Jan de Vries Healthcare Ltd conducts research into and publishes healthcare information under the healthcare brand Jan de Vries. The company respects the privacy of all visitors to its website – www.jandevrieshealth.co.uk.co.uk – and ensures that any personal information that you make available is treated confidentially. Jan de Vries does not pass on any personal data to third parties and only makes this data available when it is required to fulfil your order in our online shop or for prize contests. Jan de Vries Healthcare Ltd takes the protection of your data very seriously. Our employees and any third parties commissioned by us are obliged to respect the confidentiality of your data.
1. Name and address of the data controller and of the data protection officer
1.1 Name and address of the data controller
Jan de Vries Healthcare Ltd
Tel: 01294 204742
Email: [email protected]
1.2 Name and address of the data protection officer representing the data controller
Bioforce (UK) Ltd
2 Brewster Pace
Tel: 01294 204704
Email: [email protected]
2. Collection, processing and use of personal data
When you use our online services or interact with our website (e.g. by completing and submitting the contact form), personal data will be collected, processed and used.
2.1 Personal data
Personal data means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
They include, above all, information that allow conclusions to be made about your identity, for example, your name, phone number, address or email address. Statistical data that we may, for example, collect during your visit to our online services and that cannot be associated with your person is not included in the concept of personal data.
2.2 Use for informational purposes
We do not collect any personal data when you simply use our online services for informational purposes, with the exception of data that your browser passes on in order to allow you to visit our website. Such data includes the:
Date and time of your query
Time zone difference to Greenwich Mean Time (GMT)
Requested content (actual page)
Access status/HTTP status code
Transmitted data volume for the request
Web page from where the request originated
Operating system and its user interface
Language and version of the browser
User IP addresses are deleted or anonymised after use terminates. In the event of anonymisation, the IP addresses are modified in such a way that particulars about personal or material circumstances can no longer be attributed to an identified or identifiable natural person, or only with a disproportionately great investment of time, cost and effort. We analyse data in so-called log files in an anonymised form in order to further improve Jan de Vries’s online services, to make it more user-friendly and to allow errors to be found and rectified more quickly. They are also used to manage service capacities and, where necessary, to allow adequate data volumes to be made available.
2.3 Contact form and other interactions
In addition to the purely informational use of our online services, there are various ways for you to interact with us, and for us to offer services that you may be interested in using. These include, in particular, the contact form and registration for our newsletter as well as tests and checks and prize contests. In order to make use of these, you must provide additional personal data that we will use to provide the service in question and which we will also save. We will only use the data for the underlying purpose and in compliance with principles of data protection.
2.4 Storage period for personal data
We will only store your personal data for as long and to the extent that it is required for the purpose for which it was collected. Personal data subject to a legal retention obligation will be deleted when the legal retention period expires. Other personal data will be deleted as soon as it is no longer required for its purpose or in order to assert, exercise or defend legal claims.
We offer you the option on our website to subscribe to free newsletters on selectable subject areas.
We use Dotmailer, a service of Dotmailer Ltd., 1 London Bridge, London, United Kingdom, to send out our newsletter. We only store this information for the purpose of being able to send you the newsletter. Moreover, we store your IP address and the times of registration and confirmation in order to prevent any misuse of your personal data.
Your email address is the only mandatory information required to send you the newsletter. The disclosure of additional, specially marked information is voluntary and is only used to personalise the newsletter for you.
You can revoke your consent to receive the newsletter at any time. You can do this by clicking on the link provided in every newsletter email, by sending an email to [email protected] or by informing us of your revocation in any other manner. Any details disclosed will not be passed on to third parties. Your data will be deleted completely after your revocation.
2.6 Disclosure of data to third parties
Data collected by Jan de Vries will only be passed on to a third party if this is necessary for the purpose of executing a contract or payment, or you have given your consent to this in advance. Our service providers may only use any such disclosed data to perform their task. They were carefully chosen by us and given instructions in writing. They are obliged to follow our instructions and are monitored by us at regular intervals. It is forbidden for information to be used for any other purpose, and none of the service providers we commission will do so.
Cookies are small files that are stored on your data storage medium and which store specific settings and data required for the exchange of information with our system via your browser. Cookies cannot execute any programmes or transfer viruses to your computer. They are used to make our overall online services more user-friendly and effective.
