EHDEN / Portal

Issue tracking for EHDEN Portal
https://bioinformatics.ua.pt/ehden/
1 stars 0 forks source link

Account Creation Terms and Conditions. #47

Closed PRijnbeek closed 3 years ago

PRijnbeek commented 4 years ago

This text is shown:

"Terms and Conditions for data source contributors and users of the EHDEN Portal About EHDEN Portal The EHDEN Portal will enable verified research users to securely analyse multiple, diverse data sources through a single portal, and thereby enable data users and data sources to collaborate throughout the research lifecycle from data discovery to data access and data analysis. The ultimate aim of EHDEN Portal is to support maximum scientific research value to be derived from health data whilst ensuring patient privacy, and safeguarding the positive reputation and continuity of longitudinal research, and of research organisations. The EHDEN Portal will eventually offer a range of information, data provisioning and analytic services which are intended to support new research from health data. This Code of Practice only relates to the EHDEN Portal currently."

We need to review this text it cannot be used as such when we go live. It needs references to the legal text used for the website with respect to GDPR etc.

joaorafaelalmeida commented 4 years ago

I already updated this with a similar text as the one you mentioned. The text was the following:


Terms and Conditions for data source contributors and users of the EHDEN Portal

Privacy Policy

General

All content of this website [portal.ehden.eu] (hereinafter the “Website”) is owned or controlled by the Consortium of the European Health and Data Evidence Network (EHDEN) Project (hereinafter referred to as the “EHDEN Consortium”). The aim of this Website is to keep the public informed about the activities of the EHDEN Consortium and its efforts in the harmonisation and standardisation of health data.

This Privacy Policy informs you about how we, or our service providers, collect, use, and disclose your information, including personal information via this Website.

1. What data do we collect?

The Personal Data that you give to us, e.g when some areas of the Website may ask you to submit personal information, such as your name, your e-mail address, your phone number and your organisation (the “Personal Information”), in order for you to benefit from some specified features, such as newsletter subscriptions. Also, when you create an account, login in the website, contact us, send us an email, call us. A separate consent will by requested where appropriate.

The data that we create (e.g., data that is collected automatically when you access one of our websites e.g., IP address, device ID, what browser you use or how you interact with EHDEN Portal site.

2. Why do we process your personal data?

We may use data from or about you for the following purposes:

  • to respond to your inquiries and fulfil your requests, such as sending you newsletters or e-mail alerts;
  • to send you important information regarding our relationship with you or regarding the Website, changes to our terms, conditions, and policies and/or other administrative information;
  • for IT purposes, such as enhancing our website and identifying website usage trends.
  • For the EHDEN grant portal: please consult article 9 for more information.

We will only process the collected data for the purposes as described above and will not further process the data in a manner that is incompatible with those purposes.

The data will only be processed in so far necessary to achieve the above mentioned purposes. Your data will also be kept up to date where necessary (for which your input may be required and asked).

The personal data will be processed fairly, lawfully and in a transparent manner, meaning that at least one of the following legal bases applies:

  • We have received your explicit consent for the processing of your personal data;
  • We are obliged to process your personal data according to applicable law or court order;
  • The personal data are processed in view of the legitimate interests of the EHDEN Consortium partners.

3. Who can access your Personal Data and why?

We may disclose information collected through the website in so far necessary to achieve the above mentioned purposes:

  • to the EHDEN Consortium partners, for the purposes as listed above;
  • to our service providers (processors) who provide services such as website hosting and moderating, mobile application hosting, data analysis, IT services, e-mail and direct mail delivery services, auditing services, and other services, in order to enable them to provide services; as we believe to be necessary, if permitted or required by applicable law.

In transferring data to processors, we will conclude a contract with such processor setting out the subject matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller. We will only use processors providing sufficient guarantees to implement appropriate technical and organizational measures so that the processing of the data meets the legal requirements.

4. Do we transfer your Personal Data?

Your personal data will not be transferred to other third parties unless required or allowed by applicable law.

