MedAvante Privacy Policy

 

TRUSTe Privacy

 

Introduction

MEDAVANTE, Inc. (“MedAvante”) is a global provider of centralized, expert psychological rating services to the pharmaceutical, biotechnology, and medical device industries. Protecting consumer privacy is important to MedAvante. MedAvante (hereinafter collectively referred to as “MedAvante,” “we,” “us” or “our”) complies with the U.S. – Swiss Safe Harbor framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal data from Switzerland. MedAvante has certified that it adheres to the Safe Harbor Principles of notice, choice, onward transfer, security, data integrity, access, and enforcement. To learn more about the Safe Harbor program, and to view MedAvante’s certification, please visit https://safeharbor.export.gov/swisslist.aspx.

This privacy policy outlines our general policy and practices for implementing the Principles, including the types of information we gather, how we use it and the notice and choice affected individuals have regarding our use of and their ability to correct that information. This privacy policy applies to personal information received by MedAvante whether in electronic, paper or verbal format. It also describes your choices regarding use, access and correction of your personal information.

This Privacy Policy covers our collection, use and disclosure of information we collect through our websites www.medavante.com and www.medavante.net and our service platforms (e.g., MAVTAB, QCAT, Virgil, SMART, eLearning). The use of information collected through our service platforms shall be limited to the purpose of providing the service for which the Client has engaged MedAvante as well as the Human Resources data of our employees.

EU-U.S. Privacy Shield

MEDAVANTE, Inc. participates in and has certified its compliance with the EU-U.S. Privacy Shield Framework. MEDAVANTE, Inc. is committed to subjecting all personal data received from European Union (EU) member countries, in reliance on the Privacy Shield Framework, to the Framework’s applicable Principles. To learn more about the Privacy Shield Framework, visit the U.S. Department of Commerce’s Privacy Shield List. [https://www.privacyshield.gov/list]

MedAvante is responsible for the processing of personal data it receives, under the Privacy Shield Framework, and subsequently transfers to a third party acting as an agent on its behalf. MedAvante complies with the Privacy Shield Principles for all onward transfers of personal data from the EU, including the onward transfer liability provisions.

With respect to personal data received or transferred pursuant to the Privacy Shield Framework, MedAvante is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission In certain situations, MedAvante may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request. MEDAVANTE, Inc. has further committed to cooperate with EU data protection authorities (DPAs) with regard to unresolved Privacy Shield complaints concerning human resources data transferred from the EU in the context of the employment relationship.

Under certain conditions, more fully described on the Privacy Shield website [https://www.privacyshield.gov/article?id=How-to-Submit-a-Complaint], you may invoke binding arbitration when other dispute resolution procedures have been exhausted.

Definitions

“Personal Information” shall mean any information relating to an identified or identifiable natural person (‘data subject’); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity. Personal information does not include information that is encoded or anonymized or publicly available information that has not been combined with non-public personal information.

“Processing of personal information” (‘processing’ or ‘processes’) shall mean any operation or set of operations which is performed upon personal data, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction.

“Sensitive Personal Information” means personal information that reveals race, ethnic origin, sexual orientation, political opinions, religious or philosophical beliefs, trade union membership or that concerns an individual’s health.

“Third Party Agent” shall mean any party that has entered into a formal agreement with MedAvante for the purposes of processing, analyzing or storing personal data either manually or electronically. The agreement between MedAvante and the Third Party Agent requires them to observe our Privacy Policy and respect your confidentiality.

“Client” shall mean a party that MedAvante has entered into a formal agreement with to facilitate the processing of personal information for the purpose of supporting regulated clinical trials.

Information We Collect from Visitors

Visitors to our Web sites (www.medavante.com or www.medavante.net) can access the Web site’s home page, and browse the site, without disclosing any personal information. If you wish to contact us via our website, we will collect your name, address, and email address. We will only use this information to respond to your inquiry.

Information We Collect on Behalf of a Client

MedAvante collects and processes clinical assessment information that may include personal information and/or sensitive personal information in support of regulated clinical trials.
MedAvante collects and processes information under the direction of its Clients. MedAvante has no direct relationship with the individuals whose personal data it processes. MedAvante works with its Clients to help them provide notice to their customers concerning, the purpose for which personal information is collected.

