstig art. 6, lid 1, zin 1, onder a) van de AVG en aan art. XII.13, § 1, van het Belgische Wetboek van Economisch Recht..

5. Verwerking van gezondheidsgegevens (modules „Care Plan“ & „Wound Documentation “)

5.1. Rolverdeling: De modules „Care Plan“ en „Wound Documentation “ stellen u als zorgverlener in staat om gezondheidsgegevens van derden (patiënten) te verwerken. Het gaat hierbij om bijzondere categorieën persoonsgegevens in de zin van artikel 9 AVG. Bij het gebruik van deze modules treedt u (of uw werkgever) op als verwerkingsverantwoordelijke in de zin van artikel 4, punt 7, van de AVG. Wij, als aanbieder van de app, treden in deze context uitsluitend op als een aan instructies gebonden verwerker in de zin van artikel 4, punt 8, van de AVG, op basis van een verwerkersovereenkomst (artikel 28 van de AVG) met uw instelling. Details hierover worden geregeld in de aanvullende privacyverklaring.

5.2. Rechtsgrondslag voor de verwerking als verwerker: Wij verwerken de door u ingevoerde patiëntgegevens uitsluitend op basis van een met u gesloten verwerkersovereenkomst (AVV) overeenkomstig artikel 28 AVG. Deze overeenkomst regelt in detail onze verplichtingen als dienstverlener en waarborgt dat de verwerking uitsluitend volgens uw instructies plaatsvindt. Het gebruik van deze modules vereist dat uw beheerder vooraf elektronisch een verwerkersovereenkomst (DPA) met ons heeft gesloten door middel van elektronische aanvaarding (Click & Wrap). Zonder DPA is gebruik niet toegestaan. Geanonimiseerde gebruiksgegevens mogen door dochter- en moedermaatschappijen worden gebruikt voor productverbetering, onderzoek en ontwikkeling. De gebruiker geeft hierbij aan de in punt 12.2 van de Algemene Voorwaarden genoemde onderneming de opdracht om patiëntgegevens uitsluitend te anonimiseren op basis van een door hem te waarborgen rechtsgrondslag (in het bijzonder de toestemming van de patiënten). Pas nadat de anonimisering heeft plaatsgevonden, mogen deze gegevens door dochter- en/of moedermaatschappijen worden gebruikt voor onderzoek, productverbetering en ontwikkeling.

5.3. Uw verplichtingen als verwerkingsverantwoordelijke: U bent als gebruiker als enige verantwoordelijk voor het waarborgen van een geldige rechtsgrondslag voor de door u uitgevoerde verwerking van de patiëntgegevens. Dit zal in de regel de uitdrukkelijke toestemming van de betreffende patiënt zijn overeenkomstig art. 9, lid 2, onder a) van de AVG. Het verkrijgen van deze toestemming is uw verantwoordelijkheid. Wij als aanbieder vragen geen toestemming aan uw patiënten.

6. Gegevensverwerking met het oog op anonimisering

Wij hebben het recht om zowel technische gebruiksgegevens als de door u ingevoerde patiëntgegevens te anonimiseren.

Anonimisering van technische en algemene gebruiksgegevens: Wij verwerken puur technische gebruiksgegevens (bijv. gebruikte functies, laadtijden, crashrapporten) op basis van ons gerechtvaardigd belang overeenkomstig artikel 6, lid 1, zin 1, onder f) van de AVG, om deze te anonimiseren. Het anonimiseringsproces is erop gericht de koppeling aan een persoon blijvend en onomkeerbaar op te heffen.

Anonimisering van patiëntgegevens: Voor zover patiëntgegevens worden geanonimiseerd, gebeurt dit uitsluitend in het kader van de verwerking in opdracht en op uw instructie. De geanonimiseerde gegevens mogen door de aan de HARTMANN-groep behorende ondernemingen worden gebruikt voor onderzoeks- en ontwikkelingsdoeleinden.

