DATENSCHUTZHINWEISE FÜR KLINIKEN VON COLPITTS
Colpitts Clinical, Inc. und die hundertprozentige Tochtergesellschaft Unisphere Travel Ltd., Inc., handelnd unter dem Namen Colpitts Clinical (zusammen “Colpitts Clinical”, “uns”, “wir”, “unser”) haben sich dem Schutz Ihrer Privatsphäre verschrieben. Diese Datenschutzrichtlinie (“Hinweis”) erläutert unsere Datenschutzpraktiken und informiert darüber, wie und warum wir Ihre personenbezogenen Daten durch unsere Interaktion mit Ihnen, über unsere Produkte und Dienstleistungen sowie beim Besuch unserer Tochtergesellschafts-Websites und Subdomains durch Unternehmen oder Einzelpersonen erfassen, verwenden und weitergeben (“Website”), unsere mobilen Anwendungen (“Apps”) oder nutzen Sie unsere Kommunikationsplattformen (“Dienstleistungen”). Die Richtlinie beschreibt auch ihre Möglichkeiten in Bezug auf die Nutzung, den Zugriff, die Löschung und die Berichtigung von personenbezogenen Daten.
Die Datenschutzerklärung von Colpitts Clinical gilt für unsere Kunden (einschließlich der Endnutzer unserer Kunden) und Nutzer (alle anderen Personen, die die Produkte, Dienste, Apps oder die Website von Colpitts Clinical nutzen), die uns personenbezogene Daten direkt durch die Nutzung unserer Website, Apps oder Dienste zur Verfügung stellen (zusammenfassend “Sie”). Es steht Ihnen frei, bestimmte Daten nicht an uns zu übermitteln; dies kann jedoch Ihre Möglichkeiten zur Nutzung unserer Dienste einschränken. Sollten Sie Fragen oder Bedenken hinsichtlich der Verwendung Ihrer personenbezogenen Daten durch uns haben, kontaktieren Sie uns bitte über die am Ende dieser Erklärung angegebenen Kontaktdaten.
SCHNELLZUGRIFFE
Wir empfehlen Ihnen, diesen Hinweis vollständig zu lesen, um sicherzustellen, dass Sie umfassend informiert sind. Wenn Sie jedoch nur auf einen bestimmten Abschnitt dieses Hinweises zugreifen möchten, können Sie auf den entsprechenden Link unten klicken, um zu diesem Abschnitt zu springen.
- Informationen, die wir sammeln
- Von uns verwendete Informationen
- Weitergabe und Offenlegung von Informationen an Dritte
- Ihre Datenschutzrechte / Von unserer Mailingliste abmelden
- Drittanbieter-Websites
- Sicherheit
- Grundsätze des Datenschutzes
- Datenaufbewahrung
- Internationale Datenübertragungen
- Erweiterung der EU-US-, Schweiz-US- und Großbritannien-Rahmenvereinbarungen zum Datenschutz zwischen der EU und den USA
- Datenschutz für Kinder
- Aktualisierungen dieses Hinweises
- Kontaktieren Sie uns
INFORMATIONEN, DIE WIR ERHEBEN
Die persönlichen Daten, die wir über Sie erheben können, fallen in die folgenden Kategorien:
Informationen, die Sie uns zur Verfügung stellen
Für bestimmte Bereiche unserer Website und unserer Dienste werden Sie möglicherweise aufgefordert, bestimmte personenbezogene Daten anzugeben. Wir werden Ihnen klar mitteilen, warum Sie zur Angabe dieser personenbezogenen Daten aufgefordert werden und welche Arten von personenbezogenen Daten erforderlich sind, um eine Anfrage zu bearbeiten oder eine Dienstleistung zu erbringen.
