Right arrow icon
Back to all legal docs

Corsmed Privacy Policy

Source 1

Content

Source 2

Content

Source 3

Content

Source 4

Content

Your privacy is important, both for you and for us. We will do our very best to ensure that the data you let us process is handled in a secure way, with your integrity in focus. This Privacy Policy describes what data we collect, how and why we use it, and where you can find out more.

Any capitalized words used but not defined herein shall have the same meaning ascribed to them in the Terms & Conditions available at https://corsmed.com/legal (the “Terms”).

The following capitalized words have the following definitions:

“Account” means the account you create or that we create for you to access the Services and Software, identifiable by email.

“Customer” means the individual or entity who purchases one or several Licenses to use a Paid Version, whether or not you are a User.

“Free User” means the individual or entity who has signed up for a License to the Demo Version.

“Team Member” means the individual or entity who is part of a Team Workspace.

“Team Workspace” means the group that Corsmed will automatically create when a Customer purchases more than one License.

“User” means any person, such as a Customer, Free User or Team Member, who has signed up for an Account or in any other way uses the Services.

“Websites” means corsmed.com and education.corsmed.com, as well as any other sites related to corsmed.com and education.corsmed.com, including subsites or versions of them connected to helping or supporting you in using the Software.

Whose data do we collect?

What data we collect depends on how you interact with us. Based on the main ways to interact with us, “you” are most likely:

  • A User, who has signed up directly with Corsmed for a Full Version or Demo Version, or received a Full Version or Demo Version from an organization the User is part of.
  • An Administrator, who administers Users.
  • An Organization Contact Person, who is Corsmed’s point of contact at an organization.
  • A Visitor, who visits any of our Websites, attends webinars, sends us emails, participates in surveys, or in any other way interacts with us or uses parts of our Services without having signed up with Corsmed.

What data do we collect?

Depending on who you are, we collect:

  • Contacts — such as your name, email address and billing address.
  • Interaction Information — information about how you use the Services and your system activities, including dates, times and details of log-on and log-off; information about your history with Corsmed; technical data such as page response times, download errors and personal preferences; and your interactions with customer service.
  • Device Information — such as your IP address, user agent, browser settings, operating system, platform and screen resolution. We may, for example, use an IP address received from your browser or device to determine your approximate location.
  • Third-Party Information — information collected through third-party sites or platforms during your interaction with our Services that enables us to provide relevant communication.
  • Additional Information — other information submitted to our Websites or provided when you participate in a focus group or contest, request support, leave reviews or otherwise communicate with Corsmed.
  • Cookie Information — please see our Cookie Policy for more information.

You are liable for personal data included in information submitted by you through your use of the Software, such as documents, text and pictures submitted electronically.

If you are a Team Member, your organization, as our Customer, is liable for this personal data.

Corsmed will only store such personal data to the extent provided and as a result of your use of the Software.

How do we process your data?

The typical situations in which we process your data are listed below, divided according to who you are.

USERS

ADMINISTRATORS

We may collect all the personal data for the purposes described above under “Users,” with the following addition:

ORGANIZATION CONTACT PERSONS

VISITORS

Payment-related data

We use Stripe Payments Europe, Ltd., a compliant third-party vendor, to process credit card payments for invoicing.

We never store, handle or access payment-related data other than as described herein.

We may collect limited information, such as your email address and transaction history.

Stripe generally provides us with limited information related to you, such as:

  • A unique token that enables you to make additional purchases using the information Stripe has stored.
  • Your card type.
  • Your card’s expiry date.
  • The last four digits of your card.
  • Your IP address.
  • Your VAT number, where applicable.

If you choose to pay by invoice, we may need to collect and transfer additional information to our invoicing service provider to enable credit checks and send you invoices.

This information may include:

  • Your company name.
  • Your registration number.
  • Your phone number.

Stripe controls and is responsible for the personal data it collects.

The use of your data by our invoicing service providers is subject to their own privacy policies.

We have data-processing agreements with Stripe.

Webinars and surveys, etc.

From time to time, we may offer you the chance to participate in webinars and surveys.

These may be governed by the Terms and this Privacy Policy or, if explicitly stated, by a specific separate privacy policy with specific terms.

If you choose to participate, we may ask you for certain personal data in addition to what is stated in this Privacy Policy.

We may also cooperate with third parties to host webinars or provide similar services.

If such a third party asks you to provide personal data so it can provide its services, and you agree to do so, that third party’s terms and conditions and policies apply to its services.

We recommend that you review those terms and policies before participating in a webinar or other activity hosted by a third party.

The third party is responsible for the personal data it collects to provide its services.

We may ask you to participate in surveys regarding matters such as customer satisfaction.

With your consent, we may ask you to give us feedback about support matters or when we test new features for improvement purposes.

This may sometimes include processing your personal data as a survey respondent.

For how long is my data stored?

We store personal data for as long as needed for the purposes described in this Privacy Policy.

We may store personal data for a longer period if needed to fulfill legal requirements.

You may request deletion of your contact details, other personal data or your entire Account by emailing info@corsmed.com.

We will comply with your request promptly and no later than 30 days after receiving it.

If you are a Team Member in a Team Workspace, contact the Administrator if you wish to deactivate your Account.

If you wish to request the removal of your personal data, we will help you, but you must request our assistance through the Administrator of the Team Workspace.