7. Contact opnemen en ondersteuning

Wanneer u per e-mail of via een contactformulier contact met ons opneemt, slaan wij de door u verstrekte gegevens (bijv. e-mailadres, naam, inhoud van het verzoek) op om uw verzoek te kunnen afhandelen. Deze gegevens worden gewist zodra de opslag niet langer noodzakelijk is, tenzij er wettelijke bewaarplichten gelden. De rechtsgrondslag is art. 6, lid 1, zin 1, onder b) of f) van de AVG.

D. Toegang tot functies van uw eindapparaat (artikel 10/2 van de Belgische wet van 30 juli 2018 betreffende de bescherming van natuurlijke personen met betrekking tot de verwerking van persoonsgegevens)

Voor de werking van de app is het in sommige gevallen noodzakelijk om informatie op uw eindapparaat op te slaan of hiertoe toegang te verkrijgen. Dit gebeurt in overeenstemming met artikel 10/2 van de Belgische wet van 30 juli 2018 betreffende de bescherming van natuurlijke personen met betrekking tot de verwerking van persoonsgegevens.

1. Absoluut noodzakelijke toegang (zonder toestemming): Bepaalde vormen van toegang zijn absoluut noodzakelijk voor het aanbieden van de door u uitdrukkelijk gewenste functies van de app. Hiervoor hebben wij geen toestemming nodig. Dit betreft:

  • Het opslaan van sessiegegevens voor authenticatie na het inloggen.
  • Het opslaan van instellingen (bijv. taal) om de app gebruiksvriendelijk te maken.

2. Toegangen waarvoor toestemming vereist is: Voor alle andere toegangen vragen wij uw uitdrukkelijke toestemming voordat de toegang plaatsvindt. U kunt deze toestemmingen te allen tijde intrekken in de instellingen van uw besturingssysteem of de app. Dit betreft in het bijzonder:

  • Camera/fotogalerij: alleen als u in de module „Wound Documentation “ actief een foto wilt maken of uploaden.
  • Analyse-, tracking- en prestatiegegevens (bijv. Google Firebase Analytics): Om onze app voortdurend te verbeteren, het gebruikersgedrag gedetailleerd te analyseren, fouten te analyseren en inhoud doelgericht aan te sturen, integreren wij trackingtechnologieën en Software Development Kits (SDK’s) van derde partijen, met name Google Firebase Analytics. Hierbij worden uitgebreide interactiegegevens (bijv. navigatiepaden, gebruik van functies zoals de EVA-chatbot of de wondrichtlijnen, registratiegebeurtenissen) en apparaat-ID’s (bijv. mobiele advertentie-ID’s zoals IDFA of GAID) uitgelezen en geëvalueerd.

    Aangezien deze SDK’s actief informatie op uw eindapparaat opslaan of daar toegang toe hebben, vindt het gebruik van deze analyse- en marketingtools uitsluitend plaats na uw voorafgaande, uitdrukkelijke en vrijwillige toestemming via onze in-app-tool voor toestemmingsbeheer. Het weigeren van toestemming heeft geen invloed op de kernfuncties van de app.

    Gedetailleerde informatie over de gebruikte technologieën, de omvang van de verzamelde statistieken, de betrokken derde partijen (inclusief gegevensoverdrachten naar derde landen) en uw mogelijkheden tot intrekking vindt u in ons afzonderlijke beleid inzake app-tracking en -analyse (App Tracking and Analytics Policy). De rechtsgrondslag voor de toegang tot het eindapparaat is artikel 10/2 van de Belgische wet van 30 juli 2018 betreffende de bescherming van natuurlijke personen met betrekking tot de verwerking van persoonsgegevens; voor de daaropvolgende verwerking van de persoonsgegevens is dit art. 6, lid 1, zin 1, onder a), AVG.

