Privacy policy
This Privacy Policy describes how MMP Access DMCC (“we”, “us” or “our”), who provides the platform Magani available at www.magani.org (the "Site") as Data Controller collects, uses, and discloses your personal information when you visit, use our services, or make a purchase from the Site or otherwise communicate with us regarding the Site (collectively, the "Services"). For purposes of this Privacy Policy, "you" and "your" means the user of the Services, whether you are a customer, patient, medical professional, website visitor, or another individual whose information we have collected pursuant to this Privacy Policy.
Please read this Privacy Policy carefully.
In this Privacy Policy, we refer to personal data coming from different individuals:
- “Customers” are individuals who register to the Site to order medicines or for whom a Medical professional orders medicine;
- “Medical professionals” are doctors or other medical professionals who registered to the Site to manage their medical prescription;
- “Website visitors” are individuals who browse the Site, whether they are Customers, Medical professionals or other individuals.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time, including to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will post the revised Privacy Policy on the Site, update the "Last updated" date and take any other steps required by applicable law.
In addition to the specific uses set out below, we may use information we collect about you to communicate with you, provide or improve the Services, comply with any applicable legal obligations, enforce any applicable terms of service, and to protect or defend the Services, our rights, and the rights of our users or others.
What Personal Information we collect?
To provide the Services, we collect personal information about you from a variety of sources, as set out below. The types of personal information we obtain about you depends on how you interact with our Site and use our Services. When we use the term "Personal Information", we are referring to personal data which is information that identifies, relates to, describes or can be associated with you. The following sections describe the categories and specific types of personal information we collect.
Customers’ Personal Information we collect and process
Personal Information we collect directly from Medical professionals
Some features of the Services may require Customers to directly provide us with certain information about them. Customers may elect not to provide this information, but doing so may prevent them from using or accessing these features. Mandatory Personal Information is indicated with this symbol “*” on the Site. Information that Customers directly submit to us through our Services may include:
- Identification and contact details including name, surname, date of birth, gender, address, phone number, and email.
- Order information including purchases, billing address, shipping address, payment details (payment method, card number, payment confirmation)..
- Account information including username, password, phone number and other information used for account security purposes.
- Shopping information including the items viewed, put in the cart.
- Medical data including, but not limited to, the prescription you upload, the patient questionnaire you fulfill, any comment you, or your doctor make about your medical condition, or the medicine you order
- Customer support information including the information you choose to include in communications with us, for example, when sending a message through the Services.
Information We collect indirectly about Customers
Personal information about Customers may be collected indirectly when the purchase of medicine is made by Medical professionals for their patients.
Information about Customers that Medical professionals may provide to us through our Services may include :
- Identification and contact details including name, surname, date of birth, gender, address, phone number, and email.
- Medical data including, but not limited to, the prescription uploaded on the Site, the patient questionnaire fulfilled by the Medical professional, any comment the Medical professional makes about the Customer’s medical condition, or the medicine purchased for the Customer.
Finally, we may obtain information about Customers from third parties, including from our vendors and service providers who may collect information on our behalf, such as our payment service provider (Flutterwave), who collect payment information when the Customer makes a purchase on the Site, to process the payment and allow us to prepare the order.
Medical professionals’ information We collect and process
Personal Information we collect directly from Medical professionals
Some features of the Services may require Medical professionals to directly provide us with certain information about them. Medical professionals may elect not to provide this information, but doing so may prevent them from using or accessing these features. Mandatory Personal Information is indicated with this symbol “*” on the Site.
Information that Medical professionals directly submit to us through our Services may include:
- Identification and contact details including name, surname, professional ID, phone number, and email.
- Professional information including hospital address, professional address and department, specialty, registration documents with the medical board of the country.
- Order information including purchases, billing address, shipping address, payment details (payment method, card number, payment confirmation).
- Account information including username, password, phone number and other information used for account security purposes.
- Shopping information including the items viewed, put in the cart.
- Customer support information including the information you choose to include in communications with us, for example, when sending a message through the Services.
Personal Information we collect indirectly about Medical professionals
Personal information about Medical professionals may be collected indirectly when the purchase of medicine on our Site is made by the Customer with the prescription issued by the Medical professional.
Information about Medical professionals that Customers may provide to us through our Services may include :
- Identification and contact details including name, surname, professional ID, phone number, and email.
- Professional information including hospital address and department, specialty.
Finally, we may obtain information about Medical Professionals from third parties, including from our vendors and service providers who may collect information on our behalf, such as our payment service provider (Flutterwave), who collect payment information when the Medical professional makes a purchase on the Site, to process the payment and allow us to prepare the order.
