För patienter, HCPS/klinikpersonal, webbplatsbesökare
Välkommen till Adoreal-sekretesspolicyn.
Introduktion
Detta integritetsmeddelande är avsett för:
Adoreal förstår att integritet är viktigt för dig. Vi är fast beslutna att behandla dina personuppgifter med omsorg och integritet.
Vårt integritetsmeddelande berättar vilka personuppgifter vi samlar in och hur vi samlar in dem, inklusive alla uppgifter du kan tillhandahålla via denna webbplats när du besöker webbplatsen eller frågar om en produkt eller tjänst eller deltar i ett evenemang. Den förklarar vad vi använder dina personuppgifter till och hur vi skyddar dina personuppgifter och håller dem säkra. Detta integritetsmeddelande förklarar vår allmänna praxis. Men där lokala lagar eller förordningar kräver att vi behandlar information på ett annat sätt, eller avstår från sådan behandling, kommer vi alltid att följa tillämplig lokal lag. Denna webbplats är inte avsedd för barn och vi samlar inte medvetet in uppgifter om barn.
Adoreal värdesätter din integritet. Adoreal består av olika juridiska företag som är relaterade till oss genom gemensam kontroll eller ägande (”Adoreal Group”). Detta sekretessmeddelande utfärdas på uppdrag av Adoreal Group, så när vi nämner ”Adoreal”, ”vi”, ”oss” eller ”vår”, är detta vem vi hänvisar till. Adoreal Limited (registrerat i Irland under nummer 72345090 D, med säte på South Circular Road, Dublin 8, Irland) är personuppgiftsansvarig och ansvarig för denna webbplats.
Det är viktigt att du läser detta integritetsmeddelande tillsammans med alla andra integritetsmeddelanden eller meddelanden om rättvis behandling som vi kan tillhandahålla vid specifika tillfällen när vi samlar in eller behandlar personuppgifter om dig så att du är fullt medveten om hur och varför vi använder dina uppgifter. Detta integritetsmeddelande kompletterar andra meddelanden och sekretesspolicyer och är inte avsett att åsidosätta dem.
Vi har utsett ett dataskyddsombud (DPO) som ansvarar för att övervaka frågor i samband med detta integritetsmeddelande. Om du har några frågor om detta integritetsmeddelande, inklusive eventuella förfrågningar om att utöva dina lagliga rättigheter, vänligen kontakta DPO med hjälp av uppgifterna nedan.
Kontaktuppgifter ([email protected])
Om du har några frågor om detta integritetsmeddelande eller vår integritetspraxis, vänligen kontakta vår DPO på följande sätt:
Fullständigt namn på juridisk person: Adoreal Limited
E-postadress: [email protected]
Du har rätt att när som helst lämna in ett klagomål till dataskyddsmyndigheten i det land där du vanligtvis bor eller arbetar, eller där den påstådda överträdelsen av dataskyddet har ägt rum. Vi skulle dock uppskatta chansen att ta itu med dina problem innan du kontaktar tillämplig dataskyddsmyndighet, så kontakta oss i första hand.
Det är viktigt att de personuppgifter vi har om dig är korrekta och aktuella. Håll oss informerade om dina personuppgifter ändras under din relation med oss.
Med personuppgifter avses all information eller information som kan identifiera dig antingen direkt (t.ex. ditt namn) eller indirekt (t.ex. ett unikt ID-nummer).
I detta integritetsmeddelande förklarar vi:
Adoreal Limited (bildat i TheRepublic of Ireland under nummer 72345090 D, med säte på South Circular Road, Dublin 8, Irland) (Adoreal”) tillsammans med det lokala Adoreal-företaget som har en relation med dig, är personuppgiftsansvariga för dina personuppgifter.
Om du vill utöva dina rättigheter, har några frågor om detta integritetsmeddelande, behöver mer information eller vill ta upp en fråga kan du hitta uppgifter om varje lokal kontaktpunkt för sekretess genom att kontakta [email protected].
Personuppgifter, eller personuppgifter, betyder all information om en individ från vilken den personen kan identifieras. Det inkluderar inte uppgifter där identiteten har tagits bort (anonyma uppgifter). De personuppgifter vi samlar in och behandlar kan inkludera:
Vi samlar också in, använder och delar aggregerade data såsom statistiska eller demografiska data för alla ändamål. Aggregerade uppgifter kan härledas från dina personuppgifter men betraktas inte som personuppgifter enligt lag eftersom dessa uppgifter inte direkt eller indirekt avslöjar din identitet. Vi kan till exempel samla dina användningsdata för att beräkna andelen användare som använder en specifik webbplatsfunktion. Men om vi kombinerar eller kopplar samman aggregerade uppgifter med dina personuppgifter så att de direkt eller indirekt kan identifiera dig, behandlar vi de kombinerade uppgifterna som personuppgifter som kommer att användas i enlighet med detta integritetsmeddelande.
Du kan välja att inte ge oss personuppgifter när vi ber dig om det. Om du bestämmer dig för att inte ge oss dina personuppgifter kan det begränsa vår relation med dig. Vi kanske till exempel inte kan tillhandahålla de tjänster du har begärt.
Direkt från dig när du:
Från andra källor:
När lagen tillåter det använder vi dina personuppgifter för de ändamål som vi har beskrivit nedan i detta integritetsmeddelande, eller för ändamål som är rimligen kompatibla med de som beskrivs:
I allmänhet förlitar vi oss inte på samtycke som rättslig grund för behandling av dina personuppgifter, även om vi kommer att få ditt samtycke innan:
(1) anonymisera dina personuppgifter i syfte att utföra analyser av anonymiserade/aggregerade uppgifter från vilka du inte kan identifieras; och
(2) skicka direktmarknadsföringskommunikation till dig via e-post. Observera att Adoreals kontakt med patienter regleras av Adoreals villkor med patienten. Även efter uppsägning av ett avtal mellan Adoreal och en vårdpersonal/institution/klinik kan Adoreal behålla patientens kontaktuppgifter. Adoreal kan fortsätta lämpliga specifika marknadsföringsaktiviteter gentemot sådana patienter med avseende på patientens tidigare kontakt med Adoreal, i enlighet med förordningen om integritet och elektronisk kommunikation (EG-direktivet) 2003 (som kan uppdateras från tid till annan).
Du har rätt att när som helst återkalla samtycke till dessa aktiviteter genom att kontakta oss på [email protected]
”Berättigat intresse” avser vårt företags intresse av att bedriva och hantera vår verksamhet så att vi kan ge dig den bästa tjänsten/produkten och den bästa och säkraste upplevelsen. Vi ser till att vi överväger och balanserar eventuell påverkan på dig (både positiv och negativ) och dina rättigheter innan vi behandlar dina personuppgifter för våra legitima intressen. Vi använder inte dina personuppgifter för aktiviteter där våra intressen åsidosätts av påverkan på dig (såvida vi inte har ditt samtycke eller på annat sätt krävs eller tillåts enligt lag). Du kan få ytterligare information om hur vi bedömer våra legitima intressen mot eventuell påverkan på dig med avseende på specifika aktiviteter genom att kontakta oss.
” Fullgörande av ett avtal” avser behandling av dina uppgifter där det är nödvändigt för att fullgöra ett avtal som du är part i eller för att vidta åtgärder på din begäran innan ett sådant avtal ingås.
