Privacy Notice – ACT against Afib

Privacy Notice

Last Revised: September 21, 2023

ACT against Afib (“ACT”) is a website built and maintained by AtriCure, Inc. (AtriCure) a medical device company that provides innovative solutions designed to decrease the global atrial fibrillation (Afib) epidemic. Our first responsibility is to the patients and customers we serve and as part of that service, ACT is committed to safeguarding your privacy.

Click here for the California Privacy Policy

1. GENERAL

Introduction. We know that your privacy is important to you, and we work hard to earn and keep your trust. AtriCure, Inc. (collectively with its subsidiaries and affiliates, “AtriCure,” “we,” “us,” and “our”), respects your privacy and is committed to protecting your privacy through our compliance with this Privacy Notice (the “Policy”). The words “you” and “your” refer to you as a user of the Website (defined below), either as a website visitor, job applicant, or healthcare professional.

This website is a website built and maintained by AtriCure. AtriCure is a medical device company that provides innovative technologies for the treatment of Atrial Fibrillation (Afib) and related conditions. We did our best to provide you with all information in a clear and readable format. However, if you have any questions about our use of your Personal Information after reading this Policy, you can of course always contact us through the contact details provided below.

Scope. This Policy describes:

  • The types of information we collect from you or that you may provide when you visit our website(s) available at: www.actagainstafib.com as well as any websites directly owned by AtriCure where this Policy is linked (collectively, our “Website”).
  • Our practices for collecting, using, maintaining, protecting, and disclosing that information.

This Policy applies to information we collect on the Website or in emails and other electronic messages between you and the Website, and information gathered when you interact with our advertising on third-party websites if such advertisements include links to this Policy.

This Policy does not apply to information collected by us offline or through any other means, including on any other website operated by AtriCure (that does not link to this Policy) or any third party, or information collected by any third party through any application or content (including advertising) that may link to or be accessible from the Website (for further information, see below, “Third-party Websites”).

Please read this Policy carefully to understand our practices regarding your information and how we will treat it. If you do not agree with our policies and practices, then please do not use our Website. By using our Website, you agree to the terms of this Policy. This Policy may change from time to time (see below, “Changes to this Policy”). Your continued use of the Website after we make changes is deemed to be acceptance of those changes, so please check the Policy periodically for updates.

2. CALIFORNIA PRIVACY DISCLOSURE; TERMS OF USE

This Policy is incorporated by reference and should be read in conjunction with AtriCure’s (1) California Privacy Disclosure and (2) Terms of Use.

3. THE INFORMATION WE COLLECT

Personal Information. To ensure that we provide you with the best possible experience, we will store, use, and disclose personal information about you in accordance with this Policy. Personal information is information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular user, household or device (“Personal Information”). The Personal Information that we may receive and collect depends on what you do when you visit our Website and on the relationship we have with you. For example, you may visit the website as a:

Website Visitor. The information you share with us when you are contacting us via e-mail or through online forms on our Website (first name, last name, e-mail address, phone, gender, message).

Health Care Professionals. Certain areas of the Website contain information intended only for health care professionals. Accordingly, AtriCure processes Personal Information of health care professionals. For example, when health care professionals request information from Medical Affairs, AtriCure processes their contact information (name, email address, mailing address and phone number, and their professional qualifications, including profession and clinical affiliation).

IMPORTANT INFORMATION RELATING TO HEALTH INFORMATION. While some of the information you provide or access through the Website may be health-related, the Website and any information you provide directly to it is not subject to the Health Insurance Portability and Accountability Act (“HIPAA”) nor is any information “protected health information” as defined under HIPAA.

NOT FOR MEDICAL ADVICE. The content provided on the Website is not provided for medical, clinical or other advice. The Website is not a substitute for professional medical diagnosis or treatment. SUCH WEBSITE CONTENT IS BEING PROVIDED “AS IS” AND “WITH ALL FAULTS” AND USERS SHOULD CONSULT WITH QUALIFIED PHYSICIANS FOR ANSWERS TO GENERAL AND SPECIFIC MEDICAL AND CLINICAL QUESTIONS.

Aggregated and De-Identified Data. We may collect, use and disclose aggregated and de-identified data such as statistical or demographic data for any purpose. Aggregated and de-Identified data could be derived from your Personal Information but is not considered Personal Information under applicable law as this data will not directly or indirectly reveal your identity. However, if we combine or connect aggregated or de-identified data with your Personal Information so that it can directly or indirectly identify you, we treat the combined data as Personal Information which will be used in accordance with this Policy.

