Privacy statement of the esperity.com website
The purpose of this Privacy Statement (hereafter referred to as “Statement”) is to define the processing of your personal data as an esperity.com website (at http://www.esperity.com ; hereafter referred to as the “Site”) user (hereafter referred to as “User”) according to the definition in the General Conditions of Use (hereafter referred to as “General Conditions”). Please refer to the General Conditions concerning the use of the Site.
The Esperity Private Company with Limited Liability (hereafter referred to as “esperity”) undertakes to comply with the Belgian law of 8 December 1992 concerning the protection of privacy with regard to personal data processing. This law can be consulted on the Privacy Commission website (www.privacycommission.be).
The following definitions are provided to anchor the meanings of some of the expressions as they are used in this Statement:
Data processing is a transaction applied to data. For example, collection, recording, organization, storage, adaptation, alteration, retrieval, consultation, use, alignment, combination, blocking, erasure, destruction, disclosure by transmission, dissemination or otherwise making available, etc.
Entity in charge of data processing is a natural or legal person, unincorporated association, or government with the sole authority to determine the purpose and means of data processing. The entity can make such determinations alone or jointly with others.
Medical twin is a person similar to the User him/herself. The extent and kind of similarity is for the User to decide. For example, medical twins might have the same age or sex; they may even be living in the same city. As soon as Users enter sufficient information about themselves and their condition, esperity will start providing them with twin suggestions based on the information on its database.
Personal data is information pertaining to an identified or identifiable person. A person is considered identifiable if s/he can directly or indirectly be identified, in particular by reference to an identification number, or to one or more specific cultural or socioeconomic factors pertaining to his or her physical, physiological and/or mental attributes.
Personal health data is any personal information on the basis of which one can deduce information about the past, present or future physical or mental health. These data do not have any administrative or accounting components pertaining to treatments or healthcare.
Unstructured data is information that the User generates outside the structure provided by the Site. It typically consists of free text-input the User sends to his contacts or the comments he writes on his or her profile.
I. Entity in charge of data processing
esperity is responsible for all processing of personal data on the Site.
esperity – with its office registered at BLSI, 30, Clos Chapelle-aux-Champs, B1.30.30, B-1200 Brussels, Belgium, recorded in the Business and Company Register under number 0848.466.027, company number BE 0848.466.027 and VAT number 0848.466.027 – has declared these processing operations to the Privacy Commission, which delivered a receipt. This declaration can be consulted on the Privacy Commission website (www.privacycommission.be).
II. Your consent to processing your data in the context of esperity services
esperity attaches special importance to the transparent processing of your personal data in the context of the services provided on the Site (hereafter referred to as “Services”).
Under the terms of the 1992 privacy law, processing of personal health and ethnic data is subject to your written consent. Paper-based written consents cannot be obtained by reasonable means in the context of online services.
As a result, you accept that your registration to the Site is equivalent to giving your written consent to esperity to process your personal data concerning your health and ethnicity.
In order to ensure total transparency, we urge you to read this Statement very carefully, because it provides you with detailed explanations regarding how and why esperity processes your personal data, and how you can exercise your rights. esperity also provides a mailbox to receive all alerts concerning compliance with personal data protection laws and regulations.
III. Processed data
The main data fields comprise all the information provided in your User account during sign-up and Site use. In particular, they include the following:
- Identification data:
- Pseudonym: giving a pseudonym that cannot be linked to your real identity is strongly recommended.
- Picture: uploading a ‘fantasy’ picture that cannot be linked to your real identity is strongly recommended.
- Physical and ethnic data: height, weight, ethnic type
- E-mail address.
The use of all data provided in these fields should not break any laws or infringe on any rights of third parties. For more information, please refer to the General Conditions.
- Medical profile data:
- Personal characteristics: in particular, age, sex and date of birth.
- Physical and ethnic characteristics: in particular, height, weight and ethnicity.
- Lifestyle habits: in particular, tobacco & alcohol consumption, and physical activity.
- Health: in particular, type of cancer, first diagnosis, past & current treatments, secondary effects, depression, mood, and other characteristics associated with your quality of life or day-to-day surroundings, temperature, etc.
- Biological data: in particular, tumor markers, blood test results, etc.
- Location: in particular, your geographic zone of residence.
