Bioepic Ltd ("Bioepic") respects your right to privacy. This Privacy Notice explains who we are, how we collect, share and use personal information about you, and how you can exercise your privacy rights. This Privacy Notice only applies to personal information that we collect through our website at epichealth.io ("our site").
If you have any questions or concerns about our use of your personal information, then please contact us using the contact details provided at the bottom of this Privacy Notice.
We recommend that you read this Privacy Notice in full to ensure you are fully informed. However, if you only want to access a particular section of this Privacy Notice, then you can click on the relevant link below to jump to that section.
- What does Bioepic do?
- What personal information does Bioepic collect and why?
- Who does Bioepic share my personal information with?
- Legal basis for processing personal information
- Cookies and similar tracking technology
- International data transfers
- Data retention
- Your data protection rights
- Updates to this Privacy Notice
- How to contact us
Bioepic is a medical research company, headquartered in the United Kingdom, which aims to use its research program to help millions of people around the world manage conditions such as diabetes, cardiovascular disease and atrial fibrillation more accurately. Bioepic intends to help make managing health easier.
For more information about Bioepic, please see the “About Us” section of our site at epichealth.io/about.
Certain parts of our site may ask you to provide personal information voluntarily: for example, we may ask you to provide your contact details in order to register your interest in being notified about the launch of our mobile app and other website updates, to subscribe to receiving marketing communications from us, and/or to submit enquiries to us. The personal information that you are asked to provide, and the reasons why you are asked to provide it, will be made clear to you at the point we ask you to provide your personal information.
We may disclose your personal information to the following categories of recipients:
- to our third party services providers and partners who provide data processing services to us (for example, to support the delivery of, provide functionality on, or help to enhance the security of our site), or who otherwise process personal information for purposes that are described in this Privacy Notice or notified to you when we collect your personal information;
- to any competent law enforcement body, regulatory, government agency, court or other third party where we believe disclosure is necessary (i) as a matter of applicable law or regulation, (ii) to exercise, establish or defend our legal rights, or (iii) to protect your vital interests or those of any other person;
- to an actual or potential buyer (and its agents and advisers) in connection with any actual or proposed purchase, merger or acquisition of any part of our business, provided that we inform the buyer it must use your personal information only for the purposes disclosed in this Privacy Notice;
- to any other person with your consent to the disclosure.
Our legal basis for collecting and using the personal information described above will depend on the personal information concerned and the specific context in which we collect it.
However, we will normally collect personal information from you only (i) where we need the personal information to perform a contract with you, (ii) where the processing is in our legitimate interests and not overridden by your rights, or (iii) where we have your consent to do so. When you request that Bioepic notifies you of the launch of our App and other website updates we rely on performance of a contract (to notify you of the App) and on your consent to send you marketing communications by email, including our blogs and information on other products. In some cases, we may also have a legal obligation to collect personal information from you.
If we ask you to provide personal information to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your personal information is mandatory or not (as well as of the possible consequences if you do not provide your personal information).
If we collect and use your personal information in reliance on our legitimate interests (or those of any third party), these interest will normally be to operate our site and communicate with you as necessary to provide our services to you and for our legitimate commercial interest, for instance, when responding to your queries or request for information, improving our site, undertaking marketing, or for the purposes of detecting or preventing illegal activities. We may have other legitimate interests and if appropriate we will make clear to you at the relevant time what those legitimate interests are.
If you have questions about or need further information concerning the legal basis on which we collect and use your personal information, please contact us using the contact details provided under the “How to contact us” heading below.
Your personal information may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have data protection laws that are different to the laws of your country.
Specifically, our site servers are located in the EEA, and our group companies and third party service providers and partners operate in the EEA and US. This means that when we collect your personal information we may process it in any of these countries.
However, we have taken appropriate safeguards to ensure that your personal information will remain protected in accordance with this Privacy Notice. These include implementing the European Commission’s Standard Contractual Clauses and engaging Privacy Shield certified service providers.
Further information about safeguards in place can be provided on request.
Generally we retain the personal information we collect from you when you register your interest in the App for 12 months. If we use your data for marketing purposes, your data will be retained for three years from the date of your last interaction with us or our product. In addition, where we have any other ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, tax or accounting requirements) this period may also be longer. However, where we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, tax or accounting requirements) this period may be longer.
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymise it or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
You have the following data protection rights:
- If you wish to access, correct, update or request deletion of your personal information, you can do so at any time by contacting us using the contact details provided under the “How to contact us” heading below.
- In addition, you can object to processing of your personal information, ask us to restrict processing of your personal information or request portability of your personal information. Again, you can exercise these rights by contacting us using the contact details provided under the “How to contact us” heading below.
- You have the right to opt-out of marketing communications we send you at any time. You can exercise this right by clicking on the "unsubscribe" or "opt-out" link in the marketing e-mails we send you. To opt-out of other forms of marketing (such as postal marketing or telemarketing), then please contact us using the contact details provided under the “How to contact us” heading below.
- Similarly, if we have collected and process your personal information with your consent, then you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal information conducted in reliance on lawful processing grounds other than consent.
You have the right to complain to a data protection authority about our collection and use of your personal information. For more information, please contact your local data protection authority.
We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws.
We use appropriate technical and organisational measures to protect the personal information that we collect and process about you. The measures we use are designed to provide a level of security appropriate to the risk of processing your personal information. Specific measures we use include, but are not limited to; encryption of data at rest and in transit for all personal data, role based access management to control access to such data, periodic review of information security procedures and processes, logging and auditing of activity across systems storing such data. If you have any questions, please contact us using the contact details provided under the “How to contact us” heading below.
We may update this Privacy Notice from time to time in response to changing legal, technical or business developments. When we update our Privacy Notice we will take appropriate measures to inform you, consistent with the significance of the changes we make. We will obtain your consent to any material Privacy Notice changes if and where this is required by applicable data protection laws.
You can see when this Privacy Notice was last updated by checking the “last updated” date displayed at the top of this Privacy Notice.
If you have any questions or concerns about our use of your personal information, please contact us using the following details: [email protected].
The data controller of your personal information is Bioepic Ltd, which is registered with the ICO (UK) with registration number ZA138081.