Privacy Policy and Data Protection

The MD Anderson International Spain Foundation (hereinafter, the FOUNDATION), in accordance with EU Regulation 2016/679 on Data Protection and Organic Law 3/2018, December 5, on the Protection of Personal Data and guarantee of digital rights and other current regulations regarding the protection of data, informs users of the www.fundacionmdanderson.es website (hereinafter, the Website) of the Privacy and Data Protection Policy that will apply in the treatment of personal data that the User provides voluntarily when accessing said website.

The User, by providing the FOUNDATION with their personal data through the electronic forms on the Website and, where appropriate, by marking the corresponding acceptance box, expressly consents that the FOUNDATION may treat such data under the terms of this Privacy Policy and Data Protection clause and for the purposes expressed herein.

The FOUNDATION informs users of the Website that their personal data may only be obtained for processing when adequate, relevant and not excessive in relation to the scope and specific, explicit and legitimate purposes for which they have been obtained. Said data will be canceled when no longer necessary or relevant for said purpose or when requested by the subject in the exercise of their right of cancellation.

The FOUNDATION expresses its commitment to compliance with current legislation at all times regarding data protection.

Personal data provided by the subject will be processed by the FOUNDATION and will be used in accordance with the following information:

What personal data do we collect and for what use?

 

-Data collected directly: by voluntarily completing the contact form, donations, registration of request for scholarships, congresses and events managed through the website, request for tissue samples (Biobank), networking on our social networks, response to surveys

-Data collected indirectly by means of cookies: for statistics, to analyze the use made of our Website and to provide value-added services such as the map location of our offices.

In the table below you will find further detailed information on the treatment of your personal data, including the following sections:

 

Main purposes: The purpose for which we collect your data, that is, why we treat your information.

 

Legitimization: The reasons for which we are authorized to treat your data is described in detail.

 

Conservation periods: The specific conservation period or the criteria that determine said period are described.

 

Recipients: We identify, where appropriate, with whom we will legitimately share your data.

 

Data subjects’ rights: We inform you about your rights as a subject, or interested party, in the treatment of your personal data.

 

 

INFORMATION ON PROTECTION OF PERSONAL DATA

 (In compliance with EU Regulation 2016/679 on Data Protection)

Data Controller

Company name: MD ANDERSON INTERNATIONAL FOUNDATION SPAIN

Tax Nº: G-82822941

Address: Calle Gomez Hemans 2, 28033 Madrid

Telephone: 91 78780625

Email: info.fundacion@mdanderson.es

DPC: dpd@fundacionmdanderson.es

The FOUNDATION acts as an entity whose purpose is to promote activities in favor of research and progress in curing cancer related diseases, promoting the training of students and specialists, promoting research and prevention in all matters related to the diagnosis and treatment of cancer.

Main purposes

-Economic and material management of contributions and donations to the FOUNDATION

Respond to the queries of Users who contact us through the Contact routes

-Manage the dispatching of information related to the promotion of clinical trials and scientific research

-Process registrations for courses and events

-Manage the Volunteer Services section

-Manage newsletter subscriptions and information bulletins

-Cookies: maintain registered users’ log-in information, provide statistics associated with the use of the Website, location of our offices and anti-spam systems (captcha)

Data requested is required for transactions of users via the website

Legitimation and conservation

The legal basis for the treatment of data is the establishment of a contractual relationship with the request for the service in question and the consent granted by the User by marking, where appropriate, the corresponding acceptance box of the Privacy Policy and by validation of the user’s email account on the registration forms.

Fields on the Website forms marked with a red asterisk (*) are considered mandatory fields and must be completed in view of the circumstances in which they are requested. If said fields are not completed, the user will not be able to continue with the registration process, contract services or contact the FOUNDATION.

See our cookie policy for information on cookies required to use the website.

Conservation periods:

  • Data associated with the registered user account: until cancellation of account is requested or after a 5-year period of inactivity  
  • Data associated with the management of services: for the duration of the contractual relationship
  • Data associated with participation in courses or events: for the duration of the same
  • Data provided via contact channels: 5 years
  • Data associated with networking on the FOUNDATION's corporate profiles on social networks: for the period publications are enabled on said social networks
  • Data provided for the subscription to the Newsletter or news bulletins: until the subscription is canceled and the statutory period associated with the treatment of the data has elapsed.
  • Data provided for the management of volunteers will be stored for a period of 5 years from the termination of the relationship with the volunteer services.
  • Data provided for the request of samples from the Biobank will be stored for a period of 2 years.
  • Data associated with cookies installed on the user’s device: they are stored for different periods associated with the time required for the fulfillment of their purpose as cookies associated with the maintenance of registered users’ log-in details and, in any case, for a maximum period of two years. Likewise, the user may erase cookies from their device through the appropriate configuration of their browser, as explained in the Cookies Policy.
  • In general, the FOUNDATION may store any data deemed necessary in compliance with the different statutory limitation periods associated with legal obligations or the exercise and development of legal actions.

