Information About California Consumer Privacy Act Disclosures and Rights
California Consumer Privacy Act
The California Consumer Privacy Act of 2018 (the “CCPA”) grants California residents certain rights with respect to their Personal Data, including, as described below, the right to know about, and delete, their Personal Data. These rights are subject to certain limitations, however, such as that they do not all apply to certain types of Personal Data, including information collected as part of research studies including clinical trials that are subject to the U.S. Common Rule or other specific clinical practice guidelines that may apply to our work. Where exceptions to the CCPA apply to a request you submit, we will provide you with an explanation.
Collection of Personal Data
In the 12 months preceding the date of this Privacy Notice, we may have collected the following categories of Personal Data (some of which may not be subject to CCPA), which we intend to continue to collect:
- Personal Identifiers, such as full name, zip code, email address, and telephone number, and internal protocol (IP) address.
- Protected Class Information such as age (over 40), date of birth, and gender.
- Internet or Other Electronic Activity Data includes your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access our Website, and how you use our Website.
- Health information related to our clinical trials.
We collect Personal Data from you when you fill out forms and informational requests on our Website or when you contact us, and automatically, when you interact with our Website.
Use of Personal Data
We use the Personal Data we collect to provide you with the information you request, to evaluate your requests to participate in research studies and clinical trials. We also use Personal Data about your use of our Website to monitor or improve our Website; for internal business analysis; to prevent fraud, activities that violate our Terms of Service or that are illegal; and to protect our rights and the rights and safety of our users or others.
Disclosure of Personal Data For Business Purposes in the Past 12 Months
The following chart describes the categories of Personal Data (some of which may not be subject to CCPA) that we disclosed to third parties for a business purpose in the 12 months prior to the date of this Notice:
Categories of Consumers’ Personal Data | Categories of Third Parties With Which We Shared Personal Data for a Business Purpose |
Personal identifiers: name, zip code, email address, telephone number, and IP address. | Service providers that provide IT and hosting services in respect of this Website and clinical study recruitment services. Study research sites for study and trial qualification purposes. |
Protected Class Information: age (over 40), date of birth, and gender. | Service providers that provide IT and hosting services in respect of this Website and clinical study recruitment services. Study research sites for study and trial qualification purposes. |
Health information. | Service providers that provide IT and hosting services in respect of this Website and clinical study recruitment services. Study research sites for study and trial qualification purposes. |
Internet or Other Electronic Activity Data: your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access our Website, and how you use our Website. | Service providers that provide IT and hosting services in respect of this Website and clinical study recruitment services. |
Additional Information About How We May Share Personal Data
We may also share your Personal Data as required or permitted by law to comply with a subpoena or similar legal process or government request, or when we believe in good faith that disclosure is legally required or otherwise necessary to protect our rights and property or the rights, property or safety of others, including to law enforcement agencies, and judicial and regulatory authorities. We may also share your Personal Data with third parties to help detect and protect against fraud or data security vulnerabilities. And we may transfer your Personal Data to a third party in the event of a sale, merger, reorganization of our entity or other restructuring.
We do not and have not sold any Personal Data to third parties. We do not sell the Personal Data of minors under age 16.
Rights Related to Your Personal Data
Right to request disclosure of information we collect or share about you. You can submit a request to us for the following data regarding the Personal Data we have collected about you in the 12 months prior to our receipt of your request (a “request to know”):
- The categories of Personal Data we have collected.
- The categories of sources from which we collected the Personal Data.
- The business or commercial purposes for which we collected the Personal Data.
- The categories of third parties with which we shared the Personal Data.
- The categories of Personal Data we disclosed for a business purpose, and for each category identified, the categories of third parties to whom we disclosed that particular category of Personal Data.
- The specific pieces of Personal Data we collected.
Right to request the deletion of Personal Data we have collected from you. Upon request, we will delete the Personal Data we have collected about you, except for situations where specific information is necessary for us to provide you with a product or service that you requested; perform a contract we entered into with you; maintain the functionality or security of our systems; or comply with or exercise rights provided by the law.
The law also permits us to retain specific information for our exclusively internal use, but only in ways that are compatible with the context in which you provided the information to us or that are reasonably aligned with your expectations based on your relationship with us.
How can you make a request to exercise your rights? To submit requests to know or delete, contact our data protection officer at sar@thedpo.co.uk.
How we will handle a request to exercise your rights. For requests to know or delete, we will first acknowledge receipt of the request within 10 business days of receipt of your request. We will provide a substantive response to your request within 45 days from receipt of your request, although we may be allowed to take longer to process your request under certain circumstances. If we expect your request is going to take us longer than normal to fulfill, we’ll let you know.
When you make a request to know or delete your Personal Data, we will take steps to verify your identity. These steps may include asking you for Personal Data, such as your name, address, or other information we maintain about you. If we are unable to verify your identity with the degree of certainty required, we will not be able to respond to the request. We will notify you to explain the basis of the denial.
You are also entitled to submit a request for Personal Data that could be associated with a household as defined in the CCPA. To submit a request to know or delete household Personal Data, such requests must be jointly made by each member of the household, and we will individually verify all of the members of the household using the verification criteria explained above, and separately verify that each household member making the request currently resides in the household. If we are unable to verify the identity of each household member with the degree of certainty required, we will not be able to respond to the request. We will notify you to explain the basis of our denial.
You may also designate an authorized agent to submit requests on your behalf. If you do so, you will be required to verify your identity by providing us with certain Personal Data as described above.
Additionally, we will also require that you provide the agent with written and signed permission to act on your behalf, and we will separately confirm with you that you provided the agent with permission to submit the request. We will deny the request if the agent is unable to meet submit proof to us that you have authorized them to act on your behalf or if any of the above verification criteria are not met.
We are committed to honoring your rights. If you exercise any of the CCPA rights explained in this Privacy Notice, we will continue to treat you fairly.