FUNDACIÓ PRIVADA INSTITUT DE RECERCA DE LA SIDA-CAIXA,(hereinafter, IrsiCaixa), with Spanish tax identification number G60813227 and a registered address at Hospital Germans Trias i Pujol, Ctra del Canyet, s/n, 08916 Badalona (Barcelona, Spain), is aware of the importance of protecting your privacy, and, via this Privacy Policy, informs you in a transparent way regarding how any personal data we collect from you will be used.
1. Principles governing the processing of your personal data
Your personal data will be processed by IrsiCaixa according to the following principles:
2. Transparency
In addition to this privacy policy, website sections and forms contain specific information about the processing of personal data collected through those channels.
2.1. Description of the information provided
The information that you will find in each website form, supplemented by the “Additional Information” provided in this Privacy Policy, is as follows:
Data controller
This identifies the company that is responsible for your personal data, in this case, Fundació Privada Institut de Recerca de la Sida-Caixa.
Purpose
You will be informed of the purpose or purposes for which your personal data will be processed.
Legal basis
You will be informed of the legal basis for processing your personal data, both in cases in which your consent is required and for other legal bases recognized by the current legislation.
Other parties with access to your data
You will be informed of the identity or categories of parties that may have access to your personal data.
Storage duration and criteria
You will be informed of the duration of and criteria used for storage of your personal data for the indicated purpose.
Automated decision-making and profiling tools
We may use segmentation tools in order to be able to offer commercial communications adapted to differing interests. You will be informed about these tools in any website forms through which you submit personal data.
Ways of giving consent
If your consent is necessary for the processing of your personal data, you will be informed regarding how to grant your consent.
Consequences of withholding consent
If you do not grant your consent, we may not be able to provide the requested service.
Third-country processing
In the event that your data has to be processed in a country outside the European Union, you will be informed of the existence or not of a decision to adapt to the European Commission and/or the guarantees provided regarding the protection of your personal data.
Exercising your rights
See section 3.
Data Protection Officer (DPO) contact details
See section 4.
2.2. Specific information on the processing of personal data provided in website sections
a) “CONTACT” section
ADDITIONAL DATA PROTECTION INFORMATION
Data controller
The entity responsible for your personal data is Fundació Privada Institut de Recerca de la Sida-Caixa, with Spanish tax identification number G60813227 and a registered address at Hospital Germans Trias i Pujol, Ctra del Canyet, s/n, 08916 Badalona (Barcelona, Spain).
Purpose
The purpose of processing the personal data provided through this form is to respond to your query regarding the products, services and other activities of IrsiCaixa. If you decide not to agree to the processing of your personal data, we will not be able to perform the requested service.
Since ongoing improvement of internal response processes is a legitimate interest, we may also use your personal data, suitably anonymized, to monitor statistics related to our customer attention service.
Other parties with access to your data
The personal data that you provide through this website will not be communicated to third parties, unless requested by an administrative or judicial authority. However, service providers, including those providing website development and maintenance services, may have access to your personal data. Third countries are contractually obliged to both ensure the confidentiality of your personal data and not to use them for a purpose other than for the service they provide
You may write to the address indicated in this Privacy Policy to request a complete listing of the categories of service providers that have access to your personal data.
Storage duration
Your personal data will be processed until your query is resolved. They may subsequently be retained in anonymized form for statistical purposes and to improve the quality of our services.
Exercising your rights
You may exercise your rights to access, rectification, deletion, opposition, limitation and portability, and also ask about how your personal data are processed, by contacting the Data Protection Officer (DPO) by postal mail or email:
Include a copy of your ID so that we can verify your identity.
Further information on your rights is provided in Sections 3 and 4 of this Privacy Policy.
If you do not agree with how your personal data are processed, you have the rights to lodge a complaint with the Spanish Data Protection Agency (Agència Espanyola de Protecció Dades, AEPD).
b)“NEWSLETTER” section
ADDITIONAL DATA PROTECTION INFORMATION
Data controller
The entity responsible for your personal data is Fundació Privada Institut de Recerca de la Sida-Caixa, with Spanish tax identification number G60813227 and a registered address at Ctra del Canyet, s/n, 08916 Badalona (Barcelona, Spain).
