Privacy Notice

Privacy Notice

1. Introduction

We, European Academy of Allergy and Clinical Immunology (EAACI) take protection of your personal data very seriously and strictly adhere to the rules laid out by data protection laws and General Data Personal Regulation (GDPR).

This privacy notice aims to give you information on how EAACI collects and processes your personal data through your use of this site, including any data you may provide if you contact us regarding our products and services. EAACI have classified ourselves to be a data controller on your personal information. If there’s a change to the processors that we use, you the data subject will be made aware.

We have appointed an EU Representative as per article 27. If you have any questions about this privacy notice, including any requests to exercise your legal rights or how we process your personal information please contact the EU Representative using the contact information laid out in section 10 of this privacy notice.

The information provided on EAACI is designed to support, not to replace, the relationship that exists between a patient/site visitor and his/her physician.

2. Lawful Basis of Processing Personal Information

We only collect and use personal information about you when the law allows us to. Most commonly, we use it where:

  • The data subject has given consent to the processing
  • Processing is necessary for the performance of a contract
  • Processing is necessary for compliance with a legal obligation to which the controller is subject
  • Processing in necessary for the purpose of the legitimate interest pursed by the controller or third party

3. What Information we collect

We collect the following personal information from you, when you register to our website, request product information, contact us or use any of our services. In order for EAACI to ensure your personal information is update to, Members are invited to regularly update their profile via the member’s area. The categories of personal information that we may collect, store and process about you include:

  • Name, Work or Home Address, Telephone number, Email Address
  • Date of birth and gender
  • Membership Numbers (AAAAI, ACAAI, European Rhinologic Society, European Respiratory Society)
  • National Allergy Society Membership details
  • Your Specialty, Section Membership, Your Interest Groups, Your Working Groups, Member of National Society and
  • Professional status, years in practise, area of expertise

When you engage in any financial transaction through our websites, you will be asked to provide certain financial information, such as your credit card and billing address. These details are transferred to a secure, online payment service, hosted outside EAACI. Credit card information is not retained or processed by EAACI for compliance with the Payment Card Industry Data Security Standard (PCI-DSS). EAACI use Ingenico ePayments for secure financial transactions, if you would like to learn more about how this may affect you, please read their privacy policy (https://ingenico.co.uk/privacy-policy)

3.1 Use of ‘Cookies’

Cookies are Small text files (typically made up of letters and numbers) placed in the memory of your browser or device when you visit a website or view a message. Cookies allow a website to recognize a particular device or browser.

At EAACI we set and use some cookies ourselves but only on our site. These are called first party cookie. When cookies are served by another domain they are called “third party cookies”. We use some third party cookies on our site, please see what cookies we use below:

 

Third Party Cookies

For detailed information on the cookies we use and the purposes for which we use them, please contact us at gdpr@eaaci.org, by phone at + 41 44 205 55 36.

Cookie Name Domain Expiry Purpose
_gid .eaaci.org 2 Years These cookies are set by google analytics.
_ga .eaaci.org 24 Hours More about google analytics is available here: https://developers.google.com/analytics/resources/concepts/gaConceptsCookies

3.2 Social Activities

If you choose to input personal information to a Social Network, EAACI is no longer responsible for the personal information from the point in time that it leaves EAACI Services. Instead, the personal information will be in the control of the third party, and the relevant third party’s terms and privacy policy will apply. For example, if you use EAACI to post a message on Twitter, Twitter’s privacy policy and terms of service will apply to that message on Twitter’s server.

EAACI does not use or intend to use in the future, any social media plug-in such as Facebook, Twitter, LinkedIn on our website. If we decide to use plug-ins, EAACI would make our members aware as soon as a decision has been made.

Please click here for the EAACI Social Media Disclaimer.

3.3 Links to other websites

This Website contains links to other sites that are not owned or controlled by EAACI. Please be aware that we are not responsible for the privacy practices of these other sites. This privacy statement applies only to information collected by EAACI.

3.4 Events

Throughout the year EAACI will host a number of events around the world. To promote these events and improve the content on our media platform, we will take photos and record presentations. Due to it not being possible to ask for consent on all photos being taken, EAACI have a lawful basis of legitimate interests (GDPR Article 6 Point F). Prior to any video recording of EAACI, we will ask for your consent.

If you attend one of these events and you do not wish to have your photo uploaded to our website, please let us know and we will be able to remove this information without undue delay.[BB1]

3.5 Fellowships

Every year, EAACI awards a number of fellowships to Junior Members or members in training, interested in increasing their knowledge and skills at Europe’s leading scientific institutions.

As part of the submission process, we will gather various personal details, including but not limited to your name, address, contact information, ID or passport details, and residential certificate. Additionally, we will collect information necessary for the completion of your submission, such as membership data, curriculum vitae, publication list, etc. You may also be requested to provide details about your profession, field of study, etc., for statistical purposes.

