#Privacy PolicyProsFit Technologies JSC- Registered in Sofia, Bulgaria (EU) - UIC: 203184177, VAT: BG203184177 - Address: Blvd. Nikola Vaptsarov 53A, 1407 Sofia, Bulgaria_To contact the Data Protection Officer, please email_ [_data@prosfit.com_](mailto:data@prosfit.com)**ProsFit**- _is a Controller of data in the EU in accordance with_ _GDPR_, including for data related to health- has architected and implements best practices for data privacy into its systems and operations- _is_ _GDPR__-compliant_**ProsFit's Privacy Policy / Data Protection Policy could affect you in a number of ways**.- See (link: #context text:Context) - (link: #prosfit-01 text: ProsFit) - (link: #data-and-privacy text: Data and Privacy) - (link: #gdpr-and-compliance text: GDPR and Compliance)- See ProsFit's general principles for Privacy and Data Protection- See How this could affect youTo **jump ahead to the section most relevant to you** , click here:- Visitor to prosfit.com (and/or subdomain)- Customer / User of PandoFit and/or PandoFit Cloud- Wearer's Data input in to PandoFit; End-User of a ProsFit Product; "Patient Data"- Receiving emails; part of Direct Marketing and Sales list; CRM- We met and exchanged business cards, details; via email, or similar- Employee or potential employee- Processor / sub-contractor or potential processor / sub-contractor- I WANT TO **UNSUBSCRIBE** /STOP HEARING FROM PROSFIT!- I have a concern about my data, and/or otherwise want to speak to the person who is responsible for data protection – **how can I contact the Data Protection Officer**# Context {#context}## ProsFit {#prosfit-01}"ProsFit" represents the company ProsFit Technologies JSC, registered in Sofia, Bulgaria (EU); with UIC: 203184177, VAT: BG203184177, and at address: Blvd. Nikola Vaptsarov 53A, 1407 Sofia, Bulgaria.ProsFit is a company with the vision:* **XYZ**ProsFit delivers solutions, products and services primarily related to prosthetics, as well as orthotics, rehabilitation, and related fields.Formally, ProsFit is a manufacturer of medical devices based in the EU, and accordingly is in compliance with medical device standards including Medical Devices Directive EC/93/42; and as applicable in other geographies.ProsFit's activities include processing data, including data related to health – a special category of data according to GDPR (…)## Data and Privacy {#data-and-privacy}ProsFit is driven for quality, robustness, outcomes, security, privacy and other rights related to personal sovereignty and ability to live as a free and independent human being.In accordance with this, ProsFit's processing of data is taken from a principle of data privacy and security, including principles of minimization, practice of pseudonymisation of any patient data, and applicable security best practices.## GDPR and compliance {#gdpr-and-compliance}'GDPR'… fundamental rights for data privacy… 2018…# ProsFit general principles for privacy and data security_Note: Further information is provided depending on the case, and included in the section "_ (link: #how-does text: How does ProsFit's Privacy Policy affect you?)**ProsFit applies general principles and practices related to privacy and data security:**- Privacy and data security are fundamentally important (…)- Appropriate privacy and data security practices are required and applied- Systems, data flows and security are mapped- All processors are stated and assured as GDPR compliant- Appropriate consent is required- We make as easy as possible to remove consent and "unsubscribe"- All processing of EU data takes place within the EU- Data is treated in such a way to meet regulatory, contractual and legal obligations- Data is minimized- Reference or access to data is minimized- Pseudonymization of Patient Data is applied- Obligations towards legal and regulatory standards including for Medical Devices are applied; This includes an obligation to keep data related to provision of Class I Medical Devices for a minimum of 5 years- A Data Protection Officer is in place and may be contacted at [data@prosfit.com](mailto:data@prosfit.com)- Procedures for Data Protection and response to concerns related to data are in place- The team are motivated, trusted, trained, supported, and contractually obligated to the appropriate and correct treatment of data and confidentiality- ProsFit's Privacy Policy is in accordance with ProsFit's Quality Management System# How does ProsFit's Privacy Policy affect you? {#how-does}## Visitor to prosfit.com (and/or subdomain)- Privacy and data security are fundamentally important (…)- Data is minimized- Visitors to prosfit.com do not generally have any data processed in relation to them, except the potential for fair use of anonymous Statistical Data.