Privacy Policy

CTLS PRIVACY POLICY
Please take the time to read the following information carefully so that you fully understand our views and practices regarding your personal data and how we will use it. You must be over 18 years old to use our Site.

  1. 1. WHO DOES THIS PRIVACY POLICY APPLY TO?

This privacy policy (and any other documents referred to in it) (this Policy) applies to:

  • people who simply visit clintrialslab.com (our Site);
  • people who book a volunteer appointment via our Site or offline;
  • people who contact us for anything else; and
  • companies who supply products and/or services to us.

This Policy does not apply to people who donate blood, saliva, serum, plasma or urine to us. You will be asked to sign a separate consent form which will detail how we will process your personal data in respect of your donation.

This Site is not intended for children and we do not knowingly collect data relating to children.

It is important that you read this Policy together with any other privacy policy or fair processing policy we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your personal data. This Policy supplements other notices and privacy policies and is not intended to override them.

  1. 2. WHO WE ARE

You can read about who we are and what we do here.

For the purposes of the Data Protection Act 2018 and General Data Protection Regulation ((EU) 2016/679) (DP Laws), Clinical Trials Laboratory Services Limited is the controller and responsible for your personal data. If you have any questions regarding this Policy or believe we have breached DP Laws, please contact us at info@clintrialslab.com or write to us at Unit 3, Acorn Centre, 30-34 Gorst Road, London, NW10 6LE.

You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.

  1. 3. ABOUT THIS POLICY

This Policy sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. By using our Site, you accept the practices described in this Policy.

This Policy is effective on and from 25 May 2018. We may amend this Policy at any time, and whenever we do so we will notify you by posting a revised version on our Site or emailing you. Please review this Policy each time you visit our Site as it may have been updated since your last visit.

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us (see http://www.clintrialslab.com/?page_id=8 ). If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.

This Policy is provided in a layered format so you can consult the specific areas set out below.

  • Visitors to our Site
  • Making a Volunteer Appointment
  • Making other enquiries and requests for information from us
  • Supplying to us
  • Transferring personal data outside the EEA
  • Your rights
  • How we protect your personal data
  • Marketing
  • Links to third party websites
  1. 4. VISITORS TO OUR SITE

Personal data we collect: With regard to each of your visits to our Site, we will automatically collect:

  • Technical information, including the Internet Protocol (IP) address used to facilitate your connection to the Internet, browser type and version, time zone setting, browser plug-in types and versions, hardware information; and
  • Information about your visit, including the full Uniform Resource Locators (URL) clickstream to, through and from our Site (including date and time); services, products, publications and articles you viewed or searched for; page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), methods used to browse away from the page.

We also collect, use [and share] Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate information about how you use our Site to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this Policy.

Cookies: Our Site uses cookies to distinguish you from other users of our Site. This helps us to provide you with a good experience when you browse our Site and also allows us to improve our Site. Cookies are text files placed on your computer to collect standard internet log information and visitor behaviour information. This information is used to track visitor use of our Site and to compile statistical reports on website activity. You can enable or disable cookies by modifying the settings in your browser. You can find out how to do this, and find more information on cookies, at www.allaboutcookies.org.

Using your personal data: We will use this information for the following legitimate interests (whether ours or a third party’s):

  • to maintain our Site and keep it safe and secure;
  • to protect the rights, property or safety of CTLS, our customers, suppliers, contacts or others (we will also use your information where we are required by law to do so);
  • to improve our Site and ensure that content is presented in the most effective manner for you and for your device(s);
  • for internal operations (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data);
  • to measure or understand the effectiveness of our Site and/or any marketing we serve to you and others, and to deliver relevant marketing to you;
  • to deal with any issues you have reported with our Site;

We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us (see http://www.clintrialslab.com/?page_id=8 ).

Sharing your personal data: We will only share personal data with third parties in the following instances:

 

  • our employees, contractors and agents (but their use shall be limited to the performance of their duties and in line with the reason for processing);
  • when information about you is processed by our third party IT support provider (acting as a processor), for the purposes of providing IT support to us;
  • with analytics and search engine providers (acting as processors) that assist us in the improvement and optimisation of our Site;
  • our website hosting supplier (acting as a processor) to enable them to maintain and host our Site; and/o

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

Retaining your personal data: This information is kept for 10 years in electronic format and 5 years as hard copy and will then be deleted automatically. However:

  • if we are required by law to retain it for longer, we will retain it for the required period; and/or
  • where the information is being used in connection with legal proceedings (including prospective legal proceedings) it will be retained for the duration of those legal (and any enforcement) proceedings.
  1. 5. MAKING A VOLUNTEER APPOINTMENT

Personal data we collect: If you contact us or we contact you (by phone, email or otherwise) in connection with an appointment, we will collect your name, date of birth, height, weight, email address, phone number, address and any other non-sensitive personal data you choose to give us. We will also collect sensitive personal data such as your gender, blood group, details of any medical conditions and any other sensitive personal data you choose to give us.

