Legal · Provisional

Privacy Policy for Medical-Device Vigilance

How OrganoGEN Limited collects, uses, and protects personal data submitted in incident and adverse-event reports relating to OrganoGEN-distributed medical devices, under EU Regulation 2017/745 (MDR) Article 87 and the EU General Data Protection Regulation (EU) 2016/679.

In Short

If you submit an incident or adverse-event report to OrganoGEN regarding one of our distributed medical devices, this policy describes the personal data we collect, how we share it with the manufacturer and the Cyprus competent authority, and how to exercise your rights. Note that OrganoGEN distributes medical devices (governed by EU MDR 2017/745), not medicinal products; the regulatory regime described here is therefore medical-device vigilance, not pharmacovigilance. This wording is provisional and is being reviewed by Cyprus-licensed legal counsel before final publication.

Reporting a serious incident

If you have witnessed a serious incident or adverse event involving an OrganoGEN-distributed medical device, please contact OrganoGEN without delay: info@organogenbiotech.com or +357 95 707111. Serious incidents must also be reported to the manufacturer and may be reportable to the Cyprus competent authority under EU MDR 2017/745 Article 87.

1. Scope

This policy applies if you submit, on your own behalf or on behalf of an organisation, an incident report, adverse-event report, near-miss report, complaint, or related correspondence relating to a medical device that has been placed on the market by OrganoGEN Limited (acting as the authorised representative or distributor under EU MDR 2017/745) or distributed in Cyprus by OrganoGEN.

This policy supplements the general Privacy Policy. For surgeon CRM and clinical-marketing activities, see the Healthcare Professionals Privacy Policy instead.

2. What personal data we collect

OrganoGEN collects only the personal data necessary to receive, document, and forward a medical-device vigilance report:

From the reporter (you)

  • Name and professional role.
  • Organisation (hospital, clinic, or pharmacy).
  • Work address, email, and phone number for follow-up.
  • The content of your report (incident description, device identifier or UDI, batch / lot number, date and place of incident, clinical outcome).

About the affected patient (where the report concerns a specific patient)

OrganoGEN collects only the minimum information necessary to characterise the incident, in keeping with the data-minimisation principle (Article 5(1)(c) GDPR):

  • Initials or anonymised identifier (not full name unless statutorily required by the receiving authority).
  • Gender, age or date of birth (where clinically relevant to the incident).
  • Clinical information necessary to characterise the incident: indication for the device, the device implanted or used, the adverse event, treatment given, clinical outcome.

OrganoGEN does not routinely collect full patient names, national identifiers, or other directly identifying data for vigilance reports submitted by healthcare professionals. Where a patient self-reports directly to OrganoGEN, we collect only the minimum necessary contact information to acknowledge the report and direct the patient to their treating clinician.

3. How and why we use personal data

OrganoGEN uses vigilance-report personal data only to:

  • Acknowledge receipt of your report.
  • Document the report in OrganoGEN's vigilance file under EU MDR 2017/745 Article 87(2)(a) (distributor obligations).
  • Forward the report to the relevant manufacturer ("the legal manufacturer") promptly, in the form required by the manufacturer's vigilance procedure.
  • Report serious incidents to the Cyprus competent authority where required by EU MDR 2017/745 and Cyprus law.
  • Contact you for clarification, follow-up information, or to communicate the outcome of the manufacturer's or competent authority's investigation.
  • Maintain post-market surveillance records as required by EU MDR 2017/745 Article 83 and Annex III.

OrganoGEN does not use vigilance data for any other purpose, including marketing.

4. How we obtain your personal data

OrganoGEN receives vigilance personal data only when you (or your organisation) provide it to us, by email, phone, post, or in person.

