for
the ANABOX® smart medicine box and
the ANABOX® smart app
With this information, we, anmed GmbH, Am Gewerbegebiet 5, 09474 Crottendorf (hereinafter: “we” or “us”), in particular to inform you about what data is collected and generated in connection with the use of the ANABOX® smart medicine box (hereinafter: “connected product”) and the ANABOX® smart app (hereinafter: “connected service”), how we process this data and how you can access it. Personal data is processed only in accordance with the applicable data protection regulations; further information can be found in our Privacy Policy. The definitions set out in Regulation (EU) 2023/2854 (hereinafter: “Data Act”) apply.
The manufacturer of the connected product and the data controller for all data generated in connection with the use of the connected product and the connected service is:
anmed GmbH,
Am Gewerbegebiet 5, 09474 Crottendorf.
Tel.: +49 (0)37344 13435
Email: info@anmed.de
Other data processors in relation to the data generated by the associated service are:
wirewire GmbH, Reudnitzer Straße 1, 04103 Leipzig
The terms of use for the connected product and the associated service, including information on the term and early termination, can be found at https://anabox-smart.de/posts/allgemeine-geschaeftsbedingungen and – where applicable – during the ordering process or upon installation of the associated service .
The connected product and the associated service may generate the following data:
The data is processed by us and our technical IT and hosting service provider, wirewire GmbH.
The connected product and the associated service generate data continuously and in real time following user interaction. The volume of data generated depends on the nature and extent of use. All product data is continuously transmitted to the associated service as long as a network connection is active.
Of the data generated in connection with your use of the associated service, we use only freely available, non-personal data for the purpose of fulfilling agreements with the user, providing support, warranty, guarantee and similar services, as well as for assessing claims, monitoring and maintaining the functionality, security and integrity of the product, to improve the functionality of any products offered by the data controller, to develop new products, and to aggregate the data with other data or to create derived data. Personal data is processed exclusively in accordance with the applicable data protection regulations. Further information on the purposes of processing can be found in our Privacy Policy.
The data is stored in a cloud instance. The data is stored for as long as you have an active account and the connected product or service is linked to that account.
You can view the data described at2.2 continuously and in real time via the connected service.
Upon request, we will provide you with the data listed at2.2 that is readily available at the time your request is processed, in the form of a report (not continuously and not in real time). You can submit a request by emailinginfo@anmed.de , stating your email address.
Where there is a right to have data transferred to a third party in accordance with Article 5(1) of the Data Act, we will, upon request, also transfer the data specified at2.2 directly to a recipient designated by you, in accordance with the provisions set out at5.2 . If you wish to cancel a data transfer that you have requested, please use the same channel of communication. Please note that once the data transfer has been completed, we have no control over the further processing carried out by the recipient you have designated.
You have the right, in accordance with Article 37 of the Data Act, to lodge a complaint with the competent authority regarding breaches of the provisions on data transfer (Chapter II of the Data Act). Where the processing of personal data is concerned, you may contact the data protection authority responsible for you or for us.
These Terms of Data Use govern how you may access and use certain data relating to our products and services listed in this Annex – including which data is collected and generated, how we process this data, how you may access it, and the extent to which we are authorised to use this data.
Relevant products and services of anmed GmbH within the meaning of Section 20(1) of the General Terms and Conditions of anmed GmbH (B2C):
Further information on the processing of your personal data as a user can be found in the privacy policy on our website.
1.1 The definitions set out in the Data Act apply, unless otherwise specified in this section.
1.2 For the purposes of these Terms of Data Use (hereinafter: ‘TDU’), the following definitions apply, notwithstanding section1.1 :
2.1 The DNBs govern, in particular, the use of the data, access to it and the disclosure of such data to third parties.
2.2 The DNB apply to all data-related rights and obligations under the Data Act. Where the DNB conflict with the applicable General Terms and Conditions of anmed GmbH (B2C) (hereinafter: “Main Contract”), the DNB shall prevail in that respect. In all other respects, the provisions of the Main Contract shall continue to apply.
3.1 The user grants the data owner the non-exclusive, irrevocable, perpetual and worldwide right to use the non-personal data for their own purposes.