” Uppfylla en rättslig skyldighet” innebär behandling av dina personuppgifter där det är nödvändigt för att uppfylla en rättslig skyldighet som vi är föremål för.
För att uppnå andra syften.
Vi kommer att använda dina personuppgifter:
Nedan har vi, i tabellformat, redogjort för alla sätt som vi planerar att använda dina personuppgifter och vilka rättsliga grunder vi förlitar oss på för att göra det. Vi har också identifierat vilka våra legitima intressen är där det är lämpligt. Observera att vi kan behandla dina personuppgifter för mer än en laglig grund beroende på det specifika syftet för vilket vi använder dina uppgifter. Kontakta oss om du behöver information om den specifika rättsliga grunden som vi förlitar oss på för att behandla dina personuppgifter där mer än en grund har angivits i tabellen nedan.
Vi kan samla in och använda dina personuppgifter när något av följande gäller:
Vi vill se till att dina personuppgifter inte delas med eller används av dem som inte får se dem. Vi använder en mängd olika säkerhetsåtgärder och tekniker för att skydda dina personuppgifter.
Vi väljer noggrant tjänsteleverantörer att arbeta med och kontrollerar att de har säkerhetsåtgärder och tekniker på plats för att skydda dina personuppgifter. Dessutom begränsar vi tillgången till dina personuppgifter till de anställda, agenter, entreprenörer och andra tredje parter som har ett affärsbehov att känna till. De kommer endast att behandla dina personuppgifter enligt våra instruktioner och de är föremål för en tystnadsplikt. Vi har infört förfaranden för att hantera eventuella misstänkta personuppgiftsbrott och kommer att meddela dig och alla tillämpliga tillsynsmyndigheter om ett brott där vi enligt lag är skyldiga att göra det.
Det finns dock inga garantier för att adata överförings- eller lagringssystem är 100% säkert. Om du har anledning att tro att din interaktion med oss inte längre är säker, vänligen meddela oss omedelbart med hjälp av uppgifterna i avsnittet ”Kontaktinformation och din kontaktpunkt för sekretess”.
Du har rättigheter som vi måste göra dig medveten om. De rättigheter som finns tillgängliga för dig beror på vårt skäl för att behandla dina personuppgifter och den lokala lagstiftningen i din jurisdiktion, och det finns undantag från vissa rättigheter. Beroende på detta kan du ha rätt att:
1. Återkalla ditt samtycke till att vi behandlar dina personuppgifter när som helst för direktmarknadsföringsändamål eller där vi förlitar oss på samtycke för att behandla dina personuppgifter. Detta påverkar dock inte lagenligheten av någon behandling som utförs innan du har gett ditt samtycke. Om du återkallar ditt samtycke kanske vi inte kan tillhandahålla vissa produkter eller tjänster till dig. Vi kommer att meddela dig om detta är fallet när du återkallar ditt samtycke, vänligen kontakta [email protected] för mer information. Denna begäran om återkallande måste hanteras av Adoreal-dataskyddsombudet för att bedöma vilka personuppgifter (om sådana finns) som kan raderas, och i så fall för vilken specifik användning. Observera att personuppgifter som ingår i medicinska journaler inte kan raderas på grund av allmän ordning.
2. Fråga Adoreal om behandlingen av dina personuppgifter inklusive att få kopior av dina personuppgifter (genom en ”begäran om åtkomst till den registrerade”) . ;
3. Be oss korrigera information som du tycker är felaktig eller ofullständig, även om vi kan behöva verifiera riktigheten av de nya uppgifter du lämnar till oss;
4. Be oss att radera dina personuppgifter där det inte finns några goda skäl för oss att fortsätta behandla dem. Du har också rätt att be oss att radera eller ta bort dina personuppgifter om du framgångsrikt har utövat din rätt att invända mot behandling (se nedan), där vi kan ha behandlat din information olagligt eller där vi är skyldiga att radera dina personuppgifter för att följa lokal lagstiftning. Observera dock att vi kanske inte alltid kan uppfylla din begäran om radering av specifika juridiska skäl som kommer att meddelas dig, om tillämpligt, vid tidpunkten för din begäran;
5. Be oss att begränsa behandlingen av din information. Detta gör att du kan be oss att avbryta behandlingen av dina personuppgifter i följande situationer:
a. Om du vill att vi ska fastställa uppgifternas riktighet;
b. Om vår användning av uppgifterna är olaglig men du inte vill att vi ska radera dem;
c. Där du behöver oss för att hålla uppgifterna även om vi inte längre behöver dem som du behöver dem
d. upprätta, utöva eller försvara rättsliga anspråk; eller
e. Du har invänt mot vår användning av dina uppgifter, men vi måste kontrollera om vi har övervägande legitima skäl att använda dem.
6. Invända mot vår behandling av dina personuppgifter om vi förlitar oss på ett berättigat intresse (eller en tredje parts intressen) och det finns något i din speciella situation som gör att du vill invända mot behandlingen på denna grund eftersom du anser att det påverkar dina grundläggande rättigheter och friheter. Du har också rätt att invända om vi behandlar dina personuppgifter för direktmarknadsföringsändamål. I vissa fall kan vi visa att vi har tvingande legitima skäl att behandla din information som åsidosätter dina rättigheter och friheter.
7. Be att vi överför information som du har gett oss från en organisation till en annan, eller att ge den till dig. Vi kommer att tillhandahålla dig, eller en tredje part som du har valt, dina personuppgifter i ett strukturerat, allmänt använt, maskinläsbart format. Observera att denna rättighet endast gäller automatiserad information som du ursprungligen gav oss samtycke till att använda eller där vi använde informationen för att fullgöra ett avtal med dig; och8. Klaga till din lokala dataskyddsmyndighet.
Du kan ta reda på hur du kommer i kontakt med oss för att be oss göra något av ovanstående genom att titta på avsnittet ”Kontaktinformation och din kontaktpunkt för sekretess”.
För ditt skydd och för att skydda andras integritet kan vi behöva verifiera din identitet innan vi fullgör vad du har bett oss att göra och för att säkerställa din rätt att få tillgång till dina personuppgifter (eller att utöva någon av dina andra rättigheter). Detta är en säkerhetsåtgärd för att säkerställa att personuppgifter inte lämnas ut till någon person som inte har rätt att ta emot dem. Vi kan också kontakta dig för att be dig om ytterligare information i samband med din begäran för att påskynda vårt svar.
Du behöver inte betala någon avgift för att få tillgång till dina personuppgifter (eller för att utöva någon av de andra rättigheterna). Vi kan dock ta ut en rimlig avgift om din begäran är uppenbart ogrundad, repetitiv eller överdriven. Alternativt kan vi vägra att uppfylla din begäran under dessa omständigheter.
Vi försöker svara på alla legitima förfrågningar inom en månad. Ibland kan det ta längre tid än en månad om din begäran är särskilt komplex eller om du har gjort ett antal förfrågningar. I det här fallet kommer vi att meddela dig och hålla dig uppdaterad.
Om vi har förlitat oss på ditt tillstånd att använda dina personuppgifter, och du senare återkallar detta tillstånd, kanske vi inte kan slutföra några av de aktiviteter som beskrivs i ”Hur använder vi dina personuppgifter”.
I vissa jurisdiktioner är vi lagligen skyldiga att behålla dina personuppgifter under vissa perioder. Hur länge beror på de specifika juridiska kraven i den jurisdiktion du befinner dig i när du delar din information med oss.