5. Legal basis for processing

OrganoGEN relies on the following Article 6(1) GDPR bases, and on the special-category data conditions under Article 9(2) GDPR for the clinical health data that necessarily accompanies a vigilance report:

  • Article 6(1)(c) legal obligation. The primary basis. EU MDR 2017/745 Articles 83 (post-market surveillance), 87 (vigilance reporting), and 93 (registration of devices and economic operators) impose legal obligations on OrganoGEN as a distributor or authorised representative to receive, document, and forward incident reports.
  • Article 6(1)(c) + Article 9(2)(i) GDPR. For the special-category health data that necessarily accompanies a vigilance report, processing is "necessary for reasons of public interest in the area of public health" (Article 9(2)(i)), specifically "ensuring high standards of quality and safety of health care and of medicinal products or medical devices."
  • Article 6(1)(f) legitimate interest. Secondary basis for post-market surveillance, where the legitimate interest is the safe distribution of CE-marked medical devices in Cyprus, balanced against the rights and freedoms of the data subject (and minimised by the data-minimisation principle in section 2 above).

6. Data retention

OrganoGEN retains vigilance reports for the period required by EU MDR 2017/745 and by the contractual agreement with the relevant manufacturer:

  • For non-implantable devices: at least 10 years after the device covered by the report has been placed on the market.
  • For implantable devices: at least 15 years after the device covered by the report has been placed on the market (EU MDR Article 10(8)).
  • Longer retention may apply where required by the receiving competent authority or by the manufacturer's vigilance procedure.

7. Who has access to your personal data

OrganoGEN shares vigilance personal data only with:

  • Authorised OrganoGEN personnel. Andreas Samourides as founder and quality manager, and any other authorised personnel acting under written confidentiality.
  • The legal manufacturer of the device covered by the report. The manufacturer acts as a separate data controller (or, in some cases, a joint controller) for vigilance reports, under written agreements compliant with EU MDR 2017/745 and the GDPR.
  • The Cyprus competent authority. Where the report meets the threshold for mandatory notification under EU MDR 2017/745 Article 87 and Cyprus implementing legislation, OrganoGEN will report it to the Cyprus competent authority for medical devices. Reports may include or be linked to entries in the European Database on Medical Devices (EUDAMED).
  • Other competent authorities and Notified Bodies. Where the manufacturer or competent authority requires onward sharing, for example to the manufacturer's Notified Body for CE-mark certification follow-up.
  • OrganoGEN's professional advisors. Cyprus-licensed legal and quality-management advisors, under written confidentiality obligations.

OrganoGEN does not share vigilance data with marketing, advertising, or other third parties unrelated to vigilance.

8. Transfer of personal data outside the EEA

OrganoGEN's primary processing is within the European Economic Area. Where the legal manufacturer is established outside the EEA (for example Aspire Medical Innovation in the United States, Tulip Medical in the United States, or Auxein Medical in India), OrganoGEN transfers vigilance reports to the manufacturer under one of the safeguards in Chapter V GDPR:

  • European Commission adequacy decisions, where available for the destination country.
  • Standard Contractual Clauses approved by the European Commission under Article 46(2)(c) GDPR.
  • Article 49 derogations where strictly necessary for public-health reasons (for example "necessary for important reasons of public interest", Article 49(1)(d)).

A list of recipient countries and applied safeguards is available on request to the privacy contact below.

9. How we protect your personal data

OrganoGEN applies the same technical and organisational measures described in section 10 of the general Privacy Policy. Vigilance files are stored in restricted-access folders, kept separate from general business correspondence, and access is limited to authorised personnel with a documented need to know.

10. Your rights under GDPR

Subject to the conditions set out in the GDPR, you have the right to access, rectification, restriction, objection, and complaint as described in sections 13 and 14 of the general Privacy Policy. Note the following specific limitations for vigilance data:

  • Erasure may be limited. OrganoGEN may be unable to delete vigilance reports before the end of the statutory retention period (section 6 above) because the data is required by EU MDR 2017/745 for ongoing post-market surveillance.
  • Objection may be limited. The legal basis for vigilance processing is principally Article 6(1)(c) (legal obligation) and Article 9(2)(i) (public interest in public health); these are not bases against which Article 21 GDPR objection applies.

To exercise any right or raise a concern, email info@organogenbiotech.com.