Other situations when your data may be processed, shared or disclosed

Notifications

If you have subscribed to receive notifications about changes to our policies, updates to our Software or Services, or other matters, we will use your email address to communicate with you.

Customer access

If you use an email address provided by an organization, such as an employer or school, to access the Services, that organization may request information about your Account.

If the organization is a Customer, it may also ask us to move your Account to its Team Workspace. You will then become a Team Member.

The organization may apply its own policies to your use of the Services and may control, administer, suspend or delete access to your Account.

Please see the Terms for more information about what happens when you use an email address provided by an organization to access the Services.

To avoid this type of disclosure, register an Account with your own private email address.

You can also change your registered email address while logged in.

During a change to Corsmed’s business

If Corsmed engages in a merger, acquisition, bankruptcy, dissolution, reorganization, financing, sale of some or all of Corsmed’s assets or stock, or a similar transaction or proceeding, some or all of your personal data may be shared or transferred.

This also applies to steps taken in contemplation of such activities, such as due diligence.

Any sharing or transfer will be subject to standard confidentiality arrangements.

Aggregated or de-identified data

We may disclose or use aggregated or de-identified data for any business-related purpose, including sharing it with prospects or partners for business or research purposes.

To enforce our rights, prevent fraud and protect safety

We reserve the right to disclose all kinds of data to protect and defend the rights, property or safety of Corsmed or third parties.

This includes enforcing contracts or policies and investigating or preventing fraud or security issues.

To comply with laws

If we receive a request for information, we may disclose all kinds of data when required by:

  • Mandatory applicable laws.
  • Governmental regulations or rules.
  • An order from a court of competent jurisdiction.
  • An arbitral tribunal.
  • A governmental authority.

With consent

We may share personal data and other data with third parties when we have consent to do so.

Third-Party Service Providers

We engage third-party companies or individuals as service providers or business partners to process your Account and support our business.

These third parties act as our processors and may, for example, provide computing and storage services.

Please see our full list of processors.

From time to time, we may remove processors or engage new ones.

When we do so, Corsmed will ensure through a written contract that the processor may access and use your data only to provide the services for which Corsmed has retained it.

The processor will be prohibited from using your data for any other purpose.

Corsmed will ensure that processors are bound by written agreements requiring them to provide at least the same level of data protection required of Corsmed.

Where is my data transferred and stored?

We may transfer your personal data to countries other than the country in which you live.

Most transfers are made to processors within the United States.

All or most of these processors have joined the EU–US Privacy Shield Framework to provide an adequate level of data-privacy protection, as decided by the European Commission and the United States of America.

For more information, please see:

Corsmed uses processors to provide you with the best Services possible.

We do not sell personal data to processors.

Your rights

Right to be informed

You have the right to be informed about how we process your information.

We provide this information through this Privacy Policy, other information on our Website and answers to questions sent to us.

Right to access your data

You may request a copy of your data by emailing info@corsmed.com if you would like to know what personal data we process about you.

A copy of your personal data can also be provided in a machine-readable format.

Right to rectification

You have the right to correct inaccurate or incomplete information about yourself.

You can manage your Account and the content contained in it through your Account settings page.

For personal data that cannot be managed through the Account settings page, email info@corsmed.com.

Right to erasure

You have the right to request deletion of your personal data.

For example, you may request deletion when the data is no longer necessary for the purpose for which it was collected or when you have withdrawn your consent.

You can request deletion by emailing info@corsmed.com.

If you are a Team Member, we suggest sending requests regarding personal data through the Administrator of the Team Workspace.

Right to restrict processing of your data

If you believe your information is incorrect or that we use your data unlawfully, you have the right to ask us to stop or limit the processing.

You can make this request by emailing info@corsmed.com.

Right to lodge a complaint

You have the right to lodge a complaint with your national supervisory data-protection authority or the Swedish Data Protection Authority, referred to as the “DPA.”

Complaints to the DPA can be submitted through its website.

Controlling Account service settings

You can access and control the contents of your Account by logging into your Account.

We will respond promptly and no later than 30 days after receiving your request.

Corsmed may be required by law to retain some personal data despite your request.

When we process your personal data based on your consent or explicit consent, you may revoke that consent at any time.

You can revoke consent by unsubscribing from emails we send you or by contacting us at info@corsmed.com.

Please see our Cookie Policy if you wish to revoke consent relating to cookies.

Revoking consent for direct marketing by email will not cause any detriment to you because we do not require this information to provide our Services.

If you revoke your consent in relation to other matters, exercise your right to erasure or otherwise restrict our processing of your personal data, we may no longer be able to provide our Services.

Age limit

The Services are intended for organizations and individuals who are 16 years of age or older.

By registering an Account, you warrant and represent that you have reached the required legal age, as further described in the Terms.

Contact

Corsmed AB is a Swedish limited liability company with registration number 559093-1779 and is registered in Stockholm, Sweden.

You can contact us at info@corsmed.com.

Changes to this Privacy Policy

This Privacy Policy is not part of the Terms.

We may change this Privacy Policy from time to time.

Laws, regulations and industry standards evolve, which may make changes necessary. We may also make changes to our business.

We will post changes on this page and encourage you to review our Privacy Policy regularly to stay informed.

If we make changes that materially alter your privacy rights, we will provide additional notice through the Services or by email if you have subscribed to notifications.

If you disagree with the changes to this Privacy Policy, you should delete your Account.