Privacy Policy

This privacy policy applies to people who visit Biospecialty.com (our Site).

This privacy policy does not apply to genetic personal data (namely DNA) that we process on behalf of a client. This is because in such instance:

  • where we are a controller, details of how we will process such personal data will be set out in a separate consent form; or
  • where we are a processor, the basis on which we will process such personal data will be set out in a separate data processing agreement that we enter into with our client.

Under this privacy policy, we do not collect any personal data about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data. Nor do we collect any information about criminal convictions and offences.

(Note that if you donate at one of our facilities, some of the above information relating to your health, gender, sexual orientation and other matters will be collected in order to meet government regulations intended to ensure the safety of the blood supply. We may also collect race/ethnicity, smoking status, medications you have used, and similar types of information in relation to your donation for scientific research purposes. However, before we ask for any type of sensitive personal data, you will be informed and asked to consent to the collection.)

This Site is not intended for children and we do not knowingly collect data relating to children.

It is important that you read this privacy policy together with any other privacy policy or fair processing policy we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your personal data. This privacy policy supplements other notices and privacy policies and is not intended to override them.

Who we are and our DPO: Biological Specialty Company (BSC) and Clinical Trial Laboratory Services (CTLS) are committed to being responsible custodians of the information you provide us and the information we collect in the course of operating our business. This privacy policy sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us.

We have appointed a data protection officer (DPO) for you to contact if you have any questions regarding this privacy policy or our data protection practices. You can contact our DPO at privacy@bioivt.com or via PO BOX 770 Hicksville, NY 11802 (please mark the envelope ‘Data Protection Officer’).

You have the right to make a complaint at any time to a data protection authority about our collection and use of your personal data. For more information, please contact your local data protection authority. Contact details for data protection authorities in the European Economic Area, Switzerland and certain non-European countries (including the US and Canada) are available here. We would, however, appreciate the chance to deal with your concerns before you approach a data protection authority so please contact us in the first instance.

By using our Site, you accept the practices described in this Policy.

This Policy is effective on and from July 31, 2019. We may amend this Policy at any time, and whenever we do so we will notify you by posting a revised version on our Site or emailing you. Please review this Policy each time you visit our Site as it may have been updated since your last visit.

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us (see Who we are and our DPO). If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.

Personal data we collect: With regard to each of your visits to our Site, we will automatically collect:

  • technical information, including the Internet Protocol (IP) address used to facilitate your connection to the Internet, browser type and version, time zone setting, browser plug-in types and versions, and hardware information; and
  • information about your visit, including the full Uniform Resource Locators (URL) clickstream to, through and from our Site (including date and time); services, products, publications and articles you viewed or searched for; page response times, download errors, length of visits to certain pages, page interaction information (such as clicks) and methods used to browse away from the page.

We also collect, use Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate information about how you use our Site to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this Policy.

Cookies: Our Site uses cookies to distinguish you from other users of our Site. This helps us to provide you with a good experience when you browse our Site and also allows us to improve our Site. Cookies are text files placed on your computer to collect standard internet log information and visitor behavior information. This information is used to track visitor use of our Site and to compile statistical reports on website activity. You can read more about how we use cookies in our Cookie Policy. You can enable or disable cookies by modifying the settings in your browser. You can find out how to do this, and find more information on cookies, at www.allaboutcookies.org.

Using your personal data: We will use this information for the following legitimate interests (whether ours or a third party’s):

  • improving our Site and ensure that content is presented in the most effective manner for you and for your device(s);
  • for internal operations (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data);
  • measuring or understanding the effectiveness of our Site and/or any marketing we serve to you and others, and delivering relevant marketing to you; and/or
  • dealing with any issues you have reported with our Site.

We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us (see Who we are and our DPO).

Sharing your personal data: We will only share personal data with third parties in the following instances:

  • our employees, contractors and agents (but their use shall be limited to the performance of their duties and in line with the reason for processing);
  • other affiliates in the BioIVT Group (acting as controllers or processors) and who are based in the USA, Belgium, the UK and India, and provide IT and system administration services and undertake leadership reporting;
  • when information about you is processed by our third-party IT support provider (acting as a processor) for the purposes of providing IT support to us;
  • with analytics and search engine providers (acting as processors) that assist us in the improvement and optimization of our Site; and/or
  • our third-party website hosting supplier (acting as a processor) to enable them to maintain and host our Site.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

Retaining your personal data: This information is kept for up to 2 years and will then be deleted automatically. However:

  • if we are required by law to retain it for longer, we will retain it for the required period; and/or
  • where the information is being used in connection with legal proceedings (including prospective legal proceedings) it will be retained for the duration of those legal (and any enforcement) proceedings.

