1. Introduction
Welcome to Onnmed ("Onnmed," "we," "our," or "us"). We are committed to protecting your privacy and handling your personal information in a transparent, secure, and lawful manner.
This Privacy Policy explains how we collect, use, disclose, store, transfer, and safeguard personal information obtained through our website, https://www.onnmed.com (the "Website"), our online platforms, our professional services, and our communications with clients, researchers, healthcare professionals, institutions, universities, hospitals, pharmaceutical organizations, and other business partners.
Onnmed provides professional services including, but not limited to:
- Medical and scientific research support
- Clinical research consulting
- Study design and protocol development
- Biostatistics and statistical analysis
- Systematic reviews and meta-analyses
- Manuscript writing and editing
- Scientific publication support
- Clinical trial support services
- Research methodology consultation
- Medical writing
- Survey development and validation
- Journal publication services
- Academic consulting
- Healthcare consulting
- Related professional and scientific services
We recognize that many of our clients operate in highly regulated environments involving healthcare, scientific research, and academic institutions. Protecting confidential information and personal data is therefore a fundamental part of our operations.
This Privacy Policy has been developed to align with internationally recognized privacy principles and applicable data protection legislation, including, where applicable:
- United Arab Emirates Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data (PDPL);
- European Union General Data Protection Regulation (EU) 2016/679 (GDPR);
- United Kingdom General Data Protection Regulation (UK GDPR);
- California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA);
- Other applicable national and regional privacy laws that govern the processing of personal information.
Nothing in this Privacy Policy is intended to reduce or limit any mandatory rights granted to individuals under applicable law.
________________________________________
2. Scope of this Privacy Policy
This Privacy Policy applies to personal information collected through:
- our Website;
- online quotation requests;
- contact forms;
- customer support communications;
- email correspondence;
- telephone communications;
- video conferencing platforms;
- client onboarding processes;
- research collaboration activities;
- professional consulting engagements;
- manuscript submission systems operated by Onnmed;
- online payment systems;
- newsletters and marketing communications;
- recruitment activities;
- business development activities; and
- any other interaction in which Onnmed collects or processes personal information.
This Privacy Policy applies regardless of whether you access our services from the United Arab Emirates or from any other jurisdiction.
________________________________________
3. Who This Policy Applies To
This Privacy Policy applies to:
- website visitors;
- prospective clients;
- existing clients;
- healthcare professionals;
- researchers;
- authors;
- students;
- academic institutions;
- hospitals;
- universities;
- pharmaceutical companies;
- sponsors;
- collaborators;
- contractors;
- vendors;
- business representatives;
- applicants seeking employment or collaboration opportunities; and
- any other individual whose personal information is processed by Onnmed.
Different privacy notices or contractual agreements may supplement this Privacy Policy where required for specific services or legal obligations.
________________________________________
4. Acceptance of this Privacy Policy
By accessing or using our Website or by engaging with our services, you acknowledge that you have read and understood this Privacy Policy.
Where required by applicable law, we will obtain your consent before collecting or processing personal information that requires consent. Where consent is not the legal basis for processing, we process personal information only where another lawful basis exists under applicable legislation.
If you do not agree with this Privacy Policy, you should discontinue use of our Website and refrain from submitting personal information through our online services.
________________________________________
5. Our Commitment to Privacy
Onnmed is committed to processing personal information according to the following principles:
- Lawfulness, fairness, and transparency;
- Purpose limitation;
- Data minimization;
- Accuracy;
- Storage limitation;
- Integrity and confidentiality;
- Accountability.
We implement appropriate administrative, organizational, contractual, and technical safeguards designed to protect personal information against unauthorized access, accidental loss, unlawful disclosure, alteration, destruction, or misuse.
Privacy considerations are integrated into our operational processes, technology infrastructure, and service delivery practices wherever reasonably practicable.
________________________________________
6. Definitions
For the purposes of this Privacy Policy, the following definitions apply unless the context requires otherwise.
Account
A registered profile or access credentials that enable an individual or organization to access certain services, platforms, or features provided by Onnmed.