Wir erfassen Informationen, die Sie uns direkt zur Verfügung stellen, wenn Sie unsere Website, Apps oder Dienste nutzen. Zu den Arten von personenbezogenen Daten, die wir möglicherweise direkt von Ihnen erfassen, gehören Vor- und Nachname, E-Mail-Adressen, Postanschriften, Telefonnummern, Geschlecht, behördliche Ausweise, die das Vorgenannte sowie Geburtsdatum und -ort umfassen können, Informationen über die Art des gewünschten Dienstes, Marketingpräferenzen, Arbeitgeber, Mitarbeiteridentifikationsnummer, Berufsbezeichnungen, Visumdetails, Notfallkontaktinformationen, sofern sie angegeben werden, Kreditkartenzahlungsinformationen, Ticket- und Reisedetails, Internet-Protocol-Adresse (“IP-Adresse”), transaktionsbezogene Informationen, Tarifinformationen, Vielflieger-/Treuestatusinformationen, Reisepräferenzen auf Anfrage wie Sitzplatz, Verpflegung, besondere Assistenzleistungen, Raucherstatus sowie alle Mitteilungen, Anfragen, Kontakt- oder anderen Informationen, die Sie während der Nutzung der Dienste freiwillig bereitstellen. Es kann Fälle geben, in denen solche Informationen zu Zwecken der Qualitätssicherung audioaufgezeichnet werden; Sie werden jedoch vor der Teilnahme an solchen Vorgängen darüber informiert.
Wenn Sie diese persönlichen Daten angeben, verwenden wir diese ausschließlich für den spezifischen Zweck, für den sie bereitgestellt wurden.
Daten, die wir automatisch erfassen, wenn Sie unsere Website oder Apps besuchen oder unsere Dienste nutzen
Wir erfassen möglicherweise bestimmte Informationen über Ihre Nutzung der Website durch den Einsatz von Tracking-Technologien oder auf andere passive Weise. Zu diesen “passiv erfassten” Informationen gehören unter anderem der Domainname der Website, über die Sie auf die Website gelangt sind, die verwendeten Suchmaschinen, die verwendete IP-Adresse, die Verweildauer auf der Website, die von Ihnen auf der Website aufgerufenen Seiten, andere Websites, die Sie vor und nach dem Besuch der Website aufgerufen haben, den von Ihnen verwendeten Internetbrowser, die Häufigkeit Ihrer Besuche auf der Website sowie weitere relevante Statistiken, darunter die folgenden:
Protokollinformationen. Wenn Sie auf die Website zugreifen, zeichnen unsere Server automatisch Informationen auf, die Ihr Browser bei jedem Besuch einer Website sendet. Diese Server-Protokolle können Informationen wie Ihre Webanfrage, Ihre IP-Adresse, den Browsertyp, die Browsersprache, Datum und Uhrzeit Ihrer Anfrage sowie ein oder mehrere Cookies (kleine Textdateien, die eine Zeichenfolge enthalten) enthalten, die Ihren Browser eindeutig identifizieren können.
Links. Die Website kann Links in einem Format enthalten, das es uns ermöglicht, nachzuvollziehen, ob diese Links von IP-Adressen aufgerufen wurden. Wir verwenden diese Informationen, um die Qualität unserer Produkte und unseres Designs zu verbessern.
Kekse. Wenn Sie die Website besuchen oder darauf zugreifen, senden wir ein oder mehrere Cookies (kleine Textdateien, die eine Zeichenfolge enthalten) an Ihren Computer, die Ihren Browser eindeutig identifizieren. Wir verwenden Cookies, um die Qualität der Website zu verbessern, indem wir Benutzereinstellungen speichern und Nutzertrends verfolgen. Die meisten Webbrowser akzeptieren Cookies automatisch, können jedoch so konfiguriert werden, dass sie dies nicht tun oder den Nutzer benachrichtigen, wenn ein Cookie gesendet wird. Wenn Sie Cookies deaktivieren möchten, nehmen Sie bitte die entsprechenden Einstellungen in Ihrem Internetbrowser vor und lesen Sie unseren Hinweis zu Cookies. Bitte beachten Sie, dass Sie bei einer Deaktivierung von Cookies möglicherweise einige personalisierte Funktionen der Website nicht nutzen können.