We share your personal data within BioIVT, our parent company, and to the external third parties (the categories of which are referred to in this Policy). This may involve transferring your data outside the European Economic Area (EEA). Whenever we transfer your personal data out of the EEA, we will ensure a similar degree of protection is afforded to it. In some instances, your personal data may be transferred to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. In other instances, we will ensure at least one of the lawful safeguards are implemented, which may include:

  • Where we transfer personal data within the BioIVT group and to certain external third parties, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe; or
  • Where we use external third parties based in the US, we may transfer personal data to them if they are part of the EU-US Privacy Shield which requires them to provide similar protection to personal data shared between Europe and the US.

Further details can be provided upon request, please contact us (see Who we are and our DPO).

In relation to personal data we hold about you, you have the right to:

  • where we process your personal data based on your consent, to withdraw your consent easily and at any time (withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal data conducted in reliance on lawful processing grounds other than consent);
  • get access to your personal data that we hold, and receive information about our processing of it;
  • ask us to correct the record of your personal data maintained by us if it is inaccurate or to complete incomplete personal data;
  • ask us, in certain instances, to erase your personal data or cease processing;
  • object to us processing your personal data for direct marketing purposes (see Marketing);
  • challenge us processing your personal data which has been justified on the basis of our or a third party’s legitimate interests;
  • ask us, in certain instances, to restrict processing personal data to merely storing it;
  • request portability of your personal data in certain limited instances;
  • prevent processing that is likely to cause damage or distress to you and seek compensation from us for any damages caused to you by us breaching applicable data protection laws;
  • be notified of a personal data breach which is likely to result in high risk to your rights and freedoms; and
  • complain to a data protection authority (contact details for data protection authorities in the European Economic Area, Switzerland and certain non-European countries (including the US and Canada) are available here).

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.

If you would like to exercise any of these rights, please contact us (see Who we are and our DPO).We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

We try to respond to all legitimate requests within one calendar month (starting from the day after we receive your request). Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

To help protect the privacy of personal data you transmit, we maintain physical, technical and administrative safeguards and require the same of any third parties we share your personal data with. Any payment transactions will be encrypted. We update and test our security technology on an ongoing basis. In addition, we train our staff about the importance of confidentiality and maintaining the privacy and security of your personal data.

As you will be aware the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your personal data transmitted to our Site; any transmission is at your own risk. Once we have received your personal data, we will use physical, technical and administrative safeguards to prevent unauthorized access to your personal data.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable data protection authority of a breach where we are legally required to do so.

We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising. To opt out of marketing communications, see Opting out below.

MARKETING and NOTIFICATIONS

Donation Notifications: We may, with your opt-in, contact you via SMS text message or email, regarding your eligibility to donate either because the required wait period between specimen donations (e.g. whole blood) has ended, or because we have a special donation program for which we believe you may be qualified. We will not contact you for non-donation related items.

Test Results: We may contact you, when required, to share information resulting from the viral testing done on blood/plasma that you have previously donated. Contacting you to provide you with the viral test information on your previous donation(s) is required by various governmental entities and you may not opt-out of it.

Third-party marketing: We will get your express opt-in consent before we share your personal data with any third party for marketing purposes.

Opting out: You can ask us to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you or by contacting us (see Who we are and our DPO) any time. Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of a product/service purchase, product/service experience or other transactions. Please note that if you ask us not to contact you by email at a certain email address, we will retain a copy of that email address on a “suppression list” in order to comply with your no-contact request.

To opt out from all future communications (with the exception of the requirement to share viral test results) or to submit a request to access, modify, or delete your personal data, please email privacy@bioivt.com.

Our Site may, from time to time, contain links to and from the websites of third-party websites. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.

Where our Site uses interfaces with social media sites such as LinkedIn, Twitter and others. If you choose to "like" or share information from our Site through these services, you should review the privacy policy of that service. If you are a member of a social media site, the interfaces may allow the social media site to connect your Site visit to your personal data.