Overview

This privacy policy (the "Privacy Policy") describes how FIND, Campus Biotech, 9 Chemin des Mines, 1202 Geneva, Switzerland ("FIND"), collects, manages, uses, protects and shares personal data in compliance with applicable privacy laws and regulations, including the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP). This Privacy Policy applies to both the www.finddx.org website (the "Website") and the marketplace operated on www.marketplace.finddx.org (the "Marketplace") (jointly referred to as the "Platform").

Definitions

Unless otherwise defined herein, capitalized terms have the meaning given to them under applicable data protection laws or under our general terms and conditions (www.marketplace.finddx.org/pages/terms-of-service)

The term "User" means any user of the Platform.

Personal Data We Collect

We collect the following types of Personal Data.

Contact Details

First and last name

Email address

Job title

Company name

Company address

Professional email

Professional phone number

Usage Data

Data is sent by your browser whenever you visit our Platform and may include information such as your computer’s Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Platform that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

When you access the Platform with a mobile device, this Usage Data may include information such as the type of mobile device you use, your mobile device unique ID, the IP address of your mobile device, your mobile operating system, the type of mobile Internet browser you use, unique device identifiers and other diagnostic data.

Although Usage Data may not, in and of itself, allow to identify you, it may be linked with other categories of data (and thus potentially with your person).

Transaction Data

This information includes the chat history, response times and messages between the Buyer and Supplier and copies of the agreements concluded via the Platform.

Tracking and Cookies Data

We use cookies and similar tracking technologies to track the activity on our Service and we hold certain information.

Please refer to our Cookie Policy (www.marketplace.finddx.org / ) for an overview of the cookies that we use.

 

How We Collect Personal Data and Purposes of Processing

We collect information about you when you use our Platform, including browsing and taking certain actions within it, when you contact our staff directly. We process Personal Data to provide the Services, to comply with applicable law, to safeguard our legitimate interests (e.g. to prevent fraud and authorized use of the Platform or to defend and enforce claims) and/or with your consent, as further detailed below. The processing of some data is compulsory for the provision of the services available through the Platform. Without such data, we may not be able to provide you with all or part of the services offered through the Platform.

Means of collection

Purpose

Personal Data collected

Legal basis

Directly from Users

 

Usage of the Platform

We keep track of certain information about you when you visit and interact with our Platform, for market research, quality assurance and marketing purposes as well as to prevent unauthorised use of the Platform.

This information includes the Usage Data (as defined above in the Section "Personal Data We Collect").

Our legitimate interests

With respect to marketing activities, your consent

Communications between the Buyer and Supplier

We collect and store all communications between the Buyer and Supplier exchanged via the Platform  to provide the Services, monitor compliance with our Terms and Conditions and prevent fraud or abuse.

This information includes the Transaction Data (as defined above in the Section "Personal Data We Collect").

Performance of a contract

With respect to preventing fraud or abuse, our legitimate interests

Device and connection information

We collect information about your computer, phone, tablet, or other devices you use to access the Platform, to improve performance and usability of the Platform.

This information includes the Usage Data (as defined above in the Section "Personal Data We Collect").

How much of this information we collect depends on the type and settings of the device you use to access the Platform.

Our legitimate interests

With respect to marketing activities, your consent

Cookies and other tracking technologies

We and our third-party partners, such as our analytics partners, use cookies and other tracking technologies (e.g., web beacons, device identifiers and pixels) to provide functionality and to recognize you across different Services and devices, for market research, quality assurance and marketing purposes as well as to prevent unauthorised use of the Platform.

This information includes the Tracking and Cookies Data (as defined above in the Section "Personal Data We Collect").

For more information, please refer to our Cookie Policy.

Our legitimate interests

With respect to marketing activities, your consent

Direct personal contact

We collect data when you contact FIND staff directly, to provide the Services and customer support, and otherwise for the purpose of communication with you.

This information includes the Contact Details (as defined above in the Section "Personal Data We Collect").

