Panther Healthcare UK — Privacy Policy
1. Who we are
Panther Healthcare UK is a brand operated by LaproSurge Limited (“LaproSurge”, “we”, “us”, “our”) under licence from Panther Healthcare Medical Equipment Co., Ltd. LaproSurge is the data controller responsible for the personal data we collect and process via the Panther UK website and brand activities. We are a UK-based medical device company and the UK distributor of Panther Healthcare’s surgical stapling devices.
Registered office: Sas House Friarswood, Chipperfield Road, Kings Langley, Hertfordshire, United Kingdom, WD4 9JB
Company number: 02046470
ICO registration: ZB996659
Website: www.pantherhealthcare.co.uk
For any data protection enquiries, please contact us at admin@laprosurge.com or by post at the address above, marking your correspondence “Data Protection.”
2. The personal data we collect
We collect and process personal data in the course of operating our business. The categories of personal data we process include:
- Contact details: names, job titles, business email addresses, telephone numbers, and business postal addresses of our customers, distributors, NHS contacts, clinicians, and key opinion leaders
- Transactional data: purchase history, order details, invoicing information, and payment records
- Commercial communications: emails, meeting notes, call logs, and correspondence relating to our business activities
- Marketing data: preferences in receiving marketing communications, engagement with our emails and content, and event attendance records
- Website data: IP addresses, browser type, device information, pages visited, and cookie data (see section 11 below)
- Supplier data: names and contact details of individuals at our suppliers and third-party service providers
- Recruitment data: information provided by applicants for employment
We do not knowingly collect or process special category personal data (such as health, racial, or religious data) in the ordinary course of our business. Personal data relating to our current and former employees is handled separately under our Employee Privacy Notice, provided to employees directly. This Privacy Policy does not cover employee data processing beyond the recruitment stage.
3. How we collect personal data
We collect personal data from the following sources:
- Directly from you when you contact us, place an order, request information, attend an event, sign up to our communications, or visit our website
- In person when you meet our sales representatives, attend a product demonstration, visit our stand at an exhibition or trade event, or otherwise share your contact details with our team in the course of business
- From your employer or organisation when they engage with us
- From publicly available sources such as company websites, LinkedIn, and professional directories where we identify potential customers, distributors, or clinical contacts
- From third parties such as event organisers, NHS Supply Chain, distribution partners, and suppliers
- Automatically through our website via cookies and analytics tools
4. Lawful bases for processing
Under UK GDPR, we rely on the following lawful bases for processing personal data:
- Performance of a contract: where we process your data to fulfil orders, deliver goods, provide services, or perform a distribution agreement
- Legitimate interests: where we process your data for the day-to-day operation of our business, including managing customer relationships, marketing to existing customers and prospects in the medical device sector, business development, and improving our products and services
- Legal obligation: where we are required to process your data to comply with our legal and regulatory obligations, including medical device traceability under UK MDR, tax law, accounting law, and product safety regulations
- Consent: where we have asked for and obtained your specific consent, for example for marketing communications to new contacts who are not existing customers
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and you have the right to object to such processing at any time (see section 9).
5. How we use your personal data
We use personal data for the following purposes:
- Processing and fulfilling orders, including dispatch and invoicing
- Managing relationships with customers, distributors, and clinical contacts
- Communicating with you about your orders, our products, and your account
- Sending marketing communications about our products and services where lawful to do so
- Managing our website and improving our online presence
- Conducting market research and business development activities
- Complying with our regulatory obligations, including medical device vigilance and traceability
- Defending or pursuing legal claims
- Recruitment
6. Marketing
We may send you marketing communications about our products and services where we have a lawful basis to do so. You can opt out of marketing communications at any time by:
- Clicking the unsubscribe link in any marketing email we send
- Contacting us at admin@laprosurge.com
- Updating your preferences with us directly
Opting out of marketing communications will not affect transactional communications that we are required to send you in connection with your orders, services, or our legal obligations.
7. Who we share your data with
We share personal data with third parties only where necessary to deliver our services and with appropriate safeguards in place. We do not sell personal data to third parties, and we do not share personal data for the marketing purposes of any third party.
Categories of recipients include:
- Couriers and logistics providers: to deliver goods to you
- Payment processors and banking partners: to process payments
- Professional advisers: including accountants, auditors, and solicitors
- Regulatory authorities: including the MHRA where required for medical device reporting
- Our distribution and supply partners: including distributors through whom we sell, manufacturers and suppliers from whom we source goods, and the brand owners of products we distribute under licence, where personal data sharing is necessary for order fulfilment, product vigilance, complaints handling, or commercial reporting under our commercial arrangements
Key third-party processors:
- HubSpot: for customer relationship management and marketing operations. HubSpot data for LaproSurge is hosted in the European Economic Area (Germany). HubSpot acts as a data processor under a Data Processing Agreement compliant with UK GDPR.
