Last updated: 15 September 2025 · Version 4.2
Plain-language summary. We collect only the data we need to respond to your inquiry or run our business. We do not sell data. We retain it for as long as we have a legal or operational reason to. You can ask us to show, correct or delete your data at any time by emailing dpo@amdis.me.
Contents
1. Controller & DPO
The data controller for the processing described in this policy is:
AMDIS d.o.o.
Bulevar Revolucije 24, 81000 Podgorica, Montenegro
Company reg. 5-0825412/001 · VAT: ME 02987651
Email: office@amdis.me · Phone: +382 20 670 000
Our Data Protection Officer can be reached at dpo@amdis.me or by post marked "For the DPO" at the address above. The DPO also serves as the contact point for the Agency for Personal Data Protection and Free Access to Information of Montenegro (Agencija za zaštitu ličnih podataka i slobodan pristup informacijama).
2. What we collect
We process the following categories of personal data, depending on how you interact with the Site:
| Category | Examples | Source |
|---|---|---|
| Identification | Name, salutation, professional title | Contact form, journal subscription, business inquiry |
| Contact details | Email, phone, country, organisation | Contact form, registration as partner |
| Professional | Role, organisation type, area of interest | Contact form topic selection |
| Message content | Free-text inquiry, RFP attachments | Contact form body |
| Technical | IP address, browser type, language | Server logs, cookie banner state |
| Consent records | Cookie consent timestamp & choice | localStorage / cookie |
We do not knowingly collect special-category data (health, ethnicity, religion, etc.) through the Site. If you include such information voluntarily in a message, we will treat it as confidential and limit further processing to responding to your request.
3. Purposes & legal basis
We process personal data for the following purposes under the legal bases defined in Article 6 of the GDPR and Article 12 of the Montenegrin Law on Personal Data Protection:
| Purpose | Categories | Legal basis |
|---|---|---|
| Responding to business inquiries | Identification, contact, message | Art. 6(1)(b) — performance of pre-contractual measures |
| Sending journal / insight updates you subscribed to | Email, topic preferences | Art. 6(1)(a) — consent (you may withdraw at any time) |
| Maintaining partner & supplier records | Identification, contact, professional | Art. 6(1)(b) / (f) — contract & legitimate interest |
| Pharmacovigilance reports you submit via contact form | Identification, contact, message | Art. 6(1)(c) — legal obligation under Directive 2010/84/EU transposed nationally |
| Operating the Site, preventing abuse | Technical, consent records | Art. 6(1)(f) — legitimate interest |
| Storing cookies other than strictly necessary | Technical, identification | Art. 6(1)(a) — consent |
4. Retention periods
We keep personal data only for as long as needed for the purpose for which it was collected, after which it is deleted or irreversibly anonymised:
| Category | Retention | Trigger |
|---|---|---|
| Contact-form inquiries (general) | 24 months | Last exchange |
| Pharmacovigilance reports | 10 years | Report submission (per EU GMP Annex 11/15 record-keeping) |
| Journal subscriptions | Until withdrawn | Unsubscribe link or DPO request |
| Partner & supplier records | 10 years post-termination | Contract end (statute-of-limitations / tax law) |
| Server access logs | 90 days | Log rotation |
| Cookie consent record | 12 months | Last visit |
5. Recipients & transfers
Personal data is shared with the following categories of recipients, only to the extent strictly necessary:
- Hosting & infrastructure providers — EU-based data centres; processing under Art. 28 GDPR data-processing agreements.
- Email service provider — used solely for transactional and consent-based outbound messages; located in the EU/EEA.
- Logistics partners — only the minimum shipping data required to deliver goods under signed commercial contracts.
- Regulators & courts — where we are under a binding legal obligation to disclose.
We do not transfer personal data outside the EU/EEA. Where a sub-processor is established in a third country, we use Standard Contractual Clauses (SCCs, 2021/914) and supplementary technical measures.
We do not sell personal data. We do not share personal data with advertising networks, data brokers or social-media platforms.
6. Your rights
You have the following rights in respect of your personal data. To exercise any of them, write to dpo@amdis.me — we will respond within one month (extendable by two further months for complex requests, with notice).
- Access — obtain a copy of the personal data we hold about you (Art. 15 GDPR).
- Rectification — have inaccurate or incomplete data corrected (Art. 16).
- Erasure — request deletion where the data is no longer necessary or our legal basis no longer applies (Art. 17). Note: pharmacovigilance records are exempt from erasure while their statutory retention period runs.
- Restriction — request temporary suspension of processing (Art. 18).
- Portability — receive data you provided to us in a structured, machine-readable format (Art. 20).
- Objection — object to processing based on legitimate interest (Art. 21), including profiling.
- Withdraw consent — at any time, with effect for the future (Art. 7(3)).
7. Cookies & analytics
The Site uses only a minimal set of cookies. Strictly necessary cookies (consent state, language preference) are set without consent because they are essential to the operation of the Site. We do not currently use third-party analytics, advertising or social-media tracking cookies.
For the full list, see our Cookie Policy.
8. Security
We protect personal data using a layered set of technical and organisational measures, including: HTTPS-only transport, encrypted backups, role-based access, two-factor authentication for staff, pseudonymisation in test environments, and a documented incident-response procedure aligned with ISO/IEC 27001 controls.
In the event of a personal-data breach that is likely to result in a risk to your rights, we will notify the Montenegrin supervisory authority within 72 hours of becoming aware of it and, where required, inform affected individuals without undue delay.
9. Children
The Site is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has submitted data to us, please contact the DPO so we can delete it.
10. Complaints
If you believe our processing of your personal data is unlawful, we encourage you to contact our DPO first so we can address the issue directly. You also have the right to lodge a complaint with:
- Montenegro: Agency for Personal Data Protection and Free Access to Information (Agencija za zaštitu ličnih podataka i slobodan pristup informacijama), Bulevar Svetog Petra Cetinjskog 145, 81000 Podgorica — azlp.me.
- EU/EEA: the supervisory authority of your habitual residence, place of work or place of the alleged infringement (Art. 77 GDPR).
11. Changes
We may update this policy to reflect changes in our processing activities or in the applicable law. The "last updated" date at the top of the document will always reflect the most recent change. For material changes, we will provide additional notice on the homepage for at least 30 days.
12. Contact
For any privacy-related question, please contact our DPO:
Data Protection Officer
AMDIS d.o.o. · Bulevar Revolucije 24, 81000 Podgorica, Montenegro
dpo@amdis.me · +382 20 670 000
Legal basis
EU Regulation 2016/679 (GDPR) · Montenegrin Law on Personal Data Protection (Zakon o zaštiti podataka o ličnosti, Official Gazette of Montenegro 40/2024) · EU Directive 2010/84/EU on pharmacovigilance (transposed nationally).