Web-Beacons. Web-Beacons (auch als “Pixel-Tags” oder “unsichtbare GIFs” bezeichnet) sind 1×1-Pixel-Grafiken, die es uns ermöglichen, die Anzahl der Nutzer zu zählen, die die Website besucht oder auf sie zugegriffen haben, und Nutzer durch den Zugriff auf unsere Cookies wiederzuerkennen. Wir können Web-Beacons einsetzen, um die Verwaltung und Navigation der Website zu erleichtern, die Aktionen der Nutzer der Website zu verfolgen, aggregierte Statistiken über die Nutzung der Website und die Antwortraten zu erstellen und Besuchern der Website ein verbessertes Online-Erlebnis zu bieten. Wir können Web-Beacons auch in E-Mail-Nachrichten im HTML-Format einbinden, die wir versenden, um festzustellen, welche E-Mail-Nachrichten geöffnet wurden.
Tracking durch Dritte.
Wir gestatten Dritten nicht, wenn Sie die Website nutzen, personenbezogene Daten über Ihre Online-Aktivitäten im Laufe der Zeit und über verschiedene Websites hinweg zu sammeln.
Wenn Sie unsere Website besuchen oder unsere Apps oder Dienste nutzen, erfassen wir möglicherweise automatisch bestimmte Informationen von Ihrem Gerät. In einigen Ländern, darunter auch in der Europäischen Union, können diese Informationen gemäß den geltenden Datenschutzgesetzen als personenbezogene Daten gelten:
Nutzungshinweise –
We keep track of your activity in relation to the Website, Apps or Services, the configuration of their computers, and performance metrics related to their use of the Website, Apps or Services. For example, when you use our Services, we may collect:
- Traffic data about the communications that take place through our platform (such as calls, team chat, video conferencing, SMS,) to enable us to transmit those communications effectively and efficiently;
- Network Monitoring data to enable us to maintain the security and agility of our internal networks;
- Log data about you when they use the Services, Website or Apps including IP address, Internet Service Provider (“ISP”), browser type, referring/exit pages, the files viewed on our site (e.g., HTML pages, graphics, etc.), operating system, date/time stamp, and/or clickstream data to analyze trends in the aggregate and administer the site;
- Device data about any device including mobile phone number and other information related to mobile devices like operating system and model if you use our Services via our Apps. With respect to other devices information collected by cookies and other similar technologies, we use various technologies to collect information which may include saving cookies to your computers;
- Call Detail Records of data record produced by a telephone call or other telecommunications transactions. The record contains various attributes of the call, such as time, duration, completion status, source number and destination number;
- Meta data, which is data created about other data which can include size, formatting, other characteristics of a data item;
- Emails/Communications with us; and
- Billing data, which includes any payment data.
Cookies and other similar technologies – We use various technologies to collect information which may include cookies when you visit our Website or use our Apps or Services. Please see the Colpitts Clinical Cookies Notice for further information.
Information we collect from third parties
We learn information about you when businesses interact with us and use our services, including when someone else provides us information about you (e.g., when our client or a third party (such as an employer, travel agency, global distribution system, travel supplier, etc.) provides us your information in order for us to perform Services for them.
We may collect the names and e-mail addresses of individuals from third parties to market our products/services to these individuals. This collection of information and marketing is always carried out in compliance with applicable law. We only receive this information where we have checked that these third parties either have your consent or these third parties are otherwise legally permitted or required to disclose your personal information to us.
We may receive personal information about you from other sources, including publicly available databases or third parties from whom we have purchased data, and combine this data with information we already have about you, in accordance with applicable laws. This helps us to update, expand and analyze our records, identify new clients, and provide products and services that may be of interest to you.
We may collect personal information about you from other applications you may use if you choose to integrate Colpitts Clinical Apps or Services with other Apps or Services.
