Privacy Notice

Introduction

Lindus Health and its affiliates, subsidiaries, and related entities (“Lindus Health,” “we'', “our”) is committed to protecting the privacy and security of the personal information we collect about end customers and users of our services (“you/your”). We are further committed to ensuring we meet our legal obligations when processing your personal information under the relevant Data protection Laws, which include but are not limited to:the California Consumer Privacy Act (“CCPA”). the Canadian Personal Information Protection and Electronic Documents Act (“PIPEDA”). the Colorado Privacy Act ("CPA"). the Connecticut Data Privacy Act ("CTDPA"). the Utah Consumer Privacy Act ("UCPA").the Virginia Consumer Data Protection Act ("VCDPA").The purpose of this privacy notice is to explain what personal information we collect about you and how we use it.Please read this privacy notice carefully as it provides important information about how we handle your personal information and your rights. If you have any questions about any aspect of this privacy notice you can contact us using the information provided below, or by emailing us at: data@lindushealth.com.

What is personal information and what do we collect?

Personal information means information that identifies, relates to, or could reasonably be linked with you or your household. For example, it could include your name, social security number, email address, photographs, geolocation data, fingerprints, and inferences from other personal information that could create a profile about your preferences and characteristics.We may also collect, store, and use sensitive personal information which is a specific subset of personal information. This subset of personal information can include certain government identifiers (such as social security numbers), financial account details, contents of mail, email and text messages, biometrics and information concerning an individual’s health or sexual orientation, or information about racial or ethnic origin, religious or philosophical beliefs, or union membership. However, we will only collect the personal information outlined in the Informed Consent Form and/or Participant Information Sheet and/or HIPAA Authorization Form. This documentation will have been provided to you by the study team, please refer to it for more information on the types of data we may collect as part of this study.

How we collect your personal information

We collect most of the personal information directly from you in person, by telephone, text, or email and/or via our website.For example, we may have collected your personal information directly from you as part of the recruitment process, via our online contact/registration form, or from our email correspondence with you. We will continue to collect personal information about you for the duration of the study trial.

Purposes and lawful basis for processing

We will only use your personal information when the law allows. Most commonly, we will use your personal information in the following circumstances:

  • Where it is necessary for the purposes of facilitating your participation in the study trial
  • To respond to correspondence from you
  • In the provision of our services to a study sponsor
  • Improving our internal systems and/or website 
  • Where we need to comply with a legal obligation
  • When processing is necessary for a business purpose pursuant to this notice or the reason for collection
  • We may also use your data in the following situations:
  • With your consent
  • Where it is needed for the establishment, exercise, or defence of legal claims.

Lawful basis for which we process your data.

Where Lindus processes your personal information, we will do so under one of the following lawful bases:

  • Consent: You have given us your consent to process the data for one or more specific purposes.
  • Performance of a contract: the processing is necessary for the performance of an agreement with you or to take steps to enter into an agreement with you.
  • Legal obligation: The processing is necessary for compliance with a legal obligation to which we are subject.
  • Legitimate interests: the processing is necessary for the purposes of the legitimate interests pursued by us or by a third party.

Where we need to use medical protected health information, this will only be done where the participant or their Legally Authorized Representative has signed and/or agreed to the study-specific HIPAA Authorization Form (note this may form part of the Informed Consent Form), or in the instance where an Institutional Review Board (IRB) has approved the use of a waiver to HIPAA Authorization. 

Sharing your data

By signing the informed consent form, or in the case of a waiver of informed consent approved by the IRB by participating in the trial, you consent to your personal information being shared with the trial site and Sponsor and/or the contracted provider working on the trial. We may also disclose your information to third parties in connection with other purposes set out in this privacy notice. These third parties may include:

  • Business partners, suppliers and sub-contractors who may process information on our behalf.
  • IT service providers

We will only share (‘share’ includes making available remotely) personal information with third parties where we have a contract in place that contains the required provisions to facilitate such transfers.

International transfers

Your personal information may be processed outside of the US, as we, and the organisations we use to provide our services are based in the UK.We have taken appropriate steps to ensure that the personal information processed within the UK has an essentially equivalent level of protection to that guaranteed by the enacted US State Privacy Laws. By participating in the study, you accept that Lindus Health will transfer your personal information outside of the US where necessary.

How long we keep your data

We will retain your personal information for as long as is necessary to provide you with our services and for a reasonable period thereafter to enable us to meet our contractual and legal obligations and to deal with complaints and claims. At the end of the retention period, your personal information will be securely deleted or anonymised, for example by aggregation with other data, so that it can be used in a non-identifiable way for statistical analysis and business planning.

Your rights and options

We will always ensure, no matter where you are located in the world, that we adhere to and fully respect your data protection rights. In the US, you have the following rights:

  • You have the right of access to your personal information and can request copies of it and information about our processing of it. 
  • The right to correct inaccurate personal information about you.
  • The right to limit the use and disclosure of sensitive personal information collected. 
  • Where we are using your personal information with your consent, you can withdraw your consent at any time. 
  • In some circumstances you can compel us to erase your personal information and request a machine-readable copy of your personal information to transfer to another service provider (the right to data portability).
  • Right to equal service and price when any of the above rights are exercised.

You will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.If you wish to exercise your rights, please contact us at data@lindushealth.com

Contact us

If you have any questions, or wish to exercise any of your rights, then you can contact:

Lindus Health
2nd Floor, 90 Union Street
London
SE1 0NW
United Kingdom

Alternatively, you can email us at data@lindushealth.com

Changes to this privacy notice

We may update this notice (and any supplemental privacy notice), from time to time as shown below. We will notify you of the changes where required by applicable law to do so.