Data Protection Policy

1. Introduction

The protection and security of Personal Data is of paramount importance to Straumann Singapore Pte. Ltd. and its affiliates and related corporations (collectively, "Straumann Group"). This Data Protection Policy ("Policy") outlines how the Straumann Group, its representatives and/or agents (collectively, "us", "we", or "our") collect, use, disclose and process Personal Data in compliance with the Personal Data Protection Act (No. 26 of 2012) ("PDPA") in Singapore. 

It is important for you to be aware of how we collect, use or disclose your Personal Data and the purposes thereof, including when you visit our websites and/or sign up for our offers, products or services. This Policy also informs you about how we may implement measures to protect your Personal Data from manipulation, loss, destruction or improper use.

By interacting with us, submitting information to us, signing up for any products or services offered by us and registering for any courses or events organized by us, you agree and consent to us collecting, using, disclosing and sharing amongst ourselves your Personal Data and disclosing such Personal Data to our authorized service providers and relevant third parties in the manner and for any purposes set forth in this Policy. Additionally, this Policy sets out information on the bases upon which we may lawfully collect, use and/or disclose your Personal Data without consent, where permissible under applicable law.

This Policy supplements but does not supersede nor replace any other consents you may have previously provided to us in respect of your Personal Data. Any consents you may have provided in connection with this Policy are cumulative and additional to any rights which we may have under applicable law to collect, use and/or disclosure your Personal Data.

Our websites, platforms and/or this Policy may contain links to other sites and resources that are not operated by us. If you access or use such sites or resources, you acknowledge and agree that such access or use is entirely at your own risk and may be subject to the terms and conditions and privacy policies imposed by the provider of such sites and/or resources, which we are not responsible for and you are encouraged to review such terms and conditions and privacy policies before accessing or using such sites or resources.

2. How safe is your data?

We may implement certain technical and organizational security measures to protect your Personal Data in our possession or under our control against accidental or intentional manipulation, loss, destruction or access by unauthorized persons.

The measures we may implement include measures to ensure the confidentiality and integrity of your data such as the encryption of your data, use of firewalls and password protection. We will strive to improve our data processing and security measures in line with technological developments.

However, we cannot ensure the security of your Personal Data or the information you transmit to us, whether via the Internet or otherwise, and we urge you to take every precaution to protect your Personal Data, especially when you use our websites, platforms, products and/or services. You remain solely responsible for using adequately secured devices (e.g. with updated antivirus software) when accessing our websites, platforms, products and/or services in order to avoid any unauthorized access or similar risks to your Personal Data by third parties.

If the access to our websites and/or platforms requires the use of any username and/or password, we recommend that you change your passwords often, use strong passwords (e.g. using a combination of letters, numbers and special characters) and ensure that you use a secure browser when accessing our websites and/or platforms.

You undertake to keep your username and password secure and confidential and shall not disclose or permit them to be disclosed to any unauthorized person. Additionally, you undertake to inform us as soon as reasonably practicable if you know or suspect that someone else knows your username or password or believe that the confidentiality of your username and password has been lost, stolen or compromised in any way or that actual or possible unauthorized access of your account has taken place. We are not liable for any damages resulting from any security breaches and/or unauthorized use of your username or password.

3. Collection of Personal Data

In this Policy, "Personal Data" refers to any data, whether true or otherwise, about an individual who can be identified (a) from that data; or (b) from that data and other information to which we have or are likely to have access, and includes without limitation data in our records which may be updated from time to time.

The types of Personal Data you may provide to us will depend on the nature of your interaction with us. Examples of Personal Data that you may provide to us include your name, NRIC, passport or other identification number(s), telephone number(s), address, email address(es), invoicing details and any other information related to any individuals which you have provided us in any forms that you may have submitted to us or via any of our interaction with you.

If you provide us with any Personal Data relating to a third party (e.g. information on your customers, spouse, children, parents and/or employees), by submitting such information to us, you represent to us that you have obtained the consent of such third party to you providing us with their Personal Data for the respective purposes.

You should ensure that all Personal Data submitted and provided to us is complete, accurate, true and correct. Failure on your part to do so may result in our inability to provide you with products and/or services that you have requested.

If any form or document contains data fields for the collection of Personal Data that are marked as mandatory or with an asterisk (*), the provision of such information is either required by applicable law or by contract, or it may be necessary for the conclusion of a contract, provision of products or services, or the fulfilment of the stated purpose(s). If you do not provide the required information, it may result in us not being able to fulfil such contract, provide such products or services, or fulfil such stated purpose(s).

Generally, we collect your Personal Data in the following ways:
(a) when you submit any form, including but not limited to application, enquiry or consent forms;
(b) when you interact with our staff, including our customer service officers and other representatives via telephone calls (which may be recorded), text messaging, letters, fax, face-to-face meetings, email or any other forms of interaction;
(c) via any photographs or videos taken by us or our representatives when you attend courses or events organised by us;
(d) when you request that we contact you, be included in an email or other mailing list, or when you request to be informed of our promotions, offers, discounts and other initiatives;
(e) when you are contacted by and respond to our representatives and agents and other service providers;
(f) when you apply for a job opening, training opportunity or internship with us;
(g) when you use our electronic services or interact with us via our websites and/or platforms or use services on our websites and/or platforms; and/or
(h) when you submit your Personal Data to us for any other reason.

