Last updated: September 1, 2023
The protection of personal privacy is crucial to ensuring the future of our group. GNM Healthcare Group Companies Inc ("GNM Healthcare") has developed this Privacy Statement as a reflection of our commitment to privacy and data protection. This document outlines our practices for managing information that can be used to directly or indirectly identify an individual ("Personal Data").
The following is a summary of our privacy policy. For further information, please refer to our full "Group policy".
The purpose of the privacy statement is to explain what Personal Data is processed by GNM Healthcare, who uses your Personal Data, for what purpose(s), for how long, and what rights you have in this context.
Who collects and processes your Personal Data? GNM Healthcare in the form of the relevant legal entity, i.e. either GNM Healthcare Consulting Group Companies Inc or another entity forming part of the GNM Healthcare international group.
The GNM Healthcare Privacy Statement describes in detail which processing activities apply to which GNM Healthcare Group entity.
What personal data is collected by GNM Healthcare?
We may collect personal data from you in the course of our activities, in particular when you use our site, when you contact us or request information, when you choose to subscribe to our services or because of the relationship you may have with one or more members of our team and with our customers.
The main purpose of collecting personal information is to help us to:
- check your identity
- provide our services
- improve, develop and market new services
- respond to requests you have made on the site or in connection with our services
- comply with any applicable law, court order, other legal process, or the requirements of any regulatory authority
- uphold the agreements we have entered into in the course of our business activities
- protect the rights, property or safety of ourselves or third parties, including our other customers and users of the site or our services
- use data as required or authorized by law
For what purpose(s) does GNM Healthcare collect your Personal Data?
Information relating to your use of the services is collected for the following purposes:
Registration. To use the Services, you may be required to open an account and provide certain personal information such as your name, e-mail address, postal code, profession, occupation, specialty and, depending on your country of practice, your medical license number or equivalent. You may choose to update or supplement the personal information you provided when registering at any time via your account settings or by contacting GNM Healthcare Customer Service at info@gnmhealthcare.com.
Service information. We automatically collect and store information about your use of the Services, such as your engagement with particular content, including editorials, advertisements, information programs sponsored by our advertisers, which may include pharmaceutical companies ("Sponsored Programs"), whether you opened a particular e-mail, clicked on a link, your search queries and how often and when you engage with the Services. We also collect information about your device when you access the Services, including IP address, precise location information, browser information (including referring URL), cookie information and advertising ID (which is a unique, user-resettable identification number for advertising associated with a mobile device). We use cookies to collect information about your use of our services and your device. For more information about our use of cookies and other tracking technologies in connection with your use of the GNM Healthcare network, see our Cookie Policy.
Market research. You may be invited to participate in market surveys conducted by us or on our behalf for internal marketing purposes, as well as market surveys conducted by or on behalf of third-party sponsors who have commissioned the survey. For some surveys, you may be asked to provide personal information in order to contact you again (for example, by e-mail or telephone).
Information and registration forms. From time to time, we may offer you the opportunity to receive additional information or services from us or from third parties, including our advertisers (for example, sample requests, sales representative visits, direct marketing, etc.). If you wish to participate in such opportunities, you may be asked to provide personal information to fulfill the request. Unless otherwise specified in the request form, we may use such information as described in this Privacy Policy and the third party, if any, will be required to use such personal information as described at the time of collection.
Information from third party sources. We may obtain additional information about you from third-party sources to help us provide the Services. For example, we may use information from third parties to verify and supplement your registration information, for research purposes or to personalize services, including advertising.
Unregistered users. You must register with GNM Healthcare Network to obtain full access to the services; however, you may be able to access certain limited services without registering. Even if you are not registered, we collect information about your use of the services through cookies and other tracking technologies. The information we collect includes the referring website, if any, the type of browser you use, the material viewed, and the time and date you accessed the services.
Transfer to third parties. Transfer to recipients such as other GNM Healthcare Group entities, third-party service providers, GNM Healthcare partners and others.
If you would like to know more about each of the purposes for which GNM Healthcare may collect, transfer and use your Personal Data, including how long your data will be retained and specific aspects of the General Data Protection Regulation (GDPR), the legal basis on which GNM Healthcare pursues said purposes, please refer to the more comprehensive privacy statement below.
What are your data protection rights?
