DOCNEXUS PRIVACY POLICY
Last updated 09/06/2023
DocNexus takes privacy seriously and understands that you care about how your personal information is collected and used. This privacy policy (“Privacy Policy”) explains how we process personal information, including information about healthcare professionals, thought leaders, and academics (“Experts”), along with information about users of our website, platform, and services (“End Users”). It also tells you how you can exercise your rights and choices with respect to your personal information, and how you can contact us about our privacy practices. For the purposes of this Privacy Policy, “DocNexus” our subsidiaries and affiliates. DocNexus is in compliance with the following: General Data Protection Regulation (GDPR), California Privacy Rights Act (CPRA), Personal Information Protection and Electronic Documents Act (PIPEDA), and Act on the Protection of Personal Information (APPI).
DocNexus is reinventing the global healthcare ecosystem by providing a platform helps bring life-saving products to market faster by connecting stakeholders across the healthcare universe for greater collaboration and discovery. To facilitate these connections, we collect publicly available information about healthcare professionals worldwide. These healthcare professionals include doctors, researchers, clinicians, thought leaders, and academics (collectively, “Experts”). Industry professionals use our platform to more easily find relevant clinical and research content, identify collaborators and engage with healthcare thought leaders, improve research, promote healthier outcomes, and conduct professional networking. You can find out more about us and the services we provide here.
We also encourage Experts to actively engage with, and contribute to, the DocNexus platform. If you are an Expert, you can access, update, or delete your profile information by visiting our Privacy Preferences Center. By remaining in our database, you may be contacted by customers for their own business and research purposes.
DocNexus maintains profiles of Experts that we make available to our customers through the DocNexus platform. The Expert profiles include name, contact information, institutional affiliations, and other publicly available business and professional information, such as clinical trial and medical claims data, network and social media information, scholarly influence and ranking, and medical publications, reviews and commentary. We obtain this information in different ways, including from public sources (such as federal, state, or local records), social media, and third-party data providers. We may derive certain information about Experts through our own analysis, such as scholarly influence and ranking.
We also may receive certain information about Experts from our customers. Please note that we only use the information our customers provide to us as a data processor for their benefit and pursuant to their instructions. If you have any questions about how our customers process your information, please refer to their respective privacy policies for more information.
In addition to Experts, we also process information about users of our website, DocNexus.ai (the “Site”), the DocNexus platform, and our other products and services (collectively, our “Services”). We refer to these individuals as “End Users”.
We collect the following personal information in connection with our Services. This includes information that you provide to us, information that we obtain from third parties, and information that we collect automatically (such as through the use of cookies and similar technologies).
Experts
Information from Third-Party Sources: We collect publicly available business and professional information about you. For example, we collect information from public databases (such as PubMed); institution, government, and NGO websites (such as hospital websites, medical society websites, and the like); public news sources (such as Associated Press, Reuters); and other readily available public resources (such as government publications). In addition, we may acquire lawfully obtained proprietary data from third-party data providers.
The types of personal information we may collect include:
We may also collect de-identified and aggregate information relating to medical claims and treatments, patient populations, and clinical trials.
Information from Our Customers: We may combine the information described above with information our customers lawfully provide to us about you to furnish them with more complete datasets. We only use the information our customers provide us about Experts as a data processor for their benefit, and pursuant to their instructions. Please refer to their respective privacy policies of our customers for more information about how they collect and use your personal information.
Information You Provide to Us: We also encourage Experts to actively engage with, and contribute to, the DocNexus platform. When you provide us with information, we process the information that you choose to share with us, which could include any of the above-described professional information. In addition, if you sign up for an DocNexus account to access and use our Services as an End User, we will collect the personal information described below in the section titled “End Users”. If you would like to learn more about the DocNexus platform, and provide your input to help us build a single source of truth for healthcare information, please visit our website.
End Users
Information You Provide to Us: DocNexus collects information that you choose to share with us. For example, when you navigate the Site, fill out one of our forms, create an account on the DocNexus platform, or otherwise communicate with us, you may choose to provide us with certain personal information. For security purposes, we may also collect personal information from you if you visit one of our offices.
The types of personal information you may provide include:
Information We Collect Automatically: As you navigate through and interact with the Site, our emails, or products and services, we may automatically collect through common internet technologies certain information about your equipment, browsing actions, and use patterns, such as cookies and web beacons. This information also may include details of your visit to the Site, including your IP address and browser information, location data, logs and other communication data, and the resources that you access and use on the Site. Collecting this information helps us improve Site performance and deliver more personalized content and services by enabling us to estimate our audience’s size, usage patterns, and constituents upon return visits to the Site. Please see the “Cookies and Similar Technologies” section for more information about how we use these technologies.
