<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=551791532206281&amp;ev=PageView&amp;noscript=1">

iSchemaView, Inc. Privacy Shield Policy

iSchemaView, Inc. acknowledges current data protection laws in the European Union ("EU") under the General Data Protection Regulation (GDPR) and adopts the Privacy Shield framework here as policy governing Personal Data which may be transferred to or from iSchemaView operations, affiliates, agents, third-party distributors, patients, customers, or healthcare providers in the EU, including Switzerland, to iSchemaView operations in the United States ("U.S."). This Privacy Policy establishes the framework for treating personal data.

iSchemaView adopts the EU-U.S. Privacy Shield Frameworks administered by the U.S. Department of Commerce and applies the Principles of these frameworks to all Personal Data received from the EU (and Switzerland) in reliance on the Privacy Shield. iSchemaView’s participation in Privacy Shield is subject to investigation and enforcement by the Federal Trade Commission.

The Privacy Shield Principles apply to the data once they have been transferred to the United States. As a company involved in the Medical Device industry, iSchemaView shall ensure all data used for research, shall be anonymized when appropriate and protected as stipulated in Privacy Shield Principle 14 at www.privacyshield.gov.

A full list of companies enjoined in the Privacy Shield Framework may be found at the U.S. Department of Commerce’s website www.privacyshield.gov.

Definitions

"Data Subject" means the EU or Swiss individual whose Personal Data is covered by this Policy.

"Personal Data" means any information relating to an individual located in the EU (or Switzerland) that can be used to identify that individual either on its own or in combination with other readily available data (e.g., the individual’s name, title, work location, home address, date of birth, compensation, benefits, or family members).

"Sensitive Personal Data" means Personal Data regarding any of the following:

  • Health or medical condition;
  • Racial or ethnic origin;
  • Political opinions;
  • Religious or philosophical beliefs;
  • Trade union membership;
  • Sex life; or
  • Criminal convictions or indictments.

Scope and Responsibility

This Policy applies to the transfer, collection, use, and disclosure in the U.S. of all EU and Swiss Personal Data from countries in the EU (and Switzerland) to iSchemaView in the U.S. Where iSchemaView acts solely as an agent processing EU Personal Data under the direction of a third party, iSchemaView has no direct relationship with the Data Subjects whose Personal Data it processes, and for such Personal Data, iSchemaView instead may rely on such third parties to comply with the European legal requirements underlying the Privacy Shield Principles.

There are two primary activities where EU Personal Data may be acquired: During the operation and use of Software as Medical Device application; and through a website visit.

iSchemaView employees, contractors or third-party entities who may have access to such Personal Data in the U.S. during the course of allowed business purposes are responsible for adhering to this policy. Adherence by iSchemaView to this Policy may be limited to the extent required to meet legal, regulatory, governmental, or national security obligations, but Personal Data shall not be collected, used, or disclosed in a manner contrary to this policy without the prior written permission of iSchemaView’s executive management.

Failure of iSchemaView employees, contractors, and third-party entities to comply with this Policy may result in disciplinary action up to and including termination.

Privacy Shield Principles

Complies with the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information from European Union member countries (and Iceland, Liechtenstein, and Norway) and Switzerland transferred to the United States pursuant to Privacy Shield. iSchemaView has certified that it adheres to the Privacy Shield Principles with respect to such data. If there is any conflict between the policies in this privacy policy and data subject rights under the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification page, please visit here.

With respect to personal data received or transferred pursuant to the Privacy Shield Frameworks, iSchemaView is subject to the regulatory and enforcement powers of the U.S. Federal Trade Commission.

Notice—iSchemaView is principally a third-party in receipt of data from operations of medical device solutions which has been anonymized through agreement with first-party entities in the delivery of health care solutions to patients. As a third-party with anonymized data, no specific sensitive personal data is passed to iSchemaView.

Notice—Under Privacy Shield Principle 14, iSchemaView as a medical device company, “does not have to apply the Privacy Shield Principles with respect to the Notice, Choice, Accountability for Onward Transfer, and Access Principles in its product safety and efficacy monitoring activities, including the reporting of adverse events and the tracking of patients/subjects using certain medicines or medical devices, to the extent that adherence to the Principles interferes with compliance with regulatory requirements. This is true both with respect to reports by, for example, health care providers to pharmaceutical and medical device companies and with respect to reports by pharmaceutical and medical device companies to government agencies like the Food and Drug Administration.”