- All types of other data provided during sign-up or Site use: in particular, what is provided while updating the User profile, using the Site tools or communicating with other Users.
Some of these data fields, which are marked with an asterisk (*), are necessary and mandatory to open your User account and to access the Site. The rest of the fields are optional, but you benefit from a better service if/when you complete them.
The Site also offers Users data fields similar to those above for them to be used by third parties as caregivers. Completing these fields, caregivers can also sign up as Users on behalf of the respective cancer patients.
Whatever their nature or gravity may be, esperity cannot be held liable for any consequences of your making data, e.g., names or photographs, public, and thereby allowing others to identify you or a third party.
esperity protects your data, which are not accessible via search engines.
You undertake to enter only data concerning yourself. esperity cannot be held responsible for the registration of third party data.
An exception is made in the case of entering the data of a third party under your legal responsibility, e.g., minors or incapacitated adults. You, therefore, take full responsibility for obtaining any consent necessary to enter data concerning a third party, and you undertake to scrupulously respect their rights, including those described herein.
You undertake to enter accurate, complete and up-to-date data. You also undertake to update your personal data without delay in the event of a change.
You understand that your registration on the Site is equivalent to a written consent to process your personal data, including sensitive data pertaining to factors such as health, ethnicity and lifestyle.
Data are processed in order to operate the Site for its intended purpose, which is to enable you to do the following:
- Registering to the Site, and then using it.
- Describing your condition and following its evolution; following your treatments and identifying their implications on your life and pathology; identifying other users with whom you want to communicate by allowing them to follow your profile along with their own.
- Providing the Site and the authorized third parties with information – except for the identification data – about yourself for them to conduct studies, improve treatments, analyze statistics and develop new protocols, therapies, etc. These endeavors can involve the third parties’ wanting to contact you; in such cases, the third party sends the Site a request, which is then relayed to you.
- Interacting with other Users to exchange and share information and messages with them, and to generate reports based on your health.
- Sharing personal messages with your medical twins through the activation of the “share” function. Your messages can then be translated into other languages to facilitate communication with other Users all around the world. The translations are automatically made with software in order to ensure confidentiality.
- Contacting partners of esperity and health professionals.
- Contacting esperity to receive answers to your questions.
- Identifying your interests better.
- Displaying personalized content, possibly with ads, and receiving product or service offers. These ads and offers are customized based on your profile, such that they are the ones most likely to serve your best interests.
- Receiving updates about new developments on the Site and its activities.
- Making your data – except for the ones used to identify you – available for scientific research and statistics analyses.
V. Transfer to third parties
According to what is described above, your data – except for the ones used for your identification and the ones that are unstructured – may be shared with third parties without your prior consent. These third parties may be other Users, and if applicable, partners of the Site, medical professionals or pharmaceutical companies.
esperity does its upmost to protect your personal data in order to prevent them from being corrupted, damaged or communicated to unauthorized third parties. esperity has implemented technical and organizational measures for this purpose.
VII. Cookies and navigation
VIII. Rights of access, rectification, deletion and opt-out
You can exercise your rights of access and rectification for data concerning yourself by simply connecting to your User account.
You can always check the status of the processed data about yourself by sending us a request. We will be sending you the respective information as soon as possible, after verifying your identity.
You can request the rectification of incorrect, incomplete or out-of-date data.
You can also request the deletion of your account. As stated in the General Conditions, which you have validated, deleted accounts are no longer visible for other Users, but they are not erased either. esperity is in fact expressly authorized to indefinitely retain all the information accumulated in the account prior to its deletion, with the exception of the identification data, which must either be erased or coded at the discretion of esperity. All unstructured data will, however, be erased during the deletion process.
In addition, all the regular communications esperity sends you include information about how you can opt out of receiving them.
As a security measure, esperity reserves the right to ask you to verify your identity for all access, rectification, deletion or opt-out requests.
If you believe that the Site does not comply with privacy protection laws and regulations, please alert us by sending an e-mail to firstname.lastname@example.org
IX. Updating the Statement
You will be informed about all possible modifications to the Statement via notifications on your User account or e-mails.
Nevertheless, esperity recommends that you regularly check this page for any future changes to the Statement.
Last update: October 16th 2013