Applicable Data Protection Laws
Any laws, regulations, directives, or legally binding requirements governing the collection, use, disclosure, storage, transfer, or protection of personal information, including but not limited to the UAE Personal Data Protection Law (PDPL), the European Union General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and other applicable privacy legislation.
Client
Any individual, organization, university, healthcare institution, pharmaceutical company, research sponsor, government entity, or other party that purchases or requests services from Onnmed.
Consent
Any freely given, specific, informed, and unambiguous indication of an individual's wishes by which they agree to the processing of their personal information where such consent is required by applicable law.
Cookies
Small text files or similar technologies placed on a user's device that enable websites to recognize devices, remember preferences, improve functionality, measure performance, and support analytics and security features.
Data Controller
The natural or legal person, public authority, agency, institution, or other entity that determines the purposes and means of processing personal information.
For many research support engagements, the client acts as the Data Controller, while Onnmed processes information solely on the client's documented instructions.
Data Processor
A natural or legal person, organization, or other entity that processes personal information on behalf of a Data Controller.
Depending on the nature of the services provided, Onnmed may act as a Data Processor, a Data Controller, or both for different categories of personal information.
Healthcare Information
Information relating to an individual's physical or mental health, medical condition, diagnosis, treatment, laboratory results, imaging, medications, genetic information, clinical history, or healthcare services.
Personal Information (Personal Data)
Any information relating to an identified or identifiable natural person. An identifiable individual is one who can be identified directly or indirectly by reference to identifiers such as:
- Name
- Email address
- Telephone number
- Postal address
- Government-issued identification number
- Passport information
- IP address
- Device identifiers
- Online identifiers
- Location data
- Employment information
- Educational information
- Financial information
- Professional credentials
- Any other information that can reasonably identify an individual.
Processing
Any operation or set of operations performed on personal information, whether by automated or manual means, including but not limited to:
- Collection
- Recording
- Organization
- Structuring
- Storage
- Adaptation
- Retrieval
- Consultation
- Use
- Analysis
- Transmission
- Sharing
- Publication
- Restriction
- Archiving
- Deletion
- Destruction
Profiling
Any automated processing of personal information used to evaluate, analyze, or predict aspects concerning an individual's preferences, interests, professional activities, or behavior.
Onnmed does not use automated profiling to make legally significant decisions about individuals.
Research Data
Information processed in connection with scientific, clinical, academic, educational, or healthcare research activities.
Research Data may include:
- Study datasets
- Clinical measurements
- Laboratory results
- Survey responses
- Statistical datasets
- Research documentation
- Protocols
- Case report forms
- De-identified or pseudonymized data
- Metadata relating to research activities
Research Data may or may not constitute Personal Information depending on whether individuals are identifiable.
Sensitive Personal Information (Special Category Data)
Personal information requiring enhanced protection under applicable law, including information relating to:
- Physical or mental health
- Medical records
- Genetic information
- Biometric information
- Racial or ethnic origin
- Religious or philosophical beliefs
- Political opinions
- Trade union membership
- Sexual orientation or sexual life
- Criminal convictions where applicable
- Any other category designated as sensitive under applicable legislation.
Onnmed processes Sensitive Personal Information only where legally permitted or contractually required and applies enhanced security measures appropriate to the nature of such information.
Service Providers
Third-party organizations or individuals engaged by Onnmed to perform services on its behalf, including but not limited to:
- Cloud hosting providers
- Payment processors
- Email service providers
- Customer relationship management platforms
- Analytics providers
- Communication platforms
- Security providers
- IT infrastructure providers
- Professional advisers
- Legal and accounting firms
Service Providers are contractually required, where applicable, to process personal information only for authorized purposes and to maintain appropriate confidentiality and security safeguards.
Third Party
Any individual or organization other than:
- the data subject;
- Onnmed;
- an authorized processor acting on behalf of Onnmed; or
- a person authorized under the direct authority of Onnmed or the relevant Data Controller to process personal information.
Website
The official Onnmed website located at https://www.onnmed.com, together with all associated webpages, portals, applications, forms, subdomains, and online services operated by or on behalf of Onnmed.