INFORMATION WE USE
We may use the information we collect from you for a range of purposes, including to:
- Administer, operate, protect, and maintain the Website, Apps or Services;
- Process and complete travel, hotel/hospitality, transportation transactions, and send related information, including transaction confirmations and invoices;
- Meetings and events coordination and execution;
- Client reporting and relationship management;
- Manage and improve your use of the Website, Apps or Services;
- Provision of online and offline support to Clients and End Users;
- Prepare and provide you testimonials regarding the Website, Apps and/or Services;
- To help deliver our Website, Apps, or Services to Clients for service and support;
- Investigate and prevent fraudulent activities, unauthorized access to the Website, Apps or Services, and other illegal activities; and
- For any other purposes about which we notify and receive your consent from you;
- To help personalize your experience and retarget you for advertising purposes;
- Traveler satisfaction surveys;
- Respond to inquiries and requests and to provide you with information and access to resources that you have requested;
- Quality assurance and training purposes;
- Aggregate and analyze your use of the Website, Apps or Services for trend monitoring, marketing advertising purposes; and
- Send you technical alerts, updates, security notifications, and administrative communications.
We and our third-party marketing service providers may also use the information clients send to us for our marketing purposes if this is in accordance with your marketing preferences and applicable law. However, you may opt out of our marketing efforts. For further information, see the “Unsubscribe from our Mailing List” and “Do Not Sell My Personal Information” sections below.
Legal basis for processing personal information (EEA/UK only)
Definitions of certain terms (including but not limited to Data Subject, Personal Data, Processing, Legal Basis, Data Processor, Data Controller) within this notice are defined under Article 4 of the European General Data Protection Regulation 2016/679 (GDPR) which will also apply to UK residents under the UK Data Protection Act of 2018 (UK GDPR) found here: GDPR Definitions.
If you are from the European Union (EU) or United Kingdom, our legal basis for collecting and using your Personal Data described above will depend on the Personal Data concerned and the specific context in which we collect it. This notice provides mandatory information as required under Articles 13 and 14 of the GDPR regarding the transparency of data processing of your Personal Data as the Data Subject.
Colpitts Clinical will act as a Data Processor where the Sponsor or Contract Research Organization is our client acting as Data Controller. Under written contract, the Data Controller will pass Personal Data of consenting clinical trial participants to Colpitts Clinical to manage and process clinical study related travel arrangements and/or expense services in connection with the clinical trial. It is this contract which forms the ‘Legal Basis’ for the processing of Personal Data carried out by Colpitts Clinical in these circumstances.
Colpitts Clinical will become a Data Controller if it collects additional Personal Data directly from you only where we have your consent to do so, and where we need the Personal Data to perform a contract with you, or where the processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms. In some cases, we may also have a legal obligation to collect the Personal Data in question.
If we ask you to provide Personal Data to comply with a legal requirement or enter into a contract with you, we will make this clear at the relevant time and advise you whether the provision of your Personal Data is mandatory or not (as well as of the possible consequences if you do not provide your Personal Data).
Similarly, if we collect and use your Personal Data in reliance on our or a third party’s legitimate interests and those interests are not already listed above (see “Information We Use” section), we will make clear to you at the relevant time what those legitimate interests are.
Colpitts Clinical acts as a Data Controller for any Personal Data held regarding its own employees, and legally processes this data under its Contract of Employment with those Data Subjects.
If you have questions about or need further information concerning the legal basis on which we collect and use your Personal Data, please contact us using the contact details provided under the “Contact Us” section below.
SHARING AND DISCLOSURE OF INFORMATION TO THIRD PARTIES
To fulfill the travel arrangements on your behalf, it will in most cases be necessary to process personal information via a third party (these will include but are not limited to airlines, hotels, car hire companies, and visa or passport companies). Personal information shall only be transferred to, or processed by, third party companies where such companies are necessary for the fulfillment of the travel arrangements.
We may share and disclose your information that we collect with the following third parties for the purposes of providing you travel management services:
- Colpitts Clinical or any of its affiliates consistent with this Notice for data processing;
- Business partners, contractors, travel suppliers, vendors, and authorized third party agents, to:
- Operate, deliver, improve, and customize our Services including but not limited to:
- Airlines, hotels, property rental companies, transportation services
- Online Booking Tools (OBTs) if contracted to utilize with our Clients
- Global Distribution Systems (GDSs)
- Card payment companies
- Duty of Care providers
- Provide support and technical services;
- Send marketing and other operational communications related to our Services;
- Enforce our acceptable use policy;
- Operate, deliver, improve, and customize our Services including but not limited to:
- Law enforcement agencies, regulatory or governmental bodies, or other third parties in order to respond to legal process, comply with any legal obligation; protect or defend our rights, interests, or property or that of third parties; prevent or investigate wrongdoing in connection with the Website, Apps, or our Services;
- Any third parties in connection with prospective or actual, sale, merger, acquisition, financing, or reorganization of our business.
