PASEQ Privacy Policy
http://www.paseq.org (the “PASEQ”) is a platform as a service (PaaS) developed, provided and owned by IrsiCaixa, a Spanish foundation strictly committed to preserving the privacy of its users and which complies with the applicable EU and Spanish regulation on data protection.
The aim of this policy is to provide information about the personal data IrsiCaixa collects and processes from the PASEQ users (hereinafter, the “Users”).
- Data Controller
- What information do we collect?
- How do we collect it?
- On what legal basis do we process your personal data?
- For what purposes do we process the data?
- Automated decision-making, including profiling
- Who do we share your information with?
- International data transfers
- Data protection rights
- Third-party sites
- What are Cookies and what types of cookies do we use?
- Data retention period
- Contact Us
- Changes to our PASEQ Privacy Policy
1. Data Controller
The data provided by the User to the PASEQ, is collected and processed by FUNDACIÓ PRIVADA INSTITUT DE RECERCA DE LA SIDA-CAIXA, a Spanish foundation located at Hospital Germans Trias i Pujol, Ctra del Canyet, s/n, 08916 Badalona (Barcelona), Spain and holder of ID Number G-60813227 (hereinafter, the “Data Controller” or “IrsiCaixa”).
2. What information do we collect?
IrsiCaixa collects the following personal data from the Users:
first name, last name, organization name, organization type, country of residence, state/province, job title), email.
IrsiCaixa also collects non-identifiable data from the genetic sequence uploaded by the User to the PASEQ. Non-identifiable data is data that cannot be used to identify or contact a single person.
Please note that the patient’s information uploaded and/or sent by the User to the PASEQ or IrsiCaixa SHALL NOT contain information relating to an individual who can be directly or indirectly identified. IrsiCaixa takes no responsibility for non-compliance by the User in this regard.
3. How do we collect it?
IrsiCaixa processes the information it collects from the following sources:
- on-line registration form
- the patient’s genetic sequence information uploaded to the PASEQ
- cookies (please see the Cookie Policy)
- emails that Users send us
4. On what legal basis do we process your personal data?
The lawful basis IrsiCaixa relies on for processing the information, is the User’s active consent, given by ticking the acceptance box on the PASEQ registration form. The User can revoke his consent at any time.
By uploading the genetic sequence to the PASEQ, the User confirms to have acquired prior consent of the patient whose genetic sequence is to be tested. The burden of proof resides within the User.
5. For what purposes do we process the data?
IrsiCaixa processes the collected data for the following purposes:
- to perform the test on the genetic sequence and provide the results to the User
- to manage User’s account (to email the User for account verification purposes and answer User’s requests, to send communications about changes in our policies, to contact the User)
- for the production of statistical results for scientific research: to analyze, research and make anonymized aggregated statistics, to communicate our aggregated (anonymized) results to other researchers and investigators worldwide, to publish aggregated (anonymized) research results to the general public. When using the information for research, we use aggregated data, which is data that cannot re-identify the individuals.
Notwithstanding the fact that we are lawfully entitled to process your data for the aforementioned anonymized aggregated statistical results for scientific research without obtaining your prior consent, we hereby inform you of the possibility to exclude your data from the processing for statistical results for scientific research, via your User’s profile.
6. Automated decision-making, including profiling
We do not take any decisions involving the use of algorithms of profiling that could significatively affect the User or the patient.
7. Who do we share your information with?
We may disclose your aggregated data to other researchers and investigators worldwide and the aggregated research results to the general public. Aggregated data is data which cannot re-identify the individuals. We also may grant access to our technical and analytical service providers, which are bound by confidentiality agreements.
8. International data transfers
IrsiCaixa does not make transfers of the personal data to any third country (a country that does not poses an adequate level of data protection according to the EU standards. The PASEQ web server is located in Ireland (UE).
In case the User is required by local applicable laws to store the provided data on local servers, please contact us through dpo@irsicaixa.com.
9. Data protection rights
For site security purposes, PASeq Web will use software programs to monitor the website traffic and to identify unauthorized attempts to upload data or otherwise cause damage.
- The right to access – You have the right to access your data.
- The right to rectification – You have the right to request IrsiCaixa to correct any information you believe to be inaccurate. You also have the right to request IrsiCaixa to complete information you believe is incomplete.
- The right to erasure – You have the right to request IrsiCaixa to erase your personal data, if the retention of your data is no longer necessary in relation to the purpose of data processing.
- The right to restrict data processing – you have the right to request IrsiCaixa to restrict the processing of your personal data, under certain conditions (e.g. if you contest the accuracy of your data that we process).
- The right to object to processing – you have the right to object to IrsiCaixa’s processing of your personal data, under certain conditions (e.g. when the processing of your data is based on IrsiCaixa’s lawful interest).
- The right to data portability – you have the right to request IrsiCaixa to transfer the collected data to another organization or directly to you, under certain conditions.
If you wish to exercise your rights, please address your request by writing an e-mail to dpo@irsicaixa.com, attaching a copy of your ID and indicating the right you want to exercise.
You are not required to pay any charge for exercising your rights.
In the event that you are not satisfied with the attention received after exercising any of the aforementioned rights and wish to file a claim, you may contact the independent body set up to uphold information rights in Spain, called Spanish Data Protection Agency, through their website www.aepd.es.
10. Third-party sites
The PASEQ may contain hyperlinks or other devices that link to third-party websites, products and services. Information collected by third parties, which may include such things as location data and contact details, is governed by their privacy practices. IrsiCaixa assumes no responsibility nor liability for the content displayed in said third-party websites. This privacy policy applies only to the PASEQ, so if you go to a third-party website via a hyperlink or other device located in the PASEQ, you should read the third-party’s privacy policy.
11. What are Cookies and what types of cookies do we use?
Please see the Cookie Policy of the PASEQ for more information.
12. Data retention period
IrsiCaixa retains the personal data for the period necessary to fulfil the purposes for which it was collected and to comply with legal and/or regulatory requirements.
13. Contact Us
For any questions or requests regarding the processing of your data, please contact our data protection officer at dpo@irsicaixa.com.
14. Changes to our PASEQ Privacy Policy
This PASEQ Privacy Policy may be modified or amended at any time at IrsiCaixa’s sole discretion. The modification becomes effective upon publication on the PASEQ and although we will make our best efforts in notifying you the changes, we strongly recommend you to regularly check the latest updates on the PASEQ Privacy Policy.
Last updated: 15th December 2020