PRIVACY POLICY

Effective date: 01.08.2026.
Website: www.proxima-medical.rs

  1. Introduction

This Privacy Policy explains how PROXIMA d.o.o. collects, uses, stores, shares, and otherwise processes personal data when you:

  • visit our website;
  • contact us;
  • request product information, technical documentation, or a quotation;
  • apply to become a distributor or business partner;
  • subscribe to marketing communications;
  • communicate with our representatives; or
  • otherwise interact with our company through the website.

We process personal data in accordance with applicable data-protection legislation, including the Serbian Law on Personal Data Protection and, where applicable, the EU General Data Protection Regulation.

  1. Data Controller

The controller responsible for your personal data is:

PROXIMA d.o.o.
Registered address: Moravska 7, Čokot 18250 Niš
Registration number: 07674147
Tax/VAT number: 100621240
Privacy email: office@proxima-medical.rs
Telephone: +381 18 4 291 290

  1. Personal Data We Collect

Depending on how you interact with us, we may collect the following categories of information.

3.1 Information You Provide

This may include:

  • first and last name;
  • job title and profession;
  • company or organisation name;
  • business address;
  • country or region;
  • email address;
  • telephone number;
  • distributor or customer information;
  • details included in enquiries or correspondence;
  • product interests and requested documentation;
  • quotation, procurement, service, or partnership information;
  • marketing preferences;
  • information submitted through forms; and
  • documents or attachments that you choose to provide.

3.2 Information Collected Automatically

When you use the website, we or our authorized service providers may collect:

  • IP address;
  • device type;
  • browser type and version;
  • operating system;
  • referring website;
  • pages viewed;
  • date, time, and duration of visits;
  • approximate location derived from an IP address;
  • language settings;
  • cookie identifiers;
  • consent records; and
  • diagnostic, security, and website-performance data.

3.3 Information from Other Sources

We may receive professional or business contact information from:

  • your employer or organisation;
  • authorized distributors or representatives;
  • event organizers;
  • publicly available professional sources;
  • business partners;
  • regulatory or procurement platforms; and
  • other persons who are authorized to provide your information.
  1. Sensitive and Patient Information

Our general website is not intended for the submission of patient records, medical histories, diagnostic information, or other sensitive health data.

Please do not submit identifiable patient information through ordinary contact forms or email.

Where information concerning a product complaint, adverse event, vigilance matter, or regulatory obligation is submitted, we may be legally required to collect and retain certain details. Such information will be handled only for appropriate safety, regulatory, quality-management, and legal purposes.

Where possible, avoid including directly identifiable patient information and follow the designated reporting procedure provided by us.

  1. Purposes and Legal Bases

We may process personal data for the following purposes.

5.1 Responding to Enquiries

We use your contact and enquiry information to respond to questions, provide documentation, arrange demonstrations, or discuss products and services.

The legal basis may be our legitimate interest in communicating with customers and business contacts, taking steps at your request before entering into a contract, or performing an existing contract.

5.2 Quotations, Orders, and Contracts

We process information necessary to prepare quotations, process orders, manage deliveries, administer contracts, maintain customer accounts, and provide after-sales support.

The legal basis is taking pre-contractual steps, performing a contract, complying with legal obligations, and our legitimate business interests.

5.3 Distributor and Business Relationships

We use professional and company information to assess and manage potential or existing distributors, representatives, suppliers, consultants, and other business partners.

The legal basis may be pre-contractual steps, contract performance, compliance with legal obligations, and our legitimate interest in managing our commercial network.

5.4 Product Safety and Regulatory Compliance

We may process information concerning product complaints, incidents, adverse events, corrective actions, service records, and regulatory enquiries.

The legal basis may include compliance with medical-device, product-safety, quality-management, recordkeeping, and other legal obligations, as well as the protection of public health and our legitimate interest in maintaining product safety.

5.5 Website Operation and Security

We process technical data to deliver website content, prevent misuse, maintain security, diagnose errors, protect our systems, and generate basic operational statistics.

The legal basis is our legitimate interest in operating a secure and functional website and, where relevant, compliance with legal obligations.

5.6 Analytics and Website Improvement

Subject to applicable consent requirements, we may use analytics tools to understand how visitors use the website and to improve navigation, content, performance, and user experience.

The legal basis is your consent where required. Where applicable law permits limited analytics without consent, the basis may be our legitimate interest.

5.7 Marketing Communications

We may send product news, event invitations, company updates, or other marketing communications when:

  • you have provided consent;
  • you are an existing business contact and the communication is legally permitted; or
  • another lawful basis applies.

You may unsubscribe at any time by using the unsubscribe link or contacting us. Withdrawal does not affect processing that occurred before withdrawal.

5.8 Legal Claims and Compliance

We may process information to establish, exercise, or defend legal claims, conduct audits, prevent fraud, respond to authorities, enforce agreements, and comply with legal requirements.

The legal basis is compliance with legal obligations and our legitimate interest in protecting the company and its legal rights.

  1. Cookies and Similar Technologies

Cookies are small files or identifiers stored on, or accessed through, your device.

