Oncurate Privacy Policy

Effective Date: September 12th 2023

1.0 Introduction

Oncurate is a technology company headquartered in Clarendon Hills, Illinois, USA which focuses on providing services to the medical and healthcare community.

For more information about our services, please refer to our website:

https://www.oncurate.com

This Privacy Policy is applicable to Oncurate (“we,” “our,” or “us”) as related to our services, which collectively include:

This Privacy Policy sets out the essential details relating to your personal data relationships with Oncurate as:

  • A website visitor
  • An end user of the application (“end user”)
  • A prospective client
  • A job applicant and
  • Partners

Clients contract the use of our application and give access to their employees and other third parties, as solely decided by them, by creating users who access the application with their email address and credentials. The clients’ administrators grant end users roles, which result in different permissions and access rights to the information held in the Client account.

2.0 Personal Information We Collect 

2.1 Information You Choose to Provide to Us

WHEN

We may ask you to provide personal information when:

  • You use the website to download articles, data sheets or eBooks.
  • You request a free trial or demo.
  • You refer a friend to us.
  • You connect with us directly via phone calls or video conferencing platforms.
  • We or Client Account Administrators grant you access to the application.
  • You or Client Account Administrators upload or enter personal information into the application.
  • You participate in a marketing or sales promotion.
  • You attend trade events and other industry networking events.
  • You register or attend a webinar or other event.
  • You participate in programs we may offer from time to time.
  • You participate in chats.
  • You pay for our services.

If you choose to provide us with a third-party’s personal information (the person’s name, email and company) when taking part in our referral program, you represent that you have the third-party’s permission to do so.

WHAT

We collect personal information that may include first and last name, business email address, phone number and/or company name.

As an end user of the application, we collect your name, business email address and any comments you make in the application.

In addition, we may collect data uploaded by you, your employer or other users of the application that may be required to use Oncurate services. We expect all users to follow their organization’s privacy policy and any applicable regulatory requirements when uploading, accessing and using personal information into our application. The data uploaded may include personal information like:

  • Employee names, email addresses and contractual agreements
  • Vendor names, email addresses, contractual agreements or other personal data necessary for Oncurate services
  • Customer names and email addresses used to provide services within Oncurate’s platform

As a job applicant, we may also collect your resume and cover letter.

Further information, including specific obligations of the Oncurate, can be found in the Service and/or Data Processing Agreements.

2.2 Information We Collect Automatically

WHEN

We collect information about your visits to the website and the application when you land on any of our web pages through cookies and similar tracking technology.

WHAT

The information collected includes:

  • access times
  • the pages you view
  • the links you click on
  • the search terms you enter
  • actions you take in connection with any of the visited pages
  • your device information such as IP address, location, browser type and language
  • the Uniform Resource Locator (URL) of the website that referred you to our website and
  • the URL you browse away from our pages if you click on an external link

We may also collect information when you open email messages from us or click on links within those email messages.

2.3 Information We May Collect From Third Parties

WHEN

We may combine the information we collect from your direct interactions with us with information obtained through other third-party sources, such as Google and HubSpot. We also obtain and/or purchase lists from third parties about individuals and companies interested in our products.

WHAT

The personal information collected includes your name, email address, business address, job title, company name, and telephone number.

3.0 How We Use Personal Information

We use your personal information to:

