Privacy Policy

Sartorius Stedim BioOutsource Limited which has its registered office at 1 Technology Terrace, Todd Campus, West of Scotland Science Park, Glasgow, G20 0XA with Company Number SC319460(“we” or “us”) is committed to preserving your privacy.  Please read the following privacy policy to understand how we use and protect the information that you provide to us.

Data privacy notice website

The following information explains how we deal with your personal data.

  1. Responsible entity (“Controller”)
  2. General information on processing personal data
  3. Data collection and processing when accessing the website
  4. Purpose and scope of processing
  5. How we use your data
  6. Protection of minors
  7. Transfer of data via the internet
  8. Use of cookies
  9. Security measures
  10. Onward transfer to third parties
  11. Newsletter mailing
  12. Use of Google Analytics
  13. Use of YouTube
  14. Automated individual decision-making including profiling
  15. Your rights as a data subject (basic information based on Arts 13, 14 GDPR)
  16. Contact for questions on data protection
  17. Amendment to data privacy notice

1. Responsible entity (“Controller”)

Who is responsible for data processing and who can I contact?

Sartorius AG

Otto Brenner Strasse 20

37079 Göttingen

Phone: +49 551 308 0         Email:info@sartorius.com

You can reach our Data Protection Officer at the address shown

Sartorius Corporate Administration GmbH

Data Protection

Otto Brenner Strasse 20

37079 Göttingen

Phone: +49 551 308 0
Email: datenschutz@sartorius.com                dataprotection@sartorius.com

  1. General information on processing personal data

This data privacy statement applies to data including personal data which Sartorius collects about you. Personal data are data or a combination of individual data which can be used to identify you.

We process your personal data in compliance with the data protection laws and the European General Data Protection Regulation. We do not, under any circumstances, forward your personal data to third parties outside the Sartorius Group for advertising or marketing purposes without your consent.

As an international company we use external service providers. If the data they process have personal content, contractual agreements have been concluded and organizational measures have been taken to ensure the security of your data.

In our company, compliance with legal provisions and this statement is monitored by our data protection organization. Our employees are trained in handling personal data and are bound by written agreements to comply with the data protection regulations.

Please note that data transmission on the internet (e.g. when communicating by e-mail) can be subject to loopholes in security. Protecting your data from unauthorized access through measures such as pseudonymization, data minimization, compliance with erasure deadlines and keeping up with the latest technical developments is a very important goal for us. However, despite these protective measures, we cannot entirely rule out illegal processing by third parties.

  1. Data collection and processing when accessing the website

Whenever a user accesses a page on our internet services or retrieves a file, access data concerning this is saved in a log on our server.

Each data record consists of:

  • the page where the file was requested (“referrer URL”)
  • name and URL of the retrieved data
  • date and time of access (“time stamp”)
  • data identifying the browser and operating system
  • report whether access was successful (file transferred, file not found etc.)
  • name of your internet browser (e.g. Mozilla Firefox, Google Chrome, etc.)

Legal processing (the legal basis for this is Art. 6(1)f GDPR)

This data is collected for the purpose of enabling use of the website (connection), system security, technical administration of the network infrastructure, and optimizing our internet services. By agreeing to this data privacy statement you are giving your consent to the collection of these data by us. You may object to this data processing. If you do object to the use of the data, please note that this may restrict your use of our services. Except in the cases described above, these personal data will not be processed unless you explicitly consent to further processing.

We do not forward your data to third parties unless you have given your consent to this. However, in certain areas (e.g. hosting our website) we are dependent on our service providers who we generally oblige contractually to comply with legal requirements.

  1. Purpose and scope of processing

In accordance with the GDPR’s principles of data reduction and minimization, we only collect personal data on our website if these are either necessary for your purpose, we are obliged to do so by legal requirements or a contract, we have a legitimate interest in them and/or you have provided them voluntarily.
If you enter personal or business data (e.g. e-mail address, name, address) you explicitly do so on a voluntary basis.
We process your contact, business and business-relevant data on the basis of legal provisions within the context of an existing or new business relationship. By entering the data you further declare your willingness to have the data you have entered collected, processed or used for the legitimate purpose or for the purpose you designate. We will only process and save your entered data for as long as the purpose requires this to be done and will erase it after the purpose has been satisfied or after the end of the relevant retention period. There will not be any collection, processing or use for any other purpose. Your consent to use of your data can be withdrawn at any time, with effect for the future. If you do object to the use of the data, please note that this may restrict your use of our services.
The following are possible ways we can use your data:

On the basis of legal requirements: In order to implement our General Terms and Conditions

In order to manage our business and to protect against/investigate possible fraudulent transactions

On the basis of contractual purposes: In order to process payments for purchases and other services

In order to process your job applications

If legally permitted, in order to deliver user-specific unsolicited offers and information about Sartorius products and services,

In order to develop and provide advertising adapted to your interests

Based on your consent: Contacting you, sending samples, and information, notifying you at your request of competitions, programmes or offers, supplying other services which we have offered you.

