Website data protection statement and at the same time information for data subjects pursuant to Article 13 and Article 14 of the EU General Data Protection Regulation (GDPR)

General information

Company: Wörwag Pharma GmbH & Co. KG
Legal representative: Gerhard Mayer, Jochen Schlindwein
Address: Flugfeld-Allee 24, 71034 Boeblingen, Germany
Contact details for data protection officer: datenschutz@woerwagpharma.com

​​​​​​​This data protection statement also applies to our affiliated companies*, as stated in this document, where applicable.

General data processing information

Wörwag Pharma GmbH & Co. KG takes the protection of your personal information very seriously and strictly adheres to the rules of data privacy laws. Personal information is collected on this website only to the extent that is technically necessary. Information is never sold or forwarded to third parties for any reason. The following statement provides you with an overview of how this protection is ensured, type of information that is collected, and for which purpose.

Affected data

Personal data is only collected if you communicate it to us yourself. Apart from that, no personal data is collected. Any processing of your personal data that goes beyond the scope of the statutory permission is only possible on the basis of your express consent.

Data processing on this website

Wörwag Pharma GmbH & Co. KG collects and automatically saves information in so-called server log files which your browser transmits to us. This includes:

  •  Browser type/version used
  • Operating system used
  • Requested URL
  • Referrer URL (the last page visited)
  • Host name of the accessing computer (IP address)
  • Date and time of the server request

This data cannot be attributed to an individual. This data is not merged with other data sources; in addition, the information is deleted after a statistical evaluation.

Processing purpose
Personalized user experience, user engagement and analytics, website security and integrity, marketing and promotions. 

Legal basis for processing
Consent (Art. 6 (1) a GDPR), legitimate interest (Art. 6 (1) f GDPR).
Categories of recipients

  • Public authorities: Government agencies and regulators when required by law, such as tax authorities, social security institutions, law enforcement agencies, or other regulatory bodies based on applicable legislation.
  • External service providers or other contractors: Companies and individuals contracted to perform services on our behalf, including but not limited to IT service providers, cloud service providers, marketing agencies, consultants, and other professional service providers. These entities are bound by contractual agreements to ensure data protection and confidentiality.
  • Other external bodies: Organizations and entities that may receive personal data with the explicit consent of the data subject or when there is a legitimate interest that justifies the data transfer, such as partner companies, affiliated companies, and research institutions.

Third-country transfers
Processors could also be used outside the European Union.

Duration of data storage
We only store personal data for as long as necessary for the respective purposes or as required by law. The specific deletion periods vary depending on the type of data and the purpose of its processing. After the respective periods have expired, the corresponding data is routinely deleted in accordance with the statutory provisions. 

Use of cookies

Internet sites use so-called cookies in several locations. They serve to make our offering more user-friendly, effective and secure. Cookies are small text files that are stored on your computer and that your browser saves. Most of the cookies we use are so-called "session cookies". They are automatically deleted at the end of your visit. Cookies do not cause damage to your computer and do not contain viruses.

We utilize the Usercentrics Consent Manager to manage user consent for data processing activities on our website. The Usercentrics Consent Manager helps us ensure that we comply with GDPR and other relevant data protection laws by obtaining, storing, and managing user consents for the use of cookies and other tracking technologies. That allows ensuring that we have a valid legal basis for processing personal data. The service is offered by Usercentrics GmbH, Sendlinger Str. 7, 80331 Munich, Germany. For privacy-related matters, you can contact Usercentrics via their support at https://usercentrics.com/contact/ or through the contact form on their website. For more information on how Usercentrics handles personal data, please refer to their privacy policy at https://usercentrics.com/privacy-policy/

When you visit our website, the Usercentrics Consent Manager will present you with a consent banner. This banner provides information about the types of cookies and tracking technologies we use and requests your consent to use them. Your consent preferences are stored securely and can be accessed at any time through the consent management interface on our website. The Usercentrics Consent Manager allows you to manage and adjust your consent settings, including giving or withdrawing consent for specific categories of cookies and tracking technologies. 