Vi kommer alltid att behålla dina personuppgifter under den tid som krävs enligt lag och där vi behöver göra det i samband med rättsliga åtgärder eller en utredning som involverar Adoreal. Annars kommer vi att behålla dina personuppgifter så länge vi har en relation med dig, för att svara eller behandla en fråga eller begäran från dig. Adoreals kontakt med patienter regleras av Adoreals villkor med patienten. Även efter uppsägning av ett avtal mellan Adoreal och en vårdpersonal/institution/klinik kan Adoreal behålla patientkontaktuppgifter och Adoreal kan fortsätta lämpliga specifika marknadsföringsaktiviteter gentemot sådana patienter med avseende på patientens tidigare kontakt med Adoreal, i enlighet med förordningen om integritet och elektronisk kommunikation (EG-direktivet) 2003 (som kan uppdateras från tid till annan); och
Vi kan behålla dina personuppgifter under en längre period i händelse av ett klagomål eller om vi rimligen tror att det finns risk för rättstvister avseende vår relation med dig.
I den mån behandlingen av personuppgifter baseras på ditt samtycke kommer vi att radera dessa uppgifter om du återkallar ditt samtycke, med förbehåll för den tekniska förmågan att göra det och i den mån en sådan radering inte skulle kräva oproportionerliga ansträngningar från vår sida. Denna begäran om radering måste hanteras av Adoreal-dataskyddsombudet för att bedöma vilka personuppgifter (om sådana finns) som kan raderas, och i så fall för vilken specifik användning. Observera att personuppgifter som ingår i journalerna inte kan raderas av allmän ordning.
För att fastställa lämplig lagringsperiod för personuppgifter tar vi hänsyn till mängden, arten och känsligheten hos personuppgifterna, den potentiella risken för skada från obehörig användning eller utlämnande av dina personuppgifter, ändamålen för vilka vi behandlar dina personuppgifter och huruvida vi kan uppnå dessa syften på andra sätt och tillämpliga lagliga, regulatoriska, skatte-, redovisnings- eller andra krav.
Vi delar dina personuppgifter på grundval av behovet av att veta, och i den utsträckning som är nödvändig för att följa lagar och förordningar, och i samband med att hantera vår relation med dig.
Vi delar endast dina personuppgifter med team i våra Adoreal-företag och dotterbolag som behöver se dem för att kunna utföra sina jobb. Vi kräver att alla tredje parter respekterar säkerheten för dina personuppgifter och behandlar dem i enlighet med lagen. Vi tillåter inte våra tredjepartsleverantörer att använda dina personuppgifter för sina egna ändamål och tillåter dem endast att behandla dina personuppgifter för angivna ändamål och i enlighet med våra instruktioner.
Vi kommer också att dela dina personuppgifter med andra enheter, till exempel:
Vi arbetar över hela världen. Därför, där din tillämpliga lag tillåter det, kan vi behöva överföra och använda dina personuppgifter utanför det land där vi samlar in dem från dig. Vi vidtar lämpliga åtgärder för att skydda dina personuppgifter när vi överför dina personuppgifter utanför ditt hemland, till exempel dataöverföringsavtal som innehåller standardklausuler om dataskydd. Dataskyddslagarna i de länder vi överför dem till kanske inte är desamma som lagarna i ditt hemland. Brottsbekämpande myndigheter, tillsynsmyndigheter, säkerhetsmyndigheter eller domstolar i de länder vi överför dina personuppgifter till kan ha rätt att se dina personuppgifter. Om tillämplig lag inte tillåter överföring av specifika personuppgifter utanför ett land kommer vi att följa den tillämpliga lagen.
Europeiska kommissionen erkänner att vissa länder utanför EES har liknande dataskyddsstandarder. Om vi överför dina personuppgifter till ett land utanför EES som inte har liknande dataskyddsstandarder, gör vi det baserat på standardavtalsklausuler som antagits av Europeiska kommissionen, för att säkerställa att respektive mottagare skyddar dina personuppgifter på ett adekvat sätt i enlighet med detta integritetsmeddelande. Dessa gör det möjligt för oss att göra internationella överföringar av personuppgifter inom vår företagsgrupp och uppfylla dataskyddslagarna i Europeiska unionen och den allmänna dataskyddsförordningen (GDPR).
Även om våra tjänster vanligtvis inte riktar sig till barn, kan vi ibland få ditt barns uppgifter, till exempel om du lämnar dessa personuppgifter till oss för att du letar efter en behandling för dem som involverar estetisk/kosmetisk/plastikkirurgi. Vi kommer endast att få detta med ditt samtycke. Se ”Vilka personuppgifter vi samlar in om dig” för mer information.
Våra webbplatser kan använda cookies och liknande teknik. Du kan välja att acceptera eller avvisa cookies. Om du väljer att avvisa cookies kan inte alla delar av våra webbplatser, appar och tjänster fungera som avsett, så din upplevelse kan påverkas.
I den utsträckning som dina lokala lagar betraktar den information som samlas in av cookies och annan teknik som personuppgifter, kommer vi att behandla den informationen enligt de standarder som anges i detta integritetsmeddelande.
Vi strävar efter att ge dig valmöjligheter när det gäller viss användning av personuppgifter, särskilt när det gäller marknadsföringskommunikation från oss och/eller det relevanta företaget i Adoreal-koncernen. Du kommer att få marknadsföringskommunikation från oss eller det relevanta företaget i Adoreal-koncernen om du har begärt information från oss eller det relevanta företaget i Adoreal-koncernen och du inte har valt att ta emot den marknadsföringen.
Vi samlar in information om din dators webbläsartyp och operativsystem, webbplatser du besökte före och efter att ha besökt våra webbplatser, standardserverlogginformation, IP-adresser (Internet Protocol), platsdata, mobiltelefonleverantör och operativsystem för mobiltelefoner. Vi använder denna information för att förstå hur våra besökare använder våra webbplatser och mobilapplikationer så att vi kan förbättra dem, de tjänster vi erbjuder och vår annonsering. Vi kan också dela denna information med andra företag inom Adoreal-koncernen och med andra tredje parter. Vissa av våra webbplatser använder Google Analytics, en webbanalystjänst som tillhandahålls av Google, Inc. (”Google”). Google Analytics använder cookies för att analysera användningsmönster och kan samla in information om din användning av webbplatsen, inklusive din IP-adress. Mer information om Google Analytics finns här. Om du vill välja bort att dina uppgifter används av Google Analytics kan du välja bort det här.
Vi använder även remarketingtjänster som erbjuds av våra annonspartners för att anpassa annonser för besökare på webbplatser i deras annonsnätverk (dvs. andra webbplatser än Adoreals). På dessa sidor kan du visas annonser som hänvisar till dina tidigare interaktioner med Adoreal. Klicka här för att stänga av personalisering för annonser som visas av Google. Klicka här för att stänga av personalisering för annonser som visas av Facebook. Många företag som visar intressebaserad reklam är medlemmar i Network Advertising Initiative (”NAI”), DigitalAdvertising Alliance (”DAA”) eller European Interactive DigitalAdvertising Alliance (”EDAA”). För att välja bort intressebaserad annonsering från medlemmar i dessa initiativ kan du besöka deras webbplatser på https://optout.networkadvertising.org, https://optout.aboutads.info och https://www.youronlinechoices.com.