We may use the following categories:

Necessary Cookies

These cookies support essential website functions, security, network management, language settings, and storage of your privacy choices. They generally cannot be disabled through our website.

Preference Cookies

These remember selections such as language, region, or display preferences.

Analytics Cookies

These help us understand website usage, traffic sources, page performance, and technical issues.

Marketing Cookies

These may be used to measure advertising, limit repeated advertisements, or create relevant audience segments.

Where required by law, preference, analytics, and marketing cookies will not be activated until you provide consent.

You may change or withdraw cookie consent through Consent preferences. You can also manage cookies through your browser, although blocking necessary cookies may affect website functionality.

A separate Cookie Policy or cookie-preference panel may provide more detailed information about individual cookies, providers, purposes, and retention periods.

  1. Sharing Personal Data

We may share personal data only where reasonably necessary with:

  • companies within our corporate group;
  • authorized distributors or representatives;
  • hosting, IT, cybersecurity, and website-support providers;
  • customer relationship management providers;
  • email and communication providers;
  • analytics and cookie-management providers;
  • logistics, service, and technical-support providers;
  • professional advisers, including lawyers, accountants, auditors, and insurers;
  • certification bodies, notified bodies, regulators, public authorities, or courts;
  • potential buyers, investors, or successors in connection with a corporate transaction; and
  • other parties where you have requested or authorized the disclosure.

Service providers acting on our behalf are required to process personal data only for agreed purposes and to apply appropriate safeguards.

We do not sell personal data in the ordinary meaning of selling it for monetary consideration.

  1. International Data Transfers

Some service providers or recipients may be located outside Serbia, the European Economic Area, or the country in which you are located.

Where required, we will use an appropriate transfer mechanism, such as:

  • a recognized adequacy decision;
  • standard contractual clauses;
  • another approved contractual mechanism;
  • an applicable legal derogation; or
  • your explicit consent where legally appropriate.

You may contact us for additional information about safeguards applicable to a relevant transfer.

  1. Data Retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected and to meet legal, regulatory, accounting, quality-management, and contractual requirements.

Retention periods depend on the nature of the information. For example:

  • general enquiries may be retained for [12–36 months];
  • customer and contractual records may be retained for the contract period and the applicable statutory limitation period;
  • accounting and tax records are retained for the legally required period;
  • distributor and business-partner records may be retained for the relationship and a reasonable period afterward;
  • marketing data is retained until consent is withdrawn, an objection is received, or the data is no longer needed;
  • cookie and analytics data is retained according to the periods stated in the cookie-preference tool; and
  • product-safety, vigilance, complaint, traceability, and regulatory records may be retained for the period required by applicable medical-device legislation and quality-management rules.

Data may be retained longer where necessary for legal proceedings, investigations, regulatory requests, or the protection of legal rights.

  1. Data Security

We use reasonable organisational, contractual, and technical measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, disclosure, misuse, or unauthorised access.

These measures may include access controls, authentication, encryption where appropriate, backups, security monitoring, confidentiality obligations, staff training, and vendor assessments.

No internet transmission or storage system can be guaranteed to be completely secure. You should therefore avoid sending confidential or sensitive information through unsecured channels.

  1. Your Data-Protection Rights

Subject to applicable law and any relevant limitations, you may have the right to:

  • receive information about the processing of your data;
  • request access to your personal data;
  • request correction of inaccurate or incomplete data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • object to direct marketing at any time;
  • withdraw consent at any time;
  • request data portability;
  • request information about international-transfer safeguards;
  • lodge a complaint with a competent supervisory authority; and
  • request human intervention where a legally significant decision is based solely on automated processing.

These rights are not absolute. We may retain or continue processing certain information where required or permitted by law.

To exercise a right, contact us at office@proxima-medical.rs . We may request information needed to verify your identity and protect your data from unauthorised disclosure.

We will respond within the period required by applicable law.

  1. Supervisory Authority

You may submit a complaint to the data-protection authority responsible for your location.

We encourage you to contact us first so that we have an opportunity to address your concern.

  1. Children’s Privacy

The website is intended for business and professional audiences and is not directed toward children.

We do not knowingly collect personal data from children through the website. A parent or guardian who believes that a child has provided personal data may contact us to request its review or deletion.

  1. Automated Decision-Making

We do not ordinarily use website data to make decisions producing legal or similarly significant effects based solely on automated processing.

This section will be updated if such processing is introduced.

  1. Third-Party Links

The website may contain links to third-party websites, platforms, or services.

We are not responsible for the privacy practices of third parties. You should review their privacy notices before providing personal data.

  1. Changes to this Policy

We may update this Privacy Policy to reflect changes in our processing activities, services, technologies, or legal obligations.

The updated version will be published on this page with a new effective date. Material changes may also be communicated through a notice on the website or another appropriate channel.

  1. Contact Us

For privacy questions, requests, or complaints, contact:

PROXIMA d.o.o.
Moravska 7, Čokot 18250 Niš
Privacy email: office@proxima-medical.rs
Telephone: +381 18 4 291 290