Een weigering heeft geen invloed op de kernfunctionaliteit van de app. De rechtsgrondslag voor de toegangen waarvoor toestemming vereist is, is artikel 10/2 van de Belgische wet van 30 juli 2018 betreffende de bescherming van natuurlijke personen met betrekking tot de verwerking van persoonsgegevens in samenhang met art. 6, lid 1, onder a), AVG.

E. Doorgifte van gegevens aan derden en verwerkers

Wij geven uw gegevens alleen door aan derden als dit wettelijk is toegestaan of als u daarvoor toestemming hebt gegeven.

  • Verwerkers: Wij maken gebruik van zorgvuldig geselecteerde dienstverleners (bijv. voor hosting, technisch onderhoud) die gegevens in onze opdracht verwerken. Deze zijn contractueel gebonden aan onze instructies overeenkomstig art. 28 AVG en verplicht tot naleving van strenge normen inzake gegevensbescherming. Onze hostingdienstverlener is Microsoft Azure Cloud in de EU.
  • Salesforce (doorgifte naar derde landen): In het kader van leadgeneratie (zie C.4.) geven wij uw contactgegevens door aan Salesforce, Inc., gevestigd in de VS. Deze doorgifte is juridisch gewaarborgd door:
    1. Het adequaatheidsbesluit van de Europese Commissie voor het EU-VS Data Privacy Framework (art. 45 AVG), waaronder Salesforce is gecertificeerd.
    2. Daarnaast door het afsluiten van standaardcontractbepalingen (art. 46 AVG) als onderdeel van onze overeenkomst met Salesforce, om een blijvend hoog beschermingsniveau te waarborgen.

Wij hebben een gerechtvaardigd belang bij het voortdurend verbeteren van onze producten en diensten, het waarborgen van de veiligheid van onze app en het opstellen van statistische analyses over marktontwikkelingen. Daartoe verwerken wij technische gebruiks- en metagegevens uit uw app-gebruik (bijv. gebruikte functies, laadtijden, apparaatmodel, versie van het besturingssysteem) om deze te anonimiseren.

De rechtsgrondslag voor deze verwerking met het oog op anonimisering is ons gerechtvaardigd belang overeenkomstig art. 6, lid 1, zin 1, onder f) van de AVG. In het kader van de vereiste belangenafweging hebben wij ons ervan vergewist dat uw beschermingswaardige belangen niet zwaarder wegen. Wij gebruiken uitsluitend gepseudonimiseerde gegevens die geen directe terugvoering naar uw persoon mogelijk maken, en nemen uitgebreide technische maatregelen om de gegevensbescherming te waarborgen.

U hebt het recht om te allen tijde bezwaar te maken tegen deze verwerking om redenen die voortvloeien uit uw specifieke situatie (art. 21 AVG).

Na voltooiing van het anonimiseringsproces, dat volgens de stand van de techniek is ontworpen om de koppeling aan een persoon permanent en onomkeerbaar op te heffen, worden de anonieme gegevens ook doorgegeven aan de moedermaatschappij van de groep.

F. Bewaartermijn

Wij bewaren uw persoonsgegevens slechts zo lang als nodig is voor het bereiken van de betreffende doeleinden of zoals voorgeschreven door de wettelijke bewaartermijnen (bijvoorbeeld uit het handels- of belastingrecht). Nadat het doel is bereikt of de termijnen zijn verstreken, worden de gegevens routinematig gewist, tenzij ze nog nodig zijn voor de uitvoering of het aangaan van een overeenkomst. Gegevens uit uw gebruikersaccount worden gewist nadat het account is verwijderd, behoudens wettelijke bewaarplichten.

