AFRICA CLINICAL RESEARCH MANAGEMENT, LTD (ACE Research)
DATA PRIVACY STATEMENT
Effective Date: 14 July 2020
Notice Version: 1.0
Data Controller Contact Information:
Africa Clinical Research Management Limited (ACE Research).
The White Court Apartments, Old Airport Road
P.O. Box 3964 – 40100.
Tel: +254 796 145 263 / +254 786 690 234
This privacy statement applies to the information that we collect from you when you use our website, www.aceresearchafrica.com and our mobile application named “ACE Research App” collectively and hereinafter called “Platform.”
Our privacy statement tells you what personal data and nonpersonal data we may collect from you, how we collect them, how we protect them, how we share them, how you can access and change them, and how you can limit our sharing of them. Our privacy statement also explains certain legal rights that you have with respect to your personal data. Any capitalized terms not defined herein will have the same meaning as where they are defined elsewhere on our Platform.
‘NONPERSONAL DATA’ (NPD) is information that is in no way personally identifiable.
‘PERSONAL DATA’ (PD) means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified directly or indirectly by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person. PD is in many ways the same as Personally Identifiable Information (PII). However, PD is broader in scope and covers more data.
General Data Protection Regulation (GDPR) 2016/679 is a regulation in EU law on data protection and privacy in the European Union and the European Economic Area. It also addresses the transfer of personal data outside the EU and EEA areas.
Topics Covered in Our Privacy Statement
INFORMATION WE COLLECT AND HOW WE COLLECT IT.
HOW YOUR INFORMATION IS USED AND SHARED.
RETAINING AND DESTROYING YOUR PD.
UPDATING YOUR PD.
REVOKING YOUR CONSENT FOR USING YOUR PD.
PROTECTING THE PRIVACY RIGHTS OF THIRD PARTIES.
DO NOT TRACK SETTINGS.
LINKS TO OTHER WEBSITES.
PROTECTING CHILDREN’S PRIVACY.
OUR EMAIL POLICY.
OUR SECURITY POLICY.
USE OF YOUR CREDIT CARD.
TRANSFERRING PD FROM THE EUROPEAN UNION.
CHANGES TO OUR PRIVACY NOTICE.
If you want to exercise any of your rights included in this privacy statement, contact us by using the information at the top of this privacy statement.
You Have the Right Not to Have Your Personal Information Sold
You have the right to request that we do not use or process any of your personal information.
Personal information for this section means a natural person’s first name or first initial and last name in combination with any one or more of the following data elements when the name and data elements are not encrypted: social security number, driver’s license number, driver authorization card number, or identification card number. Account number, credit card number, or debit card number, in combination with any required security code, access code, or password that would permit access to the person’s financial account. A medical identification number or a health insurance identification number. A username, unique identifier, or electronic mail address in combination with a password, access code, or security question and answer that would permit access to an online account.
If you wish to make this request, please email us at: firstname.lastname@example.org
telling us that you do not want to have any of your personal information sold. Please include enough personal information so that we can reasonably verify your identification.
Your Rights Under the GDPR
When using our Platform and submitting PD to us, you may have certain rights under the GDPR if you reside or are in any of the countries of the European Union. Depending on the legal basis for processing your PD you may have some or all of the following rights:
- The Right to Be Informed – You have the right to be informed about the PD that we collect from you and how we process them.
- The Right of Access – You have the right to get confirmation that your PD are being processed and you have the ability to access your PD.
- The Right to Rectification – You have the right to have your PD corrected if they are inaccurate or incomplete.
- The Right to Erasure (Right to Be Forgotten) – You have the right to request the removal or deletion of your PD if there is no compelling reason for us to continue processing them.
- The Right to Restrict Processing – You have the right to ‘block’ or restrict the processing of your PD. When your PD are restricted, we are permitted to store your data, but not to process them further.
- The Right to Data Portability – You have the right to request your PD that you provided to us and use them for your own purposes.
- The Right to Object – You have the right to object to us processing your PD for the following reasons:
- Processing was based on legitimate interests or the performance of a task in the public interest/exercise of official authority (including profiling)
- Direct marketing (including profiling)
- Processing for purposes of scientific/historical research and statistics
- Rights in relation to automated decision-making and profiling.
- Automated Individual Decision-Making and Profiling – You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects regarding you or similarly significantly affects you.
- Filing a Complaint with Authorities – You have the right to file a complaint with supervisory authorities if your information has not been processed in compliance with the General Data Protection Regulation. If the supervisory authorities fail to address your complaint properly, you may have the right to a judicial remedy.
Subject to legal and contractual exceptions, you have rights under data protection laws in relation to your personal data.
