In accordance with the provisions of the Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation) of 27 April 2016 (hereinafter "RGPD"). PROMETUM SPAIN, S.L.U. (hereinafter "medmesafe") wishes to inform the user of the platform of the policy regarding the processing and protection of personal data belonging to users of the platform.
In addition, the user is informed that these conditions shall apply in a subsidiary manner to those which are established specifically for the same matter and are communicated to the user without limitation through the registration forms thus rendering this policy complementary to the previous conditions in areas which are non-contradictory.
The user is informed that any processing of personal data will fall within the scope of current Spanish legislation on data protection established by the RGPD.
For such purposes, personal data shall be understood to mean any information concerning identified or identifiable natural persons which, in the latter case, unequivocally identifies the data subject. The term user shall be understood to mean any identified or identifiable natural person who accesses the platform and who, through the means provided on the platform, provides their personal data to medmesafe. Such means include, but are not limited to, email and the completion of data collection forms or similar.
1. IDENTIFICATION OF THE REGISTERED NAME OF THE PARTY RESPONSIBLE FOR THE FILE
medmesafe hereby informs the user that PROMETUM SPAIN S.L.U. (hereinafter "medmesafe") is responsible for processing personal data as well as keeping files which contain such personal data in order to collect and store personal data derived from the use of the platform or from any type of communication sent by the user to medmesafe.
2. PURPOSES ASSIGNED TO THE PERSONAL DATA
medmesafe is a platform which provides intermediation and hosting services. The platform enables individuals, who wish to use the services offered on the platform, to contact doctors, medical professionals, laboratories and users (hereinafter collectively referred to as "third parties" or "service providers") who provide their services through the platform, which facilitates the selection, provision and enjoyment of services offered by such service providers.
In order to perform the intermediation activities, medmesafe is divided into two different areas which allow users to register either as individuals, who wish to use the services offered through the platform, or as professionals, who wish to offer their services through the platform.
As a result, the medmesafe platform acts as an intermediation mechanism in order to facilitate the contact between individuals interested in acquiring the analysis, prescription, genetic counselling and advisory services offered by the laboratories and professionals through the platform as well as facilitate the procurement of such services by the individuals in accordance with the terms established by the third-party service providers. The information generated by such services is stored centrally and is only accessible to the individual and the responsible professional assigned to the individual's file.
Therefore, medmesafe does not sell any type of product or service. It only provides an intermediation and hosting service which enables the users of the platform to view, select, offer and procure the services offered on the platform.
Hence, the only data medmesafe is responsible for is that which is provided by users when browsing the platform, completing the individual or professional registration forms and completing the contact or information request forms. The providers of the services offered through the platform shall be responsible for the data provided by the individuals for the procurement of such services and for any data generated during the contractual or service relationship they have with the individuals.
Users who access the medmesafe platform are not obliged to provide personal information to use the platform. Therefore, any communication of data for such purposes will be the result of the user voluntarily deciding to browse or use the services offered through the platform in a personalised manner.
In this sense, forms are available on the platform for purposes which include, but are not limited to, collecting personal data, such as user registration forms for both individuals and professionals, as well as contact forms and information request forms.
Notwithstanding the provisions contained in these conditions, in the aforementioned cases, the data processing conditions established and communicated to the user by medmesafe through the corresponding forms shall prevail in each case. This policy shall apply in a complementary and subsidiary manner to the aforementioned conditions in areas which are non-contradictory.
3. INFORMATION AND CONSENT
In general, personal user data may be processed for purposes including, but not limited to, the following
- If the user contacts medmesafe to make enquiries or request information, the data will be processed in order to handle and respond to the received communications, as well as send the requested information.
- If data is provided to medmesafe so as to register on the platform, the data will be processed for the purposes which apply depending on whether the user is registering as an individual or professional.