- Mailchimp: for email marketing campaigns. Mailchimp is operated by Intuit Inc. and processes data in the United States. This involves a restricted transfer of personal data outside the United Kingdom, which is lawful under the UK Extension to the EU-US Data Privacy Framework and the UK International Data Transfer Agreement, both of which form part of Mailchimp’s Data Processing Agreement with us.
- Sage 200: for accounting and financial records. Sage 200 data is hosted in the United Kingdom.
Each of these processors is contractually bound to process personal data only in accordance with our instructions and to maintain appropriate technical and organisational security measures.
8. International data transfers
Most personal data we process is held within the United Kingdom or the European Economic Area, both of which benefit from adequacy decisions under UK GDPR. Where personal data is transferred outside these jurisdictions, we ensure that appropriate safeguards are in place as required by UK GDPR.
We make the following international transfers:
- To the European Economic Area (Germany) via HubSpot, our customer relationship management platform. This transfer is covered by the UK’s adequacy decision for the EEA.
- To the United States via Mailchimp, our email marketing platform. This transfer is lawful under the UK Extension to the EU-US Data Privacy Framework and Standard Contractual Clauses incorporated in our Data Processing Agreement with Mailchimp.
- To Panther Healthcare in China, in connection with specific events such as product complaints, adverse incident investigations, regulatory vigilance reporting, and commercial reporting under our brand licence and distribution arrangement. This transfer is safeguarded by Standard Contractual Clauses under the UK International Data Transfer Agreement or UK Addendum to the EU SCCs, alongside a documented Transfer Risk Assessment.
You may request a copy of the safeguards in place for any international transfer by contacting us using the details in section 1.
9. Your data subject rights
Under UK GDPR you have the following rights in relation to your personal data:
- Right of access: to be informed of and request a copy of the personal data we hold about you
- Right to rectification: to have inaccurate or incomplete personal data corrected
- Right to erasure: to request that we delete your personal data in certain circumstances
- Right to restriction: to restrict our processing of your personal data in certain circumstances
- Right to data portability: to receive your personal data in a structured, commonly used, machine-readable format
- Right to object: to object to our processing of your personal data, including for direct marketing
- Right to withdraw consent: where we rely on consent, you may withdraw it at any time
- Right to lodge a complaint: with the Information Commissioner’s Office (see section 13)
To exercise any of these rights, please contact us using the details in section 1. We will respond within one month of receiving your request. Some rights are subject to exceptions, and we will explain if any exception applies to your request.
10. How long we retain your personal data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting requirements. Typical retention periods are:
- Customer and order records: for the duration of the customer relationship plus 7 years thereafter for tax and accounting purposes
- Medical device traceability records: for at least 10 years after the last device covered by the record was placed on the market, in accordance with UK MDR requirements
- Marketing data: until you opt out, or for up to 3 years from your last engagement with us, whichever is sooner
- Website analytics data: typically up to 26 months
- Recruitment data: for 6 months after the conclusion of a recruitment process for unsuccessful candidates, unless we have your consent to retain for longer
After the applicable retention period, personal data is securely deleted or anonymised.
11. Cookies
Our website uses cookies and similar technologies. Cookies are small text files placed on your device to help the site function, to remember your preferences, and to help us understand how visitors use the site.
We use the following categories of cookies:
- Strictly necessary cookies: required for the website to function and cannot be switched off
- Performance and analytics cookies: help us understand how visitors interact with the website
- Functional cookies: remember your choices and preferences to improve your experience
- Marketing cookies: used to track visitors across websites and display relevant advertisements
You can accept or reject non-essential cookies via the cookie banner displayed when you first visit our website, and you can change your preferences at any time via the cookie settings link in the website footer. You can also control cookies through your browser settings — see www.aboutcookies.org for guidance.
12. Security
We take the security of personal data seriously and have appropriate technical and organisational measures in place to protect against unauthorised access, loss, misuse, or disclosure.
LaproSurge is certified under Cyber Essentials Plus, the UK government-backed cyber security certification scheme, which independently verifies that we have effective controls in place against common cyber threats. Our certification covers boundary firewalls, secure configuration, access control, malware protection, and patch management.
In addition to our Cyber Essentials Plus controls, we maintain:
- Access controls limiting personal data to authorised personnel on a need-to-know basis
- Encryption of data in transit and at rest where appropriate
- Secure hosting environments operated by reputable providers
- Regular staff training on data protection and information security
- Contractual security obligations on our third-party processors
No method of transmission over the internet is completely secure, and while we do our best to protect your data, we cannot guarantee its security in transit.
13. Complaints
If you have any concerns about how we process your personal data, please contact us in the first instance using the details in section 1. We take all complaints seriously and will investigate and respond promptly.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
- Information Commissioner’s Office: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
- Telephone: 0303 123 1113
- Website: www.ico.org.uk
14. Changes to this policy We may update this Privacy Policy from time to time. The latest version will always be available on our website, and the “Last updated” date at the top of this policy will indicate when it was most recently revised. Material changes will be communicated to you where appropriate.