You have the right to ask GNM Healthcare for access to your personal data and/or the correction, return or deletion of said personal data. You may ask GNM Healthcare to restrict access to your Personal Data or to exclude it from further processing. You may revoke consent previously given or object to processing activities that GNM Healthcare may consider in a particular case. If you believe that GNM Healthcare is not processing your Personal Data in accordance with this Privacy Statement or applicable data protection laws, you are entitled to lodge a complaint with a competent supervisory authority. The GNM Healthcare Privacy Statement describes each of these rights in detail, specifying how to contact us to exercise any of them against GNM Healthcare and how to identify, if necessary, the relevant data protection authority.
In the last article below, GNM Healthcare discusses a number of national aspects that need to be explained in a privacy statement under the legislation in force in the country concerned. National requirements include those applicable in the EU and EEA, in the United States of America and more specifically in the State of California, as well as in other states around the world concerned with the protection of personal information.
What is meant by the term "GNM Healthcare" in this privacy statement?
This privacy statement applies to the collection and processing of Personal Data:
GNM Healthcare Group Companies Inc, GNM Healthcare Consulting France, and therefore each GNM Healthcare Group entity concerned are, as the case may be, hereinafter referred to as "GNM Healthcare".
This privacy statement does not apply to GNM Healthcare web pages or web services that have their own privacy statement.
For what purposes does GNM Healthcare process your Personal Data?
In the course of its activities and the operation of its various web presences and other communication channels, GNM Healthcare processes the Personal Data of persons with whom the company interacts, including customers, partners, contractors, suppliers and any other persons with whom interactions take place.
In each of these cases, GNM Healthcare may process Personal Data for one or more of the following operational purposes:
a-Providing services. We may use the information collected about you to provide and improve services and to develop new services. Services may include web services, applications, online forums, webinars and events, newsletters with non-marketing content or white papers. When you subscribe or consider subscribing to services from GNM Healthcare or if you act as a designated contact for the business relationship between a client or partner company and GNM Healthcare (a "Client Contact"), GNM Healthcare will use your Personal Data for this purpose. Specifically, GNM Healthcare may use your Personal Data to confirm the opening of a user account, to manage the performance of the contract and to provide you with information required by law.
b-Member profiles. We may combine the information we have collected about your use of the Services with your registration information and any other information we have about you, as described in this Privacy Policy, creating a profile of you (this is not profiling in the sense of behavioral tracking) that we may update from time to time ("Member Profile"). This processing of your member profile is necessary to provide you with services tailored to your specialty and interests (known or inferred), as described in more detail below in the section Personalizing services, including advertising.
c-Communications. By registering as a member of GNM Healthcare, you agree to the use of your registration information and other information collected about you, as described in this Privacy Policy, to communicate with you about services and other information that may be of interest to you. These communications may be transmitted through various channels, subject to applicable law, including e-mail, and may contain advertisements and other promotional materials from third-party sponsors, including pharmaceutical companies.
d-Customize services, including advertising. We may personalize services, including the advertising you see in GNM Healthcare, on third-party websites, and in our e-mail communications, based on information included in your member profile. For example, a user GNM Healthcare believes to be a cardiologist or who has browsed cardiology content with GNM Healthcare may receive advertising promoting a particular cardiac product within GNM Healthcare, on third-party websites and/or in an email that a user GNM Healthcare believes to be a neurologist or who has not browsed cardiology content will not see.
Personalization is necessary to fulfill the contract between you and us under which we provide the services. We analyze or infer your preferences and interests based on a number of factors, including:
- your profile (information provided at the time of registration), enriched with other information obtained from third-party sources in order to guarantee the accuracy of our data and to comply with our legal obligations.
- your interactions with our services and GNM Healthcare, such as:
- your consultation and search history,
- the time and place of your access to our services,
- he device you are using,
- your answers to surveys and quizzes,
- our content that you post, like, share or recommend, including through social media. Other users with similar tastes and preferences on our service.
- your interactions with other websites, including GNM Healthcare Network, subject to our cookie policy.
