Privacy Notice
Last updated: 1 July 2026
1. About this Privacy Notice
This Privacy Notice explains how nuaxia Limited collects, uses, shares and protects personal information.
It applies to personal information relating to:
-
healthcare professionals and other professional contacts;
-
patients, carers and members of the public who participate in nuaxia activities;
-
survey, interview, consultation and educational activity participants;
-
Clients, prospective Clients and their employees or representatives;
-
website, portal and app users;
-
alert subscribers;
-
people who contact or correspond with nuaxia; and
-
individuals whose professional information we obtain from publicly available or authorised third-party sources.
In this Privacy Notice, surveys, interviews, discussions, assessments, consultations, educational activities and other engagements organised or administered by nuaxia are referred to as Activities.
This Privacy Notice provides information about our use of personal information. It is not a contract and, except where a specific local requirement applies, you do not need to “accept” it for it to apply.
We may provide additional privacy information for a particular Activity or country where the relevant processing differs materially from this general notice or local law requires additional information.
2. Who we are
nuaxia Limited is a company registered in England and Wales under company number 10091312.
Our registered office is:
5 Walpole Avenue
Richmond
Surrey
TW9 2DJ
United Kingdom
For most of the processing described in this Privacy Notice, nuaxia acts as the controller. This means that we decide why and how the personal information is used.
You can contact us about privacy and data-protection matters at:
EU representative
We have appointed Prighter Germany GmbH, a member of Prighter Group, as our representative in the European Union under Article 27 of the EU GDPR.
Prighter Germany GmbH
Heidestraße 40
10557 Berlin
Germany
Individuals in the European Union may contact Prighter as our EU representative or exercise their data-protection rights through Prighter’s dedicated portal:
https://app.prighter.com/portal/16000750623
Prighter acts as a contact point for individuals and data-protection authorities in the European Union. nuaxia remains responsible for the processing of personal information described in this Privacy Notice.
3. When nuaxia acts for another organisation
In limited circumstances, nuaxia may process personal information solely on the documented instructions of a Client or an organisation for which the Client is acting.
In those circumstances:
-
the Client or relevant organisation is the controller;
-
nuaxia acts as a processor or subprocessor; and
-
the controller is principally responsible for explaining how the information is used.
nuaxia may act as a controller for some processing connected with a project and as a processor for other processing.
For example, nuaxia will normally act as an independent controller for:
-
maintaining its professional database;
-
professional verification and profiling;
-
identifying potentially relevant Participants;
-
managing relationships and communications with Participants;
-
administering Accounts and Honoraria;
-
preventing fraud and protecting security;
-
maintaining quality and compliance records; and
-
meeting nuaxia’s own legal and regulatory obligations.
Our standard Data Processing Terms apply where nuaxia acts as a processor or subprocessor.
4. Personal information we collect
The information we collect depends on your relationship with nuaxia and how you interact with us.
4.1 Identity and contact information
This may include:
-
name and title;
-
email address;
-
telephone number;
-
postal address;
-
country, city or region;
-
preferred language;
-
professional profile link; and
-
Account, contact or Participant identifier.
4.2 Professional information
For healthcare professionals and other professional contacts, this may include:
-
profession and professional type;
-
specialty and areas of interest;
-
qualifications;
-
professional registration or licence information;
-
job title and seniority;
-
employer, workplace and organisational affiliations;
-
city and country of practice;
-
professional experience;
-
therapeutic-area experience;
-
general or aggregated patient and caseload information;
-
publications, speaking roles and professional activities;
-
memberships of professional organisations;
-
publicly available professional information; and
-
previous interactions and Activities with nuaxia.
4.3 Professional profile and eligibility information
We may create and maintain a professional profile using information:
-
supplied by you;
-
obtained from publicly available professional sources;
-
provided by an authorised recruiter, referrer or professional network;
-
provided by a Client where lawful;
-
obtained from professional data providers; and
-
derived from your previous professional interactions with nuaxia.
We use this information to understand your professional role, experience and potential relevance to Activities.
Receiving an invitation does not mean that you will necessarily qualify. Final eligibility may be determined through screening questions and quota requirements.