Use of Google Tag Manager

We utilize the Google Tag Manager to manage and deploy marketing tags (snippets of code or tracking pixels) on our website without having to modify the code. The Google Tag Manager helps us ensure efficient management of our marketing tools and analytics services as well as complying with GDPR and other relevant data protection laws by enabling us to control and manage the deployment of tags that collect personal data and require user consent. The service is offered by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. For privacy-related matters, you can contact Google via their support at support.google.com or through the contact form on their website. For more information on how Google handles personal data, please refer to their privacy policy at https://policies.google.com/privacy.

The Google Tag Manager allows us to add and update tags on our website quickly and easily. Tags are used to measure traffic and visitor behavior, understand the impact of online advertising and social channels, use remarketing and audience targeting, as well as test and improve our site. The Google Tag Manager itself does not collect any personal data. It triggers other tags, which may collect data. Any data collected is processed by the respective service provider. Each of such tags is stated in this data protection statement.  These tags will only be triggered if you have provided the necessary consent through our consent management tool (please see above). 

You have the right to manage your consent preferences at any time. You can access the consent management interface on our website to view or change your settings. Additionally, you have the right to withdraw your consent for the processing of your personal data collected through tags managed by the Google Tag Manager.

The Google Custom Search Engine is used as the central search service within the Internet offering of Wörwag Pharma GmbH & Co. KG. The integrated search service enables full text searching of the contents of Wörwag Pharma GmbH & Co. KG's internet offering. This search function can be accessed via an integrated search field. The search field on this website ("Search Field") is provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA, 94043, USA ("Google"). You acknowledge and agree that the data privacy terms from Google (at http://www.google.de/privacy.html) apply for your use of the Search Field and that, by using the Search Field, you agree to Google's use of your personal information according to its data privacy terms.

If you do not wish to grant this approval, please do not use the Search Field. Data are only transmitted when a query is sent via the Search Field.

Use of Google Maps

We use Google Maps on sub-pages at our site to display maps. Google Maps is operated by Google. Information about use of this website, including your IP address, may be transmitted to Google as a result of the use of Google Maps. 

When you visit a sub-page of our site which contains Google Maps, your browser establishes a direct connection to Google's servers. The content of the map is transmitted from Google directly to your browser, which integrates it into the webpage. Consequently, we have no influence on the scope of the data Google acquires by this method.

For the purpose and extent of the data collection and further processing and use of the information by Google, as well as your rights and setting options for protecting your privacy in this regard, please see Google's data privacy policy at https://www.google.com/policies/privacy/.

The terms of use for Google Maps can be found at https://www.google.com/intl/en/help/terms_maps.html.

Use of Google Web Fonts

For a uniform presentation of typefaces, this site uses so-called web fonts supplied by Google. When a site is called up, your browser loads the needed web fonts into your browser cache so that texts and typefaces are displayed correctly.

The browser you use must connect with the servers of Google for this purpose. Through this, Google learns that our website was called up through your IP address. Google web fonts are used in the interest of a uniform and appealing presentation of our online offerings. The data processing is based on the user's consent according to Art. 6 (1) a GDPR. If your browser does not support web fonts, a standard font is used by your computer.

You can find further information on Google web fonts at https://developers.google.com/fonts/faq?hl=en and in the privacy policy of Google at https://www.google.com/policies/privacy/.
 

Use of YouTube plugins (videos)

We use the provider YouTube for integration of videos. YouTube is operated by YouTube LLC, headquartered at 901 Cherry Avenue, San Bruno, CA 94066, USA (“YouTube LLC”). YouTube is represented by Google.

When you retrieve sub-pages of our site which contain this plugin, a connection is established to the YouTube servers and the plugin is displayed. This transmits information to the YouTube servers regarding the websites you have visited. If you are logged in as a YouTube user, YouTube attributes this information to your personal user account. During use of the plugin, such as by clicking the start button of a video, this information is also attributed to your user account. You can prevent this attribution by logging out of your YouTube user account and other accounts from YouTube LLC and Google before using our website and by deleting corresponding cookies.