- This information is used to classify users into different groups or segments, using algorithms and machine learning. This analysis allows us to identify links and patterns between different behaviors and characteristics in order to recommend relevant services to you. This will never prevent you from accessing and browsing the services available within GNM Healthcare.
e-Electronic verification. We may use your information to recognize you as a registered member when you visit one of our properties and to verify your identity and/or professional credentials. We may ask you to provide proof of your identity, including that you are a healthcare professional, and if you are unable to do so to our reasonable satisfaction, we reserve the right to deny you access to the services. While we take steps to verify that our members who identify themselves as healthcare professionals are indeed healthcare professionals, we make no guarantees as to their identity, professional credentials or licensure status.
f-Account management. We may use your information to manage your account, answer your questions, fulfill your requests and send you administrative communications about the services.
g-Investigations. We may use your information to detect, investigate and defend against fraudulent or illegal activities, violations of GNM Healthcare's terms of use and to establish, exercise and defend our legal rights.
h-Marketing/communications. We conduct e-mail marketing activities using your personal information. We use the information we observe about you from your interactions with our site, from our e-mail communications with you and/or with services (see the Customer insight and analysis section below for details of what information is collected and how) to send you marketing communications.
i-Compliance with laws and regulations. If necessary, GNM Healthcare uses Personal Data to prevent criminal activities such as any form of cybercrime, illegal use of our products and services or fraud, to prosecute in connection with such activities, as well as to enforce our rights or defend GNM Healthcare against any legal action.
To comply with data protection requirements, depending on the country in which the relevant GNM Healthcare Group entity operates, and whether you have expressly agreed or declined to receive marketing information, GNM Healthcare may process the Personal Data necessary to take into account your privacy and data protection choices for the receipt of such information. In addition, where necessary for compliance purposes, GNM Healthcare may exchange such information with other GNM Healthcare Group entities.
j-Notifications to keep you informed. In the context of an existing business relationship between you and GNM Healthcare, GNM Healthcare processes your Personal Data to provide you with information about GNM Healthcare services similar or related to those you have already used. GNM Healthcare will communicate such information to you by e-mail where permitted by law or where GNM Healthcare has collected such data as part of the business relationship. You may object to GNM Healthcare using your data for this purpose at any time by selecting the unsubscribe option at the bottom of each marketing message.
What personal data is processed by GNM Healthcare?
GNM Healthcare processes different types of Personal Data about the people with whom we interact in the course of our business or through our various web presences and other communication channels.
Depending on the case, these may be of the following types:
Professional contact details
GNM Healthcare processes the following categories of Personal Data as contact information: first name, last name, e-mail addresses, postal address/location (country, state/province, city), telephone numbers and professional number (doctors).
Personal data related to the commercial relationship with GNM HEALTHCARE
In the context of existing business relationships, GNM Healthcare processes the partner/laboratory's company name, specialty and function as data.
Compliance-related personal data
If required by law or regulation, GNM Healthcare may process categories of data such as date of birth, university degrees, identity cards or other identification numbers, geolocation data, relevant information about partners concerning, for example, major litigation or other legal proceedings, as well as other relevant information.
Data generated by your use of or participation in GNM Healthcare Internet pages, websites or online offers
Usage data
GNM Healthcare processes certain user-related information, such as information about your browser, operating system or IP address when you visit GNM Healthcare websites. We also process information about your use of our web offerings, such as the pages you visit, the time you spend on a page, the page that referred you to our page and the links you select on our sites.
Registration data
GNM HEALTHCARE may process your contact information as described above as well as other information you may provide directly to GNM Healthcare when you register for GNM Healthcare events or other web services.
Participation data
When you participate in webinars, virtual seminars, events or other GNM Healthcare web services, GNM Healthcare may process your interactions with the relevant web service to organize the event, related sessions, polls and surveys and other interactions with GNM Healthcare and/or other participants. Depending on the event and subject to notification to participants to that effect, GNM Healthcare may collect audio and video recordings of the event or session.
Special categories of Personal Data
When registering for an event, GNM Healthcare may ask you about your dietary preferences or potential disabilities, with the aim of taking into account the health and well-being of its guests. Any collection of such information is always based on the consent of the participants. Please note that if you do not provide such information regarding your dietary preferences, GNM Healthcare may not be able to respond to requests of this type at the time of the event.
