Privacy policy

Introduction

C.B.B. Lifeline Biotech Ltd (Lifeline Cord Blood and Tissue Bank) (hereinafter “we”, “us” or “our”) is the controller of the information collected or provided directly. We respect your privacy and are committed to protecting it through our compliance with applicable privacy and data protection laws and regulations. Please read this privacy policy carefully to understand our policies and practices regarding your information and how we will treat it. If you have any questions about our privacy practices, please refer to the end of this privacy policy for information on how to contact us. This privacy policy applies to information and medical records we collect:

-directly from you or

-through third parties in the standard course of the business we do in order to provide you with the service you requested.

though testing procedures as it is required in order to provide the services you requested in general, you can visit our websites or speak with a Lifeline representative without telling us who you are or revealing any personal information about yourself. If you choose to provide your personal information to us, you explicitly agree to our collection and use of such information as described in this Privacy Policy.

Collection of Personal Information

 

We collect and use several types of information the individuals we co-operate with, including information by which you may be personally identified and that is defined as personal data or personally identifiable information under applicable law (“Personal Information”), such as your first and last name, e-mail address, billing information, demographics, telephone number, or other (online) contact information, personal details, health related information and medical records. Categories of Personal Information we collect and use on or through our Website include:

- Information that you provide by filling in forms, in particular at the time of first contact with us.

- Records and copies of your correspondence (including e-mail addresses), if you contact us.

- Details of transactions you carry out, if any, based on the Agreement you have signed with us.

 

Purposes for Which We Use Your Personal Information

In general, we use information that we collect about you or that you provide to us, including Personal Information and Sensitive Personal Information, for following purposes:

- Provision of services: to provide you with information, products or services that you request from us in accordance with the agreement we have between us;

- Customer management: to manage your account, to provide you with customer support and with notices about your account, updates about the products or services we offer or provided to you;

- Functionality and security: to detect, prevent, and respond to actual or potential fraud, illegal activities, or intellectual property infringement;

- Compliance: to enforce our terms and conditions and to comply with our legal obligations as these derive from the applicable laws or our regulators;

- in any other way we may describe when you provide the information; or for any other purpose with your consent or with our written agreement provided separately from this privacy policy. Lifeline takes precautions including administrative, technical, and physical measures to safeguard your personal information against loss, theft, and misuse, as well as against unauthorized access, disclosure, alteration, and destruction. Lifeline uses encryption technology when you communicate with us through your online account mentioned below. It is also important for you to help protect against unauthorized access to your information. You are solely responsible for signing off of our website each time you finish using it and for securing your log-in information and security responses. Any transactions using your log-in and security responses will be deemed to be authorized by you.

 

Disclosure of Your Personal Information

We want you to understand when and to whom we disclose Personal Information and other information we have collected about you or your activities on the Website. We do not share your Personal Information with third parties except as indicated below: · Local Distributor. We share above categories of Personal Information with our Local Distributors (in case this is applicable in your case) to the extent this is necessary for the purposes of provision of services, client management, customization of content, and in order to provide the services you have requested in the Agreement between you and us. · Service providers. To our authorized service providers that perform certain services on our behalf, including for purposes of provision of the services you requested from us, customer management and security, electronic data management and backup. These services may include fulfilling orders, processing credit card payments, risk and fraud detection and mitigation, providing customer service and assistance. These service providers may have access to Personal Information needed to perform their functions but are not permitted to share or use such information for any other purposes. We have taken all reasonable steps to ensure that they comply with the current data protection regulations. · Other. To the extent that this is necessary to fulfill any other purpose not mentioned above for which you provided Personal Information and, if applicable, your consent separately from this privacy policy. We also disclose your Personal Information to other third parties, including official authorities, courts, or other public bodies: · In response to a subpoena or similar investigative demand, a court order or other judicial or administrative order, or a request for cooperation from a law enforcement or other government agency; to establish or exercise our legal rights; to defend against legal claims; to comply with applicable law or cooperate with law enforcement, government or regulatory agencies; or to enforce our Website terms and conditions or other agreements or policies; or as otherwise required by law (including responding to any government or regulatory request). In such cases, we may raise or waive any legal objection or right available to us, in our sole discretion. · To the extent a disclosure is necessary in connection with efforts to investigate, prevent, report or take other action regarding illegal activity, suspected fraud or other wrongdoing; to protect and defend the rights, property or safety of our company, our users, our employees, or others; to maintain and protect the security and integrity of our Website or infrastructure. Third parties to whom we may disclose Personal Information may have their own privacy policies which describe how they use and protect Personal Information. If you want to learn more about their privacy practices, we encourage you to visit the websites of those third parties.

