EEA Privacy Disclosures
The following additional EEA privacy disclosures (the “Disclosures”) supplement the MMRF Privacy Policy. These Disclosures describe how we collect, use and share the Personal Data that we gather through the websites, mobile apps, and other digital properties that are owned and operated by MMRF and that are within the scope of the European Union’s General Data Protection Regulation (“GDPR”) (collectively, our “Website”). “We” or “MMRF” mean the Multiple Myeloma Research Foundation, Inc. and our affiliates.
If you are in the European Union the MMRF will be the data controller responsible for the collection and use of your Personal Data. If you have any questions about these Disclosures or our data practices, please contact us using the options provided below. Please read these Disclosures carefully. By using our Website, you consent to the data practices and other terms set forth in these Disclosures.
How We Collect and Use Personal Data
When we use the term “Personal Data,” we mean data that can be used to identify you as an individual person. We collect several categories of Personal Data through our Website, including data you provide, data collected automatically from your device, and data we obtain from third party sources. We use and share this Personal Data for the purposes described below, including as described under Additional Uses of Personal Data.
We rely on separate and overlapping bases to process your Personal Data lawfully. By way of example only, it may be necessary for us to process your Personal Data in certain ways in order to process a transaction you have requested or otherwise in accordance with a contract between us, or in certain cases we may process your Personal Data when necessary to further our legitimate interests, when those legitimate interests are not overridden by your rights and interests.
Information You Provide
We collect Personal Data you provide, for example when you enter the data into form fields on our Website. For example, we may collect:
Category of Personal Data |
Purposes of Processing |
Legal Bases for Processing |
Contact Information name (individual and/or organization/company), physical address, telephone number, email address, and other electronic contact information (such as Twitter, Facebook, Tumblr, and Myspace accounts) |
To administer your account and the Website, authenticate you as a user, and communicate with you To help you find a research study as a research subject To notify you of events that may be of interest to you and to provide you with event resources |
To process transactions requested by you and meet our contractual obligations Legitimate interests Your consent, when applicable |
Demographic Information including your age, occupation/employer information, donation information/history, educational history and participation at MMRF events |
To notify you of events that may be of interest to you, to target and deliver relevant offers and ads, to support our operations, and to improve our products and services including the Website To register you for professional education |
Legitimate interests Your consent, when applicable |
Payment Information including credit card number (and expiration date), billing information (such as individual/company name, physical address, telephone number) |
To process donations and investments that you make online. For more information regarding our privacy practices related to donors, please see our Donor Privacy Policy |
To process transactions requested by you and meet our contractual obligations Legitimate interests Compliance with legal obligations Your consent, when applicable |
Health Status of you and your Family including your interest in participation in studies related to multiple myeloma |
To help you identify research studies that may be of interest to you To help identify treatments and resources that may be able to assist you To connect you with advice from nurses] To help you identify treatment centers |
Your explicit consent, when applicable |
Investment Interests Including your interest in investing in potential treatments |
To identify your interests in investing in research carried about by MMRF |
Legitimate interests |
Information Collected Automatically
As is true of most digital platforms, we gather certain data automatically when you use our Website. This data may include browser, device, cookie and similar data that we collect as follows:
Category of Personal Data |
Purposes of Processing (see also Additional Uses of Personal Data below) |
Legal Bases for Processing |
Log Files including IP addresses, browser type, internet service provider, referring/exit pages, operating system, date/time stamp and/or clickstream data |
To maintain the security of our Website, for fraud detection, and to protect our rights To administer webinars and events |
Legitimate interests |
Cookies, Analytics and Related Technologies For more information, including on how to control your privacy settings and your ad choices, read our Privacy Policy. |
To manage our Website and email messages and to collect and track information about you and your activities online over time and across different websites and social media channels. For more information about our use of cookies, see the “Usage Details, IP Addresses, Cookies and Other Technologies” section of our Privacy Policy. |
Legitimate interests Your consent, when applicable |
Location Information including latitude, longitude, date and time (the precision of this data varies greatly and is determined by factors controlled by your device or mobile service provider) |
To offer you certain location-based services, such as delivering advertisements that are relevant to your particular location, and to conduct analytics to improve the Website |
Legitimate interests Your consent, when applicable |
Information We Obtain from Third Party Sources
We may obtain certain Personal Data about you from third party sources, which we may use to serve our legitimate interests, comply with legal obligations, perform a contract, or in some cases, conduct activities pursuant to your consent.
Research Studies: We sponsor and conduct research studies. When you enroll in a research study that we sponsor or conduct, you will typically be provided with a consent form that contains notice provisions regarding the uses of your personal data. Those notices supersede the terms found in these Disclosures. Please refer to the consent form that you sign when enrolling in one of our research studies to understand how your personal data collected in the study are processed.