Personal data obtained from third-party sources, including publicly available sources
GNM Healthcare generally seeks to collect Personal Data directly from data subjects. If you permit GNM Healthcare to do so (or if permitted by applicable law), GNM Healthcare may also obtain Personal Data from third party sources. Such third-party sources may include:
- any third party you have authorized to share your Personal Data with GNM Healthcare;
- third-party and publicly accessible sources, such as social networks aimed at professionals or information brokers.
Where we collect Personal Data from third party sources, established internal controls are designed to ensure that the third-party source is authorized to provide such information to GNM Healthcare and that we can use it for this purpose. GNM Healthcare will process such Personal Data in accordance with this Privacy Statement and in compliance with any additional restrictions imposed by the third party that provided the data to GNM Healthcare or by applicable national legislation.
How long does GNM Healthcare process your Personal Data?
GNM Healthcare processes your personal data for as long as necessary:
GNM Healthcare may retain your Personal Data for an additional period to comply with legal obligations that apply to the processing of your Personal Data or if it is necessary for GNM Healthcare to enforce its rights or defend itself against legal claims. GNM Healthcare will keep your Personal Data securely until the end of the applicable retention period or until the legal action is closed.
Who will receive your personal data?
Your Personal Data may be transmitted to the following categories of third parties:
What are your data protection rights?
Right of access, rectification and deletion
You may at any time ask GNM Healthcare to tell you what Personal Data about you GNM Healthcare is processing and, if necessary, request the correction or deletion of such data. Please note, however, that GNM Healthcare may or will delete your Personal Data only in the absence of a legal obligation or overriding right requiring or permitting GNM Healthcare to retain it. If you request GNM Healthcare to delete your Personal Data, you may no longer be able to use GNM Healthcare services that require the use of such data.
Right to receive your personal data from GNM Healthcare
If GNM Healthcare uses your Personal Data based on your consent or in order to perform a contract entered into with you, you may ask GNM Healthcare for a copy of the Personal Data you have provided. In this case, please contact dpo@gnmhealtcare.com specifying the information or processing activities to which your request relates, the format in which you wish to obtain such data and the recipient to whom it is to be sent, which may be yourself or a third party. GNM Healthcare will carefully examine your request and discuss with you how best to respond.
Right of restriction
You may request GNM Healthcare to cease any further processing of your Personal Data if:
- you declare that the Personal Data held about you is incorrect, subject to the time GNM Healthcare needs to verify the accuracy of the Personal Data concerned ;
- there is no legal basis for GNM Healthcare to process your Personal Data, and you require GNM Healthcare to cease processing your Personal Data ;
- GNM Healthcare no longer needs to retain your Personal Data, but you declare that you require GNM Healthcare to retain it in order to assert or exercise legal rights or defend against third party claims ;
- you object to the processing of your Personal Data by GNM Healthcare based on a legitimate interest of GNM Healthcare (as defined below), subject to the time necessary for GNM Healthcare to determine whether there is an overriding interest or legal obligation requiring the processing of your Personal Data.
Right to object
If and to the extent that GNM Healthcare processes your Personal Data based on a GNM Healthcare Legitimate Interest, in particular where GNM Healthcare pursues its legitimate interest in carrying out marketing activities, you may object to such use of your Personal Data at any time. GNM Healthcare will immediately stop processing your Personal Data for direct marketing purposes once you have made such a request. In all other cases, GNM Healthcare will carefully consider your objection and will thereafter cease to use the information concerned unless there are compelling and legitimate reasons for GNM Healthcare to continue to use such information which may override the reason for your objection, or if GNM Healthcare needs the information in question to assert, exercise and defend its legal rights.
Right to revoke your consent
Whenever GNM Healthcare processes your Personal Data based on your consent, you may withdraw your consent at any time by unsubscribing or sending us a notice of withdrawal. In the event of withdrawal of consent, GNM Healthcare will no longer process the Personal Data subject to such consent, unless required to do so by law. If GNM Healthcare is required to retain your Personal Data for legal reasons, it will not be further processed and will only be retained for the period required by law. Nevertheless, a withdrawal of consent has no effect on previous processing of Personal Data carried out by GNM Healthcare up to the time of your withdrawal. Furthermore, if your use of a GNM Healthcare offer requires your prior consent, GNM Healthcare will no longer be able to provide you with the service concerned.