- ProsFit may use cookies on prosfit.com for the provision of in-browser behavior (such as remembering login name or that you have agreed to the Terms and Conditions (where applicable)), but does not use cookies to collect from you or share to 3rd parties any data.- - _Note: Google Analytics XYZ_- Appropriate consent is required- **Please note: Consent for Contact:** When you input your name and contact data into a Contact Form, Sign up form, Newsletter signup, or otherwise -\> you provide consent that we may contact you in response to and in accordance with your request.- We make as easy as possible to remove consent and "unsubscribe"- At any time you may unsubscribe from receiving any further communication from us by contacting us at [unsubscribe@prosfit.com](mailto:unsubscribe@prosfit.com) .- You may be requested to specify for further information and/or for Customers whether you would like to also cancel your Subscription.- Note: For on-going or previous Customers: We reserve the right to exceptionally contact you including in case required to meet applicable regulatory or legal requirements- A Data Protection Officer is in place and may be contacted at [data@prosfit.com](mailto:data@prosfit.com)- Procedures for Data Protection and response to concerns related to data are in place## Customer / User of PandoFit and/or PandoFit Cloud- Privacy and data security are fundamentally important (…)- Appropriate privacy and data security practices are required and applied- Systems, data flows and security are mapped- All processors are stated and assured as GDPR compliant- Appropriate consent is required- We make as easy as possible to remove consent and "unsubscribe"- At any time you may unsubscribe from receiving any further communication from us by contacting us at [unsubscribe@prosfit.com](mailto:unsubscribe@prosfit.com) .- You may be requested to specify for further information and/or for Customers whether you would like to also cancel your Subscription.- Note: For on-going or previous Customers: We reserve the right to exceptionally contact you including in case required to meet applicable regulatory or legal requirements- You may Cancel your Subscription to PandoFit while logged in to your account at pandofit.prosfit.co.uk and/or via PayPal (where applicable)- All processing of EU data takes place within the EU- Data is treated in such a way to meet regulatory, contractual and legal obligations- Data is minimized- Reference or access to data is minimized- Pseudonymization of Patient Data is applied- Obligations towards legal and regulatory standards including for Medical Devices are applied; This includes an obligation to keep data related to provision of Class I Medical Devices for a minimum of 5 years- A Data Protection Officer is in place and may be contacted at [data@prosfit.com](mailto:data@prosfit.com)- Procedures for Data Protection and response to concerns related to data are in place## Wearer's Data input in to PandoFit; End-User of a ProsFit Product; "Patient Data"- Privacy and data security are fundamentally important (…)- Appropriate privacy and data security practices are required and applied- Systems, data flows and security are mapped- All processors are stated and assured as GDPR compliant- Appropriate consent is required- We make as easy as possible to remove consent and "unsubscribe"- All processing of EU data takes place within the EU- Data is treated in such a way to meet regulatory, contractual and legal obligations- Data is minimized- Reference or access to data is minimized- Pseudonymization of Patient Data is applied- Obligations towards legal and regulatory standards including for Medical Devices are applied; This includes an obligation to keep data related to provision of Class I Medical Devices for a minimum of 5 years- A Data Protection Officer is in place and may be contacted at [data@prosfit.com](mailto:data@prosfit.com)- Procedures for Data Protection and response to concerns related to data are in place- The team are motivated, trusted, trained, supported, and contractually obligated to the appropriate and correct treatment of data and confidentiality- ProsFit's Privacy Policy is in accordance with ProsFit's Quality Management System## Receiving emails; part of Direct Marketing and Sales list; CRM- Privacy and data security are fundamentally important (…)- Appropriate privacy and data security practices are required and applied- All processors are stated and assured as GDPR compliant- Appropriate consent is required- We make as easy as possible to remove consent and "unsubscribe"- All processing of EU data takes place within the EU- Data is treated in such a way to meet regulatory, contractual and legal obligations- Data is minimized- Reference or access to data is minimized- We make as easy as possible to remove consent and "unsubscribe"- At any time you may unsubscribe from receiving any further communication from us by contacting us at [unsubscribe@prosfit.com](mailto:unsubscribe@prosfit.com) .