CA | ES | EN

PRIVACY POLICY

PRIVACY POLICY – EXTENDED INFORMATION

 

LAST MODIFICATION: 05/25/2018

 

The Privacy Policy is part of the General Conditions that govern the Website www.idisba.es along with the Cookies Policy and the Legal Notice.

 

FUNDACIÓ INSTITUT D'INVESTIGACIÓ SANITÀRIA ILLES BALEARS (hereinafter IDISBA), reserves the right to modify or adapt this Privacy Policy at any time. Therefore, we recommend that you review it each time you access the Website. In the event that the user has registered on the website and accesses his account or profile, by accessing it, he will be informed in the event that there have been substantial changes in relation to the processing of his personal data

 

Who is responsible for the processing of your data?

 

The data collected or provided voluntarily by means of the Website, either by browsing as well as all those that you can provide us in the contact forms, via email or by phone, will be collected and processed by the Data Controller, whose data is indicated below:

 

Fundació Institut d'Investigació Sanitària Illes Balears (IdISBa).  CIF (Tax Identification Code): G-57326324

Address: Crta. Valldemossa, 79 (Hospital Universitari Son Espases), Edifici S, 1ª planta. 07010 Palma de Mallorca

Phone number: 871 20 52 34

Data Protection Officer: idisba.protecciondatos@ssib.es

Registered company data: 100000000220 (Number of Unique Register of Foundations of the Balearic Islands)

 

If, for any reason, you want to contact us in any matter related to the processing of your personal data or privacy (with our Data Protection Officer), you can do so through any of the means indicated above.

 

What data do we collect through the website?

 

By the simple fact of browsing the Website, IDISBA will collect information regarding:

 

- IP address.

- Browser version.

- Operating system.

- Duration of the visit or navigation through the Website.

 

Such information is stored using Google Analytics, so we refer to Google's Privacy Policy, as Google collects and treats such information. . http://www.google.com/intl/en/policies/privacy/

 

In the same way, the Web Page facilitates the utility of Google Maps, which can have access to your location, assuming that you allow it, in order to facilitate a greater specificity about the distance and/or our paths to our offices. In this regard, we refer to the Privacy Policy used by Google Maps, in order to know the use and treatment of such data http://www.google.com/intl/en/policies/privacy/

 

The information that we handle, will not be related to a specific user and will be stored in our databases, in order to perform statistical analysis, improvements on the Website, on our products and / or services and will help us improve our strategy commercial. The data will not be communicated to third parties.

 

User registration on the website.

 

To access certain products and/or services (such as the contact, the suggestion box or the occupation registration form), the user must register or fill in a form. To this ends, a series of personal data is requested. The necessary and obligatory data to be provided by the user to carry out such registration, are marked with the symbol *. In the case of not facilitating such fields, registration will not be carried out.

 

The generated user and password (intranet use) are personal and non-transferable, with the user being responsible for their custody. We do not recommend that you write it down somewhere or that you notify it to third parties.

 

In this case, the navigation data will be associated with the user's registry, identifying the same user who browses the Website. In this way, you can customize the offer of products and/or services that, in our opinion, best suits the user, as well as recommend certain products and/or services.

 

The registration data of each user will be incorporated into the databases of IDISBA, together with the history of operations carried out, and will be stored in them while the account of the registered user is not deleted. Once such account has been deleted, this information will be removed from our databases, keeping for 10 years those data related to the transactions carried out, without accessing or altering them, in order to comply with the legally valid terms. The data that are not linked to the transactions carried out will be maintained unless you withdraw the consent, in which case they will be eliminated immediately (always taking into account the legal deadlines).

 

The legal basis for the processing of your personal data is the execution of a contract between the parties. In relation to the sending of communications and promotions electronically and the response to requests for information, the legitimation of the treatment is the consent of the affected party.

 

The purposes of the treatment will be the following:

 

a) Manage registration in the user registration area and access to the Website.

b) Manage the purchase of products and/or services made available to you through the Website.

c) Keep you informed of the processing and status of your requests, purchases and/or reservations.

d) Respond to your request for information.

e) Manage all the utilities and/or services offered by the platform to the user.

 

In that way, please be advised that you can receive communications via email and/or on your phone, in order to inform you of possible incidents, errors, problems and/or status of your requests.

 

For the sending of commercial communications, the express consent of the user will be requested when making the registration. In this regard, the user may revoke the consent given, by contacting IDISBA, using the means indicated above. In any case, in each commercial communication, you will be given the possibility to unsubscribe when receiving them, either through a link and/or email address.

 

If you are one of the following groups, consult the information that follows:

 

+ WEB OR EMAIL CONTACTS

 

With what purposes are we going to treat your personal data?