Moreover, we will collect individual data and documents like scientific abstracts, application forms, supporting documentation, information about your home institution and supervisor, as well as details about the host institution and supervisor. Please note that this data may be made publicly accessible on online databases and related websites.

 

 

4. How long do we keep information for

We pride ourselves on ensuring that your personal data is retained for the period that EAACI needs it for. All personal information collect has a defined retention period, which is in-line with our retention policy. If you would like to find out how long your information is being retained, please see “additional information”, section 10 of this policy.

5. Security of personal information

EAACI is committed to handling your personal information with high standards of information security. In order to protect and safeguard the personal data provided to us, we have implemented and use appropriate business systems and procedures. For example, your personal information is transmitted to us through a secure server protocol, which encrypts all your personal information. The encryption method used is the industry standard “Transport Layer Security (TLS)” technology. However, due to submitting information over the Internet not being 100% secure, EAACI does not guaranteed 100% security of personal information submitted; transmissions at your own risk.

Furthermore, we have implemented and use security procedures and technical and physical restrictions for accessing and using personal information. Only authorised employees are permitted to access personal information for performing their duties in respect of our services. Our server and network are protected by firewalls against unauthorised access and we have intrusion detection systems that monitor and detect unauthorised (attempts to) access to or misuse of our servers

At EAACI we have also ensured that all employees have sufficient information security training and follow our strict media handling policy which helps maintain, enforce and communicate best practices surrounding media handling throughout the business.

6. Children’s information

EACCI does not knowingly collect or process children’s information. If we were to, we would only process the information with the appropriate consent. We have implemented controls so that we do not receive this type of information, but we cannot guarantee that it will never happen. If EACCI have collected any personal information on a child, please see section 10 immediately so we can remove this information without undue delay.

7. Your individual rights

In this Section, we have summarised the rights that you have under General Data Protection Regulation. Some of the rights are complex, and not all of the details have been included in our summaries. Accordingly, you should read the relevant laws and guidance from the regulatory authorities for a full explanation of these rights.

Your principal rights under General Data Protection Regulation are:

  • Right to Access
  • Right to Rectification
  • Right to Erasure
  • Right to Restrict Processing
  • Right to Object
  • Right to Data Portability

You have the right to confirmation as to whether or not we process your personal data and, where we do, access to the personal data, together with certain additional information. That additional information includes details of the purposes of the processing, the categories of personal data concerned and the recipients of the personal data. Providing the rights and freedoms of others are not affected, we will supply to you a copy of your personal data. The first copy will be provided free of charge, but additional copies may be subject to a reasonable fee (EUR 10).

You as a data subject have the right to rectification, which will allow you as the data subject to modify/change any personal information to the purpose of ensuring that the information we process is update to date.

The right to erasure or right to be forgotten will allow you as the data subject to inform us that you no longer want EAACI to continually to store or process your personal information. Please be aware that we may decline your right for a number of reason, which are not limited to, having a lawful basis to process your information or us needing your information for the performance of a contractual obligation.

As a data subject, you have the right to stop any processing of your personal information. Please be aware that you must provide us with a legitimate reason for us to stop processing. Any request made that doesn’t conform to the GDPR will be rejected.

On occurrence EAACI may send you emails to make you aware for its own events, to render services you have ordered and information relative to your membership that we believe can benefit you, the data subject. As you have the right to object, you can by clicking the “unsubscribe” link at the bottom of the email you receive, to inform us that you no longer want to receive marketing emails from us.

Please note, by opting-out of emails from EAACI, will cause you the data subject not to receive relative communication regarding your EAACI membership (such as membership renewal, membership deactivation) which may cause issues in your membership profile.

The right to data portability will allow you as the data subject to have you personal information securely transferred to another organisation for processing. At EAACI we place this reasonability on you that data subject. When you make this request, we will export all information about you and securely transfer it to yourself. You, the data subject will be able to give this information to your chosen organisation.

If you have any question about these rights, please see “additional information”, section 10 of this policy.

8. Data transfers/Third parties

8.1 Providing your information to others

EAACI does not sell personal information to anyone or third parties.

EAACI may disclose your personal data (full name, date of birth, email, examination results where applicable), to some third parties insofar as reasonably necessary for the purposes, and on the legal bases, set out in this policy.

When it comes to advertising, EAACI will not host any advertising on this site. Third parties that we use are listed below:

CYIM
UEMS
IML (Institute of Medical Education)

 

8.2 EAACI NAS Dual Membership

When you register with one of our events or become a member with us, we will ask for personal information which is relevant to us providing you with our services. For us to provide you with a discount on our services, we share information between our national allergy societies on an annual basis. If you haven’t provided us with this information, this section will not apply to you.

8.3 YouTube Integration

In order to provide you the data subject with a media platform that include highlights, presentations and interviews from congress we embed videos from our YouTube account to our website. The YouTube platform is operated by Google and not EAACI.

