Skip to content
ZoomRx privacy PoliCy

Privacy Statement Summary:

This Privacy Policy (“Policy”) explains how your information is collected, used, and disclosed by ZoomRx Inc. (“We” or “Us" or “Our”). This policy applies where we are acting as a Data Controller with respect to the personal data of the doctors, healthcare professionals, other participants involved in our market research activities, and all other individuals whose data we process. This also applies to data relating to individuals who visit our website and use other services; in other words, where we determine the purposes and means of the processing of that personal data.

We are committed to safeguarding the privacy of our data subjects. We will never sell, share, or use your personal information other than as described here.

By agreeing to be involved, and sharing your data with us, you agree to the terms of this policy.

Who will use your data?

ZoomRx Inc.

Who are we?

We are a full-service strategic healthcare consulting agency providing primary market research across all stages of the drug lifecycle. We are market leaders in Promotional Effectiveness Tracking; ATU and Brand Equity Tracking; and Chart Audits with integrated Health Care Professionals [HCPs]-Patient recorded dialogue. We also provide advanced market demand and opportunity assessment and communication testing. Our Customer Engagement Center of Excellence team offers advanced analysis, secondary data integration, and interactive real-time dashboards. Our Ferma.AI team offers an Artificial Intelligence tool for conference coverage and competitive intelligence.

What for? (Purpose)

We store and process data in order to provide our consulting and market research services. We act on behalf of pharmaceutical, biotech, and medical device companies and conduct market research campaigns to gather feedback from medical professionals relating to the use of their medical products, devices, treatments, drugs, medications, etc. We also provide consultancy services which may involve collaboration with healthcare professionals, representatives from relevant organisations, and others.

We will store and process your data only in order to allow us to provide our services as a strategic healthcare market research and consulting agency. If you contact us using our Contact Us form, by email, or by any other means, we will respond to your enquiry and may also send you information that we think you will be interested in. This may include a range of related services as stated above.

If you choose to use our services, you are agreeing to the collection, processing, storage, and use of your personal information as required to provide and improve those services. We will not use or share your data with anyone except as described in this Privacy Policy.

As per our legal obligations, we may need to send details to relevant authorities or any other organisation that requires them by law.

How do we collect your personal data?

Most of the personal information we process is provided directly by you for one of the following reasons:

  • If you apply for one of our open roles through the application form
  • If you sign up and create an account on our website
  • If you enter your details in one of our blog posts
  • If you send us direct messages through our social media platforms (Facebook, Twitter, Linkedin, Instagram)
  • Or based on the information collected by cookies and similar technologies when you visit our website

Where we have an appropriate lawful reason we may also collect your data from other third parties, advertising networks, social media, or other publicly available sources.

What will happen if you contact us?
  • If you contact us, we will use your data to send you the information that you have requested and updates, and other information that we think you will be interested in.
  • If you contact us as a client and choose to use our services, we may collect more information from you, and where necessary we may share your information with carefully selected third parties as required to provide the services you have requested.
  • If you enter your information in one of our blog posts we will use the information to fulfil your request and contact you about relevant insights, products, and services. You may unsubscribe from all communications at any time.
  • If you choose to apply for one of our open roles through the application form, we may scan your resume with our applicant tracking system to check if you are a qualified candidate, and then we will start the hiring process.

The data we collect is used by ZoomRx Inc. to provide our services to you. We may share your data with other companies / organisations / people as required to provide our services or operate our company; however, unless required to do so by law, we will not otherwise share, sell, or distribute any of the information you provide to us without your consent.

What data will be stored?

We collect and store only a limited amount of data – we collect only the data we require to manage our relationship with you, to provide our services to our clients, and to run and develop our company.

To provide you with our services, we are required to store your relevant information relating to enquiries, such as contact information, financial information,etc.

If you choose to use our strategic healthcare consulting services as a client, we will store information such as:

  • Your professional registration, and other professional information
  • Contact details (first name, last name, email address, physical address, telephone number, mobile number)
  • Company information
  • Financial information (information about payments made between us and you as a client)
  • Information relating to your browsing activity obtained using our cookies and similar technology
  • Publicly available data (information about articles that you’ve published, or you’re interested in)
  • Any other information that you choose to share with us

If you choose to apply for a job for one of our open roles through the application form, we will store your personal details such as:

  • Contact details (first name, last name, email address, physical address, telephone number, mobile number)
  • Qualifications
  • Employment history
  • Information relating to your browsing activity obtained using our cookies and similar technology
  • Publicly available data (information about articles that you’ve published, or you’re interested in)
  • Any other information that you choose to share with us

With your consent we may add any testimonials or other references to our website, newsletters, our social media, or through other publicly available channels. If you visit our website we will collect only information relating to your browsing activity, obtained using our cookies and similar technology.

