Last update: 1
Almirall S.A and the subsidiaries of the Group Almirall (for more information about our subsidiaries please consult www.almirall.com) (“Almirall”, “we”, “us”, “our”) is committed to the safeguard of the privacy of its stakeholders and the compliance of the data protection principles and applicable laws.
This Privacy Policy (together with our Terms of Use, Our Cookies Policy and any other documents referred to in it) sets out the basis on which any personal data we collect from you when you navigate in www.samassistant.com (the “Site”), or that you provide to us on a voluntary basis, will be collected and processed by us.
By visiting our Site you are agreeing to the practices described in this policy. By providing personal information to us or by using the Site, you agree to the terms and conditions of this Privacy Policy.
For more information about this document or how we process your personal data, you can contact our Global Data Protection Officer at the e-mail address dpo.global@almirall.com
1. Who is the controller of the data you provide?
For the purpose of the General Data Protection Regulations and any local applicable laws, the data controller of the data you provide through this Site is Almirall S.A, a Spanish company with registered office at Ronda del General Mitre, 151, -08022- Barcelona (Spain), with VAT number A-58869389, registered at the Companies Registry, Volume 21795, Folio 32, Sheet no B-28.089, and with the Ministry for Health and Consumer Affairs Registration Number -1889E, or the Almirall affiliates belonging to the Almirall Group of your country of origin. You can find more information about our affiliates at www.almirall.com.
You can contact Us at the telephone number +34 93 291 30 00.
You can find more information about us at www.almirall.com/en/.
Please note that “data controller” means the legal entity that decides the purposes and means of processing your personal data.
2. Which kind of personal data we collect and process?
We may collect and process the following data about you:
a) Information you give us
You may give us information during your registration process in the Site (such as your email address, username, password, specialty, place of work) or whenever you fill in a form which is necessary in addition to such register and/or when you report a problem with our Site.
b) Information you give us when you build a Case
You may additionally provide information related to your patients on the Cases you build. You are responsible for gathering the express consent of your patient and storing just anonymized information in the Site. Such patient’s information must not involve identifying details (i.e. comments, images or basic patient profile data that will be used through the Site, avatar, gender, race, age, height, weight, medical data, medical history, treatment, visualization of the status of disease, calculator of disease indices, etc.). You are obliged to keep the identification details of the patient separated from the clinical data to guarantee the anonymization of the patient, following the principles of patient autonomy. Therefore, all the information you store in a Case will generate the patient’s history in relation to the initial date of its creation of your Case shall be stored in accordance with our Terms of Use.
We reserve the right to review the Cases and to alert you in case we find information that may make identifiable a patient. In case you do not proceed immediately to duly anonymize any information, we reserve our right to delete the non-compliant contents.
In each case, we try to limit to collect the necessary information we need to process your request in each case.
c) Information we collect about you
As you navigate around the Site, certain information can be passively collected (that is, gathered without your actively providing the information), using various technologies. We and our third-party service providers passively collect and use information in the following ways:
- Using cookies: Cookies are pieces of information stored directly on the computer you are using. Cookies allow us to collect information such as browser type, time spent on the Site, pages visited, and language preferences. We and our service providers use the information for security purposes, to facilitate navigation and to display information more effectively. We also use cookies to recognize your computer or device, which makes your use of the Site easier and makes the Site display properly on your device. In addition, we use cookies to gather statistical information about Site usage in order to continually improve its design and functionality, understand how individuals use it, and to assist us with resolving questions regarding it. Some of our cookies are managed for us by third parties. You can refuse to accept these cookies by following your browser’s instructions; however, if you do not accept them, you may experience some inconvenience in your use of the Site. To learn more about cookies, please take a look to our Cookies Policy.
- Through your browser: The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are: browser type and browser version, operating system used, deferrer URL, host name of the accessing computer, time of the server request and IP address.
Information gathered through cookies will be anonymized and processed in aggregate.
3. For what purposes do we need your personal data?
Your personal data will be used for different purposes as follows:
- To provide you with the services and contents to which you may have access through the Site, such as for instance, the creation of your Cases or Pre-set Cases.
- These platform services also include sending electronic communications (newsletters) strictly related to the Site as more fully explained in our Terms of Use.
- Part of the data is collected also in order to ensure error-free provision of the Site and provide you with the necessary technical help and support that may be requested by you, improve the services offered through the platform and to offer you customized views depending on the data that you have already provided during the registration process. We might also use them to have analytics about the traffic of our Site.
- Almirall will take statistics, patterns and trends made from anonymized data.
Your personal data will not be used for any other different purposes.
4. For how long will we keep your personal data?
The personal data you provide will be stored and processed until the earlier of: your request to us to erase your personal data and cancel your account (as indicated in section 6 below), or until the period of time in which Almirall is obliged to comply with any legal obligation that may arise in connection with any service provided through the Site or if we identify you as an “inactive” user, as more fully detailed in our Terms of Use.
5. Which is our lawfulness to process your personal data?
The processing of your personal data for the purposes indicated above is based on your specific consent. If you use the Site without register and log in, the lawfulness lies on the legitimate interest we have to run the Site.
6. Are we going to share your personal data?
Data will not be shared with third parties other than our services providers who help us to better provide you with the services related to the Site and to make direct marketing based on your profile (i.e. agencies that help us to organize events, for digital campaigns, data analytics, among others), (hereinafter, the “Recipients”).
Whenever information needs to be transferred to Recipients outside the European Economic Area to a country, which has not received the decision of adequate level of protection issued by the European Commission, personal data will be duly protected by standard contractual clauses approved by the European Commission, the relevant Privacy Shield certification or binding corporate rules of the data processor.
7. Which are your rights as data subject and how you can exercise them?
You may exercise at any time any of the following rights before Almirall in connection with the processing of your personal data:
- Right of access: means the right to obtain access to your information that Almirall processes.
- Right to rectification: means the right to be entitled to have your information corrected if it is inaccurate or incomplete.
- Right to erasure: in simple terms, it means to request the deletion or removal of the information concerning him/her where there is no compelling reason for an organization to keep using it. This right is also known as “the right to be forgotten” and is not a general right to erasure; there are exceptions.
- Right to restrict processing: means the right to ‘block’ or suppress further use of the information concerning You in certain circumstances. When processing is restricted, we inform you that Almirall can still store your information, but may not use it further.
- Right to data portability: means the right to obtain and reuse personal data by a third party in a structured, commonly used and machine readable format in certain circumstances. If you request the direct transfer of the data to another data controller, this will only take place if it is technically feasible.
- Right to object: means the right to object to certain types of processing, in certain circumstances.
The lawfulness of the data processing up to your consent withdrawal remains unaffected by the revocation.
If you would like to exercise any of the abovementioned rights, you can send us an electronic request to our address dpo.global@almirall.com, attaching a copy of your personal ID card/passport.
Finally, we inform you that you can contact the Spanish Data Protection Agency or any European supervisory entity for any claim arising from the processing of your personal data. You can find an updated list of such organizations by jurisdiction at http://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm.