The European College of Aesthetic Medicine & Surgery (“ECAMS”) fully respects your right to privacy and we are committed to ensuring that your privacy is protected. Whether you deal with ECAMS as a member, customer, patient, supplier, or otherwise, you are entitled to the protection of your personal information. This data may relate to your name, telephone number, email address or any other information relating to you.
Please read the following privacy statement to learn more about how we collect, store, use and disclose information about you when you interact with ECAMS. This Policy applies to all your Personal Data collected by (or on behalf of) ECAMS (which includes its group companies), together referred to in this Policy as “ECAMS”, “we”, “us” and”our”.
Who is responsible for the processing of your Personal Data?
For the purpose of the EU General Data Protection Regulation 2016/679 (“GDPR”), the data controller is Experience Medical Limited (t/a the European College of Aesthetic Medicine & Surgery) whose registered office is Heritage House, Dundrum Office Park, Dundrum, Dublin 14. Office address is 3 Brighton Place, Foxrock, Dublin 18.
Who can you contact if you have Questions or Requests?
Our Data Protection Manager can will handle your questions or requests relating to this Policy or your Personal Data. For any questions or requests or complaints concerning the application of this Policy or to exercise your rights, as described in this Policy, you may contact us at the Data Protection Manager at: [email protected].
We value your Personal Data entrusted to us and we are committed to processing your Personal Data in a fair, transparent and secure way. The key principles that ECAMS applies are as follows:
- Lawfullnes: we will only collect your Personal Data in a fair, lawful and transparent manner.
- Data minimisation: we will limit the collection of your Personal Data to what is directly relevant and necessary for the purposes for which they have been collected.
- Purpose limitation: we will only collect your Personal Data for specified, explicit and legitimate purposes and not process your Personal Data further in a way incompatible with those purposes.
- Accuracy: we will keep your Personal Data accurate and up to date.
- Data security and protection: we will implement technical and organisational measures to ensure an appropriate level of data security and protection considering, among others, the nature of your Personal Data to be protected. Such measures provide for the prevention of any unauthorised disclosure or access, accidental or unlawful destruction or accidental loss, or alteration and any other unlawful form of Processing.
- Access and rectification: we will process your Personal Data in line with your legal rights.
- Retention limitation: we will retain your Personal Data in a manner consistent with the applicable data protection laws and regulations and for no longer than is necessary for the purposes for which it has been collected.
- Protection for international transfers: we will ensure that any of your Personal Data transferred outside the EEA is adequately protected.
- Safeguards re third parties: we will ensure that Personal Data access by (and transfers to) third parties are carried out in accordance with applicable law and with suitable contractual safeguards.
- Lawfulness of direct marketing and cookies: if we send you promotional materials or place cookies on your computer, we will ensure that we do so in accordance with applicable law.
How do we collect your Personal Data?
ECAMS may collect your Personal Data in two ways:
Directly provided Data: When you sign up as a member of ECAMS, purchase our products or communicate with us, you may choose to voluntarily give us certain information – for example, by filling in text boxes or completing registration forms. We will only collect this information when you have provided us with your consent.
Publicly Available Data: We may collect your data form publicly available sources. We will always ask for your permission before using your contact details to send you direct marketing materials about our courses and member benefits.
What information do we Collect?
We receive and store your Personal Data that is necessary for the provision of our training courses in aesthetic medicine and surgery. We may collect, use, store and transfer different kinds of personal data about you which we have grouped together follows:
- Identity Data including first name, last name, username or similar identifier, medical registration number, date of birth and gender;
- Contact Data including residential address, email address and telephone number(s);
- Transaction Data including details about payments to and from you and other details of products and services you have purchased from us;
- Technical Data including internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website, this is collected via google analytic;
- Marketing and Communications Data including your preferences in receiving marketing from us and our third parties and your communication preferences.
What is the legal basis for possessing my Personal Data?
The principal legal basis for this processing is our legitimate interest in the administration and operation of our training courses in aesthetic medicine and surgery, as well as our legitimate interest in marketing and promoting ECAMS’ services. We always include an unsubscribe button in our communications, so you can opt out of receiving such communications at any time.
In addition, please note that in accordance with applicable data protection law, your Personal Data can be processed if:
- you have given us your consent for the purposes of the Processing. For the avoidance of doubt, you will always have the right to withdraw your consent at any time;
- it is necessary for the performance of a contract to which you are a party;
- with such processing, we pursue a legitimate interest that is not outbalanced by your privacy rights. Such legitimate interest will be duly communicated to you if applicable; or
- it is required by law.
How do we use the information?
We will only process your Personal Data for specified, explicit and legitimate purposes and we will not process your Personal Data further in a way that is incompatible with those purposes. Such purposes include the provision of our training courses in aesthetic medicine and surgery, the improvement of your visit on one of our websites or portals, the improvement of our products and services more generally, the offering of new services, marketing communications and actions.