We do not record calls.

Using your personal data: We will use your name, date of birth, height, weight, email address, phone number, address and any other non-sensitive personal data for the following legitimate interests (whether ours or a third party’s), namely to schedule an appointment for you to make a blood donation.

We will only use your sensitive personal data (namely your gender, blood group, details of any medical conditions and any other sensitive personal data you choose to give us) with your explicit consent.

We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us (see http://www.clintrialslab.com/?page_id=8 ).

Sharing your personal data: We will only share personal data with third parties in the following instances:

  • our employees, contractors and agents (but their use shall be limited to the performance of their duties and in line with the reason for processing);
  • when information about you is processed by our third party IT support provider (acting as a processor) for the purposes of providing IT support to us;
  • our third party website hosting supplier (acting as a processor) to enable them to maintain and host our Site;
  • various third parties (acting as processors) who provide tools and cloud solutions to enable our business to operate (including email, instant messaging, document management and file-sharing) (acting as processors);
  • with professional advisers (acting as processors or joint controllers) including lawyers, auditors and insurers based in the United Kingdom who provide legal, accounting and insurance services to us;
  • when information about you is shared with our regulators and other authorities (acting as processors or joint controllers) based in the United Kingdom who require reporting of processing activities in certain circumstances;
  • if we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets;
  • where we are required by law to do so;
  • with our telephony supplier (which would get to see phone numbers if we call you) and our broadband supplier (which could see email addresses (but not the content of what you send us, if you encrypt it)) (acting as processors);

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

Retaining your personal data: This information is kept for 10 years in electronic format and 5 years as hard copy and will then be deleted automatically. However:

  • if we are required by law to retain it for longer, we will retain it for the required period; and/or
  • where the information is being used in connection with legal proceedings (including prospective legal proceedings) it will be retained for the duration of those legal (and any enforcement) proceedings.
  1. 6. MAKING OTHER ENQUIRIES AND REQUESTS FOR INFORMATION FROM US

Personal data we collect: If you contact us or we contact you (by phone, email or otherwise) for any other reason, we will collect your name, email address and any other information you choose to give us.

We do not record calls.

Using your personal data: We will use this information for the following legitimate interests (whether ours or a third party’s), namely to respond to any your enquiry or request for information.

Sharing your personal data: We will only share personal data with third parties in the following instances:

  • our employees, contractors and agents (but their use shall be limited to the performance of their duties and in line with the reason for processing);
  • when information about you is processed by our third party IT support provider (acting as a processor) for the purposes of providing IT support to us;
  • our third party website hosting supplier (acting as a processor) to enable them to maintain and host our Site;
  • various third parties (acting as processors) who provide tools and cloud solutions to enable our business to operate (including email, instant messaging, document management and file-sharing) (acting as processors);
  • with professional advisers (acting as processors or joint controllers) including lawyers, auditors and insurers based in the United Kingdom who provide legal, accounting and insurance services to us;
  • when information about you is shared with our regulators and other authorities (acting as processors or joint controllers) based in the United Kingdom who require reporting of processing activities in certain circumstances;
  • if we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets;
  • where we are required by law to do so;
  • with our telephony supplier (which would get to see phone numbers if we call you) and our broadband supplier (which could see email addresses (but not the content of what you send us, if you encrypt it)) (acting as processors);

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

Retaining your personal data: This information is kept for 10 years in electronic format and 5 years as hard copy and will then be deleted automatically. However:

  • if we are required by law to retain it for longer, we will retain it for the required period; and/or
  • where the information is being used in connection with legal proceedings (including prospective legal proceedings) it will be retained for the duration of those legal (and any enforcement) proceedings.
  1. 7. SUPPLYING TO US 

Personal data we collect: If you contact us or we contact you (by phone, email or otherwise) in connection with supply services, goods and/or software to us, we will hold your name, email address, phone number location and height, weight and blood group if known(including any other details that appear on your business card which you provide to us).

We may also collect:

  • information and documentation that we obtain about you and your business from publicly available information (e.g. your website, social media and Companies House) when we carry out research (this is to ensure that we understand you and your business);
  • information about you from social media platforms including when you interact with us on those platforms or access our social media content (the information we may receive is governed by the privacy settings, policies, and/or procedures of the applicable social media platform, and we encourage you to review them);
  • information about you on CCTV cameras if you visit our offices (CCTV cameras are used for crime prevention and public safety);

We do not record calls.

Using your personal data: We will use this information for the following legitimate interests (whether ours or a third party’s):

  • to enable us to perform our contract with the company who is supplying services, goods and/or software to us, or to take steps to enter into such contract;
  • to manage payments, fees and charges due under our contract;
  • to manage our relationship with the company who is supplying services, goods and/or software to us including notifying changes to our terms or this Policy and keeping our records updated;

We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us (see http://www.clintrialslab.com/?page_id=8 ).