Additional information on data processing and data privacy notices from YouTube/Google can be found at www.google.de/intl/de/policies/privacy/.

Use of Google Analytics

Our site utilizes Google Analytics, a web analysis service of Google. Google Analytics uses cookies (as described above).  Information generated by cookies about your use of this website is normally transferred to a Google server in the USA and saved there. In case of activation of IP anonymization on this website, however, your IP address is first truncated by Google within member states of the European Union or in other contracting member states of the European Economic Area. Only in exceptional cases is the full IP address transferred to a Google server in the USA and truncated there. 

Google utilizes this information on behalf of the operator of this website in order to evaluate your usage of this website, to compile reports on website activity for the website operator and to perform additional services connected with use of the website and the Internet in respect of the website operator. 

The IP address transmitted by your browser in connection with Google Analytics is not combined with other data from Google. You can prevent the saving of cookies by a corresponding setting in your browser software. Note that in this case, you may not be able to fully utilize all functions of this website. 

You can furthermore prevent the capturing of the data generated by the cookie and based on your usage of the website (incl. your IP address) to Google as well as the processing of this data by Google by downloading and installing the browser plugin available at the following link (http://tools.google.com/dlpage/gaoptout?hl=en). 

In light of the discussion surrounding the use of analysis tools with complete IP addresses, we would like to point out that this website uses Google Analytics with the "_anonymizeIp()" extension and therefore IP addresses are only forwarded in a truncated manner in order to prevent them from being linked to individuals. 

Specifically for browsers on mobile devices, please click this link in order to prevent the anonymous capture by Google Analytics on this website for your browser in the future, by means of a so-called "opt-out cookie."

Use of Google reCAPTCHA

Our site utilizes Google reCAPTCHA, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The primary purpose of reCAPTCHA is to determine whether the data entry on our website (e.g., in a contact form) is being made by a human or by an automated program. To this end, reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. This analysis starts automatically as soon as the website visitor enters the site. For the analysis, reCAPTCHA evaluates various information (e.g., IP address, how long the visitor has been on the website, or mouse movements made by the user). The data collected during the analysis will be forwarded to Google.

The reCAPTCHA analyses take place completely in the background. Website visitors are not advised that such an analysis is taking place. The data processing is based on the user's consent according to Art. 6(1) a GDPR. For more information about Google reCAPTCHA and Google's privacy policy, please visit the following links:

By using reCAPTCHA, data may be transmitted to a Google server in the USA and stored there. Google will use this information on behalf of the operator of this website to analyze your use of this service. The IP address transmitted by your browser as part of reCAPTCHA will not be merged with other data from Google.

You can prevent the data generated by reCAPTCHA and related to your use of the website (including your IP address) from being collected and processed by Google by not using the service. Note that if you choose to not use reCAPTCHA, certain functions on this website may not be available or may be limited.

By using our website and by providing your consent, you agree to the processing of data about you by Google in the manner and for the purposes set out above.

Use of Social Media Channels

Facebook

Facebook Page and Responsibility: we operate a Facebook page to communicate with prospects and customers and to inform about our services. In this context, we process personal data together with Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland ("Facebook"), in accordance with Art. 26 GDPR within the framework of a so-called joint controllership.

Data processing by Facebook: when you visit our Facebook page, personal data of users is collected by Facebook, e.g. through cookies or similar technologies. This data collection takes place regardless of whether the user has a Facebook account or not. The data collected includes, but is not limited to, IP address, browser data, location information and other information that Facebook collects in the course of using its services.

Purpose of processing: data processing by Facebook is carried out for market research and advertising purposes as well as for the creation of user profiles. On the basis of these profiles, Facebook can play out targeted advertising inside and outside the platform. We receive statistical evaluations (so-called "Facebook Insights") from Facebook that help us to analyze usage behavior on our page. However, these evaluations do not contain any information that allows conclusions to be drawn about individual users.