  • Deliver the contracted services and allow full use of the application functionality as purchased by the clients.
  • Deliver training and support to our application end users and/or carry out the transactions you have requested.
  • To communicate with you directly through emails, calls, chats and video conferencing.
  • Process payments for application subscriptions.
  • Send communications to you about:
    • New application features and upgrades.
    • Our services and offerings.
    • Event announcements.
    • Product notices and changes to our terms and policies.
    • Particular programs in which you have chosen to participate.
    • Promotional offers and surveys.
    • Scheduling demos and managing free trials.
  • Advertise and market our products and services, including delivering interest-based advertisements on this website and other sites or content syndication platforms and websites.
  • Carry out market research to understand how to improve our services and their delivery.
  • Create and manage marketing campaigns.
  • Generate sales leads and increase our market share.
  • Analyze user clicks and usage of the application and website to improve user experience and maximize usage of our services.
  • Manage our website and application to maintain and deliver the contracted functionality and services.
  • Enforce our website and application terms and/or separate contracts (if applicable) with you
  • Prevent fraud and other prohibited or illegal activities.
  • Protect the security or integrity of the website, application, our business or services.
  • Or otherwise, as disclosed to you at the point of collection or as required or permitted by law.

Please note that sometimes we may record the video conferencing call in which you participate to analyze and improve our staff’s communication skills. If we do so, we will be announcing it at the beginning of the conference call and in the meeting invite, and we will be providing a link to our Privacy Policy in the meeting invites and on the registration page.

We do not sell your information to any third party.

4.0 How We Share Personal Information

Our Application and Services

If you are an end user of our application, your personal information may be viewed by other users with access to the application.

Service Providers

We use third parties to help us provide our services. They will have access to your information as collected by the website or the application, as reasonably necessary to perform the contracted tasks on our behalf. We sign contractual agreements to obligate them to protect the personal information, only use it to deliver the contracted services to us, prohibit them from selling it and not disclose it without our knowledge and permission.

Service Provider NameBusiness PurposeInformation Collected by the Service ProviderData Location
Google AnalyticsWebsite analyticsIP address, browser version, URL visitedGoogle Analytics
HubSpotWebsite analyticsIP address, browser version, URL visited, email addressHubSpot
SentryApplication analyticsIP address, browser version, URL visited, email addressSentry

It is possible that we may need to disclose personal information when required by law, subpoena or other legal processes as identified in the applicable legislation.

We attempt to notify our clients about legal demands for their personal data when appropriate in our judgment unless prohibited by law or court order or when the request is an emergency.

Change in Control

We can also share your personal data as part of a sale, merger, change in control or in preparation for any of these events.

Any other entity which buys us or part of our business will have the right to continue to use your data, but only in the manner set out in this Privacy Policy unless you agree otherwise.

5.0 How We Secure Personal Information

We are committed to protecting the security of all of the personal information we collect and use.

We use a variety of physical, administrative and technical safeguards designed to help protect it from unauthorized access, use and disclosure. We have implemented best-practice standards and controls in compliance with internationally recognized security frameworks. We use encryption technologies to protect data at rest and in transit.

6.0 Your Rights

We provide the same suite of services to all of our clients and end users worldwide.

We offer the following rights to all individuals regardless of their location or applicable privacy regulations.

For personal information we have about you, you can:

  • Access your personal information or request a copy.

You have the right to obtain information about what personal information we process about you or to obtain a copy of your personal information.

If you have provided personal information to us, you may contact us to obtain an outline of what information we have about you or a copy of the information.

If you are an end user of the application, you can log in to see the personal information in the account or approach your employer for more information.

  • You have the right to be notified of what personal information we collect about you and how we use it, disclose it and protect it.

This Privacy Policy describes what personal information we collect and our privacy practices. We may also have additional privacy notices and statements available to you at the point of providing information to us directly.

  • Change or correct your personal information.

You have the right to update or correct your personal information or ask us to do it on your behalf.

You can edit your information through the user account in the application or ask us to change or correct it by contacting us at [email protected].

  • Delete or erase your personal information.

You have the right to request the deletion of your personal information at any time. We will communicate back to you within reasonable timelines the result of your request. We may not be able to delete or erase your personal information, but we will inform you of these reasons and any further actions available to you.

  • Object to the processing of your personal information.

You have the right to object to our processing of your personal information for direct marketing purposes. This means that we will stop using your personal information for these purposes.

  • Ask us to restrict the processing of your personal information.

You may have the right to ask us to limit the way that we use your personal information.

