Erepsonline Pty Ltd understands that your privacy is important to you and that you care
about how your information is used and shared online. We respect and value the privacy of
everyone who visits Our Site and will only collect and use information in ways that are useful
to you and in a manner consistent with your rights and Our obligations under the law.
This Policy applies to Our use of any and all data collected by us in relation to your use of
Our Site. Please read this Privacy Policy carefully and ensure that you understand it. You will
be required to read and accept this Privacy Policy when signing up for an Account. If you do
not accept and agree with this Privacy Policy, you must stop using Our Site immediately.
-
Definitions and Interpretation
In this Policy the following terms shall have the following meanings:
“Account” |
means an account required to access and/or use
certain areas and features of Our Site; |
“Cookie” |
means a small text file placed on your computer or
device by Our Site when you visit certain parts of
Our Site and/or when you use certain features of Our
Site. Details of the Cookies used by Our Site are set
out in section 12, below; |
“Our Site” |
means this website, www.erepsonline.com; |
“Australia and EU Cookie Law” |
means the relevant parts of the Privacy and
Electronic Communications (EC Directive)
Regulations 2003 as amended in 2004, 2011 and
2015; and]
|
“We/Us/Our” |
Means Thirty Seven, Inc. of Los Angeles, CA |
-
Information About Us
- Our Site, www.erepsonline.com is owned and operated by Thirty Seven, Inc of Los Angeles, CA.
-
Our data protection officer is Brett Jarosz who can be contacted at
[email protected]
-
Scope – What Does This Policy Cover?
This Privacy Policy applies only to your use of Our Site. It does not extend to any
websites that are linked to from Our Site (whether We provide those links or whether
they are shared by other users). We have no control over how your data is collected,
stored or used by other websites and We advise you to check the privacy policies of
any such websites before providing any data to them.
-
What Data Do We Collect?
Some data will be collected automatically by Our Site, other data will only be
collected if you voluntarily submit it and consent to Us using it for the purposes set
out in section 5, for example, when signing up for an Account. Depending upon your
use of Our Site, We may collect some or all of the following data:
- Name;
- date of birth;
- business/company name
- title;
- qualifications/post-nominals;
- contact information such as email addresses and telephone numbers;
- demographic information such as post code;
- financial information such as credit / debit card numbers;
-
How Do We Use Your Data?
- All personal data is stored securely in accordance with the EU General Data
Protection Regulation (Regulation (EU) 2016/679) (GDPR). For more details on
security see section 6, below.
-
We use your data to provide the best possible products and services to you.
This includes:
- Providing and managing your Account;
- Providing and managing your access to Our Site;
- Personalising and tailoring your experience on Our Site;
- Supplying Our services to you;
- Personalising and tailoring Our services for you;
- Responding to communications from you;
- Supplying you with email e.g. newsletters, alerts etc. that you have
subscribed to (you may unsubscribe or opt-out at any time by the
unsubscribe link in the email or by telling us as [email protected];
- In some cases, the collection of data may be a statutory or contractual
requirement, and We will be limited in the services We can provide you
without your consent for Us to be able to use such data.
- With your permission and/or where permitted by law, We may also use your
data for marketing purposes which may include contacting you by email with
information, news and offers on Our products and services. We will not,
however, send you any unsolicited marketing or spam and will take all
reasonable steps to ensure that We fully protect your rights and comply with
Our obligations under the GDPR and the Privacy and Electronic
Communications (EC Directive) Regulations 2003, as amended in 2004, 2011
and 2015.
-
Under GDPR we will ensure that your personal data is processed lawfully,
fairly, and transparently, without adversely affecting your rights. We will only
process your personal data if at least one of the following basis applies:
- you have given consent to the processing of your personal data for one
or more specific purposes;
- processing is necessary for the performance of a contract to which you
are a party or in order to take steps at the request of you prior to
entering into a contract;
- processing is necessary for compliance with a legal obligation to which
we are subject;
- processing is necessary to protect the vital interests of you or of
another natural person;
- processing is necessary for the performance of a task carried out in the
public interest or in the exercise of official authority vested in the
controller; and/or
- processing is necessary for the purposes of the legitimate interests
pursued by us or by a third party, except where such interests are
overridden by the fundamental rights and freedoms of the data subject
which require protection of personal data, in particular where the data
subject is a child.