Sharing your personal data: We will only share personal data with third parties in the following instances:

  • our employees, contractors and agents (but their use shall be limited to the performance of their duties and in line with the reason for processing);
  • when information about you is processed by our third party IT support provider (acting as a processor), for the purposes of providing IT support to us;
  • when information about you is processed by our accounting software which is owned, hosted and supported by a third party software provider (acting as a processor);
  • various third parties who provide tools and cloud solutions to enable our business to operate (including email, instant messaging, document management and file-sharing) (acting as processors);
  • with professional advisers (acting as processors or joint controllers) including lawyers, bankers, auditors and insurers based in the United Kingdom who provide legal, banking, accounting and insurance services to us;
  • when information about you is shared with our regulators and other authorities (acting as processors or joint controllers) based in the United Kingdom who require reporting of processing activities in certain circumstances;
  • if we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets;
  • where we are required by law to do so;
  • with our telephony supplier (which would get to see phone numbers if we call you) and our broadband supplier (which could see email addresses (but not the content of what you send us, if you encrypt it)) (acting as processors);

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

Retaining your personal data: This information will be kept for the duration of our contract with the company who is supplying services, goods and/or software to us and then for 10 years in electronic format and 5 years as hard copy thereafter. However:

  • if we are required by law to retain it for longer, we will retain it for the required period; and/or
  • where the information is being used in connection with legal proceedings (including prospective legal proceedings) it will be retained for the duration of those legal (and any enforcement) proceedings.
  1. 8. TRANSFERRING PERSONAL DATA OUTSIDE THE EEA (EEA CITIZENS/RESIDENTS ONLY)

Whenever we transfer your personal data out of the European Economic Area, we will ensure a similar degree of protection is afforded to it. In some instances, your personal data may be transferred to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. In other instances, we will ensure at least one of the lawful safeguards are implemented, which may include:

  • Where we transfer personal data to certain external third parties, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe, including standard contractual clauses; or
  • Where we use external third parties based in the US, we may transfer personal data to them if they are part of the EU-US Privacy Shield which requires them to provide similar protection to personal data shared between Europe and the US.

Further details can be provided upon request, please contact us:

(see http://www.clintrialslab.com/?page_id=10 ).

  1. 9. YOUR RIGHTS (EEA CITIZENS/RESIDENTS ONLY)

In relation to personal data we hold about you, you have the right to:

  • where we process your personal data based on your consent, to withdraw your consent easily and at any time (withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal data conducted in reliance on lawful processing grounds other than consent);
  • get access to your personal data that we hold and receive information about our processing of it;
  • ask us to correct the record of your personal data maintained by us if it is inaccurate or to complete incomplete personal data;
  • ask us, in certain instances, to erase your personal data or cease processing;
  • object to us processing your personal data for direct marketing purposes
  • challenge us processing your personal data which has been justified on the basis of our legitimate interests;
  • ask us, in certain instances, to restrict processing personal data to merely storing;
  • request portability of your personal data in certain instances;
  • not to be subject to automated decision making (including profiling) in certain circumstances;
  • prevent processing that is likely to cause damage or distress to you and seek compensation from us for any damages caused to you by us breaching DP Laws;
  • be notified of a personal data breach which is likely to result in high risk to your rights and freedoms; and
  • complain to the ICO if you believe we have breached DP Laws (please contact the ICO via ico.gov.uk).

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.

If you would like to exercise any of these rights, please contact us:

(see http://www.clintrialslab.com/?page_id=10 ).We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

We try to respond to all legitimate requests within one calendar month (starting from the day after we receive your request). Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

  1. 10. HOW WE PROTECT YOUR PERSONAL DATA 

To help protect the privacy of personal data you transmit, we maintain physical, technical and administrative safeguards and require the same of any third parties we share your personal data with. We update and test our security technology on an ongoing basis. In addition, we train our staff about the importance of confidentiality and maintaining the privacy and security of your personal data.

As you will be aware the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your personal data transmitted to our Site; any transmission is at your own risk. Once we have received your personal data, we will use physical, technical and administrative safeguards to prevent unauthorised access to your personal data.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

  1. 11. MARKETING

Third-party marketing: We will get your express opt-in consent before we share your personal data with any third party for marketing purposes.

Opting out: You can ask us or third parties to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you or by contacting us (see http://www.clintrialslab.com/?page_id=8 ) any time. Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of a product/service purchase, product/service experience or other transactions. Please note that if you ask us not to contact you by email at a certain email address, we will retain a copy of that email address on a “suppression list” in order to comply with your no-contact request.

You are free to change your marketing choices at any time.

  1. 12. LINKS TO THIRD PARTY WEBSITES

Our Site may, from time to time, contain links to and from the websites of third party websites. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.

Our Site uses interfaces with social media sites such as Facebook, LinkedIn, Twitter and others. If you choose to “like” or share information from our Site through these services, you should review the Policy of that service. If you are a member of a social media site, the interfaces may allow the social media site to connect your Site visit to your personal data.