Legal
Privacy Policy
Innocens BV · Version 01
1. Controller and contact
The controller for the processing described in this document is:
Innocens BV, a besloten vennootschap incorporated under Belgian law, with registered office at Sterstraat 18, 2000 Antwerp, Belgium, registered in the Register of Legal Persons Antwerp, division Antwerp, under enterprise number 0777.424.019, VAT BE 0777.424.019 ("Innocens", "we", "us").
Email: info@innocens.be
Data Protection Officer: Charlie Beirnaert, dpo@innocens.be
Any question about this policy, and any request to exercise a right described in section 7, should be directed to dpo@innocens.be.
2. Personal data we collect
When you contact us or book a call
Name, professional email address, telephone number, employer and role, and the content of the message you send or the meeting you book.
When you correspond with us by email
The content and metadata of that correspondence.
When you visit our website
IP address, browser and device type, operating system, referring page, pages viewed, and the date and time of the visit. Some of this is collected through cookies and similar technologies, described in the Cookie Policy.
When you apply for a job
Curriculum vitae, covering letter, education and work history, and anything else the applicant chooses to send. Where an applicant is invited to interview, our notes and assessment of the application.
When we contact you first
Name, role, employer and professional contact details, obtained from the employer website, professional networks, conference materials, publications or a mutual contact.
Special categories of data
We do not knowingly collect health data or any other special category of personal data through our website. Visitors are asked not to include patient information in a contact form or in email to us.
3. Purposes and legal bases
We process personal data for the following purposes, on the legal bases stated:
• Responding to an enquiry and arranging meetings: Article 6(1)(b), steps prior to a contract, or Article 6(1)(f), legitimate interest.
• Managing our relationship with customers, partners and suppliers: Article 6(1)(b) or Article 6(1)(f).
• Business development contact with healthcare professionals and institutions: Article 6(1)(f), our legitimate interest in offering clinical software to the professionals for whom it is intended.
• Assessing a job application: Article 6(1)(b), steps prior to a contract at the applicant's request.
• Keeping an application on file for future roles: Article 6(1)(a), consent, requested separately from the application itself.
• Non-essential cookies, website analytics and advertising measurement: Article 6(1)(a), consent.
• Website security, abuse prevention and logging: Article 6(1)(f).
• Meeting our legal, accounting and regulatory obligations: Article 6(1)(c).
Where we rely on legitimate interest we have weighed that interest against the rights and freedoms of the data subject. A data subject may object at any time, as described in section 7.
4. Recipients and processors
We use service providers who process personal data on our behalf. They act only on our documented instructions and under a written data processing agreement meeting the requirements of Article 28 GDPR. The categories of recipient are:
• Providers of website hosting and publishing.
• Providers of email, productivity and file storage.
• Providers of customer relationship management and meeting scheduling tools.
• Providers of website analytics, where consent has been given.
• Providers of advertising and campaign measurement, where consent has been given.
We also share personal data with our professional advisers and auditors where necessary, and with public authorities and notified bodies where the law requires it.
We do not sell personal data. Where a visitor has consented to advertising cookies, the provider named in our Cookie Policy receives data through those cookies for campaign measurement and remarketing. We do not otherwise share personal data for third party advertising.
The internal record identifying each individual processor, its role and the status of its data processing agreement is maintained in the Record of Processing Activities and is not published.
5. International transfers
Some of our providers process personal data outside the European Economic Area. Where that happens we rely on one of the following:
• An adequacy decision of the European Commission, including certification under the EU-US Data Privacy Framework where applicable.
• The European Commission Standard Contractual Clauses, combined with a transfer impact assessment and appropriate additional technical measures.
Details of the safeguards in place for a specific transfer are available on request from dpo@innocens.be.
6. Retention
We keep personal data no longer than is necessary for the purposes set out in section 3. The criteria we apply are:
• Enquiries that do not lead to a relationship: kept while there is a realistic prospect of further contact, then deleted.
• Business contacts and correspondence: kept for the duration of the relationship, and thereafter for as long as the record may be needed to establish, exercise or defend a legal claim.
• Job applications: kept for the duration of the recruitment process. Where an applicant is not appointed, the application is deleted afterwards unless the applicant has consented to it being kept on file for future roles.
• Website, server and security logs: kept for the standard period applied by our website platform.
• Records subject to statutory retention, including accounting and regulatory records: kept for the period prescribed by law.
7. Rights of data subjects
Rights available
Under the GDPR a data subject has the right to obtain access to their personal data, to have it rectified, to have it erased, to restrict processing, to data portability, and to object to processing based on legitimate interest. Where processing is based on consent, that consent may be withdrawn at any time, which does not affect the lawfulness of processing carried out before the withdrawal.
A data subject also has the right to lodge a complaint with a supervisory authority. In Belgium this is the Gegevensbeschermingsautoriteit, Drukpersstraat 35, 1000 Brussels, contact@apd-gba.be. A complaint may also be lodged with the authority in the data subject's country of residence or work.
Handling a request
Send a request to dpo@innocens.be. We confirm the identity of the requester where there is reasonable doubt, and we respond within one month of receipt. Where a request is complex we may extend that period by up to two further months, and we tell the requester about the extension and its reason within the first month.
8. Patient data and clinical use of our software
This document does not apply to patient data processed within the Intellicens Data Platform or Intellicens Neo.
Where our software is deployed in a healthcare institution, that institution is the controller of the patient data. Innocens acts as a processor and processes that data only on the institution's documented instructions, under a data processing agreement concluded with that institution and under our quality management system. The Intellicens Data Platform is designed to run on the institution's own infrastructure, inside its own security perimeter.
A patient with a question about data held by a healthcare institution that uses our software should contact the data protection officer of that institution.
9. Automated decision making
We do not carry out automated decision making producing legal effects concerning a data subject, or similarly significantly affecting them, on the basis of personal data collected through our website.
10. Changes to this document
This document is subject to document control. Any change is made in this master document, approved in accordance with the approval table on the first page, and only then reflected on the published web page. Material changes are announced on that page.