4.4 Activity and response information
When you take part in an Activity, we may collect:
-
screening and eligibility responses;
-
survey and interview answers;
-
opinions, attitudes and professional judgements;
-
information about clinical practice or professional experience;
-
educational responses and assessment results;
-
free-text comments;
-
Activity completion and timing information;
-
response-quality and validation information;
-
technical issues and support requests; and
-
follow-up correspondence.
Survey and interview responses may remain personal information while they are linked, or reasonably capable of being linked, to you.
4.5 Patient, carer and public-participant information
Where you participate because of your experience as a patient, carer or member of the public, we may collect:
-
demographic information;
-
health conditions;
-
treatment and healthcare experiences;
-
opinions and preferences;
-
quality-of-life or patient-impact information; and
-
other information relevant to the Activity.
Health information is subject to additional legal protection.
4.6 Audio, video and image information
Where an Activity involves recording, we may collect:
-
audio recordings;
-
video recordings;
-
photographs or images;
-
transcripts;
-
identifiable quotations; and
-
information derived from a recording.
You will be informed before an Activity is recorded.
Any proposed public use of your name, image, voice or identifiable quotation will be separately explained and authorised.
4.7 Honorarium and reward information
This may include:
-
Activities completed;
-
Honoraria earned;
-
accumulated incentive balances;
-
the email address used to issue a reward;
-
reward value, currency and status;
-
information received from our rewards provider;
-
tax or transfer-of-value information where required; and
-
correspondence concerning an Honorarium.
nuaxia normally issues Honoraria as digital rewards through Tremendous. We do not normally need to collect bank details ourselves to issue these rewards, although
Tremendous may collect further information from you if you select a reward option that requires it.
4.8 Client and business information
For Clients, prospective Clients and their representatives, this may include:
-
business contact details;
-
organisation and role;
-
project and service requirements;
-
proposals, contracts and purchase orders;
-
invoicing and payment information;
-
project correspondence;
-
portal-access and Account information;
-
meeting and event records; and
-
information about business interests and previous interactions.
4.9 Website, portal, app and technical information
This may include:
-
IP address;
-
browser and device type;
-
operating system;
-
login and authentication information;
-
pages or features accessed;
-
access date, time and duration;
-
referring source;
-
portal or app activity;
-
error and performance information;
-
security logs; and
-
cookie or similar-technology information.
Non-essential cookies and similar technologies are governed by our Cookie Notice and applicable preference controls.
4.10 Communications and preferences
We may collect:
-
emails, messages and other correspondence;
-
support and complaint records;
-
research-invitation preferences;
-
alert and communication preferences;
-
unsubscribe requests;
-
consent and objection records; and
-
records showing when privacy or participation information was provided.
5. Where we obtain personal information
We may obtain personal information in the following ways.
5.1 Directly from you
For example, when you:
-
create or update a profile;
-
take part in an Activity;
-
answer screening questions;
-
use a website, portal or app;
-
subscribe to an alert;
-
contact us;
-
attend a meeting or event;
-
ask to redeem an accumulated Honorarium; or
-
otherwise correspond with us.
5.2 From publicly available professional sources
These may include:
-
professional registers;
-
employer and healthcare-organisation websites;
-
professional profiles;
-
publications and conference materials;
-
professional associations;
-
regulatory and licensing bodies;
-
company websites; and
-
other legitimate public professional sources.
5.3 From other organisations
These may include:
-
Clients and End Clients;
-
medical education, research and communications agencies;
-
recruitment and referral partners;
-
professional networks;
-
event and conference organisers;
-
professional-data providers;
-
employers and healthcare organisations;
-
survey and technology providers; and
-
other organisations authorised or permitted to provide the information.
Where required, we will tell you the categories and source of information obtained from another organisation.
6. How and why we use personal information
6.1 Maintaining our professional database
We may use professional information to:
-
create and maintain professional profiles;
-
verify identity, qualifications, specialty, role and workplace;
-
understand professional experience and areas of interest;
-
link professionals with relevant healthcare organisations;
-
improve the accuracy and completeness of our database;
-
maintain participation and relationship histories;
-
identify potentially relevant Activities; and
-
develop our healthcare professional and healthcare organisation intelligence.
6.2 Identifying and inviting Participants
We may use profile information to:
-
identify people who may be relevant to an Activity;
-
select potential Participants according to role, specialty, experience, location or other professional characteristics;
-
send invitations;
-
manage recruitment and quotas;
-
avoid excessive or irrelevant invitations; and
-
improve the relevance of future invitations.
