NUVASIVE® PRIVACY NOTICE
Effective Date: 1/1/2020
Thank you for visiting this NuVasive, Inc. (“NuVasive,” “we,” or “us”) owned Internet website (“Site”) located at www.nuvasive.com. This Privacy Notice describes how NuVasive collects, uses, and shares the information that you provide to us through your use of the Site or any NuVasive owned website, service, or web-based and mobile application (collectively, “Services”) that link to this Privacy Notice.
The Data Controller
NuVasive Inc., with registered office in the United States, and which can be contacted at the following address 7475 Lusk Blvd, San Diego CA 92121, +1.858.909.1800, [email protected] is the data controller of the processing of your personal information collected through the Site and Services.
Information We Collect
We can collect identifying data, such as for instance name, surname, email address, residence, and any other information that you voluntarily provide by communicating with us, such as by sending an email or submitting an online information request form.
Additionally, we can collect any other personal information that you choose to provide to us through our Services. This includes information you provide to us (or our service provider) to apply for a job. Other information provided through a job application may include, for example, your educational and employment background, your contact information, and immigration status.
Data Collected Automatically
To learn more about cookies, similar technologies and the choices offered to control these types of activities, click here to view our Cookies Notice.
If there are any changes to our practice in the future, this will be reflected in an updated Privacy Notice.
Use and Disclosure of Information
If you do voluntarily provide personal data through our Site or Services, we may use this information to provide you the business service or to respond to your requests (including to consider you for employment).
Furthermore, we may send you communications in order to provide other information that we think may be of interest to you. Please see below the "Marketing Communications" section for more information on your options for such communications.
We may process personal data in order to fulfil legal obligations relevant to us.
NuVasive, Inc. does not sell personal data as it is defined in the California Consumer Privacy Act (CCPA). To the extent permitted by applicable local law, we may provide your personal information to other entities - which can process your data as our processors or as autonomous controllers - as described in this section:
- We may provide your personal information to our parent, subsidiary, and affiliate entities within our corporate family and our partner entities that are not within our corporate family.
- In the United States, we may use your personal information to communicate with you via email or share with vendors and service agencies that we may engage to assist us in providing our Services to you. For example, we may provide your personal information to a marketing, research, or advertising agency to send advertising to you on our behalf.
- We may release any information, including personal information, in response to court and governmental orders, civil subpoenas, or discovery requests where permitted by applicable local law, and as otherwise required by law. We cooperate with law enforcement agencies in identifying those who may be using our servers or services for illegal activities. We also reserve the right to report any suspected illegal activity to law enforcement entities for investigation or prosecution.
- We may transfer your personal information to a successor entity in connection with a merger, acquisition, consolidation, or other corporate reorganization in which NuVasive participates or to a purchaser of all or substantially all of NuVasive’s assets to which this Site relates, including a sale in bankruptcy where permitted by applicable local law.
- We may also share your personal information with your consent, such as if we ask your permission to use your testimonial in our advertising. You can withdraw such consent at any time.
You may request for us to provide an accurate list of our processors by writing to the email contact below.
In jurisdictions that require prior consent for marketing communications, we may send you promotional e-mails if you have consented to receiving such communication. At any time, you may revoke your consent for the receipt of communications that NuVasive sends to you by following the unsubscribe process or contacting us at [email protected]. Please follow the instructions in our emails to unsubscribe from receiving future marketing communications from us.
Please note that even if you unsubscribe from newsletters and promotional emails, we may still need to contact you with important transactional information about your account or your equipment.
Legal Basis for the Processing
NuVasive will only process (i.e. use) your personal data when the law allows us to, that is, when we have a legal basis for processing.
We use your personal data in the following circumstances:
- Performance of a contract: where we need to perform a contract which we are about to enter into or have entered into with you as a party or to take steps at your request before entering into such a contract;
- Legal or regulatory obligation: where we need to comply with a legal or regulatory obligation that we are subject to;
- Legitimate interests: where necessary for our interests (or those of a third party), provided that your fundamental rights do not override such interests. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests; and
- Consent and explicit consent: where you have provided your consent to processing your personal data.
NuVasive does not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).
We only rely on consent as the legal basis for processing your personal data where it is required by applicable local law (for instance, in relation to some of our electronic marketing). You have the right to withdraw your consent at any time. When you withdraw your consent, we will stop the data processing.
Data Retention Period
NuVasive will keep your personal data for as long as is reasonably necessary or required by law for the purpose of the processing.
Purpose Limitation and Data Integrity
NuVasive will only process personal information in a way that is compatible with and relevant to the purpose for which it was collected or authorized for by the individual. NuVasive will take reasonable steps to ensure that personal information is accurate, complete, current, secure, and reliable for its intended use.