Website visitors’ Information We Collect about Your Usage
We, or the partners we work with, may also collect certain information about your interaction with the Services ("Usage Data"). To do this, we may use cookies, pixels and similar technologies ("Cookies"). Usage Data may include information about how you access and use our Site and your account, including device information, browser information, information about your network connection, your IP address and other information regarding your interaction with the Services.
How We Use Your Personal Information?
-
Providing Products and Services. We use your personal information to provide you with the Services in order to perform our contract with you, including to process your payments, fulfill your orders, to send notifications to you related to your account, purchases, returns, exchanges or other transactions, to create, maintain and otherwise manage your account, to arrange for shipping, facilitate any returns and exchanges and other features and functionalities related to your account. The legal basis for these data processing activities is the performance of the contract.
-
Analyzing the prescription and advising the patient. We collect and process your prescription to ensure its authenticity and to give you advice on the drug purchased. The legal basis for these data processing activities is compliance with our legal obligations regarding the dispensing of medicine.
-
Pharmacovigilance & drug safety. We collect and process your Personal Information to detect, assess, monitor and prevent adverse effects related to the medicine. The legal basis for these data processing activities is compliance with our legal obligations regarding the dispensing of medicine.
-
Marketing and Communication. We may use your personal information for marketing and promotional purposes, such as to send promotional communications by email, text message or postal mail, and to show you news about our products or services. This may include using your personal information to better tailor the Services on our Site. The legal basis for these data processing activities is our legitimate interest in selling our products.
-
Security and Fraud Prevention. We use your personal information to detect, investigate or take action regarding possible fraudulent, illegal or malicious activity. If you choose to use the Services and register an account, you are responsible for keeping your account credentials safe. We highly recommend that you do not share your username, password, or other access details with anyone else. If you believe your account has been compromised, please contact us immediately. The legal basis for these data processing activities is our legitimate interest in keeping our website secure for you and other customers.
-
Communicating with You and Service Improvement. We use your personal information to provide you with customer support and improve our Services. This is in our legitimate interests in order to ensure the quality in delivering our Services, be responsive to you, to provide effective services to you, and to maintain our business relationship with you.
-
Analyzing and measuring the audience and traffic. See paragraph 4. Cookies for more information. The legal basis to use Cookies for such purpose is your consent.
Cookies
Like many websites, we use Cookies on our Site. Cookies are small text files that are placed on your computer or mobile device (such as a smartphone or tablet) when you visit the medicine marketplace. We use Cookies to power and improve our Site and our Services (including to remember your actions and preferences), to run analytics and better understand user interaction with the Services (in our legitimate interests to administer, improve and optimize the Services and with your consent for analytics purposes).
The following cookies are used on the online shop:
- Analytical cookies
- Functionnal cookies
Analytical cookies collect information about how you use and navigate the marketplace (for example, the frequency of your visits, the pages you consult and the other websites you visited before coming to the Marketplace). These cookies enable us to improve and optimise the functionality of the Marketplace, its content and your browsing experience.
Functional cookies are used to enhance the user experience on the marketplace by enabling specific functionalities, such as remembering user preferences, settings, or actions. Unlike strictly necessary cookies, functional cookies are not essential for the basic operation of the website, but they significantly improve its usability and performance.
Cookie Name | Cookie Type | Purpose | Retention Period | Shared with Third Parties |
---|---|---|---|---|
Matomo | Analytical | Collects anonymized data about website usage (pages visited, session duration, etc.) to analyze and improve user experience. | 6 months | No |
Chatwoot | Functional | Allows Chatwoot to maintain the conversation when the user navigates through the website or revisits it later. | 7 Days | No |
If you have any questions or complaints about this Policy and Magani's cookie practices, you can contact us in writing using our contact form.
Who are the recipients of your Personal Information?
In certain circumstances, we may disclose your personal information to third parties for contract fulfillment purposes, to comply with legal obligations, legitimate purposes and other reasons subject to this Privacy Policy. Such circumstances may include:
- With vendors or other third parties who perform services on our behalf (e.g., IT management, payment processing, data analytics, customer support, cloud storage, fulfillment and shipping). The vendors are the Processor of the personal data related to the individual User.
- With business partners to provide services to you. Our business partners will use your information in accordance with their own privacy notices.
- When you direct, request us or otherwise consent to our disclosure of certain information to third parties, such as to ship you products or through your use of social media widgets or login integrations, with your consent.
- With our affiliates or otherwise across our organization, in our legitimate interests to run successful activities and provide quality Services.