 

  • Answer your questions, applications or requests.
  • Manage the requested service, answer your request or process your application.
  • Information by electronic means, that relate to your application/request.
  • Commercial information or events by electronic means, as long as there is express authorization.

 

What is the legitimacy for the treatment of your data?

 

The acceptance and consent of the interested party: In those cases where it is necessary to fill in a form and click on the submit button in order to complete an application, this completion will necessarily imply that you have been informed and have expressly granted your consent to the content of the clause annexed to that form or acceptance of the privacy policy.

 

All our forms have a checkbox with the following formula, in order to send the information: "□ I have read and accept the Privacy Policy."

 

+ CLIENTS

 

With what purposes are we going to treat your personal data?

 

  • Preparation of the budget and its monitoring by means of communications between both parties.
  • Information by electronic means, that relate to your request.
  • Commercial information or events by electronic means, as long as there is express authorization.
  • Manage the administrative, communications and logistics services performed by the Responsible.
  • Invoicing/billing.
  • Carry out the corresponding transactions.
  • Invoicing/billing and declaration of the appropriate taxes.
  • Control and recovery management.

 

What is the legitimacy for the treatment of your data?

 

The legal basis is your consent.

 

+ SUPPLIERS.

 

With what purposes are we going to treat your personal data?

 

  • Information by electronic means, that relate to your request.
  • Commercial information or events by electronic means, as long as there is express authorization.
  • Manage the administrative, communications and logistics services performed by the Responsible.
  • Invoicing/billing.
  • Carry out the corresponding transactions.
  • Invoicing/billing and declaration of the appropriate taxes.
  • Control and recovery management.

 

What is the legitimacy for the treatment of your data?

 

The legal basis is the acceptance of a contractual relationship, or otherwise your consent to contact us or offer your products by any means.


+ SOCIAL NETWORK CONTACTS

 

With what purposes are we going to treat your personal data?

 

  • Answer your questions, applications or requests.
  • Manage the requested service, answer your request or process your application. .
  • Connect with you and create a community of followers.

 

What is the legitimacy for the treatment of your data?

 

The acceptance of a contractual relationship in the environment of the corresponding social network, and in accordance with its Privacy policies:

 

Facebook       http://www.facebook.com/policy.php?ref=pf

Twitter            http://twitter.com/privacy

LinkedIn         http://www.linkedin.com/legal/privacy-policy?trk=hb_ft_priv  

 

How long are we going to keep personal data?

 

We can only consult or cancel your data in a restricted way by having a specific profile. We will process them as long as you let us: following us, being friends or giving "like", "follow" or similar buttons.

 

Any rectification of your data or restriction of information or postings must be made through the configuration of your profile or user in the social network itself.

 

+ JOBSEEKERS

 

With what purposes are we going to treat your personal data?

 

  • Organization of staff selection processes for recruitment.
  • Make an appointment for job interviews and evaluate your candidacy.
  • If you have given us your consent, we can transfer it to collaborating or related entities, with the sole purpose of helping you find a job.

 

What is the legitimacy for the treatment of your data?

 

The legal basis is your unequivocal consent, when you give us your CV/résumé and receive and sign information regarding the processing we are going to carry out.

 

How long are we going to keep personal data?

 

The curriculum will be stored for a period of one year, after which, in the case of not having contacted you, it will be eliminated.

           

+ HR/TRAINEES

 

With what purposes are we going to treat your personal data?

 

  • Management of the employment relationship and the worker's file.
  • Carry out all the administrative, fiscal and accounting procedures necessary to comply with our contractual commitments, obligations regarding labor regulations, Social Security, occupational risk prevention, taxation and accounting.
  • Payroll management by financial entity.
  • Working hours control through a time & attendance fingerprint/card access management system (if applicable).
  • Management of group insurances /pension schemes of the entity.
  • Perform training activities both subsidized and non-subsidized.

 

What is the legitimacy for the treatment of your data?

 

The legal basis for the processing of your data is the execution of your employment contract. The fulfillment of the pertinent legal obligations. The consent of the interested party.

 

+ COL.LABORATORS

 

With what purposes are we going to treat your personal data?

 

  • Management of the relationship with the entity.
  • Carry out all the administrative, fiscal and accounting procedures necessary to comply with our contractual commitments.

 

What is the legitimacy for the treatment of your data?

 

The legal basis for the processing of your data is the execution of your employment contract. The fulfillment of the pertinent legal obligations. The consent of the interested party.

 

+ PARTICIPANTS

 

With what purposes are we going to treat your personal data?

 

  • Management of participation in the studies and research of the entity.
  • Carry out all the administrative procedures necessary to comply with our commitments.
  • Information by electronic means, that relate to your request.
  • Commercial information or events by electronic means, as long as there is express authorization.

