Privacy and Security Policy
Privacy and Security
PathPresenter (“PathPresenter”) is committed to protecting your personal information. This statement explains our practices for this Web site.
What Personal Information We Gather
We collect personal information through the following methods:
- Directly Collected Information: We collect information you provide directly to us (e.g., your contact details when you sign up for our newsletter).
- Indirectly Collected Information: We automatically collect certain information through cookies, analytics tools, and via our service partners to improve site functionality and user experience.
- Special Category and Criminal Conviction Data: We generally do not process special category data (as defined by Art. 9 GDPR) or criminal conviction data. If such processing becomes necessary, we will identify the appropriate legal basis, implement heightened safeguards, and notify you as required by law.
How We Use Your Information
We only use the personal information we gather for purposes that you have agreed to, for example, to send you a newsletter. We do not collect personal information about any of our site’s visitors unless the visitor authorizes us to do so.
PathPresenter processes personal information based on applicable data protection laws and relies on different legal bases depending on the nature and purpose of the processing. We process your personal information for the following specific purposes, each supported by an applicable legal basis:
- Newsletter Subscription: To provide you with requested updates and marketing communications. Legal Basis: Consent – Where required, PathPresenter relies on consent for specific processing activities, such as when you choose to subscribe to newsletters or receive certain communications. You may withdraw your consent at any time by contacting us.
- Account Management & Customer Support: To manage your user account, provide technical support, and respond to your inquiries. Legal Basis: Contractual Necessity – PathPresenter may process personal information where processing is necessary to provide requested products and services, manage customer relationships, support users, and fulfill contractual obligations.
- Website Performance & Security: To monitor site functionality, prevent fraud, and ensure the security of our services. Legal Basis: Legitimate Interests – PathPresenter may rely on legitimate interests where processing is necessary for purposes that support the operation, security, and improvement of our business and services, and where those interests are not overridden by an individual’s privacy rights. Before relying on legitimate interests, PathPresenter considers the impact of the processing on individuals and ensures that appropriate safeguards are implemented. Examples of legitimate interests include:
- maintaining and improving the security, reliability, and performance of our systems and services;
- managing customer relationships and responding to inquiries;
- preventing fraud, misuse, security threats, and unauthorized access;
- managing business operations and service providers that support PathPresenter’s services; and
- protecting PathPresenter’s legal rights and business interests.
- Legal Compliance: To comply with applicable laws, regulations, and legal obligations. (Legal Basis: Legal Obligations – PathPresenter may process or disclose personal information where required to comply with applicable laws, regulations, legal processes, or lawful requests from authorities.)
Data Retention
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected. To ensure compliance, we apply the following retention criteria:
- Account Information: We retain your account data for the duration of our relationship. Following account closure, we retain the data temporarily to allow for potential reactivation, after which it is anonymized or deleted, unless required for legal compliance.
- Marketing & Communications: We retain your contact details for marketing purposes until you withdraw your consent or opt out of our communications.
- Transaction & Billing Records: Where applicable, we retain financial records for as long as necessary to satisfy applicable statutory tax, accounting, legal, and regulatory obligations, after which they are securely deleted or anonymized.
- Clinical/Healthcare Data: Retention of clinical data is governed by specific healthcare regulations and our agreements with your healthcare provider.
- Legal & Dispute Resolution: We may retain specific records beyond these periods if necessary to resolve disputes, enforce agreements, or comply with legal obligations.
Rights of Data Subjects
Under applicable data protection laws, you have the following rights:
- Right of Access: You may request a copy of the personal data we hold about you.
- Right of Rectification: You may ask us to correct inaccurate or incomplete data.
- Right to Erasure: You may request that we delete your personal data under certain circumstances.
- Right to Restriction of Processing: You may request that we limit how we process your data.
- Right to Object to Processing: You may object to our processing of your data.
- Right to Data Portability: You may request to receive your data in a structured, commonly used format.
To exercise these rights, please contact us at privacy@pathpresenter.com.