Likewise, as you use the Site, we may collect anonymous usage information about layout, design, content, and functionality to improve our products and services. The data collected for these purposes are de-identified.
We collect and process personal information for a variety of purposes. If you are located in the EEA or UK, we need a legal basis to process your information. Our legal basis will depend on the information concerned and the context in which it is processed. We may process your information in order to enter into or perform a contract with you, when DocNexus or a third party has a legitimate interest in processing your information, when it is necessary to comply with our legal obligations, or with your consent. The table below sets out our purpose for processing your information and our legal basis for doing so.
Experts
Purpose | Description | Legal Basis |
Providing our Services | We process your personal information to make our database available to customers who have purchased a license to access the Services. Compiling and maintaining this database supports scientific and academic research and helps facilitate connections with Experts for healthcare collaboration, research, speaking opportunities, clinical trials, and partnerships, as well as supporting our customers’ strategic initiatives in research, sales, and marketing. | Our legitimate interests to facilitate scientific and academic research, and facilitate connections between Experts and the healthcare industry. |
Managing Expert profiles | We process your personal information to create, update and maintain your profile in our database. Providing this information ensures that our database is accurate and up-to-date, and supports the purposes described above. | Our legitimate interests to maintain accurate and up-to-date records of Expert profiles. |
Complying with legal obligations | We may process your personal information to cooperate with public authorities, including courts or regulators, to the extent required by applicable laws. We also may process or disclose personal information to enforce our legal rights, or as is necessary for our legitimate interest in protecting our Services, pursuing remedies available to us, limiting our damages, and complying with judicial proceedings and other valid legal proceedings. | Legal obligations or our legitimate interests to cooperate with public authorities, enforce our legal rights, and comply with judicial and other legal proceedings. |
End Users
Purpose | Description | Legal Basis |
Providing our Site and Services | We process your personal information to provide our Site and Services, including to perform our contract with you and to fulfil our obligations under the applicable terms of use. | Performance of a contract or our legitimate interests to provide and administer our Site and Services. |
Managing End User accounts | If you have registered for an account with us, we process your personal information to manage your account and fulfil our obligations under our contract with you. | Performance of a contract. |
Sending administrative communications | We may process your personal information for the purposes of sending you information related the Site and our Services, such as confirmations, invoices, expiration and renewal notices, technical notices, support updates, and administrative messages. | Performance of a contract. |
Customer support | If you contact us for technical or customer support, we will process your personal information in order to fulfil your request. | Performance of a contract or our legitimate interests to respond to support requests. |
Improving our Site and Services | We may process your personal data to analyze usage trends and help us improve the overall user experience on our Site and services. | Our legitimate interests to improve and provide a well-functioning and relevant Site and Services. |
Promoting the security of our Site and Services | We process your personal information for the purposes of promoting the safety, security, integrity of our site and Services, including verifying accounts and activity, investigating suspicious activity, and enforcing our terms and policies. | Our legitimate Interests to combat harmful conduct and promote safety, integrity and security. |
Registering office visitors | We may process your personal information to register office visitors for security reasons, and to manage non-disclosure agreements that visitors may be required to sign. | Our legitimate interests to ensure the safety and security of our offices and protect our confidential information against unauthorized access. |
Displaying personalized advertisements and content | We may process your personal information to conduct market research, advertise to you, provide personalized information about us on and off our Site, and provide other personalized content based upon your activities and interests to the extent it is necessary for our legitimate interest in advertising our Site and services, or where necessary, to the extent you have provided your prior consent. | Consent or our legitimate interests to display and measure personalized advertising. |
Sending marketing communications | We may process your personal information to send you marketing information, product recommendations and other non-transactional communications (e.g. marketing newsletters, telemarketing calls, SMS, or push notification) about in accordance with your marketing preferences, including information about our products or services. Please see the “Your Privacy Rights” section below to learn how you can control the processing of your personal information for marketing purposes. | Consent or our legitimate interests to send marketing regarding our products and services. |
Creating anonymous statistics | We may aggregate and/or anonymize your personal information for the purposes of creating internal statistics related to product, usage, research and improvement. | Our legitimate interests to analyse usage of our Site and Services, develop our business and inform our marketing strategy. |
Other business purposes | We may process your personal information for other legitimate business purposes, such as conducting audits; protecting against and investigating fraudulent or otherwise illegal activity; developing new products; conducting product research; identifying usage trends; determining the effectiveness of our promotional campaigns; and operating and expanding our business activities. | Our legitimate interests to conduct our business activities and support the improvement and expansion of the business. |
Complying with legal obligations | We may process your personal information to cooperate with public authorities, including courts or regulators, to the extent required by applicable laws. We also may process or disclose personal information to enforce our legal rights, or as is necessary for our legitimate interest in protecting against misuse of our Site or Services, protecting personal property or safety, pursuing remedies available to us, limiting our damages, and complying with judicial proceedings and other valid legal proceedings. | Legal obligations or our legitimate interests to cooperate with public authorities, enforce our legal rights, protect our property, and comply with judicial and other legal proceedings. |
We may share your information with certain third parties for the purposes described in this Privacy Policy, including group companies, our customers, and service providers.
