Last updated: November 2019
POLICY ON DATA PRIVACY
This policy is subject to applicable data protection laws, and DrugStars undertakes to ensure that the collection, use and other processing of Personal Information about you complies with such laws applicable from time to time.
DATA CONTROLLER AND CONTACT INFORMATION
The data controller of your personal data is:
CVR: 36 89 39 74
Address: Emdrupvej 28 A, 4., 2100 København Ø
DrugStars’ Data Protection Officer (DPO) is:
CVR nr.: 38 53 80 71
Langelinie Allé 35 2100 København Ø
Tel: 72 27 30 02.
PROTECTION OF YOUR PERSONAL INFORMATION
WHAT INFORMATION WE OBTAIN AND THE PURPOSE FOR WHICH IT IS OBTAINED
We may collect Personal Information (such as your name, email, address etc.) from you;
- If you complete the registration process,
- If you contact us by email or letter,
- If you submit information or other content to DrugStars,
- If you otherwise provide us with such information.
We may collect and store any content that you upload, download or access by use of DrugStars, which may include Personal Information and sensitive information about you (such as your uploaded pictures of your prescription or over the counter medication).
We may automatically collect certain information when you use DrugStars, such as information about your operating system, browser, the address of a referring site and your activity on DrugStars. Such information is not treated as Personal Information unless it is combined with or linked to any of the personally identifiable information mentioned above.
PURPOSES AND LEGAL BASES OF PROCESSING PERSONAL DATA
We may use the information collected through DrugStars (including Personal Information) for the following purposes and with the following legal bases:
- to provide our services (GDPR article 6 (1) (b))
- to remind you to collect Stars (consent cf. GDPR article 6 (1) (a))
- to respond to your emails, submissions, questions, comments, requests, and complaints, (legitimate interest GDPR article 6 (1) (f))
- to provide customer service (legitimate interest GDPR article 6 (1) (f));
- to monitor and analyze usage and trends (legitimate interest GDPR article 6 (1) (f)),
- to increase the functionality and user friendliness of our services (legitimate interest GDPR article 6 (1) (f))
- to provide content or features that match your profile or interests, including our voucher program where vouchers will be matched with your diseases (legitimate interest GDPR article 6 (1) (f)),
- to send you confirmations, updates, security alerts, administrative messages
- to facilitate your use of our services (consent cf. GDPR article 6 (1) (a))
- to facilitate our administration and operation of the Services (legitimate interest GDPR article 6 (1) (f))
Some of the Personal Information we obtain from you might be of a sensitive nature (such as information related to your health). However, we only obtain, anonymize and process such information in order to provide the services and for statistical use in anonymized form if you have given a prior consent (GDPR article 9 (2) (a)).
PERIOD FOR WHICH THE PERSONAL DATA WILL BE STORED
We will only store Personal Information about you until we have finished processing such information for the stated purposes and up to 6 months after the suspension, disablement or termination of your access, use and/or account. Hereafter, we will erase any Personal Information about you to ensure your privacy. However, the personal data may be processed and stored for a longer period in anonymized form.
You may always exercise your right to erase data. User request to erasure or (the right to be forgotten) will take up to 30 days. Users who have not used the app in 13 months will have their personal data permanently erased.
DISCLOSURE OF PERSONAL INFORMATION
We may disclose Personal Information about you (such as name and email) with third parties only:
- In connection with your participation in the DrugStars Charity Program / including the Donation and Voucher setup for the purpose of redeeming and fulfilling your voucher (such merchants are obligated to use your Personal Information only to redeem and fulfill your voucher and are obligated not to disclose it or use it for any other purposes).
- we may share your information, including Personal Information, with service providers who have a contractual relationship with us in connection with the operation of our site or our services (these service providers have access to your Personal Information only to perform services on our behalf and are obligated not to disclose it or use it for any other purposes);
- we may also do data analysis on aggregated levels on medical reviews. No information on your medications or diseases will be linked to your individual Personal Information.
LINKS TO OTHER SITES OR APPLICATIONS
ACCESS AND MODIFICATION OF YOUR PERSONAL INFORMATION
If you have an account, you can access and modify the Personal Information (that you have provided to us) associated with your account.
You can request to delete your Personal Information you have made available by contacting us and requesting that your Account be deleted. We will take steps to delete your Personal Information as soon as is possible, but some information may remain in archived/backup copies for our records and as otherwise required by law.
You may request access to the personal information we have obtained about you. We are obligated to inform you whether or not we are processing personal information about you, the purpose of the processing, the categories of the personal information and any other available information as to the source of such data.
If we cannot comply with the request within 4 weeks from receipt of your request, we will inform you of the reasons for this and when we expect to be able to comply with your request.
You may at any time object our processing of Personal Information concerning you.
If your objection is justified, we will no longer process such information.
You may request us to rectify, erase or block Personal Information which is inaccurate or misleading or in any other way processed in violation of law or regulations.
We will make great efforts to notify any third party to whom Personal Information may have been disclosed of any rectification, erasure or blocking carried out in compliance with your request.
You may at any given time withdraw your consent to our processing of Personal Information concerning you.
You are free to contact us at any time if you feel that we are processing of Personal Information about you in violation of applicable law. However, you may also file a complaint to the appropriate supervisory authority concerning the processing of Personal Information about you.
How to contact the appropriate authority: Should you wish to report an issue or if you feel that we have not addressed your concerns in a satisfactory manner, you may contact the Danish Data Protection Agency: https://www.datatilsynet.dk/ Email: email@example.com Address: Borgergade 28, 5., 1300 Kbh K Telephone: +45 33 19 32 00
If you are located outside of Denmark or outside the EU and choose to provide information to us, we may transfer your information to the respective countries and process it there (or any other country where we operate).
By continuing to access or use DrugStars after those changes become effective, you are agreeing to be bound by the revised policy.