–         Contact form (legal basis: Art. 6(1)a GDPR)

There are a several contact forms on our website which can be used for electronic contact. If you use the relevant contact form to write to us, we will process your data entered in the contact form to get in touch with you and respond to your questions and requests. We follow the principles of data minimization and data reduction by requiring you to only enter the data we absolutely need to make contact with you. These are your first and last name, your company, your e-mail address, telephone number, , country, region, type of enquiry,  choice of services, how you heard about us, and the text field itself. This information is stored in our CRM System in order to maintain a business relationship.

Based on our legitimate interest: Determining the effectiveness of our advertising, developing new products and services, analyzing the use of our products, services and websites, learning how you came to our website

  1. How we use your data

We will use the data we store to provide the products and services you request, to inform you of other products and services offered by Sartorius, to administer our websites and services (e.g. newsletter) and to comply with our legal rights and obligations with regard to data processing.
In order to provide you with a comprehensive website presence, your data are transferred and used within the Sartorius Group (you can find information on the Sartorius Group at https://www.sartorius.com/sartorius/en/EUR/sartorius-companies

  1. Protection of minors

As a general rule, children and individuals under 16 do not provide us with any personal data without the consent of their parents or guardians. We do not ask for any personal data from children and we assure you that we do not knowingly collect personal data on children, use such data in any way or disclose such data to third parties without authorization.

  1. Transfer of data via the internet

The internet is a worldwide open platform. Due to how the internet operates and the systemic risks, all your data transfers are at your own risk. For your security we offer our services exclusively through encrypted transmission.

  1. Use of cookies

Our internet pages also use so-called cookies. These are small text files which are stored on your computer, which your browser saves. They do not damage your computer and do not contain any viruses. Cookies help make our service more user-friendly, effective and secure. Some cookies (“session and functionality cookies”, e.g. for language settings) are essential for ensuring key functions of the website. Without them the website cannot be used as intended.
Most of the cookies we use are so-called session cookies, which are automatically deleted at the end of your visit. Other cookies remain stored on your device until you delete them. These cookies enable us to recognize your browser on your next visit. We use cookies to make our service more user-friendly, effective and secure. Cookies also enable our systems to recognize your browser and offer you services even if you change pages. Some functions of our website cannot be offered without the use of cookies. These require your browser to be recognized even after changing pages.

You can set your browser to notify you when cookies are set and only allow cookies on a case by case basis, or to block cookies in specific cases or generally. You can also activate the automatic deletion of cookies when you close your browser. If you reject the use of cookies (a possible setting in your browser) you can still use our website (although use may be restricted).

You can learn more about how to manage cookies on the most popular browsers (including deactivating them) at the following links:
Chrome
Internet Explorer
Mozilla Firefox
Safari

On our website we use session cookies (technically necessary), functional cookies for web analytics and marketing cookies. The legal basis for processing personal data using session cookies is Art. 6(1)f GDPR. The legal basis for processing personal data using cookies for web analytics and marketing cookies is Art. 6(1)a GDPR, provided that the user consents to this. On accessing our website the user is notified of the use of cookies and has the opportunity to deselect individual cookies in the banner, except for the session cookies which are required for operation. The default setting for cookies is to accept them. This setting obtains your consent to process the personal data used in this connection before the processing starts. In connection with this, there is also notification of the data privacy statement:

For reasons based on your particular situation, you have the right to object to the processing of your personal data at any time in accordance with Art. 6(1)f GDPR.

Find out further information our cookie policy.

  1. Security measures

We have taken extensive measures to protect the security of your data. The data you have transferred to us e.g. by entering it in HTML pages (contact forms) is transferred to Sartorius through the public data network in encrypted form (SSL – Secure Socket Layer), and stored and processed there.

This page uses SSL encryption for reasons of security and to protect the transfer of confidential content, e.g. the enquiries you send us as page operator. An encrypted connection is shown by the change in your browser’s address line from “http://” to “https://” and the lock symbol in your browser line.

If SSL encryption is activated, any data you transfer to us cannot be read by third parties.

  1. Onward transfer to third parties

We do not forward your personal data to third parties (i.e. outside the Sartorius Group) without your prior consent. An exception to this is other service providers who are used in contract preparation and processing, e.g. IT service providers or hosting services for the website. These companies work as processors for Sartorius and may only use personal data in accordance with our instructions.
Sartorius has contractually obliged these service providers to comply with the German data protection level and monitors them.
One further exception is the transfer of data within the Sartorius Group in order to process orders, deliver goods, providing services, or for accounting and invoicing purposes. Otherwise there is no transfer of data to third parties without your consent.
In all these cases, transfer is in accordance with the prevailing national and European data protection provisions; the scope of transferred data is limited to the necessary minimum.

  1. Newsletter mailing

If you subscribe to a newsletter we have offered, we will store your name and e-mail address, together with information which allows us to check that you are the owner of the e‑mail address entered and agree to receive the newsletter. Our registration system sends a registration e-mail with a confirmation link to ensure that you actually want the selected newsletter (double opt-in procedure). Processing is done on the basis of Art. 6(1)a GDPR with your consent.