  • Export your personal data.

You have the right to request that we export to you in a machine-readable format all of the personal information we have about you.

We do not process personal information through the use of automated means.

If you would like to exercise any of the rights described above, please contact us at [email protected].

You also have the right to lodge a complaint with the local organizations in charge of enforcing the privacy legislation applicable in your territory.

7.0 How Long We Keep Your Personal Information

We retain information as long as it is necessary to provide the services to you and our clients, subject to any legal obligations to further retain such information.

We may also retain information to comply with the law, prevent fraud, collect fees, resolve disputes, troubleshoot problems, assist with investigations, enforce our Terms of Service and take other actions permitted by law.

The information we retain will be handled following this Privacy Policy.

Information connected to you that is no longer necessary and relevant to provide our services may be de-identified or aggregated with other non-personal data. This information may provide insights that are commercially valuable to Oncurate, such as statistics of the use of the services.

8.0 Other Important Information

We process data in locations in the United States and rely on legally-provided mechanisms to lawfully transfer data across borders, such as contracts incorporating data protection and sharing obligations. We provide the capability for the return, transfer and/or disposal of personal data in a secure manner.

We will only collect and process your personal data where we have a lawful reason for its collection.

When you visit our website and provide us with your personal information, we collect and use it with your consent.

As an application end user, you consent to our collection of your personal information when you log in for the first time. However, your employer has control of the account and may upload and share additional personal information. Your employer’s responsibility is to ensure that collecting, using and sharing the personal information uploaded to the application complies with all applicable legislation.

You can review the terms and conditions of use here: https://www.oncurate.com/terms

Where we rely on your consent to process personal data, you have the right to withdraw or decline your consent at any time. If you have any questions about the lawful bases upon which we collect and use your personal data, please contact us at [email protected].

How to select your communications preferences 

You may choose to receive or not receive marketing communications from us. Please click the “Unsubscribe” link in the email we sent you to stop receiving marketing communications.

You may choose which information we collect automatically from your device by controlling cookie settings on your browser or by selecting your preferences through our cookie policy management tool.

Even if you opt-out of receiving marketing communications, we may still communicate with you regarding security and privacy issues, servicing your account, fulfilling your requests, or administering any promotion or any program in which you may have elected to participate.

9.0 Contact Information

You may contact us to exercise any of your rights or ask for more information about your personal information and our privacy practices by contacting us at [email protected].

Appendix 

A.1 For Individuals Based in the  European Economic Area (EEA), United Kingdom (UK) and Switzerland

If you are based in one of these jurisdictions, Oncurate is the controller of your personal data collected in the following instances:

Oncurate is a processor of all personal data processed on the application, on behalf of our clients. We only process the personal data under their direction. Please contact your employer or the organization that granted you access to the application for details on their privacy practices.

We only process personal data if we have a lawful basis for doing so. The lawful bases applicable to our processing as controller are:

  • Consent: We will ask for your express and informed consent every time we collect your personal data on this legal basis.
  • Contractual basis: We process the personal data as necessary to fulfill our contractual terms with you or our clients.
  • Legitimate interest: We process the names, contact details, job titles, companies of our existing and prospective clients for our marketing purposes, including market research and sales leads generation.

You have the following rights under the GDPR:

  • Be informed about the collection and use of your personal data
  • Access your personal data
  • Correct errors in your personal data
  • Erase your personal data
  • Object to the processing of your personal data.
    • This right is also available to individuals whose personal data is processed by us for direct marketing purposes. If you object to the processing of your personal data for direct marketing purposes, we shall stop processing within 30 days of receipt of your request.
  • Export your personal data
  • Restrict our processing of your personal data for specific reasons, including any of the purposes supported by the legitimate interest legal bases (see the section above).
  • Not to be subject to a decision based solely on automated decision making

We process personal data in the United States and share it with our service providers in the United States and other jurisdictions. We use standard contractual clauses, approved by the European Commission or competent UK authority (as applicable), as the data transfer mechanism for transferring personal data from the EEA or UK to other countries subject to data transfer requirements. See the table of our service providers here.

