Skip to main content

    Privacy Policy

    Effective Date: February 2025

    1. Introduction

    Sonoref Healthcare GmbH ("Sonoref", "we", "us", or "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website, use our services, or otherwise interact with us.

    This policy is designed to comply with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable Austrian data protection laws.

    2. Data Controller

    The data controller responsible for your personal data is:

    Sonoref Healthcare GmbH
    Julienhöhestrasse 1b
    9521 Treffen
    Austria

    Email: central@sonoref.com
    Phone: +43 3135 206 16

    3. Categories of Personal Data We Collect

    We may collect and process the following categories of personal data:

    3.1 Technical Data

    When you visit our website, we automatically collect certain technical information, including:

    • IP address
    • Browser type and version
    • Operating system
    • Referring website
    • Pages visited and time spent
    • Date and time of access

    3.2 Account and Contact Data

    When you register for an account, request a quote, or contact us, we collect:

    • Company name
    • Contact person name
    • Email address
    • Phone number
    • Business address
    • VAT identification number
    • Customer type (hospital, clinic, distributor, etc.)

    3.3 Communication Data

    Records of correspondence with us, including emails, phone calls, and messages sent through our website.

    3.4 Transaction Data

    Details of services provided, orders placed, invoices, and payment information.

    3.5 Marketing Data

    Your preferences for receiving marketing communications from us.

    4. Legal Basis for Processing

    We process your personal data on the following legal bases under Article 6 GDPR:
    • Contract Performance (Art. 6(1)(b) GDPR): Processing necessary for the performance of a contract with you or to take steps at your request before entering into a contract.
    • Legal Obligation (Art. 6(1)(c) GDPR): Processing necessary to comply with legal obligations, such as tax and accounting requirements.
    • Legitimate Interests (Art. 6(1)(f) GDPR): Processing necessary for our legitimate business interests, such as improving our services, fraud prevention, and direct marketing to existing customers.
    • Consent (Art. 6(1)(a) GDPR): Where you have given explicit consent to processing for specific purposes, such as marketing communications or cookies.

    5. Purposes of Processing

    We use your personal data for the following purposes:
    • To provide our repair, refurbishment, and loaner services
    • To process orders and manage customer accounts
    • To communicate with you about services, quotes, and deliveries
    • To send invoices and process payments
    • To respond to inquiries and provide customer support
    • To improve our website and services
    • To comply with legal and regulatory requirements
    • To send marketing communications (with your consent or based on legitimate interest)
    • To detect and prevent fraud

    6. Data Sharing and Recipients

    We may share your personal data with the following categories of recipients:
    • Shipping and Logistics Providers: DHL, UPS, FedEx, and other carriers for delivery services.
    • IT Service Providers: Hosting, cloud services, and software providers who assist in operating our systems.
    • Payment Processors: For secure payment processing.
    • Professional Advisors: Accountants, lawyers, and auditors as required.
    • Regulatory Authorities: When required by law or to protect our legal rights.
    • International Partners: Where necessary for service delivery in your region.

    We ensure that all third parties with whom we share data are bound by appropriate data protection agreements.

    7. International Data Transfers

    Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data outside the EEA, we ensure appropriate safeguards are in place, including:
    • Transfers to countries with an adequacy decision by the European Commission
    • Standard Contractual Clauses approved by the European Commission
    • Other legally recognized transfer mechanisms

    8. Data Retention

    We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
    • Contract data: For the duration of the business relationship plus statutory retention periods (typically 7 years for tax purposes in Austria).
    • Communication records: For 3 years after last contact or as required for dispute resolution.
    • Technical data: Typically deleted or anonymized within 12 months.
    • Marketing consents: Until consent is withdrawn.

    9. Your Rights Under GDPR

    Under the GDPR, you have the following rights regarding your personal data:
    • Right of Access (Art. 15): You may request confirmation of whether we process your data and obtain a copy of it.
    • Right to Rectification (Art. 16): You may request correction of inaccurate or incomplete data.
    • Right to Erasure (Art. 17): You may request deletion of your data under certain circumstances ("right to be forgotten").
    • Right to Restriction (Art. 18): You may request limitation of processing in certain situations.
    • Right to Data Portability (Art. 20): You may request to receive your data in a structured, machine-readable format.
    • Right to Object (Art. 21): You may object to processing based on legitimate interests, including direct marketing.
    • Right to Withdraw Consent (Art. 7(3)): Where processing is based on consent, you may withdraw it at any time.

    To exercise any of these rights, please contact us at request@sonoref.com.

    10. Cookies and Tracking Technologies

    Our website uses cookies and similar technologies to enhance your experience. Cookies are small text files stored on your device that help us:
    • Remember your preferences and settings
    • Understand how you use our website
    • Improve website functionality and performance
    • Provide relevant content

    Types of cookies we use:

    • Essential cookies: Necessary for the website to function properly.
    • Analytics cookies: Help us understand website usage patterns.
    • Preference cookies: Remember your settings and choices.

    You can manage your cookie preferences through our cookie banner or your browser settings.

    11. Data Security

    We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
    • Encryption of data in transit and at rest
    • Secure access controls and authentication
    • Regular security assessments
    • Employee training on data protection
    • Incident response procedures

    12. Business-to-Business Services

    Sonoref primarily provides services to businesses (B2B). Our customers are typically hospitals, clinics, medical equipment distributors, and healthcare providers. Personal data we process generally relates to business contacts rather than consumers.

    Important: Customers must ensure that no patient data is transmitted to Sonoref during repair or similar processes. We assume no liability for loss or disclosure of patient data transmitted to us.

    13. Children's Privacy

    Our services are not directed at individuals under the age of 18, and we do not knowingly collect personal data from children.

    14. Changes to This Privacy Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated policy on our website with a new effective date.

    15. Complaints

    If you believe that we have not complied with your data protection rights, you have the right to lodge a complaint with the competent supervisory authority:

    Austrian Data Protection Authority
    Österreichische Datenschutzbehörde
    Barichgasse 40-42
    1030 Vienna, Austria
    Website: www.dsb.gv.at

    16. Contact Us

    If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:

    Sonoref Healthcare GmbH
    Julienhöhestrasse 1b
    9521 Treffen
    Austria

    Email: request@sonoref.com
    Phone: +43 3135 206 16

    Language Disclaimer

    These terms have been originally written in English. Translations are provided for convenience only. In the event of any discrepancies, misunderstandings, or translation errors arising from language barriers, the English version shall prevail. Under no circumstances shall Sonoref Healthcare GmbH be held liable for any misunderstanding resulting from translated versions. If you have any questions or require clarification, please contact us at request@sonoref.com.