3.2 The data owner’s right of use shall include – without prejudice to any statutory rights of use held by the data owner – the following purposes in particular:
3.3 The data owner shall not use the data to gain insights into the user’s financial position, assets and production methods, or for any other purpose that could undermine the user’s commercial position. Furthermore, the data owner is prohibited from accessing the user’s data or using the data in a manner that significantly harms the user’s legitimate interests, in particular where such data contains sensitive business information or is protected by trade secrets or intellectual property rights.
3.4 The data owner may only disclose non-personal product data to third parties for the purposes set out in clause3.2 , in the context of sub-licensing or transferring data usage rights. In doing so, the data owner must ensure, by contractual means, that the third party guarantees a level of protection comparable to the requirements set out in clause3.3 .
3.5 In order to achieve the agreed purposes set out in clause3.2 , the data owner may, at its own expense and under its own responsibility, use processing services such as cloud computing services (including Infrastructure as a Service, Platform as a Service and Software as a Service), hosting services or similar services at any time. Third parties may also make use of such services for the aforementioned purposes at their own expense and under their own responsibility.
4.1 If the user (hereinafter also referred to as the ‘original user’) (i) ownership of the Product and/or (ii) their rights of use or claims to the Product to a subsequent person (hereinafter: “subsequent user”) and, following the transfer to the subsequent user, loses their status as a user, the original user undertakes to comply with the requirements set out in this clause.
4.2 Insofar as access to the data is account-based or account-linked, the original user must ensure that the subsequent user cannot use the original user’s account.
4.3 In all other cases – i.e. where data is not account-linked – the original user must ensure that the rights and obligations as a user are transferred to the subsequent user; the data owner hereby consents to such a transfer in advance. In such cases, when transferring ownership, rights of use and/or claims to the product, the original user shall ensure that the subsequent user grants the data owner a right of use to the extent set out in section3 , taking into account section10 .
4.4 If the original user grants another party (hereinafter: ‘additional user’) the right to use the product whilst retaining their own status as a user (hereinafter: ‘multiple use’), the preceding provisions of this clause shall apply accordingly.
4.5 The original user shall indemnify the data owner against all claims made by the subsequent and/or additional user against the data owner arising from a breach of the original user’s obligations under this clause.
4.6 The Data Owner’s rights to use data generated prior to the transfer shall not be affected by the transfer.
5.1 Where the product is designed in such a way that the data, including the relevant metadata required for the interpretation and use of that data (hereinafter: ‘metadata’), is directly accessible to the user, the user may extract the data directly from the product. Details of whether the relevant product provides direct access, as well as information on the data that can be extracted, the file format and how the data can be extracted, can be found in the information on networked products and associated services under the product’s Data Act.
5.2 Where the user cannot access the data directly from the product, they shall, upon request, be granted access to all data readily available to the data owner – including the metadata. The request may be made by email toinfo@anmed.de , stating your email address.
5.3 Access to the data – including the metadata – as set out in clause5.2 shall be provided in at least the same quality as that available to the data owner; in any event, however, in a comprehensive, structured, commonly used and machine-readable format and, where technically feasible, continuously and in real time. The user shall be granted easy and secure access.
5.4 If the user considers their right of access to have been infringed, they are entitled to lodge a complaint with the competent authority under the Data Act. In addition, they are entitled to their statutory rights.
6.1 The data and metadata readily available to the data owner must be made available by the data owner to a data recipient designated by the user as soon as this is requested by the user or a party authorised by them. The request may be made by email toinfo@anmed.de , stating your email address.
6.2 Further details regarding the transfer of data shall be agreed between the data owner and the data recipient.
The provision and transfer of the data is free of charge for the user.
8.1 The data owner is entitled to refuse access to the data in accordance with section5 or the disclosure of the data to third parties in accordance with section6 , insofar as this is prohibited by statutory provisions – in particular the GDPR, the BDSG and the TDDDG.
8.2 When making a request under sections5.2 and6.1 , the user must demonstrate that the statutory conditions are met, provided that (i) the user’s request for access to and/or disclosure of data relates to personal data and the user is not the data subject, or (ii) the provision of the data requires the storage of information on terminal equipment or access to information stored on terminal equipment.
The user undertakes not to alter or remove the data controller’s technical safeguards, unless the data controller has expressly consented in writing.
The processing of personal data is subject to the relevant data protection provisions (in particular those of the GDPR and the BDSG).
The warranty and liability provisions of the main contract shall apply.