You may contact us at [email protected].

You may also lodge a complaint with your local supervisory authority:

  • EU Data Protection Authorities (DPAs). See their contact details here National Data Protection Authorities.
  • Information Commissioner’s Office (ICO)
  • Swiss Federal Data Protection and Information Commissioner (FDPIC).

A.2 For Individuals Based in The United States 

Under the California Privacy Rights Act (‘CPRA’) – which amended and expanded on CCPA, Connecticut Data Privacy Act (‘CTDPA’),  Virginia Commonwealth Data Protection Act (‘CDPA’), Utah Consumer Privacy Act (‘UCPA’), and the Colorado Privacy Act (‘CPA’), consumers may be able to exercise the following rights in relation to the personal information about them that we have collected (subject to certain limitations at law):

  • The right to access/know any or all of the information relating to your personal information that we have collected, processed or disclosed in the preceding 12 months (upon verification of your identity). For details on the categories of personal information we have collected and/or shared, refer to section “2.0 Personal Information We Collect” and “4.0 How We Share Personal Information” in the notice. Oncurate will provide a copy of the consumer’s personal data in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance.
  • The right to request the deletion of personal information we have collected from you.
  • The right to opt-out of personal information sales to third parties now or in the future. However, we do not sell your personal information.
  • The right to opt-in to personal information sales to third parties for consumers under the age of 16. However, we do not sell personal information of minor consumers.
  • The right to opt-out of sharing of personal information to third parties now or in the future. To view the information we have shared in the preceding 12 months, refer to section “4.0 How We Share Personal Information” in the notice.
  • The right to request rectification/correction of inaccurate personal information, considering the nature and purposes of the processing of the information. (Not Applicable under UCPA)
  • The right to limit use and disclosure of sensitive personal information to that which is necessary to perform the services or provide the goods reasonably expected by an average consumer. (Applicable under CCPA, as amended by CPRA)
  • The right to opt-out of the processing of sensitive personal information (i.e., data that reveals ethnic or racial origin, mental or physical health diagnosis, religious beliefs, sexual orientation, or citizenship or immigration status. (Applicable under UCPA)
  • The right to opt-out of targeted advertising. (Applicable under CPA, CTDPA, UCPA, VCDPA)
  • The right to opt-out of profiling in connection with automated decisions. (Applicable under CPA, CTDPA, UCPA)

Please note that if exercising these rights limits our ability to process personal information (such as a deletion request), we may no longer be able to provide you with our products and services or engage with you in the same manner. Additionally, Oncurate has established processes (including reviewing business processes, systems and resources on a periodic basis) to ensure consumers who exercise any of the above rights under US state privacy laws are not discriminated against.

A.2.1 How to Exercise Your Consumer Rights

To exercise any of your right mentioned above, please submit a request by contacting us at [email protected].

We will need to verify your identity before processing your request.

In order to verify your identity, we will generally require sufficient information from you so that we can match it to the information we maintain about you in our systems. Sometimes we may need additional personal information from you to be able to identify you. We will notify you.

We may decline a request where we cannot verify your identity or locate your information in our systems or as permitted by law. In this case, we may request that you provide additional information reasonably necessary to authenticate you and your request.

You may choose to designate an authorized agent to make a request under the CCPA on your behalf. No information will be disclosed until the authorized agent’s authority has been reviewed and verified. Once an authorized agent has submitted a request, we may require additional information (i.e., written authorization from you) to confirm the authorized agent’s authority.

If you are an employee/former employee of a Oncurate client that uses our application and services, please direct your requests and/or questions directly to your employer or former employer.

If you are a third party (auditor, business associate, etc.), who was given access to the Oncurate application by a Oncurate client, please direct your requests and/or questions directly to the Oncurate client that gave you access.