What data will be shared?

We will not share your data with any third parties other than as described in this policy, and as you would reasonably expect. We may need to share your information with regulators or legal bodies that request it.

We will not share your data with any third parties other than as required to fulfil our contracts and as described here. We will only share any data that is particularly relevant to our process in order to provide the services that we offer.

How long will data be stored?

Your data will be stored only for as long as strictly necessary to provide our services, to meet our obligations to you and meet our legal obligations. For more information, please contact us about our Data Retention Policy.

Who can access my data?

We will never sell, share, or otherwise distribute your data to any other third party other than as described here.

We will share your information with any regulator or legal body that requests it, as well as any parties relevant to the application process.

We ensure access is restricted to only those persons authorised by us to access your data.

Access to your data is strictly controlled. For more information, please contact us about our Information Security Policy.

Who do we share data with?

We only share your data with trusted and relevant companies which ensure an adequate level of protection and where there is an appropriate agreement in place, which includes obligations in relation to the confidentiality, security, and lawful processing of any personal data shared with them.

For example, we share your personal data with trusted companies such as:

How is my data kept secure?

We will store your data on secure based servers. We use industry-standard security protocols/technology to secure your data.

Where data is transferred from the UK and/or EU to other countries we will take all appropriate precautions to protect your data, including establishing DPA/SCCs and completing risk assessments.

We take your privacy seriously and will only use your personal information to provide the services you have requested from us and to send you information about services you may be interested in. We will never sell, share, or use your personal information other than as described here.

About This Privacy Policy

This policy sets out how we will use and share the information that you give us. This policy describes your relationship with ZoomRx Inc. The General Data Protection Regulation (GDPR) describes how organisations must collect, handle, process, and store personal information.

These rules apply regardless of whether data is stored electronically, on paper, or on other materials. To comply with the law, personal information must be collected and used fairly, stored safely, and not disclosed unlawfully. GDPR is underpinned by eight important principles. These say that personal data must:

  • Be processed fairly and lawfully
  • Be obtained only for specific, lawful purposes
  • Be adequate, relevant, and not excessive
  • Be accurate and kept up to date
  • Not be held for any longer than is necessary
  • Be processed in accordance with the rights of the data subjects
  • Be protected in appropriate ways
  • Not be transferred outside our borders, unless that country or territory also ensures an adequate level of protection

We take these responsibilities seriously; this document describes our approach to data protection. This policy helps to protect us from data security risks, including:

  • Breaches of confidentiality. For instance, information being given out inappropriately.
  • Failing to offer choice. For instance, all individuals should be free to choose how the company uses data relating to them.
  • Reputational damage. For instance, the company could suffer if hackers successfully gained access to sensitive data.
  • Any other loss or damage caused as a result of our failure to meet our data protection obligations.
  • Any other risk associated with processing your data.
Who We Are And How To Contact Us

ZoomRx Inc. is registered in the US and India. The Data Protection Lead is Kendall Anderson. You can contact us in any of the following ways:

Email: kendall.anderson@zoomrx.com

Address: ZoomRx, 245 Main Street, Floor 2, Cambridge, Massachusetts, 02142, US

No. 40 Global Infocity Park, 2nd Floor, Block B, MGR Salai, Kandanchavadi, Perungudi, 600096

Our UK Representative:

Under Article 27 of the UK Data Privacy Act, we have appointed a UK Representative to act as our data protection agent. Our nominated UK Representative is: GDPR Local Ltd.

Adam Brogden: contact@gdprlocal.com

Tel +44 1772 217800

1st Floor Front Suite,
27-29 North Street, Brighton,
England,
BN1 1EB

Who This Privacy Policy Applies To

Processing of your data is required in order to offer you our services. This policy relates to every data subject that chooses to share their personal data with us; data subjects whose data is provided to us by a third party; data subjects where we collect, store, or process their data in order to provide our services; and all other data subjects whose data we process in order to operate and develop our company.