Your Data Access Rights
NuVasive respects your rights concerning your personal information. Accordingly, you have the right, subject to necessary validation of your identity, to:
- Request confirmation whether your personal data is being processed;
- Request correction of inaccurate personal data relating to you;
- Object to NuVasive's processing of your personal data for direct marketing;
- Oppose processing based on our legitimate interest for reasons relating to your particular situation;
- We may continue to process your personal data, even if you have opposed the processing, if we have compelling legitimate grounds for the processing which overrides your privacy interest.
- Request (under certain circumstances) the restriction of the processing of your personal data; and
- Lodge a complaint with a Data Protection Authority if you have concerns about our practices regarding the processing of personal data.
Additionally, you have the right to access your personal information. You may request a copy of your personal data, which, upon proper verification of your identity, NuVasive will provide in a structured format and, if technically feasible, transfer the data to another data controller (data portability). You may also request:
- The categories of personal information we collected about you;
- The categories of sources for the personal information we collected about you;
- Our business or commercial purposes for collecting that personal information;
- The categories of third parties with whom we share that personal information; and
- The categories of personal information about you that we disclosed to third parties for a business purpose and the categories of recipients of that information.
Furthermore, you have the right to request that we delete your personal information. Depending on the nature of the data, deletion may consist of erasing, aggregating, or anonymizing your information. After we receive and validate your request, we will delete and direct our service providers to delete your personal information, unless an exception applies. We may deny your deletion request, in whole or in part, if retaining the information is necessary for us or our service providers to:
- Complete the transaction for which we collected the personal information, provide a service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform a contract with you;
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities;
- Debug to identify and repair errors that impair existing intended functionality;
- Enable solely internal uses that are reasonably aligned with your expectations based on your relationship with us or make other internal and lawful uses of that information that are compatible with the context in which you provided it; or
- Comply with a legal obligation.
Exercising Your Rights
You may, without charge, request to review, know, correct, update, delete, or restrict or object to the processing of your personal information at any time by calling +1.858.909.1800 or emailing us at [email protected].
Only you or an authorized agent may make a request to access your personal information. The request must:
- Provide sufficient information for us to reasonably verify you are the person or an authorized representative of the person about whom we collected the personal information; and
- Describe your request with sufficient detail for us to properly understand, evaluate, and respond to it.
For your safety and the safety of your information, we cannot fulfill a request to provide or to delete personal information if we cannot:
- Verify your identity or your authority to make the request; and
- Confirm the personal information relates to you or to an individual for whom you are a lawful agent.
We may require additional verification before deleting or disclosing particularly sensitive information. We will not use the verification information you provide for any purpose other than verifying your identity or authority to make the request.
Submitting a request does not require you to create an account with us. However, we do consider requests made through your password protected account sufficiently verified when the request relates to personal information associated with that specific account.
Links to Third Party Sites
We employ procedural and technological security measures that are designed to protect your personally identifiable information from loss, unauthorized access, disclosure, alteration, or destruction.
Users Outside of United States
If you are visiting our Site from locations outside of the United States, please note that any information you provide to us through your use of the Site may be transferred to and processed in countries other than the country from which you accessed this Site, including the United States where our computer systems are currently based.
Please be aware that your personal data may also reside on servers in other countries. Your data may be transferred to the United States and other countries, which may not offer an equivalent level of protection as that in your country. For visitors from the European Economic Area, note that NuVasive has signed the EU Standard Contractual Clauses adopted by the European Commission with non-EEA service providers in order to ensure that an adequate level of data protection is provided according to local standards. Upon request, we will make a copy of these clauses available to you.
This Site is not intended for children under the age of 18. NuVasive does not target its services or this Site to children under 18. NuVasive does not knowingly collect personal information from children under the age of 18. In the case of NuVasive unconsciously collecting such information, NuVasive will promptly delete and/or destroy it.
Privacy Notice Updates
NuVasive may need to update this Privacy Notice on occasion. If we update this Privacy Notice, we will post the updated Privacy Notice on our Site and update the effective date at the top of the notice. We encourage you to regularly visit this Privacy Notice to ensure that you are aware of our current practices with respect to any information that you provide to us through the Site.
Questions / Data Protection Officer
Please contact our data protection officers if you have any further questions, suggestions, or requests regarding data protection at the following email addresses:
United States, Puerto Rico, Australia, New Zealand, Singapore, and Brazil:
Netherlands and Germany, Italy, UK, Switzerland, Austria, Poland, Sweden, and Finland:
If you have any questions regarding this Privacy Notice, please contact us via email at [email protected].