Access to Data Controlled by our Clients

MedAvante has no direct relationship with the individuals whose personal data it processes. An individual who seeks access, or who seeks to correct, amend, or delete inaccurate data should direct his query to the MedAvante Client (the data controller). If requested to remove data, we will respond within a reasonable timeframe.

Access to Data Controlled by MedAvante

MedAvante shall allow an individual access to their personal information and allow the individual to correct, amend or delete inaccurate information except where the burden or expense of providing access would be disproportionate to the risks to the privacy of the individual in the case in question or where the rights of persons other than the individual would be violated.

Upon request, MedAvante will provide you with information about whether we hold any of your personal information. You may access, correct, or request deletion of your personal information by emailing our Privacy Officer at privacy@medavante.com or by contacting us by postal mail at the contact information listed below. We will respond to your request within a reasonable timeframe.

We will retain your information for as long as your account is active or as needed to provide you services. MedAvante will retain personal information we process on behalf of our Clients for as long as needed to provide services to our Client. We will retain and use this information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

Storage of Personal Information

MedAvante does not collect the following personal information in support of regulated clinical trials: subject’s first and last name, address, social security number, telephone number, or birth month and day. Information we do collect is stored on our secure database servers (in whatever country they may be located) or hosted by third party agents who have entered into agreements with us that require them to observe our Privacy Policy. We have a firewall and other technology to prevent individuals from accessing information without authorization. Data centers are designed to be physically secure and protected from unauthorized access by unauthorized persons.

Information in our data centers is backed up routinely, in order to aid in the recovery of information in the event of accidental damage of information or due to a natural disaster. The backup media is stored in a physically secure storage facility.

We have implemented technology and security policies, procedures, and other measures to protect the personal information that we have under our control from unauthorized access, improper use, alteration, unlawful or accidental destruction, and accidental loss. We also protect personal information by requiring that all our employees and third party agents who have access to or are associated with the processing of your data respect your confidentiality.

MedAvante uses security methods to determine the identity of each registered user, so that appropriate rights and restrictions can be enforced for that user. Reliable verification of user identity is called authentication. MedAvante uses strong passwords and usernames to authenticate users.

Use of Cookies and other Tracking Technologies on the Websites and Services Platforms

Technologies such as: cookies, beacons, tags and scripts are used by MedAvante and our business partners, affiliates, and service providers. These technologies are used in analyzing trends, administering the website, tracking users’ movements around the site and to gather demographic information about our user base as a whole. We may receive reports based on the use of these technologies by these companies on an individual as well as aggregated basis.

We use cookies to make it easier for you to navigate our site. Users can control the use of cookies at the individual browser level. If you reject cookies, you may still use our website, but your ability to use some features or areas of our site may be limited. Log Files. As is true of most web sites, we gather certain information automatically and store it in log files. This information may include Internet protocol (IP) addresses, browser type, internet service provider (ISP), referring/exit pages, operating system, date/time stamp, and/or clickstream data. We do not link this automatically collected data to other information we collect about you.

Behavioral Targeting / Re-Targeting. We partner with a third party to either display advertising on our website or to manage our advertising on other sites. Our third party partner may use technologies such as cookies to gather information about your activities on this site and other sites in order to provide you advertising based upon your browsing activities and interests. If you wish to not have this information used for the purpose of serving you interest-based ads, you may opt-out by clicking here (or if located in the European Union click here) Please note this does not opt you out of being served ads. You will continue to receive generic ads. We use cookies on this site. We do not link the information we store in cookies to any personal information you submit while on our site. We use session ID cookies. We use session cookies to make it easier for you to navigate our site. A session ID cookie expires when you close your browser.

Principles

The privacy principles included in this statement are based on the Safe Harbor Privacy Principles that can be found on the U.S. Department of Commerce website where you can learn more about the Safe Harbor program and view MedAvante’s certification, https://safeharbor.export.gov/swisslist.aspx. These privacy principles apply to information MedAvante collects directly from individuals. When MedAvante collects and processes your information on behalf of a Client, we will work with the Client to ensure adherence to these principles.

Notice

MedAvante or Client shall inform an individual of the purpose for which it collects and uses personal information. MedAvante or Client shall provide the individual with the choice and means for limiting the use and disclosure of their personal information. Notice will be provided in clear and conspicuous language when individuals are first asked to provide Personal Information to MedAvante, or as soon as practicable thereafter, and in any event before MedAvante uses or discloses the information for a purpose other than for which it was originally collected or processed.