It applies to all data that the company holds relating to identifiable individuals, even if that information technically falls outside of the GDPR. This can include:

  • Names of Individuals
  • Contact details
  • Postal addresses
  • Email addresses
  • Telephone/mobile numbers
  • Financial information
  • Employment information
  • Criminal convictions or pending legal actions against you
  • Any other information relating to individuals as required to provide our services and to run and develop our company
Our Lawful Basis

This section describes our lawful basis for processing:

We will only use your personal data for the purposes for which we collected it and as you would reasonably expect your data to be processed, and only where there is a lawful basis for such processing, for example:

Purpose/Activity Type of data Lawful basis for processing
To register you as a new customer a) Identity,
b) Contact,
c) Financial
a) Performance of a contract with you,
b) Consent,
c) In our legitimate interest
To process and deliver the products and services you request including digital signages, and to manage payments, fees, and charges. a) Identity,
b) Contact,
c) Financial,
d) Transaction,
e) Marketing and Communications
a) Performance of a contract with you,
b) Necessary for our legitimate interests to recover debts owed to us,
c) Consent
To manage our ongoing relationship with you which will include notifying you about changes to our terms, services or privacy policy, to maintain our records. a) Identity,
b) Contact,
c) Profile,
d) Marketing and Communications
a) Performance of a contract with you,
b) Necessary to comply with a legal obligation,
c) Necessary for our legitimate interests to keep our records updated and to study how customers use our services,
d) Consent
To administer and protect our business and our site (including troubleshooting, data analysis, testing, system maintenance, support, reporting, and hosting of data). a) Identity,
b) Contact,
c) Technical
a) Necessary for our legitimate interests for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise,
b) Necessary to comply with a legal obligation,
c) Consent
To use data analytics to improve our website, services, marketing, customer relationships and experiences. a) Technical,
b) Usage
a) Necessary for our legitimate interests to define types of customers for our services, to keep our site updated and relevant, to develop our business and to inform our marketing strategy,
b) Consent
To make suggestions and recommendations to you about services that may be of interest to you. a) Identity,
b) Contact,
c) Technical,
d) Usage,
e) Profile
a) Necessary for our legitimate interests to develop our services and grow our business,
b) Consent

Personal data we receive will be used for the purposes it was provided, including but not limited to:

  • To operate our consulting and market research services
  • To respond to queries from you regarding our services
  • To carry out our obligations arising from any contracts entered into between you and us including provision of services, and to respond to queries from you regarding those contracts
  • To manage and administer the relationships between you and us
  • To notify you about changes to our services and to otherwise communicate with you
  • To obtain feedback from you regarding us and our services
  • To manage data protection requests from clients and other third parties
  • To operate, develop, and protect our business

In accordance with your preferences, we may also use your personal information to provide you with information about services, promotions, and offers that may be of interest to you. This document explains how you can change whether to receive this information. Please note that even if you choose not to receive this information, we may still use your personal information to provide you with important services and communications, including communications in relation to any purchases you make or services you use.

How To Change Your Preferences

We operate in line with GDPR data protection guidelines. We respect your rights and will respond to any request for access to personal information and requests to delete, rectify, or transfer data, or to stop processing. We will also advise you on how to complain to the relevant authorities. Any requests or objections should be made in writing to the Data Controller, or you can visit our website, call, or email us to contact us to change your preferences at any time.

We may from time to time use your information for marketing, account management, or relationship management purposes. The main purpose of this is to provide you with information about services which we think may be of interest to you and/or to maintain any existing relationship we may have with you. You will be able to change your preferences at any time by the methods described in this document.

Where you give your consent for us to process your data you can contact us to amend or withdraw your consent at any time. You can also choose to object to processing and request deletion of your data. We respect all user rights as defined in GDPR. If you have any comments or wish to complain, please contact us.

How We Store & Process Your Data

Your data will be collected, stored, and processed primarily in the US and India. Where we transfer your data outside our borders, we will ensure we take appropriate precautions to protect this data. Your data will be stored only for as long as strictly necessary to ensure we have records of services and other interactions. For more information, please contact us about our Data Retention Policy.

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to find out more about how the processing for the new purpose is compatible with the original purpose, please email us. If we need to use your personal data for a purpose unrelated to the purpose for which we collected the data, we will notify you and we will explain the legal ground for processing.

We may be legally obliged to disclose your personal information without your knowledge to the extent that we are required to do so by law; in connection with any ongoing or prospective legal proceedings; in order to establish, exercise, or defend our legal rights (including providing information to others for the purposes of fraud prevention and reducing credit risk); to any person who we reasonably believe may apply to a court or other competent authority for disclosure of that personal information where, in our reasonable opinion, such court or authority would be reasonably likely to order disclosure of that personal information.