 

You can edit, update, correct and/or request to delete information about you.

If you prefer not to receive information from us please let us know by calling us at 00357 22 817 222, or by sending us an email to qualitymanager@lifelinecordblood.com. Please be sure to include your email address, mailing address, full name, and specifically what information you do not want to receive. If you would like to update or correct your personal details kept by us, including email address, mailing address or other personal information you may call us at 00357 22 817 222, or send us a written request to below address (P.O.Box) or create an online account with us by registering through our website: www.lifelinecordblood.com. We strongly encourage you to do so but it is very important to help protect against unauthorized access to your information: You are solely responsible for signing off of our website each time you finish using it and for securing your log-in information and security responses. Any transactions using your log-in and security responses will be deemed to be authorized by you. You may also contact us by postal mail at C.B.B. Lifeline Biotech Ltd., P.O.Box 28987 2084 Nicosia, Cyprus, Attn: Customer Service.

 

How We Store Your Personal Information

The information that we collect about you, including Personal Information, will be stored and processed in Cyprus and/or in the Countries and regions in which we and the third parties mentioned above maintain facilities. If you are located in the European Union or other regions with laws governing data collection and use that may differ from European data protection laws, please note that in the course of providing you with the service you requested we may transfer Personal Information to some of these countries and jurisdictions that have data protection laws that do not provide the exact same level of protection as in your jurisdiction, however we make every effort possible to verify and audit that the processor and sub processors shall provide the best level of protection of personal data.

 

Retention of Personal Information

To the extent we have collected your Personal Data for purposes of provision of services, customer management, and customization of content (for descriptions of these purposes see above), we keep your Personal Information for as long as you have an account with the Website, as needed to provide you with our respective services and in compliance with relevant laws of Cyprus. For further information regarding specific retention period please contact us at qualitymanager@lifelinecordblood.com The period for which we keep your Personal Information that is necessary for compliance and legal enforcement purposes varies and depend on the nature of our legal obligations and claims in the individual case. However, with regards to the medical records we maintain, we are obliged by the law to maintain such records for a period of 20 years from the day the last medical data have been collected.

 

Legal Bases for Collection, Use and Disclosure of Your Personal Information

There are different legal bases that we rely on to collect, use and disclose your Personal Information, namely:

• Performance of contract: The use of your Personal Information for purposes of providing the services, customer management and functionality and security as described above is necessary to perform the services provided to you under our term and conditions and any other contract that you have with us.

• Compliance with legal obligation: We are permitted to use your Personal Information in to the extent this is required to comply with a legal obligation to which we are subject.

• Informed Consent: We also rely on your consent for processing your personal information for the purposes of providing the services to you How We Protect the Security of Your Personal Information We take appropriate security measures (including physical, electronic and procedural measures) to safeguard your Personal Information from unauthorized access and disclosure. For example, only authorized employees are permitted to access Personal Information, and they may do so only for permitted business functions. In addition we have trained our employees on how to handle, manage and process personal data, applied upgraded technical measures and transformed our policies and procedures in a way that will comply with the General Data Protection Regulation. Users should also take care with how they handle and disclose their Personal Information and should avoid sending Personal Information through insecure email. We are not responsible for circumventions of any privacy settings or security measures contained on the Website.

 

Choices About How We Collect, Use and Disclose Your Personal Information

We strive to provide you with choices regarding the Personal Information you provide to us. · You can choose not to provide us with certain Personal Information, but that may result in you being unable to receive our services. · When you register or enroll with us, you may be given a choice as to whether you want to receive email messages, newsletters or material about scientific updates, improvements, or any other information about our services. If consented yet later on you decide you no longer want to receive emails or newsletters from us, you will need to avail yourself of the unsubscribe mechanism set out in the applicable communication or contact us on the email we provide for that purpose. It may take up to seven days for us to process an opt-out request. We may send you other types of transactional and relationship e-mail communications, such as service announcements, administrative notices, and surveys, without offering you the opportunity to opt out of receiving them as these will related directly to your relationship with us. · If you provided Personal Information, you may terminate your relationship with us at any time as per the provision of the between us agreement. If you choose to do so, your Personal Information will be deleted in accordance with our retention policy however, we are obliged to maintain your medical records as prescribed by the relevant legislation.  

