Effective date: 27 June 2019
Who ‘we’ are?
ERGOMED PLC, having its registered office in Guildford, England, together with its affiliated companies (jointly hereinafter: ‘ERGOMED’ and/or ‘we’) provides services in clinical research, pharmacovigilance, medical writing and recruitment.
At ERGOMED, we are strongly committed to protecting your privacy. To protect your privacy, we provide this notice explaining our general and online information practices and the choices you can make about the way your information is collected and used.
Why does ERGOMED collect personal data?
ERGOMED collects and processes the personal data for the following purposes:
There may be more than one business reason for processing your personal data. Furthermore, the reason(s) for processing your personal data will depend on in which of our services you are interested.
The legal basis in the GDPR for processing your personal data is:
ERGOMED will inform data subjects of the purpose for which it processes their personal data and the types of third parties to which it may disclose their personal data. Notice will be provided in clear language when data subjects are first asked to provide personal data to ERGOMED, or as soon as practicable thereafter, and in any event before ERGOMED processes the personal data for a purpose other than for which it was originally collected.
ERGOMED may not need to furnish notice where the processing in question is required by applicable laws, court orders or government regulations; or is necessary to protect ERGOMED’s legal interests.
What personal data does ERGOMED collect?
ERGOMED endeavours to use and transfer personal data only in ways that are compatible with the purposes for which it was collected or subsequently authorized by the data subject.
The list below identifies the categories of data subjects that ERGOMED processes:
The list below identifies the categories of personal data that ERGOMED collects:
To this effect, ERGOMED processes following personal data while performing below actions and services:
NOTE: Please pay attention! ERGOMED is partnering with SmartRecruiters and is using its recruitment software platform. Keep in mind that there are specifics with regards to personal data processing for job seekers using SmartRecruiters’ Recruiting Software (elaborated in detail in the following section: Recruiting Software – SmartRecruiters).
Recruiting Software – SmartRecruiters
ERGOMED is using services provided by SmartRecruiters. SmartRecruiters is a technology services company which provides a recruitment software platform to other businesses. This software helps Ergomed to publicise its roles, manage its interaction with candidates, assess suitability and manage the offer process.
Please be aware that you may be required to set up a personal account (“Candidate Portal”) which allows you to manage different job opportunities and track your applications of several Employers (one of them potentially being ERGOMED). In your Candidate Portal, which is accessible on https://my.smartrecruiters.com/, you may register through the email you received after applying, or if your consent was requested. This is operated by SmartRecruiters for which it is responsible. The registration requires your email address and a password. Your profile will be made available and visible to the Employer to which you applied. You will receive job alerts from the Employers to which you applied. In order to provide world-class services to you and the Employer, SmartRecruiters uses third-party providers to help perform statistical analysis, technical support, and data hosting. Your application information will be collected by SmartRecruiters and be made available to you through the Candidate Portal. SmartRecruiters will never sell, rent, or lease the collected Personal Data.
Please note that SmartRecruiters will collect the following data from you:
From the ERGOMED perspective, your collected and processed personal data shall be stored for a period of 12 (twelve) months after collection. You may be contacted by Ergomed during this time about relevant job vacancies that become available. After 12 (twelve) months you will be contacted directly from ERGOMED and asked to explicitly opt-in if you want your data still to be used and stored by ERGOMED. Only if you explicitly agree, ERGOMED will continue to process your data. If you do not explicitly agree (opt-in) all of your data collected and stored shall be deleted in line with established procedures within the Company. During the 12-month period you may request deletion of your data at any time.
How personal data will be collected?
Your personal data will be collected primarily from you – through the online forms (our websites or via other channels) or paper forms, your visit card, emails, phone calls, application / recruitment process and others. We may possibly receive your personal data from a third party, too (for example from a recruitment company). Further information will be obtained directly from you during the course of your engagement with us, for example through communication with you.
In conducting clinical research, ERGOMED sources personal data of investigators and research teams from ERGOMED’s databases, indirectly from public sources, data brokers and reliable referrals.
The use of the cookies, Google analytics & plugins
Please note that you can find sharing buttons on our websites (for Facebook, Twitter etc.). Once you use these buttons you will be linked to the social media websites with their own privacy policies (they are not our personal data processors).
Finally, ERGOMED uses a variety of security measures (physical, organizational, electronic, and technical) to enhance the security of personal data processing – both internally and on webpages to secure any personal information from loss, misuse, unauthorized access or disclosure, alteration or destruction.