We may disclose your personal information to the following categories of recipients:
We may also disclose your personal information to enforce or apply our Terms of Use and other agreements that govern the sale or use of our Services, and to protect the rights, property, or security of DocNexus or others.
DocNexus uses cookies and similar technologies to identify and track visitors to the Site and users of the DocNexus platform. We use this information to maintain and improve our Services and for analytics and advertising purposes.
Cookies are small text files placed on your device or browser that to store data that can be recalled by a web server in the domain that placed the cookie. Our Services may make use of first- or third-party cookies (whether session or persistent cookies) and similar technologies for purposes such as session management, account authentication, recognizing you and remembering your preferences and settings, combating fraud, maintaining the Services, ensuring security and debugging, analysing how our Services perform and other analytics purposes, and fulfilling other legitimate purposes as further described in this Privacy Policy. We also use analytics cookies to better understand how our Services are being used by tracking how you interact with the Services.
Depending on your browser, you may be able to change settings to refuse all or some browser cookies, or to alert you when cookies are being set. If you disable or refuse cookies, please note that some parts of the Services may be inaccessible or not function properly. In relation to emails, you can disable most email tracking technology by preventing the loading of embedded pictures in the email. You can do this using your email software settings.
Google Analytics: We use cookies served by Google Analytics to collect limited data directly from End User browsers to enable us to better understand your use of the Site and services. Further information on how Google collects and uses this data can be found here. You can opt-out of all Google supported analytics within the Services by visiting this site.
FullStory: We use FullStory to provide a better user experience for you and collect data to diagnose End User issues. Further information about the cookies used by FullStory can be found here. You can opt-out of FullStory support analytics within the Services by visiting this site.
We are serious about security and take reasonable steps to protect your personal information. We also only retain personal information for so long as we have an ongoing legitimate need to do so and for a period of time consistent with the purposes described in this Privacy Policy.
We have implemented appropriate technical and organizational measures designed to protect your personal information against unauthorized, accidental, or unlawful access, destruction, loss, alteration, disclosure, or use. These measures have been implemented taking into account the state of the art of the technology, the cost of implementation, the risks presented by the processing, and the nature of the personal information, with particular care for sensitive data.
The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of the Site, products, or services, you are responsible for keeping this password confidential. Please do not share your password with anyone. Although we take reasonable security measures to protect your personal information (for example, by using Secure Socket Layer encryption when you transmit your password), we cannot guarantee the security of your personal information transmitted to the Site. The transmission of information via the internet is never 100% secure, and we cannot ensure or warrant the security of any information you transmit to us. We are not responsible for circumvention of any privacy settings or security measures contained on the Site.
We retain personal information we collect from you where we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, tax, or accounting requirements). Where we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it, or, if this is not possible (for example, because your personal information has been stored in backup archives), we will securely store your personal information and isolate it from any further processing until deletion is possible.
DocNexus is a global business and our headquarters are located in the United States. We may transfer your personal information to the United States and other countries where the data protection laws are different from those of your country (and which, in some cases, may not be as protective). Regardless of where your information is processed, we will treat all personal information in accordance with applicable law and this Privacy Policy.
Specifically, our servers are located in the United States and our affiliates and third-party service providers operate around the world, including in India. Wherever your information is processed, we take appropriate steps to ensure that your personal information continues to be processed in accordance with applicable legal requirements and this Privacy Policy.
If you are located in the EEA, UK, or Switzerland, we will protect your personal information when it is transferred outside of such locations by processing it in a country that provides an adequate level of protection (see here for a list of countries deemed adequate by the European Commission) or by implementing appropriate safeguards to protect your personal information, including through the use of standard contractual clauses or another lawful transfer mechanisms approved by the European Commission and/or the UK or Swiss authorities (as applicable).
Privacy Shield: DocNexus maintains compliance with the EU-US and Swiss-US Privacy Shield Frameworks (“Privacy Shield”) as set forth by the U.S. Department of Commerce with respect to personal information concerning individuals from the EEA, UK and Switzerland. In light of the Court of Justice of the European Union decision regarding the legal effect of the Privacy Shield, DocNexus does not rely on the Privacy Shield to transfer personal information from the EEA, UK or Switzerland to the United States. Please see our Privacy Shield Notice to learn more.