You will only receive marketing communications from us if you have:

  • Requested information from us
  • Used our services previously
  • Provided us with your details and ticked the box at the point of entry of your details for us to send you marketing communications
  • Not opted out of receiving marketing
  • Where we believe you will be interested in our services and we have a valid legitimate interest to process your information

We will get your express opt-in consent before we share your personal data with any third party for marketing purposes.

Our Obligations

We are a Data Controller. In relation to the information that you provide to us, we are legally responsible for how that information is handled. We will comply with the GDPR in the way we use and share your personal data.

Under certain circumstances, you have rights under data protection laws in relation to your personal data. These include the right to:

  • Request access to your personal data.
  • Request correction of your personal data.
  • Request erasure of your personal data.
  • Object to processing of your personal data.
  • Request restriction of processing your personal data.
  • Request transfer of your personal data.
  • Withdraw consent.

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. Alternatively, we may refuse to comply with your request in these circumstances.

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

Third Parties

We may have to share your personal data with the parties set out below for the purposes described in this document:

  • ZoomRx Healthcare Technology Solutions Private Ltd.
  • Service providers who provide IT and system administration services
  • Third parties including equipment providers, and other third parties as required to run our business
  • Professional advisers including lawyers, bankers, auditors ,and insurers who provide consultancy, credit scoring, banking, legal, fraud protection, insurance, and accounting services.
  • Third parties to whom we sell, transfer, or merge parts of our business or our assets.
  • Other companies as required to deliver our services to you, to operate our company, to grow and develop our business, and to protect our interests

Under the GDPR, we are also permitted to share some information with third parties who use such data for non-marketing purposes (including credit and risk assessment and management, identification and fraud prevention, debt collection, and returning assets to you).

We require all third parties to whom we transfer your data to respect the security of your personal data and to treat it in accordance with the law. We only allow such third parties to process your personal data for specified purposes and in accordance with our instructions.

Security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know such data. They will only process your personal data per our instruction, and they are subject to a duty of confidentiality.

We will report any breaches or potential breaches to the appropriate authorities within 24 hours and to anyone affected by a breach within 72 hours. If you have any queries or concerns about your data usage, please contact us.

This website may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit.

Cookies

A cookie is a small file which asks permission to be placed on your computer’s hard drive. Once you agree, the file is added, and the cookie helps analyse web traffic or lets you know when you visit a particular site. Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes, and dislikes by gathering and remembering information about your preferences. We use traffic log cookies to identify which pages are being used. This helps us analyse data about webpage traffic and improve our website in order to tailor it to customer needs. We only use this information for statistical analysis purposes, and then the data is removed from the system.

Overall, cookies help us provide you with a better website experience by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us.

You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. This may prevent you from taking full advantage of the website.

As well as your ability to accept or reject cookies, we also require your permission to store cookies on your machine, which is why when you visit our site, you are presented with the ability to accept our terms of use, including the storage of cookies on your machine. Should you not accept, then you are free to leave our website at any time.

For California, Virginia, Colorado, Utah, and Connecticut residents

Your Rights Under the California Consumer Protection Act, Virginia Consumer Data Protection Act, Colorado Privacy Act, Utah Consumer Privacy Act, and Connecticut Data Privacy Act pursuant to the state regulations, and subject to certain exceptions and limitations, residents of the above states can contact ZoomRx to exercise the rights described below with respect to certain personal information that ZoomRx holds about them. To the extent those rights apply to you, they are described below. ZoomRx also handles certain personal information on behalf of ZoomRx customers. You should contact those customers to exercise any rights you may have with respect to that personal information.

Right to Know About Personal Information Collected, Disclosed, or Sold

You have the right to request that we provide you with details about the personal information we collect, use, disclose and sell. ZoomRx reserves the right to verify your identity to our satisfaction, including by asking you to log into your account if you have one.

You are entitled to receive the following:

  • The categories of your personal information that ZoomRx has collected in the preceding 12 months
  • The categories of sources from which that information was collected
  • The business/commercial purpose for the collection or selling
  • The categories of third parties with whom ZoomRx shares personal information
  • The specific pieces of personal information ZoomRx has collected about you (subject to some exceptions)

Because ZoomRx has disclosed or sold personal information to third parties in the last 12 months, you are also entitled to receive:

  • The categories of personal information that ZoomRx has disclosed or sold in the past 12 months
Right to Request Deletion of Personal Information

You have the right to request deletion of the personal information we have collected about you (subject to some exceptions). You can submit your request as described above, and we reserve the right to conduct the verification described above.

