This statement relates to the processing of any personal data or to personally identifiable information by Brain Science Tools BV (referred to as "personal data" hereafter).
Brain Science Tools BV (BST) is responsible for the processing of personal data under the General Data Protection Regulation (GDPR). This document describes how we process, safeguard, use and allow you to control your personal data and how we meet the GDPR.
Brain Science Tools BV
Bunnikseweg 39, De Bilt
1. What types of data do we collect and for what purposes?
Information about our customers
BST processes data of customers. Two types of customers are distinguished: customers who buy and use our medical equipment use (hereinafter "Product Customer") and customers who register for one of our events using a web form on our website (‘Event customers”).
We collect the following information about such customers, with the stated reason:
- contact information such as name, address, work address, name of institution or hospital or business, country of residence
- Serial numbers of the products delivered
- delivery date and order number
In order to comply with the European law on medical devices (MDD 93/42/eec), we need to acquire and store the personal data mentioned above, for example to check periodically whether our products will be used safely and correctly. We keep this information only in a secure manner both on paper and digitally in a secure encrypted environment, and only authorized individuals have access to this data.
- contact information such as name, address, work address, employer name, country of residence
- Selected course topics
The registration webforms for our events have adequate encryption in order to transmit the personal data such that they cannot be intercepted by unauthorized third parties. The data is securely stored on our server. Moreover, customers will be asked for permission to allow us to store and process this data. We need this information in order to organize the event and notify customers on time about any program changes. Payment of the registration fees for our events are made directly through the online payment service we use (Mollie), and not through our own website. Payment details of such clients we never get to see and are not stored nor processed by us.
Data from visitors to our website
BST processes information from all visitors to our website. This means even those who do not fill out web forms mentioned in the paragraph above, such as random visitors. We accomplish this through a so-called tracking code and processing service provided by Google Analytics. This service allows us to optimally adapt our website to the visitors' interests, by acquisring the following information:
- the visitors location as far as disclosed by the visitor
- what pages they visit on our website, for how long and in what order
- which web browser and language is used
- if the user uses a mobile phone to visit our website or a desktop computer
- the masked IP address of the visitor
We use this information solely to improve our website, and it will be processed only as average values and not individually for each person. We have ensured that the last 3 numbers from the IP address of the visitor are masked such that they are not received by us, and we can hence not trace the visitors behavior to their personal. We do not share this information directly with Google or others.
Information of our employees, such as their name, address, social security number, email address, telephone number and bank details are for the duration of the assignment stored in the personnel file, for up to two years after termination of employment. The purpose of this information is to correctly fulfill our obligations as an employer, the payment of wages, the payment of taxes, and employee insurances. BST ensures:
- the correctness and accuracy of the data in the personnel file;
- the adequate protection of the personnel file, so they do not get lost or fall into the wrong hands;
- access to the complete personal data in the personnel file by employees, and correct, update or remove them when required;
- To point out to employees the their right of objection to the processing of their data on the grounds of legitimate interests;
- allow employees the right to data portability to another employer or agency.
2. Will my personal data be provided to third parties?
BST will never sell your information to third parties and will provide it only if necessary for the implementation of our agreement with you, to improve our services or to meet a legal obligation. We have signed agreements known as processors agreements with companies that process your data on our behalf, as laid out in the GDPR, in order to provide the same level of security and confidentiality of your information that BST guarantees to you. BST remains responsible for this processing.
3. How long do we retain personal information?
The personal information we receive through our website, emails or otherwise will be retained for as long as they are required for the purpose they are collected for, as mentioned above. Your personal data are retained for up to 4 years and destroyed afterwards, except for the contact details of customers of our medical equipment as mentioned above. We are required by law to keep this information of customers of our medical devices as long these devices are used, which usually is at least 10 years.
4. How will my personal data be protected?
BST takes the protection of your data seriously and takes appropriate measures to prevent abuse, loss, unauthorized access, unwanted disclosure or unauthorized modification. We use with secure and encrypted online transmission of your personal data when entered through our website. If you feel that your data is not properly protected or there is evidence of abuse, please contact us (see contact information above).
5. Where can I submit a request to view my personal data, or to correct or delete it?
You have the right to view your personal information, and to correct or delete it, as far as laws and regulations allow. Thes adjustments will be also disclosed to third parties who process data for BST. You can send a request for inspection, correction or removal of your personal data to email@example.com. To ensure that the application is done by you, we may ask you to send a copy of your personal identification document. We ask you to make your passport photo and social security number (SSN) invisible in this copy, in order to protect your privacy. If you make such a request, we will make available an encrypted connection to upload this copy in order to keep your data protected. BST will respond to your request as soon as possible and in any case within four weeks.
6. Changes in data processing policy
This Privacy Statement was last amended on May 24, 2018