Privacy Notice

Dear user,

This document describes how your data will be processed when you access www.devitecpharma.com (hereinafter referred as “Website” or “Marketplace”) and when you purchase goods on it.

Data Controller and contacts
“Devintec Sagl” (hereinafter referred as “us”, “Devintec”, or the “Controller”) is the data Controller. The Controller can be contacted by e-mail at privacy@devitecpharma.com or at the registered office in Switzerland at Lugano, Corso Elvezia 14 – 6900.

2. Categories of personal data processed

The processing involves the use of the categories of personal data listed below.

Identification data: first name, last name, date of birth, IP address;

Data collected by cookies: if you accept the installation of cookies and other trackers, they will process personal data about you in accordance with our cookie policy, depending on their purpose;

Navigation data: data relating to the way you interact with the website, transmitted by mean on the internet protocol.

3. Data processing purposes and legal basis

Personal data will be processed for specific purposes, on the basis of a legal basis, which is the justifying reason

provided for by law. The table below indicates these purposes and, for each of them, the supporting legal basis

and the categories of data processed.

PURPOSE DESCRIPTION LEGAL BASIS DATA
Website connection Enable website connection Performance of a service requested by the data subject (Art. 6(1)(b) GDPR) Navigation data
Service improvement Analysing user activity to identify improvements to the browsing experience Legitimate interest of the data controller in improving its product (art. 6(1)(f) GDPR) Data collected by cookies
Security Infrastructure security management Legitimate interest of the data controller in ensuring product safety (art. 6(1)(f) GDPR) Navigation data
Legal compliance Fulfilment of legal obligations in tax and accounting matters Execution of legal obligations (art. 6(1)(c) GDPR) Identification data, data collected by cookies
Litigation Defending and/or enforcing the controller's rights in court Legitimate interest of the data controller in defending its rights in court (art. 6(1)(f) GDPR) Identification data, data collected by cookies, navigation data

Below you can find detailed information for each of the purposes described.

Website management

In order to ensure the stability of the connection to the Website and the normal operation of network protocols,
some navigation data is used. The Controller pursues this purpose in order to provide a service requested by

the user (art. 6(1)(b) of the GDPR).

Service improvement

Information about user activity is used to evaluate improvements to the service. For example, information about
the malfunctioning of a page could be used to modify its functioning. The processing is carried out on the basis
of the data controller’s legitimate interest in improving the functioning of the application and the user experience,
within the meaning of Article 6(1)(f) of the GDPR. Some of the data used for this purpose will be collected through the use of cookies and tracking, in accordance with our cookie policy.

Security

Information about users’ activities on the system, and in particular the logs generated, are used for security purposes, such as detecting anomalous behaviour and potential cyber-attacks. The processing is carried out on the basis of the data controller’s legitimate interest in ensuring the security of the infrastructure and the personal data stored (Article 6(1)(f) GDPR).

Legal compliance

Some data is processed in order to comply with specific legal obligations, such as tax obligations and to demonstrate how we register and store users’ consent. The processing is carried out as necessary to comply with a legal obligation (Art. 6(1)(b) GDPR).

Litigation

In the event of a dispute between Devintec and the user, the data may be used to prove Devintec’s rights in court or to defend against the user’s legal claims. In this case, it is not possible to foresee the specific information that will be processed, but only the data necessary to prove the rights of the data Controller will be processed.
The processing is carried out on the basis of the data controller’s legitimate interest in defending its rights in court (Article 6(1)(f) of the GDPR).

4. Cookies and trackers

This Website uses cookies and other tracking tools to ensure the smooth operation of the network, to carry out statistical surveys and re-marketing activities.
You can choose which cookies you wish to install, depending on the purpose, by clicking on the cookie banner that appears when you first visit the Website, and you can subsequently change your preferences by using the “Cookie preferences” function, accessible from the bottom left-hand corner of the Website’s home page.
For more information on the operation of these trackers, please consult the Website’s cookie policy.

5. Data retention

Your personal data will be kept for as long as necessary to fulfil the purpose for which it was collected.
Usage data and navigation data are kept for a maximum of 1 year, and information processed for the fulfilment of legal obligations is kept for a maximum of 10 years, depending on the applicable legislation. Data processed for the purposes of legal defence will be processed until the relevant judgement has become final.

6. Circulation of Personal Data and Transfers Abroad

Data will be stored in a server based in the European Union. It is possible that data will be transferred to countries outside the EEA and Switzerland. In this case, the transfer will only take place once all legal requirements for the transfer have been met, in accordance with applicable law.
The Controller only transfer data to countries who provide an adequate level of protection of personal data,
relying on the decision of an international organisation (such as the Swiss Parliament or the European Commission) or on the subscription of specific binding clauses.

7. Data proving

Providing personal information is optional. However, you may not be able to access some or all of the features of the application without providing it.

8. How personal data are protected

We undertake to implement the appropriate technical and organisational measures necessary to maintain and guarantee the confidentiality, integrity and security of personal data and to prevent such personal data from any loss, misuse, alteration or unauthorised access. Similarly, we periodically check its systems to identify any vulnerabilities and attacks. The servers used by the controller are ISO27001 certified, which guarantees the security of the information they contain.

9. User’s rights on personal data

At any time, and where applicable, you may request from the Controller to access, rectify and delete your data. If you believe that your personal data have been processed in violation of applicable data protection laws, you have the right to lodge a complaint with the competent Data Protection Authority or take legal action before the competent court pursuant.

10. Definitions and Useful Information

Below you will find a list of definitions and useful explanations to help you understand this notice:

Processing of personal data: any operation performed on personal data (e.g., storing, reading,

archiving, or viewing data);

Data controller: the entity (or entities) that determine how and why personal data is processed, and that

are responsible for ensuring its protection;

Data processor: third parties who process personal data on behalf of the controller (e.g., IT service

providers);

Data subject: you – the individual whose personal data is processed and to whom this notice is

addressed;

Purpose of processing: the reason the data controller uses your personal data.

Last update: 26/06/2025