Vi kan använda de uppgifter du delar med oss för att fatta beslut om dina intressen och preferenser så att vi kan göra marknadsföringsmaterialet vi skickar till dig mer relevant. Vi kan också kombinera den information vi har om dig med uppgifter om dina intressen eller demografi som tredje part har samlat in från dig online och offline, för att göra din upplevelse mer personlig och ytterligare skräddarsy vårt marknadsföringsmaterial. Du har vissa rättigheter i samband med detta — se ”Vilka rättigheter har du när det gäller dina personuppgifter?” ovan för ytterligare information.
Vi använder Facebooks anpassade målgruppsverktyg. Detta gör det möjligt för oss att tillhandahålla personlig reklam till dig när du använder Facebooks plattformar genom att matcha den e-postadress vi har åt dig med e-postadressen Facebook har för dig, för att visa dig de mest relevanta Adoreal-annonserna. Vi gör detta endast där du har gett oss samtycke. Ibland kan vi också använda information om dig för att bygga lookalike-modeller. Detta gör det möjligt för oss att generera liknande målgrupper av potentiella kunder (som kan ha liknande intressen eller demografi som dig) via reklamplattformar som Facebook eller Google, baserat på data som annonseringsplattformen har om andra personer. Vanligtvis innebär detta att du delar din e-postadress med våra annonspartners. Om du vill välja bort liknande målgrupper på Google kan du göra det här.
Adoreal delar inte dina personuppgifter med någon tredje part för marknadsföringsändamål. I händelse av att vi vill göra det kommer vi att få ditt uttryckliga samtycke innan vi delar dina personuppgifter med någon tredje part för marknadsföringsändamål.
Du kan be oss att sluta skicka marknadsföringsmeddelanden när som helst genom att följa opt-out-länkarna på alla marknadsföringsmeddelanden som skickas till dig eller genom att när som helst kontakta oss på [email protected].
Du kan ställa in din webbläsare så att den vägrar alla eller vissa webbläsarcookies, eller att varna dig när webbplatser ställer in eller använder cookies. Om du inaktiverar eller vägrar cookies, observera att vissa delar av denna webbplats kan bli otillgängliga eller inte fungera korrekt. För mer information om de cookies vi använder, se vårt cookiemeddelande.
Vi kommer endast att använda dina personuppgifter för de ändamål för vilka vi samlade in dem, såvida vi inte rimligen anser att vi behöver använda dem av en annan anledning och att anledningen är förenlig med det ursprungliga syftet. Om du vill få en förklaring till hur behandlingen för det nya ändamålet är förenlig med det ursprungliga syftet, vänligen kontakta oss. Om vi behöver använda dina personuppgifter för ett orelaterat syfte kommer vi att meddela dig och vi kommer att förklara den rättsliga grunden som tillåter oss att göra det. Observera att vi kan behandla dina personuppgifter utan din vetskap eller samtycke, i enlighet med ovanstående regler, där detta krävs eller tillåts enligt lag.
Från tid till annan kommer vi att uppdatera detta integritetsmeddelande. Eventuella ändringar träder i kraft när vi publicerar det reviderade sekretessmeddelandet på Adoreal-webbplatsen. Detta sekretessmeddelande uppdaterades senast från och med datumet ”Senast uppdaterad” som visas ovan. Om uppdateringsändringar är betydande kommer vi att ge ett mer framträdande meddelande för att meddela dig vad ändringarna är.
Våra webbplatser och applikationer kan innehålla länkar till tredje parts webbplatser, plug-ins eller mobilapplikationer som vi inte äger eller kontrollerar. Genom att klicka på dessa länkar eller aktivera dessa anslutningar kan tredje part samla in eller dela data om dig. Vårt integritetsmeddelande täcker inte dem. Läs sekretessmeddelandena på dessa webbplatser och mobilapplikationer om du vill ta reda på hur de samlar in, använder och delar dina personuppgifter.
This privacy notice is intended for:
1. Users of Adoreal’s services;
2. Visitors to Adoreal’s websites;
3. Users of Adoreal’s systems and applications;
4. Members of the general public who are interested in contacting us or who may be contacted by Adoreal; and
5. Any individual who has received this notice.
Adoreal understands that privacy is important to you. We are committed to treating your personal data with care and integrity.
Our privacy notice tells you what personal data we collect and how we collect it, including any data you may provide through this website when you visit the site or inquire about a product or service or take part in an event. It explains what we use your personal data for and how we protect your personal data and keep it safe. It also informs you how long we keep your data, who we share your data with or how we otherwise process it. This privacy notice explains our general practices. However, where local laws or regulations require that we process information differently, or refrain from such processing, we will always comply with the applicable local law. This website is not intended for children, however we may collect data relating to children subject to their parent’s or guardian’s consent.
Adoreal values your privacy. Adoreal is made up of different legal companies related to us by common control or ownership (the “Adoreal Group”). This privacy notice is issued on behalf of the Adoreal Group so when we mention “Adoreal”, “we”, “us” or “our”, this is who we are referring to. Adoreal Limited (incorporated in the Republic of Ireland under number 72345090 D, whose registered office is at South Circular Road,Dublin 8, Ireland) is the controller and responsible for this website.
The terms “you”, “your” or “user” refer to you as the person interacting with Adoreal via this website or in any other capacity including as a professional adviser, employee or contractor, investor, vendor or any other entity interacting with us on behalf of another person.
It is important that you read this privacy notice together with any other privacy notice or fair processing notice we may provide to you on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This privacy notice supplements other notices and privacy policies and is not intended to override them.
We have appointed a data protection officer (DPO) who is responsible for overseeing questions in relation to this privacy notice. If you have any questions about this privacy notice, including any requests to exercise your legal rights, please contact the DPO using the details set out below.
DPO Centre Limited
50 Liverpool Street,
London EC2M 7PY, UK
Contact email: [email protected]
Telephone number: +44 (0) 203 797 1289
If you have any other enquiries please contact us on [email protected].
You have the right to make a complaint at any time to the data protection regulator in the country where you usually live or work, or where the alleged data protection infringement has taken place. We would, however, appreciate the chance to deal with your concerns before you approach the applicable data protection regulator so please contact us in the first instance.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us by contacting us on [email protected].
Personal data means any information or piece of information which could identify you either directly (e.g. your name) or indirectly (e.g. a unique ID number).
Who is the controller of your personal data?
Contact information and your privacy point of contact
What personal data do we collect about you?
How do we collect your personal data?
How do we use your personal data?
Why are we allowed to collect and use your personal data?
How do we protect your personal data?
What are your rights regarding your personal data?
With whom do we share your personal data?
In what instances do we transfer your personal data outside of your home country?
Additional information if you are in the European Economic Area (EEA)
Information about children
Marketing
Withdrawal of Consent/ Opting out of Marketing
Change of Purpose
How we update this Privacy Notice?
Our responsibility regarding websites that we do not own or control
Adoreal is the controller of personal data provided by you in relation to the set up and registration for an Adoreal account (“Operational Data”)
You are the controller of any data, such as communication messages, files, images or other contentthat you add to your Adoreal account or that is added by a third party to your account or that we otherwise process in accordance with your or the third party’s instructions (“Customer Data”). Adoreal is a data processor in regard to Customer Data.
If you want to exercise your rights, have any questions about this privacy notice, need more information or would like to raise a concern or make a complaint, you can do so by contacting [email protected].
