Select Your Country or Region

You are now at UK (English)

Privacy Policy

Introduction

This Privacy Notice explains how Arjo UK Ltd uses personal data about customers, customer representatives, consumers, contacts, suppliers, patients and leads. It explains what personal data we use, why we use it, where it may be processed, who it may be shared with and what rights individuals have.

Arjo UK Ltd is part of the Arjo group and supports Arjo’s business activities in the UK. In this notice, “Arjo”, “we”, “us” and “our” refer to Arjo UK Ltd.

 

Who is processing the personal data?

Arjo UK Ltd is the data controller for most of the personal data described in this notice. This means we decide why and how that personal data is used. To make this notice easier to read, Arjo UK Ltd is referred to as Arjo for the rest of this document. If you have any questions or concerns about how we use your personal data, you can contact us using the details below:

Arjo UK Ltd

Morton House, Kimpton Road, Luton, LU2 0HL

01582 745700

dataprivacy@arjo.com.

Arjo aims to handle personal data lawfully, fairly and responsibly. Please contact us if you have any questions or concerns about how we use your personal data. We have also appointed a local Data Protection Lead who can help with privacy-related questions. For Arjo UK Ltd, this is:

James Stone

Director, IT Governance

01582 745700

dataprivacy@arjo.com.

 

What personal data are we processing?

The personal data we use depends on who you are and your relationship with Arjo.

Customer or supplier representatives

This includes people who work for Arjo customers or suppliers, including those who provide services or products to Arjo. We may use the following types of personal data:

·         Identifiers –

o    Name

o    Job title

·         Contact data –

o    Phone number

o    Email address

·         Location data –

o    Address

o    IP address

·         Financial data –

o    Banking details

The contact, location and financial information we use is usually business-related. It may come directly from individuals or from the organisation they work for.

Webinar platform users

·         Identifiers –

o    Name

o    Job title

·         Contact data –

o    Email address

·         Location data –

o    Address

o    IP address

·         Audio / visual data –

o    Photos (only when provided by the platform user).

The contact and location information we use is usually business-related. It may come directly from you or from the organisation you work for.

Commercial leads and prospects

Before you become an Arjo customer, we may collect personal data from you when you subscribe to marketing materials, sign up for webinars or education sessions, or show interest in Arjo, our products or our services. We may use the following types of personal data:

·         Identifiers –

o    Name

o    Job title

·         Contact data –

o    Email address

·         Location data –

o    Address

o    IP address

Patients using Arjo products

In some cases, customers provide us with patient information. We use this information only where necessary for the purpose for which it was provided. This may include the following:

·         Identifiers –

o    Name

·         Location data –

o    Address

Why are we processing personal data?

We use personal data for the reasons listed below.

Representatives of customers, contacts and suppliers and webinar platform users

  • We use personal data to manage the production and delivery of our products and equipment, fulfil customer orders and requests, support customer representatives, handle complaints or issues, and manage claims. We rely on legitimate interests for this processing where we have assessed that our business need does not unfairly affect people’s rights and freedoms.
  • We also use personal data to meet our legal and regulatory obligations, keep accurate administrative and accounting records, and manage queries, concerns and investigations.

Where customers provide patient data to us, we use it only where necessary for the purpose for which it was provided. This may include supporting customer requests, handling complaints, investigating product-related issues, meeting legal or regulatory obligations, or keeping quality and safety records. We aim to use as little patient data as possible and avoid using information that directly identifies a patient unless it is necessary.

Leads and prospects

  • We use personal data for marketing activities, where permitted by law.

We do not sell personal data.

 

Which lawful basis do we use for processing personal data?

Arjo only processes personal data where we have a lawful reason to do so. For the personal data described in this Privacy Notice, we rely on the following lawful reasons:

Lawful basis for processing

Processing activities

Your explicit consent – this means you have clearly agreed to the processing.

You are able to withdraw your consent at any time. You can do this by contacting dataprivacy@arjo.com.

Marketing activities and managing our relationship with you as an Arjo contact.

Legal obligation — this means we need to use the data to comply with the law.

Activities linked to our regulatory and statutory requirements.

Legitimate interests — this means we have a business reason to use the data, and we have assessed this against people’s rights and freedoms.

Marketing activities, managing our relationship with you as an Arjo contact, managing product and equipment distribution, and fulfilling customer orders and requests.

 

Where we rely on a legal obligation, this means we need to use personal data to meet legal or regulatory requirements.

Sometimes we rely on legitimate interests to use personal data. Before doing this, we assess our interests and consider the needs, expectations, rights and freedoms of the people affected. We only rely on legitimate interests where we believe our interests are reasonable and do not unfairly affect individuals. For private customers or consumers, we may also use personal data where this is needed to enter into or perform a contract with the individual.

 

For how long do we process your personal data?

We keep personal data for as long as we need it for the purpose it was collected. We may keep personal data for longer where the law requires this, for example under medical device regulations. Arjo has processes in place to help make sure we do not keep personal data for longer than necessary.

Information regarding representatives of customers and contacts

  • Most commercial, customer and financial information, such as purchase, order and order history, is kept for five years.
  • As a global organisation in a highly regulated field, we need to retain information relating to production, distribution, quality, or performance of any of our products for 15 years in accordance with strict European and global regulatory obligations. Where these records contain personal data, it is usually limited and low risk.
  • Information relating to a customer service case is kept until the matter is resolved. It may then be kept in a de-identified format for 15 years.
  • Information collected with consent is kept for as long as it remains relevant, and for no longer than six months after consent is withdrawn.

Information regarding prospects and leads

  • Information collected with consent is kept for as long as it remains relevant, and for no longer than six months after consent is withdrawn.

 

Where are we processing personal data and who do we transfer personal data to?