There are two basic different types of cookie: session cookies, which are deleted when you close your browser (i.e. at the end of the session); and temporary/permanent cookies, which are stored for a longer period, or permanently, on your data storage medium. Storing these cookies helps us to design our website and makes it easier for you to use it, for example, by remembering certain input that you make in such a way that you do not have to constantly re-enter it.
You can delete the cookies in your browser’s security settings at any time and also configure your browser settings in accordance with your wishes (e.g. accept third-party cookies or reject all cookies). The help function in the menu bar of your web browser will generally show you how you can reject new cookies and delete those already received. In this case, however, we wish to point out that you may not be able to use all the functions of our online offering.
3.1 Cookies at Jan de Vries
The cookies we use cannot be attributed to a specific person and thus not to you either. When a cookie is activated, it is assigned an identification number. It is not possible to attribute your personal data to this identification number at any time, and no attempt is made to do so either. We do not store your name or similar data that make it possible to attribute the cookie to you.
3.2. Web analysis with Google Analytics
Google will use the information obtained by the cookies to analyse your use of the website, to compile reports about website activities on behalf of the website operator and to provide additional services associated with website and Internet use. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google’s behalf.
As explained above, you can configure your browser in such a way that it rejects cookies, or you can prevent the data generated by the cookie relating to your use of this website (including your IP address) from being collected and processed by Google by downloading and installing this browser plug-in.
As an alternative to the browser add-on, or when using a browser on mobile devices, you can activate an opt-out cookie in order to prevent any future collection of data by Google Analytics on this website (the opt-out only works in the browser and for the domain). If you delete your cookies in this browser, you will have to click on this link again.
4. Data subjects rights
4.1 Right to information
You may at any time request information regarding the data stored about you, about the processing purposes, the categories of personal data that are processed, recipients or categories of recipients to whom personal data has been disclosed or are to be disclosed, and if possible, the planned duration of retention of personal data or, if this is not possible, the criteria used to define this period.
You can contact our data protection officer or any other employee of our company any time to make use of this right to information.
4.2 Right to correction, erasure or restrictions to processing
You are entitled to request immediate correction to your personal data at any time.
Furthermore, you can request the erasure of your personal data if the data is no longer required for the purpose for which it was collected, you wish to revoke your consent to processing and there is no other legal basis for its processing, you wish to object to processing, and there are no overriding, justifiable reasons for processing, or you wish to object to the processing of data for direct marketing when personal data was processed unlawfully, or when erasure is legally binding for us.
Moreover, you can request a restriction to the processing of your personal data if you dispute the accuracy of your personal data – namely for as long as it takes us to check the accuracy of data – if processing is unlawful but you reject the erasure and instead wish to restrict the use, if we no longer require your personal data for processing but you require data to assert, exercise or defend legal claims, or if you have objected to processing but it has not yet been clarified whether justified reasons on our part outweigh your reasons.
You can contact our data protection officer or any other employee of our company any time to assert the aforementioned rights.
4.3 Right to object
You are entitled to object at any time to the processing of your personal data for reasons arising from your particular situation if processing is necessary for the performance of a task carried out in the public interest or subject to the exercise of official authority vested in us, or if processing is performed in pursuit of our legitimate rights or those of third parties, and your basic rights or basic freedoms requiring the protection of personal data do not have priority. In this case, we will not continue to process your personal data unless we can provide proof of compelling, legitimate reasons for processing that outweigh your interests, rights and freedoms, or if processing serves the assertion, exercise or defence of legal claims.
The right to object also exists when we use personal data for direct marketing; this also applies to profiling when it is associated with direct marketing. Your personal data will no longer be used for direct marketing purposes following objection.
You can contact our data protection officer or any other employee of our company at any time to make use of this right to objection.
4.4 Right to revoke your consent
You also have the right to revoke your consent to the processing of your personal data at any time without affecting the legitimacy of the processing based on your consent up to the time of revocation.
You can contact our data protection officer or any other employee of our company at any time to make use of this right of revocation.
5. Social plug-ins
Facebook is a social network operated by Facebook Ireland Limited (Hanover Reach, 5–7 Hanover Quay, Dublin 2, Ireland). Facebook functions can be recognised by the Facebook logo. Depending on the type of functions, additional information may also appear (e.g. ‘Share’, ‘Like’).
When a Jan de Vries page contains a Facebook button and you click on this button, your browser or the application will establish a direct connection with the Facebook servers and the button for the function in question will be loaded from there. In doing so, the information that the respective Internet page of Jan de Vries has been accessed shall be transmitted to Facebook.
