Privacy Policy

Trialbee AB
Privacy Policy
Effective Date: 27.OCT.2022

INTRODUCTION

This website and policy are provided and maintained by Trialbee AB (Trialbee), corporate registration number 556814-3019, with its principal place of business at Södra Tullgatan 3, SE-211 40 Malmö, Sweden.

This privacy policy informs you of the principles governing our use of the personal data which you submitted, or we obtained by you via a website or by registering as a user of the online services which we provide.

Trialbee’s approach to protecting personal data recognizes the Federal Trade Commission, which has jurisdiction over our compliance when applicable regarding personal data. If you do not agree to the terms of this privacy policy, you should not access or use Trialbee’s website.

TABLE OF CONTENTS

  1. PURPOSE
    1. Processor
    2. Contact Details
    3. Complaints
    4. Changes to privacy policy and your duty to inform us of changes in your personal data
    5. Third-party links
  2. DEFINITIONS AND ACCRONYMS
  3. DATA WE COLLECT ABOUT YOU
  4. HOW YOUR PERSONAL DATA IS COLLECTED
  5. HOW WE USE AND DISCLOSE YOUR DATA
    1. Why and how we use your data
    2. Disclosing information to third parties
    3. Use of health data
    4. Opting out of communications from Trialbee
    5. Use of Cookies
      1. Cookie privacy preferences and consent
      2. Use of data for marketing
      3. Trialbee cookie statement
  6. TRANSFER OF PERSONAL DATA
  7. DATA SECURITY
  8. DATA RETENTION
  9. YOUR DATA PRIVACY UNDER CCPA
  10. CHILDREN
  11. OTHER INFORMATION

1. PURPOSE

This privacy policy describes how Trialbee collects, uses, processes, and protects your personal data and informs the choices available to you regarding how you can manage your personal data.

We recommend that you read this privacy policy with any other privacy policy or processing notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are aware of how and why we are using your data. This privacy policy supplements the other notices and is not intended to override them.

This privacy policy identifies Trialbee as “we”, “us” or “our” and is mentioned in this privacy policy, we are responsible for processing your data.

1.1. PROCESSOR

We have a data protection officer who is responsible for dealing with questions, and/or requests in relation to this privacy policy. If you have any questions about this privacy policy, including requests to exercise your legal rights, please contact the data protection officer using the contact details below.

1.2. CONTACT DETAILS

Trialbee’s contact details for privacy rights questions and requests are:

Full name of legal entity: Trialbee AB, Data Privacy Officer

Email Address: privacy@trialbee.com

1.3. COMPLAINTS

You have the right to make a complaint at any time to the supervisory authority.

We would however appreciate the chance to deal with your concerns before you approach one of the national supervisory authorities, so please contact us in the first instance at privacy@trialbee.com.

To find more about this right and to locate the appropriate Data Privacy Authority, you may contact the US Federal Trade Commission at: https://www.ftc.gov/faq/consumer-protection/submit-consumer-complaint-ftc

1.4. CHANGES TO PRIVACY POLICY AND YOUR DUTY TO INFORM US OF CHANGES IN YOUR PERSONAL DATA

We reserve the right to amend this privacy policy and will notify you by updating this notice, so please check this privacy policy from time to time. It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us by contacting us at privacy@trialbee.com.

1.5. THIRD-PARTY LINKS

This website may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.

2. DEFINITIONS AND ACCRONYMS

Anonymized: type of information sanitization whose intent is privacy protection. It is the process of removing personally identifiable information from data sets, so that the person’s identity becomes anonymous.

CCPA: United States California Consumer Privacy Act

PII: Personal Identifiable Information

PHI: Protected Health Information

Third Parties:

  • Service providers acting as processors and who provide services to us.
  • Professional advisers acting as processors or joint controllers including lawyers, bankers, auditors, and insurers who provide consultancy, banking, legal, insurance, and accounting services to us.
  • Regulators and other state authorities acting as processors or joint controllers in any jurisdiction in which we are operating and who require reporting of processing activities in certain circumstances.

Covered Entity: an institution, organization or other entity that is subject to the rules of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). Covered Entities include: (i) a health plan, (ii) a healthcare clearinghouse and, (iii) a healthcare provider which transmit any personal identifiable health information in electronic form in connection with a transaction covered by HIPAA.

PIHI: Personal Identifiable Health Information and is any information including demographic information collected from an individual that:

(i) relates to (a) the past, present or future physical or mental health or condition of an individual; (b) the provision of healthcare to an individual; or (c) the past, present or future payment for the provision of healthcare to the individual; and

(ii) identifies the individual or there is a reasonable basis to believe it can be used to identify the individual; and

(iii) PIHI does not include education records or medical records covered by the Family Education Rights and Privacy Act or employment records held by Trialbee in its role as an employer.