Free-Text Boxes. The information that you provide in each case will vary. In some cases, you may be able to provide Personal Information via email or free text boxes, such as contacting AtriCure to request further information. When providing your Personal Information, please provide only relevant information and do not provide unnecessary sensitive information, such as Social Security numbers, credit card information or other sensitive personal data, unless required for our services.

Information of Other Individuals. You may have the opportunity to provide information of other individuals. When providing such information, you are solely responsible for obtaining the necessary consents and authorizations from any individuals in accordance with applicable data security laws and regulations, and AtriCure shall not be responsible or held liable for your failure to obtain the necessary consents.

Recording Use of the Website. We partner with trusted third-party vendors to analyze performance and traffic of our Website. This may include things like buttons you click, mouse movements and other behavior on the Website, date and time of access, pages visited, web beacons, and cookie or pixel tag information. Please see our Automatic Information Collection section below to learn more about cookies, pixels tags, and analytic technologies.

(a) INFORMATION WE MAY COLLECT ON THE WEBSITE

You may have the opportunity to provide Personal Information on our Website, including but not limited to:

  • Personal identifiers: first and last name; telephone number; email address.
  • Internet activity: browsing history; search history; information in relation to our Website.

(b) SOURCES OF INFORMATION COLLECTED

We may obtain the Personal Information listed above from the following categories of sources:

  • Directly from you. For example, when you:
    • complete any form or text field on our Website; or
    • otherwise communicate with us, such as contacting us for more information.
  • Publicly available sources.
  • Indirectly from you. For example, through information we collect from you in the course of providing our services to you.
  • Directly and indirectly from activity on our Website. For example, from Website usage details that are collected automatically. For more information on automatic information collection, please review the “Automated Information Collection” section below.

4. AUTOMATED INFORMATION COLLECTION

Website. In addition to the information that you provide to us, we may also collect information about you during your visit to our Website. We collect this information using automated tools that are detailed below. These tools may collect information about your behavior and your computer system, such as your internet address (IP Address), the pages you have viewed, and the actions you have taken while using the Website. Some of the tools we use to automatically collect information about you may include:

(a) Cookies. A “cookie” is a small data file transmitted from a website to your device’s hard drive. Cookies are usually defined in one of two ways, and we may use either (or both) of them:

  1. session cookies, which do not stay on your device after you close your browser, and
  2. persistent cookies, which remain on your device until you delete them or they expire.

We may use the following categories of cookies on our Website.

  1. Strictly Necessary Cookies. These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not work. These cookies do not store any of your Personal Information.
  2. Performance Cookies. These allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site and will not be able to monitor its performance.
  3. Functionality Cookies. These cookies remember choices you make such as the country from which you visit our Website, your preferred language, and your search parameters. This information can then be used to provide you with an experience more appropriate to your selections and to make your visits to our Website more tailored to your preferences. The information in these cookies may be anonymized. These cookies cannot track your browsing activity on other websites.
  4. Targeting Cookies or Advertising Cookies. These cookies collect information about your browsing habits in order to make advertising more relevant to you and your interests. Our website makes use of Google Analytics, as described below. If you choose not to allow these cookies, you will experience less targeted advertising.

Of course, if you do not wish to have cookies on your devices, you may turn them off at any time by modifying your internet browser’s settings. However, by disabling cookies on your device, you may be prohibited from full use of the Website’s features or lose access to some functionality.

(b) Google Analytics. Our website makes use of the Google Analytics web service from Google, Inc. Google Analytics also utilizes cookies. Examples of the items of data collected include your operating system, your browser, the AtriCure web page you accessed, and the time and date of your visit. The information generated by the text file about the use of the website will be transmitted to and stored by Google on servers in the United States. Google will use this information for the purpose of evaluating your use of our website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. Google may also transfer this information to third parties when required to do so by law, or where such third parties process the information on Google’s behalf. This use is made anonymously. For more information on how Google Analytics supports the Website and uses information sent from the Website, please review Google’s privacy policy available at https://policies.google.com/technologies/partner-sites.

