Privacy Policy
Last Revised: 2026.06.01
1. Scope of This Policy
This Privacy Policy (hereinafter "this Policy") applies to users of the eIFU (Electronic Instructions for Use) website (hereinafter "this Website") operated by MEDIANA Co., Ltd. (hereinafter "the Company"), as well as to users who request a paper copy of the Instructions for Use (IFU). The Company handles personal information of users in a secure manner in accordance with applicable personal data protection laws and regulations, and has established this Policy to provide transparent guidance on the purposes and methods of processing.
The terms used in this Policy are defined as follows:
• "Personal information" or "personal data" means any information that identifies or is capable of identifying a specific individual.
• "Processing" means any act involving personal information, including collection, storage, use, provision, retention, and deletion.
• "This Website" means the eIFU web page operated by the Company.
2. When Downloading Documents
2-1. Information Processed by the Company
When a user browses or downloads an IFU from this Website, the Company does not collect any personal information directly entered by the user (e.g., name, email address, etc.). However, the following technical information may be automatically generated and processed in the form of server logs for the purpose of stable operation and security maintenance of the Website. Some of this automatically collected information (e.g., IP addresses) may constitute personal information under applicable laws and regulations.
• Date and time of access
• IP address of access
• Browser and device information (User-Agent)
• Product reference number (REF) of the downloaded document
• Document language and version information
2-2. Purposes of Processing
The above information is processed on a limited basis solely for the following purposes:
• Operation and maintenance of eIFU delivery services
• System security and incident response
• Detection of abnormal access and security auditing
• Management of document access history in accordance with EU MDR 2017/745 and ISO 13485
3. When Requesting a Paper Copy
3-1. Personal Information Collected by the Company
When a user requests a paper copy of the IFU, the following information is collected for the purpose of processing the request:
• Name, email address, delivery address (if delivery by courier is selected), fax number (if delivery by fax is selected), country, preferred language, and occupation (healthcare professional / patient)
• The collected information shall not be used for any purpose other than the delivery of the paper copy and regulatory compliance, and shall be managed securely after delivery is completed.
3-2. Purposes of Use of Personal Information
The collected personal information is used solely for the following purposes:
• Receiving and processing paper copy requests
• Additional verification or guidance related to requests
• Compliance with regulatory requirements by country
• Confirmation of document provision
• Delivery of documents in the selected language and manner
3-3. Legal Basis for Processing
The Company processes personal information on the following legal bases:
• Performance of a contract to fulfill the user's paper copy request
• Compliance with applicable medical device regulations
• Legitimate interests of the Company in customer support and request processing
4. Disclosure and International Transfer of Personal Information
4-1. Disclosure to Third Parties
As a general principle, the Company does not disclose users' personal information to third parties. However, exceptions may be made only where required by applicable laws and regulations, such as when the relevant product manufacturer or logistics service provider performs delivery of documents requested by the user.
4-2. International Transfers
In the course of operating the Company's services or providing support from the manufacturer, personal information may be transferred to countries outside the Republic of Korea. In such cases, the Company applies appropriate safeguards in accordance with applicable laws and regulations, including Standard Contractual Clauses (SCCs), access restrictions, and encryption measures.
5. Entrustment of Personal Information Processing
For the smooth operation of services, the Company may entrust tasks such as website operation, cloud infrastructure, and logistics handling to external specialist companies. Unlike the disclosure to third parties described in Article 4, this arrangement involves the entrusted company processing personal information under the Company's instructions for the Company's business operations, and the Company remains the principal entity controlling the use of personal information. The Company exercises management and supervision over entrusted companies in accordance with applicable laws and regulations.
6. Personal Information Protection Measures
The Company implements technical and administrative protection measures, including minimization of access rights to personal information, encryption of data in transit (TLS), and security log monitoring.
7. Retention and Deletion of Personal Information
7-1. Retention Period
• Server logs: Retained for a maximum of 3 months for the purposes of security and incident response.
• Paper copy request information: Retained for a maximum of 3 years after the completion of request processing, and then deleted without delay. However, if a dispute or complaint arises, the information may be retained until the matter is resolved.
7-2. Storage Location
The Company's servers are located in Seongnam-si, South Korea.
7-3. Deletion
The Company's procedures and methods for deleting personal information are as follows:
A. Deletion Procedure
After the purpose for which the user's personal information was collected has been achieved, the information is separately stored for a certain period in accordance with internal regulations for information protection, and then deleted.
B. Deletion Method
Personal information stored in electronic file format is deleted using technical methods that make recovery impossible.
8. Rights of Users
Users may request access to, rectification, deletion, restriction of processing, and portability of their personal information. However, where a statutory mandatory retention period applies to certain information, deletion requests may be restricted during that period, and in such cases, the Company will inform the user of the reason.
To exercise your rights, please contact us at:
► Personal Information Protection Officer
Name: Bongjun Kim
Position: Management Division / Director
E-mail: aiden.b.kim@mediana.co.kr
Phone: +82-33-742-5400
9. Complaints and Supervisory Authorities
• Republic of Korea: Personal Information Protection Commission (https://www.privacy.go.kr), Korea Internet & Security Agency (https://privacy.kisa.or.kr)
• EU/EEA: Data Protection Authority (DPA) of the country of residence, or the European Data Protection Board (https://edpb.europa.eu)
• EU Authorised Representative (EAR) Information: Obelis S.A.
E-mail: mail@obelis.net
Address: Bd. Général Wahis, 53, 1030 Brussels, Belgium
10. Changes to This Policy
The Company may amend this Policy in response to changes in applicable laws and regulations, service content, or internal policies. If this Policy is amended, the updated content will be posted on this Website and the "Last Revised" date at the top will be updated.