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). The personal data we collect, and process may include:
Identity data – your name, surname (including prefix or title), alias, gender, age or date of birth, social security number, as well as your preferred language. Similar information about children may also be collected in very limited circumstances, see ‘Information about children’ for more information;
Contact data – information that enables us to contact you, e.g. your personal or business email, mailing address, telephone and mobile numbers and profile on a social media platform;
Booking Data – information provided for the booking of an appointment with a chosen clinic e.g. name, surname, date/time, health/ medical data;
Special Categories of personal data- information about your health, medical treatment, equality and diversity, ethnicity;
Background Check Data – information to verify the accuracy of an individual’s personal and professional history including criminal convictions and records, credit history, education;
Recruitment Data - information gathered during the hiring process including, demographic information, education and employment history, cv’s, interview notes, gender;
Employee Data - information collected for employment purposes including name, surname, gender, date of birth, contact details, dependents and next of kin information, marital status, emergency contact information, financial information, professional memberships and licenses, appraisals and disciplinary details;
Technical data and Network Activity Information – information about your device and your usage of our websites, apps and systems, including your IP address, device ID, hardware model and version, mobile network information, operating system, platform and other online identifiers, type of browser, browser plug-in types and versions, browsing history, search history, access time, pages viewed, URLs clicked on, forms submitted, time zone setting/physical location and other technology on the devices that you use to access our website;
Financial Information – your credit card, paypal account or bank details, including account name, account number and sort code if payments are made by you to Adoreal;
Usage Data – data related to your use of our services offered (including feedback), your purchase history and preferences, your interactions with us, your preferred method of communications with us, and services you may use relating to your selection of aesthetic/cosmetic/plastic surgery practitioners and institutions/clinics, your use of the 3D enhanced imaging and simulation creator including details of healthcare professional and clinic selected, surgery type information, cost ;
Health Information – your health status, current and historical health conditions and health information inferred from information that you have provided to us, including an aesthetic assessment where you would be asked questions related to any previous procedures/treatment that you have had, and your potential maximum expenditure, any medication that you are prescribed.
Feedback and Opinion Data - we will collect feedback from you regarding your feelings towards your consultation, treatment and post-surgical experience so that we can maintain and improve our service and reduce barriers in communication between you and your healthcare provider;
Marketing and Communications Data - includes your preferences for receiving marketing materials from us and your communication preferences such as via email; and
Audio Visual Data – photos, videos and voice recordings of you, if you choose to submit those to us. These may include any 3D enhanced images or simulations that you may create using the Crisalix 3D image creator provided to you within your Adoreal account. The 3D enhanced images or simulations are created using ARKit, TrueDepth API, Camera APIs, Photo APIs, or other software for depth of facial mapping information.
Audiovisual Recording Data – audiovisual recordings of meetings held on Teams, Zoom, Google Meet that we may hold with you, including collection of information from Microsoft Outlook Calendar or Google Calendar about the meeting held. The recordings of the meetings are created using an AI tool called Fathom, which is also used to transcribe and take notes of matters discussed at the meeting we may have with you. The transcript is shared with you.
We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. ‘Aggregated Data’ could be derived from your personal data but is not considered personal data as this data will not directly or indirectly reveal your identity or contain any of your persona data. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy notice.
You can choose not to give us personal data when we ask for it. If you decide not to give us your personal data, it may restrict our relationship with you. For example, we may not be able to provide you with the services that you have requested.
When you visit our websites or use our services, we collect your personal data.
Directly from you when you:
Visit or use some parts of our websites and/or services we might ask you to provide personal data to us. We also collect some information about you automatically when you visit our websites or use our services, like your IP address, device type, and browser details.
Use your Adoreal account that a clinic created for you as one of their patients, or you use your own Adoreal account to update your personal details, photos and images, use it to communicate with the clinic or healthcare professional about your treatment, provide feedback or take part in surveys, use the 3D enhanced imaging or simulation to create images, or make any bookings and payments through the account, when you contact us with any queries, complaints or for IT support;
Register with us to use Adoreal’s authentication services (currently OTP via mobile phone and email);
Create an account and profile on one of our websites, or apps - as you interact with our website, we will automatically also collect Technical Data about your equipment, browsing actions and patterns subject to us obtaining your consent where this is required, for example for marketing or tracking cookies. We collect this personal data by using cookies, server logs and other similar technologies. We may also receive Technical Data about you if you visit other websites employing our cookies. Please also see our Cookie Notice for additional information.
We may also receive personal data including Technical Data about you if you visit our websites, apps and systems to inquire about our services:
• Book an appointment for example by using our booking widget, or through your Adoreal account;
• Share or use your social media profile to contact Adoreal;
• Sign up with Adoreal to receive promotional marketing materials and direct marketing communications;
• Get in touch for support or to provide feedback to Adoreal;
• Attend any online events that Adoreal may organise, such as a webcast;
• Respond to any self-assessment surveys that you choose to participate in; and
• Share any adverse events or medical information enquiries in your Adoreal account.
From other sources:
The majority of information that we collect, we collect directly from you. However, sometimes we may collect personal data about you from other sources, such as publicly available materials or trusted third parties like the healthcare clinics that use our product, and from marketing and research partners. We use this information to supplement the personal data we already hold about you, in order to better inform, personalise and improve our services. Where a clinic creates an Adoreal account for you as a patient – therefore the clinic that you have contacted for treatment provides personal data about you to Adoreal to create your Adoreal account;
When you talk about us online, for example when you mention an Adoreal product in a Tweet or on other social media, we may collect your personal data from the third-party, such as social media handles and other personal data you make available. If you connect your social media account to our websites, or apps, certain personal data from your social media account will be shared with us. This may include, amongst other personal data, your name, email address, photos, list of social media contacts, and any other accessible information;
We use your personal data for the purposes we have described below in this privacy notice, or for purposes which are reasonably compatible to the ones described.
“Consent” means that the individual has given clear permission for their personal data to be processed for a specific purpose. Consent must be freely given, specific, informed and unambiguous indication. Of the individual's wishes by which he or she. By clear affirmative action. Shows agreement to the processing of personal data relating to him or her.
“Legitimate interest” means the interest of our business in conducting and managing our business to enable us to give you the best service/product and the best and most secure experience. We make sure we consider and balance any potential impact on you and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us.
“Performance of a contract” means processing your data where it is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract.
“Comply with a legal obligation” means processing your personal data where it is necessary for compliance with a legal obligation that we are subject to.
“Vital Interest” means processing your personal data in a life or death circumstance. Where the processing is vital to the individual’s survival and where they need emergency medical care and are incapable of giving consent.
We have set out below, in a table format, a description of the ways we may use your personal data, for what purposes, and the applicable legal bases we rely on to do so.
We have also identified what our legitimate interests are where appropriate. Note that we may process your personal data on more than one lawful basis depending on the specific purpose for which we are processing your data.
Generally, we do not rely on consent as a legal basis for processing your personal data except as set out above, where we are obliged to obtain your consent prior to undertaking any specific activities where we must seek your consent, including our use of an AI tool for audiovisual recordings and transcripts, your use of the 3D imaging service, marketing activities and carrying out of any background checks where we will seek to obtain your explicit consent prior to processing of your data.
Where you have provided your consent to receive direct marketing communications from Adoreal via email, we draw your attention to the fact that Adoreal may continue to send appropriate specific marketing communications to you even in the event that you are no longer a consumer or hold an account with Adoreal provided that you have not withdrawn your consent to receive such marketing communications or you have previously purchased an Adoreal product, which marketing communication may be provided to you pursuant to the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)(as may be updated from time to time).