Personal Information: any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household according to the California Consumer Privacy Act (“CCPA”).

3. DATA WE COLLECT ABOUT YOU

Like many commercial organizations we monitor the use of this website by collecting aggregate information using cookies.

Typically, we collect information about the number of visitors to the website, to each web page and the originating domain name of the visitor’s Internet Service Provider.

This information is used to understand the visitor’s use of the website and may be shared with our affiliates and/or other third parties. We have no means reasonably available to us to ascertain the identity of individual users from aggregate information.

We may collect, use, and share Aggregated Data such as general statistical data for any purpose. Aggregated Data may be derived from your personal data but is not considered personal data in law as this data does not directly or indirectly reveal your identity.

We may also perform or collect categories of personal data about you which are grouped as follows:

  • Monitor customer traffic patterns and usage.
  • Site usage information which helps us improve the design and layout of our website, and to personalize your experience by tailoring the content you see thus optimizing your user experience.
  • Perform statistical analysis on our members’ accounts to determine:
    • how many are active,
    • how frequently they are used, and
    • how many of our other websites you are registered with.
  • Identity Data includes first name, maiden name, last name, username, or similar identifier.
  • Contact Data includes physical address, delivery address, email address, and telephone numbers.
  • Transactional Data includes details of products and services you have received or purchased from us and/or our affiliates.
  • Technical Data includes Internet Protocol (“IP”) address, login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology that is on the device you use to access this website.
  • Usage Data includes information about how you use our website, products, and services.
  • Marketing and Communications Data includes your preferences in receiving marketing from us and/or our affiliates.
  • Health Data includes information in relation to any aspect of your health and/or consequences of taking part in any clinical trials organized by our clients.

Occasionally, we may obtain sensitive personal data, for example, information relating to your physical or mental health or condition, but only if you voluntarily provide us with this information and consent to our collection of such information for the purposes set out in this Privacy Policy and any specific privacy statement provided.

We may also obtain information about your opinions if, for example, you send us feedback, or ask us questions.

We may also, occasionally, receive information about you from other sources which we will add to the information that we may already hold about you to help us improve and personalize our service to you.

4. HOW YOUR PERSONAL DATA IS COLLECTED

We use various methods to collect the categories of data described above through but not limited to:

  • Data Interactions. You may have given your personal data by filling in forms or by corresponding with us by mail, phone, and email or otherwise. This includes personal data you provide when you:
    • apply or register online,
    • contract to receive products and/or services,
    • request information, and/or
    • request marketing material to be sent to you.
  • Automated Technologies or Interactions. As you interact with our website, we may automatically collect technical data about your equipment, browsing actions or patterns.
    • We collect this personal data by using cookies, log files, and other similar technologies.
    • We may also receive technical data about you from other websites that you visit employing our cookies. This aggregate data gives a “macro-view” of visitor traffic patterns and provides insight to what sections of the website users visit the most. None of this information is linked to any personal information.
    • We collect and log technical data as described in section 3 above.
  • Third-parties or publicly available sources. We may receive personal data about you from various third parties and public sources such as:
    • Analytics providers such as Google, Matomo
    • Advertising Networks
    • Search Information Providers
    • Portals
  • Contact and Transaction Data from providers of technical, payment, and delivery services.
  • Identity and Contact Data from data brokers or aggregates.

5. HOW WE USE AND DISCLOSE YOUR DATA

Trialbee will not sell, trade, or lease your PII or PHI to third parties. However, we may sometimes engage other companies and individuals to perform services on our behalf.

We will use your personal data in the following circumstances:

  • To perform the services or provide the products that you request
  • To perform legal obligations to you, our clients, or as required by law,
  • Where we need to comply with a legal or regulatory obligation.

Trialbee will not share your personal data unless:

  • We have informed you otherwise and obtained your permission, or
  • There is a legal or regulatory obligation, or
  • The law forces us to share the data.

Declaration of Consent

Trialbee study websites will describe how we plan to use your data. This consent area usually appears before or after an online questionnaire, but always before you submit any personal data to us.

 

5.1. WHY AND HOW WE USE YOUR DATA

The matrix below describes the ways we plan to use your personal data, the legal basis, and identifies the legitimate interests where appropriate.

Note, that we may process your personal data for more than one lawful ground depending on the specific purposes, this has been set out in the table below:

How we plan to use your data

Category(ies) of data

Lawful basis for processing, including legitimate interest

To complete your registration request.

