(Note that if you donate at one of our facilities, some of the above information relating to your health, gender, sexual orientation and other matters will be collected in order to meet government regulations intended to ensure the safety of the blood supply. We may also collect data about race, ethnicity, smoking status, medications you have used, and similar types of information related to your donation for scientific research purposes. However, before we ask for any type of sensitive personal data, you will be informed and asked to consent to the collection.)
This Site is not intended for children and we do not knowingly collect data relating to children.
You have the right to make a complaint at any time to a data protection authority about our collection and use of your personal data. For more information, please contact your local data protection authority. Contact details for data protection authorities in the European Economic Area, Switzerland and certain non-European countries (including the US and Canada) are available here. We would, however, appreciate the chance to deal with your concerns before you approach a data protection authority so please contact us in the first instance.
By using our Site, you accept the practices described in this Policy.
This Policy is effective on and from July 31, 2019. We may amend this Policy at any time, and whenever we do so we will notify you by posting a revised version on our Site or emailing you. Please review this Policy each time you visit our Site as it may have been updated since your last visit.
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us (see Who we are and our DPO). If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
Personal data we collect: With regard to each of your visits to our Site, we will automatically collect:
We also collect Aggregated Data such as statistical or demographic data. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate information about how you use our Site to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this Policy.
Using your personal data: We will use this information for the following legitimate interests (whether ours or a third party’s):
We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us (see Who we are and our DPO).
Sharing your personal data: We will only share personal data with third parties in the following instances:
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
Retaining your personal data: This information is kept for up to 2 years and will then be deleted automatically. However:
We share your personal data within BioIVT, our parent company, and to the external third parties (the categories of which are referred to in this Policy). This may involve transferring your data outside the European Economic Area (EEA). Whenever we transfer your personal data out of the EEA, we will ensure a similar degree of protection is afforded to it. In some instances, your personal data may be transferred to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. In other instances, we will ensure at least one of the lawful safeguards are implemented, which may include:
Further details can be provided upon request, please contact us (see Who we are and our DPO).
In relation to personal data we hold about you, you have the right to:
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.
If you would like to exercise any of these rights, please contact us (see Who we are and our DPO). We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
We try to respond to all legitimate requests within one calendar month (starting from the day after we receive your request). Occasionally it may take longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
To help protect the privacy of personal data you transmit, we maintain physical, technical and administrative safeguards and require the same of any third parties we share your personal data with. Any payment transactions will be encrypted. We update and test our security technology on an ongoing basis. In addition, we train our staff about the importance of confidentiality and maintaining the privacy and security of your personal data.
The transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your personal data transmitted to our Site; any transmission is at your own risk. Once we have received your personal data, we will use physical, technical and administrative safeguards to prevent unauthorized access to your personal data.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable data protection authority of a breach where we are legally required to do so.
We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising. To opt out of marketing communications, see Opting out below.
MARKETING and NOTIFICATIONS
Donation Notifications: We may, with your opt-in, contact you via SMS text message or email regarding your eligibility to donate either because the required wait period between specimen donations (e.g. whole blood) has ended, or because we have a special donation program for which we believe you may be qualified. We will not contact you for non-donation related items.
Test Results: We may contact you, when required, to share information resulting from the viral testing done on blood/plasma that you have previously donated. Contacting you to provide you with the viral test information on your previous donation(s) is required by various governmental entities and you may not opt-out of it.
Third-party marketing: We will get your express opt-in consent before we share your personal data with any third party for marketing purposes.
Opting out: You can ask us to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you or by contacting us (see Who we are and our DPO) any time. Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of a product/service purchase, product/service experience or other transactions. Please note that if you ask us not to contact you by email at a certain email address, we will retain a copy of that email address on a “suppression list” in order to comply with your no-contact request.
To opt out from all future communications (with the exception of the requirement to share viral test results) or to submit a request to access, modify, or delete your personal data, please email firstname.lastname@example.org.
Our Site may, from time to time, contain links to and from the websites of third-party websites. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.