Right to file a complaint
If you believe that GNM Healthcare is not processing your Personal Data in accordance with the requirements set out in this privacy statement or applicable data protection laws, you may at any time, in accordance with applicable law, make a complaint to the relevant local data protection authority, in particular if you reside in an EEA country, or to the data protection authority of the country or state where GNM Healthcare's registered office is located.
How can you exercise your data protection rights?
Please address any requests relating to the exercise of your rights to: dpo@gnmhealtcare.com
How will GNM Healthcare deal with requests to exercise data protection rights?
GNM Healthcare will take the necessary steps to verify your identity with a reasonable degree of certainty before processing the data protection right you wish to exercise. Wherever possible, GNM Healthcare will compare the Personal Data you provide when submitting a request to exercise your rights with information already managed by GNM Healthcare. In particular, this may involve comparing two or more data points provided when submitting your request with two or more data points already managed by GNM Healthcare.
GNM Healthcare will refuse to process requests that are manifestly unfounded, excessive, fraudulent, represented by third parties without duly representing the respective authority, or otherwise unrelated to the provisions of local law.
Can I use GNM Healthcare services as a minor?
Generally, GNM Healthcare websites and online services are not intended for users under the age of 16 or the equivalent minimum age in the relevant jurisdiction. If you are under 16, you may not register for or use the websites or online services.
Additional privacy provisions specific to certain countries or regions
Where GNM Healthcare is subject to data protection requirements in the EU, EEA or other countries affected by the GDPR
Who is the Data Protection Officer for the Data Controller?
You can contact the GNM Healthcare Group Data Protection Officer at any time at dpo@gnmhealtcare.com or infoprivacypolicy@gnmhealthcare.com.
Who is the data protection authority for the Data Controller in Europe?
GNM Healthcare's main supervisory authority for data protection is in France. It is the Commission Nationale Informatique et Libertés at 3 place de Fontenoy 75007 Paris, France. GNM Healthcare has appointed a Data Protection Officer at the CNIL. He can be contacted at: dpo@gnmhealtcare.com
If you live in another EU or EEA country, you can find the contact details of your competent data protection supervisory authority here.
What legal authorizations does GNM Healthcare have to process Personal Data?
GNM Healthcare processes your Personal Data for the operational purposes defined above based on the following legal authorizations:
General note on GNM Healthcare's processing of personal data based on your prior consent
GNM Healthcare may process your Personal Data for the specific purposes covered by your prior consent.
General note on GNM Healthcare's processing of Personal Data based on a legitimate interest
In cases where we mention Article 6.1 (f) of the GDPR and, therefore, GNM Healthcare's legitimate interest, as the legal basis authorizing us to process your Personal Data, GNM Healthcare pursues its legitimate interests:
- to effectively manage and execute its business activities ;
- to maintain and operate intelligent management processes within a group structure optimized in terms of division of labor and in the interests of our employees, customers and partners ;
- to maintain lasting business relationships with GNM Healthcare customers and partners ;
- to provide you with the best possible user experience when using GNM Healthcare web services ;
- to comply with certain extraterritorial laws and regulations ;
- to assert your rights or defend against legal action.
We believe that our interest in pursuing these business purposes is legitimate and, therefore, that we should not cease processing on the grounds that your personal interest and rights would be overriding. In all such cases, we take due account in our balancing of the following criteria:
- the operational purpose reasonably pursued by GNM Healthcare in the case in question ;
- the categories, volume and degree of sensitivity of the Personal Data that must necessarily be processed ;
- the level of protection of your Personal Data that is provided through our general data protection policies, guidelines and processes ;
- and the rights you have in relation to the processing activity.
If you would like more information about this process, please contact the Data Protection Officer (DPO) at: dpo@gnmhealtcare.com
Guaranteed compliance with laws and regulations
To ensure compliance with applicable laws and regulations, GNM Healthcare and local GNM Healthcare Group entities may process your Personal Data based on the following:
- Article 6.1 (c) of the GDPR, if necessary to comply with the legal requirements of the legislation of the European Union or EU Member States to which GNM Healthcare is subject ;
- Article 6.1 (f) of the RGPD, if necessary, to comply with extraterritorial laws and regulations vis-à-vis the EU (legitimate interest in complying with extraterritorial laws and regulations) ;
- or equivalent articles of other national laws, where applicable.