Final eligibility may be determined through screening questions presented before or during the Activity.
6.3 Administering Activities
We may use personal information to:
-
verify identity and professional status;
-
assess eligibility;
-
administer screening and participation;
-
provide access to a survey, interview or educational platform;
-
communicate Activity instructions;
-
analyse and report responses;
-
resolve technical issues;
-
contact Participants about clarification or validation;
-
arrange Honoraria;
-
maintain project and audit records; and
-
meet quality, ethical and compliance requirements.
6.4 Quality, fraud prevention and security
We may use information to:
-
prevent duplicate participation;
-
identify false or misleading profile information;
-
check response quality and authenticity;
-
detect automated or improper participation;
-
investigate suspected fraud;
-
protect Accounts, links, websites, portals and apps;
-
protect the integrity of Activities and data; and
-
enforce applicable Participant and Website Terms.
Where appropriate and lawful, this may involve comparing information across Accounts, Activities, devices and previous interactions.
6.5 Research, educational and analytical outputs
We may use Activity information to:
-
prepare reports, presentations and analyses;
-
create aggregated, anonymised or de-identified findings;
-
carry out needs assessments and outcomes assessments;
-
evaluate educational impact;
-
assess patient impact;
-
develop behavioural intelligence;
-
perform benchmarking and predictive analysis;
-
validate findings;
-
improve research methods; and
-
support the purposes explained for the relevant Activity.
6.6 Managing Client and business relationships
We may use business information to:
-
respond to enquiries;
-
prepare proposals;
-
enter into and administer contracts;
-
deliver Services;
-
manage projects and approvals;
-
provide portal access;
-
issue and administer invoices;
-
maintain business relationships;
-
provide relevant information about nuaxia services; and
-
establish, exercise or defend legal rights.
6.7 Alerts and other communications
Where you subscribe or otherwise ask to receive them, we may send:
-
medical and industry alerts;
-
regulatory and product-approval updates;
-
compensation and reimbursement updates;
-
industry news;
-
educational information;
-
nuaxia service information; and
-
other communications covered by your stated preferences.
You can unsubscribe or change your preferences at any time.
Research invitations, operational messages, alerts and commercial marketing are treated as different categories of communication.
6.8 Measuring communications
Where permitted and enabled, we may collect limited information about the delivery and use of opted-in alerts and communications, such as:
-
whether an email was delivered;
-
whether it appears to have been opened;
-
whether a link was selected; and
-
the approximate date, time and type of interaction.
We may use this information to:
-
identify delivery problems;
-
understand whether communications are useful;
-
improve their relevance; and
-
reduce unnecessary communications.
Email-open and click information can be incomplete or inaccurate because of email-provider controls, privacy protections, device settings and technical limitations. We do not treat it as definitive evidence that an individual read or acted on a communication.
Where a tracking technology requires consent, we will use it only where the required permission or another applicable legal exception is available. The ICO identifies tracking pixels and navigational link tracking as technologies that may require prior consent unless an exception applies.
6.9 Developing and improving our services
We may use information to:
-
improve the quality and accuracy of our databases;
-
improve Participant matching and profiling;
-
understand how websites, portals and apps are used;
-
improve accessibility, usability and performance;
-
develop and test services;
-
evaluate communications;
-
generate statistics and business insights; and
-
improve security and fraud detection.
Where reasonably possible, we use anonymised or aggregated information for these purposes.
6.10 Legal, regulatory and safety purposes
We may use or disclose information to:
-
comply with data-protection, tax, accounting and other legal duties;
-
respond to courts, regulators and public authorities;
-
establish, exercise or defend legal claims;
-
investigate suspected unlawful conduct;
-
comply with sanctions and anti-fraud requirements;
-
report adverse events, product complaints and other safety information; and
-
maintain records required by law or applicable industry standards.
7. Our lawful bases
The lawful basis depends on the purpose and circumstances.
7.1 Contract
We may process personal information where necessary to:
-
provide an Account or requested service;
-
administer participation under the applicable Participant Terms;
-
issue or administer an Honorarium;
-
provide contracted Client services; or
-
take requested steps before entering into a contract.
7.2 Legitimate interests
We may rely on our legitimate interests, or those of another organisation, where those interests are not overridden by your rights and interests.