In any case, the data will be deleted when its treatment is no longer required and will be eliminated from our records and anonymized in such a way that its identification be disabled.

 

Additional purposes

The sending invitations to acts or events sponsored by the FOUNDATION, by postal or electronic means, related to services offered by the foundation in the sector of scientific development and the promotion of research for the cure of cancer related diseases, allowing the Foundation to carry out automatic evaluations, obtaining profiles and segmentation tasks, based on the information available in order to personalize treatment according to users’ characteristics and/or needs.

Legitimation and conservation

The legal basis for the treatment of data is the consent granted by the User by marking, where appropriate, the corresponding acceptance box of the Privacy Policy.

The conservation periods for the data obtained for additional purposes are indefinite until its deletion is requested.

Recipients of disclosures and international transfer of data

-the subject’s data may be communicated to Public Bodies with tax and inspection powers for the correct management of donations.

- To Entities for the management of hospital stays and travel for certain types of events.

-To collaborating staff in the organization of activities or events and sponsors.

-To insurance companies in the field of volunteer activity in the event of accidents.

-Owners of social networks and web analytics management: the FOUNDATION uses social networks Facebook, Twitter, Instagram, YouTube and LinkedIn: interaction with users via said profiles or tools implies the international transfer of analytical or technical data in relation to the Website and network profiles, stored in servers in which the FOUNDATION treats the data provided by Users.

Web analytics service managements: The Website has enabled the Google Analytics services provided by Google LLC. Interaction with users by means of said tool implies the international transfer of analytical and technical data in relation to the Website.

The FOUNDATION makes use of the MICROSOFT CORPORATION "Online Services for companies" with tools such as Office 365, Azure, with such use constituting an international transfer of data authorized by the Spanish Agency for Data Protection TI-00032-2014 dated 09-05-2014 (AEPD: TI-00032-2014_Resolucion-de-día-09-05 -2014).

In any case, when carrying out an international transfer of data, the data controller ensures the transfer is carried out with the appropriate guarantees allowing the subject to exercise their enforceable rights and effective legal actions.

Rights of the Subject

 

Los interesados tienen derecho a retirar el consentimiento prestado a través de los diferentes formularios de la página en la dirección arriba indicada.

The subject can exercise their rights of access, rectification, deletion, portability and limitation or opposition, before the Controller in writing at Plaza 25 de julio, PO Box 10681, 38004 Santa Cruz de Tenerife or by email at the following address protecciondedatos@fundacionmdanderson.es, attaching a copy of their Spanish Identification Card or other legal form of identification.

The subject has the right to withdraw consent given via the different forms on the website at the address indicated above.

 

The subject has the right to present complaints to the Control Authority (Spanish Data Protection Agency: www.aepd.es).

The user will be solely responsible for the veracity of data provided to the FOUNDATION.

The FOUNDATION manages its server environment appropriately, having a strictly compliant firewall infrastructure. It continually uses current technologies to ensure the confidentiality and privacy of information is not compromised. The Website uses the SSL (Secure Socket Layer) protocol to improve security. The secure server establishes a connection so that the information is transmitted encrypted using 128-bit algorithms, ensuring it is only intelligible to the Client's computer and that of the Website. In this way, using the SSL protocol guarantees:

-That the Client communicates their data to the server center of the Website and not any other server.

That between the Client and the Website data is transmitted in encrypted form, thus avoiding it being read or manipulated by third parties.

When accessing their accounts or submitting information from secure Internet pages, encryption will encode the users’ data in an illegible format to prevent unauthorized users from accessing this type of data.

The FOUNDATION takes the technical and organizational measures necessary to guarantee the security of personal data contained therein and to avoid its alteration, loss, treatment or unauthorized access, taking into account the state of the technology, the nature of the data and the risks to which they are exposed.

Any change in the Privacy Policy and in information management practices will be reflected in a timely manner, and the FOUNDATION may add, modify or eliminate said privacy policy when deemed necessary.

In any case, the FOUNDATION will not, at any time, modify these policies or practices to make them less effective in protecting the personal data of our clients previously stored, without the prior consent of the affected clients.

Last Updated: November 12, 2020