 

What is the legitimacy for the treatment of your data?

 

The legal basis for the processing of your data is the execution of your employment contract. The fulfillment of the pertinent legal obligations. The consent of the interested party.

 

 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 

Do we include personal data of third parties?

 

No, as a general rule we only treat the data provided by the holders. If you provide us with data from third parties, you must first inform and request your consent to those persons, or otherwise you will exempt us from any responsibility for the breach of this requirement.

 

And data of minors?

 

We do not process data for children under 14 years of age, therefore, refrain from providing them if you are not that old.

 

Will we make communications by electronic means?

 

  • They will only be made to manage your request, if it is one of the means of contact you have given us.
  • If we make commercial communications, they will have been previously and expressly authorized by you.

 

 What security measures do we apply?
 

 

You can rest assured: We have adopted an optimal level of protection of the Personal Data that we manage, and we have installed all the means and technical measures at our disposal, according to the technology condition, to avoid loss, misuse, alteration, unauthorized access and theft of Personal Data.

 

To what extent will decision making be automated?

 

IDISBA does not use fully automated decision making processes to engage, develop or terminate a contractual relationship with the user. In case we use these processes in a particular case, we will keep you informed and we will inform you of your rights in this regard if the law prescribes it.

 

Will profiling take place?

 

In order to be able to offer you products and/or services according to your interests and improve your user experience, we can elaborate a "commercial profile" based on the information provided. However, automated decisions will not be made based on that profile.

 

To which recipients will your data be communicated?

 

To the participating entities and necessary to achieve the aims of IDISBA.

 

Your data will not be transferred to other entities, except legal obligation. Specifically, the State Agency of the Tax Administration and banks and financial entities will be notified for the collection of the service provided or product purchased, as well as those responsible for the treatment necessary for the execution of the agreement.

 

In the event that you have given us your consent for the treatment of your name and images and other information related to the activity of IDISBA, it will be disclosed in the different social networks and IDISBA website.

 

International transfers.

 

In the event that it is necessary to carry out international transfers of data by IDISBA, they will only be made to entities under the authorization of the US-European Union Privacy Shield agreement (more information: https://www.privacyshield.gov/welcome), to entities that have demonstrated that they comply with the level of protection and guarantees in accordance with the parameters and requirements set forth in current legislation on data protection, such as the European Regulation, or when there is a legal authorization to carry out the international transfer.

 

What rights do you have?

 

  • To know if we are processing your data or not.
  • To access your personal data.
  • To request the rectification of your data if they are inaccurate.
  • To request the deletion of your data if they are no longer necessary for the purposes for which they were collected or if you withdraw the consent granted.
  • To request the limitation of the processing of your data, in some cases, in which case we will only keep them in accordance with current regulations.
  • To take the data with you, which will be provided to in a structured, commonly used or mechanical reading format. If you prefer, we can send them to the new manager you designate. It is only valid in certain cases.
  • To file a claim with the Spanish Data Protection Agency, if you believe that we have not treated you correctly.
  • To revoke consent for any processing for which you have consented, at any time.

 

If you modify any data, we would appreciate it if you would notify us to keep them updated.

 

Do you want a form for the exercise of Rights?

 

  • We have forms for the exercise of your rights, ask for them by email or if you prefer, you can use the ones elaborated by the Spanish Data Protection Agency or third parties.
  • These forms must be signed electronically or accompanied by a photocopy of the ID card.
  • If someone represents you, you must attach a copy of the ID card of that person, or he/she must sign it with their electronic signature.
  • The forms can be presented in person, sent by letter or by mail at the address of the person responsible at the beginning of this text.

 

You have the right to file a claim with the Spanish Agency for Data Protection, in the event that you consider that the request for your rights has not been adequately addressed.

 

The deadline for resolving on the request by IDISBA, is one month, counting from the effective reception of your request by us.

 

You have the right to revoke consent at any time for any of the processing for which you have granted.

 

Do we process cookies?

 

If we use other types of cookies that are not necessary, you can consult the cookies policy in the corresponding link from the beginning of our website.

 

How long are we going to keep your personal information?

 

  • Personal data will be maintained while you are still connected with us.
  • Once you dissociate, the personal data processed in each purpose will be maintained during the legally foreseen terms, including the period in which a judge or court may request them, taking into account the limitation period for legal actions.
  • The data processed will be maintained as long as the aforementioned legal deadlines do not expire, if there is a legal maintenance obligation, or if the legal term does not exist, until the interested party requests their suppression or revokes the consent granted.
  • We will keep all the information and communications related to your purchase or to the provision of our service, while the guarantees of the products or services last, to attend to possible claims.
Copyright 2019 IDISBA | Privacy policy | Cookies policy | Legal notice