Xtrac Privacy and Data Protection Policy and Notice
Xtrac O.S Ltd. (“Xtrac”, “we”, “us”, “our” or the “Company”) provides a patented lead extraction medical solution, provided to cardiac disease patients who require extraction of their cardiac implantable electronic devices (the “Medical Solution” or the “Services”). The medical solution involves the use of a unique medical device intended to reduce the risk and tissue damage involved in lead extraction procedures (the “Medical Device”).
Xtrac Ltd. respects the privacy of its clients, partners, clinical trial participants, vendors, service providers and website visitors, and is committed to protecting the personal information that is shared with us (these and any others with respect to whom we collect personal data, shall collectively be referred to as “you” or “Data Subjects”).
For the purposes of EU General Data Protection Regulation (the “GDPR”) and other applicable privacy laws, Xtrac is a data controller (“Controller”) in relation to the personal data of the representatives of our clients and prospective clients, employees, partners, vendors, website visitors and clinical trial participants.
WHICH INFORMATION MAY WE COLLECT?
Summary: we collect various categories of personal data in order to meet our contractual obligations, and also to meet various legitimate interests, such as fraud prevention and marketing. We also collect clinical trial data in order to conduct clinical research regarding our Medical Solution.
One type of data collected is non-identifiable and anonymous information (“non-personal data”). We also collect several categories of personal data (“Personal Data”), as described below.
(a) Contact Information and other personal data provided voluntary by you:
We collect Personal Data when you or your organization send it to us, or when a vendor, distributor or other business partner, sends it to us; we also collect Personal Data through our website and through our interactions with you.
Personal Data which we collect consists of any details which are personally identifiable and which are provided consciously and voluntarily by you, or by an organization you represent or are associated with. We collect Personal Data required to provide Services when you register interest, or when you provide us such information in meetings or conferences, or in the course of preparing a contract, or when contacting us or submitting requests for information or support, through your use of our website, by email, or other ways in which you communicate and interact with us. This personal data generally includes your name (first and last), email address, phone number, job title, company name, country and other information you may choose to provide to Xtrac.
You do not have any legal obligation to provide any information to Xtrac. However, we require certain information in order to perform contracts, for internal audit purposes or to provide any Services. If you choose not to provide us with certain information, then we may not be able to provide you or your organization with some or all of the Services.
We may also use this Personal Data to send you communications and/or direct marketing materials on our Services, products or offers we feel may be of interest to you, subject to separate consent, if needed under Applicable Privacy law.
(b) Clinical Trial Data:
We obtain clinical data from our research partners regarding our clinical trial participants (“Clinical Trial Data”). This dataset includes demographic data, medical and family history record, physical examination results, cardio evaluation, ECG, Echocardiography, medicines, vital signs, blood tests, coagulation tests, imaging data, concomitant medications, adverse events and associated data which is detailed in our clinical trials’ protocols. We do not directly obtain source medical records or other data which contains directly identifying information of clinical trial participants (such as names and contact information). This information is only accessed by a delegated CRO representative for auditing purposes, as well as by the relevant delegated research site teams. If the results of our studies are published, participants’ identities further remain fully confidential.
(c) Technical and behavioral information we collect through your use of our website:
When you are using our website, we are aware of it and may gather, collect and record the information relating to such usage, either independently or through the help of third-party services as detailed below. This includes technical information and behavioral information such as the user’s Internet protocol (IP) address used to connect your device to the Internet, your uniform resource locators (URL), operating system, type of browser, browser plug-in types and versions, screen resolution, Flash version, time zone setting.
We likewise place functional cookies on your browsing devices (see 'Cookies' section below).
2. WHAT ARE THE PURPOSES OF PERSONAL DATA WE COLLECT?
Summary: we process Personal Data to conduct clinical research, operate our website, meet our obligations, protect our rights and manage our business.
We will use Personal Data to provide and improve our Services to our clients and others, operate our website, meet our contractual, ethical and legal obligations and conduct medical research. All Personal Data will remain accurate, complete and relevant for the stated purposes for which it was processed, including for example:
Processing which is necessary for scientific health research purposes:
using Clinical Trial Data for the conduction of clinical trials and medical research related to lead extraction and the implementation of our Medical Solution and Medical Device.
Processing which is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract:
carrying out our obligations arising from any contracts entered into between you and Xtrac and/or any contracts entered into with Xtrac and to provide you with the information, support and Services that you request from Xtrac;
verifying and carrying out financial transactions in relation to payments you make in connection with the Services.
Processing which is necessary for the purposes of the legitimate interests pursued by Xtrac or by a third party of providing an efficient and wide-ranging service to clients:
notifying you about changes to our website and Services;
contacting you to give you commercial and marketing information about events or promotions or additional Services offered by Xtrac which may be of interest to you, provided that you express your consent for such communications;
soliciting feedback in connection with the Services;
tracking use of our website to enable us to optimize it.
for security purposes and to identify and authenticate your access to the login zone.
