Boston Scientific Privacy Policy
Effective Date: February 14, 2018
Policy Scope
This Privacy Policy (Policy) sets forth the Boston Scientific Corporation (BSC) privacy practices regarding the collection and use of personal data relating to BSC websites (Sites) addressing Europe and Switzerland, including mobile sites and our applications. BSC is dedicated to treating people with respect, transparency, and integrity; therefore, we don’t sell or lease your personal data to a third party. This Policy also describes your choices regarding our use of your personal data and how you can access and update your information. When we refer to BSC, we mean Boston Scientific Corporation, including our affiliates and subsidiaries. BSC adheres to privacy best practices, including the Generally Accepted Privacy Principles (GAPP), and complies with international personal data transfer framework requirements.
International users who access our international, EU and Swiss Sites and applications or provide information to BSC, understand and agree with BSC’s legitimate interest to collect, use, disclose, retain and transfer your personal data to the United States and other countries and territories for the purposes stated in this Policy. This includes, but is not limited to, the transfer of personal data between BSC's third parties, affiliates and subsidiaries located in the United States and globally.
BSC complies with the EU-U.S. Privacy Shield Framework and the Swiss – U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland to the United States, respectively. Boston Scientific has certified to the Department of Commerce that it adheres to the Privacy Shield Principles. If there is any conflict between the terms in this privacy policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification, please visithttps://www.privacyshield.gov/.
BSC remains accountable for onward transfers of EU and Swiss personal data to third party agents acting on BSC’s behalf, where those parties have processed personal data in a manner inconsistent with the Principles, unless BSC proves it is not responsible for the event. The U.S. Federal Trade Commission has jurisdiction over BSC’s compliance with Privacy Shield. If you have an unresolved privacy or data use concern that BSC has not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider, JAMS Privacy Shield Program, (free of charge). Under certain conditions, more fully described on the Privacy Shield website, you may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.
BSC protects any EU and Swiss information transferred to other third countries by introducing privacy provisions to our contracts with online providers or by ensuring the providers adopt the EU standard model clause of the European Commission to ensure information are protected in an adequate manner.
Table of Contents
- Information Collection & Use
- Data Sharing & Onward Transfers
- Cookies & Similar Technologies
- Access & Choice
- Security
- Links to Other Sites
- Minors
- California Privacy Rights & Do Not Track Disclosures
- Updates to Privacy Policy
- Contact, Questions, Comments, Complaints
- Information Collection & Use
Personal data is data that can be used to identify or contact you, such as your name, email address, telephone number or similar information. BSC collects personal data you voluntarily give us, such as but not limited to, requesting information via our Sites, resume submission, online event registration, or Site registration. We provide interactive digital health tools through which information is collected from users. We also collect information about your interactions with our Sites and applications (e.g., browsing behavior). Our Sites automatically track certain behavior (Usage Data) during visits, such as, referring/exit URLs and we also collect other basic information about you which does not directly identify you but which may correspond with you or a particular device. We use this information to learn more about how our websites and online resources are used and to otherwise improve and administer the site. We also use this information to enable us to deliver information tailored to your interests and preferences, based on your use of the site. For example, we may collect the Internet Protocol Address assigned to your computer by your internet service provider. This address may change each time you connect to the internet (a “dynamic” IP address), or it may remain the same (a “static” IP address). In most cases, this information is collected automatically, for our legitimate business interests. In some jurisdictions, we are required to ask for your consent before collecting this information, in which case you will be presented with a choice as to whether you wish to allow the collection and use of this type of information, generally this will present itself in the form of a consent banner (providing you with a choice to accept or reject such collection). If you are a registered user, we may use your Usage Data with or without your personal data, in order to measure the Site's performance and improve the Site's design and functionality.
We may also collect the following voluntarily from you:
We use this information to:
We may also collect from you the following personal data about your contacts:
When you provide us with personal data about your contacts we will only use it for the specific reason for which it is provided. If you believe one of your contacts has provided us with your personal data and you want to submit a removal request, please contact us at [email protected] or at [email protected] if you are located in the EU, Swiss, or EEA zone.