4. How do we use your Personal Data?

We collect, use and disclose your Personal Data for the following purposes depending on your interaction with us and the nature of our relationship with you. It includes the following:

(a) Administrative processes
We collect, use and disclose your Personal Data to manage our administrative and business operations and to comply with our internal policies and procedures. We may also use your Personal Data in managing and preparing reports on incidents and accidents.

(b) Contact and information requests
We collect, use and disclose your Personal Data to process and respond to your requests for information (including without limitation, information on ClearCorrect and dental service providers that use ClearCorrect products or services), complaints, feedback and suggestions.

(c) eShop
We collect, use and disclose your Personal Data to register and otherwise manage your account in our eShop, to allow you to purchase, book and/or download our products or services, to process your orders, for invoicing purposes and to address your inquiries about our products or services. Your Personal Data will also be disclosed to and used by third party providers of production services in relation to the production and shipping of the products you order and addressing any inquiries you may have about our products or services. Your Personal Data may further be used to review, develop and improve the quality of our products and services in our eShop.

(d) Course and event registrations
We collect, use and disclose your Personal Data to provide you with information about courses or events, to process registration for courses and events and for invoicing purposes. Your Personal Data may also be disclosed to and used by third party service providers in connection with the organisation, management and execution of these courses and events.

(e) Job applications
When you apply for a job opening, training opportunity or internship with us, we collect, use and disclose your Personal Data to process and evaluate your application and to contact you in relation to your application.

(f) Compliance with laws and regulations or legal purposes
We collect, use and disclose your Personal Data
(a) in complying with any applicable rules, laws and regulations, codes of practice or guidelines or to assist in law enforcement and investigations by relevant authorities; or
(b) in relation to any claims, actions or proceedings (including but not limited to drafting and reviewing documents, transaction documentation, obtaining legal advice, and facilitating dispute resolution), and/or protecting and enforcing our contractual and legal rights and obligations.

(g) Improvement of Products and Services
We collect, use and disclose your Personal Data to help us review, develop, improve, manage the delivery of and – to the extent this requires the use of Personal Data – enhance our products and services, including analysing customer behaviour and future customer needs, conducting market research and data analytics (including by requesting feedback from you or your participation in surveys)

(h) Other purposes
We collect, use and disclose your Personal Data for any other purpose relating to or reasonably necessary for any of the above.

Furthermore, where permitted under applicable law, we may also collect, use and disclose your Personal Data for the following additional purposes ("Marketing Purposes"):
(a) to provide you with marketing services, including without limitation discounts, offers, information on our products or services, courses and events;
(b) to conduct market research and customer analysis in order to provide you with customised information, discounts, offers, courses and events; and/or
(c) to provide you with customer surveys.

If you have provided your Singapore telephone number(s) and have indicated that you consent to receive marketing or promotional information via your Singapore telephone number(s), then from time to time, we may contact you using the provided Singapore telephone number(s) (including via voice calls, text messaging, fax or other means) with information about our products and services (including discounts, offers, events and other promotional information).

In relation to particular products or services or in your interactions with us, we may also have specifically notified you of other purposes for which we collect, use or disclose your Personal Data. If so, we will collect, use and disclose your Personal Data for these purposes as well.

5. With whom do we share your Personal Data?

Subject to the provisions of any applicable law, your Personal Data may be disclosed, for the purposes listed above (where applicable), to the following entities or parties, whether they are located in Singapore or overseas:

(a) our affiliates for purposes such as support, processing, supply, marketing, or invoicing relating to products and/or services provided by us or our affiliates, including without limitation ClearCorrect Operating, LLC for the manufacturing of ClearCorrect aligners;

(b) professionals and organisations that provide services using our products or services;

(c) third party service providers, suppliers and other cooperation partners used by us for processing, fulfilling and servicing your orders, requests and registrations, including without limitation registrations for any courses and/or events;

(d) third party service providers that provide support services to us, including but not limited to providers of printing services or equipment, lettershops services, call center services, advertising services, internet and IT services, and data center services;

(e) our professional advisers including but not limited to our auditors and lawyers;

(f) relevant government regulators, government ministries, statutory boards or authorities and/or law enforcement agencies, whether local or overseas, to comply with any directions, orders, laws, rules, guidelines, regulations or schemes issued or administered by any of them; and/or

(g) any other party to whom you authorise us to disclose your Personal Data to.

Any disclosure of Personal Data to the above third parties and affiliates is generally subject to their compliance with the privacy and confidentiality terms that we may impose on them.

6. Deemed consent

In addition to the matters set forth above, subject to and in accordance with applicable law, you shall be deemed to have consent to us collecting, using, disclosing and sharing amongst ourselves your Personal data, and disclosing such Personal Data to the authorized service providers and relevant third parties:

(a) where in response to a request for your Personal Data in connection with identified purposes, you voluntarily provide such Personal Data to us for such purpose(s);

and where the collection, use or disclosure of your Personal Data is reasonably necessary for the conclusion and/or performance of a contract between you and us or any other organisation entered into at your request, which may include recipients of your Personal Data not indicated in this Policy.