For EU/UK persons only:
Personal Data shall not be transferred to a country or territory outside the EU or UK unless the transfer is made to a country or territory recognized by the EU or UK as having an adequate level of data security, or is made with the consent of the Data Subject, or is made to satisfy the Legitimate Interest of Colpitts Clinical in regard to its contractual arrangements with its Clients.
All internal group transfers of Personal Data shall be subject to written agreements under the Company’s Intra Group Data Transfer Agreement (IGDTA) for internal data transfers which are based on Standard Contractual Clauses recognized by the European Data Protection Authority.
YOUR PRIVACY RIGHTS/UNSUBSCRIBE FROM OUR MAILING LIST
Update and access to your information
Where we process personal information collected via our Website or Apps or via our Services for our own account management, billing, or marketing purposes, we provide individuals with the opportunity to access, review, modify, and delete any such personal information that we process as required by the applicable law of your residence.
Where you have provided your consent to the collection, use, or disclosure of your personal information, you may have the legal right to withdraw your consent to our use or disclosure of your personal information, under certain circumstances. To withdraw your consent, if applicable, you may contact us at the coordinates provided in the “Contact Us” section of this Notice. Please note that if you withdraw your consent, we may not be able to provide you the programs, products, services, events, or information that you requested or that could be offered to you.
Unsubscribe from our mailing list
If you have opted in to receive electronic marketing communications from us or if we otherwise have your implied consent to send such communications under applicable laws, but you no longer wish to have your email or other electronic address used for promotional purposes, you may opt out
- by clicking “unsubscribe” within any marketing email you receive,
- or by following the opt-out instructions provided when you receive an electronic marketing communication.
Please note that:
- Even if you have opted out of receiving marketing communications from us, we may still contact you for transactional purposes, in compliance with applicable laws (e.g., for customer service, product information, service or reminder notices, or recalls). We may also need to contact you with questions or information regarding your customer service inquiries; and
- It may take some time for all of our records to reflect changes in your preferences (e.g., if you request that you not receive personalized marketing communications from us, your preference may not be captured for a promotion already in progress).
Your Privacy Rights as an EU/UK Person
In addition, if you are from the EU or UK, you may have broader rights to access and delete your Personal Data, to object to or restrict processing of your Personal Data, or request portability of your personal information.
To make such requests, you can send an email to ColpittsPrivacy@dt.com or write to us at the mailing address in the “Contact Us” section below. We will consider and handle all requests in accordance with applicable laws.
If we have collected and processed your Personal Data with your consent, then you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your Personal Data conducted in reliance on lawful processing grounds other than consent.
You also have the right to complain to your local data protection authority at any time. In general, when processing Personal Data to provide our Services, we do so only on behalf of our EU/UK Clients and in accordance with their instructions. This means that if you wish to access, review, modify or delete any Personal Data we process on behalf of a Colpitts Clinical client, under applicable EU/UK law or otherwise, you should contact that Client with your request. We will then help them to fulfill that request in accordance with their instructions.
Your Privacy Rights as a Resident in CA, CO, CT, UT, and VA (United States Only).
If you are a resident of California, Colorado, Connecticut, Utah, or Virginia, you may have certain rights under the applicable states’ comprehensive data privacy laws (including but not limited to, the CCPA, CPRA, SB 190, SB6, SB227, and SB1392. In some states, you need not be physically present in the states listed above to exercise these rights, provided that you have a current residence in the aforementioned states, subject to certain limitations and applicability.