An exception is made, however, when you visit a page where we use a Facebook plug-in by means of which we present Jan de Vries’s latest Facebook activities on www.jandevrieshealth.co.uk. In this case, your browser or the application will establish a direct connection with the Facebook servers.
If you are simultaneously logged into Facebook as a user, it is also possible that a page visit can be allocated to your profile on Facebook. If you click on integrated Facebook buttons and then log into Facebook (or are already logged in), the information that was ‘liked’ or ‘recommended’ can be published on Facebook in your profile and your timeline in an abbreviated form. Facebook may thus collect and store additional usage data, if applicable. It is therefore possible for Facebook user profiles to be created that go beyond what you yourself disclose on Facebook.
At no time does Jan de Vries find out which Facebook buttons you have used and when; instead Facebook only receives summarised, non-personal statistics about the use of Jan de Vries’s fan pages on Facebook and summarised statistics about the use of Facebook buttons.
Twitter is a micro blogging service operated by the US company Twitter, Inc. (795 Folsom St., Suite 600, San Francisco, CA 94107). If you access one of our web pages that contains a Twitter button and click on that Twitter button, your browser will establish a direct connection with Twitter servers, and the button will load from there. In doing so, the information that the respective Internet page of Jan de Vries has been accessed shall be transmitted to Twitter. It is thus possible for Twitter to collect and also store usage data even when you are not logged in.
An exception is made, however, when you visit a page where we use a Twitter plug-in by means of which we present Jan de Vries’s latest Twitter activities on www.jandevrieshealth.co.uk. In this case, your browser or the application will establish a direct connection with the Twitter servers without you specifically clicking on the Twitter button.
When you click on the Twitter buttons and ‘tweet’ information via the Twitter window that opens up, the tweeted information will be transferred to Twitter. This information will then be published in your Twitter user profile.
The video platform ‘YouTube’, where users can upload videos and make them publicly available, is operated by YouTube LLC, C901 Cherry Ave., San Bruno, CA 94066, USA and is a subsidiary of Google Inc., based in San Bruno, California, USA.
We have integrated YouTube video clips in our online offering. These are stored on http://YouTube.com and can be played directly on our web pages. The videos have all been integrated in ‘advanced data protection mode’, i.e. no data about you as a user will be transferred to YouTube if you do not play the videos. It is only when you play the videos that the following data is sent. We have no influence on the transfer of data.
By playing the video, the third party receives the information that you accessed the corresponding sub-page of our website. Moreover, additional information about the purpose and extent of data collection and about the processing of such data is collected by the plug-in provider. You can obtain more information about how YouTube collects, processes and uses your data in the information provided on data privacy at: https://policies.google.com/privacy. You will also find additional information on your associated rights and the setting options you can use to protect your privacy.
The information that you accessed the corresponding sub-page of our website will be sent to YouTube irrespective of whether you are logged into a YouTube user account, or whether such an account exists. If you are logged into YouTube as a user, the data will be attributed directly to your account. If you do not want this information to be attributed directly to you, you must log out of your user account before activating the button.
YouTube stores the data as user profiles and uses it for the purposes of advertising, market research and/or a custom design of its web page. This type of evaluation is used in particular (including for users not logged in) to create user-specific advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of such user profiles. Please contact YouTube if you wish to exercise your right to object.
6. Google Maps
This website uses the map service Google Maps operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (‘Google’). This service is used by us in particular to provide the integrated ‘store finder’ service. In order for the Google map material to be integrated and displayed in your web browser, your web browser must establish a link to a Google server that may be located in the USA when it accesses a contact page. This provides Google with information that the contact page of our online access was accessed by your device’s IP address. You can find additional information in the Google Maps Terms of Service.
7. Data security
We undertake the latest technical, state-of-the-art measures to ensure data security, in particular with the aim of protecting your personal data against risks during data transfers and against access by third parties. These are constantly adapted to reflect the current state of the art.
8. Purpose of data collection and legal basis
We process personal data in order to ensure a smooth connection establishment to our website and ease of use for visitors, to evaluate system security and stability and for other administrative purposes. The legal basis is article 6 section 1 p. 1 lit. f of the GDPR (General Data Protection Regulation) Moreover, we process data with your explicit consent in accordance with article 6 section 1 p. 1 lit. a of the GDPR as well as to meet our contractual obligations to you or to perform pre-contractual measures in response to your enquiry in accordance with article 6 section 1 p. 1 lit. b of the GDPR.
Irvine UK, May 23, 2018