If Oncurate does not take action on your Consumer Rights Request within the 45 days, or in the event of an extension, within the maximum 90-day response period, we will inform you in writing of the reasons for not taking action, as well as provide an explanation of any rights you have to appeal the decision. For opt-out or limit use and disclosure requests submitted under the CCPA, Oncurate will respond as soon as feasibly possible, with up to a maximum of 15 days.

For consumers residing in Virginia, within 60 days of receipt of an appeal, and for consumers residing in Colorado, within 45 days of receipt of an appeal, Oncurate will inform the consumer, in writing, of any action taken/not taken in response to the appeal, including an explanation of the reasons for the decisions. If the appeal is denied, Oncurate will provide consumers with an online mechanism, if available, or another method which allows the consumer to contact the Attorney General to submit a complaint.

Minors Under Age 16

Our application and services are intended for business use, and we do not expect them to be of any interest to minors. We do not intentionally collect any personal information of consumers below the age of 13. If you believe that a child under 13 may have provided us their Personal Information, please contact us at [email protected].

A.3  For Individuals Based in Australia

This section is applicable to individuals whose personal information is collected, stored, used or disclosed by an APP Entity under the Australian Privacy Principles (“APPs”) contained in the Privacy Act of 1988.

A.3.1 Providing Anonymous and Pseudonymous Options

You have the option of anonymity or using a pseudonym when dealing with Oncurate. However, this option may not be made available to you in certain cases, including if it’s impractical for Oncurate to allow this option or when Oncurate is required or authorized to deal with an identified individual by or under the law.

A.3.2 Collection, Use and Disclosure of Personal Information 

Oncurate collects personal information only by lawful and fair means. Additionally, Oncurate collects personal information directly from you or your authorized representative, unless we have your consent for collection from another source (i.e., third parties), it is required or authorized by law, or it is unreasonable to collect the information only from you. Oncurate may collect ‘sensitive information’ about you where you have consented to the collection and it is reasonably necessary for one of our functions or activities or if it is required or authorized by law.

Oncurate only uses and discloses your information for the purpose for which it was collected (the primary purpose) unless one or more of the following apply:

  • You have consented
  • You would reasonably expect the secondary purpose
  • It is required or authorized by or under law
  • Oncurate believes that it is reasonably necessary for an enforcement body’s activities

We disclose your personal information with our service providers in the United States and other jurisdictions. We do not disclose your personal information to any overseas recipients unless one of the following applies:

  • You have consented to the disclosure
  • The recipient is subject to a law or binding scheme substantially similar to the APPs, and you can enforce that law/binding scheme
  • It is required or authorized by law
  • It is required or authorized by an international agreement relating to information sharing
  • It is reasonably necessary for an enforcement body’s or similar entity’s activities

See the table of our service providers here.

A.3.3 Your Rights Under the APPs

You have the following rights related to the collection, use and disclosure of your personal data:

  • Be informed about the collection and use of your personal data
  • Access your personal information
  • Correction of your personal information to ensure accuracy and completeness
  • Request to not receive direct marketing communications from us or to not disclose your personal information to others for direct marketing purposes

If you wish to access your personal information or correct that information, please contact us at [email protected]. You may opt-out (unsubscribe) of receiving marketing communications by using the links provided in our emails. If you are unable to find the opt-out instructions, please contact us at [email protected] for assistance.

If you are concerned about Oncurate’s handling of your personal information, you may lodge a complaint in writing to the email address listed above and we will provide a written response to your complaint within a reasonable time (30 days).

You may also complain directly to the Office of the Australian Information Commissioner (OAIC) by:

  • Email: [email protected] (be aware that email isn’t encrypted, if you’re concerned about this, use the online form on OAIC’s website which is secure)
  • Mail: GPO Box 5218, Sydney NSW 2001 (send it by registered mail if you’re concerned about sending it by standard post)
  • Fax: 02 9284 9666