Children’s Privacy
Our website and services are not directed at children under the age of 16, and we do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without the required parental consent, we will take immediate steps to delete that information. If you believe we have inadvertently collected data from a child, please contact us at privacy@pathpresenter.com.
Who Has Access to Your Information
Only people within PathPresenter who need to access your personal information can access it; for example, the people who send a newsletter need to know your email address.
How We Share Your Information
We do not sell your personal information or otherwise share it with third parties, except as necessary to provide our services, comply with applicable laws and legal obligations, or in connection with a merger, acquisition, reorganization, sale of assets, or other corporate transaction. In such circumstances, your personal information may be transferred to the relevant successor or acquiring entity, subject to applicable privacy and data protection requirements.
We might share your personal information under the following circumstances:
- We have your consent.
- We are required to share customer information by law, to protect the interests of the company or in the discharge of public duty.
- We may share your personal information with business partners as necessary to provide a service you have requested. Our business partners’ use of your information is restricted to providing that service.
We may share personal information with third parties only when necessary for our business operations or as required by law. We categorize these recipients as follows:
- Service Providers: We engage third-party vendors to support our business operations, including IT hosting, cloud storage, and analytics platforms. Legal Basis: Contractual Necessity / Legitimate Interests.
- Business Partners: We share information with partners solely to facilitate the delivery of specific services you have requested. Legal Basis: Contractual Necessity / Consent.
- Legal & Regulatory Authorities: We may disclose data to comply with legal obligations, protect our legal rights, or in the discharge of a public duty. Legal Basis: Legal Obligation / Legitimate Interests.
Data Controller
PathPresenter Inc. is the data controller for personal data processed through our website, customer interactions, account management activities, and other business operations.
For questions regarding the processing of personal data or this Privacy Policy, please contact: Email: privacy@pathpresenter.com
Data Protection Officer
PathPresenter has appointed a Data Protection Officer to oversee data protection compliance and act as a point of contact for privacy-related matters.
Data Protection Officer: Brian Matcheski
Email: brian@pathpresenter.com
Contacting Us and Complaints
If you have any questions, concerns, or requests regarding this Privacy Policy, your personal information, or to exercise any of your data subject rights, please contact our Data Protection Officer.
If you remain dissatisfied, you can make a complaint about the way we process your personal information to the relevant supervisory authority.
EU and UK Representatives
Where required under applicable data protection laws, PathPresenter has appointed representatives in the European Union and the United Kingdom to act as points of contact for data protection matters.
European Union Representative
Under Article 27 of the General Data Protection Regulation (GDPR), PathPresenter has appointed an EU Representative:
- Instant EU GDPR Representative Ltd.
Adam Brogden | Email: contact@gdprlocal.com | T: +35 3155 49700 - Office 2, 12A Lower Main Street, Lucan, Co. Dublin, |K78 X5P8, Ireland
United Kingdom Representative
Under the UK General Data Protection Regulation (UK GDPR), PathPresenter has appointed a UK Representative:
- GDPR Local Ltd.
Adam Brogden | Email: contact@gdprlocal.com | T: +44 1772 217800
1st Floor Front Suite, 27-29 North Street, Brighton, England
Roles and Responsibilities
PathPresenter is committed to protecting personal data and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR), where applicable. Depending on the nature of the processing activity, PathPresenter may act as either a data controller or a data processor.
PathPresenter as a Data Controller
PathPresenter acts as a data controller when it determines the purposes and means of processing personal data for its own business activities. This may include processing related to:
- managing customer and user accounts;
- responding to inquiries and providing customer support;
- managing business relationships;
- operating and improving our website, products, and services;
- fulfilling legal, regulatory, security, and contractual obligations.
When acting as a controller, PathPresenter is responsible for ensuring that personal data is processed lawfully, fairly, and transparently. PathPresenter maintains appropriate technical and organizational measures to protect personal data, provides transparency regarding its processing activities, supports applicable data subject rights, and maintains appropriate records and documentation as required by applicable data protection laws.