If the processing of your personal data would take place in a third country (i.e. a country outside the European Economic Area) which does not offer an adequate level of protection, this processing shall be carried out in accordance with the requirements and appropriate safeguards under the applicable data protection legislation, such as, entering into EU standard contractual clauses.

With your explicit consent (in so far required), we may also use and disclose information collected through the website in other ways and for any other purpose. In addition, we may use and disclose information that is not considered to be personally identifiable and thus not personal data for any purpose.

5. What are your rights with regard to your personal data?

You have the right to request, review, correct, update, or delete the personal data that you have provided via the Website as described below:

  • Right to inspection: If you are capable of proving your identity, you obtain the right to acquire information about the processing of your data. Consequently, you have the right to the processing objectives, the data categories, the categories of recipients to which the data are sent, the criteria that determine the period of data storage and the rights that you can exercise with regard to your data.
  • Right to correct personal data: Inaccurate or incomplete data may be corrected. It is first and foremost the User’s responsibility to make the necessary modifications to his or her “User Profile”. You may also contact us with a request to modify the data.
  • Right to delete personal data: You also have the right to obtain the deletion of your personal data under the following circumstances:
    • Your personal data are no longer necessary for the intended purpose;
    • You revoke your consent to process your data and there is no other legal basis for processing your data;
    • You have legitimately exercised your right of objection;
    • Your data has been unlawfully processed;
    • Your data must be deleted arising from a legal obligation.
    • Deleting data is primarily related to visibility; the deleted data may remain temporarily stored.
  • Right to restrict processing: In some cases, you have the right to request restrictions on the processing of your personal data. This certainly applies in the case of a dispute relating to the accuracy of data, if the data are necessary in the context of a legal procedure or during the time necessary for EHDEN to determine that you are validly able to exercise your right of deletion.
  • Right to object: You have the right to object at any time to the processing of your personal data for “direct marketing” purposes, profiling purposes or purposes arising from the legitimate interests of the data controller. EHDEN will stop processing your personal data unless it can demonstrate that there are compelling legal reasons to process that prevail over your right to object.
  • Right to data portability: You have the right to obtain the personal data provided to EHDEN in a structured, common and machine-readable form. In addition, you have the right to transfer such personal data to another data controller unless this is technically impossible.
  • Right to withdraw consent and opt-out or unsubscribe to mailing communication: You are entitled to withdraw your consent at any time, purposes and you will receive an unsubscribe link in every communication e-mail you will receive from us.

Where consent is asked from you and you are a child below the age of 16 years, your holder of parental responsibility needs to give or authorise such consent.

6. How can I exercise my rights?

  • Should you wish to exercise your rights, you must submit a written request and proof of identity by email to [enquiries@ehden.eu] or by using our portal.ehden.eu/feedback contact form. We will answer as soon as possible and no later than thirty (30) days after having received your request.
  • Option of lodging a complaint: If you are not satisfied with the processing of your personal data by EHDEN Portal, you are entitled to lodge a complaint with the Data Protection regulator You may lodge a complaint with a supervisory authority competent for your country or region.  Please click find contact information for such authorities here: http://ec.europa.eu/justice/data-protection/article-29/structure/data-protection-authorities/index_en.htm.

7. How do we secure your data?

We use a variety of measures to keep your Personal Data confidential and secure, including restricting access to your Personal Data on a need to know basis and following appropriate security standards to protect your data.

We take every reasonable step to ensure that your Personal Data is only processed for the minimum period necessary in connection with:

  • the purposes set out in this Privacy Notice;
  • any additional purposes notified to you at or before the time of collection of the relevant Personal Data or commencement of the relevant processing; or
  • as required or permitted by applicable law; and thereafter, for the duration of any applicable limitation period. In short, once your Personal Data is no longer required, we will destroy or delete it in a secure manner.

In case of a personal data breach, we will notify the personal data breach to:

(i)  the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons and

(ii) you, the data subject without undue delay if the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons.