Management of GNM Healthcare web pages, web offers and other online events
As part of the management of its Internet pages, web offers or other online events ("web services") and depending on the operational purpose concerned, GNM Healthcare or the local entity of the GNM Healthcare Group processes your Personal Data based on the following legal authorizations:
- Article 6.1 (b) and (f) of the GDPR to provide web services and functions, create and administer your online account, update, secure, troubleshoot the service, provide support, improve and develop the web service, respond to your requests or carry out your instructions (legitimate interest in efficiently performing or managing GNM Healthcare's operational activities) ;
- Article 6.1 (c) and (f) of the GDPR to manage and ensure the security of our web services and to prevent and detect security threats, fraud or other criminal or malicious activities and, where applicable, to enforce the terms of the web services, to initiate or pursue legal action or defense, to prevent fraud or other unlawful activities, including attacks against our computer systems (legitimate interest to effectively perform or manage GNM Healthcare's operational activities and to enforce its rights or defend against legal action) ;
- Article 6.1 (a) of the GDPR if it is necessary for us to ask for your consent to process your Personal Data ;
- or equivalent legal authorizations under other applicable national laws.
Cookies and similar tools
In the context of monitoring and evaluating the behavior of users of our web services by means of cookies or similar technologies, GNM Healthcare processes your Personal Data based on the following legal authorizations:
- Article 6.1 (a) of the GDPR if it is necessary for us to ask for your consent to process your Personal Data ;
- Article 6.1 (f) of the RGPD if necessary to fulfil (pre)contractual obligations towards the company or other legal entity you represent as Customer Contact (legitimate interest in efficiently performing or managing GNM Healthcare's operational activities) ;
- or equivalent legal authorizations under other applicable national laws.
Data collection from third parties, including publicly available sources
In the context of the collection of Personal Data concerning you from third parties, the legal basis for such collection by GNM Healthcare or the local entity of the GNM Healthcare Group may be based on:
- Article 6.1 (a) of the GDPR if it is necessary for your consent to the processing of your Personal Data to be requested by us or by the third party transferring your Personal Data to GNM Healthcare ;
- Article 6.1 (b) of the GDPR if necessary to fulfill (pre)contractual obligations to you ;
- Article 6.1 (c) of the GDPR, if necessary to comply with the legal requirements of the legislation of the European Union or EU Member States to which GNM Healthcare is subject ;
- Article 6.1 (f) of the GDPR if necessary to comply with extraterritorial laws and regulations vis-à-vis the EU (legitimate interest in complying with extraterritorial laws and regulations), or to maintain our business relationship with you, ensure your satisfaction as a user or customer representative and provide you with information about other GNM Healthcare products and services in response to an interest you have expressed or a request from you (legitimate interest in maintaining lasting business relationships with GNM Healthcare customers and partners) ;
- or equivalent legal authorizations under other applicable national laws.
How does GNM Healthcare justify international data transfers?
GNM Healthcare is part of an international group of companies operating worldwide and as such works with affiliated companies (the "GNM Healthcare Group") and third-party service providers located outside the European Economic Area ("EEA"). GNM Healthcare may transfer your Personal Data to countries outside the EEA as part of its international business activities. If we transfer Personal Data from an EU or EEA country to a country outside the EEA for which the European Commission has not issued an adequacy decision, GNM Healthcare uses the EU Standard Contractual Clauses to contractually require the data importer to ensure a level of data protection consistent with that of the EEA to protect your Personal Data. You can obtain a copy (redacted to remove commercial or irrelevant information) of said standard contractual clauses by sending a request to dpo@gnmhealtcare.com. You can also obtain further information on the international dimension of data protection from the European Commission here.
Where GNM Healthcare is subject to certain confidentiality requirements in force in the United States, the following provisions apply:
Privacy of children residing in the United States. GNM Healthcare does not knowingly collect Personal Data from children under the age of 13. If you are a parent or guardian and believe that GNM Healthcare has collected information about a child, please contact GNM Healthcare as set forth in this Privacy Statement. GNM Healthcare will take steps to delete the information as soon as possible. Because GNM Healthcare's websites and online services are not directed to users under the age of 16, and in accordance with the disclosure requirements of the CCPA, GNM Healthcare does not sell the Personal Data of minors under the age of 16.