PathPresenter as a Data Processor
For customer clinical data processed through the PathPresenter Clinical Viewer, PathPresenter generally acts as a data processor on behalf of healthcare organizations and other customers who act as the data controllers.
In this role, PathPresenter processes personal data only in accordance with documented instructions from the customer, including applicable agreements governing the use of the PathPresenter platform. Customers remain responsible for determining the purposes for which clinical data is processed, including decisions regarding patient care, access permissions, retention requirements, and applicable legal bases.
As a processor, PathPresenter is responsible for:
- processing personal data only as instructed by the customer;
- implementing appropriate technical and organizational safeguards to protect personal data;
- maintaining confidentiality and limiting access to authorized personnel;
- supporting customers in meeting applicable data protection obligations;
- maintaining appropriate records of processing activities where required;
- notifying customers of applicable personal data breaches in accordance with contractual and legal requirements; and
- ensuring that approved subprocessors are appropriately managed.
PathPresenter does not determine the purposes of clinical data processing performed by healthcare organizations and does not use customer clinical data for independent purposes unrelated to providing the contracted services.
Shared Commitment to Data Protection
PathPresenter regularly reviews its privacy and security practices to ensure appropriate protection of personal data and to support compliance with applicable data protection requirements.
Security – How We Protect Your Information
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. Our security practices include:
- Encryption: We use industry-standard encryption protocols (such as TLS/SSL) to protect data in transit. Sensitive data at rest is protected using robust encryption standards.
- Access Controls: We employ strict, role-based access controls to ensure that only authorized personnel who have a legitimate business need to access personal information can do so. All employees are required to adhere to confidentiality agreements.
- System Security: Our infrastructure is protected by firewalls, regular security monitoring, and vulnerability assessments to prevent unauthorized access and mitigate threats.
- Breach Notification: In the event of a personal data breach that poses a risk to the rights and freedoms of individuals, we are committed to notifying the affected individuals and relevant regulatory authorities without undue delay and in accordance with applicable legal requirements.
Data Storage and International Transfers
We primarily store and process personal information in the United States. Where we transfer personal information from the European Economic Area (EEA) or the United Kingdom (UK) to countries outside of these regions, we ensure that appropriate safeguards are in place—such as Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA)—to ensure that your data is protected in accordance with applicable data protection laws.
Credit Cards
We do accept credit card payments for registrations. If someone uses your credit card to make an unauthorized purchase, check with the institution that issued your card to find out what the exact liability is.
If you send us an email, we may save it if we think we’ll need it to communicate with you. We never sell or share email addresses. Remember, email is not a secure way to send personal information because it is not encrypted. Please don’t send any personal information to us using email.
Cookies
Our Web site stores information in a small text file, called a cookie, on your computer. We use what is called a “persistent cookie,” which is stored as a file on your computer and remains there when you close your Web browser. The cookie can only be read by the Web site that created it when you visit that site again.
Our Use of Cookies
PathPresenter stores a unique number (not any personal information) in the cookie that we place on your computer. We use this cookie to determine if you have visited the site before, and to ensure you are only prompted once to fill in certain forms such as our newsletter form. The information we store in the cookie does not include data such as your name, company, email address, telephone number, state/province, country.
Note: If you do not allow cookies to be saved on your computer, you will not be able to download information from this site.
Security Concerns
Once the cookie is saved on your computer, our Web site is the only site that can access and read the information that you provide. PathPresenter will not provide this information to any third parties or use it for sending unsolicited email.
Java and Javascript
Java is a language that allows different kinds of computers to talk to each other. We use Java technology to provide functionality such as navigation menus and forms. You will still be able to use this Web site if you have Java or Javascript disabled, but some functionality may not be available.
Changes to this Statement
We may amend this privacy and security statement. If we make any substantial changes in the way we use your personal information, we will notify you by posting a prominent announcement on this Web site.