The list of our current Processors and partners is available hereunder:
Name of the processor or partner | Processing activity carried out | Location |
---|---|---|
Mink | Maintenance of the Site | France |
Flutterwave | Payment service provider | Cameroun |
Axeptio | Consent management platform for Cookies | France |
Amex Healthcare | Drug supplier | Austria |
How long do we keep your Personal Information?
How long we retain your personal information depends on different factors, such as whether we need the information to maintain your account, to provide the Services, comply with legal obligations, resolve disputes or enforce other applicable contracts and policies.
Your Personal information will not be kept for longer than is necessary to achieve the purposes set out in section 3 of this Policy and to comply with the laws and regulations applicable to us. In particular:
- Personal information relating to prescription and the supply of drugs through our Services will be kept for 10 years to comply with our contractual obligations related to your purchase and our legal obligations regarding the dispensing of medicine.
- Transaction details will be kept for 10 years to comply with our legal obligations regarding accounting and fraud prevention.
Third Party Websites and Links
Our Site may provide links to websites or other online platforms operated by third parties. If you follow links to sites not affiliated or controlled by us, you should review their privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy or security of such sites, including the accuracy, completeness, or reliability of information found on these sites. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators, except as disclosed on the Services.
Children's Data
The Services are not intended to be used by children. We could collect personal and medical information about children, under the responsibility of their parent or guardian, only in case the treatment and / or prescription used for the order has been made for a child patient. If you are the parent or guardian of a child who has provided us with their personal information, you may contact us using the contact details set out below to request that it be deleted.
Security of Your Information
Appropriate technical and organizational measures are implemented to protect your personal information from loss, alteration or unauthorized disclosure.
For the Site in particular, the following measures are implemented :
- Strong authentification procedure to access the Site;
- Platform network segmentation;
- Encryption measures for data flows;
- Encryption measures for data at rest;
- Strict access management policy;
- Physical access control to the servers;
- History logs;
- Regular backups.
Please be aware that no security measures are perfect or impenetrable, and we cannot guarantee “perfect security.” We recommend that you do not use insecure channels to communicate sensitive or confidential information to us.
Your Rights
Depending on where you live, you may have some or all of the rights listed below in relation to your personal information. However, these rights are not absolute, may apply only in certain circumstances and, in certain cases, we may decline your request as permitted by law.
- Right to Access / Know: You may have a right to request access to personal information that we hold about you, including details relating to the ways in which we use and share your information.
- Right to Delete: You may have a right to request that we delete personal information we maintain about you.
- Right to Correct: You may have a right to request that we correct inaccurate personal information we maintain about you.
- Right of Portability: You may have a right to receive a copy of the personal information we hold about you and to request that we transfer it to a third party, in certain circumstances and with certain exceptions.
- Restriction of Processing: You may have the right to ask us to stop or restrict our processing of personal information.
- Withdrawal of Consent: Where we rely on consent to process your personal information, you may have the right to withdraw this consent.
- Objection and Managing Communication Preferences: you have the right to object at any time, for reasons relating to your particular situation, to the processing of your personal information. The exercise of this right can only be refused if we have legitimate and compelling reasons to continue the processing activities. Moreover, we may send you promotional emails, and you may opt out of receiving these at any time by using the unsubscribe option displayed in our emails to you. If you opt out, we may still send you non-promotional emails, such as those about your account or orders that you have made.
You may exercise any of these rights where indicated on our Site or by contacting us using the contact details provided below in section 13 of this Policy.
We will not discriminate against you for exercising any of these rights. We may need to collect information from you to verify your identity, such as your email address or account information, before providing a substantive response to the request. In accordance with applicable laws, you may designate an authorized agent to make requests on your behalf to exercise your rights. Before accepting such a request from an agent, we will require that the agent provide proof you have authorized them to act on your behalf, and we may need you to verify your identity directly with us. We will respond to your request in a timely manner as required under applicable law.
Complaints
If you have complaints about how we process your personal information, please contact us using the contact details provided below. If you are not satisfied with our response to your complaint, depending on where you live you may have the right to lodge your complaint with your local data protection authority.
International Users and data transfer
Please note that we may transfer, store and process your personal information outside of your country.
Contact
Should you have any questions about our privacy practices or this Privacy Policy, or if you would like to exercise any of the rights available to you, please call or email us at magani@paris.msf.org or contact us at Unit No: 3O-01-5799 Jewellery & Gemplex 3 Plot No: DMCC-PH2-J&GPlexS Jewellery & Gemplex, Dubai, United Arab Emirates.
For the purpose of applicable data protection laws and if not explicitly stated otherwise, MMP Access DMCC is the controller of the personal data related to the individual users.