Sometimes we use suppliers who process personal data outside the UK. Where possible, we use suppliers in countries that the UK recognises as providing an adequate level of data protection. This means the country has data protection laws that the UK considers to provide appropriate protection. To learn more about countries with adequacy decisions, please see the Information Commissioner’s Office website. In some cases, we may need to use suppliers in countries that do not have a UK adequacy decision, including India. In these cases, we assess the privacy and transfer risks and put appropriate safeguards in place. These may include data processing agreements and approved standard contractual clauses. If those safeguards are not enough, we will only proceed where another valid legal safeguard applies, such as obtaining your consent where appropriate.

 

We use different systems and platforms to manage personal data. Some of our key processors are listed below:

 

·         Advanced Applications.

·         AWS.

·         Bishopsgate.

·         CEVA.

·         Descartes.

·         Digital Space.

·         MyMediset.

·         ON24.

·         Salesforce.

·         Tech Mahindra.

·         Other subsidiaries of the Arjo group as part of global functions.

 

 

We also use Microsoft Office storage and productivity tools for business activities such as commercial, production, logistics, operational, research and administrative work.

 

 

We may also share personal data with partners, or where needed to meet legal or regulatory obligations. We only share personal data where we have a lawful reason to do so. Before sharing personal data, we may carry out privacy and transfer risk assessments to check that appropriate safeguards are in place.

 

How are we processing personal data?

Arjo uses technical and organisational measures to help keep personal data secure and handled appropriately. These measures include:

·         Arjo has policies covering IT, information security, acceptable use of IT devices and data protection compliance.

·         We manage access using the principle of least privilege, meaning people only get the access they need for their role. We review access quarterly and require users to have individual, non-shared usernames.

·         Administrator access is limited to appropriate system and database owners with the necessary skills and training.

·         We use a change management process to review, approve and manage system changes.

·         Where Arjo controls the hosting solution, access to systems is restricted through our VPN. Data and systems are protected using encryption at rest and in transit, and users must sign in with individual credentials to access the data they are authorised to use.

·         Third parties that host or work on Arjo systems are risk assessed at least annually.

·         Arjo has an incident management process run by our Service Management team.

·         We manage software patches as part of our service management processes.

·         We carry out penetration testing and vulnerability management to help identify and address security weaknesses.

·         We arrange annual third-party IT audits.

As indicated above, we use a number of systems, platforms and resources to process your personal data.

We do not use automated decision-making, except to monitor the success of marketing activities. This may include creating a profile based on how our online resources are used. We use this information only to help us understand how Arjo can support you. We do not use this information in a way that removes or limits your data protection or legal rights. A person can review any evaluation if needed. If you have any questions or concerns about the potential use of automated decision making, please contact dataprivacy@arjo.com.

 

What are your rights in relation to this data processing?

Under data protection law, you have several rights about how your personal data is used. These include:

Ø  Your right of access – You can ask us for a copy of the personal data we hold about you. This helps you understand what personal data we hold and how we use it. This right applies where information identifies you and is about you. If a record also contains personal data about other people, we may remove or hide that information to protect their privacy. If someone else asks for access to a record that includes your personal data, we will remove or hide your personal data where appropriate. The law also allows some exemptions, for example where legal privilege or confidentiality applies. If we cannot provide some information because an exemption applies, we will explain this where appropriate.

 

Ø  Your right to be informed – You have the right to understand how we use your personal data. This Privacy Notice is one way we explain this. We may also provide information through FAQs, contracts or discussions. If you have questions about how we use your personal data, you can contact us at dataprivacy@arjo.com.

 

Ø  Your right to rectification – You can ask us to correct personal data you think is inaccurate. You can also ask us to complete personal data that you think is incomplete. Where appropriate, we will also ask relevant processors to correct the personal data they hold on our behalf. We will manage this process and will not ask you to contact our processors separately.

 

Ø  Your right to erasure – You can ask us to delete your personal data where we no longer need it, or where you withdraw consent and there is no other lawful reason for us to keep it. Arjo is required to keep some records to meet legal or regulatory obligations. This means we may not be able to delete every record about you. If this applies, we will explain why. Where appropriate, we will also ask relevant processors to delete the personal data they hold on our behalf.

 

Ø  Your right to restriction of processing – You can ask us to limit how we use your personal data in certain circumstances, for example while we check whether the data is accurate or still needed.

 

Ø  Your right to object to processing – You can object to our use of your personal data in certain circumstances. This right applies where we rely on legitimate interests, including certain profiling activities. If you object, we must show strong legitimate reasons to continue using the personal data for that purpose.

 

Ø  Your right to data portability – You can ask us to provide certain personal data in a reusable format or ask us to transfer it to another organisation where technically possible. This right usually applies where we use personal data based on your consent or because it is needed for a contract. It only applies to personal data that you provided to Arjo yourself.

 

Ø  Your right regarding automated decision-making – You can ask for a person to review any profiling or automated decision-making that affects you.

 

Ø  Your right to withdraw consent – Where we rely on your consent, for example for certain marketing activities, you can withdraw your consent at any time.

 

For more information about your data protection rights, please visit the Information Commissioner’s Office website.

 

You usually do not have to pay a fee to exercise your rights. If you make a request, we will usually respond within one month.

To make a request, please contact us using the details below.

Arjo UK Ltd

Morton House, Kimpton Road, Luton, LU2 0HL

01582 745700

dataprivacy@arjo.com.

You also have the right to complain to a data protection authority. For Arjo UK Ltd, the relevant data protection authority is the Information Commissioner’s Office, also known as the ICO. You can contact the ICO using the details below:

Information Commissioner’s Office

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

0303 123 1113

Using the online form.

If the ICO is not your local data protection authority, you may contact your local authority for advice on how to proceed.

 

Last updated August 2026.