You have the right to withdraw consent to these marketing activities at any time by contacting us at [email protected].
The security of your data is important to us. We implement technical and organisational measures designed to ensure a level of security for the personal data which is appropriate to the risks to you, our consumers and customers that may result from the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to the personal data.
Adoreal carefully choose the third-party service providers we work with and carry out necessary due diligence to ensure that they have appropriate security, technical and organisational measures and technologies in place to protect your personal data. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and are subject to a duty of confidentiality. We have robust procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so. All data is encrypted in transit and at rest.
A disciplinary policy is enforced to prevent unauthorized access.
However, there are no guarantees that a data transmission or storage system is 100% secure. If you have reason to believe that your interaction with us is no longer secure, please immediately notify us using the details at the ‘Contact information and your privacy point of contact’ section above.
You have rights relating to your personal data. Depending on the applicable data privacy law, you may have the right to direct Adoreal to take certain actions related to your personal data. You may have the right to request confirmation as to whether Adoreal is processing your personal data. Depending on this you may have the right to:
1. Withdraw your consent for processing of your personal data at any time for direct marketing purposes or where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.,
2. Request information relating to the categories of personal data involved, purposes of processing, recipients of your data, retention periods/criteria, and your rights as a Data Subject.
3. Ask Adoreal to access any of your personal data that Adoreal is processing and to be provided with copies of your personal data.
4. Ask Adoreal to correct information you think is inaccurate or incomplete, although we may need to verify the accuracy of the new data you provide to us.
5. Ask Adoreal to delete your personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note however, that we may not always be able to comply with your request of erasure due to specific legal exceptions which will be notified to you, if applicable, at the time of your request.
6. Ask Adoreal to restrict the processing of your information. This enables you to ask us to suspend the processing of your personal data in the following scenarios:
a. If you want us to establish the data's accuracy;
b. Where our use of the data is unlawful, but you do not want us to erase it;
c. Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or
d. You have objected to our use of your data, but we need to verify whether we have overriding legitimate grounds to use it.
7. Object to Adoreal processing of your personal data where we are relying on legitimate interest as the lawful basis for processing. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes, that includes profiling that is related to direct marketing and upon receipt of this objection Adoreal will stop processing your personal data for this purpose.
8. Ask that Adoreal transfer your personal data that you have given to us to another organisation, or to give it to you. We will provide the personal data to you, or a third party you have chosen, in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you; and
9. Right to complain to your local Data Protection Authority or Supervisory Authority.
To exercise any of these rights described above, please email [email protected] with a description of your request.
For your protection, and to protect the privacy of others, we may need to verify your identity before completing what you have asked us to do and to ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that Personal Data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.
We will respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
Where we have relied upon your consent to use your personal data, and you later withdraw that consent, we may not be able to complete some of the activities described in ‘How do we use your personal data’.
In some jurisdictions, we are legally required to keep your personal data for certain periods. How long depends on the specific applicable laws within a specific jurisdiction.
We will retain your personal data only for as long as is necessary for the purposes set out in this Privacy Policy in line with our Retention Policy and Schedule. To determine the appropriate retention period for personal data, we consider various criteria including the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements. Where it is necessary to retain personal data to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies or otherwise establish, defend or exercise legal claims, then we will do so.
Once specific retention timelines have passed and we have no further specific reason to retain that personal data, the relevant personal data will be erased or adapted so that it no longer is personal data.
In some circumstances, you can ask us to delete your data. See ‘What are your rights regarding your personal data?’ section above for information on your data protection rights. You also have the right to object to our processing of personal data for direct marketing purposes (though where you do so, we will retain sufficient information to make sure we don’t send you direct marketing messages in the future).
There will be times when we need to share your personal data with third parties. We may share your personal data within the Adoreal Group of companies and any third-party service providers that we may use to provide supporting services to us. We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions. We ensure that we have contractual agreements in place with our third-party service providers.
We may disclose your personal data to:
a. Other Adoreal Group companies;
b. Third party service providers providing support services such as technology suppliers and system administration services providers assist with the development and improvement of our websites, digital forums and apps etc such as Amazon Web Services, Microsoft, Google, Slack, Figma, GoDaddy, JetBrains, GitHub, Chameleon, Vumetric, DataDog Miro, Webflow, Lokalise, Tramco Cloud, Crisalix and Hypersonix, Fathom AI, Facebook, LinkedIn.
c. Marketing agencies working with us to market or promote our product and services to you where you have consented to receive marketing communications and materials from us;
d. Media services providers;
e. Any entity making enquiries in connection with an actual or proposed purchase, merger or acquisition of any part of our business or brands. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy notice;
f. Suppliers of healthcare professionals/institutions/clinics that are managing adverse event reports;
g. Local or foreign regulators, courts, government agencies, tax authorities and law enforcement authorities and other third parties where we think it’s necessary to comply with applicable laws or regulations, or to exercise, establish or defend our legal rights and where we have an obligation to report certain processing activities. Where possible and appropriate, we will notify you of this type of disclosure; and
h. Professional advisors, such as insurers, bankers, auditors, accountants and lawyers;
i. Other entities or individuals where we have your consent to share your personal data.
Adoreal adheres to all relevant Data Privacy Regulations in the jurisdictions in which we operate. We are a global company and therefore when we share your personal data, it may be transferred to, and processed in, countries other than the country you live in, for example to the United States or Costa Rica. These countries may have laws different to the one you are resident in. Where we disclose personal data to a third-party in another country, we put safeguards in place to ensure your personal data remains secure and protected.
We implement appropriate measures to protect your personal data when we transfer your personal data outside of your home country such as execution of data transfer agreements with service providers that incorporate the EU Standard Contractual Clauses or UK Addendum ot the EU Standard Contractual Clauses.
Law enforcement agencies, regulatory agencies, security authorities or courts in the countries we transfer your personal data to may have the right to see your personal data. If applicable law does not allow transfer of specific personal data outside a country, we will comply with that applicable law.
If you have any questions about where and how your personal data may be transferred, please contact us on [email protected].
For individuals in the European Economic Area (EEA), or in the United Kingdom (UK) this means that your data may be transferred outside of the EEA/UK, for example to the United States. The European Commission recognises that some countries outside the EEA/ European Union or United Kingdom have similar data protection standards. If we transfer your personal data to a country outside the EEA / European Union or United Kingdom (UK) that does not have similar data protection standards, or to a third party we will ensure that we have an approved transfer mechanisms in place to protect your personal data, for example we do so based on EU Standard Contract Clauses adopted by the European Commission or the UK Addendum to the European Standard Contractual Clauses, to ensure the respective recipient protects your Personal Data adequately. These enable us to make international transfers of personal data within our group of companies and meet the data protection laws of the European Union and the General Data Protection Regulation (GDPR). We will also comply with other requirements, such as completing appropriate transfer risk assessments as required.
Whilst our services are not directed at children, occasionally we may receive a child’s data, for example, if you, as the child’s parent or legal guardian provide that personal data to us because you are looking for a treatment for them that involves aesthetic/cosmetic/plastic surgery. We will only ever collect children’s personal data with the parent’s or legal guardian’s consent. Please see ‘What personal data we collect about you’ for more information.
You will only receive marketing communications from us or any other company in the Adoreal Group if you have either provided consent to receive marketing communication or you are one of clients that has purchased our product and has not opted out of receiving such marketing communications.