Choice

MedAvante does not sell, share, rent or trade your personal information with third parties other than as disclosed within this privacy policy.

MedAvante or Client will offer individuals the opportunity to choose (opt out) whether their personal information is to be used for a purpose other than the purpose for which it was originally collected or subsequently authorized by the individual. For Sensitive Personal Information, MedAvante or Client will give individuals the opportunity to affirmatively or explicitly (opt out) consent to the disclosure of the information for a purpose other than the purpose for which it was originally collected or subsequently authorized by the individual.

We reserve the right to disclose your personal information as required by law and when we believe that disclosure is necessary to protect our rights and/or to comply with a judicial proceeding, court order, or legal process.

Onward Transfers

We may transfer personal information to companies that help us provide our service. Transfers to subsequent third parties are covered by the service agreements with our Clients.

We shall notify an individual of disclosure of personal or sensitive personal information to a third party and allow the individual the choice (opt out) of such disclosure. MedAvante shall ensure that any third party for which personal or sensitive personal information may be disclosed subscribes to the Principles or are subject to laws providing the same level of privacy protection as is required by the Principles and agrees in writing to provide an adequate level of privacy protection.

If MedAvante is involved in a merger, acquisition, or sale of all or a portion of its assets, you will be notified via email and/or a prominent notice on our website of any change in ownership or uses of your personal information, as well as any choices you may have regarding your personal information.

Data Security

MedAvante shall take all reasonable steps to protect your personal information from loss, misuse and unauthorized access, disclosure, alteration and destruction. MedAvante has appropriate physical, electronic and managerial procedures to safeguard and secure the Information from loss, misuse, unauthorized access or disclosure, alteration or destruction.

When logging in to your account to participate, please note that this is a secure login; we use SSL encryption. We follow generally accepted standards to protect the personal information submitted to us, both during transmission and once we receive it. However, no method of transmission over the Internet, or method of electronic storage, is 100 percent secure. Therefore, we cannot guarantee its absolute security. If you have any questions about security on our website, you can contact us at privacy@medavante.com.

Data Integrity

MedAvante shall only process information in a way that is compatible with and relevant for the purpose for which it was collected or authorized by the individual. To the extent necessary for those purposes, MedAvante shall take reasonable steps to ensure that information is accurate, complete, current and reliable for its intended use.

Enforcement

MedAvante uses a self-assessment approach to assure compliance with this Privacy Policy and periodically verifies that the policy is accurate, comprehensive for the information intended to be covered, prominently displayed, completely implemented and accessible and in conformity with the Principles. You may raise questions or concerns regarding MedAvante’s collection, processing, storage or disclosure of Information by using the contact information below. We will investigate and attempt to resolve any concerns and disputes regarding misuse or improper disclosure of your information in accordance with the principles contained in this policy. When applicable, corrective and preventive action will be implemented to resolve any concern or dispute and appropriate follow-up action will be taken to verify that the expressed concern or dispute has been resolved.

Amendments

If we decide to change our privacy policy, we will post the changes to this privacy policy, on our website so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we disclose it. We reserve the right to modify this privacy policy at any time, so please review it frequently. If we make any material changes we will notify you by email (sent to the email address specified in your account) or by means of a notice on this Site prior to the change becoming effective.

Information Subject to Other Policies or Agreements

MedAvante is committed to following the Principles for all Personal Information within the scope of the Safe Harbor Agreement. However, certain information is subject to policies of MedAvante that may differ in some respects from the general policies set forth in this privacy policy.

Links to Other Sites

If you click on a link to a third party site, you will leave MedAvante’s site and go to the site you selected. Because we cannot control the activities of third parties, we cannot accept responsibility for any use of your personal information by such third parties, and we cannot guarantee that they will adhere to the same privacy practices as we would. We encourage you to review the privacy policies of any other service provider from whom you request services. If you visit a third party website that is linked to our site, you should read that site’s privacy policy before providing any personal information.

Contact Information

Questions, comments, or complaints regarding MedAvante’s Privacy Policy or data collection and processing practices can be mailed or emailed to:

  • MedAvante, Inc.
  • Privacy Officer
  • 100 American Metro Blvd. Suite 106
  • Hamilton, NJ 08619
  • privacy@medavante.com

Effective date: 30 September 2016