These interests may include:
-
maintaining an accurate professional database;
-
identifying and inviting relevant professional Participants;
-
managing professional and Client relationships;
-
carrying out healthcare research and educational Activities;
-
improving data quality and services;
-
preventing fraud and duplicate participation;
-
protecting systems and information;
-
communicating with professional and business contacts;
-
establishing and defending legal rights; and
-
operating and developing our business.
Where required, we assess the necessity and potential effect of this processing.
7.3 Consent
We may rely on consent where it is appropriate or legally required, including for:
-
optional alerts and electronic marketing;
-
non-essential cookies and tracking technologies;
-
certain uses of audio, video, images or identifiable quotations;
-
identifiable disclosure in a particular Activity;
-
public-facing or promotional use of Participant material; and
-
some processing of health or other special-category information.
You may withdraw consent at any time. Withdrawal does not affect processing that lawfully occurred before withdrawal.
7.4 Legal obligation
We may process information where necessary to comply with legal or regulatory obligations, including accounting, taxation, court, regulatory, data-protection and safety-reporting duties.
7.5 Special-category information
Where we process health information or another special category of personal information, we must also have an additional legal condition.
Depending on the Activity and applicable law, this may include:
-
explicit consent;
-
establishing, exercising or defending legal claims;
-
an applicable research or statistical condition with appropriate safeguards; or
-
another condition permitted by law and explained where relevant.
8. Profiling and automated processing
nuaxia creates and maintains professional profiles to understand matters such as a person’s:
-
role and specialty;
-
qualifications and experience;
-
professional interests;
-
therapeutic-area experience;
-
location and workplace;
-
previous participation; and
-
potential relevance to Activities.
We may use automated tools and rules to:
-
organise, check or enhance profiles;
-
match profiles to potentially relevant Activities;
-
prioritise invitations;
-
apply screening or quota rules;
-
identify possible duplicates;
-
identify possible fraud or unusual participation; and
-
flag information for review or updating.
Automated matching may affect whether you receive an invitation or proceed through a screener. These processes are not intended to make decisions that produce legal or similarly significant effects.
Where applicable, you may contact us to:
-
ask about information held in your profile;
-
correct inaccurate information;
-
object to profiling based on legitimate interests; or
-
request human review of an applicable automated decision.
9. Who we share personal information with
9.1 Clients, agencies and End Clients
Research findings are normally shared in aggregated, anonymised or de-identified form.
We do not normally provide Participant names, contact details, Account information or reward information to a commissioning organisation.
Limited identifiable information may be shared where:
-
an agency needs the information to administer or oversee an Activity;
-
the Activity involves agreed observation or recording access;
-
an identifiable quotation, recording or contribution is being used with appropriate permission;
-
adverse-event or product-complaint reporting requires disclosure;
-
disclosure is required by law; or
-
the use has otherwise been clearly explained and has an appropriate lawful basis.
Where a Client or End Client acts as a controller, supplies the personal information, or will receive identifiable information, the relevant organisation will be named where required. If naming the organisation before participation would undermine the integrity of the Activity, its identity may be disclosed later where permitted and appropriately explained.
9.2 Service providers
We may use service providers for:
-
website and cloud hosting;
-
survey and interview platforms;
-
portals and apps;
-
email and communications;
-
relationship and database management;
-
data verification and enrichment;
-
analytics and security;
-
transcription and translation;
-
technical support;
-
professional advice;
-
reward administration; and
-
other operational services.
Providers are required to use personal information only for authorised purposes and to maintain appropriate protections.
9.3 Forsta Decipher
We use Forsta Decipher to program, host and administer surveys and to process survey responses.
Forsta may process personal information and survey data as a service provider to nuaxia. The exact processing location may depend on nuaxia’s contracted service environment and Forsta’s authorised infrastructure and subprocessors.
Forsta publishes technical and organisational measures including encryption, access control, backup and recovery, vulnerability management and subprocessor controls.
9.4 Tremendous
We use Tremendous, a provider based in the United States, to issue and administer digital Honoraria.
We may provide Tremendous with information such as:
-
name, where needed;
-
email address;
-
country or currency;
-
reward amount; and
-
information required to issue and support the reward.
Tremendous manages reward delivery and redemption and may collect additional information directly from you where required for the reward option you select.