Right to Non-Discrimination for the Exercise of a Consumer’s Privacy Rights

You have the right not to receive unlawful discriminatory treatment by ZoomRx for the exercise of your privacy rights.

Right to Opt-Out of Sale of Personal Information

You have the right to opt-out of the sale of your personal information by ZoomRx. You may request to opt-out by sending an email to kendall.anderson@zoomrx.com.

List of Categories of Personal Information to be Collected and May Have Been Sold or Disclosed
Categories of Personal Information Collecte

ZoomRx collects personal information from research participants during and after registration with a panel, including, without limitation, during participation in a survey and in connection with the receipt and redemption of rewards and incentives and/or during the Application/Services registration and download process.

The categories of personal information we may collect include:

“Identifiers” such as:

  • Name
  • Address(es)
  • Telephone number(s) (including home, cell, and/or business telephone numbers)
  • Email address(es)
  • Internet Protocol address
  • Unique device identification number (such as identifiers for analytics or advertising)
  • Network provider user ID (a number uniquely allocated to you by your network provider)
  • Media Access Control (MAC) address
  • Unique cookie identifiers
  • Internet or other electronic network activity information, and other information collected through automated means such as:
  • Information about your device (e.g., device operating system, the other applications on your device, device network provider, device type, time zone, network status, browser type, browser identifier and other information that alone or in combination may be used to uniquely identify your device)
  • Geolocation
  • Cookies and similar technology
  • Social media information
  • Log files
  • Digital fingerprinting
  • Watermarking
  • Browsing activity
  • Other behavioral information
  • Professional or employment-related information, including occupation
  • Education information
  • Additional content/material you submit, including photos, videos and/or similar content
  • Characteristics of potentially protected classifications under federal or international law (e.g., health and medical conditions, sexual orientation or sexual life, political opinions/views, race/ethnic origin, gender, religious and philosophical beliefs and trade-union membership)
  • Other medical information
  • Demographic information

All of the information above was collected for the purposes described. These purposes, which are described further in that section of our Privacy Policy, include but are not limited to the following examples:

  • Auditing related to a current interaction with you and concurrent transactions, including, but not limited to, counting ad impressions to unique visitors, verifying positioning and quality of ad impressions;
  • Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and prosecuting those responsible for that activity;
  • Debugging to identify and repair errors that impair existing intended functionality;
  • Short-term, transient uses;
  • Performing or using services, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing or using advertising or marketing services, providing or using analytic services, or providing or using similar services;
  • Undertaking internal research for technological development and demonstration;
  • Undertaking activities to verify or maintain the quality or safety of services and devices, and to improve, upgrade, or enhance services and devices; and
  • Facilitating the operational purposes of ZoomRx or our service providers.
Categories of Personal Information that May Have Been Sold

ZoomRx sold all of the above categories of personal information in the last 12 months.

Categories of Personal Information that Were Disclosed

ZoomRx disclosed all of the above categories of personal information in the last 12 months.

Information for European territory residents: Our legal bases and your rights

Our Legal Basis: If you interact with our Services or Website while within the European Economic Area, Switzerland or the United Kingdom (the “European Territories”), our legal basis for processing the personal data as described hereunder may vary depending on the personal data at issue as well as the context in which we collect it.

Ordinarily, we process personal data about you in reliance on your consent or on legitimate interest. We may also process data to comply with our legal obligations, or to fulfill a contract you have entered into with us.

To contact us with any questions regarding the legal bases we rely on for processing your personal data, please email ZoomRx's Data Protection Lead, Kendall Anderson, at kendall.anderson@zoomrx.com. You may also contact us at the following addresses:

ZoomRx Inc.
245 Main Street, Floor 2
Cambridge, MA 02142, USA

 

ZoomRx Healthcare Technology Solutions Private Limited
No. 40 Global Infocity Park, 2nd Floor, Block B, MGR Salai, Kandanchavadi, Perungudi, 600096

European Residents' Privacy Rights: Residents of a European Territory have the following data subject rights under European Territory data protection law:
  • You have the right to access, correct, update or request deletion of your personal data. To submit a request to exercise those rights, you may contact our Data Protection Lead at kendall.anderson@zoomrx.com for more information.
  • You have the right to object to our processing your personal data. To submit a request to exercise that right, or to otherwise restrict our processing of your personal data, you may contact our Data Protection Lead at kendall.anderson@zoomrx.com for more information.
  • If we are relying on your consent to process your personal data, you have the right to withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any personal data processing prior to such withdrawal, nor will it affect any personal data processing that we undertake in reliance on legal bases other than consent (such as legitimate interests).
  • You have the right to complain to a data protection authority about our collection and use of your personal data. Please contact our Data Protection Lead at kendall.anderson@zoomrx.com with any questions you may have and before making a complaint so that we may answer any questions you have and attempt to assist you in resolving the basis for your complaint. If you do choose to make a complaint, contact details for data protection authorities in the European Territories are available from the European Data Protection Board website.