G. Uw rechten als betrokkene

U hebt ten aanzien van uw persoonsgegevens de volgende rechten ten opzichte van ons:

  • Recht op inzage (art. 15 AVG)
  • Recht op rectificatie (art. 16 AVG)
  • Recht op verwijdering („recht om te worden vergeten“) (art. 17 AVG)
  • Recht op beperking van de verwerking (art. 18 AVG)
  • Recht om bezwaar te maken tegen de verwerking (art. 21 AVG), voor zover de verwerking is gebaseerd op art. 6, lid 1, onder f) AVG.
  • Recht op gegevensoverdraagbaarheid (art. 20 AVG)
  • Recht op intrekking van gegeven toestemmingen (art. 7, lid 3 AVG) met werking voor de toekomst.
  • Recht om een klacht in te dienen bij een toezichthoudende autoriteit voor gegevensbescherming (art. 77 AVG)

Om uw rechten uit te oefenen, kunt u te allen tijde contact met ons of onze functionaris voor gegevensbescherming opnemen.

H. Gegevensbeveiliging

Wij nemen uitgebreide technische en organisatorische beveiligingsmaatregelen (TOM's) volgens de stand van de techniek om uw gegevens te beschermen tegen onopzettelijke of opzettelijke manipulatie, verlies, vernietiging of tegen toegang door onbevoegde personen.

I. Wijziging van deze privacyverklaring

Wij blijven onze app voortdurend verder ontwikkelen. Daarom behouden wij ons het recht voor om deze privacyverklaring indien nodig aan te passen. De actuele versie is te allen tijde binnen de app te raadplegen.

Privacy Policy for the “HARTMANN Easy” Mobile App

We, PAUL HARTMANN AG, place the utmost importance on protecting your personal data. Please take the time to read this Privacy Policy carefully. This Privacy Policy provides you with information in accordance with the General Data Protection Regulation (GDPR). To fully understand this policy, it is essential to be aware of our different roles:

  1. HARTMANN as the data controller (for your user data): We are the data controller for your own personal data as a user (e.g., your name, email address, and password for your user account). All sections of this policy (in particular C.1–C.4, C.7, D, E, F, G, and H) refer exclusively to this data processing, for which we are the data controller. This also expressly applies to the access to your end device described in Section D (§ 25 TDDDG), which concerns exclusively your device as a user (e.g., your smartphone).
  2. HARTMANN as a Data Processor (for patient data): As soon as you enter patient data in the “Care Plan” or “Wound Documentation” modules, you or your institution act as the data controller. We then act exclusively as your data processor, bound by your instructions. Sections C.5 and C.6 transparently describe our role as a data processor and the associated instructions (e.g., regarding anonymization).

Detailed provisions regarding data processing (in particular regarding your obligations as the data controller and our obligations as the data processor) can be found in the separate “Supplementary Privacy Notices” for the respective applications and in the Data Processing Agreement (DPA) that your institution enters into with us.

A. General Information and Definitions

“Personal data,” as defined by the General Data Protection Regulation (GDPR), refers to any information relating to an identified or identifiable natural person. This includes data such as your name, your email address, or your user behavior.
We strictly adhere to applicable data protection regulations and protect your data through comprehensive technical and organizational measures.

B. Data Controller and Data Protection Officer

PAUL HARTMANN AG, Paul-Hartmann-Straße 12, 89522 Heidenheim, email: [info@hartmann.info], is responsible for processing your personal data in connection with the “HARTMANN Easy” app.

You can contact the Data Protection Officer at: PAUL HARTMANN AG, CFO-DPM / DPO Department, Paul-Hartmann-Straße 12, 89522 Heidenheim, email: datenschutz@hartmann.info.

Data Processor: PAUL HARTMANN AG (parent company) operates this app as a central technical platform. If you use modules whose content is provided by local PAUL HARTMANN subsidiaries (e.g., the HARTMANN subsidiary in your country), PAUL HARTMANN AG processes your user data as a technical service provider (data processor) on behalf of these subsidiaries. However, we remain your central point of contact for your data protection rights regarding app usage.

C. Processing of Your Personal Data When Using the App

The scope and nature of data processing depend on how you use our app. To increase transparency on mobile devices, this statement follows the recommended “layered approach,” which allows you to navigate to the sections relevant to you by selecting the headings.