Purpose
The purpose of processing the personal data is to keep you informed of IrsiCaixa activities, promotions and scientific and educational innovations. If you decide not to agree to the processing of your personal data, we will not be able to perform the requested service.
Personalization of communications
We may use segmentation tools for outgoing communications in order to personalize communications and to avoid sending information that may not be of interest to you. To personalize communications, we use and analyse data from different sources, such as the personal data that you have provided (age, sex, etc), historical information on products and services acquired by you from IrsiCaixa and browsing data collected through cookies installed in your browser (see our Information on cookies)
While segmentation itself is computerized, the criteria used are always decided by people.
Other parties with access to your data
The personal data that you provide through this website will not be communicated to third parties, unless requested by an administrative or judicial authority. However, service providers, including those providing website development and maintenance services, may have access to your personal data. Third countries are contractually obliged to both ensure the confidentiality of your personal data and not to use them for a purpose other than for the service they provide.
You may write to the address indicated in this Privacy Policy to request a complete listing of the categories of service providers that have access to your personal data.
Your data will be processed within the European Union. However, to send emails we use the MailChimp web platform (Rocket Science Group, LLC), for which purpose your personal data will be transferred to the United States of America.
Rocket Science Group, LLC subscribes to the Privacy Shield arrangement and so provides guarantees regarding the processing of your personal data. You can verify Rocket Science Group LLC’s Privacy Shield certification, as well as additional information about how your data are processed by MailChimp. at the following link:
https://www.privacyshield.gov/participant?id=a2zt0000000TO6hAAG
Storage duration
Your data will be processed until you unsubsribe. If you unsubscribe, your personal data will be blocked to avoid sending you unwanted communications.
You can easily cancel your subscription at any time by clicking on the link that appears at the bottom of each email you receive.
Exercising your rights
You may exercise your rights to access, rectification, deletion, opposition, limitation and portability, and also ask about how your personal data are processed, by contacting the Data Protection Officer (DPO) by postal mail or email:
Include a copy of your ID so that we can verify your identity.
Further information on your rights is provided in Sections 3 and 4 of this Privacy Policy.
If you do not agree with how your personal data are processed, you have the rights to lodge a complaint with the Spanish Data Protection Agency (Agència Espanyola de Protecció Dades, AEPD).
c) “WORK WITH US” section
ADDITIONAL DATA PROTECTION INFORMATION
Data controller
The entity responsible for your personal data is Fundació Privada Institut de Recerca de la Sida-Caixa, with Spanish tax identification number G60813227 and a registered address at Hospital Germans Trias i Pujol, Ctra del Canyet, s/n, 08916 Badalona (Barcelona, Spain).
Purpose
The purpose of processing your personal data is to manage your participation in staff recruitment processes. You will need to consent to the processing of your personal data for this purpose, as otherwise we will be unable to include you in IrsiCaixa recruitment processes.
Other parties with access to your data
The personal data that you provide through the website will not be communicated to third parties, unless required by an administrative or judicial authority. However, service providers, including those providing website development and maintenance services, may have access to your personal data. Third countries are contractually obliged to both ensure the confidentiality of your personal data and not to use them for a purpose other than for the service they provide.
Storage duration
Your data will be kept for a year, unless you authorize us to keep them for longer during the recruitment processes in which you participate.
Exercising your rights
You may exercise your rights to access, rectification, deletion, opposition, limitation and portability, and also ask about how your personal data are processed, by contacting the Data Protection Officer (DPO) by postal mail or email:
Further information on your rights is provided in Sections 3 and 4 of this Privacy Policy.
If you do not agree with how your personal data are processed, you have the right to lodge a complaint with the Spanish Data Protection Agency (Agència Espanyola de Protecció Dades, AEPD).
d.) “IAN” section
ADDITIONAL DATA PROTECTION INFORMATION
Data Controller
Fundació Privada Institut de Recerca de la Sida, with tax ID number G-60813227, is responsible for your processed data.
Purposes
Additionally, IrsiCaixa will also process your data for the expressly indicated specific purposes.