9.5 Recruitment and referral partners
Where you are introduced by a recruiter, agency, colleague or referral partner, we may share limited information needed to:
-
confirm eligibility or participation;
-
avoid duplicate recruitment;
-
administer the Activity;
-
reconcile recruitment records; or
-
address a query or complaint.
Each organisation is responsible for explaining its own processing.
9.6 Regulators, authorities and advisers
We may disclose information where required or reasonably necessary to:
-
courts;
-
regulators;
-
law-enforcement bodies;
-
tax authorities;
-
safety and pharmacovigilance teams;
-
insurers;
-
auditors;
-
lawyers; and
-
other professional advisers.
9.7 Corporate transactions
Personal information may be disclosed as part of a proposed or completed:
-
investment;
-
financing;
-
merger;
-
restructuring;
-
acquisition; or
-
sale of all or part of nuaxia’s business or assets,
subject to appropriate confidentiality and data-protection arrangements.
10. Adverse events and product complaints
Where an Activity concerns a medicine, medical device or other healthcare product, information supplied may include:
-
an adverse event or side effect;
-
a product complaint;
-
product misuse;
-
pregnancy or breastfeeding exposure;
-
lack of effectiveness; or
-
another safety matter.
We may be required to report relevant information to the commissioning organisation, its safety team or another appropriate organisation.
Where relevant, the Activity information will explain:
-
what information may be reported;
-
who may receive it;
-
whether follow-up may occur; and
-
whether identity or contact details may be disclosed.
We will not automatically disclose the identity of a Participant or treating healthcare professional merely because safety information arises. Any identifiable disclosure must be lawful and consistent with the information provided for the Activity.
11. International processing and transfers
nuaxia is based in the United Kingdom and operates internationally.
Our primary professional database is hosted in Germany.
We use Forsta Decipher to administer surveys and process survey information. The locations from which Forsta and its authorised providers process information may depend on the relevant contracted service environment.
We use Tremendous, which is based in the United States, to issue and administer digital rewards.
Personal information may therefore be processed in:
-
the United Kingdom;
-
Germany and other countries in the European Economic Area;
-
the United States; and
-
other countries in which an authorised provider or relevant project operates.
Where personal information is transferred to a country that is not covered by an applicable adequacy decision or regulation, we use an appropriate lawful safeguard where required. This may include:
-
approved contractual clauses;
-
the UK International Data Transfer Agreement;
-
the UK Addendum to approved EU contractual clauses; or
-
another lawful transfer mechanism or exception.
You may contact us for further information about the safeguards applying to a particular transfer.
12. How long we keep personal information
We retain personal information only for as long as it is reasonably required for the purposes for which it is used, including professional relationship management, research, quality assurance, fraud prevention, accounting, legal compliance and the establishment or defence of claims.
The applicable period depends on:
-
the type and sensitivity of the information;
-
why it is held;
-
whether we have a continuing relationship with the individual;
-
relevant Client, legal, regulatory or professional requirements;
-
the risk of fraud or duplicate participation;
-
whether a complaint or dispute may arise; and
-
whether the information can be anonymised instead of retained identifiably.
Data-protection principles require organisations to be able to justify retention, review information periodically and erase or anonymise it when it is no longer needed.
12.1 Professional profiles
We may retain professional profile and contact information while:
-
it remains relevant to our professional database and services;
-
we have an active or reasonably anticipated professional relationship;
-
it is required to maintain an accurate history of participation;
-
it is needed to prevent duplicate or fraudulent participation;
-
it is needed to respect communication preferences; or
-
retention remains necessary for legal, regulatory or compliance purposes.
We periodically review professional information and may update, restrict, anonymise or delete it when it is no longer reasonably required.
12.2 Activity responses and project records
We retain survey, interview and related project information for as long as reasonably required to:
-
complete and report the Activity;
-
carry out analysis, validation and quality assurance;
-
answer queries or resolve disputes;
-
meet applicable Client, legal, audit or regulatory requirements; and
-
maintain appropriate research and compliance records.
Where we no longer need to identify the Participant, we may delete identifying information or retain responses only in anonymised form.
12.3 Audio and video recordings
Recordings are retained only for the period reasonably required for the purposes explained for the Activity.
A more specific period may be stated before recording.