When you select one of our videos and start playing, a connection will be made to the YouTube servers which will include minimal personal information as in IP Address. If you are happen to be logged in to your YouTube account while on our site, YouTube will be have access to additional information based on your YouTube personal profile. If you do not want to provide additional information, you can prevent this by signing out of your YouTube account. For more information on how YouTube collect and process your personal information be see https://policies.google.com/privacy?hl=en&gl=ZZ

8.4 Analytics

We use third-party analytic tools to better understand who is using the website and how people are using it so we can continuously improve it. These tools may use cookies and other technologies to collect information about your use of the website and your preferences and activities. These tools collect information sent by your device or the website and other information that assists us in improving the website. This information may be used to analyse and track data, determine the popularity of certain content, and better understand your online activity, among other things.

We use Google Analytics to better understand who is using the website and how people are using it. Google Analytics uses cookies to collect and store information such as website pages visited, places where users click, time spent on each website page, Internet Protocol address, type of operating system used, location-based data, device ID, search history, gender, age, and phone number. We use this information to improve the website and as otherwise described in this Privacy Policy. Please see http://Analytic.google.com/policies/privacy/partners/ for information about how Google Analytics uses this information, and visit https://tools.google.com/dlpage/gaoptout for information about the Google Analytics Opt-out Browser Add-on. Google may track your activity over time and across websites.

8.5 Wiley Journals

When you login our members area (My EAACI Portal), member will be able to click on two banners which will transfer you to from the EAACI domain to Wiley’s platform. The purpose of this is to provide the member’s access to publications that EAACI creates. By clicking on the Wiley banners no personal data is exchanged. For more information on how EAACI use Wiley Journals, please see Section 10 of this privacy notice.

8.6 Newsletters

Within our website we provide you to access to subscribe to our newsletter. Once you have subscribed, the only type of personal information that will be processed with be your email address. This will be first populated in our website platform first and then transferred to our mass mailing platform Campaign Monitor.

If you decide that you no long want to be subscribed to EAACI newsletters, you can do this by clicking the “unsubscribe” link at the bottom of the email you receive, which will inform us that you no longer want to receive a newsletters from us.

8.7 Information security with Transfers

In this Section 8.7, we provide information about the circumstances in which your personal data may be transferred to countries outside the European Economic Area (EEA).

We, EAACI do transfer personal information to third parties outside of the European Economic Area (EEA). We take steps to ensure that where your information is transferred outside of the EEA by our service providers and hosting providers, appropriate measures and controls are in place to protect information in accordance with applicable data protection laws and regulations. For example, we may share information with affiliates based outside the EEA for the purposes foreseen by this Privacy Notice. EAACI are subject to EAACI data protection policies designed to protect data in accordance with EU data protection laws. In each case, such transfers are made in accordance with the requirements of Regulations (EU) 2016/679 (the General Data Protection Regulations or “GDPR”) and may be based on the use of the European Commission’s Standard Model Clauses for transfers of personal data outside the EEA

We at EAACI has achieved the HONcode code of conduct which demonstrates the intent of our website to publish transparent information with accordance to offering quality health information. If you would like to verify this, please see click here.

All Information that is being transferred within the EEA we follow strict Information Transfer Policy, more can be requested from section 10 of this policy.

9. Right to complaint

We take any complaints about our collection and use of personal information very seriously.

If you think that our collection or use of personal information is unfair, misleading or inappropriate, or have any other concern about our data processing, please raise this with us through the appropriate channels below:

Contact Information
EAACI Head Office – Charalampos Kostaras
(For raising issues directly with EAACI)
By Post: EAACI Headquarters, 111 Hagenholzstrasse, 3rd Floor, 8050 Zurich, Switzerland
By email: gdpr@eaaci.org
By Website: https://www.eaaci.org/contact-top.html
By Phone: +41 44 205 55 33
Data Protection and Information Commissioner of Switzerland
(For raising issues about EAACI to the Commissioner)
By Post: Feldeggweg 1, 3005 Bern, Switzerland
By Website: www.admin.ch
By Email: contact20@edoeb.admin.ch
By Phone: +41 58 462 43 95
EU Representative
(For raising issues from data subjects based in the EU)
By Post: Rickert Rechtsanwaltsgesellschaft mbH, Kaiserplatz 7-9, 53113 Bonn, Germany
By email: datenschutz@rickert.net

10. Additional information

Your trust is important to us. That is why we are always available to talk with you at any time and answer any questions concerning how your data is processed. If you have any questions that could not be answered by this privacy notice or if you wish to receive more in depth information about any topic within it, please contact Charalampos Kostaras via email gdpr@eaaci.org

11. Review of this Notice

We keep this notice under regular review. This notice was last updated on 30th November 2023.

11.1 Amendments

We reserve the right to update this privacy notice at any time, and we will provide you with a new privacy notice when we make any substantial updates. We may also notify you in other ways from time to time about the processing of your personal information.