Privacy Notice: Patients

OUR COMMITMENT

Your personal data is very important, and any information collected will be handled responsibly. The company UNIVERSKIN whose registered office is located at 12 Rue Paul Déroulède, 06000 Nice – France is accountable for the data processing.

UNIVERSKIN is committed to strictly comply with its obligations under all applicable laws and regulations, including, but not limited to, the European Union (EU), the European Economic Area (EEA) and their member States, applicable to processing of these data, including the general Data Protection Regulation EU 2016/679 (GDPR).


Identifiable data

Civil status information, identity and identification data:

-     your first and last name,

-     your date of birth,

-     your photo, and

-     your address.

Contact information:

-     your email address, and

-     your phone number.


Qualifying data

Location information:

-     your area of residence.


Health Information

-     your pathology, your ailments,

-     family History,

-     data related to health care,

-     alterations, anomalies, physiological changes,

-     risky situations/behaviours, and

-     photos related to your physiological problem (optional).


MAIN AIMS AND LEGAL BASIS

This information will be published on the website UNIVERSKIN (www.universkin.com) to enable contact with future patients. The legal basis of treatment is the provision of your services to patients.

This data will also be used to analyze in a scientific way the inflammatory skin disease you suffer (rashes, itchy skin and visible redness) and thus allow the establishment of a clinical evaluation by your doctor. The legal basis for treatment is the need for medical diagnostic treatment.


TREATMENT

As part of the main treatment, UNIVERSKIN will not allow itself to access your identifiable data.

UNIVERSKIN will only have access to your qualifying data. Qualifying data will be considered pseudonymous data by replacing your identifiable data with a code. Pseudonymization always allows you to identify an individual through his or her personal data because it is simply to replace one attribute with another in a record. Pseudonymization allows the subtraction of anonymity or the study of correlations in case of need.

The qualifying data may be processed by the employees of the UNIVERSKIN services who are responsible for carrying out the activities described above, who have been authorized to process the data and who have received appropriate operating instructions.

Qualifying and identifiable data can be processed on behalf of the data controller by external party firms designated as data processors carrying out specific activities for the controller.

Your data will be stored for a period of 3 years after reporting the identifiable data. They will be accessible to your doctor and will not in any way be transferred to third parties or outside the European Economic Area (EEA).


YOUR RIGHTS

As a subject, you have the possibility to request the exercise of the following rights

- RIGHT TO INFORMATION: Before and during each data collection, UNIVERSKIN will be able to explain its treatment process in a clear and simple language.

- RIGHT OF ACCESS: you are entitled to ask UNIVERSKIN to provide you with all the information held about you;

- RIGHT OF RECTIFICATION: you are entitled to ask UNIVERSKIN to rectify, in particular by completing or correcting, all or certain information held about you.

- RIGHT TO ERASURE (“RIGHT TO OBLIVION”): You are entitled to ask UNIVERSKIN to remove all information held about you from its systems;

- RIGHT TO LIMITATION OF TREATMENT: You can ask UNIVERSKIN that some of your data is not processed. They are then said to be locked.

- RIGHT OF OBJECTION: You may object to the processing of personal data concerning you.

- RIGHT TO DATA PORTABILITY: You can have your data transmitted between your different service providers or ask to retrieve your information.

In order to allow the exercise of your rights, you are requested to contact the data Protection officer, Mr. Xavier Gobert at + 33 9 70 70 20 09 or by sending an email to

            UNIVERSKIN.RGPD@ mydata-trust.info

As a subject of the data, you have the right to lodge a complaint with the competent supervisory authority in the Member State where you reside or work, or in the Member State where the alleged violation took place.

The supervisory authority in France is the “Commission Nationale Informatique et Libertés” (CNIL) located at 3 Place de Fontenoy, 75334 Paris CEDEX 07-Tel: + 33 01 53 73 22.