Processing which is necessary for compliance with a legal obligation to which Xtrac is subject:
compliance and audit purposes, such as meeting our reporting obligations in our various jurisdictions, anti money laundering, tax related obligations, and for crime prevention and prosecution in so far as it relates to our staff, clients, service providers, facilities etc;
if necessary, we will use Personal Data to enforce our terms, policies and legal agreements, to comply with court orders and warrants and assist law enforcement agencies as required by law, to collect debts, to prevent fraud, infringements, identity thefts and any other service misuse, and to take any action in any legal dispute and proceeding.
3. SHARING DATA WITH THIRD PARTIES
Summary: we share Personal Data with our service providers, partners, and group companies, and authorities where required.
We transfer Personal Data to:
Members of our Group: If in the future we have affiliates - which means affiliate companies - whether wholly or partially owned by Xtrac, and co-owned companies – we will transfer Personal Data to them.
Third Parties. We transfer Personal Data to third parties in a variety of circumstances. We endeavor to ensure that these third parties use your information only to the extent necessary to perform their functions, and to have a contract in place with them to govern their processing on our behalf. These third parties include business partners, suppliers, affiliates, agents and/or sub-contractors for the performance of any contract we enter into with you. They assist us in providing the Services we offer, processing transactions, fulfilling requests for information, receiving and sending communications, analyzing data, providing IT and other support services or in other tasks, from time to time. These third parties also include analytics and search engine providers that assist us in the improvement and optimization of our website, and our marketing.
We periodically add and remove third party providers. At present services provided by third-party providers to whom we transfer Personal Data include also the following:
Document management and sharing services;
Client ticketing and support;
On-site and cloud-based database services;
Data security, data backup, and data access control systems;
Our lawyers, accountants, and other standard business software and partners.
We transfer Clinical Trial Data only to third parties who assist in the conduction of our clinical trials and medical research, including:
Contract Research Organizations
Security and Data Monitoring Committees, auditors, prosecutors, inspectors, other doctors, nurses or other persons entities involved in conducting the clinical trials
external parties cooperating within the framework of the clinical trials or other technical and organizational service providers, enabling the provision of health services and management of their organization: ICT service providers, diagnostic equipment suppliers, providers of legal, accountancy, control, advisory and support services (courier).
In addition, we will disclose Personal Data to third parties if some or all of our companies or assets are acquired by a third party including by way of a merger, share acquisition, asset purchase or any similar transaction, in which case Personal Data will be one of the transferred assets. Likewise, we transfer Personal Data to third parties if we are under a duty to disclose or share your Personal Data in order to comply with any legal or audit or compliance obligation, in the course of any legal or regulatory proceeding or investigation, or in order to enforce or apply our terms and other agreements with you or with a third party; or to assert or protect the rights, property, or safety of Xtrac, our clients, or others. This includes exchanging information with other companies and organizations for the purposes of fraud protection and credit risk reduction and to prevent cybercrime.
For avoidance of doubt, Xtrac may transfer and disclose non-Personal Data to third parties at its own discretion.
4. WHERE DO WE STORE YOUR DATA?
Summary: we store your Personal Data across multiple locations globally
We store your Personal Data on servers owned or controlled by Xtrac, or processed by third parties on behalf of Xtrac, by reputable service providers (see the following section regarding international transfers).
Clinical Trial Data is stored and processed on ShareCRF. ShareCRF uses the services of AWS (Amazon Web Services) data centers, located in Germany and Ireland, as computing infrastructure for processing and data storage.
5. INTERNATIONAL DATA TRANSFERS (EU DATA SUBJECTS)
Summary: we transfer Personal Data within and to the EEA, USA, Israel and elsewhere, with appropriate safeguards in place.
EU Personal Data is transferred to, and stored and processed at, a destination outside the European Economic Area (EEA). This includes transfer to our headquarters in Israel, a jurisdiction deemed adequate by the EU Commission, and to the USA, not currently deemed adequate. As stated above, Clinical Trial Data is stored and processed on ShareCRF, located in the EU. This data is accessed by our headquarters in Israel for the purposes of conducting the clinical trial and research.
We transfer Personal Data to locations outside of the EEA, including in particular USA and Israel, in order to:
store or backup the information;
enable us to provide you with the Services and fulfill our contract with you;
fulfill any legal, audit, ethical or compliance obligations which require us to make that transfer;
facilitate the operation of our group businesses, where it is in our legitimate interests and we have concluded these are not overridden by your rights;
to serve our clients across multiple jurisdictions; and
to operate our affiliates in an efficient and optimal manner.
6. DATA RETENTION
Summary: we retain Personal Data according to our data retention policy, as required to conduct clinical research, meet our obligations, protect our rights, and manage our business.
