Date of last revision: 20 May 2021
Protecting your personal data is important to ResMed. This Privacy Notice applies to your use of the Supplier Portal Aiding Remote Collaboration (SPARC) and associated services operated by ResMed ("ResMed", "us" or "we"). If you use other ResMed products and services, your relationship with us will be governed by separate privacy notices for each of them.
For the purposes of this Privacy Notice, the terms "you" and "your" refer to the person accessing the http://supplier.resmed.com and https://sparc.resmed.com/ websites.
ResMed is committed to ensuring compliance with the requirements set out in applicable data protection laws.
This Privacy Notice provides information on your rights and our practices in relation to your privacy and the protection of your personal data.
1. What personal data do we collect and how do we use it?
We will only collect the personal data you provide to us in order to enable you to access SPARC and associated services, including to:
- operate the log in process;
- respond to your enquiries; and
- enhance SPARC and personalise your experience when you use SPARC (with your consent).
When your account is created by your organisation or ResMed as a professional supplier, and you log into your account to access our documentation, ResMed collects the following personal data from you:
- Identification data: First name, last name and username;
- Professional data: professional email address, name of your company;
- Connection data: password, date of last login and last password reset, as well as the status of your account.
The use of this personal data is necessary for us to create, maintain and manage your account on SPARC and to allow you to access our documentation.
When you create your account, ResMed collects your professional email address, which you will use as an access identifier.
The use of your professional email address for this purpose is based on ResMed's legitimate interest in maintaining its commercial relations with its suppliers.
When you fill out the form to contact ResMed, ResMed collects the following personal data:
- Identification data: first name, last name;
- Professional data: professional email address;
- Information you may share in the "message" field of your request: identification data, professional information, or other information that you may disclose to us in your message.
The use of this personal data is necessary to allow us to answer your questions or to process your request.
ResMed may also send you further information on our products and services via email. The use of your professional email address for this purpose is based on the consent you gave to ResMed when you submitted your details to us.
2. Who do we share your personal data with?
We do not sell or lease your personal data. We will only share it as stated in this Privacy Notice, and only to the extent permitted under applicable laws.
We may, from time to time, share your personal data:
- with another ResMed entity or branch and any company held or controlled by ResMed;
- if all or some of ResMed's activity is transferred to another entity under a merger, an assignment of assets or otherwise;
- in a controlled and secure way, with third parties that we engage to provide aspects of our services on our behalf, including our emailing tool (Microsoft), our hosting provider (AWS), our Quality Management System (Trackwise), our Customer Relationship Management (Salesforce). Our third-party processors are contractually bound to protect your personal data and to use it only for the purpose of providing the services that ResMed instructs them to provide; or
- if we are bound by law to share personal data with (including with courts, arbitration tribunals, authorities or legal advisors, if this is necessary to comply with applicable law or to assert, exercise or defend against legal claims).
3. How long will we retain your personal data?
ResMed will only process your personal data for as long as it is necessary to fulfil the purpose of the processing (e.g., until the matter you have contacted us with is completely clarified), or until you revoke your consent or object to the processing and there is no other legal basis or overriding legitimate reasons for the processing.
To the extent that ResMed needs to process your personal data in order to fulfil a legal obligation, or where the processing is necessary for the establishment, exercise or defence of legal claims, ResMed stores your personal data until the legal obligation is fulfilled or the legal claims have been asserted.
ResMed stores your personal data (apart from data collected via cookies) for different periods of time, depending on the purpose for which it was collected, for example:
- Contact requests: ResMed will keep your personal data for as long as necessary in order to process the request. This personal data will be stored securely within the SPaRC system until it is securely destroyed or deleted.
- Claims: if a request submitted via the contact form is identified as a claim, it will be then stored securely in our Quality Management System for up to 15 years, in order to allow us to track our responses and resolution;
- Emailing: ResMed will keep your personal data for a period of up to 3 years from our last contact.
Data collected via cookies or similar technologies will be stored in accordance with the periods provided for in our Cookies Policy.
4. How do we protect your personal data?
We use various security and privacy measures to ensure we protect your personal data and comply with applicable data protection laws.
Despite the security measures we take, you must bear in mind that it is impossible to guarantee an absolute level of security for data sent over the Internet. If we receive confirmation that personal data has been compromised, ResMed will comply with all applicable legal obligations relating to the notification of data breaches.
5. Where is your personal data hosted and processed?
Your personal data will be securely stored in a data centre located in Australia.
To provide SPARC and associated services, your personal data may also need to be accessed from or transferred to locations outside the jurisdiction in which you provide it, including Australia, New Zealand, Japan, India, Malaysia, Singapore, the European Union, Canada and the United States of America.
Please see section 2 above for more detail on how your personal data may be shared with other ResMed entities and third-party service providers.
If your personal data is accessed from or transferred to locations outside the country in which you provide it, we will implement appropriate measures to ensure that your personal data remains protected and secure and otherwise comply with applicable data protection laws. For instance, where required, we implement the use of the Standard Contractual Clauses of the European Commission in order to ensure that any transfer of personal data to third countries outside of the EU is compliant with applicable data protection laws.
Transfer of data between ResMed entities from within to outside the EU is covered by European Union standard contractual clauses that are in place between all ResMed entities that share and process personal data.
6. What are your personal data rights?
Applicable data protection laws may provide you with certain personal data rights. Where you have personal data rights at law, you may exercise those rights. For example:
You may at any time exercise your right of access, which include the right to information in order to understand how ResMed processes your personal data, as well as the right to instruct ResMed to provide you with a copy of the personal data that we hold.
You may also instruct us to delete the personal data that we hold in the systems described above under certain conditions; this is known as the right to erasure of personal data.
You may instruct us to correct your personal data if you believe that it is not accurate; this is known as your right to rectify your personal data.
In certain cases, you may instruct us to restrict how we use your personal data; this is known as the right to restriction of personal data processing.
You may also object to ResMed's use of your personal data under certain conditions; this is known as the right to object to processing.
You may have the right to instruct ResMed to transfer your personal data to you, in a structured, commonly used and machine-readable format, or request that your personal data be transmitted to another recipient. This is known as the right to portability of personal data.
If you live in France, you may also provide instructions on what is to happen to your personal data following your death.
For any of the rights above which you cannot exercise yourself (e.g., by logging into your account and viewing or updating your information) please contact the ResMed data protection team. Contact details can be found in section 7 below.
We will promptly process your request to exercise your rights. We will inform you, in any event, of any action taken to process your request within a period of one month from receipt.
Please note that some legal obligations may limit your request to exercise rights. In this case, we will always keep you informed.
7. ResMed contact details
The ResMed entity responsible for your personal data is ResMed Holdings Limited, a company incorporated in Australia (company registration number 28 003 765 133), at 1 Elizabeth Macarthur Drive, Bella Vista, NSW 2153.
If you wish to make a complaint or have any questions about this Privacy Notice, you can contact us by email at firstname.lastname@example.org or by mail at the following address:
ResMed Privacy Officer
1 Elizabeth Macarthur Drive
Bella Vista NSW 2155
This Privacy Notice may be updated from time to time. The date of the last update can be found at the beginning of this Privacy Notice. We recommend that you visit this page regularly to check for any updates that may have been made. We will inform you if we make material changes to this Privacy Notice that may affect you.