(c) Web Beacons. A Web Beacon is an electronic image. Web Beacons can track certain things from your computer and can report activity back to a web server allowing us to understand some of your behavior. If you choose to receive emails from us, we may use Web Beacons to track your reaction to our emails. We may also use them to track if you click on the links and at what time and date you do so. Some of the third-party marketers we engage with may use Web Beacons to track your interaction with online advertising banners on our Website. This information is only collected in aggregate form and will not be linked to your Personal Information. Please note that any image file on a webpage can act as a Web Beacon.

(d) Embedded Web Links. Links provided in our emails and, in some cases, on third-party websites may include tracking technology embedded in the link. The tracking is accomplished through a redirection system. The redirection system allows us to understand how the link is being used by email recipients. Some of these links will enable us to identify that you have personally clicked on the link and this may be attached to the Personal Information that we hold about you. This data is used to improve our service to you and to help us understand the performance of our marketing campaigns.

(e) Third-party Websites and Services. We work with a number of service providers of marketing communications technology. These service providers may use various data collection methods to improve the performance of the marketing campaigns we are contracting them to provide. The information collected can be gathered on our Website and also on the websites where our marketing communications are appearing. For example, we may collect data where our banner advertisements are displayed on third-party websites.

5. HOW WE USE YOUR INFORMATION

The information we gather and that you provide is collected to provide you information and the services you request, in addition to various other purposes, including, but not limited to:

  • security, credit or fraud prevention purposes;
  • providing you with effective customer service;
  • providing you with a personalized experience when you use the Website;
  • developing new products and services;
  • contacting you with special offers and other information we believe will be of interest to you (in accordance with any privacy preferences you have expressed to us);
  • contacting you with information and notices related to your use of the Website;
  • inviting you to participate in surveys and providing feedback to us (in accordance with any privacy preferences you have expressed to us);
  • better understanding your needs and interests;
  • improving the content, functionality and usability of the Website;
  • improving our products and services;
  • improving our marketing and promotional efforts; and
  • any other purpose identified at the point of data collection, in an applicable privacy notice, in a click-through agreement or in any other agreement between you and us.

Duration. The length of time AtriCure intends to retain Personal Information, including sensitive personal information, if any, is for as long as reasonably necessary to carry out AtriCure’s intended business purpose for such information. Your Personal Information will be removed or made anonymous when your Personal Information is no longer necessary for the purposes for which the Personal Information is processed.

6. HOW WE DISCLOSE YOUR INFORMATION

We do not sell or lease your Personal Information to any third party. We may disclose your Personal Information to a third party for a business purpose, including the following categories of third parties:

  • Within Our Organization. As a global organization, data we collect may be transferred internationally throughout our worldwide organization, including our affiliates and parent and subsidiary companies, in order to provide our products, services and effective customer support. Our employees are authorized to access Personal Information only to the extent necessary to serve the applicable purpose and to perform their jobs.
  • Third-party Service Providers. We disclose Personal Information collected through the Website with third-party Service Providers who act for or on behalf of AtriCure. These third parties may need information about you to perform their functions. “Service Providers” may include suppliers, dealers, distributors, companies and consultants that provide website hosting, software development, payment processing, website and data analytics, order fulfillment, information technology and related infrastructure support, customer service, email delivery, and auditing. When Service Providers are given access to your Personal Information, we will take the required contractual, technical, and organizational measures to ensure that your Personal Information are only processed to the extent that such processing is necessary.
  • In Aggregate or De-Identified Form. We may aggregate or otherwise anonymize the data we collect for purposes of analytics, research, marketing and other business interests of AtriCure. Such use shall not include Personal Information or information that can identify you as an individual or reasonably be used to identify you.

Except as described in this Policy, we will not disclose your information with third parties without your notice and consent, unless it is under one of the following circumstances:

  • Legal Reasons.
    • We believe that disclosure is reasonably necessary to comply with any applicable law, regulation, subpoena, or court order;
    • To respond to duly authorized information requests from law enforcement or other governmental authorities;
    • To enforce our agreements or policies;
    • To investigate and prevent security threats, fraud, or other malicious activity; or
    • To respond to an emergency that we believe in good faith requires us to disclose such information to assist in preventing the death or serious bodily injury of any person or AtriCure employee.
  • Sale of Business or Merger. There are circumstances where AtriCure may decide to buy, sell, or reorganize its business. Under these circumstances, it may be necessary to disclose or receive Personal Information with prospective or actual purchasers, acquisition targets, partners or affiliates. In such circumstances, AtriCure will ensure your information is used in accordance with this Policy.