- Right to be informed that we are collecting personal data about you;
- Right to access personal data that we hold about you and request for information about how we process it;
- Right to request that we correct your personal data where it is inaccurate or incomplete;
- Right to request that we erase your personal data noting that we may continue to retain your information if obligated by the law or entitled to do so;
- Right to object and withdraw your consent to processing of your personal data. We may continue to process if we have a legitimate or legal reason to do so;
- Right to request restricted processing of your personal data noting that we may be entitled or legally obligated to continue processing your data and refuse your request;
- Right to request transfer of your personal data in [an electronic format].
Our customers and users are permitted to request certain information about the types of information shared by our company with third parties and the identities of those third parties.
If you wish to exercise any of the rights set out above, please send an email to: email@example.com or write to us at:
Africa Clinical Research Management Limited (ACE Research).
The White Court Apartments, Old Airport Road
P.O. Box 3964 – 40100.
Tel: +254 796 145 263 / +254 786 690 234
INFORMATION WE COLLECT AND HOW WE COLLECT IT
Generally, you control the amount and type of information that you provide to us when using our Platform.
Our Legal Basis for Collecting and Processing PD
Our legal basis for collecting and processing your PD when you access our products or services is based on and the necessity for the performance of a contract or to take steps to enter into a contract. Our legal basis for collecting and processing your PD when you sign up for our newsletter, access free audios, videos, and webinars through our Platform is based on consent.
We shall ensure that Personal Data is;-
(1) accurate and, where necessary, kept up to date, with every reasonable step being taken to ensure
that any inaccurate personal data is erased or rectified without unnecessary delay.
(2) collected only where a valid explanation is provided whenever information relating to family
or private affairs is required.
(3) processed in accordance with the right to privacy of the data subject.
(4) processed lawfully, fairly and in a transparent manner in relation to any data subject.
(5) collected for explicit, specified and legitimate purposes and not further processed in a manner incompatible with those purposes.
(6) adequate, relevant, limited to what is necessary in relation to the purposes for which it is processed.
(7) kept in a form which identifies the data subjects for no longer than is necessary for the purposes
which it was collected.
We automatically receive information from your web browser or mobile device. This information may include the name of the website from which you entered our Platform, if any, as well as the name of the website you’ll visit when you leave our Platform. This information may also include the IP address of your computer/the proxy server you use to access the Internet, your Internet service provider’s name, your web browser type, the type of mobile device, your computer operating system, and data about your browsing activity when using our Platform. We use all this information to analyze trends among our users to help improve our Platform.
You have a right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning or significantly affects the data subject
When Entering and Using Our Platform
When you enter and use our Platform and agree to accept cookies, some of these cookies may contain your PD.
- Performance Cookies – These cookies collect information about the use of the Platform, such as pages visited, traffic sources, users’ interests, content management, and other measurements.
- Functional Cookies – These cookies enable the Platform to remember users’ choices, such as their language, usernames, and other choices while using the Platform. They can also be used to deliver services, such as letting a user create a blog post, listen to audios, or watch videos on the Platform.
- Media Cookies – These cookies can be used to improve a Platforms performance and provide special features and content. They can be placed by us or third parties who provide services to us.
- Advertising or Targeting Cookies – These cookies are usually placed and used by advertising companies to develop a profile of your browsing interests and serve advertisements on other websites that are related to your interests. You will see less advertising if you disable these cookies.
- Session Cookies – These cookies allow a Platform to link the actions of a user during a browser session. They may be used for a variety of purposes, such as remembering what a user has put in their shopping cart as they browse a Platform. Session cookies also permit users to be recognized as they navigate a Platform so that any item or page changes they make are remembered from page to page. Session cookies expire after a browser session; they are not stored long term.
- Persistent Cookies – These cookies are stored on a user’s device between browser sessions, which allows the user’s preferences or actions across a website or across different websites to be remembered. Persistent cookies may be used for several purposes, including remembering users’ choices and preferences when using a Platform or to target advertising to them.
- identifying the areas of our Platform that you have visited
- personalizing content that you see on our Platform
- our Platform analytics
- remarketing our products or services to you
- remembering your preferences, settings, and login details
- allowing you to post comments
- allowing you to share content with social networks.
We may also use a technology called web beacons to collect general information about your use of our Platform and your use of special promotions or newsletters. The information we collect by web beacons allows us to statistically monitor the number of people who open our emails. Web beacons also help us to understand the behavior of our customers and users.
At User and Member Registration or When accessing Products or Services
First name, last name, email address, phone number, physical address, education background, resume, username, point of contact person name, project detail.
Collecting Information About Your Physical Location
When you use our Platform, we may collect and process information about your actual physical location. We use several technologies such as GPS and IP tracking to determine your location. These technologies may also give us information about nearby cell towers, Wi-Fi access points, and other devices.