- You may be requested to specify for further information and/or for Customers whether you would like to also cancel your Subscription.- Note: For on-going or previous Customers: We reserve the right to exceptionally contact you including in case required to meet applicable regulatory or legal requirements- A Data Protection Officer is in place and may be contacted at [data@prosfit.com](mailto:data@prosfit.com)- Procedures for Data Protection and response to concerns related to data are in place## We met and exchanged business cards, details; via email, or similar- Appropriate consent is requiredPrior consent assumed. Please see "Receiving emails; part of Direct Marketing and Sales list; CRM"## Employee or potential employee- Privacy and data security are fundamentally important (…)- Appropriate privacy and data security practices are required and applied- Systems, data flows and security are mapped- Appropriate consent is required- We make as easy as possible to remove consent and "unsubscribe"- Data is treated in such a way to meet regulatory, contractual and legal obligations- Data is minimized- Reference or access to data is minimized- Obligations towards legal and regulatory standards including for Medical Devices are applied; This includes an obligation to keep data related to provision of Class I Medical Devices for a minimum of 5 years- A Data Protection Officer is in place and may be contacted at [data@prosfit.com](mailto:data@prosfit.com)- The team are motivated, trusted, trained, supported, and contractually obligated to the appropriate and correct treatment of data and confidentiality- ProsFit's Privacy Policy is in accordance with ProsFit's Quality Management System## Processor / sub-contractor or potential processor / sub-contractor- Privacy and data security are fundamentally important (…)- Appropriate privacy and data security practices are required and applied- Systems, data flows and security are mapped- All processors are stated and assured as GDPR compliant- All processing of EU data takes place within the EU- Data is treated in such a way to meet regulatory, contractual and legal obligations- Data is minimized- Reference or access to data is minimized- Obligations towards legal and regulatory standards including for Medical Devices are applied; This includes an obligation to keep data related to provision of Class I Medical Devices for a minimum of 5 years- A Data Protection Officer is in place and may be contacted at [data@prosfit.com](mailto:data@prosfit.com)- Procedures for Data Protection and response to concerns related to data are in place- ProsFit's Privacy Policy is in accordance with ProsFit's Quality Management System## I WANT TO UNSUBSCRIBE /STOP HEARING FROM PROSFIT!- Privacy and data security are fundamentally important (…)- We make as easy as possible to remove consent and "unsubscribe"- At any time you may unsubscribe from receiving any further communication from us by contacting us at [unsubscribe@prosfit.com](mailto:unsubscribe@prosfit.com) .- You may be requested to specify for further information and/or for Customers whether you would like to also cancel your Subscription.- Note: For on-going or previous Customers: We reserve the right to exceptionally contact you including in case required to meet applicable regulatory or legal requirements- Data is treated in such a way to meet regulatory, contractual and legal obligations- A Data Protection Officer is in place and may be contacted at [data@prosfit.com](mailto:data@prosfit.com)- Procedures for Data Protection and response to concerns related to data are in place## I have a concern about my data, and/or otherwise want to speak to the person who is responsible for data protection – how can I contact the Data Protection Officer- Privacy and data security are fundamentally important (…)- Appropriate privacy and data security practices are required and applied- A Data Protection Officer is in place and may be contacted at [data@prosfit.com](mailto:data@prosfit.com)- Procedures for Data Protection and response to concerns related to data are in place