3.1. Registering as an Individual:
If the user is registering as an Individual, their data will be processed for the following purposes:
- To manage the process of registering on the platform as well as to guarantee the management and administration of the account and to assign a professional to the individual's file who is registered on the platform and who will be responsible for providing the individual with the proper advice. On their account, the individual will have access to range of services offered by third parties which they may engage and procure according to their profile.
- If the data is provided for the procurement of a service offered by third parties through the platform, the data shall be processed by the responsible provider in order to manage the procurement process and provide the service. They shall provide them with the corresponding information regarding the processing of their personal data derived from the provision of the service.
- In those cases where the individual gives their express consent by checking the corresponding boxes which appear on the 'legal texts' section, their data may be processed for any of the following purposes:
- The issuance of commercial communications and advertisements by medmesafe via email or other equivalent means of electronic communication about products and services offered by third parties through the medmesafe platform relating to prevention and diagnosis as well as life quality improvement, wellbeing and healthy lifestyle. In these cases, their data will be processed by medmesafe to manage the issuance of the commercial communications as well as the potential revocation of consent by the individual, objection to processing, deregistration or exclusion from the issuance of advertisements or from the service. In the latter case, medmesafe may process the minimum amount of data required to guarantee the cessation or non-receipt of the commercial communications and advertisements, if so requested.
- The issuance of commercial communications and advertisements by medmesafe via email or other equivalent means of electronic communication about products and services offered by third parties, with whom medmesafe has established intermediation relationships, relating to prevention and diagnosis as well as life quality improvement, wellbeing and healthy lifestyle. In these cases, the individual's data will be processed by medmesafe to manage the issuance of the commercial communications as well as the potential revocation of consent by the individual, objection to processing, deregistration or exclusion from the issuance of advertisements or from the service. In the latter case, medmesafe may process the minimum amount of data required to guarantee the cessation or non-receipt of the commercial communications and advertisements, if so requested.
- The communication of the individual's contact details by medmesafe to third parties from the prevention, diagnosis, life quality improvement, wellbeing and healthy lifestyle sectors for the issuance of electronic advertisements via email or other equivalent means of electronic communication about their products or services.
- The communication of pseudonymised and anonymised data, which is derived from the analyses and results reports, by the laboratories and professionals to medmesafe for processing for statistical purposes and anonymous integration into research databases and methodological analyses, with the data being removed from any report or analysis of the results.
3.2. "Registering as a Professional:":
If the user is registering as a professional, their data will be processed for the following purposes:
- To carry out the registration process, perform the necessary checks in order to verify compliance with the requirement to be a member of a professional association as well as any other necessary requirements and to create and manage the account the professional has registered on the medmesafe platform in order to provide the services requested by individuals.
- In those cases where the professional gives their express consent by checking the corresponding boxes which appear on the 'legal texts' section, their data may be processed for any of the following purposes:
- The issuance of electronic advertisements by medmesafe via email or other equivalent means of electronic communication about the intermediation services offered by PROMETUM SPAIN, S.L.U.
- The issuance of electronic advertisements by medmesafe via email or other equivalent means of electronic communication about products and services offered by third parties from the prevention, diagnosis, life quality improvement, wellbeing and healthy lifestyle sectors.
- The communication of the professional's contact details by medmesafe to third parties from the prevention, diagnosis, life quality improvement, wellbeing and healthy lifestyle sectors for the issuance of electronic advertisements via email or other equivalent means of electronic communication about their products or services.
Accordingly, if the user does not want their data to be processed by medmesafe, they must refrain from communicating or sending their personal data to medmesafe, thus browsing the platform anonymously or, where appropriate, refraining from using the services available on the platform. Otherwise, we hereby inform users that communicating their data to medmesafe in accordance with the established terms implies that the user gives their free, unequivocal, specific, informed and express consent for their data to be processed by medmesafe.
Personal information will only be used for limited purposes such as those set forth above and/or including but not limited to those which, where appropriate, are unequivocally indicated prior to the collection and processing of the data of the data subject and which therefore constitute legitimate processing on the part of medmesafe.