- You can opt out of the creation of a user profile, Hotjar’s storing of data about your usage of our website, and Hotjar’s use of tracking cookies on other websites by visiting: https://www.hotjar.com/legal/compliance/opt-out.
Chat Software or Contact Forms
Our Platform contains chat software or contact forms that enable visitors to communicate with us live online or offline by email. In some cases visitors can communicate with us without accessing our products and services. When you use our chat software or contact forms, we may collect some or all the following information: your email address, first name, last name, location, and any other information you willingly choose to give us. You should limit the information you give to us to one that is necessary to answer your questions.
Google Ad and Content Network
Our Platform uses Google Analytics to collect information about the use of our Platform. Google Analytics collects information from users such as age, gender, interests, demographics, how often they visit our Platform, what pages they visit, and what other websites they have used before coming to our Platform. We use the information we get from Google Analytics to analyze traffic, improve our marketing, advertising, and Platform. Google Analytics collects only the IP address assigned to you on the date you visit our Platform, not your name or other identifying information. We do not combine the information collected using Google Analytics with PD. Although Google Analytics plants a permanent cookie on your web browser to identify you as a unique user the next time you use our Platform, the cookie cannot be used by anyone but Google. Google also uses specific identifiers to help collect information about the use of our Platform.
- For more information on how Google collects and processes your data visit: https://www.google.com/policies/privacy/partners/
- You can prevent Google Analytics from using your information by opting out at this link: https://tools.google.com/dlpage/gaoptout
We also use analytics and crash reporting services from other companies to collect information about the use of our Platform. Analytics collects information such as how often users visit our Platform, what pages they visit, when they do so, what other websites they used before coming to our Platform, and their IP addresses. We use the information we get from analytics to improve our services.
What Happens If You Don’t Give Us Your PD
If you do not provide us with enough PD, we may not be able to provide you all our products and services. However, you can access and use some parts of our Platform without giving us your PD.
HOW YOUR INFORMATION IS USED AND SHARED
We use the information we receive from you to:
- provide our products and services you have requested or purchased from us
- personalize and customize our content
- make improvements to our Platform
- contact you with updates to our Platform, products, and services
- resolve problems and disputes
- contact you with marketing and advertising that we believe may be of interest to you.
Communications and Emails
When we communicate with you, we will use the email address you provided when you registered as a user or customer. We may also send you emails with promotional information about our Platform or offers from us or our affiliates unless you have opted out of receiving such information. You can change your contact preferences at any time through your account or by contacting us using the contact information at the top of this privacy notice.
Sharing Information with Affiliates and Other Third Parties
We do not sell or rent your PD to third parties for marketing purposes. However, for data aggregation purposes we may use your NPD, which might be passed on to other parties at our discretion. Any such data aggregation would not contain any of your PD. We may give your PD to third-party service providers whom we hire to provide services to us. These third-party service providers may include but are not limited to payment processors, web analytics companies, advertising networks, call centers, data management services, help desk providers, accountants, law firms, auditors, shopping cart and email service providers, and shipping companies.
Sharing Your Information When You Login Using Social Media Websites
We may share your information with third parties such as Facebook.com, Twitter.com, YouTube.com, Instagram.com, and Google.com. If you decide to login to our Platform using these third parties or other social media websites, you are agreeing to let us use and store your profile information from those websites to make better use of any social media features on our Platform. This sharing of information helps us provide you a better experience when using our Platform and services. It also provides us with useful information such as visitor traffic. If you use any of the social sharing icons on our Platform to share our information, you may also be sharing your personal information through social media websites.
Sharing Information With Business Partners
We may share your PD with our business partners. The business partners include general vendors and subcontractors. We share this information with them so that they can perform tasks for us. When you choose to take part in our services and/or program, you are authorizing us to provide your PD to our business partners.
Text Messaging and Push Notifications
If you provide a mobile telephone number to us, you are giving your consent and authorize us or a third party to send you text messages and push notifications. You are not required to give us your consent for these text messages and push notifications. However, withholding your consent may interfere or prevent us from providing some or all of our services to you. You can stop receiving text messages and push notifications at any time by contacting us at firstname.lastname@example.org.
Legally Required Releases of Information
We may be legally required to disclose your PD if such disclosure is (a) required by subpoena, law, or other legal process; (b) necessary to assist law enforcement officials or governmental enforcement agencies; (c) necessary to investigate violations of or otherwise enforce our terms and conditions; (d) necessary to protect us from legal action or claims from third parties, including you and/or other users; or (e) necessary to protect the legal rights, personal/real property, or personal safety of our company, users, employees, and affiliates.
