Privacy policy HL7

July 18, 2018

In this privacy policy, we, the HL7 User Group Switzerland, explain how we collect and otherwise process personal data. This is not an exhaustive description; other privacy policies or general terms and conditions, articles of association, conditions of participation and similar documents may govern specific matters. Personal data refers to all information relating to an identified or identifiable person.

It is possible to use this website without providing personal data. This information is always provided on a voluntary basis. Your data will not be passed on to third parties for advertising purposes etc. without your express consent.

If you provide us with the personal data of other persons such as family members, work colleagues etc., please ensure that the person(s) are aware of this privacy policy and only share the data with us if you are permitted to do so and the personal data is correct.

This privacy policy is based on the EU General Data Protection Regulation (GDPR). Although the GDPR is a regulation of the European Union, it is relevant to us. The Swiss Data Protection Act (DSG) is strongly influenced by EU law, and companies outside the European Union or the EEA must comply with the GDPR under certain circumstances.

Definitions

Personal data

Personal data is any data relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online pseudonym or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person.

Data subject

The data subject is the identified or identifiable natural person whose personal data is processed by the controller.

Processing

Processing means any operation which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, retrieval, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, erasure or destruction.

Restriction of processing

Restriction of processing is the marking of stored personal data with the aim of restricting its future processing.

Profiling

Profiling is any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements.

Pseudonymization

Pseudonymization is the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

Controller or controller responsible for the processing

The controller or controller responsible for the processing is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

Processor

A processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

Recipient

Recipient is a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.

Third party

A third party is a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorized to process personal data.

Consent

Consent is any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

1. controller

The controller responsible for the data processing described here is

HL7 User Group Switzerland
Head office
Oberstrasse 222
CH-9014 St. Gallen

2. collection and processing of personal data

We primarily process the personal data that we receive from our customers and other business partners as part of our business relationship with them and other persons involved or that we collect from their users when operating our websites, apps and other applications.

3 Purposes of data processing and legal bases

As an association, we primarily use the personal data we collect to conclude and process our contracts with our customers, members and business partners, in particular in the context of communication with our customers and the purchase of products and services from our suppliers and subcontractors, as well as to comply with our legal obligations in Switzerland and abroad. If you work for such a customer or business partner, your personal data may of course also be affected in this function.

If you have given us your consent to process your personal data for specific purposes, for example when you register to receive newsletters or carry out a background check, we will process your personal data within the scope of and based on this consent, unless we have another legal basis and require one. Consent that has been given can be withdrawn at any time, but this has no effect on data processing that has already taken place.

4. cookies, tracking and other technologies associated with the use of our website

E-mail

Our website provides users with e-mail addresses based on legal regulations to enable direct communication with us. If you contact us by e-mail, the personal data you provide will be stored. The personal data transmitted on a voluntary basis will be stored for the purpose of processing and contacting you. This data will not be passed on to third parties. This data is only collected to process your request.

Newsletter

We only send newsletters with mainly informative content with the explicit consent of the recipient or with legal permission.

Registration for our newsletter takes place via a so-called double opt-in procedure, in which you receive an email after registration asking you to confirm your registration. This confirmation is necessary to avoid registrations with third-party email addresses. The registration is logged in order to be able to prove that the process complies with the legal requirements. This includes storing the e-mail address, the time of registration and confirmation, the IP address and any names.

We use the GoEast Mailwriter from GoEast GmbH, Oberstrasse 222, CH-9014 St. Gallen, Switzerland, for sending emails. The e-mail addresses of the recipients, as well as their other data, are stored on the servers of the mailing service provider. The mailing service provider uses this data to send and analyze the newsletter on our behalf.

This data is treated as strictly confidential and is not passed on to third parties, e.g. for advertising purposes.

The newsletter contains a web beacon, a pixel-sized file that transmits the time of reading when the newsletter is opened. This is used for simple statistics on the number of readers of the newsletter. Furthermore, the opening of the links in the newsletter can be tracked statistically. The evaluation serves only to recognize the reading behavior of our users and to adapt our content to them. You can view the data protection provisions of the mailing service provider here: Link to privacy policy

You can unsubscribe from the newsletter at any time. You will find a link to unsubscribe at the end of each newsletter.

Member account

We offer users the opportunity to open a member account via the PDF registration form on our website, which allows them to use additional functions.

In order to become a member of your association and open the member account, the data entered in the registration form will be processed and stored. Mandatory fields are marked as such, as we require such data to process the contract. We store your profile data until you have your account deleted by sending a message to the above address, your membership ends, or as required to provide the contractually agreed services, etc. Your data may be transferred to third parties for payment transactions, newsletters, etc.

Data collection by the website hosting provider

Our hosting provider is GoEast GmbH, Oberstrasse 222, CH-9014 St. Gallen, Switzerland.

The web servers of GoEast GmbH collect general data and information each time our website is accessed. This is stored in the server log files. Among other things, the browser used and its version, the operating system, the referrer website, the sub-websites, the date and time of access, an Internet Protocol (IP) address, the Internet Service Provider (ISP) and other data and information that serve to ward off dangers in the event of system attacks are recorded.

We do not use this general data and information to draw any conclusions about the person. Rather, this information is used to deliver the content correctly, to optimize the website, to ensure the functionality of our IT systems and to provide law enforcement authorities with the necessary information in the event of a cyber attack.