In some cases, we act as a processor for our Customers. In cases where we act as a processor, you should direct any requests to exercise your data protection rights to the relevant Customer or User of our Service, not to us. If you are uncertain whether we process your personal data as a controller or a processor in any specific context, you can contact our Data Protection Lead at kendall.anderson@zoomrx.com for more information.

International transfers

ZoomRx's Services and Website are hosted in the United States. If you use ZoomRx’s Services or visit the Website from a European Territory, Asia, or any other region with laws or regulations governing personal data collection, use, and disclosure that differ from United States laws, you understand that through your continued use of the Services or Website you may be transferring your personal information to the United States and if so, you consent to that transfer. Additionally, you understand that your personal information and the information you provide may be processed in countries (including the United States) where laws regarding processing Personal Information may be less stringent than in your country.

Please do not provide information to us unless you have the proper consents required in the country in which the information was collected.

Compliance with the Data Privacy Framework

ZoomRx complies with the EU-U.S. Data Privacy Framework (“EU-U.S. DPF”), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (“Swiss-U.S. DPF”) as set forth by the U.S. Department of Commerce.

ZoomRx adheres to the EU-U.S. DPF Principles with regard to personal data transferred from the European Union and the United Kingdom and the Swiss-U.S. DPF Principles with regard to personal data transferred from Switzerland.

ZoomRx has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (“EU-U.S. DPF Principles”) with regards to the processing of personal information received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. ZoomRx has also certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (“Swiss-U.S. DPF Principles”) with regards to the processing of personal information received from Switzerland in reliance on the Swiss-U.S. DPF.

If there is any conflict between the terms in this Privacy Policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (“DPF”) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.

Types of personal information, purposes, rights and more

This Privacy Policy sets out:

  • The types of individuals about whom ZoomRx collects personal information
  • The types of personal information ZoomRx collects
  • The purposes for which ZoomRx processes personal information
  • The recipients to whom ZoomRx discloses personal information
  • Your privacy rights and how to exercise them; and
  • How we can be contacted
Complaints

In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, ZoomRx commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU and UK and Swiss individuals with inquiries or complaints regarding our handling of personal information received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF should first contact ZoomRx’s Data Protection Lead at kendall.anderson@zoomrx.com

Dispute resolution

In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, ZoomRx commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (“DPAs”) and the UK Information Commissioner’s Office (“ICO”) and the Gibraltar Regulatory Authority (“GRA”) and the Swiss Federal Data Protection and Information Commissioner ("FDPIC") with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF.

Arbitration

You have the possibility, under certain conditions, to invoke binding arbitration for complaints regarding DPF compliance not resolved by any of the other mechanisms set out in this Privacy Policy. For more information, please see here

Jurisdiction

The Federal Trade Commission has jurisdiction over ZoomRx's compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF.

Disclosures to public authorities

ZoomRx may, from time to time, be required to disclose personal information it receives under the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

Liability for onward transfers

ZoomRx is liable for the processing of personal information it receives under the DPF Principles and subsequently transfers to a third party acting as an agent on its behalf. ZoomRx shall remain liable under the DPF Principles if its agent processes such personal information in a manner inconsistent with the DPF Principles, unless ZoomRx proves that it is not responsible for the event giving rise to the damage.

Contacting Us, Exercising Your Information Rights & Complaints

If you have any questions or comments about this Privacy Policy, wish to exercise your information rights in connection with the personal data you have shared with us, or wish to complain, please contact:

Email: kendall.anderson@zoomrx.com

Address: ZoomRx, 245 Main Street, Floor 2, Cambridge, Massachusetts, 02142, US

No. 40 Global Infocity Park, 2nd Floor, Block B, MGR Salai, Kandanchavadi, Perungudi, 600096

We will process data protection requests within 30 days. Subject Access Requests (SARs) are usually free, but we reserve the right to charge for excessive or unfounded requests. We fully comply with Data Protection legislation and will assist in any investigation or request made by the appropriate authorities. If you remain dissatisfied, then you have the right to apply directly to the relevant Supervisory Authority.