Disclosures to Successors
If our business is sold or merges in whole or in part with another business that would become responsible for providing our Platform to you, we retain the right to transfer your PD to the new business. The new business would retain the right to use your PD according to the terms of this privacy notice as well as to any changes to this privacy notice as instituted by the new business. We also retain the right to transfer your PD if our company files for bankruptcy and some or all of our assets are sold to another individual or business.
Community Discussion Boards, Blogs, or Other Mechanisms
Our Platform may offer the ability for users to communicate through online community discussion boards, blogs, or other mechanisms. We do not filter or monitor what is posted on such discussion mechanisms. If you choose to post on these discussion mechanisms, you should use care when exposing any PD, as such information is not protected by our privacy notice nor are we liable if you disclose your PD through such postings. Also, PD which you post on our Platform for publication may be available worldwide by means of the Internet. We cannot prevent the use or misuse of such information by others.
RETAINING AND DESTROYING YOUR PD
We retain information that we collect from you (including your PD) only for as long as we need it for legal, business, research, or tax purposes. Your information may be retained in electronic, paper, or a combination of both forms. When your information is no longer needed, we will destroy, delete, or erase it.
UPDATING YOUR PD
You can update your PD using services found on our Platform. If no such services exist, you can contact us using the contact information found at the top of this privacy notice and we will help you. However, we may keep your PD as needed to enforce our agreements and to comply with any legal obligations.
REVOKING YOUR CONSENT FOR USING YOUR PD
You have the right to revoke your consent for us to use your PD at any time. Such opt-out will not affect disclosures otherwise permitted by law including but not limited to disclosures to governmental agencies or law enforcement departments, or as otherwise required to be made under applicable law.
PROTECTING THE PRIVACY RIGHTS OF THIRD PARTIES
If any postings you make on our Platform contain information about third parties, you agree to make sure that you have permission to include that information. While we are not legally liable for the actions of our users, we will remove any postings about which we are notified, if such postings violate the privacy rights of others.
DO NOT TRACK SETTINGS
Some web browsers have settings that enable you to request that we do not track your movement within our Platform. Our Platform does not obey such settings when transmitted to and detected by our Platform. You can turn off tracking features and other security settings in your browser by referring to your browser’s user manual.
LINKS TO OTHER WEBSITES
Our website may provide hyperlinks to other locations or websites on the Internet. These hyperlinks lead to websites published or operated by third parties who are not affiliated with or in any way related to us and have been included in our website to enhance your user experience and convenience, and are presented for information purposes only.
We do not endorse, recommend, approve or guarantee any third- party products and services by providing hyperlinks to an external website or webpage and do not have any co-operation with such third parties unless otherwise disclosed. We are not in any way responsible for the content of any externally linked website or webpage.
PROTECTING CHILDREN’S PRIVACY
We do not knowingly collect PD from children under the age of 16 without parental consent. If you are a parent or guardian and believe that your child is using our Platform, please contact us. Before we remove any information we may ask for proof of identification to prevent malicious removal of account information. If we discover that a child is accessing our Platform, we will delete his/her information within a reasonable period of time.
If we collevt data from a minor with the consent given by the childs parent or guardian, we shall endevour to use such information such a manner that protects and advances the rights and best interests of the child.
We shall endevour to incorporate appropriate mechanisms for age verification and consent in order to process personal data of a child.
OUR EMAIL POLICY
You can always opt-out of receiving email correspondence from us or our affiliates. We will not sell, rent, or trade your email address to any unaffiliated third party without your permission except in the sale or transfer of our business, or if our company files for bankruptcy.
OUR SECURITY POLICY ON SAFEGUARDING AND PROTECTING INFORMATION
ACE Research has put in place technical and operational measures to protect your information from unauthorised access, accidental loss or destruction. We have built our Platform using industry-standard security measures and authentication tools to protect the security of your PD. We and the third parties who provide services to us also maintain technical and physical safeguards to protect your PD. Unfortunately, we cannot guarantee prevention of loss or misuse of your PD or secure data transmission over the Internet because of its nature. We strongly urge you to protect any password you may have for our Platform and not share it with anyone.
CHANGES TO OUR PRIVACY NOTICE
We reserve the right to change this privacy notice at any time. If our company decides to change this privacy notice, we will post those changes on our Platform so that our users and customers are always aware of what information we collect, use, and disclose. Any amendment or modification to this statement will take effect from the date of notification on the ACE Research website.
RIGHT TO LODGE COMPLAINT
You have the right to lodge a complaint with the relevant supervisory authority that is tasked with personal data protection within the Republic of Kenya
ACE Research Copyright ©2020. This Privacy Notice is protected under copyright laws. The copying, redistribution, use or publication by you, is strictly prohibited.