Licensed medical professionals must provide additional personal data to register (e.g., profession, title, Medical ID and clinical affiliation) in case of websites with restricted access. In addition to the uses mentioned above, we use this data to review and verify your registration.
Job applicant personal data is used solely for the purpose of the employment process. It is retained only for the purpose of considering your application for current BSC positions or as necessary to comply with the law.
We may use your personal data to support the activities of unaffiliated third parties that are under contract to perform services for or on behalf of BSC (including to maintain computer database, perform marketing activities when allowed by law, or conduct surveys). For example, personal data collected through interactive digital health tools we provide may be used to improve these tools and determine payment amounts for vendors who assist us in making these tools available.
- Data Sharing & Onward Transfers
BSC won’t sell or lease your personal data to a third party; however, there are certain circumstances where we may share your personal data without additional notice to you. In addition to the disclosures described throughout this Policy, and subject to applicable law, we and our third parties may disclose your personal data:
We may share aggregate data with selected third parties. For example, BSC may disclose aggregate Usage Data to third parties to understand how the Site is used or for marketing purposes. See also "Cookies", below. Aggregate data does not identify individuals.
The access granted to our affiliates, subsidiaries, and third parties is limited solely to the purpose for which such information was provided. Furthermore, we require our affiliates, subsidiaries and third parties to uphold and maintain BSC’s policies with respect to privacy and the treatment of your personal data. Regardless of their locations or the laws of the countries they are based in, they are contractually required to provide at least the same level of protection as required by the Privacy Shield Principles.
- Cookies & Similar Technologies
BSC and our partners use a variety of technologies to facilitate the delivery of services to you via our Sites and applications and to understand and preserve your personal preferences. Use of these is governed by our Policy or the privacy policy of the third party providing the service.
Cookies: We use a combination of "session" and "persistent" cookies, small pieces of information that are sent to your browser and stored in text files on your device. Cookies remember certain user inputs on the Site, like login information or personalized content and services, as well as feedback related to marketing and email campaigns. Persistent cookies may hold personal data, but only if you are a registered user or have otherwise consented to the provision of personal data in accordance with the terms of this Policy.
Session cookies are temporary and expire once your browsing session ends. Persistent cookies remain on your device until their expiration date or when you delete the cookie. Subject to applicable law and in accordance with the terms of this Policy, information gathered via persistent cookies may be shared with our third parties.
Cookies do not damage your computer and you have choices about managing them. You can set your browser to notify you about cookies, to refuse them, or to delete them. Refusing or deleting cookies may impact the functionality of the site. To learn more about cookies, search for "cookie" in the Help portion of your web browser.
Local Shared Objects (LSOs), also called Flash cookies, are used to store your preferences such as volume control, or to display personalized content. To learn how to manage privacy and storage settings for Flash cookies, go to Macromedia Settings Manager.
3rd Party Tracking: Our third-party partners may use cookies and LSOs. We may not always have access or control over these cookies, however, the third parties act on our behalf. Our third parties use session ID cookies to track certain information about your behavior while visiting the Site, to facilitate surveys, to deliver advertising, and to identify groups of users and deliver appropriate Site content and services, as well as feedback related to marketing and email campaigns. Our third parties employ clear gifs (a.k.a. Web Beacons/Web Bugs), images, and scripts that help them better manage Usage Data. We do not tie the information gathered to your personal data.
Widgets: Our Sites may include widgets, such as the Share this button or interactive mini-programs that run on our site. This feature may collect your IP address, page visitation history, and may set a cookie to enable the feature to function properly. Widgets are either hosted by a third party or directly by BSC.
Clear Gifs: Our Sites may use clear gifs (also known as web beacons). A clear gif is typically a transparent graphic image (usually 1 pixel by 1 pixel in size) and it allows the site to measure user actions on the page containing the clear gif. BSC uses clear gifs to measure traffic and related behavior, to improve user experience, and to manage the content available on the Site. Clear gifs are not tied to personal data.
