Privacy Policy

Your personal data and how we handle it

Your personal data is the data that we collect and store about you, which directly or indirectly identifies you. We use this data to establish communication that you have initiated with your acceptance of this privacy policy.

The information you can find below is a summary of the way we collect and manage your data, in accordance with the Law on Personal Data Protection of the Republic of Serbia and relevant EU directives.

Type of personal data we collect

Contact information
When submitting a contact form, reporting an adverse drug reaction, incident or inquiry to the commercial sector, we collect the following information from you:
name and surname, address, e-mail address and telephone number, as well as appropriate information depending on the type of contact established.

Information and correspondence about medicines – medical devices
We keep data about which medicines / medical devices – products you have ordered.

How do we collect personal data
We collect and process data that:

  • you enter yourself when you submit a contact form, report an adverse drug reaction or an incident related to medical devices;
  • you share with us when you contact any organizational unit or department via email or phone.

The exact types of information we collect about you depend on the type of services you use with us.

What we use personal data for

In order for us to process your data at all, one of the following legal bases must be met:

  • that the data is necessary for the establishment of a contractual obligation;
  • that the data is necessary for Zorex Pharma to fulfill its legal obligations;
  • that the processing of the data is in the interest of both you and Zorex Pharma;
  • that we have your consent for the specific processing of the data.

In order to provide you with information, deliver medicines / medical devices and / or other services, we need to process your data. Below you can find information about what we use your data for, as well as the legal basis on which we do so.

Providing information, processing orders, other services
We process personal data in order to identify you as a user / client, and provide the requested information or prepare and deliver the products / services you have ordered. We also do this so that we can process invoices and payments for ordered products.
Legal basis: necessary to fulfill the contractual terms.

Communication
We may use personal information from previous communications with you to provide you with more appropriate help and support. We use your contact information and information about the products and services you use as a basis for providing information, invoicing, shipping ordered products, sending important information, as well as offers and advice on the use of our products and services.
Legal basis: legitimate interest, consent and necessity to fulfill the contracted terms of use.

Marketing
We process personal data about the type of services and services you use, as well as how you use them, in order to offer you relevant products, according to your needs.
Legal basis: legitimate interest and consent.

Security and prevention of abuse
We process personal data to detect and prevent the following actions:

  • abuse
  • violation of the law
  • violation of the terms of use

Legal basis: necessary to fulfill contractual terms, legal obligations.

Legal obligations
We also process personal data to fulfill legal obligations.
Legal basis: legal obligation.

How long do we keep personal data

We store personal data for a maximum period of time corresponding to the documented purpose of the data processing. For details, please contact the Data Protection Officer.

Location of data processing

Zorex Pharma processes your data in Serbia.

Who do we share personal data with

Partners and subcontractors
Zorex Pharma sends instructions from the controller to those who process the data on how the data may be processed. We strive to never share more data than is necessary with each of our partners. We implement appropriate safeguards to ensure that your personal data is handled in accordance with applicable laws regarding security and privacy.

We may be required to share certain personal data under applicable law and as ordered by competent authorities.

How do we protect your personal data

We use industry standards for storing, processing and transmitting personal data, such as SSL/TLS secure connection. Protection is implemented with system and technical measures that ensure integrity, confidentiality and availability.

Your rights

You have the right to receive information about the processing of your personal data and the purpose of the processing. The following information provides an overview of how we fulfill your rights in relation to personal data, based on positive legal regulations. You can contact the Data Protection Officer at Zorex Pharma at privacy@zorexpharma.com.

Right to information
You have the right to request a summary of your personal data.

Right to rectification
If the personal information we hold about you is inaccurate or incomplete, you have the right to request that the information be amended or supplemented.

Right to erasure
You have the right to have your personal data erased if:

  • the data is no longer necessary for the purposes for which it was collected;
  • you withdraw your consent for data for which there is no other legal basis for its storage;
  • the purpose of the data processing is direct marketing and you object to the processing;
  • you object to the legitimate interest as a legal basis and there is no other overriding legal basis;
  • the personal data is not processed in accordance with data protection law;
  • the erasure is necessary to comply with a legal obligation.

The exception is personal data required by law that are stored for as long as prescribed by the applicable legal act.

Right to object

If you believe that we are processing your data in violation of data protection law, you should notify our Data Protection Officer as soon as possible at privacy@zorexpharma.com. You may also file a complaint with the Commissioner for Information of Public Importance and Personal Data Protection.