Legal basis: the use of our Facebook page and the associated data processing by Facebook is based on our legitimate interest in accordance with Art. 6 (1) f GDPR to communicate with users and to present our offer via social media.

Data processing by us: we ourselves do not process any personal data that goes beyond the use of our Facebook page. We only receive aggregated and anonymized data in the form of statistics.

Rights of data subjects: users can assert their data protection rights (e.g. right to information, deletion or objection) against us as well as against Facebook. For information on the processing and Facebook's privacy policy, please refer to Facebook's privacy statement at www.facebook.com/privacy/explanation.

If you have any questions or would like to exercise your rights with regard to the processing of your personal data by us, please do not hesitate to contact us.

Instagram

Instagram Profile and Responsibility: we operate an Instagram profile to communicate with prospects and customers and to inform about our services and activities. In this context, we process personal data together with Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland ("Instagram"), on the basis of joint controllership in accordance with Art. 26 GDPR.

Data processing by Instagram: when you visit our Instagram profile, Instagram processes users' personal data, e.g. through cookies or similar technologies. This data collection takes place regardless of whether you are logged in to Instagram or have an account. The data collected includes, but is not limited to, IP address, browser data, location information and other information that Instagram collects in the course of using its services.

Purpose of processing: data processing by Instagram is carried out for market research, advertising and analysis purposes. Instagram uses the data collected to create user profiles to display targeted advertising, both on the platform and beyond. We receive aggregated statistics from Instagram about the use of our profile in order to understand user behavior and optimize our content. However, these statistics do not include personal data of individual users.

Legal basis: the data processing is carried out on the basis of our legitimate interest in accordance with Art. 6 (1) f GDPR to interact with users and offer our services via social media.

Data processing by us: we ourselves do not process any personal data of Instagram users that goes beyond the use of our Instagram profile. The statistics we receive are anonymized and do not allow conclusions to be drawn about individual users.

Rights of data subjects: users can assert their rights with regard to the processing of their personal data both against us and against Instagram. Further information on data processing by Instagram and data protection rights can be found in the Instagram privacy policy at help.instagram.com/519522125107875.

If you have any questions or would like to exercise your rights with regard to the processing of your personal data by us, please do not hesitate to contact us.

Information about other data processing procedures

Specific information about the application process

Affected data and legal basis for processing: Application information (e.g., name, address, email, telephone number, educational background, employment history, and any other information included in a CV or cover letter or communicated to us by you directly or by authorized third parties). The personal data collected as part of the application process is processed for the implementation of pre-contractual measures in accordance with Art. 6 (1) b GDPR. In Germany, processing is also carried out in accordance with § 26 Federal Data Protection Act (BDSG).
Processing Purpose: Implementation of application process.
Categories of recipients: Public authorities in the event of priority legislation.
External service providers or other contractors, e.g., for data processing and hosting. 
Our affiliated companies in case of consideration and/or search for suitable positions within Wörwag Pharma Group.
Third-country transfers: As part of contractual execution, processors could also be used outside the European Union, e. g. email provider. Besides, our affiliated countries outside of European Union as described above.
Duration of data storage: Application data will generally be deleted within six months after the end of application process (§ 26 BDSG and § 15 Abs. 4 General Act on Equal Treatment (AGG).

 

Specific information for the processing of customer data/prospective parties’ data

Affected data and legal basis for processing: Data communicated for contract execution (e.g., name, email) (Art. 6 (1) b GDPR); if necessary, additional data for processing on the basis of your express consent (Art. 6 (1) a GDPR).
Processing Purpose: Execution and effective management of contracts, including making offers, processing orders, conducting sales transactions, incl. delivery creation, issuing invoices, and ensuring quality. It also supports the continuous optimization of these processes to enhance our efficiency. 
Categories of recipients: Public authorities in the event of priority legislation.
External service providers or other contractors, e. g. for data processing and hosting, shipment, transport and logistics, service providers for print and dispatch of information, call center.
Other external bodies may access personal data upon the data subject's consent or when necessary due to a prevailing interest. Examples include conducting credit checks for purchases made on invoice, electronically distributing information, and enhancing our processes through quality assurance measures.
Third-country transfers: As part of contractual execution, processors could also be used outside the European Union, e. g. email provider.
Duration of data storage: The duration of data storage depends on the statutory storage requirements and is usually 10 years (§ 147 Fiscal Code (AO) und § 257 Commercial Code (HGB)).