1. Downloading the App from an App Store

Certain information is processed by the app store operator as soon as you access our app listing in the respective app store (e.g., Apple App Store or Google Play Store) and when you download the app. This includes detailed statistical metrics for measuring reach (such as product page views, impressions, visitors to the store listing, and first-time downloads on a new device) as well as personal data such as your username, your email address, your account’s customer number, the time of the download, and, if applicable, payment information.

We have no influence over this data collection and processing; it is the sole responsibility of the respective app store operator (Apple or Google), which acts as an independent data controller under data protection law. We receive only aggregated, anonymized statistical reports from the store operators regarding the reach and performance of our app, which do not allow us to identify you personally. For more information on data processing in the app stores, please refer to the privacy policies of Apple or Google.

2. Technically Necessary Data Processing When Launching the App

Every time you use the app, we automatically process data that your device transmits to our servers for technical reasons. This data is absolutely necessary to ensure the stability, localization, and security of the app.

  • IP address
  • Date and time of the request
  • Device identifier (e.g., IMEI, IMSI)
  • Name of your mobile device
  • Operating system and its version
  • Language and version of the app

The legal basis for this processing is our legitimate interest in providing a functional and secure app in accordance with Article 6(1)(f) of the GDPR.

To ensure IT security, defend against cyberattacks (e.g., brute-force attacks on user accounts), and for technical troubleshooting (debugging), we also collect security-related log data on the server side, such as, in particular, failed registration and login attempts (Failed Registrations) in our modules. This data processing is strictly necessary to maintain system integrity and the confidentiality of your data. It is based on our legitimate interest in ensuring network and information security pursuant to Article 6(1), sentence 1, subparagraph (f) of the GDPR in conjunction with the exception provision of Section 25(2), No. 2 of the TDDDG.

3. Registration and Management of Your User Account

Creating a user account is required to use the app. Depending on whether you are already listed as a contact with us, we distinguish between two registration methods. The data collected during this process is processed for the purpose of creating and managing your account, authenticating you, and enabling your use of the app. The legal basis for this processing is the performance of the user agreement pursuant to Article 6(1), first sentence, letter b) of the GDPR.

Specifically, the following data is processed depending on the registration method:

  1. Guest Registration (for new users): As part of the registration process for new users, we collect the following required information: your title, first and last name (for unique identification and account management), your email address (as a unique identifier, for communication and login), your country (for country-specific content/regulations), the name of your institution, your ZIP code, and your industry (for assignment to the contractual partner and for B2B verification, respectively). You may optionally provide your profession. Providing your HCP/AHPRA/NPI number is also optional. The legal basis for the required information is Article 6(1)(b) of the GDPR; for country-specific mandatory information, the legal basis may additionally be derived from Article 6(1)(c) or (f) of the GDPR.
  2. Contact Registration (for existing contacts): If you are already registered in our CRM system, we collect the following mandatory information for registration: your HARTMANN CRM ID (to link to your existing customer account), your first and last name (for matching and verification), your email address (as a unique identifier, for communication and login), your title (for personalized communication), and your profession (to verify your professional affiliation). The legal basis for this processing is also Article 6(1)(b) of the GDPR.

If you already have a user account for the HARTMANN Supply Management, you can use it to log in to the app. In this case, the data required for verification and linking (specifically, name, email address, and customer number) will be exchanged between the systems.

4. Data Processing for Lead Generation (the “Inco Guide” and “Wound Guide” Modules)

When registering for the free “Inco Guide” and “Wound Guide” modules, you have the option to voluntarily give us your consent to use your contact information (first name, last name, email address, job title) for marketing purposes. This consent is separate and voluntary. Use of the modules is not contingent upon granting this consent. The consent covers: - The transfer of your data to our CRM system (Salesforce) for managing prospect contacts. - Contacting you via email with information about our products, services, and events. To ensure that you actually wish to receive these emails, we use the double opt-in procedure: After you give your consent, you will receive an email with a confirmation link. You will only be added to our mailing list after clicking this link. You may revoke your consent at any time and without providing a reason, effective for the future—for example, via the unsubscribe link in every email or through your account settings in the app. Revocation does not affect the lawfulness of processing carried out up to that point . The legal basis is your explicit consent pursuant to Art. 6(1)(a) of the GDPR.

