...

The type of personal information we collect

We currently collect and process the following information:

  • Personal identifiers, contacts and characteristics (that are provided by members and collaborators)
  • Photographs, video and audio recordings
  • Data on website usage, including purchases made via Stripe

 

How we get the personal information and why we have it

Most of the personal information we process is provided to us directly by you for one of the following reasons:

  • Membership subscriptions
  • Enrolment to or participation in courses, events, surveys
  • Job applications, grant applications, abstract submissions
  • Reimbursement of expenses

We also receive personal information indirectly, from the following sources in the following scenarios:

  • Google Analytics and Amplitude (to track website usage)
  • National Societies (to process membership subscriptions)

We use the information that you have given us in order to respond to queries and provide after-sales customer service, report on involvement in ESVS activities, process requests, provide information on activities that may be of interest to you (marketing).

We may share this information with other companies including, but not limited to, Elsevier (journal publishers), ESVS event organising committees, committee chairs or directors, third party collaborators (managing event logistics and registrations), EACCME, industry partners (when consent is clearly given).

Under the EU General Data Protection Regulation (EU GDPR), the lawful bases we generally rely on for processing this information are:

  • Your consent. You are able to remove your consent at any time. You can do this by contacting the ESVS Data Protection Officer
  • We have a contractual obligation
  • We have a legitimate interest

 

How we store your personal information

Your information is securely stored.   The IT systems used by the ESVS Office staff are protected by Collaboration Protect (Microsoft 365’s protection system), Veeam Backup, EPP&EDR anti-virus systems and Double Authentication protection.  O2Switch website hosters provide security for our website which includes, Anti DDOS software, Anti Bruteforce software and multiple WAF (Web Application Firewalls). By using the esvs.org website you consent to the terms of this Privacy Policy.

We generally keep personal information for 7 years.  What we may consider as ‘main data’ will be treated as per our Data Retention Policy, however email addresses are kept indefinitely under legitimate interests and unsubscribing from these is always an option.

Your data protection rights

Under data protection law, you have rights including:

Your right of access – You have the right to ask us for copies of your personal information.

Your right to rectification – You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.

Your right to erasure – You have the right to ask us to erase your personal information in certain circumstances.

Your right to restriction of processing – You have the right to ask us to restrict the processing of your personal information in certain circumstances.

Your right to object to processing – You have the the right to object to the processing of your personal information in certain circumstances.

Your right to data portability – You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.

You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.

Please contact us at if you wish to make a request.

How to complain

If you have any concerns about our use of your personal information, you can make a complaint to us at ESVS.dpo@mydata-trust.info .

You can also complain to the CNIL if you are unhappy with how we have used your data.  The CNIL (Commission nationale de l’informatique et des libertés) is an independent French administrative regulatory body whose mission is to ensure that data privacy law is applied to the collection, storage, and use of personal data.  As data processed by the ESVS are held in France (where the Society offices are based) they must be treated in compliance with the (CNIL). 

The CNIL’s address:           

CNIL – Service des Plaintes

3 Place de Fontenoy

TSA 80715

75334 PARIS CEDEX 07.

 

Helpline number : +33 (0)1 53 73 22 22

CNIL website: https://www.cnil.fr/en