Notice—iSchemaView takes steps so that Data Subjects covered by this Policy are notified about the types of Personal Data it collects about them, the purposes for which it uses such Personal Data, the types of third parties to which it discloses such Personal Data, the choices, and means that it offers for limiting its use and disclosure of such Personal Data, and how Data Subjects can contact ISchemaView with any inquiries or complaints. Notice is provided in clear and conspicuous language at the time of collection or as soon as practicable thereafter; before iSchemaView uses or discloses Personal Data for a purpose other than that for which it was originally collected, and through this Policy.

Principally, in the use of Software as a Medical Device applications, iSchemaView is the recipient of anonymized data from first-party entities.

In the course of EU and/or Swiss individuals visiting www.iSchemaView.com personal data may be captured.

First-party obtained data may be used by iSchemaView for:

  • Compliance as required by law, or as permitted by law;
  • The delivery of current and future products and services;
  • Our everyday business operations such as:
    • product safety and product complaint reporting;
    • patient assistance;
    • communicating information about diseases, products and services, or via e-mail, direct mail and other channels;
    • business and marketing research; auditing our programs and resources for compliance and security purposes; and

iSchemaView may disclose Personal Data to the following types of third-parties:

  • To third-parties that are designated by the Data Subject or customer to which the Personal Data pertains for purposes of providing health care treatment (including training and service);
  • Study partners with uses defined under Privacy Shield Principle 14;
  • As required by law, including disclosure in response to lawful requests by public authorities, such as to meet national security or law enforcement requirements.

In addition, iSchemaView collects, uses, and discloses Personal Data collected from users of iSchemaView’s public website.

Website Information Collection, Use, and Sharing

We are the sole owners of the information collected on this site. We only have access to collect information that you voluntarily give us via email or other direct contact from you. We will not sell or rent this information to anyone.

We will use your information to respond to you, regarding the reason you contacted us. We will not share your information with any third party outside of our organization, other than as necessary to fulfill your request, e.g. to ship an order.

Unless you ask us not to, we may contact you via email in the future to tell you about new products or services, or changes to this privacy policy.

Your Access to and Control Over Information

You may opt-out of any future contacts from us at any time. You can do the following at any time by contacting us via telephone at (650) 388-9767 ext. 5 or by email dpo@ischemaview.com 

  • See what data we have about you, if any
  • Change/correct any data we have about you
  • Have us delete any data we have about you
  • Request that we delete data we have about you. We will process the request in accordance with the law.
  • Express any concern you have about our use of your data

Security

We take precautions to protect your information. When you submit sensitive information via the website, your information is protected both online and offline.

Wherever we collect sensitive information, (such as credit card data), that information is encrypted and transmitted to us in a secure way. You can verify this by looking for a closed lock icon at the bottom of your web browser, or looking for “https” at the beginning of the address of the web page.

While we use encryption to protect sensitive information transmitted online, we also protect your information offline. Only employees who need the information to perform a specific job (for example, billing or customer service) are granted access to personally identifiable information. The computers/servers in which we store personally identifiable information are kept in a secure environment.

Cookies

We use “cookies” on this site. A cookie is a piece of data stored on a site visitor’s hard drive to help us improve your access to our site and identify repeat visitors to our site. For instance, when we use a cookie to identify you, you would not have to log in a password more than once, thereby saving time while on our site. Cookies can also enable us to track and target the interests of our users to enhance the experience on our site. Usage of a cookie is in no way linked to any personally identifiable information on our site.

Sharing

We share aggregated demographic information with our partners. This is not linked to any personal information that can identify any individual person.

Links

This website contains links to other sites. Please be aware that we are not responsible for the content or privacy practices of such other sites. We encourage our users to be aware when they leave our site and to read the privacy statements of any other site that collects personally identifiable information.

Choice

In the event EU or Swiss Personal Data covered by this Policy is to be used for a new purpose that is materially different from the purpose(s) for which the Personal Data was originally collected or subsequently authorized, or is to be transferred to the control of a third party, iSchemaView provides Data Subjects an opportunity to choose (opt-out) whether to have their Personal Data so used or transferred. In the event that Sensitive Personal Data is used for a new purpose or transferred to the control of a third party, the Data Subject’s explicit consent (opt-in) will be obtained prior to such use or transfer of the Sensitive Personal Data.