If you are an Expert, you can access, update or delete your profile information by visiting our Privacy Preferences Center.
Depending on your location, you can also exercise your data protection rights (including your rights to access, update or delete your personal information) through DocNexus’s Privacy Preferences Center. We respond to requests we receive in accordance with applicable data protection laws.
Access, Update or Delete Your Profile Information: If you are an Expert, you can update your profile information, delete your information, or opt out of our database by visiting our Privacy Preferences Center. Alternatively, you can submit an access request, update your information or opt out of our database by visiting our Privacy Preferences Center.
Opt Out from Marketing: You can opt out of receiving marketing communications from us at any time. If you do not wish to receive marketing communications from DocNexus, you can opt out by sending us an e-mail at mahek@docnexus.ai. If you choose to no longer receive marketing information, we may still communicate with you regarding such things as your security updates, product functionality, responses to service requests, or for other transactional, non-marketing purposes.
Exercise Your Rights: DocNexus provides a self-serve Privacy Preferences Center where you can submit a data protection rights request. Alternatively, you can contact us using the details provided in the “Contact Us” section below. We respond to all requests we receive in accordance with applicable data protection laws. Depending on your location and applicable data protection laws, you may have the right to:
Our Services are not directed to children under the age of thirteen (13). DocNexus does not knowingly collect personal information relating to children without the consent of a parent or legal guardian. If you become aware that a child has provided us with their personal information, please contact us so that DocNexus can take the necessary steps to remove the personal information.
We may include links to third-party websites on our Services, including the DocNexus Blog. When you click on a link to a third-party website, the collection and use of your personal information is governed by that website’s policies and not by those of DocNexus. We are not responsible for the information practices of such third parties and we encourage you to review their privacy and user policies.
DocNexus may change this Privacy Policy from time to time, and at DocNexus’s sole discretion. When we update our Privacy Policy, we will take appropriate measures to inform you, consistent with the significance of the changes we make. For example, if we make any material changes to this Privacy Policy we may provide you with prior notice by posting a notice on our Site, contacting you directly, or seeking your consent where required by applicable data protection laws. You can see when this Privacy Policy was last updated by checking the “last updated” date displayed at the top of this Privacy Policy.
1. YouTube API Data: DocNexus API Client utilizes the YouTube API for research purposes. When you use our services, we may collect data from YouTube, including but not limited to video metadata, comments, and user interactions.
2. User-Provided Information: We may collect information you provide directly when you interact with DocNexus API Client, such as your name, email address, or any other information you voluntarily submit.
3. Automatically Collected Information: We may automatically collect certain information about your device and how you interact with our services, including your IP address, browser type, operating system, and usage data.
We use the information collected for the following purposes:
1. Research Purposes: We use the YouTube API data to conduct research and analysis, with the goal of improving our services and understanding user behavior on the platform.
2. Communication: We may use your contact information to send you updates, notifications, and respond to inquiries.
3. Security: We use collected data to monitor and enhance the security of our services, including the prevention of unauthorized access or fraudulent activities.
4. Aggregate Data: We may aggregate and anonymize data for statistical purposes, which may be shared with third parties. However, this data will not personally identify you.
We may share your information in the following circumstances:
1. Legal Compliance: We may disclose information when required by law or to protect our rights, privacy, safety, or property.
2. Business Transfers: In the event of a merger, sale, or transfer of assets, we may share information with the acquiring entity.
As an API client utilizing DocNexus services, you must adhere to the following obligations:
1. YouTube Terms of Service: You must state in your terms of use that, by using DocNexus API Client, users are agreeing to be bound by the YouTube Terms of Service, available at YouTube Terms of Service.
2. Google Privacy Policy: Your privacy policy must contain a reference and link to the Google Privacy Policy at Google Privacy Policy.
3. User Data Collection: You must explain how user data is being collected, stored, and otherwise used.
4. Data Processing and Sharing: You must mention how user data is being processed and shared with internal and external parties.
5. Device Data Collection: You must explain how user data is being collected from the user's device.
6. Contact Information: Provide contact information for inquiries and concerns. You can reach DocNexus at mahek@docnexus.ai.
DocNexus API Client is not intended for use by individuals under the age of 13. If you believe we have collected information from a child under 13, please contact us, and we will promptly remove such data.
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will post any updates on our website, and the revised policy will be effective immediately upon posting.
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at mahek@docnexus.ai.
By using DocNexus API Client, you consent to the practices described in this Privacy Policy.
09/06/2023