7. Other bases for handling or processing your Personal Data

In addition to and without limiting the consent you have provided for the collection, use and disclosure of your Personal Data for the purposes set out elsewhere in this Policy, where permitted by applicable law, we may collect, use and/or disclose your Personal Data as further detailed below including without your further consent, where we meet the requirements of applicable law:

(a) for our legitimate interests or the legitimate interests of any other person, including but not limited to the purposes expressly set forth in this Policy;

or for improving our products, services, processes or business, understanding customer preferences and personalising experiences and recommendations, based on your Personal Data records with us (regardless whether you are an existing or prospective customer).

8. Cookies and web tracking

a. Cookies
Cookies are small files that are sent to your computer's hard drive using your web browser or other programs. These are stored locally on your computer's hard disk and kept ready for later retrieval.

b. Use of Cookies
Cookies are used on Straumann Group websites

(a) to facilitate and ensure required technical functions,

(b) to make our website user-friendly,

(c) to match your needs optimally or to evaluate visits to our website for marketing and optimization purposes.

Session cookies are only used for the session. These cookies are deleted after the session has ended, i.e. after leaving our website or closing the browser window.

Other cookies remain on your device for a longer period of time and allow us to recognize your browser on your next visit.

c. Approval or rejection of Cookies
You can approve or reject the use of cookies – also for web tracking – via your web browser settings. You can set your browser to notify you when cookies are being enabled or to reject cookies altogether. However, when you reject cookies, you will not be able to use all our website features. You can inquire about this facility for popular browsers at the following links:

9. Google Analytics

When you click or close our consent banner, our website will use Google Analytics, a web analytics service provided by Google Inc., 1600 Amphitheater Parkway, Mountain View, CA 94043, USA ("Google"). Google Analytics uses cookies stored on your computer to analyse your use of our website. The information generated by the cookies is usually transmitted to a Google server in the USA and stored there.

By activating IP anonymisation on the Google website, however, your IP address will be shortened by Google beforehand within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be sent to a Google server in the US and shortened there.

Google has signed up to the EU Privacy Shield certificate available at: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI.

You may prevent the collection of data generated by the cookie (including your shortened IP address) and your use of the website as well as the processing of this data by Google by downloading and installing the browser plug-in available through the following link: http://tools.google.com/dlpage/gaoptout?hl=en

10. Sever log files and IP addresses

Every time a visitor accesses our website, data about this process is temporarily stored in a log file (Server Log Files) and processed. The log file stores the following information:

(a) a description of the type and version of the web browser;
(b) the operating system used;
(c) the referrer URL category;
(d) the host name of the accessing terminal;
(e) the date and time of the server request; and
(f) the IP address.

An IP address is a numerical address of your technical device (computer or mobile device) used for accessing the internet and our websites. The IP address enables communication between computers and servers. The processing of this so-called server log data by the Straumann Group is required for technical reasons, website analysis and improvement as well as to ensure system security.

11. Amendments

We may modify or revise this Policy from time to time, including modifications to ensure that this Policy is consistent with future developments, industry trends and/or any changes in legal or regulatory requirements. We may send you notification of modifications or revisions to this Policy in such form as we deem appropriate, including by publishing the modified or revised Policy on our websites which may be accessed at https://www.straumann.com/clearcorrect/sg/en/home.html, and where required by applicable law, by posting a notice, or reaching you via other forms of communication (e.g. sending you an SMS message or email) according to such contact particulars that we may have of you in our records from time to time. You may also contact us in the manner disclosed in this Policy to learn about our handling or processing of your Personal Data.

To the maximum extent permissible under applicable law, you agree to be bound by the prevailing terms of this Policy as may be updated from time to time, and/or as you may be notified. Therefore, please check back regularly for updated information on this Policy.

12. Our contact information

If you:

(a) have any questions or feedback relating to your Personal data or this Policy;
(b) would like to withdraw your consent to any use of your Personal Data as set out in this Policy; or (c) would like to obtain access and make corrections to your Personal Data records,

you can contact our Data Protection Officer via the following:

by email: privacy.sg@straumann.com; or
by mail: #19-05 Raffles City Tower, 250 North Bridge Road, Singapore 179101.

If your Personal Data has been provided to us by a third party, you should contact such party directly to make any queries, feedback, and access and correction requests to us on your behalf.

You may withdraw your consent to any or all collection, use and/or disclosure of your Personal Data. However, depending on the nature of your request, we may not be in a position to continue to provide our products or services to you, administer any contractual relationship already in place, or perform or conclude an existing or prospective agreement. This may also result in the termination of any agreements you have with us and your being in breach of your contractual obligations or undertakings. Our legal rights and remedies in such event are expressly reserved.

13. Governing law

This Policy and your use of this website shall be governed in all respects by the laws of Singapore.

Version: November 2022