Within the framework of the provision of services and the content offered through the platform, medmesafe may at any time request personal information about the user of the platform through forms or other means. In such cases, medmesafe will include an informative notice on the data collection form which indicates all of the conditions for processing personal data in accordance with RGPD, such as the obligatory or optional nature of answering the questions on the form, the consequences of obtaining data or refusing to supply it, the purposes of collecting the data as well as the potential transfer of data. Where appropriate, medmesafe shall request the user's consent prior to processing the personal data. In addition, with regard to those services which have special conditions, if these services include an informative text on data protection in order to regulate the use of the service, this policy shall always apply in a complementary and subsidiary manner to such informative texts in areas which are non-contradictory.
4. IDENTIFICATION OF THE RECIPIENTS TO WHOM MEDMESAFE INTENDS TO TRANSFER OR COMMUNICATE DATA
medmesafe only intends to transfer or communicate data where required in accordance with RGPD, in order to implement, comply with and control the relationship with the user and to meet their obligations with the competent public administrations in cases where required according to current legislation and, where appropriate, other entities such as State Security Forces and Bodies, Judges, the Public Prosecutor's Office, Courts, Court of Auditors and the Ombudsman at all times and in all applicable instances.
If the user participates in any event organised by medmesafe, their data may be transferred to third parties involved in the management of the event.
medmesafe hereby informs the user that they are obliged to notify the user of any other obligation to transfer data where provided for in the RGPD. medmesafe shall inform the user in an express, precise and unequivocal manner of the recipients of the information, the purpose of the transfer of the data and the nature of the transferred data or, where provided for in the RGPD, medmesafe shall request the unequivocal, express and informed consent of the user.
5. OTHER RECIPIENTS OF THE INFORMATION
medmesafe advises the user that this entity has sole responsibility and hereby guarantees the confidentiality, security and processing of the data in accordance with this policy with regard to the personal data collected from the user through the platform. medmesafe may not be held responsible for any processing or subsequent use of the personal data performed by third parties who offer their services through the platform and/or third-party providers of information society services which may access such data as a result of the provision of their services or through their operations.
Third-party providers of information society services shall be understood to mean, without limitation, any natural or legal persons who provide the following services: (i) Transmission of data provided by the recipients of the service through a communication network. (ii) Services for accessing the aforementioned network. (iii) Data storage or data hosting services. (iv) Provision of contents or information.
Furthermore, medmesafe shall not be responsible for data processed by third parties who establish hyperlinks to medmesafe, or for those who refer users to the platform through medmesafe hyperlinks.
6. QUALITY OF THE DATA
medmesafe advises the user that, unless in cases of legally constituted representation or with the corresponding authorisation, no user can use the identity of another person and communicate their personal data. The user must therefore take into account at all times that if they use the email or registration service on the platform, they may only provide personal data corresponding to their own identity which must be correct, relevant, up to date, exact and true. To this end, the user shall be solely responsible for any damage, direct and/or indirect, caused to third parties or medmesafe through the use of the personal data of another person or their own personal data if it is false, erroneous, out of date, inadequate or irrelevant. Equally, users who communicate the personal data of a third party shall be liable to them under the information obligation established in RGPD for instances when personal data has not been obtained from the data subject and/or the consequences of not having informed the data subject of such.
7. DATA OF MINORS OR LEGALLY INCAPACITATED PERSONS
In addition, if the user is under eighteen (18) years of age or is legally incapacitated, medmesafe points to the need to obtain the consent of their parents, guardians or legal representatives in order to communicate their personal data to medmesafe. Medmesafe therefore requests that such users refrain from communicating their data through the contact forms and from registering on the platform. The registration and use of the services on this site, in particular the purchase of such services, by persons who are under the age of eighteen (18) years or legally incapacitated is prohibited. In this last case, such persons are not legally represented in accordance with current legislation. Medmesafe shall not be held responsible for the actions of the minor or legally incapacitated person.