8. Statement

Please note that some sites may collect and use data differently. These sites will have a local privacy notice explaining these practices. If the user leaves the EHDEN Consortium website and visits a website operated by a third party, The EHDEN Consortium cannot be held responsible for the protection and privacy of any information that users provide when visiting such third-party websites. Accordingly, users should exercise caution and review the privacy statement applicable to the website in question.

9. EHDEN SME application portal

Article 9 is applicable to the processing of personal information when using the SME application portal only.

The SME application portal is a dedicated portal on the EHDEN website designed to receive SMEs application for the EHDEN SME certification procedure.

You can access the EHDEN SME Application Portal by following the link below. You can register yourself as a grant applicant on the main page of the application portal.

Link to Portal : EHDEN Application Portal

(A) Purpose and legal basis for handling personal information

Personal information that the EHDEN Consortium collects via the grant application portal is used for

  • handling of the SME applications and administration regarding given certifications
  • communication with SME applicants / certification receivers

To the register is being stored

  • the information requested in the SME application forms, including personal information
  • the information regarding given certification and information requested in the final report, including personal information.
  • contact information regarding the SME applicant, members of a working group (…) This information, including personal information, is collected directly from the SME applicant in the portal.

In addition to this, the technical server log information and information regarding the messages between the SME applicant and EHDEN is being collected in the portal.

The basis for collecting and handling personal information is in the consent of the SME applicant. If the applicant includes personal information of other parties, such as project partners, to the grant application, then s/he needs to make sure in beforehand that it is fine for these third parties to have their personal information stored in the grant application portal.

In order for EHDEN to be able to process the application, it is required that the SME applicant provides all the personal information required to complete the application form. If the personal information required in the form is insufficient, EHDEN reserves the right to leave the application in question unprocessed.

(B) Who handles the personal information over the grant applicant in the portal?

Following groups have the right to handle the personal information over grant applicants in the portal:

  • Project management office of EHDEN
  • Employees of the EHDEN Consortium partners and their affiliates
  • Evaluators of the SME applications, designated by EHDEN
  • Persons giving technical support regarding the application portal and applications
  • Auditor of EHDEN and other possibly appointed persons

Access is granted on a need-to-know basis only and only the personal information relevant for the group in question (evaluators/auditor… etc.) is being shown to them in the application portal.

(C) How is personal information in the grant application portal being protected?

The right to use the SME application portal requires a personal user name. The main user of the portal defines the level and the extent of rights in the portal regarding individual users.

In order to be able to log in, a user needs his/her own personal password to the portal. The portal is used through a protected SSL connection. The use of the portal and sign-ins are being continuously monitored.

All the information in the portal is stored in a database. The database is protected with firewalls and other technical means. The database is physically located in a closed and guarded space, accessed only by certain designated persons.

(D) How long is personal information being stored in the application portal?

Usernames

  • Username and personal information connected to it remains saved if the user in question has incomplete/completed applications in the portal.
  • If a username remains inactive, then it will be removed. A username is automatically removed, if it has not been used during the last 4 years in the portal.

Incomplete applications

  • A user can him/herself remove his/her own incomplete applications in the portal.
  • EHDEN will remove all the incomplete applications after a year from the end of the grant application period.
 (E) The right of a user of the SME application portal

As an applicant, a user has the access to their information by signing in to the portal and opening the application form. A user has the right and the obligation to correct possible faulty information. If a user has inquiries regarding faulty information, s/he can address a question to EHDEN using the contact form or by sending a message in the application portal.

We will use your information in accordance with our Privacy Policy to respond to your inquiries and fulfil your requests with regards to the creation of an SME application profile, as necessary for our legitimate interest and possibly to comply with our legal obligations.

The data collected will be your name, your e-mail address, your phone number and your organisation in order for you to benefit from the SME portal features such as creating an account, login in the website, contacting us, sending us an email, calling us

Registration helps us communicate with you better and permits you to participate and submit an application. We will use the information you provide during the enrolment for the purposes mentioned herein, and in accordance with our Privacy Policy.