User
Any individual who visits, browses, accesses, communicates with, registers on, or otherwise interacts with the Website or any service provided by Onnmed.
________________________________________
7. Information We Collect
The categories of personal information we collect depend on how you interact with Onnmed, the services you request, and the nature of our professional relationship with you. We collect only the information that is reasonably necessary to provide our services, comply with legal obligations, maintain our business operations, and protect our legitimate interests.
7.1 Information You Provide Directly
You may voluntarily provide personal information when you:
- Submit an inquiry through our Website.
- Request a quotation.
- Contact us by email, telephone, messaging applications, or social media.
- Register for webinars, newsletters, or educational events.
- Submit a manuscript or research project.
- Engage us for consulting or research services.
- Apply for employment or collaboration opportunities.
- Complete surveys, questionnaires, or feedback forms.
- Participate in meetings, interviews, or consultations.
Depending on the circumstances, this information may include:
- Full name
- Professional title
- Organization or institution
- Department
- Country of residence
- Postal address
- Email address
- Telephone number
- Academic qualifications
- Professional licenses or registrations
- Curriculum vitae (CV) or résumé
- Areas of expertise
- ORCID iD, ResearcherID, Scopus Author ID, or similar academic identifiers
- Billing information
- Company information
- Tax information where required
- Any other information voluntarily submitted by you.
________________________________________
7.2 Research and Scientific Information
Because Onnmed provides research and scientific consulting services, clients may submit information relating to research activities, including:
- Research protocols
- Study proposals
- Ethics submissions
- Institutional Review Board (IRB) documentation
- Case report forms
- Survey instruments
- Clinical datasets
- Statistical datasets
- Research manuscripts
- Grant applications
- Publication correspondence
- Peer review comments
- Laboratory data
- Imaging data
- Scientific documentation
- Supporting appendices
Where such materials contain personal information, Onnmed processes them solely for the purposes agreed with the client and in accordance with applicable law and contractual obligations.
Clients are responsible for ensuring that they have the legal authority to disclose such information to Onnmed.
________________________________________
7.3 Patient and Healthcare Information
Certain services may require the processing of healthcare-related information, including de-identified, pseudonymized, or identifiable patient data.
Examples may include:
- Clinical histories
- Laboratory results
- Radiological reports
- Medication information
- Demographic characteristics
- Clinical outcome measures
- Study participant information
- Medical records provided for research purposes
Where feasible and appropriate, we encourage clients to provide anonymized or pseudonymized information rather than directly identifiable patient information.
Onnmed does not collect patient information directly from patients through its Website unless explicitly stated for a specific service.
________________________________________
7.4 Information Collected Automatically
When you visit our Website, certain technical information may be collected automatically through your browser or device.
This may include:
- IP address
- Browser type and version
- Device type
- Device identifiers
- Operating system
- Screen resolution
- Language preferences
- Internet service provider
- Date and time of access
- Referring website
- Exit pages
- Pages visited
- Session duration
- Clickstream information
- Geographic region derived from IP address
- Error logs
- Security logs
This information helps us:
- Maintain Website security.
- Diagnose technical issues.
- Improve Website performance.
- Detect fraud and abuse.
- Understand Website usage.
- Enhance user experience.
________________________________________
7.5 Cookies and Similar Technologies
We use cookies and similar technologies to:
- Remember user preferences.
- Maintain session functionality.
- Improve Website performance.
- Analyze Website traffic.
- Measure marketing effectiveness.
- Enhance security.
- Prevent fraudulent activity.
Cookies may include:
- Essential cookies
- Functional cookies
- Analytics cookies
- Performance cookies
- Preference cookies
- Security cookies
Non-essential cookies are deployed only where required by applicable law after obtaining the necessary consent.
Additional information regarding our use of cookies is provided in our Cookie Policy.
________________________________________
7.6 Communications
We retain records of communications between you and Onnmed, including:
- Emails
- Website contact forms
- Live chat communications
- Customer support requests
- Telephone records where legally permitted
- Meeting notes
- Video conference communications
- Feedback forms
- Complaint correspondence
- Service-related communications
These records help us provide support, improve our services, resolve disputes, maintain quality assurance, and comply with legal obligations.