Rights to Access and Data Portability:
You have the right to request that we disclose certain information to you about the collection and use of your personal information over the preceding twelve (12) months. Once we receive and confirm your verifiable consumer request, we will disclose to you:
(1) information identifying each third-party company to whom we may have disclosed, within the past year, personal information pertaining to you for our direct marketing purposes;
(2) a description of the categories of personal information disclosed with third parties;
(3) our business or commercial purposes for collecting or selling that personal information;
(4) the specific pieces of personal information we collected about you (also known as a data portability request);
(5) if we sold or disclosed your personal information for a business or commercial purpose, two separate lists disclosing (a) sales, identifying the categories that each category of recipient purchased; (b) disclosures for a business purpose, identifying the categories that each category of recipient obtained.
Right to Request Deletion or Data Correction:
You have the right to request that we delete or correct any of the personal information we collected from you and retained, subject to certain exceptions.
We may deny your deletion or correction request if retaining the information is necessary for us or our service providers to:
- Complete transaction for which we collected the personal information, provide the service you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise reasonably perform our contract with you or on behalf of you for our Clients;
- Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.);
- Comply with a legal or regulatory obligation;
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such acts;
- Debug products and software to identify and repair errors that impair existing intended functionality;
- Enable solely internal uses that are reasonably aligned with consumer expectations based on our dealings and your relationship with us;
- Make other internal and lawful uses of that information which are compatible with the context that you provided said information.
If you are a resident of CA, CO, CT, UT, or VA who qualifies to receive such an accounting or would like to exercise a correction, deletion, or data portability request, please email, or contact us at (888) 546-1504, and we will contact you within ten (10) days of such request to verify your identity and eligibility.
Your Privacy Rights as a Resident in Canada
Privacy rights in Canada are protected under the Personal information Protection and Electronic Documents Act (Canada) (“PIPEDA”). Alberta, British Columbia and Quebec have provincial privacy laws that may apply in place of PIPEDA. The Personal Information Protection Act is Alberta’s private-sector privacy law. Similarly, for residents of British Columbia, the BC Personal Information Protection Act will apply. In Quebec, your rights are governed by and protected under the Act Respecting the Protection of Personal Information in The Private Sector. Ontario, New Brunswick, Newfoundland and Labrador and Nova Scotia have health-related privacy laws that have been declared substantially similar to PIDEDA and will apply with respect to health information for residents in those provinces.
You have the right to request access to and to correct the personal information that we hold about you. To request access or correct your personal information, you may contact us at the coordinates provided in the “Contact Us” section of this Notice. Your right to access or correct your personal information is subject to applicable legal restrictions. Upon request, we will provide you with access to your personal information within a reasonable timeframe, in compliance with applicable laws. We may take reasonable steps to verify your identity before granting access or making corrections. If we cannot provide you with access to your personal information, we will inform you of the reasons why, subject to any legal or regulatory restrictions or requirements
Please note that, in order to better safeguard your privacy and the privacy of others, we may (to the extent permitted — and/or required — by applicable law/regulation) ask you to provide additional information to verify your identity and/or residency before processing any data-related requests. We strive to respond to a verifiable consumer request in a prompt manner. If we require additional time, we will inform you of the reason and extension period in writing. Any disclosures we provide will only cover the 12-month period preceding a verifiable consumer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests and for compliance with state privacy laws, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance, specifically by electronic mail communication.
There is no charge for making privacy-related requests or responding to your verifiable consumer requests unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will inform you of our decision and why, and provide you with a cost estimate for you to consent to before completing your request.
Do Not Sell My Personal Information
Click the above to submit a request as a resident under the CCPA, CPRA, SB 190, SB6, SB227, and SB1392.
THIRD-PARTY SITES
This Notice does not apply to, nor are we responsible for, the privacy, information, or other practices of any third parties, including any third party operating any site or service to which the Website links including but not limited to social media sites. The inclusion of a link on the Website does not imply our endorsement of the linked site or service. You should check the privacy notices of those sites before providing your personal information to them.