5. Processing of Health Data (the “Care Plan” and “Wound Documentation” modules)

5.1. Allocation of Roles: The “Care Plan” and “Wound Documentation” modules enable you, as a healthcare professional, to process health data of third parties (patients). This constitutes special categories of personal data within the meaning of Article 9 of the GDPR. When using these modules, you (or your employer) act as the data controller under data protection law within the meaning of Article 4(7) of the GDPR. As the provider of the app, we act in this context exclusively as a data processor bound by instructions within the meaning of Article 4(8) of the GDPR, based on a data processing agreement (Article 28 of the GDPR) with your institution. Details regarding this are set forth in the Supplementary Privacy Notice.

5.2. Legal Basis for Processing as a Data Processor: We process the patient data you enter exclusively on the basis of a Data Processing Agreement (DPA) concluded with you in accordance with Article 28 of the GDPR. This agreement sets forth in detail our obligations as a service provider and ensures that processing takes place only in accordance with your instructions. Use of these modules requires the prior electronic conclusion of a Data Processing Agreement (DPA) by your administrator through electronic acceptance (click-and-wrap) with us. Use is not permitted without a DPA. Subsidiaries and parent companies may use anonymized usage data for the purposes of product improvement, research, and development. The user hereby instructs the company named in Section 12.2 of the Terms and Conditions to anonymize patient data exclusively on the basis of a legal basis to be ensured by the user (in particular, the patients’ consent). Only after anonymization has been completed may this data be used by subsidiaries and/or the parent company for research, product improvement, and development.

5.3. Your Obligations as the Data Controller: As the user, you are solely responsible for ensuring a valid legal basis for your processing of patient data. This will generally be the explicit consent of the respective patient pursuant to Art. 9(2)(a) of the GDPR. It is your responsibility to obtain this consent. We, as the provider, do not obtain consent from your patients.

6. Data Processing for Anonymization

We are authorized to anonymize both technical usage data and the patient data you enter.

Anonymization of technical and general usage data: We process purely technical usage data (e.g., features used, loading times, crash reports) based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR in order to anonymize this data. The anonymization process is designed to permanently and irreversibly remove any personal reference.

Anonymization of patient data: To the extent that patient data is anonymized, this is done exclusively within the scope of data processing on behalf of a client and in accordance with your instructions. The anonymized data may be used by companies belonging to the HARTMANN Group for research and development purposes.

7. Contact and Support

If you contact us via email or through a contact form, we store the data you provide (e.g., email address, name, content of the inquiry) in order to process your request. This data is deleted as soon as storage is no longer necessary, unless there are legal retention requirements. The legal basis is Art. 6(1)(b) or (f) of the GDPR.

D. Access to Functions on Your Device (Section 25 TDDDG)

In some cases, the operation of the app requires storing information on your device or accessing it. This is done in accordance with § 25 TDDDG.

1. Absolutely Necessary Access (Without Consent): Certain types of access are absolutely necessary to provide the app features you have expressly requested. We do not require your consent for this. This applies to:

  • Storing session information for authentication after login.
  • Storing settings (e.g., language) to make the app user-friendly.

2. Access Requiring Consent: For all other access, we obtain your explicit consent before granting access. You can revoke this consent at any time in the settings of your operating system or the app. This applies in particular to:

  • Camera/photo gallery: Only if you actively wish to take or upload a photo in the “Wound Documentation” module.
  • Analytics, tracking, and performance data (e.g., Google Firebase Analytics): To continuously improve our app, conduct detailed analysis of user behavior, perform error analysis, and deliver targeted content, we integrate third-party tracking technologies and software development kits (SDKs), particularly Google Firebase Analytics. In this process, comprehensive interaction data (e.g., navigation paths, use of features such as the EVA chatbot or wound care guides, registration events) as well as device identifiers (e.g., mobile advertising IDs such as IDFA or GAID) are collected and analyzed.

