GENERAL PRINCIPLES
PSI is committed to respecting the privacy of individuals. PSI values the confidence of those who have entrusted PSI with their personal data: clinical investigators and other healthcare professionals, job applicants, employees, customers, and business partners. PSI has developed procedures and practices to periodically review and monitor the use of personal information to ensure that it is used responsibly and complies with internationally recognized standards of privacy protection. Such international standards include but are not limited to the European Union Data Protection Directive [EC/95/46] and the US-EU Safe Harbor Privacy Principles. In addition to following these transnational regulations, PSI always strives to collect and use personal data in a manner consistent with the national laws of the countries where PSI does business.
Internationally recognized standards require that the processing of personal data, both automated and manual, meet the following data protection principles:
- Data are collected and processed in a fair, responsible, and lawful manner.
- Data are collected, stored, transferred, processed, analyzed and used in accordance to PSI’s established guidelines and in compliance with local laws/regulations in the territory where those activities occur.
- Data are collected for specified, legitimate purposes and not processed in ways incompatible with those purposes.
- Data are relevant to and not excessive for the purposes for which they are collected and used.
- Data are current and accurate with reasonable steps taken to rectify or delete inaccurate records.
- Data are kept only for as long as it is necessary for the purposes for which they were collected and processed.
- Appropriate measures are taken to prevent unauthorized access, unlawful processing, and unauthorized or accidental loss, destruction, or damage to data.
- Data are not transferred to third parties unless adequate level of data protection exists.
PURPOSES OF DATA PROCESSING
PSI processes personal data for specific, limited, and legitimate purposes, which data subjects are informed about whenever such data are requested from them. Examples of such purposes include, but are not limited to:
- Investigator data processed by PSI to be able to identify and contact individual investigators to ascertain their interest in participating in clinical trials in accordance with their experience, specialty, availability, and other factors. Investigators selected to conduct clinical trials may also be required to provide additional information to facilitate reimbursement for their participation.
- Personal data of job applicants processed by PSI to enable screening of candidates and communication with them.
- Personal data of potential customers processed by PSI to enable prompt responses to requests for information.
Prior to processing personal data, PSI will provide notice to data subjects in a clear and conspicuous language. Depending on the type of data processing, notice may be given in person, by e-mail, post, or telephone, as well as posted on the PSI Website.
DATA COLLECTION
Categories of data collected for one of the purposes described in the previous section include contact information, company information and job application information. For example, name address, phone number, e mail address, company name, position, resume, desired compensation and/or “cookie" information may be collected for processing external requests.
Every effort is made to ensure that the information is accurate and current, and all communications with individuals provide easy means of validating, correcting, and updating data.
RIGHTS OF DATA SUBJECTS
All processing of personal data is done by consent, for the purposes listed above, and under the supervision of PSI, the data controller. Individuals have the right to:
- Gain access to their personal data.
- Obtain copies of their personal records.
- Request correction of their data.
- Prevent processing of their data for direct marketing or any other purposes not stated in the notice.
- Withdraw consent to allow processing of their data.
- Prevent cross-jurisdictional disclosures to third parties in case of inadequate data protection controls.
DATA SECURITY
PSI employs reasonable safeguards to protect personal information in its possession from loss, misuse and unauthorized access, disclosure, alteration, and destruction. For personal information subject to electronic storage or transmission, PSI maintains a secure network that is protected from computer virus infection and monitored for unauthorized access. Both electronic and paper based records holding personal information are maintained in access controlled facilities.
RELEASE AND TRANSFER OF DATA
To the extent necessary, personal information provided to PSI may be made available to the company, all its subsidiaries and, occasionally, entities employed as subcontractors of PSI. Access to personal data and equipment is at all times restricted to appropriately trained and duly authorized staff.
PSI will not trade or sell any personal information. PSI will not release, share, or transfer any personal information for use by any entity outside PSI without the prior consent of the data subject or in a form other than what was disclosed to the data subject at the time the information was collected, unless permitted or required by law.
Under some circumstances PSI may be required to release personal information to law enforcement agencies or judicial authorities.
Companies working as subcontractors of PSI, as well as PSI customers, are required to sign confidentiality agreements or provide other contractual assurance agreeing to handle all personal data, if disclosed to these entities for legitimate reasons, with due care and in accordance with applicable laws.
PSI is a global company that collects and processes information at different locations and in different jurisdictions. PSI may transfer personal data to one of its entities outside the country of domicile of an individual. If the level of privacy protection in a country does not comply with internationally recognized standards, PSI will ensure that data being transferred to that country are adequately protected and, where necessary, formal data exchange agreements are put in place.
THIRD PARTY WEBSITES
The PSI Website may contain links to websites of entities that are not affiliated with the company. Such websites are not under control of PSI. This Policy does not cover third party websites, and individuals are recommended to review the privacy policy of each linked website they may choose to go onto.
COOKIES AND IP ADDRESSES
A “cookie" is a piece of data stored on the hard drive of a computer connected to the Internet. PSI enables temporary cookies (also known as session only cookies) to allow site visitors to easily move from one interactive feature to another, offering visitors a better experience while navigating the PSI Website. However, use of a cookie does not link to or reveal personally identifiable information while on the PSI Website, unless the individual explicitly provides that information to PSI. Furthermore, the cookie will expire after a short period of time and will automatically be removed completely when the Internet browser is closed.
PSI receives IP addresses in the normal course of the operation of the Website. An IP address is a number assigned to each user by the Internet service provider so one can access the Internet. PSI does not use IP addresses to personally identify individuals or disclose them to others.
CHILDREN’S PRIVACY PROTECTION
PSI does not collect or keep information from its Website from individuals known to be underage. No part of the PSI Website is designed or structured to attract children.
TRAINING
PSI has provided its employees with appropriate training to ensure that all those who process personal data are fully aware of their individual responsibilities and of management's objectives with respect to the protection of privacy.
INQUIRIES, COMPLAINTS, AND ACCESS REQUESTS
All inquiries and complaints, as well as individuals’ requests for accessing their data, should be addressed to:
Liubov Dobryagina
Data Privacy Officer
PSI Co Ltd.
19/21 Dostoyevsky str.
St. Petersburg, 191119
Russia
or forwarded electronically for action or response at
privacy@psi-cro.com.
Using reasonable effort, PSI will promptly respond to any queries or complaints regarding the protection of privacy. For unresolved disputes between PSI and complainants, PSI will cooperate with competent data protection authorities, where available.
POLICY CHANGES
PSI reserves the right to modify or amend this Policy. For instance, this Policy may need to be changed as new privacy legislation is introduced or as existing regulations are amended. Changes to this Policy will be posted on the PSI Website.
The Policy was last modified on 13 August 2008.