  • Identity Data
  • Contact Data

Performance of a contract with you or upon your request/registration submission.

To process and deliver services/products and/or perform contractual obligations for you.
  • Identity Data
  • Contact Data
  • Transactional
  • Marketing and Communications Data
  • Performance of a contract with you.
  • Necessary for our legitimate interest.

To manage our relationship with you which could include:

 

  • Notifying you about changes to our terms or privacy policy.
  • Asking you to leave a review or take a survey/questionnaire.
  • Identity Data
  • Contact Data
  • Profile
  • Marketing and Communications Data
  • Performance of a contract with you.
  • Necessary for our legitimate interest, to keep our records updated and to study how customers use our products/services.
To study how our products/services are being used and to develop and grow our products/services and our business when you complete a survey/questionnaire or when you use our products/services.
  • Identity Data
  • Contact Data
  • Profile
  • Usage Data
  • Marketing and Communications Data
  • Necessary for our legitimate interest, to study how customers use our products/services, to develop them and grow our business.
To consider whether you are eligible/suitable for participating in a clinical trial, related to a clinical investigation, or clinical support program sponsored by our clients.
  • Identity Data
  • Contact Data
  • Health Data
  • Necessary for scientific research purposes when participating in the recruitment process to be enrolled in a clinical trial sponsored by one of our clients.
  • Necessary for our client’s legitimate interests in conducting and completing a clinical trial.
To administer and protect our business and this website, including troubleshooting, data analysis, testing, system maintenance, support, reporting, and hosting of data.
  • Identity Data
  • Contact Data
  • Technical Data
  • Necessary for out legitimate interests, for running our business, provision of administration, IT services and network security, to prevent fraud, and in the context of a business reorganization or group restructuring exercise.
  • Necessary to comply with a legal obligation.
  • Necessary to resolve disputes.
To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you.
  • Identity Data
  • Contact Data
  • Profile
  • Usage Data
  • Marketing and Communications Data
  • Technical Data
Necessary for our legitimate interests, to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy.

To use data analytics to improve our website, products and services, marketing, customer relations, experience, and to provide audit record for consent.

  • Technical Data
  • Usage Data
Necessary for our legitimate interests, to define types of customers for our products and services, to keep our website updated and relevant, to develop our business, and inform our marketing strategy.
To make recommendations to you about products or services that may be of interest.
  • Identity Data
  • Contact Data
  • Technical Data
  • Usage Data
  • Profile
Necessary for our legitimate interests, to develop our products and services, and grow our business.
To comply with legal obligations, including government investigations, subpoenas, or other legal process or as otherwise necessary to prevent physical or financial harm or to prevent crime and fraud.
  • Identity Data
  • Contact Data
  • Technical Data
  • Usage Data
  • Profile
  • Necessary for our legitimate interests, to protect our business, employees, customers, and the public.
  • Necessary to comply with a legal obligation.
  • Necessary to resolve disputes.

5.2. DISCLOSING INFOROMATION TO THIRD PARTIES

Trialbee may share your personal data with trusted clients and service providers where needed, as set out below for the purposes set out in the table in section 5.1 above.

  • Clinical research centers, sites, or clinics who are conducting the clinical trial that you submitted your information for.
  • Third party sub-contractors who provide services for us and/or help to provide services to you.
  • Third party sub-contractors who sell, transfer, or merge. If change of control arises in relation to our business, the new owners may use your personal data in the same way as set out in this privacy policy.
  • We may disclose personal information to law enforcement, government authorities, or otherwise in response to a legal subpoena or process as required by applicable law or in the circumstances involving the possibility of physical or financial harm, fraud, or crime.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law.

We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for the specified purposes and in accordance with our instructions.

We do not sell or lease your personal data to any third party. Our use and disclosure of PHI is limited to the minimum amount needed to accomplish the intended purpose of the specific clinical trial and is used in relation to pre-qualification activities for such clinical research studies. This includes using study questionnaires that only ask questions related/associated to the specific clinical research study as specified in approved protocols. Your information will not be disclosed unless we have clear consent from you to do so.

5.3. USE OF HEALTH DATA

The Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and subsequent regulations published by the Department of Health and Human Services (“DHHS”) impose restrictions on other organizations (Covered Entities) which may be covered under HIPAA with respect to your relationship with Trialbee. Trialbee may, in providing recruitment services for one of these organizations, be required to comply with certain aspects of HIPAA in their conduct of human subject research activities.

Although Trialbee is not a Covered Entity as defined in the HIPAA privacy regulations, our policies, and procedures, which govern the privacy rights of research participants included in this privacy policy, are compatible with those required by HIPAA for Covered Entities and will become standard for research activities involving PIHI.