7. YOUR CHOICES AND SELECTING YOUR PRIVACY PREFERENCES

We want to provide you with relevant information that you have requested. When possible, we will always provide options as to what information we collect and how you can manage any preferences that pertains to such information.

8. ACCURACY AND ACCESS TO YOUR PERSONAL INFORMATION

We strive to maintain and process your information accurately. We have processes in place to maintain all of our information in accordance with relevant data governance frameworks and legal requirements. We employ technologies designed to help us maintain information accuracy on input and processing.

To view and change the Personal Information that you have provided to us, you can contact us directly for assistance.

9. INFORMATION OF MINORS

We do not knowingly collect or use information from individuals under the age of sixteen (16) without parental or guardian consent. We do not target the Website to minors, and would not expect them to be engaging with Website or services. We encourage parents and guardians to provide adequate protection measures to prevent minors from providing information unwillingly on the internet. If we are aware of any Personal Information that we have collected about minors under the age of sixteen (16), we will take steps to securely remove it from our systems.

10. FEEDBACK

We welcome inquiries or feedback on the services or products you might use or like to use. Any inquiries, feedback, suggestions, or ideas you provide to us (collectively, “Feedback”) will be treated as non-proprietary and non-confidential. Your Feedback on or through this Website may be available to others who visit this Website. In addition, we may use your Feedback in advertising campaigns and other promotions. We may or may not use your name in connection with such use, and we may or may not seek your consent before using the Feedback for such purposes. Therefore, you should have no expectation of privacy with respect to your Feedback on or through this Website. You should not submit any content you do not wish to make available to the general public, and you must take special care to make sure your Feedback comply with our Terms of Use or other applicable agreements. All terms and conditions of our Terms of Use apply to Feedback on or through this Website. In particular, your Feedback must not violate the privacy or other rights of others. You may not use false identifying information or contact information, impersonate any person or entity, or otherwise mislead us as to the origin of any Feedback.

11. THIRD-PARTY WEBSITES

This Policy does not apply to websites or other domains that are maintained or operated by third parties or our affiliates. Our Website may link to third-party websites and services. For example, if you click on an advertisement on the Website, you may be taken to another website that we do not control. These links are not endorsements of these websites, and this Policy does not extend to them. Because this Policy is not enforced on these third-party websites, we encourage you to read any posted privacy policy of the third-party website before using the service or website and providing any information.

12. YOUR CALIFORNIA RIGHTS

If you are a California consumer, as that term is defined under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, you may have additional rights to your Personal Information. For more information regarding these rights, please review our California Privacy Disclosure.

13. LOCATION OF OUR WEBSITE AND SERVICES

We do not warrant or represent that this Policy or the Website’s use of your Personal Information complies with the laws of every jurisdiction. Furthermore, to provide you with our services, we may store, process, and transmit information in the United States and other locations around the world, including countries that may not have the same privacy and security laws as yours. Regardless of the country in which such information is stored, we will process your Personal Information in accordance with this Policy.

14. FOR WEBSITE USERS OUTSIDE THE UNITED STATES

Under the (i) General Data Protection Regulation (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, or “GDPR”), (ii) Data Protection Act 2018, (iii) the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland (i.e., “UK GDPR”) as provided in the Data Protection Act 2018, and (iv) any other applicable data protection legislation of any country or other jurisdiction (collectively “International Data Protection Laws”) individuals have specific rights with respect to their Personal Information, or “personal data” as defined under the International Data Protection Laws. For the purposes of this Policy, AtriCure operates as a data controller. Any personal data we collect from you is processed under the terms of this Policy.

Any personal data we collect from you is processed in the legitimate interest of our business and providing our services to you as the lawful means of such processing. You may always withdraw your consent to our use of your personal data as described below. We will only retain your personal data for the time necessary to provide you the information and services to which you have consented, to comply with the law and in accordance with your rights below. Depending on the purpose for which we process the personal data and the relationship we have with you, the processing of the Personal Information is based on one of the following legal grounds. These “legal grounds” are set out in the International Data Protection Laws and allow Controllers to process Personal Information only when the processing is permitted by that legal ground. The table below provides a description of the legal grounds that we rely on:

For processing Personal Data and special categories of Personal Data
Legal ground Details
(1) Performance of our contract with you Processing is necessary for the performance of a contract to which you are party, or in order to take steps at your request prior to entering into a contract.
(2) Consent Processing based on your explicit consent; such consent may be withdrawn at any time.
(3) Compliance with a legal obligation Processing is necessary for compliance with a legal obligation under International Data Protection Laws to which we are subject.
(4) For our legitimate business interests Processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of your personal data.