Where GNM Healthcare is subject to certain U.S. privacy requirements in the State of California, the following provisions apply in accordance with the requirements of the California Consumer Privacy Act ("CCPA") and the Consumer Privacy Rights Act ("CRPA").
You can request the following information on how we have collected and used your personal data over the last 12 months:
- The categories of personal information we have collected.
- The categories of sources from which we have collected personal information.
- The professional or commercial purpose of collecting and/or selling personal information.
- The categories of third parties with whom we share personal information.
- Categories of personal information we have sold or disclosed for commercial purposes.
- Categories of third parties to whom personal information has been sold or disclosed for commercial purposes.
- Access: You can request a copy of the personal information we have collected about you in the last 12 months.
- You can ask us to delete the personal information we have collected from you.
- You can exercise the rights described above without being discriminated against under the Data Protection Act.
If you request access to your Personal Data, such information must be portable and, if possible, provided in an easily usable format enabling you to transmit it unhindered to another recipient.
During our business activities, we may share Personal Data with third parties or authorize third parties to collect data on various GNM Healthcare websites.
How to exercise your rights
You may submit requests to exercise your California privacy rights described above as follows:
- Right of information, access and deletion. If you reside in California, you may submit a request to exercise your rights of information, access, deletion and portability by sending an e-mail to infoprivacypolicy@gnmhealthcare.com. In the event of a request for deletion, the client companies (third parties) who have purchased this information are also obliged to respect your wishes.
- You have the right to rectify any inaccurate or outdated data.
- Right to refuse the "sale" and "sharing" of your personal information. We do not sell your personal information in the conventional sense. You can obtain more information and opt-out of the sale and sharing of your personal information by clicking on the Do not sell and share my personal information link on our home page and setting your preferences. You will need to set your preferences from each device and web browser you wish to unsubscribe from. This feature uses a cookie to remember your preferences, so if you delete all cookies from your browser, you'll need to reset your settings.
These rights are not absolute, and, in some cases, we may refuse your request to the extent permitted by law. We will need to verify your identity to process your requests for information, access and deletion and we reserve the right to confirm your California residency. To verify your identity, we may ask you to log in to your user account (if applicable), provide government identification, make a statement as to your identity under penalty of perjury and/or provide additional information.
Your authorized agent may apply on your behalf upon verification of the agent's identity and receipt of a copy of the valid power of attorney given to your authorized agent pursuant to California Probate Code sections 4000-4465. If you have not provided your agent with such a power of attorney, you must provide your agent with a written and signed authorization to exercise your CCPA rights on your behalf, provide the information we request to verify your identity and provide us with written confirmation that you have authorized the authorized agent to submit the application.
Our personal information collection and use practices
The categories of personal information we collect are described below with reference to the statutory categories of personal information specified in the CCPA (California Civil Code section 1798.140):
- Identifiers, such as name, e-mail address, postal address, username, password, IP address.
- Information on Internet or network activity, such as information generated by interactions with our online services, such as data collected via server logs and cookies and similar technologies.
- Geolocation, such as your city or other general location.
- Information from third party sources. We may obtain additional information about you from third-party sources to help us provide the Services. For example, we may use third-party information to verify and supplement your registration information, for research purposes or to personalize the Services, including advertising.
- Inferences we derive from previous information or from other information we collect.
We do not collect any sensitive personal information as defined by the CPRA.
We do not make fully automated decisions.
Sources. Information about Internet/network activity, geolocation, IP address and other online identifiers is collected automatically when you use our online services. We may collect business information and California customer-registered information from our affiliates, third-party data providers or publicly available sources. Otherwise, we collect the above information from you.
Disclosures to third parties for commercial purposes. We describe the categories of third parties to whom we disclose the personal information described above for commercial purposes in the section of our privacy policy entitled "With whom we share your information".
Business/commercial use. We describe the business and commercial purposes for which we use the personal information described above in the section of our privacy policy entitled "How we use your personal information".
This section describes our practices now and during the 12 months prior to the "last update" date of this declaration.
California's Shine the Light law
Under California's Shine the Light law, you may also ask companies with whom you have entered a business relationship primarily for personal, family or household purposes to provide the names of third parties to whom they have disclosed certain personal information (as defined by the Shine the Light law) during the previous calendar year for their own direct marketing purposes and the categories of personal information disclosed. You can send us requests for this information at infoprivacypolicy@gnmhealthcare.com. In your request, you must include the phrase "Shine the Light Request" and provide your full name and mailing address and certify that you are a California resident. We reserve the right to request additional information to confirm your identity and California residency. Please note that we will not accept requests via telephone, mail or fax, and we are not responsible for notices that are not labeled or sent correctly, or that do not contain complete information.