8. FOLLOW US ON SOCIAL NETWORKS
Social networks are services provided by third-party providers which enable users to interact with one another in a virtual community. Users can create their own public profile where they can create and share content, information and personal data with other users on the network.
Users can create an account or profile on a social network for professional or personal purposes. The operation of the social network is governed primarily by the conditions established by the owner and/or provider of the network and secondly, with regard to accounts and profiles created for commercial purposes, by the terms and conditions established by the party responsible for the official profile, page or commercial account.
medmesafe has profiles on social networks such as, but not limited to, LinkedIn, Facebook, Twitter and Instagram. You can follow us and become a medmesafe fan on the aforementioned social networks as well as on other social networks we mention on the medmesafe platform.
Our official sites and pages on the social networks are aimed at persons over eighteen (18) years of age. Therefore, if you wish to access our official sites and pages, you must be over eighteen (18) years of age and must carefully read the conditions and policies published by medmesafe.
medmesafe is responsible for the management of their official sites and pages on social networks provided that they are the original official sites and pages created by medmesafe and the social network itself allows medmesafe to manage their official sites and pages.
If the user becomes a follower of the official medmesafe sites and pages, the user must respect the specific conditions established and published on each official site and page by the provider and owner of the social network as well as those published by medmesafe. Becoming a "friend" or "follower" of our official sites and pages on social networks implies that the user consents to the processing of their data as established in the policies and conditions which govern their use as stated above.
medmesafe is not responsible for any unofficial sites and pages created by third parties on the social networks, even those which imitate the look & feel of medmesafe.
medmesafe is responsible for data processed on their official sites and pages on social networks. If the user becomes a friend or follower of our official sites and pages on the social networks, their personal data will be processed in order to properly manage the official website or page, discover their opinions and/or see their comments, as well as inform the user about and include them in the various events held by medmesafe through these official sites and pages on the social networks.
In any case, the user is hereby informed that medmesafe may remove from their official sites and pages on social networks any information which goes against the rules laid down in the legal conditions of the provider or owner of the social network and the special conditions established by medmesafe which govern their official sites and pages, as well as any information which goes against the provisions of the law, morals and public order and/or goes against the legitimate rights of third parties.
Similarly, the owners and providers of the social networks may remove any content which goes against the operating rules and regulations established by the providers or owners of these networks, either automatically or as the result of a complaint made by another user.
To stop following the official medmesafe site or page or any of the official sites and pages on the social networks, the user must follow the steps indicated in the operating conditions and conditions of use established by each network provider without medmesafe being able to intervene in this process. However, medmesafe reserves the right to create, edit, modify and/or remove their official sites and/or pages without informing the user beforehand.
For any questions regarding the processing of follower data on the official medmesafe sites and pages on the social networks, users can contact medmesafe by sending an email to firstname.lastname@example.org or by calling us at +34 91 128 45 91 or by completing the contact form on the platform.
9. UPDATING DATA
Users are the only source of information regarding their personal data. medmesafe therefore requests that users notify medmesafe of any changes to their personal data in order to keep their data up to date at all times in accordance with the principles of the RGPD. Registered users on the platform can make such changes directly by amending the data on their account or through exercising their rights in accordance with the process established in this policy in the section on the exercise of rights of access, rectification, transfer, restriction of processing, cancellation and objection.
10. EXERCISE OF RIGHTS OF OBJECTION AND REVOCATION OF THE CONSENT GIVEN FOR THE RECEIPT OF COMMERCIAL COMMUNICATIONS VIA EMAIL OR OTHER EQUIVALENT MEANS OF ELECTRONIC COMMUNICATION
The user is hereby informed that, under Articles 21.2 and 22.1 of the Spanish Law 34/2002 on the Information Society and Electronic Commerce Services (LSSICE), the user has the right to object to the processing of their data for promotional purposes, such as for the receipt of commercial communications, as well as revoke at any time their consent given for such purposes. In both cases (objection and revocation), the user must simply notify medmesafe of their request for such.