We may use the data you share with us to make decisions about your interests and preferences so we can make the marketing materials we send you more relevant. We may also combine the information we hold about you with data about your interests or demographics that we have obtained from third parties, to make your experience more personalised and further tailor our marketing materials. You have certain rights in relation to this – please see 'What are your rights regarding your personal data?' above for further information.
Sometimes we may also use information about you to build lookalike models. This allows us to generate similar audiences of prospective customers (who may have similar interests or demographics to you) through advertising platforms like Facebook or Google, based on data that the advertising platform holds about other people. Usually this means sharing your email address with our advertising partners. If you wish to opt out of similar audiences and you do not want us to use your personal data in this way please contact us on [email protected].
We use Facebook custom audience tools. This allows us to provide personalised advertising to you when you use Facebook’s platforms by matching the email address we hold for you with the email address Facebook holds for you, to show you the most relevant Adoreal advertisements. We only do this where you have given us your consent.
We use remarketing services offered by our advertising partners, such as, Google and Facebook to personalise advertisements for visitors to sites of their advertising networks (i.e. websites other than Adoreal’s). On these pages, you may be shown advertisements that refer to your interactions with Adoreal.
Many companies that display interest-based advertising are members of the Network Advertising Initiative ("NAI"), the Digital Advertising Alliance ("DAA") or the European Interactive Digital Advertising Alliance (“EDAA”). To opt-out of interest-based advertising by members of these initiatives, you can visit their websites athttps://optout.networkadvertising.org, https://optout.aboutads.info andhttps://www.youronlinechoices.com.
You can withdraw your consent to receive marketing communication or opt-out of receiving any marketing communication from us at any time, by either following the opt-out links in any marketing communication sent to you or by contacting us at any time at [email protected].
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another purpose and that purpose is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
From time to time, we will update this Privacy Notice. Any changes become effective when we post the revised Privacy Notice on the Adoreal website. This Privacy Notice was last updated as of the “Last Updated” date shown at the top of the Privacy Notice. If updating changes are significant, we will provide a more prominent notice to let you know what the changes are.
Our websites and applications may contain links to third party websites, plug-ins or mobile applications we do not own or control. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. Our Privacy Notice does not cover them. Please read the privacy notices on those websites and mobile applications if you would like to find out how they collect, use and share your personal data.
Welcome to the Adoreal Privacy Notice.
Introduction
This privacy notice is intended for:
Adoreal understands that privacy is important to you. We are committed to treating your personal data with care and integrity.
Our privacy notice tells you what personal data we collect and how we collect it, including any data you may provide through this website when you visit the site or inquire about a product or service or take part in an event. It explains what we use your personal data for and how we protect your personal data and keep it safe. This privacy notice explains our general practices. However, where local laws or regulations require that we process information differently, or refrain from such processing, we will always comply with the applicable local law. This website is not intended for children and we do not knowingly collect data relating to children.
Adoreal values your privacy. Adoreal is made up of different legal companies related to us by common control or ownership (the “Adoreal Group”). This privacy notice is issued on behalf of the Adoreal Group so when we mention “Adoreal”, “we”, “us” or “our”, this is who we are referring to. Adoreal Limited (incorporated in the Republic of Ireland under number 72345090 D, whose registered office is at South Circular Road,Dublin 8, Ireland) is the controller and responsible for this website.
It is important that you read this privacy notice together with any other privacy notice or fair processing notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This privacy notice supplements other notices and privacy policies and is not intended to override them.
We have appointed a data protection officer (DPO) who is responsible for overseeing questions in relation to this privacy notice. If you have any questions about this privacy notice, including any requests to exercise your legal rights, please contact the DPO using the details set out below.
Contact details ([email protected])
If you have any questions about this privacy notice or our privacy practices, please contact our DPO in the following ways:
Full name of legal entity: Adoreal Limited
Email address: [email protected]
You have the right to make a complaint at any time to the data protection regulator in the country where you usually live or work, or where the alleged data protection infringement has taken place. We would, however, appreciate the chance to deal with your concerns before you approach the applicable data protection regulator so please contact us in the first instance.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
Personal data means any information or piece of information which could identify you either directly (e.g. your name) or indirectly (e.g. a unique ID number).
In this privacy notice, we explain:
Adoreal Limited (incorporated in theRepublic of Ireland under number 72345090 D, whose registered office is at South Circular Road, Dublin 8, Ireland) (“Adoreal”) together with the local Adoreal company which has a relationship with you, are the controllers of your personal data.
If you want to exercise your rights, have any questions about this privacy notice, need more information or would like to raise a concern, each local privacy point of contact’s details can be found by contacting [email protected].
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). The personal data we collect, and process, may include:
We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy notice.
You can choose not to give us personal data when we ask you for it. If you decide not to give us your personal data, it may restrict our relationship with you. For example, we may not be able to provide you with the services that you have requested.
Directly from you when you:
From other sources:
When the law allows us to, we use your personal data for the purposes we have described below in this privacy notice, or for purposes which are reasonably compatible to the ones described:
Generally, we do not rely on consent as a legal basis for processing your personal data although we will get your consent before:
(1) anonymising your personal data with a view to performing analytics on anonymised/aggregated data from which you will not be identifiable; and
(2) sending you direct marketing communications to you via email. Please note that Adoreal’s contact with patients is governed by Adoreal’s terms and conditions with the patient. Even after any termination of a contract between Adoreal and a healthcare professional/institution/clinic, Adoreal may retain patient contact details. Adoreal may continue appropriate specific marketing activities towards such patients in respect of that patient’s previous contact with Adoreal, pursuant to the Privacy and Electronic Communications (EC Directive) Regulations 2003 (as may be updated from time to time).
You have the right to withdraw consent to these activities at any time by contacting us at [email protected]
“Legitimate interest” means the interest of our business in conducting and managing our business to enable us to give you the best service/product and the best and most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent orare otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us.
“Performance of a contract” means processing your data where it is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract.
“Comply with a legal obligation” means processing your personal data where it is necessary for compliance with a legal obligation that we are subject to.
To achieve other purposes.
We will use your personal data:
We have set out below, in a table format, a description of all the ways we plan to use your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate. Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal ground we are relying on to process your personal data where more than one ground has been set out in the table below.
We can collect and use your personal data when one of the following applies:
We want to make sure your personal data is not shared with or used by those not allowed to see it. We use a variety of security measures and technologies to help protect your personal data.
We carefully choose service providers to work with, and check they have security measures and technologies in place to protect your personal data. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality. We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
However, there are no guarantees that adata transmission or storage system is 100% secure. If you have reason to believe that your interaction with us is no longer secure, please immediately notify us using the details at the ‘Contact information and your privacy point of contact’ section.
You have rights we need to make you aware of. The rights available to you depend on our reason for processing your personal data and the local law in your jurisdiction, and there are exceptions to some rights. Depending on this you may have the right to:
1. Withdraw your consent to us processing your personal data at any time for direct marketing purposes or where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you with draw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent, please contact [email protected] for further details. This withdrawal request will need to be handled by the Adoreal data protection officer, to assess what personal data (if any) can be deleted, and if so, for what specific use. Please note that personal data that forms apart of medical records cannot be deleted as a matter of public policy;
2. Ask Adoreal about the processing of your personal data including to be provided with copies of your personal data (through a "data subject access request").;
3. Ask us to correct information you think is inaccurate or incomplete, although we may need to verify the accuracy of the new data you provide to us;
4. Ask us to delete your personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request;
5. Ask us to restrict the processing of your information. This enables you to ask us to suspend the processing of your personal data in the following scenarios:
a. If you want us to establish the data's accuracy;
b. Where our use of the data is unlawful but you do not want us to erase it;
c. Where you need us to hold the data even if we no longer require it as you need it to
d. establish, exercise or defend legal claims; or
e. You have objected to our use of your data, but we need to verify whether we have overriding legitimate grounds to use it.