The Data Controller is:

NAME: AtriCure, Inc.
ADDRESS: Privacy Office
7555 Innovation Way
Mason, OH 45040
EMAIL ADDRESS: privacy@atricure.com

You can exercise any of the following rights, subject to verification of your identity, by notifying us as described below:

  • Access. You may request a copy of the personal data our Website databases currently contain.
  • Automated Processing and Decision-Making. You may request that we stop using your personal data for automated processing, such as profiling. When contacting AtriCure, please explain how you wish us to restrict automated processing of your personal data. When such restrictions are not possible, we will advise you accordingly. You can then choose to exercise any other rights under this Policy, to include withdrawing your consent to the processing of your personal data.
  • Correction or Rectification. You can correct what personal data our Website database currently contains by emailing us (as provided below) to request that we correct or rectify any personal data that you have provided to us. We may not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause information to be incorrect. Where applicable, we will ensure such changes are shared with trusted third parties.
  • Restrict Processing. When applicable, you may restrict the processing of your personal data by submitting a request via email (to the email provided below). In your email, please explain how you wish us to restrict processing of your personal data. When such restrictions are not possible, we will advise you accordingly. You can then choose to exercise any other rights under this Policy, to include withdrawing your consent to the processing of your personal data. Where applicable, we will ensure such changes are shared with trusted third parties.
  • Object to Processing. When applicable, you have the right to object to the processing of your personal data by submitting a request via email to (to the email provided below). When such objections are not possible, we will advise you accordingly. You can then choose to exercise any other rights under this Policy, to include withdrawing your consent to the processing of your personal data. Where applicable, we will ensure such changes are shared with trusted third parties.
  • Portability. Upon request and when possible, we can provide you with copies of your personal data. When such a request cannot be honored, we will advise you accordingly. You can then choose to exercise any other rights under this Policy, to include withdrawing your consent. Where applicable, we will ensure such changes are shared with any trusted third parties.
  • Withdraw Consent. At any time, you may withdraw your consent to our processing of your personal data through this Website by notifying us via email (to the email provided below). Using the same email address associated with your Website account, simply type the words “WITHDRAW CONSENT” in the subject line of your email. Upon receipt of such a withdrawal of consent, we will confirm receipt and proceed to stop processing your personal data. Where applicable, we will ensure such changes are shared with trusted third parties.
  • Erasure. If you should wish to cease use of our Website and have your personal data deleted from our Website, then you may submit a request by emailing us at the email provided below. Upon receipt of such a request for erasure, we will confirm receipt and will confirm once your personal data has been deleted. Where applicable, we will ensure such changes are shared with trusted third parties.

Exercising your rights. If you are a data subject that has rights under the International Data Protection Laws, who chooses to exercise the rights listed above, you can submit a request via email at privacy@atricure.com.

Submit Complaints or Questions. If you wish to raise a complaint on how we have handled your personal data, you can contact us as described below. If you reside in a European Union member state or the United Kingdom, you may also lodge a complaint with the supervisory authority in your country.

15. SAFEGUARDING THE INFORMATION WE COLLECT

We use reasonable technical, administrative, and physical safeguards in order to protect your Personal Information against accidental loss and from unauthorized access, use, alteration, and disclosure. However, we can never promise 100% security. If you believe your information has been compromised, please notify us immediately.

16. CHANGES TO THIS POLICY

This Policy describes our current policies and practices with regard to the information we collect through the Website. We are continually improving and adding to the features and functionality of the Website along with the products and services we offer through the Website. If we make any changes to this Policy, a revised Policy will be posted on this webpage and the date of the change will be reported in the “Last Revised” block above. You can get to this page from any of our webpages by clicking on the “Privacy Notice” link (usually at the bottom of the screen).

17. HOW TO CONTACT US

We value your opinions and welcome your feedback. To contact us about this Policy or your Personal Information, please contact us by email at privacy@atricure.com or:

You may also write to us at:

AtriCure, Inc.
Privacy Office
7555 Innovation Way
Mason, OH 45040

A Dedicated Data Protection Officer has been assigned for data protection services to:

A. Cardoso
AtriCure B.V.
De Entrée 260
1101 EE Amsterdam
Netherlands
privacy@atricure.com