For this, the user can request objection to and/or revocation of consent, as well as exclusion or removal from the subscription service for commercial communications, by sending medmesafe an email to the following address: email@example.com with "Remove" as the subject or by expressly indicating their request for objection, revocation of consent, exclusion from or cessation of the issuance of commercial communications by email or equivalent means of communication.
The user's request will be taken into account by medmesafe in order to guarantee the exercise of their rights to be excluded from the receipt of commercial communications via email or equivalent means of communication in accordance with the legislation on e-commerce and the information society. For this, medmesafe shall process the minimum amount of user data required to guarantee the cessation or non-receipt of the commercial communications and advertisements, if so requested.
11. EXERCISE OF RIGHTS OF ACCESS, RECTIFICATION, TRANSFER, RESTRICTION OF PROCESSING, CANCELLATION AND OBJECTION TO DATA
medmesafe hereby informs the user of the possibility to exercise their rights of access, rectification, transfer, restriction of processing, cancellation and objection by means of written request addressed to medmesafe at the following address or any address which replaces it and is specified in the General Data Protection Register:
PROMETUM SPAIN, S.L.U., calle Zurbano nº 92 (6º Dcha), 28003 Madrid, Spain.
For such purposes, the data subject must send the written communication indicating the request or right they are exercising to PROMETUM, together with a copy of their national identity card or other legally valid proof of identity.
medmesafe reminds the user that, if they are registered on the platform, they may access and amend their data from their account.
12. COOKIES AND DATA STORAGE AND RECOVERY DEVICES IN TERMINAL EQUIPMENT
13. SECURITY MEASURES TAKEN FOR THE PROCESSING OF PERSONAL DATA
medmesafe would like to inform the user that, in accordance with the legal requirements explained in RGPD, technical and admisistrative measures have been taken to guarantee personal data safety, preventing alterations, loss, unauthorised access and treatment, taking into account the technological advances, stored data nature and the inherent risks they are exposed to, taking into consideration those derived from human action and physical or natural environment. We Will only store personal data in adequate files, complying with the Regulation in terms of data integrity and security, and of treatment centers, machines, systems and programs. Medmesafe guarantees the user that professional secrecy confidenciality will be maintained with respect to personal user data, and the duty of storage of these data.
14. RECOMMENDATIONS TO USERS
medmesafe recommends that users install and use the latest software versions when browsing the internet, as they incorporate greater security measures.
Equally, medmesafe recommends that users use the security measures they have at their disposal (secure web servers, cryptography, digital signature, firewall, etc.) to protect the confidentiality and integrity of their data where necessary, as there are risks of impersonation or data breaches.
medmesafe hereby reminds users that the internet is not secure. However, there are measures in place and which are being developed that allow users to better protect their data. medmesafe therefore recommends that users use any available means to protect their data and communications, such as legal encryption for confidential emails and access codes for their own devices with internet access.
Finally, medmesafe points to the importance of reading, understanding and, in case of compliance, accepting the conditions published on websites, especially the legal conditions published on this website, prior to using and, in particular, purchasing services through the platform.
15. POLICY CHANGES
Any modification to this policy will be published and disclosed on the medmesafe platform as well as in the policy itself. The user hereby acknowledges that any processing of data communicated to medmesafe shall be regulated by the published data processing policies and conditions in force at the time when the personal data was provided to medmesafe or by the new, modified version, if the modification is applicable. Such shall apply without prejudice to the preferential application of specific legal texts, such as informative texts inserted in data collection forms as well as the conditions for particular services.
16. CONTACT INFORMATION
medmesafe welcomes any comments from users in relation to this privacy and personal data protection policy. To send us comments or to ask us any questions relating to this policy, the user can contact medmesafe by sending an email to firstname.lastname@example.org or by calling us at +34 91 128 45 91 or by completing the contact form on the platform.