-
How and Where Do We Store Your Data?
-
We only keep your data for as long as We need to in order to use it as
described above in section 5, and/or for as long as We have your permission
to keep it. In any event, We will conduct a regular reviews to ascertain
whether we need to keep your data. Your data will be deleted if we no longer
need it in accordance with the terms of our Data Retention Policy. Our Data
Retention Policies are:
- We must by law keep data for 7 years unless our users request deletion.
- When users request deletion we delete all user information and patients files
associated with that subscription. All of user information and patient files
associated with the subscription will not be recoverable after this.
- Some or all of your data may be stored or transferred outside of the European
Economic Area (“the EEA”) (The EEA consists of all EU member states, plus
Norway, Iceland and Liechtenstein). You are deemed to accept and agree to
this by using Our Site and submitting information to Us. If We do store or
transfer data outside the EEA, We will take all reasonable steps to ensure that
your data is treated as safely and securely as it would be within the EEA and
under the GDPR. Such steps may include, but not be limited to, the use of
legally binding contractual terms between Us and any third parties We
engage and the use of the EU-approved Model Contractual Arrangements.
- Data security is of great importance to Us, and to protect your data We have
put in place suitable physical, electronic and managerial procedures to
safeguard and secure data collected through Our Site.
-
Steps We take to secure and protect your data include:
- Store your information in a secure password protected industry standard
database.
- Use a secure php framework Symfony 2.
- Only share the portions of your personal information that pertains to use
of any third-party service required.
- We do not store any credit card or financial information. Financial
services and security are provided by Braintree (a PayPal service).
- Notwithstanding the security measures that We take, it is important to
remember that the transmission of data via the internet may not be
completely secure and that you are advised to take suitable precautions
when transmitting to Us data via the internet.
-
Do We Share Your Data?
-
We may contract with third parties to supply products and services to you on
Our behalf. These may include payment processing, delivery of goods, search
engine facilities, advertising and marketing. In some cases, the third parties
may require access to some or all of your data. Where any of your data is
required for such a purpose, We will take all reasonable steps to ensure that
your data will be handled safely, securely, and in accordance with your rights,
Our obligations, and the obligations of the third party under the law. We
currently contract with:
- Mailchimp® who we share your name and email address;
- Mandrill® (a transactional email API for Mailchimp® users) who we
share your name and email address;
- Braintree (a PayPal service) who we share your credit card details.
-
In certain circumstances We may be legally required to share certain data
held by Us, which may include your personal information, for example, where
We are involved in legal proceedings, where We are complying with the
requirements of legislation, a court order, or a governmental authority. We do
not require any further consent from you in order to share your data in such
circumstances and will comply as required with any legally binding request
that is made of Us.
-
What Happens If Our Business Changes Hands?
- We may, from time to time, expand or reduce Our business and this may
involve the sale and/or the transfer of control of all or part of Our business.
Data provided by users will, where it is relevant to any part of Our business so
transferred, be transferred along with that part and the new owner or newly
controlling party will, under the terms of this Privacy Policy, be permitted to
use the data for the purposes for which it was originally collected by Us.
- In the event that any of your data is to be transferred in such a manner, you
will be contacted in advance and informed of the changes.
-
How Can You Control Your Data?
-
When you submit information via Our Site, you may be given options to
restrict Our use of your data. We aim to give you strong controls on Our use
of your data (including the ability to opt-out of receiving emails from Us which
you may do by unsubscribing using the links provided in Our emails and/or
by notifying us at [email protected];.
-
You may also wish to sign up to one or more of the preference services
operating in Australia: The Telephone Preference Service (“the TPS”), the
Corporate Telephone Preference Service (“the CTPS”), and the Mailing
Preference Service (“the MPS”). These may help to prevent you receiving
unsolicited marketing. Please note, however, that these services will not
prevent you from receiving marketing communications that you have
consented to receiving.
-
Your Right to Withhold Information and Your Right to Withdraw
Information After You Have Given it
-
You may access certain areas of Our Site without providing any data at all.
However, to use all features and functions available on Our Site you may be
required to submit or allow for the collection of certain data.
-
You may restrict your internet browser’s use of Cookies. For more
information, see section 12.