Performance of a contract

With respect to contents provided to you or other requests you make outside of the performance of a contract, your consent

Direct communications

We collect data when you contact our staff or submit requests via our Platform to receive FIND offer such as publications, newsletters, webcasts, whitepapers, online seminars, conferences, and events, to provide the Services and customer support, to provide you with requested contents or related contents that may be of interest to you, and otherwise for the purpose of communication with you.

This information includes the Contact Details (as defined above in the Section "Personal Data We Collect").

Performance of a contract

With respect to contents provided to you or other requests you make outside of the performance of a contract, your consent

Communications relating to the FIND Technology Scouting process

We collect data when you contact us with respect to the FIND Technology Scouting process.

This information includes the Contact Details (as defined above in the Section "Personal Data We Collect").

Performance of a contract

Your consent

Registration to a FIND-sponsored seminar or congress

We collect data when you register to seminar or congresses that we sponsor, to facilitate your registration, as well as for market research, quality assurance and marketing purposes.

This information includes the Contact Details (as defined above in the Section "Personal Data We Collect").

Performance of a contract

Our legimitate interests

With respect to marketing activities, your consent

Indirectly

 

Other partners

We receive information about you and your activities on and off the Platform from third-party partners, such as advertising and market research partners who provide us with information about your interest in and engagement with our Services.

This information includes the Usage Data and Tracking and Cookies Data (as defined above in the Section "Personal Data We Collect").

For more information, please refer to the Section "Service Providers".

 

 

 

In the event that you submit or otherwise communicate to us information regarding other Data Subjects (such as contact details of members of your organization), you represent and warrant that you have the right to share such data with us, that the relevant Data Subjects are informed of the contents of this Privacy Policy and, as required, consent to the processing of their Personal Data.

Processors

All Personal Data is held in confidence and is never provided to any third party outside of FIND without an appropriate legal basis. We may employ third party companies and individuals to facilitate the operation of our Platform, provide the Platform on our behalf, perform Platform-related services or assist us in analysing how our Platform is used. These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

For example and without limitation, we use the following processors on our Platform:

  • Azure virtual machine: a virtual, cloud-based environment that is used to host proprietary software and use data.
  • Sendgrid: used for marketplace EDMs (sender and recipient email address, delivery status).
  • Twilio: internal chat feature between Buyer and Supplier.
  • Jotform: used for information collection of pre-onboarding vetting form and need forecast form that has been created specifically for DxConnect marketplace.
  • GoogleSheets: used to automatically collect and collate submissions from JotForm.

Disclosure to third party Controllers

We may disclose information about you to authorities in Switzerland and in other jurisdictions where required by applicable law and/or to other Users (such as your counterparties for the sale and purchase of devices sold via the Marketplace) where necessary to provide the Services or operate the Platform. In addition, when using our services, you may encounter links to documents, websites and mobile applications created and / or maintained by third parties. If you follow any link to such third party content, the processing of your data in relation to this content may be governed by the relevant third parties' privacy policies or similar documents.

We are not the controller responsible for the data processing outlined in the immediately preceding paragraph. We accept no liability for any processing of your data by third parties controllers.

Data Retention

We retain Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy, and to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes and enforce our legal agreements and policies.

FIND retains any Personal Data for the duration of the appropriate business relationship. As an organization operating under and governed by Swiss law, FIND is obliged to keep a record of all operational relevant information for a period of ten (10) years. Personal Data may fall within this definition.

Data Transfers

We are a Swiss organization located in Switzerland. If you are located outside Switzerland, your data will be transferred to and processed in Switzerland. Swiss data protection laws may differ from those of your jurisdiction.

We take all the steps reasonably necessary to ensure that no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your Personal Data. Recipients of the data may be located outside of Switzerland, in particular in the jurisdictions where products can be purchased or sold through the Marketplace, however potentially in any country in the world. If FIND shares your personal data with any other third party as described in this Privacy Policy and the Personal Data in question will be transferred to a State which is not a Member State of either the European Union or the EEA, or deemed adequate by the European Commission, FIND (as a Controller/data exporter) will only conduct such transfer (to a Processor/data importer) if there are suitable safeguards in place, such as binding corporate rules, standard contractual clauses, approved Codes of Conduct, or approved certification mechanism. For more information, please contact FIND (see contact details below).