    Since these SDKs actively store information on or access your device, the use of these analytics and marketing tools is subject exclusively to your prior, explicit, and voluntary consent via our in-app consent management tool. Withholding consent has no impact on the app’s core functions.

    Detailed information on the technologies used, the scope of the metrics collected, the third-party providers involved (including data transfers to third countries), and your options for revoking consent can be found in our separate App Tracking and Analytics Policy. The legal basis for accessing the end device is Section 25(1) of the TDDDG; for the subsequent processing of personal data, it is Article 6(1)(a) of the GDPR.

Refusal has no effect on the app’s core functionality. The legal basis for access requiring consent is Section 25(1) of the TDDDG in conjunction with Article 6(1)(a) of the GDPR.

E. Data Transfer to Third Parties and Processors

We will only disclose your data to third parties if this is permitted by law or if you have given your consent.

  • Processors: We use carefully selected service providers (e.g., for hosting and technical maintenance) who process data on our behalf. These providers are contractually bound by our instructions in accordance with Article 28 of the GDPR and are obligated to comply with strict data protection standards. Our hosting provider is Microsoft Azure Cloud in the EU.
  • Salesforce (transfer to a third country): As part of lead generation (see C.4.), we transfer your contact information to Salesforce, Inc., which is headquartered in the United States. This transfer is legally safeguarded by:
    1. The EU Commission’s adequacy decision for the EU-U.S. Data Privacy Framework (Article 45 of the GDPR), under which Salesforce is certified.
    2. Additionally, by entering into Standard Contractual Clauses (Art. 46 GDPR) as part of our contract with Salesforce to ensure a consistently high level of protection.

We have a legitimate interest in continuously improving our products and services, ensuring the security of our app, and compiling statistical analyses of market trends. For this purpose, we process technical usage and metadata from your app usage (e.g., features used, loading times, device model, operating system version) in order to anonymize this data.

The legal basis for this processing for the purpose of anonymization is our legitimate interest pursuant to Art. 6(1)(f) of the GDPR. As part of the required balancing of interests, we have ensured that your interests worthy of protection do not outweigh ours. We use only pseudonymized data that does not allow for direct identification of you, and we take comprehensive technical measures to ensure data protection.

You have the right to object to this processing at any time on grounds relating to your particular situation (Article 21 of the GDPR).

Once the anonymization process—which is designed in accordance with the state of the art to permanently and irreversibly remove any personal reference—is complete, the anonymous data is also transferred to the parent company.

F. Retention Period

We store your personal data only for as long as is necessary to achieve the respective purposes or as required by statutory retention periods (e.g., under commercial or tax law).

Once the purpose has been fulfilled or the retention periods have expired, the data is routinely deleted, provided it is no longer required for the performance or initiation of a contract. Data from your user account is deleted upon deletion of the account, subject to statutory retention obligations.

G. Your Rights as a Data Subject

You have the following rights with respect to your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (“right to be forgotten”) (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to object to processing (Art. 21 GDPR), provided that the processing is based on Art. 6(1)(f) GDPR.
  • Right to data portability (Art. 20 GDPR)
  • Right to withdraw consent (Art. 7(3) of the GDPR) with future effect.
  • Right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR)

To exercise your rights, you may contact us or our Data Protection Officer at any time.

H. Data Security

We implement comprehensive state-of-the-art technical and organizational security measures (TOMs) to protect your data against accidental or intentional manipulation, loss, destruction, or access by unauthorized persons.

I. Changes to This Privacy Policy

We are constantly developing our app. Therefore, we reserve the right to amend this Privacy Policy as needed. The current version is available within the app at any time.