Accountability for Onward Transfer (transfers to affiliates and/or other third parties)—In the event iSchemaView transfers EU and/or Swiss Personal Data covered by this Policy to an affiliate or other third-party, it will do so consistent with any notice provided to Data Subjects and any consent they have given. iSchemaView will transfer Personal Data to such third parties only if the transfer is for limited and specified purposes and the third party will provide at least the same level of privacy protection as is required by this Policy and the Privacy Shield Principles. When iSchemaView has knowledge that a third party is using or sharing Personal Data in a way that is contrary to this Policy, iSchemaView will take reasonable steps to prevent or stop such use or sharing.

With respect to transfers to its agents, iSchemaView remains responsible under the Privacy Shield Principles if an agent processes Personal Data in a manner inconsistent with the Principles, except where iSchemaView is not responsible for the event giving rise to the damage.

Access—Data Subjects whose Personal Data is covered by this Policy have the right to access such Personal Data and to correct, amend, or delete such Personal Data if they can demonstrate that it is inaccurate or incomplete or has been processed in violation of the Principles (except when the burden or expense of providing access, correction, amendment, or deletion would be disproportionate to the risks to the Data Subject’s privacy, or where the rights of persons other than the Data Subject would be violated).

Security—iSchemaView takes reasonable precautions to protect EU and Swiss Personal Data covered by this Policy from loss, misuse, and unauthorized access, disclosure, alteration, and destruction.

Data Integrity and Purpose Limitation—EU and Swiss Personal Data covered by this Policy that is collected, processed, and maintained by iSchemaView shall be kept and used for its intended purpose. iSchemaView takes reasonable steps to ensure that the Personal Data is used for its intended purpose(s), and is accurate, complete, and current.

Recourse, Enforcement, and Liability—To ensure compliance with these Privacy Shield Principles, iSchemaView will:

  • In the investigation and resolution of complaints that cannot be resolved between iSchemaView and the complainant, cooperate with and comply with the dispute resolutions mechanisms of:
    • For non-HR Personal Data, the Better Business Bureau’s ("BBB") EU Privacy Shield Dispute Resolution Procedure, which is based in the U.S. (see below);
      • Periodically review and verify its compliance with the Privacy Shield Principles; and
      • Remedy issues arising out of any failure to comply with the Privacy Shield Principles.
    • iSchemaView acknowledges that its failure to provide an annual self-certification to the U.S. Department of Commerce will remove it from the Department’s list of Privacy Shield participants, and thereafter transfers of Personal Data will not be allowed unless iSchemaView otherwise complies with EU data protection law.

Enforcement and Dispute Resolution

In compliance with the Privacy Shield Principles, iSchemaView commits to resolve complaints about your privacy and our collection or use of your personal information transferred to the United States pursuant to Privacy Shield. European Union and Swiss individuals with Privacy Shield inquiries or complaints should first contact iSchemaView by email at dpo@ischemaview.com or via post at:

iSchemaView Inc.
ATTN: Data Privacy Officer
433 Park Point Drive, Suite 220
Golden, CO 80401

iSchemaView has further committed to refer unresolved privacy complaints under the Privacy Shield Principles to an independent dispute resolution mechanism, the BBB EU PRIVACY SHIELD, operated by the Council of Better Business Bureaus. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit here for more information and to file a complaint. This service is provided free of charge to you.

If your Privacy Shield complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms. See Privacy Shield Annex 1 at www.privacyshield.gov.

You may also have the right to make a GDPR complaint to the relevant Supervisory Authority. A list of Supervisory Authorities is available here. If you need further assistance regarding your rights, please contact us using the contact information provided below and we will consider your request in accordance with applicable law. In some cases our ability to uphold these rights for you may depend upon our obligations to process personal information for security, safety, fraud prevention reasons, compliance with regulatory or legal requirements, or because processing is necessary to deliver the services you have requested. Where this is the case, we will inform you of specific details in response to your request.

Changes to This Policy

This Policy may be amended from time to time consistent with the requirements of the Privacy Shield Principles. Appropriate notice will be given concerning such amendments. If you feel that we are not abiding by this privacy policy, you should contact us immediately via telephone at (650) 388-9767 or by email: dpo@ischemaview.com