Recipients
The personal data you provide through the website form will not be communicated to third parties, except when requested by an administrative or judicial authority. However, we may share your personal data to companies providing specific services on behalf of IrsiCaixa, such as computer service providers or website developers. Said third-party service providers are contractually obliged to maintain your information confidential and to use and process your data only for the provision of the agreed services.
In case you wish to receive information on the categories of said third-party providers, please contact the above-mentioned address.
Your data will be transferred to the United States of America.
Rocket Science Group LLC is certified by the Privacy Shield standard, which guarantees appropriate processing of your personal data.
On the following link you can verify adhesion of the Rocket Science Group LLC to the Privacy Shield:
https://www.privacyshield.gov/participant?id=a2zt0000000TO6hAAG
Further information on the processing of your data by MailChimp can be found at:
https://mailchimp.com/legal/privacy/?_ga=2.216932179.433230548.1573051711418792641.1570049144&_gac=1.253903420.1570187940.EAIaIQobChMIlb_s672C5QIVU_hRCh2iVQo4EAAYASAAEgL3YvD_BwE
Data conservation
Your data will be processed until you unsubscribe from the IAN via email to dpo@irsicaixa.com. The data will be subsequently blocked during the legally established period.
Rights
You may exercise your rights of access, rectification, deletion, opposition, limitation and portability, and address any query you may have about the processing of your personal data by contacting the Data Protection Officer (DPO) through any of the following channels:
Do not forget to include/attach a copy of your ID so we can verify your identity.
Further information on your rights is provided in Sections 3 and 4 of this Policy.
If you are not satisfied with the processing of your personal data, you can contact the Spanish Data Protection Agency.
3. Your rights by law
In accordance with current legislation, you have the following rights in relation to the processing of your personal data.
Rights of access and rectification: You have the right to know how your personal data are used, how they are being processed and, where appropriate, the purpose of the processing, the origins of the data and any communications made or planned regarding your personal data. You also have the right to request that your personal data be modified and updated.
Right to erasure: You have the right to request that your personal data be erased, provided there is no other compelling legitimate grounds for keeping them.
Right to opposition: You have the right to state your opposition to the processing of your personal data at any time, provided there is no other compelling legitimate grounds for processing.
Right to portability: You have the right to be provided with your personal data in a structured, commonly used and mechanically readable format. Your right to portability applies as follows:
Right to data minimization: You have the right to limit the processing of your personal data to their conservation by the data controller and to prohibit them from being processed in any other way or for any other purpose. Your right to data minimization applies as follows:
Right to lodge a complaint with the supervisory authority: : If you do not agree with the processing of your personal data, you may lodge a claim with the Spanish Data Protection Agency (Agència Espanyola de Protecció Dades, AEPD).
IrsiCaixa will respond to any request from you regarding the exercise of your rights as quickly as possible and, bearing in mind the nature of the personal data processing, will comply with the request without undue delay.
4. Data Protection Officer
IrsiCaixa has a designated Data Protection Officer (DPO) registered with the Spanish Data Protection Agency (Agència Espanyola de Protecció Dades, AEPD). You can exercise any or all of your rights (see previous section) and make queries or suggestions by contacting the IrisCaixa DPO as follows:
Include a copy of your ID so that we can verify your identity.
5. Security of your personal data
IrsiCaixa makes every effort to guarantee the security of your personal data and to protect them from unauthorized access by implementing suitable computer security measures that are updated on an ongoing basis to adapt to technological advances.
6. Access to your personal data by third parties
The personal data that you provide through the IrsiCaixa website will not be communicated to third parties, unless requested by an administrative or judicial authority. However, service providers, including those providing website development and maintenance services, may have access to your personal data. Third countries are contractually obliged to both ensure the confidentiality of your personal data and not to use them for a purpose other than for the service they provide. You may, at any time, write to the address indicated in this Privacy Policy to request a complete listing of the categories of service providers that have access to your personal data.
7. Where your personal data are processed
Your personal data will be processed within the European Union. However, the data may be transferred to third countries for the provision of a specific service. If this is the case, you will receive specific information on the service provider, the country or countries where your data will be processed and the guarantees provided regarding the protection of your personal data.