11. Status and contact

This wording is provisional and will be reviewed by Cyprus-licensed legal counsel (with specialist medical-device vigilance experience) before final publication.

OrganoGEN Limited · Souliou 12, Mesa Geitonia, Limassol 4000, Cyprus
Vigilance reports, privacy and general enquiries: info@organogenbiotech.com · Phone: +357 95 707111

Last revision date: 2026-05-13. Version: 1.0 (provisional, pre-counsel-review).

mail_outlineGET IN TOUCH
arrow_back
Privacy: Vigilance
Legal · Provisional

Privacy Policy for Medical-Device Vigilance

How OrganoGEN handles personal data in incident and adverse-event reports for OrganoGEN-distributed medical devices, under EU MDR 2017/745 Article 87 and the EU GDPR. Provisional wording, pending counsel review.

Reporting a serious incident. If you have witnessed a serious incident involving an OrganoGEN-distributed device, contact OrganoGEN without delay: info@organogenbiotech.com or +357 95 707111.

In short

This policy describes the personal data we collect when you submit an incident or adverse-event report, how we share it with the manufacturer and the Cyprus competent authority, and how to exercise your rights. OrganoGEN distributes medical devices (governed by EU MDR 2017/745), not medicinal products: the regime here is medical-device vigilance, not pharmacovigilance.

1. Scope

Applies if you submit an incident, adverse-event, near-miss report, or complaint relating to a medical device placed on the market by OrganoGEN, or distributed in Cyprus by OrganoGEN. Supplements the general Privacy Policy.

2. What we collect

From you: name, role, organisation, work address/email/phone, the content of your report (incident description, UDI, batch number, date and place, clinical outcome).

About the affected patient (minimum necessary): initials/anonymised ID, gender, age or DOB if relevant, clinical information necessary to characterise the incident. Not full patient names or national identifiers unless statutorily required.

3. How we use it

To acknowledge receipt, document under EU MDR Article 87(2)(a), forward to the manufacturer, report serious incidents to the Cyprus competent authority, contact you for follow-up, and maintain post-market surveillance records (EU MDR Art. 83 and Annex III). Not used for marketing.

4. How we obtain it

Only when you (or your organisation) provide it to us, by email, phone, post, or in person.

5. Legal basis

Primarily Article 6(1)(c) GDPR (legal obligation under EU MDR Articles 83, 87, 93) and Article 9(2)(i) GDPR (public-interest health data). Secondary: Article 6(1)(f) legitimate interest in safe device distribution.

6. Retention

Non-implantable devices: ≥10 years after market placement. Implantable devices: ≥15 years (EU MDR Art. 10(8)). Longer if required by the competent authority or manufacturer.

7. Who has access

Authorised OrganoGEN personnel; the legal manufacturer of the device; the Cyprus competent authority for medical devices (may be linked to EUDAMED); other competent authorities or Notified Bodies as required; OrganoGEN's legal/QMS advisors. Not marketing or unrelated third parties.

8. International transfers

Where the manufacturer is outside the EEA (e.g., Aspire and Tulip in the USA, Auxein in India), transfers rely on European Commission adequacy decisions, Standard Contractual Clauses, or Article 49 derogations for important public-health reasons.

9. Security

Same measures as section 10 of the general Privacy Policy. Vigilance files are stored in restricted-access folders, kept separate from general correspondence, access limited to authorised personnel with a documented need to know.

10. Your rights

Access, rectification, restriction, objection (limited), and complaint. Note: erasure and objection rights are limited for vigilance data because the legal bases (Art. 6(1)(c) and 9(2)(i)) are not bases under which Article 21 objection applies, and vigilance reports must be retained for the statutory period. Email info@organogenbiotech.com to raise a concern.

11. Status and contact

Provisional wording, pending Cyprus-licensed legal counsel review (specialist medical-device vigilance experience).

OrganoGEN Limited · Souliou 12, Mesa Geitonia, Limassol 4000, Cyprus · Vigilance reports, privacy and general enquiries: info@organogenbiotech.com

Last revision: 2026-05-13. Version 1.0 (provisional, pre-counsel-review).