Please note that your rights related to your personal data remain unchanged. You are entitled to request your data, change it, ask for its deletion, ask for a copy in a machine-readable format and even lodge a complaint if you consider that we didn’t respect your rights. Please refer to the article 5 of this Privacy for a precise list of your rights.

10. Updates to this privacy policy

This Privacy Policy may be changed and updated from time to time. Changes and updates will be announced on our Website. Any changes or updates to this Privacy Policy will become effective when the revised Privacy Policy is posted on the website. This policy was last updated on 26th March 2019.

Legal notice

1. Content

The aim of this Website is to keep the public informed about the activities of the EHDEN Consortium and its efforts in the harmonisation and standardisation of health data. This Website is intended for use by the residents of the European Economic Area.

We strive to keep the information and materials provided on this website up-to-date and accurate. If any errors are brought to our attention, we will do our best to correct them.

2. Disclaimer & Liability

However, the EHDEN Consortium makes no warranties or representations of any kind as to the content’s accuracy, currency or completeness. Neither the EHDEN Consortium, IMI, EFPIA, associated partners or any individual party involved in creating, producing or delivering content for this Website shall be liable for any damages resulting from your access to, or inability to access, this Website or from your reliance on any materials or information provided on this Website.

In order to give the public additional information on the EHDEN project, this Website may provide links or references to external website over which the EHDEN Consortium has no control and for which the EHDEN Consortium partners – except for the EHDEN Consortium partner to whose website the link is made – assume no responsibility. Once you visit an external website, you are subject to the policies of that website. The EHDEN Consortium partners do not intend to advertise or market directly or indirectly any of the products, services or other items which may be mentioned on such external website.

EHDEN Consortium makes no representation or warranty that use of this website, or materials downloaded from it, will not cause computer virus infection or other damage to property. You are advised to ensure that you have adequate measures to prevent any such problems.

3. Acceptable use

Please feel free to explore our Website and, where available, contribute to it.

However, use of the Website and materials posted to it should not be illegal or offensive in any way.  You should be mindful not to:

  • breach another person’s right to privacy;
  • infringe any intellectual property rights;
  • make statements that are defamatory, relate to pornography, are of a racist or xenophobic nature, promote hatred or incite to violence or disorder;
  • jeopardize the integrity of the Website.

4. Intellectual Property

All content of this Website is protected by worldwide copyright. You may download content for your personal use or for non-commercial purposes, but no modification or further reproduction of the content is permitted. Furthermore, it is not permitted to link this Website to any third party website without the EHDEN Consortium’s prior written consent.

The EHDEN Consortium partner’s names and logos and all related trademarks, trade names, and other intellectual property rights are the property of the EHDEN Consortium partners and cannot be used, copied or distributed in any way without the express prior written permission of the EHDEN Consortium partner concerned.

5. IMI funding

The EHDEN project has received funding from the Innovative Medicines Initiative 2 Joint Undertaking (JU) under grant agreement No 806968. The JU receives support from the European Union’s Horizon 2020 research and innovation programme and EFPIA.

6. Update

This legal notice may be changed when necessary. The updated version will always be made available immediately on this Website. This legal notice was last updated on March 2019.

7. Governing law and jurisdiction

You and EHDEN Consortium agree that any claim or dispute relating to the Website shall be governed by the law of Belgium and brought before the courts of Brussels.

8. Contact us

If you have any questions about this Privacy Policy, please contact us by sending an e-mail to enquiries@ehden.eu or by using our contact form (available at portal.ehden.eu/feedback)


PRijnbeek commented 4 years ago

would remove article 9 that does not apply here.

PRijnbeek commented 4 years ago

would not say "for data source contributors", users is enough

PRijnbeek commented 4 years ago

Would leave this open until we sign it off by legal JnJ, will ask Jelle to pick this up.

joaorafaelalmeida commented 4 years ago

The article 9 was removed as well as the mention "for data source contributors".

joaorafaelalmeida commented 3 years ago

This issue was already solved in previous discussions with Jelle Praet.