Data security

The respect of privacy is a serious concern to which we pay special attention when processing and using personal data. We therefore attribute great importance to the protection of your personal data. Insofar as personal data is collected (e.g. your name, address or other contact details), it is processed and used exclusively in accordance with applicable data protection regulations. In the following we would like to inform you about the processing of personal data when using this website. Personal data are all data that identify you, e.g. name, address, e-mail addresses, user behavior.

1. Controller & Data Protection Officer

Responsible Controller for the collection, processing and use of your personal data in the context oft he GDPR is:

  PHOENIX Pharma Polska Sp. z o.o. z o.o.
  Rajdowa 9 St.
  05-850 Konotopa

You can reach our Data Protection Officer at or our postal address with the addition "The Data Protection Officer".

2. Data Collection during the visit of the website

(1) When using the website for information purposes only, i.e. if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server. If you wish to view our website, we collect the following data, which is technically necessary for us to display our website to you and to ensure its stability. This includes the following information:

  • IP address
  • Date and time of the request
  • Time zone difference to Greenwich Mean Time (GMT)
  • Content of the request (specific page)
  • Access status/HTTP status code
  • Amount of transferred data
  • Referrer URL
  • Browser type
  • Operating system and its interface
  • Language and version of the browser software

(2) In addition to the aforementioned data, cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your hard disk in the browser you use and through which certain information flows to the instituion that sets the cookie. Cookies cannot run programs or transmit viruses to your computer. They serve to make the Internet offer more user-friendly and effective overall.

(3) Use of cookies:
a) Persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie. You can delete cookies at any time in the security settings of your browser.
b) You can configure your browser settings according to your wishes and, for example, refuse the acceptance of third party cookies or all cookies. Please note that you may not be able to use all functions of this website.
c) We use cookies to identify you for follow-up visits if you have an account with us. Otherwise you would have to log in again for each visit.
d) The Flash cookies used are not collected by your browser, but by your Flash plug-in. We also use HTML5 storage objects that are stored on your mobile device. These objects store the required data independently of your browser and do not have an automatic expiry date. If you do not wish the Flash cookies to be processed, you must install an appropriate add-on, e.g. "Better Privacy" for Mozilla Firefox ( or the Adobe Flash killer cookie for Google Chrome. You can prevent the use of HTML5 storage objects by using private mode in your browser. We also recommend that you regularly delete your cookies and browser history manually.
e) Of course, you can also view our website without cookies. Internet browsers are regularly set to accept cookies. In general, you can deactivate the use of cookies at any time via the settings of your browser. Please use the help functions of your Internet browser to find out how you can change these settings. Please note that some features of our website may not work properly or at all if you have disabled the use of cookies.

(4) The legal basis for data processing in accordance with the above paragraphs is art. 6 (1) lit. f) GDPR. Our interests in data processing are in particular to enable the use of the website by ensuring the stability of its operation and the security of the website. Unless specifically stated, we only store personal data for as long as is necessary to fulfil the purposes pursued.

(5) If we make use of contracted service providers for individual functions of our offer or would like to use your data for advertising purposes, we will inform you in detail about the respective processes below. We also specify the defined criteria for the storage period.

3. E-Mail Contact

If you contact us (e.g. via contact form or e-mail), we store your details for processing the enquiry and for any follow-up questions. We delete the data arising in this context after the storage is no longer necessary, or limit the processing if statutory retention obligations exist. We only store and use further personal data if you give your consent or if this is legally permissible without special consent.

4. Further functions and offers of our website

(1) In some cases, we use external service providers/contract processors to process your data. These have been carefully selected and commissioned by us, are bound by our instructions and are regularly checked.
(2) Furthermore, we may pass on your personal data to third parties if we offer participation in promotions, competitions, conclusion of contracts or similar services together with partners. You will receive more detailed information when you provide your personal data.
(3) If our service providers or partners are based in a country outside the European Economic Area (EEA), we will inform you of the consequences of this circumstance in the description of the offer.

5. Plugins

Google Maps
This website uses Google Maps API to display geographical information visually. When using Google Maps, Google also collects, processes and uses data about the use of map functions by visitors. You can find more information about Google's data processing in the Google Privacy Policy. There you can also change your personal data protection settings in the Data Protection Center.

Google Web Fonts
Google Fonts are used to improve the visual presentation of various information on this website. The web fonts are transferred to the cache of the browser when the page is called up so that they can be used for display. If your browser does not support Google Web Fonts or does not allow access, the text will be displayed in a default font. Data submitted in connection with the page visit is sent to resource-specific domains such as or They are not associated with data that may be collected or used in connection with the parallel use of authenticated Google services. You can set your browser so that the fonts are not loaded from Google servers (e.g. by installing add-ons like NoScript or Ghostery for Firefox). If your browser does not support Google Fonts or if you block access to the Google servers, the text will be displayed in the system's default font.

6. Your Data Privacy Rights

We gladly want to you inform you regarding your rights according to the general data protection regulation:
- Right of Access
  You have the right to request confirmation whether data concerning you are being processed and to request information regarding these data according to art. 15 GDPR.
- Right to rectification
  In accordance with art. 16 of the GDPR, you have the right to request the completion or correction of inaccurate data concerning you.
- Right to erasure
  In accordance with art. 17 GDPR, you have the right to demand that relevant data may be deleted in case there are no legal obligations preventing the deletion.
- Right to restriction of processing
  You may demand a restriction of the processing in accordance with art. 18 GDPR.
- Right of data portability
  You have the right to request to receive the data provided to us in accordance with art. 20 GDPR and additionally to request its transmission to other processors.
- Right to object
  You may object to the future processing according to art. 21 GDPR at any time.
- Right to revocation
    You have the right to revoke consent anytime according to art. 7 Par. 3 GDPR valid for the future.
- Right to notify the supervisory authority
  In accordance with art. 77 GDPR you have the right to file a complaint with the competent supervisory authority.

7. Reporting System

The PHOENIX group, i.e. the PHOENIX Pharmahandel GmbH & Co KG as well as its affiliated companies according to §§ 15ff AktG, has established a web based reporting system which is designed to enable employees, business partners, customers and third parties an easy system by which to report data incidents or concerns.   These reports are taken seriously and are reviewed and actioned regularly and are used to improve the protection of personal data.
You can access this reporting tool at any time via:
In order to explain the background to the reporting system in more detail, we have also answered a number of frequently asked questions below: - When should I report an incident?
PHOENIX group has an obligation to notify the supervisory authority within 72 hours of becoming aware of an incident, due to this, all incidents must be reported without delay via the online reporting tool.  
- What data incidents should be reported and how?
All personal data incidents are to be reported to the Data Protection Officer via the online reporting tool.
- What is a data protection incident?
Data Protection incidents are any event which has, or could have, resulted in the accidental or deliberate loss of personal data (electronic or paper) or destruction of data, or unauthorised access to data (e.g. loss or theft of laptop, smartphone, paper record, prescriptions).
- What happens after I submit a report?
The Data Protection Officer will review the incident report and will contact you for further information or, where necessary, will assist you with the post incident actions.

8. General Comments

We retain the right to change our data privacy statement. This may be necessary as a result of technical developments. We therefore ask you to consult the data privacy statement from time to time and to apply the current version. If you have do have any further questions or concerns regarding you personal data, please contact the designated data protection officer.