 

Specific information for the processing of supplier data

Affected data and legal basis for processing: Data communicated for contract execution (e.g., name, email) (Art. 6 (1) b GDPR); if necessary, additional data for processing on the basis of your express consent (Art. 6 (1) a GDPR).
Processing Purpose: Execution and effective management of contracts, including processing requests, purchasing, and ensuring quality. It also supports the continuous optimization of these processes to enhance our efficiency. 
Categories of recipients: Public authorities in the event of priority legislation, e. g. finance authority, customs. 
External service providers or other contractors, e. g. for data processing and hosting, accounting, payment processing. 
Other external bodies in so far as the data subject has given his/her consent or a transmission is permitted due to a prevailing interest.
Third-country transfers: As part of contractual execution, processors could also be used outside the European Union, e.g., email provider. 
Duration of data storage: The duration of data storage depends on the statutory storage requirements and is usually 10 years (§ 147 AO and § 257 HGB).

 

Specific information for the processing of scientific experts/opinion leaders data

Affected data and legal basis for processing: Information available in public space, data communicated for contract execution (Art. 6 (1) b GDPR) or personal data available in a professional context; if necessary, additional data for processing on the basis of express consent (Art. 6 (1) a GDPR) (medical/scientific speciality, specializations, areas of expertise and interest, spoken languages, active participation in international professional events, activities in clinical trials, patient care, expert opinion writing, information about lecturing activities, memberships in medical-scientific societies and guideline committees, other professional contact data).
Processing Purpose: Contacting and addressing the most relevant scientific experts for projects, execution and effective management of contracts.
Categories of recipients: Public authorities in the event of priority legislation, e. g. finance authority. 
External service providers or other contractors, e. g. for data processing and hosting, accounting, payment processing. 
Other external bodies in so far as the data subject has given his/her consent or a transmission is permitted due to a prevailing interest.
Third-country transfers: As part of contractual execution, processors could also be used outside the European Union, e.g., email provider. 
Duration of data storage: The duration of data storage depends on the statutory storage requirements and is usually 10 years (§ 147 AO and § 257 HGB).

 

Specific information for the processing of medical information inquiries and quality complaints

Affected data and legal basis for processing: Data (e.g., name, address, email, telephone number, medical history) communicated to us by you directly or by authorized third parties based on your consent through:

  • Contact form on our website
  • Per telephone
  • Per E-Mail
  • Social media channels (e.g., Xing, LinkedIn, YouTube)

If necessary, additional data for processing on the basis of your express consent (Art. 6 (1) a GDPR).
Processing Purpose: Processing medical information inquiries and quality complaints.
Categories of recipients: Data may be shared with public authorities under priority legislation and our affiliated companies. Additionally, employees of our affiliates across various countries may access this data as necessary for processing. Other external bodies may also access data upon the data subject’s consent or if a prevailing interest exists.
Third-country transfers: Processors could also be used outside the European Union, e. g. email provider. Affiliated companies having access to your personal data could be located outside of the European Union as well.
Duration of data storage: The duration of data storage depends on the statutory storage requirements and is usually:

  • For quality complaints: up to 6 years after receipt the complaint (§20 German regulation on the application of good manufacturing practice in the production of medicinal products (AMWHV).
  • For medical information inquiries: 
    • in case inquiry contains pharmacovigilance report or complain, please refer to Pharmacovigilance Data Protection Statement
    • in case inquiry contains quality complain, please refer to respective terms defined above
    • in case inquiry contains a request for providing samples and comes from healthcare professionals (HCPs)-up to 10 years after receipt of the inquiry (§ 47 (3), (4) Medicinal Products Act (AMG))
    • in other cases:

If received from end customers-up to 12 months following the end of the calendar year  in which the inquiry was submitted.
If received from HCP-up to 10 years following the end of the calendar year in which the inquiry was submitted.