The data can be statistically analyzed, but no personal reference is made. The anonymous data of the server log files are stored separately from all personal data provided by a person for six months.

Shipping company

In order to fulfill the contract in accordance with Art. 6 para. 1 sentence 1 lit. b GDPR, some of your data may be passed on to the shipping company commissioned with the delivery. This may include the delivery address, your name and your e-mail address (for tracking).

Matomo

We use the open source software "Matomo", which is hosted on the servers of GoEast GmbH, for the statistical analysis of visitor access. Your IP address is stored exclusively in anonymized form. We use Matomo to analyze which content is relevant to you, where users come to our website from and where there are problems. No specific observation of our users as identifiable persons is carried out. Matomo uses cookies to enable us to analyze the use of our website. The information collected is stored on servers in the EU and deleted after three months.

If you have activated the Do-Not-Track feature on your browser, Matomo will not be activated.

Cookies

Both we and the third party providers we work with (GoEast Mailwriter) may use scripts, web beacons and cookies associated with your use of the Service, third party websites and mobile applications. Cookies may be placed on your computer, mobile device, emails sent and on our website. Cookies may transmit information about your use of our Service such as IP addresses, browser types and the date and time of use.

You can make some cookie settings in your browser to prevent cookies from being set or to permanently object to them. Cookies that have been set can also be deleted. However, this may impair the functionality of our website. The settings vary depending on the device and browser. They can usually be found under Security settings.

Cookies enable us to recognize users of our website. The purpose of this recognition is to make it easier for users to use our website. For example, they do not have to log in every time they visit.

5. data transfer and data transfer abroad

As part of our business activities and for the purposes set out in section 3, we also disclose data to third parties where permitted and where we deem it appropriate, either because they process it for us or because they wish to use it for their own purposes. This applies in particular to the following parties:

  • Service providers of ours (both internal and external, such as banks, insurance companies), including contract processors (such as IT providers);
  • Dealers, suppliers, subcontractors and other business partners;
  • Association members;
  • domestic and foreign authorities, official bodies or courts;
  • the media;
  • the public, including visitors to websites and social media;
  • competitors, industry organizations, associations, organizations such as HL7 International and other bodies
  • other parties in potential or actual legal proceedings;

all joint recipients.

6. duration of the storage of personal data

We process and store your personal data for as long as is necessary for the fulfillment of our contractual and legal obligations or otherwise for the purposes pursued with the processing, i.e., for example, for the duration of the entire business relationship (from the initiation, processing to the termination of a contract) and beyond in accordance with the statutory retention and documentation obligations. It is possible that personal data may be stored for the period in which claims can be asserted against our company and insofar as we are otherwise legally obliged to do so or legitimate business interests require this (e.g. for evidence and documentation purposes). As soon as your personal data is no longer required for the above-mentioned purposes, it will be deleted or anonymized as far as possible. For operational data (e.g. system protocols, logs), shorter retention periods of twelve months or less generally apply.

7 Data security

We take appropriate technical and organizational security precautions to protect your personal data from unauthorized access and misuse, such as issuing instructions, training, IT and network security solutions, access controls and restrictions, encryption of data carriers and transmissions, pseudonymization, checks.

SSL encryption

For security reasons and to protect the transmission of confidential content, we use SSL encryption. An encrypted connection can be recognized by the fact that the URL in the browser begins with "https://" instead of "http://" and by the lock symbol in the browser line. If SSL encryption is activated, third parties have no access to the data you transmit without enormous effort.

8. obligation to provide personal data

As part of our business relationship, you must provide the personal data that is required for the establishment and execution of a business relationship and the fulfillment of the associated contractual obligations (as a rule, you do not have a legal obligation to provide us with data). Without this data, we will generally not be able to conclude or execute a contract with you (or the entity or person you represent). It will also not be possible to use the website if certain information to secure data traffic (e.g. IP address) is not disclosed.

9 Rights of the data subject

You have the right to information, correction, deletion, the right to restrict data processing and otherwise to object to our data processing as well as to the disclosure of certain personal data for the purpose of transfer to another body (so-called data portability) within the scope of the data protection law applicable to you and insofar as provided for therein (as in the case of the GDPR). Please note, however, that we reserve the right to assert the restrictions provided for by law, for example if we are obliged to store or process certain data, have an overriding interest in doing so (insofar as we are entitled to invoke this) or require it for the assertion of claims. If you incur costs, we will inform you in advance. We have already informed you about the possibility of withdrawing your consent in section 3. Please note that exercising these rights may conflict with contractual agreements and may have consequences such as premature termination of the contract or cost consequences. We will inform you in advance if this is not already contractually regulated.

The exercise of such rights generally requires that you provide clear proof of your identity (e.g. by means of a copy of your ID where your identity is otherwise not clear or cannot be verified). To assert your rights, you can contact us at the address given above.

Every data subject also has the right to enforce their claims in court or to lodge a complaint with the competent data protection authority. The competent data protection authority in Switzerland is the Federal Data Protection and Information Commissioner.

10 Changes

We may amend this privacy policy at any time without prior notice. The current version published on our website shall apply. If the data protection declaration is part of an agreement with you, we will inform you of the change by e-mail or other suitable means in the event of an update.