IDTM DATA PROTECTION POLICY
This policy describes how the International Doping Tests and Management AB (IDTM AB, also referred to as 'IDTM', 'we' or 'us') will make use of your data. References to ‘you’ means the person creating an individual account for the IDTM Healthcare Services Portal (‘the Portal’).
What information do we collect?
We collect and process certain information about you when you create and use an account on the Portal and when you access services via the Portal.
This includes:
- your name, username and password;
- your gender and date of birth;
- your contact details – email address, telephone number, residential address;
- your professional experience, education and other work-related information
Systems used to process data
We gather information directly from you through your use of the Portal. We use the following systems to process your data:
- The Portal;
- IDTM's computer networks and connections;
- remote access systems;
- email and SMS systems;
- telephone, voicemail, mobile phone records; and
- other hardware and software owned, used or provided by or on behalf of us.
Cookies
When you use our website we may gather information about you through Internet access logs, cookies and other technical means. ‘Cookies’ are text files placed on your computer to collect Internet log information and user behaviour information. These are used to track website usage and monitor website activity and for other data processing reasons set out below.
The only cookie we use is essential for our website to operate, a so-called session cookie. It allows the site to remember that you are an authenticated user for the duration of your logged-in session. It gets deleted when you log-out or close your browser.
Reasons for processing
We process information about you for the following reasons:
- Include your professional profile in our network of Healthcare professionals;
- Operational reasons, such as assigning work orders to you;
- Preventing unauthorised access to the Portal; and
- Modifications and improvements to our systems.
Legal bases for processing your personal data
We process your personal data when you create an account on the Portal. The Portal is a necessary system within our business, and improves our ability to handle your personal data fairly and securely. You can upload and download important content about yourself in relation to your IDTM Healthcare profile, and communicate with IDTM.
We process your personal data on the following legal basis:
- As required to pursue and exercise our operations as a Healthcare Service provider, which includes:
- planning and co-ordinating clinical trials;
- processing work orders and match with network members;
- providing you with relevant information needed for your work;
- In pursuit of our legitimate interests (but only where those legitimate interests are not overridden by your data protection interests or fundamental rights and freedoms). Our legitimate interests include:
- updating, consolidating and improving our business and the operation of the IDTM Healthcare Service, as well as the accuracy of our records;
- monitoring and analysing the use of your account; and
- obtaining your feedback and responding to and rectifying complaints received by you and other users of the Portal;
Disclosures and exchange of information
In order to protect the personal data that we collect and process about you, we have robust security measures in place, including:
- Encryption: used when data is transferred between the server and any user;
- 2-factor authentication: used when a user logs on to the system;
- Access logs: to identify who views a a users' sensitive personal data;
- Security logs: to detect if any data is lost or accessed without authority;
Retention period
We store and keep your data as long as you are an active member of IDTM Healcare Services. You can at any point end your membership with us, at which point we permanently delete your personal data within this system.
However, completed work orders for our clients are not deleted as this information is important for our clients and our operations.
Your rights
You have a number of rights over your personal data processed by us. These include your rights to request:
- Access to your personal data.
- Correct incomplete, inaccurate or outdated personal data.
- Transmission of personal data to you or to another person or organisation.
- Erasure of personal data.
- Restriction to our processing of your personal data.
The extent of these rights are limited by law and we may not act on part or all of your request(s) where the right(s) are not applicable. If we do not act on your request, we will explain our reasons why.
Further enquiries
Please contact healthcare@idtm.se or +46 8 555 10 900 if you would like to correct or request access to or (in accordance with applicable law) information that we hold relating to you or if you have any questions about how we process, store, share or use your data. If you request access to your personal data, we may charge a fee for providing that data as permitted by applicable law.
Direct marketing
We will not use the information you provide to conduct any direct marketing.
General
We may need to change this privacy notice in the future. If we make any substantial changes that materially affect you, we will inform you before they take effect.