All PIHI data collected by Trialbee in connection with clinical study recruitment is captured electronically and transmitted through a secure network connection to a secure database. Trialbee’s data security policies are consistent with Good Clinical Practices, and HIPAA standards.

5.4. OPTING OUT OF COMMUNICATIONS FROM TRIALBEE

You can opt-out and request us to stop sending you information, and/or reminders, at any time by contacting us at privacy@trialbee.com.

Opting-out of receiving information, and or reminders, will not impact the personal data provided to us because of a product/service such as registration, product/service experience or other transaction.

5.5. USE OF COOKIES

We use cookies and other technologies to improve our website to record user-specific information on webpages which are accessed or visited. The use of cookies allows a better user experience when visitors return to the website.

In addition to using strictly necessary cookies, which are those that allow the website to open and function, we use cookies:

(1) to learn how our website is used and how it performs, including cross-site statistics,

(2) to provide you with additional functionalities and personalization,

(3) to provide you social media interactions, and

(4) for targeting and marketing purposes.

You may set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, some parts of the website may become inaccessible or not function optimally.

5.5.1. COOKIE PRIVACY PREFERENCES AND CONSENT

When you accept cookies, you consent those cookies will be stored on your computer, tablet, or smartphone. If you opt-out of cookies, you will not be able to see all the website content.

5.5.2. USE OF DATA FOR MARKETING

We do not sell, lease, or transfer your personal data to any non-affiliated entity for their own direct marketing use unless we provide clear notice to you and obtain your explicit consent. We use third party advertising companies to place advertising on other websites. These companies may use data about your visits to this and other websites to measure advertising effectiveness and to provide advertisements about goods and services that may be of interest to you. If you would like more information about this practice and your choices to opt out of having this information used by these companies, see our Cookie Policy.

5.5.3. TRIALBEE COOKIE STATEMENT

We use cookies to make the website work optimally. Cookies are used to save your settings, analyse how you browse, and customize content to suit you. They are also used to promote our services, and some cookies come from companies we work with.

6. TRANSFER OF PERSONAL DATA

Your personal information may be stored and processed in any country where we have facilities or service providers, and by using our Service or by providing consent to us (where required by law), you agree to the transfer of information to countries outside of your country of residence, which may provide for different data protection rules than in your country. Appropriate contractual and other measures are in place to protect personal information when it is transferred to our affiliates or third parties in other countries.

7. DATA SECURITY

We and our third-party hosting partners have put in place the appropriate security measures to prevent your personal data from being lost, used, or accessed in an unauthorized way, altered, or disclosed. In addition, we limit access to your personal data with least privilege to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.

We have procedures in place to deal with suspected data security breaches and will notify you and any applicable regulators of breaches in accordance with relevant legal requirements.

8. DATA RETENTION

We will only retain your personal data for as long as necessary to fulfil the purpose we collected it for, including for the purpose of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for persona data, we consider the amount, nature, and sensitivity of the personal data, the potential risk or harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data, and whether we can achieve those purposes through other means, along with the applicable legal requirements.

We also anonymize your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.

9. YOUR DATA PRIVACY RIGHTS UNDER CCPA

If you are a resident of California, you have the following rights under the California Consumer Privacy Act (https://oag.ca.gov/privacy/ccpa), with respect to your personal data:

  • The right to know what Personal Information we have collected, used, disclosed, and sold about you. To submit a request to know, please contact us at privacy@trialbee.com. You also may designate an authorized agent to make a request for access on your behalf.
  • The right to request that we delete any Personal Information we have collected about you. To submit a request for deletion, please contact us. You also may designate an authorized agent to make a request for deletion on your behalf.
  • The right to opt-out of the sale of your personal information.
  • The right to non-discrimination for exercising your rights under the CCPA rights.

When you exercise these rights and submit a proper request to us, we will verify your identity by asking you for identifying information such as your email address, telephone number, and/or information about your account with us. We also may use a third-party verification provider to verify your identity. Please note that we are only required to honour such requests twice in a 12-month period.

Your exercise of these rights will have no adverse effect on the price and quality of our goods or services.

10. CHILDREN

Our website is directed at an adult audience (such as individuals interested in clinical research, healthcare professionals, investors, and individuals seeking information about Trialbee and our products and services). We do not knowingly collect information from or about children. Please do not use this website if you are under 18.

11. OTHER INFORMATION

You should note that if our business (or any part of it) is sold or transferred at any time, the information we hold may form part of the assets transferred although it will still only be used in accordance with this Privacy Policy.

For quality control and training purposes, we may monitor or record your communications with us.