Where GNM HEALTHCARE is subject to the requirements of the Australian Personal Data Protection Act, the provisions of the federal Privacy Act 1988 (Cth) ("Privacy Act") and the Australian Privacy Principles ("APPs") apply.
Where GNM HEALTHCARE is subject to the requirements of the Brazilian Personal Data Protection Law, the provisions of the Brazilian General Data Protection Law ("LGPD") apply.
GNM HEALTHCARE has appointed a Data Protection Officer for Brazil. Written questions, requests or complaints to our DPO can be addressed to: dpo@gnmhealtcare.com
Your privacy rights
- Confirm the existence of treatment ;
- Rectify inaccurate or obsolete information ;
- Request the anonymization, blocking or elimination of unnecessary or excessive personal data processed in violation of Brazilian data protection law ;
- Request a review of decisions taken solely based on automated processing of your personal data whenever they affect your interests ;
- Obtain information about the entities with which we share their personal data ;
- Residents of Brazil may request a list of third parties who have received their personal data for commercial prospecting or direct marketing purposes during the previous calendar year. This list also contains the types of personal data shared. We provide this list free of charge. We will provide this information within 15 (fifteen) days of the date of your request, in accordance with our commercial and industrial secrecy. If you are a resident of Brazil and would like to request this information, please contact us via infoprivacypolicy@gnmhealthcare.com link.
Where GNM HEALTHCARE is subject to the requirements of China's Personal Data Protection Law, the provisions of the Personal Information Protection Law ("PIPL") apply.
Where GNM HEALTHCARE is subject to the requirements of the Personal Data Protection Act of South Korea, the provisions of the Personal Information Protection Act ("PIPA") apply.
In South Korea, we follow the Personal Information Protection Act (PIPA), which prohibits the collection and use of personal data without the user's consent. We have therefore put in place a clear process to obtain users' consent before collecting their personal data, and for them to be able to withdraw it at any time. In addition, clear procedures have been put in place to enable users to exercise their right of access, rectification, erasure and opposition to certain processing operations.
Finally, we have implemented strict security protocols to protect our users' personal data.
GNM HEALTHCARE has appointed a Chief Privacy Officer for South Korea. Written questions, requests or complaints to our CPO may be addressed to: dpo@gnmhealtcare.com
Where GNM HEALTHCARE is subject to the requirements of the Dubai Personal Data Protection Law, the provisions of the Data Protection Law of 2020 ("DIFC Law") apply.
GNM HEALTHCARE has appointed a Chief Privacy Officer (CPO) at Group level. Written questions, requests or complaints to our CPO can be addressed to: dpo@gnmhealtcare.com
Where GNM HEALTHCARE is subject to the requirements of the Indian Personal Data Protection Act, the provisions of the Indian Personal Data Protection Bill 2019 ("PDPB") apply.
Where GNM HEALTHCARE is subject to the requirements of the Personal Data Protection Act of Japan, the provisions of The Act on the Protection of Personal Information ("APPI") apply.
Where GNM HEALTHCARE is subject to the requirements of the Mexican Personal Data Protection Act, the provisions of The Federal Act on the Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares) ("the Law") shall apply.
GNM HEALTHCARE has appointed a Data Protection Officer for Mexico. Written questions, requests, or complaints to our DPO can be addressed to: dpo@gnmhealtcare.com
Where GNM HEALTHCARE is subject to the requirements of the Qatar Personal Data Protection Law, the provisions of the Data Protection Law ("DPL") apply.
Where GNM HEALTHCARE is subject to the requirements of the Singapore Personal Data Protection Act, the provisions of the Personal Data Protection Act 2012 (No. 26 of 2012) ("PDPA"), which was subsequently amended/improved by the Personal Data Protection (Amendment) Act 2020 shall apply.
GNM HEALTHCARE has appointed a Data Protection Officer for Singapore. Written questions, requests or complaints to our Data Protection Officer may be addressed to: dpo@gnmhealtcare.com