 

Your Rights Related to Your Personal Information

Subject to the provisions of the General Data Protection Regulation, you have certain rights regarding the Personal Information we collect, use or disclose and that is related to you, including the right

• to receive information on the Personal Information concerning we hold about you and how such Personal Information is used (right to access);

• to rectify inaccurate Personal Information concerning you (right to data rectification);

• to delete/erase your Personal Information (right to erasure/deletion, “right to be forgotten”);

• to receive the Personal Information provided by you in a structured, commonly used and machine-readable format and to transmit those Personal Information to another data controller (right to data portability)

• to object to the use of your Personal Information where such use is based on our legitimate interests or on public interests (right to object); and

• in some cases, to restrict our use of your Personal Information (right to restriction of processing). If we ask for your consent to use your Personal Information, you can withdraw your consent at any time. You may, at any time, send us an e-mail at qualitymanager@lifelinecordblood.com to exercise your above rights in accordance with the applicable legal requirements and limitations. If you are located in the European Economic Area, you have a right to lodge a complaint with your local data protection authority. Note that some requests to delete certain Personal Information will require the deletion of your user account as the provision of user accounts are inextricable linked to the use of certain Personal Information (e.g., your e-mail address). Also note that it is possible that we require additional information from you in order to verify your authorization to make the request and to honor your request. You can delete your User Contributions from the Website as specified in the “User Contributions” section.

 

Changes to Our Privacy Policy

We may modify or revise our privacy policy from time to time. Although we may attempt to notify you when major changes are made to this privacy policy, you are expected to periodically review the most up-to-date version found at our website so you are aware of any changes, as they are binding on you. If we change anything in our privacy policy, the date of change will be reflected in the “last modified date”. You agree that you will periodically review this privacy policy and refresh the page when doing so. You agree to note the date of the last revision to our privacy policy. If the “last modified” date is unchanged from the last time you reviewed our privacy policy, then it is unchanged. On the other hand, if the date has changed, then there have been changes, and you agree to re-review our privacy policy, and you agree to the new ones. By continuing to use the Website subsequent to us making available an amended version of our privacy policy in a way that you can easily take notice of it, you thereby consent to such amendment.

 

Web-based communications differ if you are located outside Cyprus

We control and operate this website from our head offices in Cyprus (EU). Any information you provide to Lifeline through this website is stored and processed on Lifeline’s servers in Cyprus or on those of our third-party service providers. Persons who choose to access this website from outside Cyprus EU, do so on their own initiative, and are responsible for compliance with local laws, rules and regulations, if and to the extent applicable.

 

Enforcement; Cooperation

We regularly review our compliance with this privacy policy. Please feel free to direct any questions or concerns regarding this privacy policy or our treatment of Personal Information by contacting us at qualitymanager@lifelinecordblood.com. When we receive a formal written complaint, it is our policy to contact the complaining party regarding his or her concerns. We will cooperate with the appropriate regulatory authorities, including local data protection authorities, to resolve any complaints regarding the collection, use and disclosure of Personal Information that cannot be resolved by an individual and us.

 

No Rights of Third Parties

This privacy policy does not create rights enforceable by third parties or require disclosure of any Personal Information relating to users of the Website.

 

No Error Free Performance

We do not guarantee error-free performance under this privacy policy. We will use reasonable efforts to comply with this privacy policy and will take prompt corrective action when we learn of any failure to comply with our privacy policy. We shall not be liable for any incidental, consequential or punitive damages relating to this privacy policy. This website is not intended to collect or maintain personally identifiable information from persons under 12 years old. IF YOU ARE UNDER 12 YEARS OF AGE, PLEASE DO NOT USE OR ACCESS THIS WEBSITE. If Lifeline learns that personally identifiable information has been collected from a person under 12 years old without verifiable parental consent, then Lifeline will take the appropriate steps to delete this information and not to assume any responsibility for the information provided.

 

Contact Information

If you have any questions about this privacy policy or our information-handling practices, please contact us at qualitymanager@lifelinecordblood.com. You may also contact us at C.B.B. Lifeline Biotech Ltd., P.O.Box 28987 2084 Nicosia, Cyprus, Attn: Customer Service, telephone +357 22817222.