Behavioral Advertising: We partner with third party ad networks to display advertising on our Sites and to manage our advertising on other sites. Our ad network partners use cookies and Web beacons to collect non-personally identifiable information about your activities to provide you with interest-based advertising on our Sites. If you wish not to receive targeted ads, you may opt out by clicking here. Please note this only stops interest-based advertising; you will continue to receive generic ads.
Registered users and those who have provided BSC with personal data may request to review, change or delete information by logging in and modifying their profile, by e-mailing [email protected]. Deletion or change requests should be made by you directly. We will respond to all access requests within 30 days.
To "opt-out" of (1) having your Site provided personal data disclosed to third parties for promotional purposes, or (2) any other consent previously granted for a specific purpose concerning your personal data on this Site, send an e-mail to BSC at[email protected], contact us at [email protected] or at [email protected] if you are located in the EU, Swiss, or EEA zone. To "opt-out" of receiving a particular marketing or promotional communication, follow the unsubscribe instructions included in the specific communication.
If you wish to update or delete a testimonial you submitted, please contact us at [email protected].
The information you post in publicly-accessible Site blogs or community forums may be read, collected, and used by others who access them. To request removal of your personal information from our blog or community forum, contact us at [email protected]. In some cases, we may not be able to remove your personal information, in which case we will let you know if we are unable to do so and why.
Data Retention
We retain your information while your account is active or as needed to provide you services. We also retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
- Security
BSC takes security seriously. We use reasonable and appropriate data protection measures, such as robust technologies, security policies, and procedures, to reduce the risk of misuse, alteration, accidental destruction or loss, and unauthorized disclosure or access to our systems and data. For example, we encrypt the transmission of sensitive information using secure socket layer technology (SSL). We follow industry standards and best practices to protect your personal data during transmission and once we receive it. Unfortunately, no security method is 100% secure; therefore, we cannot guarantee absolute security. Please email any Site or application security questions to [email protected].
This Policy applies only to BSC Sites and applications that link to this Policy. Our Sites include links to both our affiliated sites and to non-BSC web sites, including access to content, products and services of such affiliated and non-affiliated sites (Other Sites). BSC is not responsible for the privacy practices of Other Sites. You should directly contact these Other Sites to read their privacy policies and for more information about their practices.
Our Sites and applications are not intended for use by individuals under the age of 18, and BSC does not knowingly collect personal data from those in this age group. If you are under 18, please discontinue the use of our Sites and applications. If we become aware that someone under the age of 18 has registered, we will expunge any related personal data from our records.
- California Privacy Rights & Do Not Track Disclosures
Under the California “Shine the Light Act,” California residents have the right to request 1.) The identity of any third parties to whom BSC has disclosed personal data for the third parties’ direct marketing purposes, and 2.) The type of personal data disclosed. Not all information sharing is covered by the "Shine the Light" requirements and only information on covered sharing will be included in our response. To make a request, please send your full name, street address, city, state and zip code to[email protected].
Please be aware BSC does not respond to your browser’s Do Not Track signals.
BSC may, in its sole discretion, update this Policy by posting the amended Policy on this Site. We will notify you prior to the changes, where required, of material Policy changes via your account email address or by a Site notice
This Policy was last updated on February 14, 2018.
- Contact, Questions, Comments, Complaints
Please direct privacy-related issues, questions, comments or complaints to one of the following:
Email: [email protected]
Postal Mail:
Boston Scientific Corporation
Global Privacy Office/Legal
300 Boston Scientific Way
Marlborough, MA 01752 (USA)
EU/EEA/Switzerland countries :
Email: [email protected]
Postal Mail:
Boston Scientific
c/Ribera del Loira, 38 Edificio 4
28042 Madrid (Spain)
Finally, in the EU/EEA and Switzerland you have the right to lodge a complaint with the data protection authority of your country where you believe that your rights have been violated [see EU list, Switzerland].
Rest of the world at Email: [email protected]
Postal Mail:
Boston Scientific Corporation
Global Privacy Office/Legal
300 Boston Scientific Way
Marlborough, MA 01752 (USA)