Xtrac will retain Personal Data it processes only for as long as required in our view, to provide the Services, to conduct our clinical trials, and as necessary to comply with our legal and other obligations, to resolve disputes and to enforce agreements. We will also retain Personal Data to meet any audit, compliance and business best-practices.
7. SERVICES AND WEBSITE DATA COLLECTION AND COOKIES
Xtrac uses only cookies that are necessary for functionality of the website; these cookies enable core functionality such as security, network management, and accessibility. These cookies are not used to identify users of the website. Functionality cookies do not require your consent.
You may disable these by changing your browser settings, but this may affect how the website functions, and you may not be able to access all or parts of the website. For further information about deleting or blocking cookies, please visit: https://www.aboutcookies.org/how-to-delete-cookies/
To consult the list of cookies which we use on our website, please check your browser's settings. Instructions: https://www.wikihow.com/View-Cookies.
8. SECURITY AND STORAGE OF INFORMATION
Summary: we take data security very seriously, invest in security systems, and train our staff. In the event of a breach, we will notify the right people as required by law.
We take great care in implementing, enforcing and maintaining the security of the Personal Data we process. Xtrac implements, enforces and maintains security measures, technologies and policies to prevent the unauthorized or accidental access to or destruction, loss, modification, use or disclosure of Personal Data. We likewise take steps to monitor compliance of such policies on an ongoing basis. We use industry standard SSL (secure socket layer technology) encryption to transfer Personal Data. Likewise, we take industry standard steps to ensure our website and Services are safe and to prevent unauthorized access to our data bases.
ShareCRF, the platform in which Clinical Research Data is stored and processed, is ISO 27001 and ISO 9001 certified.
ShareCRF implements access controls with logs and encrypts Personal Data in transit and at rest. ShareCRF’s Quality Policy and Information Security may be found at: https://www.sharecrf.com/quality.
Note however, that no data security measures are perfect or impenetrable, and we cannot guarantee that unauthorized access, leaks, viruses and other data security breaches will never occur.
Xtrac shall act in accordance with its policies and with applicable law to promptly notify the relevant authorities and data subjects in the event that any Personal Data processed by Xtrac is lost, stolen, or where there has been any unauthorized access to it, all in accordance with applicable law and on the instructions of qualified authority. Xtrac shall promptly take reasonable remedial measures.
9. DATA SUBJECT RIGHTS
Summary: depending on the law that applies to your Personal Data, you may have various data subject rights, such as rights to access, erase, and correct Personal Data, and information rights. We will respect any lawful request to exercise those rights.
Data subjects with respect to whose data GDPR applies, have rights under GDPR and local laws, including, in different circumstances, rights to data portability, rights to access data, rectify data, object to processing, and erase data.
It is clarified for removal of doubt that where Clinical Trial Data has already been processed in relation to our clinical trials or included in academic research material, it may no longer be feasible for such data to be accessed, erased, rectified etc.
It is clarified that where Personal Data is provided by a client being the data subject's employer, such data subject rights will have to be effected through that client, the data subject’s employer. In addition, data subject rights cannot be exercised in a manner inconsistent with the rights of Xtrac employees and staff, with Xtrac proprietary rights, and third-party rights. As such, job references, reviews, internal notes and assessments, documents and notes including proprietary information or forms of intellectual property, cannot be accessed or erased or rectified by data subjects. In addition, these rights may not be exercisable where they relate to data that is not in a structured form, for example emails, or where other exemptions apply. If processing occurs based on consent, data subjects have a right to withdraw their consent.
A data subject who wishes to modify, delete or retrieve their Personal Data, may do so by contacting Xtrac (privacy@Xtrac-medical.com). Note that Xtrac may have to undertake a process to identify a data subject exercising their rights. Xtrac may keep details of such rights exercised for its own compliance and audit requirements. Please note that Personal Data may be either deleted or retained in an aggregated manner without being linked to any identifiers or Personal Data, depending on technical commercial capability. Such information may continue to be used by Xtrac.
Data subjects in the EU have the right to lodge a complaint, with a data protection supervisory authority in the place of their habitual residence. If the supervisory authority fails to deal with a complaint, you may have the right to an effective judicial remedy.
We do not knowingly collect or solicit information or data from or about children under the age of 16 without parental consent, or knowingly allow children under the age of 16 to register for Xtrac Services. If you are under 16, do not register or attempt to register for any of the Xtrac Services or send any information about yourself to us. If we learn that we have collected or have been sent Personal Data from a child under the age of 16 without appropriate permissions, we will delete that Personal Data as soon as reasonably practicable without any liability to Xtrac. If you believe that we might have collected or been sent information from a minor under the age of 16, please contact us at: privacy@Xtrac-medical.com, as soon as possible.
11. THIRD PARTY LINKS
13. CONTACT US
Xtrac’s data protection officer (DPO) may be contacted at: privacy@Xtrac-medical.com
* * * * *
Last Revised: October 2, 2022