ERGOMED operates in compliance with detailed policies and procedures. We put in place appropriate, industry accepted controls and measures to mitigate and manage the risk, including but not limited to: security policy, physical and logical security, access control, firewalls including IPS, data encryption, anti-malware scanners, security patching, backups & DRPs and staff training.
ERGOMED archives and processes some documents containing personal data in hard-copy formats. All such documents are stored in lockable cabinets with access granted only to personnel on a need-to-know basis. ERGOMED ERGOMED has implemented various safety measures in case of a fire, such as, smoke detectors and fire-fighting equipment.Furthermore, our offices are supplied with shredders, in order to secure proper disposal of data and preventing unauthorised access to files containing confidential and personal data.
In addition, we have implemented an access control system, by installing card-access at entrance doors to our premises. No biometric data, such as the fingerprints of the users of these cards, are being processed. Also, at the entrance of some of our offices, parking lots and in front of server rooms we installed CCTV (security cameras systems) for the purpose of crime prevention and protecting monitoring server rooms’ access. None of such surveillance is aimed to record ERGOMED employees’ performance. We have displayed warning signs within the area captured by CCTV.
Disclosure and transfer of personal data
ERGOMED will not trade in any way with your personal data. Generally, all information collected through our websites will be sent through to company mailboxes and further processed in the company’s internal network. Our clients and patients use the standard channels of communication to provide us with the personal data for research. We use selected contract-based processors for the processing your personal data which assure the same level of your personal data security as we do.
All companies within ERGOMED Group have executed Intercompany Personal Data Processing Agreement with purpose to create a common policies and procedures for all ERGOMED Group to comply with data protection legislation while processing and transferring personal date between themselves and with third parties.
The cross-border transfer of personal data to a third country (country which is neither an EU member nor an EEA member and which do not ensure an adequate level of data protection as per GDPR) will be carried out by ensuring compliance with all the formalities and procedures reasonably required by the GDPR, such as execution of a Standard Contractual Clauses obtaining written explicit consent of data subjects, etc.
Until the end of 2020, the UK is bound by EU Legislation and still considered as the Member State within the Community (with established and accepted appropriate level of data protection). In In consideration of future changes, this Policy will be further amended accordingly.
For how long does ERGOMED store personal data?
Generally, we will retain your personal data during the statutory (including fiscal) retention periods and limitation periods. If such periods do not apply to the relevant personal data, we will keep your personal data for no longer than is necessary for the purposes for which the personal data is processed, unless the law requires us to hold your personal data for a longer period, or delete it sooner, or unless you exercise your right to have your data erased and we do not need to hold it in connection with any of the reasons permitted or required under the law.
Your IP-address, collected during your website visits, will be deleted as soon as possible, unless there are legitimate security reasons for keeping it.
Please note that where you unsubscribe from our marketing communications, we will keep a record of your email address to ensure that we do not send you marketing emails in future.
At the end of the retention period, your data will be reviewed and deleted, unless there is a specific legitimate reason for keeping it.
What are your rights and obligations regarding your personal data?
With regard to your personal data that ERGOMED processes, you have the right to:
ERGOMED reserves the right to charge in some cases a reasonable fee to cover costs for accommodating your requests.
Furthermore, you have the right to lodge a complaint with your national data protection authority.
All these rights are subject to the conditions as laid down in the GDPR.
You have the right to ask us not to process your personal data for marketing purposes. We will usually upfront inform you if we intend to use your data for such purposes or if we intend to disclose your data to any third party for such purposes.
While conducting clinical research, ERGOMED has no direct relationship with clinical research subject. Therefore, clinical research subjects who participate in the clinical research should address all their requests and inquiries to the investigator or sponsor of the clinical research.
What if you do not want to provide us with your personal data?
Finally, what happens if you do not want to provide ERGOMED with your personal data? Providing appropriate personal data is a precondition for specific services, such as the performance of an executed contract, the possibility to apply successfully for a job, or where there is a legal obligation to process the personal data. Failure to provide specific personal data may affect ERGOMED’s ability to enter into a contract with you, to contact you and/or to proceed with the selection procedure (e.g. investigator, reporter, job applicant, etc.).
Contact, questions and further information
+44 (0)1483 307920
(+1) 781 703 5540
United Kingdom (Head Office)