We may also use the information you send to us to communicate with you via email and, possibly, other means, regarding our training courses in aesthetic medicine and surgery, events or services we think may be of interest to you, if you have consented to such contact. However, you will always be able to opt-out of such communications at any time (see the “How can I Exercise my Data Subject Rights” section below).
Is my Personal Data secure?
We use appropriate technical, organisational and administrative security measures to protect any information we hold in our records from loss, misuse, and unauthorized access, disclosure, alteration and destruction. These measures have been designed taking into account our IT infrastructure, the potential impact on your privacy and the costs involved and in accordance with current industry standards and practice.
Your Personal Data will only be processed by a third party data processor if that data processor agrees to comply with those technical and organisational data security measures.
Maintaining data security means protecting the confidentiality, integrity and availability of your Personal Data:
- Confidentiality: we will protect your Personal Data from unwanted disclosure to third parties.
- Integrity: we will protect your Personal Data from being modified by unauthorised third parties.
- Availability: we will ensure that authorized parties are able to access your Personal Data when needed.
Our data security procedures include: access security, backup systems, monitoring, review and maintenance, management of security incidents and continuity, etc.
How long will we use your Personal Data for?
We retain the Personal Data of our members for the duration of their membership or for so long as you have consented to receiving marketing communications from us. We always include an unsubscribe button in our communications, so you can opt out of receiving such communications at any time, in which case, we will delete your personal data.
We will only retain your Personal Data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for Personal Data, we consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorised use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether we can achieve those purposes through other means, and the applicable legal requirements.
Information We Automatically Collect:
When you visit our Website we collect certain information related to your device, such as your device’s IP address, referring website, what pages your device visited, and the time that your device visited our Website.
Disclosure of Personal Data
ECAMS will not sell or rent your Personal Data to third party. Depending on the purposes for which we collect your Personal Data, we may disclose it to the following categories of recipients, which will then process your Personal Data only for one of the following purposes:
a) Within our organisations:
- Our authorised staff members;
- Our affiliates and subsidiary companies;
b) Other third parties:
- when required by law or as lawfully necessary to protect ECAMS:
- to comply with the law, requests from authorities, court orders, legal procedures, obligations related to the reporting and filing of information with authorities, etc.;
- to verify or enforce compliance with ECAMS’s policies and agreements; and
- to protect the rights, property or safety of ECAMS and/or its customers;
- in connection with corporate transactions: in the context of a transfer or divestiture of all or a portion of its business, or otherwise in connection with a merger, consolidation, change in control, reorganisation or liquidation of all or part of ECAMS’s business.
If you have consented to receiving certain promotional or marketing communications from us, you can opt-out of receiving such promotional or marketing communications from us at any time, by using the unsubscribe link in the emails communications we send, or send us an email or message via our website.
Automated decision-making and profiling
We do not use any personal data for the purpose of automated decision-making or profiling.
How can I Exercise my Data Subject Rights?
Under the General Data Protection Regulation, you have the following rights:
Right to object: If we are using your data because we deem it necessary for our legitimate interests to do so, and you do not agree, you have the right to object. We will respond to your request within 30 days (although we may be allowed to extend this period in certain cases). Generally, we will only disagree with you if certain limited conditions apply.
Right to withdraw consent: Where we have obtained your consent to process your Personal Data for certain activities, or consent to market to you, you may withdraw your consent at any time.
Right to Rectification: if your Personal Data that we hold is inaccurate or incomplete, you have the right to request the rectification of your Personal Data.
Data Subject Access Requests: Just so it's clear, you have the right to ask us to confirm what information we hold about you at any time, and to provide you with copies of that information. We will respond to your request within 30 days. At this point we may comply with your request or, additionally do one of the following:
- we may ask you to verify your identity, or ask for more information about your request; and
- where we are legally permitted to do so, we may decline your request, but we will explain why if we do so.
Right to erasure: In certain situations (for example, where we have processed your data unlawfully), you have the right to request us to "erase" your Personal Data. We will respond to your request within 30 days (although we may be allowed to extend this period in certain cases) and will only disagree with you if certain limited conditions apply. If we do agree to your request, we will delete your data.
Right of data portability: If you wish, you have the right to transfer your data from us to another data controller. We will help with this – either by directly transferring your data for you, or by providing you with a copy in a commonly used machine-readable format.
Right to lodge a complaint with a supervisory authority: You also have the right to lodge a complaint with the Office of the Data Protection Commissioner.
If your interests or requirements change, you can unsubscribe from part or all of our marketing content (for example job role emails or ECAMS newsletters) by clicking the opt-out link in the email, or by sending us a request via email).
Changing this Policy
We may need to change this Privacy Statement from time to time. We will alert you to material changes by, for example, placing a notice on our websites and/or by sending you an email (if you have registered your e-mail details with us) when we are required to do so by applicable law. You are responsible for periodically reviewing this Privacy Statement.
This Privacy Statement was most recently updated on 25/05/2018.