 

Specific information for processing of adverse drug reactions reporting

Please refer to Pharmacovigilance Data Protection Statement.

 

Specific information for data processing for advertising purposes

Affected data and legal basis for processing: Name, contact details (e.g., email).
This processing is based on:

  • For doctors and pharmacists- consent (Art. 6 (1) a GDPR)
  • Our legitimate interests in conducting direct marketing activities for other data subjects, as per Art. 6 (1) f GDPR

Processing Purpose: Sending the information about our products and services, such as event invitations, promotional offers via post, e-mail or fax.
Categories of recipients: Public authorities in the event of priority legislation, e. g. finance authority. 
External service providers or other contractors, e. g. for data processing and hosting. 
Other external bodies in so far as the data subject has given his/her consent or a transmission is permitted due to a prevailing interest.
Third-country transfers: Processors could also be used outside the European Union, e.g., email provider. 
Duration of data storage: The duration of data storage depends on the statutory storage requirements and is usually 10 years (§ 147 AO and § 257 HGB).

 

Specific information for data processing for lotteries

Affected data and legal basis for processing: Name, contact details (e.g., email).
Processing is based on consent (Art. 6 (1) a GDPR).
Processing Purpose: Contacting lottery participants before and after a lottery event in order to establish the identity of the participants, contact winners, send prizes and check their delivery.
Categories of recipients: Public authorities in the event of priority legislation. 
External service providers or other contractors, e. g. for data processing and hosting, delivery services. 
Other external bodies in so far as the data subject has given his/her consent or a transmission is permitted due to a prevailing interest.
Third-country transfers: As part of contractual execution, processors could also be used outside the European Union, e.g., email provider. 
Duration of data storage: The duration of data storage depends on the statutory storage requirements and is usually 10 years (§ 147 AO and § 257 HGB).

Contact form

We need your personal information in order to answer your request. You can revoke your consent for the storage of information at any time.

Data subjects rights

Information, revocation of consent, rectification, erasure, restriction of processing and objection
If the requirements for this are met, you have the right under GDPR to obtain information about your processed data and to have it rectified, erased and transferred. You also have the right under certain requirements to request that the processing of your personal data be restricted or to object to the processing. 
If the processing is based on your declaration of consent, you have the right to revoke it at any time with effect for the future, without the revocation affecting the legality of the processing up to the time of revocation, via sending an e-mail to our Data Protection Officer at datenschutz@woerwagpharma.com or by post to Wörwag Pharma GmbH & Co.KG / Data Protection Officer / Flugfeld-Allee 24 / 71034 Böblingen.

Right to file a complaint with the supervisory authority
In accordance with Art. 77 GDPR, you have the right to file a complaint, in particular with the data protection supervisory authority responsible for us, if you believe that we are not processing your personal data lawfully. The supervisory authority responsible for us is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg. Up-to-date contact details could be found at BfDI - Landesbehörden - Baden-Württemberg.

More information

Your trust is important to us. For that reason, we would like to be available to you for any questions with regard to the processing of your personal information. If you have questions that this data protection statement has not answered or if you would like more in-depth information about any point of this data protection statement, please contact us at:

Wörwag Pharma GmbH & Co.KG
Flugfeld-Allee 24
71034 Böblingen
Germany

Email: info@woerwagpharma.de

Security notice

We endeavor to save your personal information by undertaking all technical and organizational possibilities so that it is not accessible to third parties. Complete data security cannot be guaranteed when communicating via email; for that reason, we recommend sending confidential information by regular postal mail.

*List of affiliated companies

Wörwag Pharma Production GmbH & Co. KG
Gewerbeallee 1
82343 Pöcking
Germany
 

We're here to help you!
Contact us