Last Revised: August 30, 2021
2. Preliminary Notes
2.1 Not for minors. If you are under the age of 16, do not use the Services, unless your parent or legal guardian are doing so on your behalf.
2.4 Data Controller. With respect to Users who are HCP, Patients or Visitors, Kahun acts as a Data Controller. With respect to third party data, submitted about an individual by a HCP, Kahun acts as a Data Processor. The meaning of Controller and Processors are those given them by the GDPR.
2.7 Your Personal Data. You are not required by law to provide us with Personal Data and you do so voluntarily. You can always avoid providing us certain Personal Information, however, you acknowledge that it may prevent us from providing you certain Services, or, may result in an ineffective Services. We sometimes process Personal Data about data subjects that were not provided to us by them, for example, when the User is an HCP, submitting Personal Data about their patients or study cases; in such cases, we require the HCP to hold a legal basis for the processing of such Personal Data.
3. Your Consent
3.2 Certain information we may collect, such as general usage information, device information, analytics, statistics, or any other data that enable us to provide the Services, is collected as part of our legitimate interest. You can find further explanation below, under the “Legal Basis” section.
3.3 Third-party information and consent:
4. Information we collect
4.1 The Personal Information we may process originates from one or more of the following sources: (i) Information you actively provide to us, including by way of contacting us or interacting with our Services; (ii) Information automatically accessed or collected while you use our Services or while you brows the Website, such as cookies and tags that are required for their functionality; (iii) Information submitted about your conditions by a User of the Services, based on your consent to them.
in addition to the Personal Information processed about Visitors, the following will be further processed about the usage of Patients:
5. Using cookies and similar web technologies
6. Our legal basis for use of your information
6.2 Legitimate Interest:
6.4 Contract: if you partner with us on a business-to-business level, or otherwise engage in a contract with us, we will process personal Information to preparing for a contract, proposing a business offering, or fulfilling a contractual obligation with the organization you represent.
7. Purpose for processing your information
In addition to the purposes described next to each data category, we may use information that we collect about you for the following purposes:
Any information you submit to us via the Services is used respectively to the purposes indicated in the relevant form or webpage.
8. Sharing information with third parties
We keep the information processed by us in strict confidence and only share your information with third parties in very limited circumstances and for very specific purposes, as described below:
8.1 Third Party Services: We are partnering with a number of selected service providers, whose services and solutions complement, facilitate and enhance our own. These include hosting, database and server co-location services (e.g., Amazon (AWS)), data analytics services (e.g. Google Analytics) and session replay records for analytic purposes such as crashes, functionality and usability (e.g. MixPanel) and our business, legal and financial advisors (collectively, “Third Party Service Providers”).
Such Third Party Service Providers may receive or otherwise have access to certain of your Personal Information, depending on each of their particular roles and purposes in facilitating and enhancing the Services, and may only use your Personal Information for such purposes. Disclosures of Personal Information is subject to the respective third party’s undertaking of confidentiality obligations, and the prevention of any independent right to use this data except as required to help us provide you with the Services.
8.2 Our auditors, consultants, investors, and contractors with whom we may share samples of Personal Data on a need-to-know basis only and under strict confidentiality obligations.
8.3 Law enforcement, legal proceedings, and as authorized by law: We may disclose or otherwise allow access to Personal Information pursuant to a legal requirement or request, such as a subpoena, search warrant or court order, or in compliance with applicable laws and regulations. Such disclosure or access may occur with or without notice to you, if we have a good faith belief that we are legally required to do so, or that disclosure is appropriate in connection with efforts to investigate, prevent, or take action regarding actual or suspected illegal activity, fraud, or other wrongdoing.
8.4 Protecting Rights and Safety: We may share your Personal Information with others, with or without notice to you, in cases of emergency or if we believe in good faith that this will help protect the rights, property or personal safety of our company, any of our Users, or any members of the general public.
8.6 Change of control: In the event that Kahun is acquired by or merged with a third party entity, we reserve the right to transfer or assign the information we collected as part of such merger, acquisition, sale, or other change of control.
8.7 In the unlikely event of our bankruptcy, insolvency, reorganization, receivership, or assignment for the benefit of creditors, or the application of laws or equitable principles affecting creditors’ rights generally, we may not be able to control how your information is treated, transferred, or used.
For the avoidance of doubt, we may share your Personal Information in additional manners, pursuant to your consent, or if we are legally obligated to do so. Additionally, we may transfer, share or otherwise use Non-Personal (including anonymized, statistical or aggregated) Information in our sole discretion and without the need for further approval.
9. Where we store your personal information
9.1 Your information will be maintained, processed and stored by us and our authorized affiliates (if applicable) in secure cloud storage, provided by our Third Party Service Providers based in the United States.
10. Data retention and security
10.1 As a matter of principle, we retain Personal Data for no longer than necessary to achieve the purpose for which it was collected. Further, when feasible, we process Personal Data on a temporary basis. The Personal Data we process to provide, maintain, and develop the Services, is not attributed, connected or associated with any identified individual, to ensure their privacy protection.
10.2 We retain the Personal Information we collect or receive from you only for as long as your registered account exists in our system and as needed in order to provide you with the Services and as otherwise necessary to comply with applicable laws and regulations. If you withdraw your consent to us processing your Personal Information, including by deleting your account, we will delete your Personal Information from our systems, except to the extent such data in whole or in part is required to comply with any applicable rule or regulation and/or to respond to or defend against legal proceeding brought against us or our affiliates.
10.3 We take great care in implementing and maintaining the security of the Services and of your Personal Information. We employ industry standard procedures and policies to ensure the safety of your information, reduce the risks stemming from loss of information and prevent unauthorized use of any such information. However, we do not and cannot guarantee that unauthorized access will never occur and reiterate that no measure can provide absolute information security
11. Your privacy rights
11.1 The following rights apply to certain individuals, depending on their country of residence:
11.2 You can exercise your rights by contacting us at firstname.lastname@example.org. Subject to legal and other permissible considerations, we will make every reasonable effort to honor your request promptly in accordance with applicable law or inform you if we require further information in order to fulfill your request.
11.3 Verification: When processing your request, we may ask you for additional information to confirm or verify your identity and for security purposes, before processing and/or honoring your request. We reserve the right to charge a fee where permitted by law, for instance, if your request is manifestly unfounded or excessive. In the event that your request would adversely affect the rights and freedoms of others (for example, would impact the duty of confidentiality we owe to others) or if we are legally entitled to deal with your request in a different way than initially requested, we will address your request to the maximum extent possible, all in accordance with applicable law.
12. Minors and third-party information provided by you
12.1 To access or use the Services, you must be over the age of sixteen (16), and in any case, not an underage according to the legislation in your country of residence. Kahun does not knowingly process Personal Information from children under the age of sixteen (16) and does not wish to do so. We reserve the right to request proof of age at any stage so that we can verify that minors under the age of sixteen (16) are not using the Services.
12.2 If it comes to our attention that a person under the age of sixteen (16) is using the Services, we may prohibit and block such User from using the Services and will make all efforts to promptly delete any Personal Information with respect to such User.
12.3 If you are submitting to the Services any Personal Information pertaining to any minor child, you hereby represent and warrant that you have received all the necessary legal consents or approvals or that you are the parent or legal guardian and have the actual authority and legal right to upload, submit, disclose or otherwise share the Non-personal Information and/or Personal Information and/or any other form of sensitive information, on the minor’s behalf.
15. Have any questions?