SECURITY
Keeping your information secure is important to us. We maintain a variety of appropriate technical and organizational safeguards to protect your personal information both during transmission and once it is received. We implement policies and practices to protect your personal information, including:
- policies and procedures that define the roles and responsibilities within our organization for handling your personal information from the moment we gather it until it is destroyed, and limit access to that information on a “need-to-know” basis;
- procedures for responding to complaints or inquiries related to the protection of personal information;
- if the information is collected or stored electronically, technical safeguards such as encryption, firewalls, passwords, anti-virus software and similar measures;
- contractual protections and other measures to ensure that service providers with whom we share personal information maintain adequate protections and security standards;
- employee training in privacy and information security
Colpitts Clinical has no control over or responsibility for the security or privacy policies or practices of other sites on the Internet you might visit, interact with, or from which you might buy products or Services, even if you visit them using links from our Website.
Please note that no website, mobile app, or service is completely secure and so, while we endeavor to protect our Clients’ information using the measures described above, we cannot guarantee that unauthorized access, hacking, data loss or a data breach will not occur.
DATA PROTECTION PRINCIPLES
- Personal Data shall be processed lawfully, fairly, and in a transparent manner.
- The Personal Data collected will only be those specifically required to fulfill travel, accommodation, or other travel-related requirements. Such data may be collected directly from the Data Subject or provided to Colpitts Clinical via his /her employer or a contracted relationship on behalf of such Data Subject. Such data will only be processed for that purpose.
- Personal Data shall only be retained for as long as it is required to fulfill legal, contractual, and financial requirements.
- Personal Data shall be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are collected and/or processed. Personal Data shall be accurate and, where necessary, kept up to date.
- Where legally required, the Data Subject has the right to request from Colpitts Clinical access to and rectification or erasure of their Personal Data, to object to or request restriction of processing concerning the data, or to the right to data portability. In each case such a request must be put in writing and sent to ColpittsPrivacy@dt.com.
- Personal Data shall only be processed based on the legal basis as explained above, except where such interests are overridden by the fundamental rights and freedoms of the Data Subject which will always take precedent. If the Data Subject has provided specific additional consent to the processing, then such consent may be withdrawn at any time (but may then result in an inability to fulfil travel requirements).
- Colpitts Clinical will not use Personal Data for any monitoring or profiling activity or process, and will not adopt any automated decision-making processes, aside from the activities requested pursuant to performing a contract.
- Where legally required, the Data Subject has the right to make a complaint directly to a supervisory authority within their own country. Colpitts Clinical’s Data Protection compliance is supervised by:
Attn: Privacy Team
Colpitts Clinical
7430 East Caley Avenue, Suite 320E
Centennial CO 80111
DATA RETENTION
We will retain your personal information/Personal Data for no longer than is necessary to fulfill the purposes for which the information was originally collected unless a longer retention period is required or permitted by law, for legal, tax or regulatory reasons, or other legitimate and lawful business purposes.
Where we have no ongoing legitimate business need to process your personal information/Personal Data, we will either delete, aggregate, or otherwise anonymize it.
INTERNATIONAL DATA TRANSFERS
Your personal information/Personal Data may be transferred to, and processed in, countries other than the country in which you are resident. Specifically, information collected outside the United States, including in the EU may be transferred to and stored on our servers in the United States, Canada, and potentially in other countries where our group of companies and third-party service providers and partners operate. These countries may have data protection laws that are different to the laws in your country (and in some cases, may not be as protective). When your personal information/Personal Data is used or stored in a jurisdiction other than where you are residing, it may be subject to the law of that foreign jurisdiction, including any law permitting or requiring disclosure of personal information/Personal Data to the government, government agencies, courts and law enforcement in that jurisdiction.
However, we have taken appropriate safeguards to ensure that your personal information will remain protected in accordance with this Notice and applicable laws. For example, with respect to personal information originating from the EU, UK, and Switzerland, Colpitts Clinical has self-certified to the EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, and UK Extension to the EU-U.S. Data Privacy Framework which can be verified here.
Under certain conditions, more fully described on the Data Privacy Framework website https://www.dataprivacyframework.gov/, you may invoke binding arbitration when other dispute resolution procedures have been exhausted.
