Prudentia Group, LLC, Prudentia Management and Technology Consulting LLP, and Prudentia Consulting India Pvt Ltd. (collectively, “Prudentia”, “we”, “us”, “our”) take the protection of personally identifiable information (“Personal Data”) very seriously. This Privacy Policy (the “Policy”) applies to Personal Data we may receive in our web-based applications PV TREND, MedCodr, E2B BRIDGE, NEOS, eQMS-Sign and eQUATe as well as in the course of providing Pharmacovigilance (PV) consulting services, coding services, and customer support services (collectively, the “Services”). This Policy does not apply to Personal Data we collect by other means, such as Personal Data that we receive directly through Prudentia’s own publicly accessible websites.
Prudentia acts as a Data Processor, for the Personal Data we process for our clients when providing our Services. This means that Prudentia’s clients determine the type of Personal Data they provide for Prudentia to process on their behalf and defines purpose and means of processing. Prudentia typically has no direct relationship with the individuals whose Personal Data it receives from its clients.
We receive your Personal Data from our clients in the course of providing the Services or, in certain cases, directly from individuals or data subjects of our client’s.
Prudentia processes Personal Data solely on documented instructions from its clients, who act as Data Controllers and determine the legal basis for the processing. Where required by applicable pharmacovigilance legislation, Prudentia may also process Personal Data to comply with legal obligations.
Prudentia typically processes the following types of Personal Data:
We retain Personal Data for as long as instructed by the respective client (that acts as a Data Controller). We delete the Personal Data submitted to us by our clients within six months of the termination of the applicable service agreement with Prudentia, unless otherwise instructed by our client within the service agreement, or in case applicable law requires or allows for a different retention period.
We share Personal Data with our service providers, who process Personal Data on behalf of Prudentia, and who agree to use the Personal Data only to assist us in providing our Services or as required by law. Our service providers include those providing the following services:
Our service providers may be located within or outside of the United States and we will require that those third parties maintain at least the same level of privacy and security that we maintain for such Personal Data, as defined in the adequate agreements with these providers. Where required under applicable law, transfers may also be protected through Standard Contractual Clauses (SCCs) or other approved transfer mechanisms.
Being part of Ergomed Group, Prudentia may share Personal Data with other Ergomed Group entities that support Prudentia in provisioning of the Services. Such sharing of data is regulated by Intra Group Data Processing Agreement.
We may disclose Personal Data as stated below: (i) to the extent required by law or if we have a good-faith belief that such disclosure is necessary in order to comply with official investigations or legal proceedings initiated by governmental and/or law enforcement officials, or private parties, including but not limited to: in response to subpoenas, search warrants, or court orders, or (ii) if we sell or transfer all or a portion of our company’s business interests, assets, or both, or in connection with a corporate merger, consolidation, restructuring, or other company change, (iii) to our subsidiaries or affiliates only if necessary for business and operational purposes as described in the section above, or (iv) to protect an individual’s vital interests. We also use and may otherwise process aggregated, anonymous data, which does not include any Personal Data, about individuals whose Personal Data we process in connection with providing our Services, as a group, for any legitimate business purpose, such as analyzing usage trends and seeking compatible business opportunities. Prudentia does not sell or share Personal Data for cross-context behavioral advertising.
Prudentia has implemented and will maintain technical, administrative, and physical measures that are reasonably designed according to industry standards to help protect Personal Data from unauthorized processing, such as unauthorized access, disclosure, alteration, or destruction. However, please note that no method of transmission over the Internet, or method of electronic storage, is 100% secure.
Depending on applicable law, individuals may have rights of access, rectification, erasure, restriction of processing, objection, data portability, and the right to lodge a complaint with a supervisory authority. Any data subject rights will be fulfilled by our clients (that are owners of Personal Data and Data Controllers). However, we are able to support our clients in fulfilling such requests. Requests should be sent directly to the Prudentia client who provided your Personal Data to Prudentia. Prudentia has limited rights to access Personal Data our clients submit to us. Therefore, if you contact us with such a request, please provide the name of the Prudentia client who submitted your Personal Data to us. We will forward your request to that client and provide any needed assistance as they respond to your request. Where required by applicable law, we will assist our clients in responding to consumer privacy requests.
With respect to Personal Data processed in the scope of this Policy, Prudentia Group, LLC complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), and Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce and the European Commission, and the Swiss Federal Administration to provide U.S. organizations with reliable mechanisms for personal data transfers to the United States from the European Union / European Economic Area, and Switzerland while ensuring data protection that is consistent with EU and Swiss law. Prudentia Group, LLC has certified to the Department of Commerce that it adheres to the DPF Principles with respect to such information. If there is any conflict between the terms in this privacy policy and the DPF Principles, the DPF Principles shall govern. Where applicable, Prudentia will work with our EU/Switzerland clients to assure the appropriate measures and data privacy agreements are put in place to secure and protect Personal Data between EU/Switzerland and United States. To learn more about the DPF, please visit https://www.dataprivacyframework.gov To view Prudentia Group, LLC’s certification, please visit https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt0000000TX44AAG&status=Active
For the projects conducted in European Economic Area (EEA) and clients located in the EEA, it is important to note that Prudentia GDPR representative in the European Union for data protection matters, pursuant to Article 27 of the General Data Protection Regulation of the European Union is Ergomed Klinicka Istrazivanja Zagreb. If you are in the EEA, Ergomed Klinicka Istrazivanja Zagreb can be contacted only on matters related to the processing of personal data within EEA. To contact Ergomed Klinicka Istrazivanja Zagreb (only on matters related to processing personal data in the EU): GDPRREP@ergomedgroup.com
Ergomed istraživanja Zagreb d.o.o., Oreškovićeva 20A, 10010 Zagreb, Croatia.
Where a privacy complaint or dispute cannot be resolved through Prudentia Group, LLC’s internal processes, Prudentia Group, LLC has agreed to participate in the VeraSafe Data Privacy Framework Dispute Resolution Procedure; https://verasafe.com/privacy-solutions/data-privacy-framework-dispute-resolution-program/. Subject to the terms of the VeraSafe Data Privacy Framework Dispute Resolution Procedure, VeraSafe will provide appropriate recourse free of charge to you. To file a complaint with VeraSafe and participate in the VeraSafe Data Privacy Framework Dispute Resolution Procedure, please submit the required information here: https://www.verasafe.com/public-resources/dispute-resolution/submit-dispute/
If your dispute or complaint can’t be resolved by us, nor through VeraSafe’s Data Privacy Framework Dispute Resolution Procedure, you may have the right to require that we enter into binding arbitration with you pursuant to the Recourse, Enforcement and Liability Principle and Annex I of the Data Privacy Framework.
Prudentia Group, LLC is subject to the investigatory and enforcement powers of the United States Federal Trade Commission.
If we make any material change to this Policy, we will post the revised Policy on our own publicly accessible websites and update the “Effective” date above to reflect the date on which the revised Policy became effective.
If you have any questions about this Policy or our processing of your Personal Data, please write to our privacy contact:
Ergomed Group Limited
Attn: Data Protection Officer (DPO)
1O Occam Court Occam Road,
Surrey Research Park,
Guildford GU2 7HJ,
UK
Email: dpo@ergomedgroup.com .