Data Storage and Security

In general, all Personal Data is held in confidence and is never provided to any third party outside of FIND, without the express authorisation of the data subject, as required by applicable law or as otherwise set out under this Policy. We maintain reasonable and appropriate technical and organizational security measures to safeguard your data, for example against loss, misuse or accidental destruction. However, there is no method of transmission over the Internet, or method of electronic storage is 100% secure and we therefore cannot guarantee its absolute security.

Data Protection Rights

You have certain data protection rights on the basis of the applicable data protection law (including its conditions, restrictions or exceptions). We will respond to your request without undue delay, at the latest within one calendar month after receipt. Please note that we may ask you to verify your identity before responding to such requests. When you wish to exercise such rights, we may require that you provide information to confirm your identity.

If the GDPR applies to you, you have in particular the following rights (subject to such conditions, restrictions or exceptions as may be set forth in the GDPR) :

Right to access

You have a right to request a copy of the Personal Data held by us as a Controller, which we will provide to you in an electronic form.

Right to amendment

You have the right to ask us to correct our records if you believe they contain incorrect or incomplete information about you.

Right to withdraw consent

If you have provided your consent to the collection, processing, and transfer of your Personal Data, you have the right to fully or partly withdraw your consent. This includes cases where you wish to opt out from marketing messages.

Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose(s) to which you originally consented unless there is another Legal Basis for the processing. To stop receiving emails from us, please click on the "unsubscribe" link in the email you received from us or contact us.

Right to erasure

You have the right to request that we delete your Personal Data when it is no longer necessary for the Purposes for which it was collected, or when it was unlawfully processed.

Right to restriction of processing

You have the right to request the restriction of our processing of your Personal Data where you believe it to be inaccurate, our processing is unlawful, or where we no longer need to process it for the initial Purpose, but where we are not able to delete it due to a legal obligation or because you do not want us to delete it.

Right to portability

You have the right to receive or to request that we transmit your personal data to another Controller in a common format such as Excel, where this is data which you have provided to us and where we are processing it by automated means on the basis of your consent or in order to perform our contractual obligations (e.g. to provide our Services).

Right to object to processing

Where the legal basis for our processing of your personal data is our legitimate interest, you have the right to object to such processing on grounds relating to your particular situation. We will abide by your request unless we have compelling legitimate legal basis for the processing which override your interests, or if we need to continue to process the data for the establishment, exercise or defense of a legal claim.

Right to lodge a complaint with a supervisory authority

You have the right of appeal to a data protection supervisory authority if you believe that the processing of your personal data violates data protection law. In Switzerland, you can contact the Federal Data Protection and Information Commissioner, Feldeggweg 1, CH-3003 Bern

 

The exercise of your rights (e.g. your objection to the processing of your data or withdrawal of any previously given consent) may prevent us from providing you with all or part of our services. If we consider that, by agreeing to your request, we would no longer be able to provide our services to you in a manner that fulfils our quality standards, we may decide to terminate our relationship with you.

Your rights may also be limited, for example when we are required to obtain and process your data to comply with applicable law and regulation, to assert or defend against legal claims, or when we have other legitimate grounds for the processing that override your interests and rights. We may therefore be entitled to continue processing your data even after you have chosen to withdraw your consent or objected to the processing of your data.

If requests are manifestly unfounded or excessive, in particular because of their repetitive character, we reserve the right to either charge a reasonable fee taking into account the request or refuse to act on the request.

Amendments to this Policy

We reserve the right, at our sole discretion, to amend this Privacy Policy at any time, including to reflect changes in our data processing practices or in data protection laws. Such amendments will be communicated to you in accordance with the General Terms and Conditions for the Platform. You will be deemed to have accepted these amendments when using the Platform for the first time after the amendments have been communicated to you or, if you have neither used the Platform nor raised an objection, upon expiration of the deadline set forth in the General Terms and Conditions. The Privacy Policy retrievable at marketplace.finddx.org/pages/privacy-policy is the policy currently in force.

Contact Us

If you have any questions, concerns, or complaints about FIND's Personal Data practices or this Privacy Policy, we encourage you to get in touch with us.

Contact information: marketplace@finddx.org