Infonetica Ltd ("Infonetica") provides the Ethics Review Manager service (also referred to as Ethics RM and/or ERM) to its customers. In doing so, we hold the personal information of registered Ethics RM users. Infonetica acts as a data processor under the UK GDPR and the Data Protection Act 1998 ("the Act"). We have specific obligations regarding the processing of personal information. This privacy policy outlines how Infonetica handles personal data related to the provision of the Ethics RM service. Please note that our Customer is the data controller. For services where Infonetica acts as a data controller, please refer to our General Privacy Policy (http://infonetica.net/general-privacy-policy/). We are Infonetica Ltd (company number 04503405), with a registered address at: The Lower Ground Floor Office, The Civic Centre, High Street, Esher, Surrey, KT10 9SD. You can contact us: Ethics Review Manager (also known as Ethics RM and/or ERM) is a software application that is owned and operated by Infonetica. Organisations wishing to use the Ethics RM service ("Customers") are required to register with Infonetica. Once registered, Ethics RM accounts are created for individuals within or affiliated with the Customer. When an Ethics RM account is created, the registered user is required to provide a small amount of personal data either: This personal data is held by Infonetica in a database on servers located at Infonetica's principal place of business and at least one other location within the United Kingdom. The personal data held includes name, organisational identifier, department, email address, username, role and other information which Infonetica requires to provide the Ethics RM service. No data that is not necessary to provide the Ethics RM service is stored in the database. Personal information about an account is available to the relevant Ethics RM system administrators via the Ethics RM Administration Interface. This information is used by the administrator to: Ethics RM system administrators are appointed by Infonetica and the Customer through a joint approval process. They are subject to terms and conditions that include adhering to appropriate privacy legislation. These terms are outlined in a separate contract but are summarized below: These lists highlight the core obligations related to personal privacy but do not represent the entirety of Administrator and User responsibilities. Each Ethics RM administrator is required to provide Infonetica with the following personal data: Infonetica will hold this personal information on the Ethics RM database and use it to contact system administrators regarding the Ethics RM accounts for which they are responsible. Customers must also input at least two of the following identifiers into the Ethics RM application: This enables registered users to contact their Ethics RM administrator with Ethics RM-related inquiries. This information is visible to registered users on the Ethics RM website. Infonetica will retain the personal data of system administrators for as long as they remain the nominated Ethics RM administrator for the Customer. Data will be deleted upon account deletion. We will keep the personal data of registered users while they remain registered. This information is deleted when: Following account deletion, Ethics RM will still hold statistical information about the account. However, this information is linked only to the username and/or a persistent ID. This link does not allow access to any personal information about the individual. If Infonetica or the Ethics RM service is sold or integrated with another business, details of all registered users within Ethics RM would be passed on to the new owners of the business. A "cookie" is a small text file that a website transfers to your browser on your computer's hard drive. Cookies enable the website to recognize your browser and remember certain information. The Ethics RM application uses or may use the following two types of cookies: You can set your browser to warn you before accepting cookies and refuse them when alerted. You can refuse cookies by adjusting your browser settings; however, this may limit your ability to use all of the Ethics RM features. You can easily delete any cookies that have been installed. Please consult your browser's documentation for instructions on managing cookies. Registered users can view their personal information held by logging into Ethics RM with their username and password. Users are responsible for maintaining their information; however, administrators can also update and monitor it. This privacy policy applies only to the use of your personal information by Infonetica in connection with the Ethics RM service. The use of personal information by the Customer or any resource provider is governed by their own privacy policies. Infonetica are unable to accept responsibility for the use of any of personal data or information by the Customer or any resource provider. Infonetica may update this privacy policy from time to time. Any changes shall be notified by posting on the Infonetica website or a location as chosen by the Customer. Regularly reviewing this information ensures the user is always aware of the personal data Infonetica has access to and how it is used. Infonetica is required to take appropriate technical and organisational measures to secure personal data. In order to comply with this requirement, the servers containing personal data are located in secure data centre locations with physical access limited to authorised staff. All data transmissions to and from the Ethics RM database are encrypted. Furthermore, password information sent to Ethics RM is hashed (a form of one-way encryption that produces a result from which it is computationally infeasible to deduce the original text) before it is stored in the Ethics RM database. The data is processed automatically by Infonetica’s systems without any human intervention. Only in the event of a technical problem will any Infonetica staff become involved. All Infonetica’s staff are instructed in the importance of and adherence to the principles and requirements of the Act, and Infonetica itself endeavours to ensure they comply with the terms of this privacy policy. The personal data which Infonetica holds is never modified or disclosed to a third party other than as described in this policy. Infonetica continually monitors measures which seek to ensure the security and confidentiality of the information that Infonetica collects and its proper use. Users should contact the Customer in the first instance with any enquiries (since the Customer is the data controller for the purposes of the Act). Any questions or enquiries about this privacy policy or Infonetica's compliance with the Act should be addressed in the first instance to: Infonetica, The Lower Ground Floor Office, The Civic Centre, High Street, Esher, Surrey KT10 9SD, or by emailing enquiries@www.infonetica.net or by telephoning +44 (0) 208 334 6900. This document is designed as a brief on the underlying principles of privacy for the Ethics RM System. It is possible for our Customers to specify different criteria, and therefore not everything within this document may be applicable.
Ethics Review Manager Privacy Policy
Introduction
Who we are and how you can contact us
Ethics RM
Registered Users
Administrator Responsibilities:
Individual User Responsibilities:
Ethics RM Administrators
Data Retention
Business Transfer
Cookies
Refusal/Deletion of Cookies
Access to your personal information
Scope of this privacy policy and updates
Security of your personal information
Queries or complaints
Disclaimer