-
You may withdraw your consent for Us to use your personal data as set out in
section in 5 at any time by contacting Us using the details set out in section
10, and We will delete Your data from Our systems.
However, you
acknowledge this may limit Our ability to provide the best possible products
and services to you.
-
How Can You Access Your Data?
You have the legal right to ask for a copy of any of your personal data held by Us
(where such data is held). Please contact Us for more details at
[email protected]; or using the contact details below in section 10.
-
What Cookies Do We Use and What For?
- Our Site may place and access certain first party Cookies on your computer
or device. First party Cookies are those placed directly by Us and are used
only by Us. We use Cookies to facilitate and improve your experience of Our
Site and to provide and improve Our products and services. For more details,
please refer to section 5, above, and to section 12.4 below. We have carefully
chosen these Cookies and have taken steps to ensure that your privacy is
protected and respected at all times.
- All Cookies used by and on Our Site are used in accordance with current
English and EU Cookie Law.
- EU Cookie Law deems these Cookies to be “strictly necessary”. These
Cookies are shown below in section 12.4. Your consent will not be sought to
place these Cookies. You may still block these Cookies by changing your
internet browser’s settings as detailed below in section 12.5, but please be
aware that Our Site may not work as intended if you do so. We have taken
great care to ensure that your privacy is not at risk by allowing them.
-
The following first party Cookies may be placed on your computer or device:
Name of Cookie |
Purpose |
Strictly Necessary |
PHPSESSID |
Used to identify the session of the user |
Yes |
- You can choose to enable or disable Cookies in your internet browser. Most
internet browsers also enable you to choose whether you wish to disable all
cookies or only third party cookies. By default, most internet browsers accept
Cookies but this can be changed. For further details, please consult the help
menu in your internet browser or the documentation that came with your
device.
- You can choose to delete Cookies at any time however you may lose any
information that enables you to access Our Site more quickly and efficiently
including, but not limited to, login and personalisation settings.
- It is recommended that you keep your internet browser and operating system
up-to-date and that you consult the help and guidance provided by the
developer of your internet browser and manufacturer of your computer or
device if you are unsure about adjusting your privacy settings.
-
Summary of Your Rights under GDPR
Under the GDPR, you have:
- the right to request access to, deletion of or correction of, your
personal data held by Us;
- the right to complain to a supervisory authority;
- be informed of what data processing is taking place;
- the right to restrict processing;
- the right to data portability
- object to processing of your personal data;
- rights with respect to automated decision-making and profiling (see
section 14 below).
To enforce any of the foregoing rights or if you have any other questions about Our
Site or this Privacy Policy, please contact Us using the details set out in section 10
below.
-
Automated Decision-Making and Profiling
- In the event that We use personal data for the purposes of automated decision-
making and those decisions have a legal (or similarly significant effect) on
You, You have the right to challenge to such decisions under GDPR,
requesting human intervention, expressing their own point of view, and
obtaining an explanation of the decision from Us.
-
The right described in section 14.1 does not apply in the following circumstances:
- The decision is necessary for the entry into, or performance of, a
contract between the You and Us;
- The decision is authorised by law; or
- You have given you explicit consent.
-
Where We use your personal data for profiling purposes, the following shall
apply:
-
Clear information explaining the profiling will be provided, including its
significance and the likely consequences;
- Appropriate mathematical or statistical procedures will be used;
-
echnical and organisational measures necessary to minimise the risk
of errors and to enable such errors to be easily corrected shall be
implemented; and
-
All personal data processed for profiling purposes shall be secured in
order to prevent discriminatory effects arising out of profiling.
-
We currently make the following automated decisions:
None.
-
We currently profile your personal data for the following purposes:
None.
-
Contacting Us
If you have any questions about Our Site or this Privacy Policy, please contact Us by email
at [email protected];. Please ensure that your query is clear, particularly if it is
a request for information about the data we hold about you (as under section 4, above).
-
Changes to Our Privacy Policy
We may change this Privacy Policy as we may deem necessary from time to time, or as may
be required by law. Any changes will be immediately posted on Our Site and you will be
deemed to have accepted the terms of the Privacy Policy on your first use of Our Site
following the alterations. We recommend that you check this page regularly to keep up-to-
date.