12.4 Honorarium and reward records
We retain Honorarium and reward information for as long as needed to:
-
issue and support rewards;
-
administer accumulated balances;
-
resolve queries;
-
maintain quality, fraud and audit records; and
-
meet tax, accounting and legal requirements.
An accumulated incentive balance may be lapsed after more than three years of inactivity in accordance with the applicable Participant Terms and applicable law.
12.5 Alerts and communication preferences
Alert-subscription information is retained while you remain subscribed.
Where you unsubscribe or object, we may retain limited information on a suppression list so that we can continue to respect your request.
12.6 Technical and security records
Technical logs, access information and security records are retained for periods appropriate to:
-
operating and protecting the relevant service;
-
investigating incidents;
-
preventing misuse; and
-
meeting legal requirements.
12.7 Backups
Information removed from active systems may remain temporarily in protected backups until overwritten or deleted through the ordinary backup cycle.
Backup information remains protected and is not used for unrelated purposes.
13. Security
We use appropriate technical and organisational measures designed to protect personal information from:
-
unauthorised access or disclosure;
-
accidental loss or destruction;
-
inappropriate alteration;
-
misuse; and
-
loss of availability.
Measures may include:
-
access controls;
-
confidentiality requirements;
-
authentication and password controls;
-
encryption where appropriate;
-
system, network and endpoint protection;
-
backup and recovery arrangements;
-
logging and monitoring;
-
staff training;
-
incident-response procedures; and
-
supplier security and contractual controls.
No information system can be guaranteed to be completely secure.
14. Your data-protection rights
Depending on the applicable law and circumstances, you may have the right to:
-
receive information about how your personal information is used;
-
access personal information held about you;
-
correct inaccurate or incomplete information;
-
request deletion;
-
request restriction of processing;
-
object to processing based on legitimate interests;
-
object to direct marketing;
-
receive certain information in a portable format;
-
withdraw consent;
-
request safeguards relating to qualifying automated decisions; and
-
complain to a data-protection authority.
These rights are not absolute. We may need to retain or continue using information where, for example:
-
retention is required by law;
-
another person’s rights must be protected;
-
the information is required to establish or defend a claim;
-
a valid legal exception applies; or
-
a limited suppression or fraud-prevention record is necessary.
You may exercise your rights by contacting:
We may request reasonable information to confirm your identity.
Where another organisation acts as controller, we may direct the request to that organisation and assist it where appropriate.
15. Communication, invitation and profiling preferences
You may ask us to:
-
stop sending research invitations;
-
stop sending a particular category of communication;
-
unsubscribe you from alerts;
-
update your communication preferences;
-
object to profiling based on legitimate interests;
-
correct your professional profile; or
-
close an Account.
You can normally unsubscribe using the link included in the relevant email or by contacting us.
Where you object to direct marketing, we will stop using your information for that purpose. We may retain limited information on a suppression list to ensure that the relevant communication is not sent again.
Closing an Account or stopping invitations does not necessarily require deletion of all related records. Some information may need to be retained for legal, security, fraud-prevention, audit or suppression purposes.
16. Country-specific healthcare market-research provisions
The following provisions apply to healthcare market research conducted in the stated country. They supplement the rest of this Privacy Notice.
Other country-specific information may be provided before or at the beginning of an Activity.
16.1 Germany
For healthcare market research conducted in Germany:
-
data supplied to the Client or another third party will be provided in a form that does not permit individual Participants to be recognised or identified;
-
a Participant cannot waive this market-research anonymity requirement by consenting to identifiable disclosure to the Client;
-
information used to administer an Honorarium will be kept in a form that prevents it from being merged with the relevant research responses;
-
for a one-off study, study-specific identifiable information will be deleted or separated from the responses once necessary quality controls and data checks have been completed, unless another lawful and separately stated purpose requires retention; and
-
for a follow-up or repeat study, contact information will be kept separate from the information collected for the duration of the research.
These provisions reflect the Germany-specific anonymity, incentive-record and retention requirements in the EphMRA Code.
16.2 France
For healthcare market research conducted in France:
-
Participant anonymity will be protected;
-
details identifying a Participant will be separated from their research responses after necessary identity, eligibility and quality checks have been completed; and
-
research results supplied to the commissioning organisation will not identify the individual Participant unless a lawful exception expressly applies.