EU-US/Swiss-US and UK Extension to the EU-US Data Privacy Frameworks
In compliance with the Data Privacy Framework, Colpitts Clinical commits to resolve complaints about our collection or use of your Personal Data. EU, UK, and Swiss individuals with inquiries or complaints regarding our Data Privacy Framework policy should first contact Colpitts Clinical at:
Attn: Privacy Team
7430 E. Caley Avenue, Suite 320E
Centennial, CO 80111
ColpittsPrivacy@dt.com
Colpitts Clinical has further committed to cooperate with the panel established by the EU data protection authorities (DPAs), the Swiss Federal Data Protection and Information Commissioner (FDPIC) and the UK Information Commissioners Office (ICO) with regard to unresolved Data Privacy Framework complaints concerning data transferred from the EU, Switzerland, and UK.
Colpitts Clinical complies with the EU-US Data Privacy Framework, the Swiss-US Data Privacy Framework, and the UK Extension to the EU-US Data Privacy Framework as set forth by the US Department of Commerce regarding the collection, use, and retention of Personal Data transferred from the European Union and Switzerland to the United States, respectively.
Colpitts Clinical has certified to the Department of Commerce that it adheres to the Data Privacy Framework. If there is any conflict between the terms in this privacy policy and the Data Privacy Framework, the Data Privacy Framework shall govern.
Colpitts Clinical commits to all Personal Data transferred from the EU, Switzerland, and UK to the US to be subject to the principles of the Data Privacy Framework. Colpitts Clinical only receives Personal Data for the purpose of arranging travel-related services, and will not use this data for any other purpose. The types of Personal Data collected may include mandatory items such as passport data, contact information, and methods of payment. This list is not exhaustive. That Personal Data will at all times be kept secure, and Colpitts Clinical will take responsibility and appropriate measures to protect it from loss, misuse and unauthorized access, disclosure, alteration, and destruction.
Personal Data will only be onward transferred to third parties who are directly involved in fulfillment of travel arrangements for our travelers, and for that specific purpose only. These will include (but are not limited to) airlines, hotels, and global distribution systems. This data will be kept securely by the third party. Colpitts Clinical commits to fully comply and be liable with the ‘Accountability for Onward Transfer’ Principal in the Data Privacy Framework in as far as the Personal Data transfer applies as required by applicable law.
Individuals have the right to access their own Personal Data with the ability to have that data corrected or deleted, or limiting its use or its disclosure. An individual may also elect not to have their Personal Data transferred to one or more third parties, or processed for a specific purpose, but it may severely limit or prevent travel arrangements being made on their behalf in such circumstance. That application must be made in writing to the address above.
Colpitts Clinical acknowledges the investigatory and enforcement powers of the Department of Transportation (DoT), and the requirements to disclose Personal Data in response to a lawful request by any public authority, or to meet national security or law enforcement requirements in the United States. Colpitts Clinical commits to making public any order from the DoT or a court relating to any non-conformance to the principles of the Data Privacy Framework.
Colpitts Clinical will utilize the external services of the UK Information Commissioner’s Office, Swiss Federal Data Protection and Information Commissioner’s Office, or EU Data Protection Authorities for free dispute resolution arising from the processing of Personal Data under the Data Privacy Framework. It may be possible for an individual to invoke binding arbitration in certain circumstances if agreed with the Commissioner’s Office.
Colpitts Clinical will conduct internal audits to ensure that the policy statements made above remain true and accurate, and that they have been implemented in accordance to the Data Privacy Framework.
CHILDREN’S PRIVACY
Children are not eligible to use our Websites, Apps or Services, and we ask that minors (children under the age of 18) not submit any personal information to us. If you are a minor, you may use the Site only in conjunction with your parents or guardians.
UPDATES TO THIS NOTICE
We may update this Notice from time to time in response to changing legal, technical, or business developments. If we change our Notice, we will post those changes on this page in addition to updating the “Last Updated” date at the top of this webpage. If we make material changes, we will notify you more directly, for example by posting a notification or message on the Website or by emailing you prior to such changes taking effect. We encourage you to review this Notice regularly to stay informed of the latest modifications.
KONTAKTIEREN SIE UNS
If you have any questions, comments, or concerns about this Notice, please e-mail us at ColpittsPrivacy@dt.com. Or, you can write to us at:
Colpitts Clinical
Attn: Privacy Team
7430 E. Caley Avenue, Suite 320E
Centennial, CO 80111