Privacy statement
Introduction
This Privacy Statement applies to personal data collected, used and stored by MyClusters in connection with the use of our services (the “Services”) that are being offered to you on our website www.MyClusters.nl. This Privacy Statement explains the types of personal data we collect from and about you and how we use, disclose and protect that data as well as your ability to control certain uses of it.
MyClusters is responsible for the data you share with us as a data controller under the General Data Protection Regulation 2016/679 (GDPR’). It goes without saying that MyClusters adheres to the rules as set forth therein.
Who is responsible for the personal data collected?
Your personal data is controlled by MyClusters [MyClusters BV, KvK: 94966958, based in Leiden, Netherlands} (“MyClusters”). Our company details can be found at the end of this document.
Purpose of processing your personal data
In this Privacy Statement, your “personal data” means information or pieces of information that could allow you to be identified. For example, your name, address, telephone number and e-mail address, but also your IP address.
1. Personal data we may collect and/or use directly from you when you visit our website and/or make an enquiry via the contact form on our website you find below. The legal basis for this data processing consists in our legitimate interest in processing your email inquiry and providing information requested by you:
· e-mail address;
· IP address;
2. If you become a user of our Services, we will collect and use the following personal data:
· username and password;
· e-mail address;
· date of birth;
· city where you live;
· your gender;
· Diagnosis confirmation;
· Year of diagnosis;
· Medication data;
· Headache related data;
· Lifestyle related data.
· Ethnic Background
The legal basis for this data processing is that it is necessary for the performance of the agreement between MyClusters and you, which is realised when you accept the Terms of Use.
We only request the personal data that we specifically need to provide the Services in your particular case. Without this personal data, we are unable to deliver our Services. It is therefore important that you have verified its accuracy.
We will only retain this information for the duration of your use of the Services and for a maximum of 7 years thereafter if we are required to do so by law.
Automated decision making
Your personal data will always be processed by a human being. MyClusters will not take any decisions that may affect you personally based on automated processing.
Our third-party service providers
We use Squarespace for our e-mail service and newsletter hosting, and AWS for our data storage. We use fly.io to host our Cloud and they have servers in the EU. We use Google Analytics, Umami and Squarespace to monitor and analyze your use of the website and the Services.
We will make sure that all our third-party services providers comply with GDPR. These third-party services providers may be located outside in a country outside the European Economic Area (“EEA”). If the level of data protection in a country does not correspond to the European level, we shall ensure by contract (standard contractual clauses issued by the European Commission) that the protection of your personal data corresponds at all times to that of the European Economic Area, or countries that are ‘whitelisted’ by the European Commission.
Will we share your personal data with other parties (other than our third-party service providers)?
As detailed in this Statement, we are committed to safeguarding your personal data. We will not share your information with any third parties without your explicit consent, unless we are legally compelled to do so.
MyClusters does share data with medical researchers, however, all personal data will be anonymized before it is shared in this regard.
How do we protect your personal data?
The collection, use and disclosure of personal data is safeguarded by technological and organisational security measures with the objective of protecting the personal data against loss, misuse and unauthorised access, alteration, disclosure or destruction. These measures are continually improved in line with technological developments.
In particular, we restrict access to personal information to our employees, retailers and all other parties we work with, who are subject to strict contractual confidentiality obligations and may be disciplined or terminated if they fail to meet these obligations.
We will not retain your personal data for a period longer than necessary to fulfil the purposes for which it was collected for, unless we have to keep it for legitimate business, tax or legal purposes.
Your privacy rights
You have the following rights regarding your data:
• Access. You can request a written copy of the personal data we hold about you;
• Correct. We want to ensure that your personal data is accurate and current. You can rectify data with us that you believe to be incorrect;
• Erase: You can request us to erase your personal data. If we need the personal data to be able to provide you with our services, we may not be able to erase it immediately. We may not delete information that we are required to keep by law;
• Object. You can object at any time to the processing of your personal data on the basis of Article 21 GDPR;
• Restrict processing. You can limit the processing of your data in accordance with Article 14 of the GDPR;
• Withdraw consent. When the processing of your personal data is based on your consent, you have the right to withdraw your consent, without affecting the lawfulness of the processing based on your consent before the withdrawal;
• Data portability: If your personal data is processed by automated decision-making for the fulfilment of our contractual relationship, you have the right to request that we provide you with your personal data in a machine-readable format for transfer to another controller;
• Complain. You can submit a complaint at any time to the authority via https://autoriteitpersoonsgegevens.nl/;
• Ask for information. You have the possibility to request information about your personal data; and
• E-mail. Questions, comments, requests or complaints concerning the processing of your personal data or this privacy statement can be addressed to privacy@myclusters.nl
Modifications to this Privacy Statement
This Statement may change from time to time. If we make material changes to this Statement and the way we use your personal data when you use our Services, we will notify you. Nevertheless, we encourage you to review this Statement periodically.
Questions?
If you have any questions or comments about our Statement, please send us an e-mail at privacy@myclusters.nl.
You may also contact us by postal mail at:
MyClusters BV
Langegracht 70
2312NV, Leiden
The Netherlands
Chamber of Commerce: 94966958