Business Partners and Service Providers: We use business partners and service providers, such as payment processors and analytics providers, to perform services on our behalf. Some of these partners have access to Personal Data about you that we may not otherwise have (for example, when you sign up directly with that provider) and may share some or all this data with us. We use this data to administer the Website and conduct marketing and advertising campaigns as well as to process transactions that you request.
Supplemental Information: We may receive additional Personal Data from third-party sources, such as credit reference agencies and public databases, which we may append to existing consumer data, such as email address verification. We may use this supplemental information to process transactions that you request and to prevent fraud, deliver relevant offers and advertising to you and to improve our operations, Website and our advertising and marketing campaigns.
Additional Uses of Personal Data
In addition to the uses described above, we may use your Personal Data for the following purposes, which uses may under certain circumstances be based on your consent, may be necessary to fulfill our contractual commitments to you, and are necessary to serve our legitimate interest in the following business operations:
-
- Operating our business, administering the Website and managing your accounts;
- Contacting you to respond to your requests or inquiries;
- Processing and completing your transactions including, as applicable, donations that you make online;
- Providing you with newsletters, articles, product or service alerts or announcements, event invitations, and other information that we believe may be of interest to you;
- Preventing, investigating, or providing notice of fraud, unlawful or criminal activity, or unauthorized access to or use of Personal Data, our website or data systems, or to meet legal obligations;
- Enforcing our Terms of Use and other agreements; and,
- Sending you text messages or push notifications when you sign up for one of our messaging programs, such as through a research study. These messages may be sent by automated means. You may opt out of a text message program by following the instructions in the “Your Privacy Choices” section.
Legitimate Interests
We rely on several legitimate interests in using and sharing your Personal Data. These interests include:
- improving and customizing the Website for you;
- understanding how the Website are being used;
- obtaining insights into usage patterns of the Website;
- exploring ways to develop and grow our business;
- ensuring the safety and security of the Website; and
- enhancing protection against fraud, spam, harassment, intellectual property infringement, crime and security risks
Data Retention
We will retain your Personal Data only for as long as is necessary for the purposes set out in these Disclosures (for example, if you have an account, for as long as your account is active), subject to your right, under certain circumstances, to have certain of your Personal Data erased (see Your Rights below), unless a longer period is required under applicable law or is needed to resolve disputes or protect our legal rights.
How We Share and Disclose Personal Data
We share your Personal Data with third parties only in the ways described in these Disclosures. We may share your Personal Data within our family of companies, with service providers and business partners, in connection with business transfers and to comply with the law, protect health and safety and enforce our legal rights.
International Data Transfers
MMRF may transfer your Personal Data within our family of companies and/or to the third parties discussed above. Your Personal Data may be transferred to, stored, and processed in a country other than the one in which it was collected. We may transfer your Personal Data outside the European Economic Area (“EEA”) and when we do so, we rely on appropriate or suitable safeguards recognized under data protection laws.
Additional Policies
Certain websites, mobile applications or other digital properties included in the Website may contain additional disclosures related to your privacy. For example, if you choose to submit a testimonial through one of our websites, the content of your submission will be used according to the terms set out on the submission webpage as well as in the ways described in these Disclosures.
Please also review the following additional privacy policies, which apply to the Website referenced in such policies: Donor Privacy Policy.
Children’s Privacy
We are committed to protecting the privacy of children. Our Website are not directed to, and we do not intend to or knowingly collect or solicit Personal Data online from children under the age of 18. If you are under the age of 18, do not provide us with any Personal Data.
Your Rights
We process all personal data in line with your rights, in each case to the extent required by and in accordance with applicable law (including in accordance with any applicable time limits and fee requirements).
Links to Third Party Sites [and Social Media]
The Website may include links to websites and digital services operated by third parties. These Disclosures do not apply to, and we are not responsible for the content, privacy policies or data practices of third parties that collect your data. We encourage you to review the privacy policies for those third parties to learn about their data practices.
Updates to the Disclosures
These Disclosures are subject to occasional revision, and if we make any material changes in the way we use your Personal Data, we will notify you by sending you an email to the last email address you provided to us and/or by prominently posting notice of the changes on the Website and updating the effective date above.
Managing Communication Preferences
If you have opted in to our marketing communications (or when permitted by law, if you have provided us with your contact information), we may send you email messages, direct mail offers, push notifications or other communications regarding products or services depending on the method of communication selected. You may ask us not to do so when you access our websites or mobile applications, or change your preferences by updating any accounts you have with us. At any time, you may elect to discontinue receiving commercial messages from us by submitting an opt-out request to the contact information below or by following the unsubscribe instructions in the form of the communication you received, as described below.
Contact Us
If you have any questions, comments, requests or concerns about these Disclosures or other privacy-related matters, you may contact us in the following ways:
Multiple Myeloma Research Foundation (MMRF)
383 Main Avenue, 5th Floor, Norwalk, CT 06851
Phone: 203-229-0464
Fax: 203-972-1259
Email: [email protected]
Web:www.themmrf.org