16.3 Spain
For healthcare market research conducted in Spain:
-
Participant identity will be blinded from a commissioning pharmaceutical company;
-
the pharmaceutical company will not ordinarily be able to learn the Participant’s identity before, during or after the study; and
-
where temporary access to identity is permitted solely to supervise or control study quality, no identifiable Participant record may remain with the pharmaceutical company after the quality-control work is completed.
16.4 Italy
For healthcare market research conducted in Italy, personal or confidential information provided during the research will not be disclosed in identifiable form without the Participant’s permission or another applicable lawful basis.
16.5 Denmark
For healthcare market research involving Danish doctors, dentists or pharmacists, nuaxia may use a double-blind design under which the Participant and the commissioning pharmaceutical or medical-technology company do not know each other’s identity.
This may be necessary to preserve the research’s treatment as independent market research and avoid creating a reportable professional association under applicable Danish requirements.
16.6 Mexico
Where Mexican privacy law applies, nuaxia will provide or make available an appropriate aviso de privacidad before collecting personal information.
The local notice may include additional information about:
-
nuaxia’s identity and address;
-
processing purposes;
-
methods for limiting use or disclosure;
-
access, rectification, cancellation and objection rights;
-
withdrawal of consent;
-
proposed transfers; and
-
how changes to the local notice will be communicated.
Where required, agreement to the Mexican privacy notice will be recorded separately from general acceptance of the Participant Terms.
16.7 Japan
Where Japanese privacy law applies, nuaxia will specify the Purpose of Use of personal information as clearly and fully as reasonably possible.
Where information is collected through a survey, form, contract or other electronic document, the relevant Purpose of Use will be stated before collection.
nuaxia will not use personal information beyond a purpose reasonably related to the stated Purpose of Use without obtaining any further permission required by applicable law.
16.8 Australia
Where Australian privacy requirements apply, additional information may be provided concerning:
-
the organisation responsible for collection;
-
the purpose of collecting identifiable research information;
-
access, correction, de-identification and destruction;
-
the complaints process;
-
overseas disclosure; and
-
quality-control recontact.
Where an Activity is identifiable rather than anonymous, this will be explained before participation, together with the intended recipient and purpose of any identifiable disclosure.
16.9 United States
Privacy requirements in the United States may differ by state and according to the type of information involved.
Additional state-specific or consumer-health-data information may be provided where required.
Where nuaxia processes protected health information on behalf of an organisation covered by the US HIPAA Privacy Rule, appropriate contractual and privacy arrangements will be put in place before that processing begins. EphMRA notes that US privacy requirements consist of sector-specific federal rules and numerous state privacy laws.
17. Cookies and similar technologies
We use cookies and similar technologies to:
-
provide essential website and portal functions;
-
maintain security;
-
remember preferences;
-
understand use and performance; and
-
support analytics and communications where permitted.
Non-essential technologies will be used only where permitted by applicable law and the choices made through our preference controls.
Further information is provided in our Cookie Notice.
18. Children and young people
nuaxia’s general website, professional database and standard Activities are not directed at children.
A person under 18 may participate only where:
-
the Activity is specifically designed for younger Participants;
-
appropriate age-related information is provided;
-
the necessary parent or responsible-adult permission is obtained;
-
any legally required agreement from the young person is obtained; and
-
appropriate privacy and safeguarding arrangements are in place.
Local age and consent requirements will apply.
19. Third-party websites and services
Our websites, portals, apps, communications and Activities may link to services operated by other organisations.
Those organisations are responsible for their own privacy practices. You should review their privacy information before using their services.
20. Changes to this Privacy Notice
We may update this Privacy Notice to reflect changes in:
-
our services and technology;
-
our use of personal information;
-
our providers;
-
applicable law and regulatory guidance; or
-
our organisational arrangements.
The current version will be published on our website with its effective date.
Where a change materially affects how we use information already collected, we will take reasonable steps to bring the change to the attention of affected individuals where required.
21. Complaints
Please contact us first if you have a concern about how we use personal information:
You also have the right to complain to the Information Commissioner’s Office, the United Kingdom’s data-protection regulator.
If you live or work in another country, you may also be entitled to complain to the relevant local data-protection authority.
22. Contact details
Privacy contact
nuaxia Limited
5 Walpole Avenue
Richmond
Surrey
TW9 2DJ
United Kingdom
Email: legal@nuaxia.com