6. Object to our processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms;
7. Ask that we transfer information you have given us from one organisation to another, or to give it to you. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you; and8. Complain to your local data protection authority.
You can find out how to get in touch with us to ask us to do any of the above by looking at the ‘Contact information and your privacy point of contact’ section.
For your protection, and to protect the privacy of others, we may need to verify your identity before completing what you have asked us to do and to ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that Personal Data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.
We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
Where we have relied upon your permission to use your personal data, and you later withdraw that permission, we may not be able to complete some of the activities described in ‘How do we use your personal data’.
In some jurisdictions, we are legally required to keep your personal data for certain periods. How long depends on the specific legal requirements of the jurisdiction you are in when you share your information with us.
We will always keep your personal data for the period required by law and where we need to do so in connection with legal action or an investigation involving Adoreal. Otherwise, we will keep your personal data for as long as we have a relationship with you, in order to respond or process a question or request from you. Adoreal’s contact with patients is governed by Adoreal’s terms and conditions with the patient. Even after any termination of a contract between Adoreal and a healthcare professional/institution/clinic, Adoreal may retain patient contact details and Adoreal may continue appropriate specific marketing activities towards such patients in respect of that patient’s previous contact with Adoreal, pursuant to the Privacy and Electronic Communications (EC Directive) Regulations 2003 (as may be updated from time to time); and
We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
Insofar as the processing of personal data is based on your consent, we will delete this data if you withdraw your consent, subject to the technical ability to do so and so far as such a deletion would not require disproportionate effort on our part. This deletion request will need to be handled by the Adoreal data protection officer, to assess what personal data (if any) can be deleted, and if so, for what specific use. Please note that personal data that forms a part of medical records cannot be deleted as a matter of public policy.
To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data, and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting, or other requirements.
We share your personal data on a need to know basis, and to the extent necessary to follow laws and regulations, and in the context of managing our relationship with you.
We share your personal data only with teams in our Adoreal companies and affiliates who need to see it to do their jobs. We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
We will also share your personal data with other entities, for example:
We work all over the world. Therefore, where your applicable law allows it, we may need to transfer and use your personal data outside of the country where we collect it from you. We implement appropriate measures to protect your personal data when we transfer your personal data outside of your home country such as data transfer agreements that incorporate standard data protection clauses. The data privacy laws in the countries we transfer it to may not be the same as the laws in your home country. Law enforcement agencies, regulatory agencies, security authorities or courts in the countries we transfer your personal data to may have the right to see your personal data. If applicable law does not allow transfer of specific personal data outside a country, we will comply with that applicable law.
The European Commission recognises that some countries outside the EEA have similar data protection standards. If we transfer your personal data to a country outside the EEA that does not have similar data protection standards, we do so based on standard contract clauses adopted by the European Commission, to ensure the respective recipient protects your Personal Data adequately in accordance with this privacy notice. These enable us to make international transfers of personal data within our group of companies and meet the data protection laws of theEuropean Union and the General Data Protection Regulation (GDPR).
Whilst our services are not ordinarily directed to children, occasionally we may receive your child’s data, for example, if you provide that personal data to us because you are looking for a treatment for them that involves aesthetic/cosmetic/plastic surgery. We will only ever receive this with your consent. Please see ‘What personal data we collect about you’ for more information.
Our websites may use cookies and similar technologies. You can choose to accept or decline cookies. If you choose to decline cookies, not all elements of our websites, apps and services may function as intended, so your experience may be affected.
To the extent that your local laws consider the information collected by cookies and other technologies as personal data, we will treat that information to the standards set out in this privacy notice.
We strive to provide you with choices regarding certain personal data uses, particularly around marketing communications from us and/or the relevant company in the Adoreal Group. You will receive marketing communications from us or the relevant company in the Adoreal Group if you have requested information from us or the relevant company in the Adoreal Group and you have not opted out of receiving that marketing.
We collect information about your computer browser type and operating system, websites you visited before and after visiting our websites, standard server log information, Internet Protocol (IP) addresses, location data, mobile phone service provider, and mobile phone operating system. We use this information to understand how our visitors use our websites and mobile applications so that we can improve them, the services we offer, and our advertising. We may also share this information with other companies within the Adoreal group and with other third parties. Some of our websites use Google Analytics, a web analytics service provided by Google, Inc.(“Google”). Google Analytics uses cookies to analyse use patterns and may collect information about your use of the website, including your IP address.More information on Google Analytics can be found here. If you would like to opt-out of having your data used by Google Analytics, you can opt out here.
We also use remarketing services offered by our advertising partners to personalise advertisements for visitors to sites of their advertising networks (i.e. websites other than Adoreal’s). On these pages, you may be shown advertisements that refer to your interactions with Adoreal previously. To turn off personalisation for advertisements served by Google click here. To turn off personalisation for advertisements served by Facebook click here. Many companies that display interest-based advertising are members of the Network Advertising Initiative ("NAI"), the DigitalAdvertising Alliance ("DAA") or the European Interactive DigitalAdvertising Alliance (“EDAA”). To opt-out of interest-based advertising by members of these initiatives, you can visit their websites athttps://optout.networkadvertising.org, https://optout.aboutads.info andhttps://www.youronlinechoices.com.
We may use the data you share with us to make decisions about your interests and preferences so we can make the marketing materials we send you more relevant. We may also combine the information we hold about you with data about your interests or demographics that third parties have collected from you online and offline, to make your experience more personalised and further tailor our marketing materials. You have certain rights in relation to this – please see 'What are your rights regarding your personal data?' above for further information.
We use Facebook custom audience tools. This allows us to provide personalised advertising to you when you use Facebook’s platforms by matching the email address we hold for you with the email addressFacebook holds for you, to show you the most relevant Adoreal advertisements. We only do this where you have given us consent. Sometimes we may also use information about you to build lookalike models. This allows us to generate similar audiences of prospective customers (who may have similar interests or demographics to you) through advertising platforms like Facebook or Google, based on data that the advertising platform holds about other people. Usually this means sharing your email address with our advertising partners. If you wish to opt out of similar audiences in Google, you can do so here.
Adoreal does not share your personal data with any third party for marketing purposes. In the event, we wish to do so, we will get your express opt-in consent before we share your personal data with any third party for marketing purposes.
You can ask us to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you or by contacting us at any time at [email protected].
You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly. For more information about the cookies we use, please see our Cookie Notice.
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
From time to time, we will update this Privacy Notice. Any changes become effective when we post the revised Privacy Notice on the Adoreal website. This Privacy Notice was last updated as of the“Last Updated” date shown above. If updating changes are significant, we will provide a more prominent notice to let you know what the changes are.
Our websites and applications may contain links to third party websites, plug-ins or mobile applications we do not own or control. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. Our Privacy Notice does not cover them. Please read the privacy notices on those websites and mobile applications if you would like to find out how they collect, use and share your personal data.