You can withdraw the consent to store the data and e-mail address and to use it to mail the newsletter at any time, for example with the “Cancel my subscription” link in the newsletter.

  1. Use of Google Analytics

This website uses Google Analytics, a web analysis service of Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; “Google”). Google Analytics uses Cookies.

Processing is for the purpose of analyzing this website and its visitors. For this, Google will use the information that has been obtained to analyze your use of the website on behalf of the operator of this website, to generate reports on website activity and provide other services to the website operator in connection with the website and internet use. Google does not combine the IP address transmitted by your browser in connection with Google Analytics with other data.
Google Analytics uses cookies which enable an analysis of your use of the website. The information about your use of this website which has been generated by the cookies is generally transferred to a Google server in the USA and stored there. IP anonymization is activated on this website. This means that Google first truncates your IP address within the member states of the European Union or other member states of the Agreement on the European Economic Area. The full IP address is only transferred to a Google server in the USA and truncated there in exceptional cases. Your data may also be transferred to the USA. Transfer of data to the USA requires an Adequacy Decision by the European Commission. Processing takes place in accordance with Art. 6(1)f GDPR based on the legitimate interest in providing a needs-based and goal-oriented website. We have signed a contract on processing with Google and are fully meeting the strict requirements of the German data protection authorities for using Google Analytics.

You have the right to object at any time for reasons based on your particular situation to this processing of your personal data based on Art. 6(1)f GDPR.
You can also block storage of the cookies by making an appropriate setting on your browser; however, please note that in this case, you may not be able to fully use all the functions of this website. You can also block the transfer of the data generated by the cookie to Google relating to your use of the website (including your IP address) as well as the processing of the data by Google by downloading and installing the browser plugin here.

In order to block logging by Google Analytics on multiple devices you can set an opt-out cookie. These cookies block the future logging of your data when you visit this website. You must set the opt-out on all the systems and devices you use in order to cover them all. Click here to set the opt-out cookie: Deactivate Google Analytics.
You can find more information on use conditions and data protection at https://www.google.com/analytics/terms/gb.html or https://policies.google.com/?hl=en.

  1. Use of YouTube

Our website uses plugins from the YouTube site operated by Google. The operator of these pages is YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. YouTube is a company affiliated with Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; “Google”).

The function shows videos on YouTube in an iFrame on the website. The “Privacy enhanced mode” option is activated. This means that YouTube will not store any information concerning visitors to the website. If you visit one of our pages with a YouTube plugin, a connection is established with YouTube servers. This notifies the YouTube server which of our pages you visited.
If you are logged in to your YouTube-account, you enable YouTube to assign your surfing behaviour directly to your personal profile. You can prevent this by logging out of your YouTube account.
You can find further information on handling user data in YouTube’s privacy statement here.

  1. Automated individual decision-making including profiling

There is no automated individual decision-making, including profiling, on our websites.

  1. Your rights as a data subject (basic information based on Arts 13, 14 GDPR)

You have the right to obtain information at any time, without charge, concerning your stored personal data, their origin and recipients, the purpose of data processing as well as the right to rectification, blocking, restriction or erasure of this data. You also have the right to receive personal data which you have provided to a responsible entity (“controller”) in a structured, commonly used and machine-readable format.

You can also withdraw at any time consent you have given to the processing and use of your data, unless this is required directly to perform an existing contract or for compliance with an overriding legal obligation. You can contact us about this and with further questions about your personal data at the address given in the Impressum. On request we will notify you in writing in accordance with prevailing law as to what personal data relating to you (if any) we have stored.

  1. Contact for questions on data protection

If you have questions about processing of your personal data, you can contact our Data Protection Officer and their team directly, who are also available for requests for information, applications or complaints:

Sartorius Corporate Administration GmbH

Data Protection

Otto Brenner Strasse 20

37079 Göttingen

Email:   dataprotection@sartorius.com            datenschutz@sartorius.com

16.1. Your right to information

Under the General Data Protection Regulation our customers have rights including the right to information without charge on their stored data. On request we will notify you in writing in accordance with prevailing law as to what personal data relating to you (if any) we have stored.

16.2. Your right to complain to a supervisory authority

If you have a complaint, you can contact the responsible supervisory authority:
Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstrasse 5
30159 Hannover

  1. Amendment to data privacy notice

We reserve the right to update this data privacy statement periodically. Updates to this data privacy statement will be published on our website. Amendments take effect on publication on our website. We advise you to visit this page regularly in order to stay informed of any updates.

This is the current data privacy statement as of July 2018

Sign-up to our newsletter to be the first to hear about our new services & offers

Sign-up to our newsletter to be the first to hear about our new services & offers

Enter your email address to subscribe to our newsletter which provides information about our services. By subscribing, you are agreeing to the processing of your personal information for this purpose as set out in our privacy policy