________________________________________
7.7 Payment Information
When payments are made for our services, we or our authorized payment service providers may process information necessary to complete the transaction, including:
- Billing name
- Billing address
- Organization name
- VAT or tax identification numbers where applicable
- Transaction reference numbers
- Payment amount
- Currency
- Payment status
Onnmed does not intentionally store complete payment card numbers, CVV codes, or other sensitive payment authentication data on its own servers unless specifically required for a secure and compliant payment solution.
Payment card information is generally processed directly by authorized third-party payment processors that comply with applicable payment security standards, including the Payment Card Industry Data Security Standard (PCI DSS), where applicable.
________________________________________
7.8 Marketing Preferences
If you subscribe to our newsletters, educational updates, promotional communications, or event announcements, we may collect:
- Email address
- Name
- Organization
- Country
- Areas of professional interest
- Subscription preferences
- Communication preferences
- Records of consent where required by law
You may withdraw your consent or unsubscribe from marketing communications at any time by following the instructions included in the communication or by contacting us directly.
________________________________________
7.9 Information from Third Parties
We may receive personal information from trusted third-party sources, including:
- Universities
- Hospitals
- Research institutions
- Pharmaceutical companies
- Research collaborators
- Professional referral partners
- Conference organizers
- Academic publishers
- Publicly available professional directories
- Professional networking platforms
- Identity verification providers where legally required
We process such information only where there is a lawful basis for doing so.
________________________________________
7.10 Information We Do Not Intentionally Collect
Unless specifically required for an agreed professional service, Onnmed does not intentionally collect:
- Personal information from children under the applicable age of digital consent.
- Government-issued identification documents unrelated to our services.
- Biometric identifiers for identification purposes.
- Financial account credentials.
- Passwords for third-party services.
- Sensitive personal information unrelated to the services requested.
If we inadvertently receive information that is unnecessary for the purposes for which it was provided, we may securely delete, anonymize, or return such information in accordance with applicable law and our internal data management procedures.
________________________________________
8. How We Use Your Information
Onnmed processes personal information only for specified, explicit, and legitimate purposes. We use personal information only to the extent necessary to provide our services, operate our business, comply with applicable legal obligations, protect our rights, and improve the quality and security of our services.
The purposes for which we process personal information include, but are not limited to, the following.
________________________________________
8.1 Providing Our Services
We use personal information to:
- Respond to inquiries and quotation requests.
- Evaluate service requirements.
- Prepare proposals and service agreements.
- Deliver consulting services.
- Perform medical writing and editing.
- Conduct statistical analyses.
- Prepare systematic reviews and meta-analyses.
- Support clinical research projects.
- Assist with manuscript preparation and publication.
- Develop study protocols and research documentation.
- Support ethics and regulatory submissions.
- Coordinate scientific collaborations.
- Provide publication support services.
- Deliver educational and academic consulting services.
- Manage ongoing client engagements.
________________________________________
8.2 Client Relationship Management
Personal information may be used to:
- Create and maintain client records.
- Verify client identity.
- Communicate regarding projects.
- Provide project updates.
- Respond to requests for information.
- Schedule meetings and consultations.
- Deliver reports and project outputs.
- Manage contractual relationships.
- Maintain service history.
- Improve client support.
________________________________________
8.3 Website Administration
We process technical information to:
- Operate and maintain our Website.
- Ensure Website availability.
- Improve functionality.
- Detect software errors.
- Monitor Website performance.
- Diagnose technical problems.
- Prevent misuse.
- Enhance accessibility.
- Optimize user experience.
________________________________________
8.4 Account Administration
Where users create accounts or access secure client portals, personal information may be used to:
- Authenticate users.
- Maintain account security.
- Reset passwords.
- Verify identity.
- Manage user permissions.
- Record account activity.
- Prevent unauthorized access.
________________________________________
8.5 Communication
We use personal information to communicate with users regarding:
- Service inquiries.
- Quotations.
- Active projects.
- Customer support.
- Technical assistance.
- Administrative notices.
- Security notifications.
- Contractual matters.
- Billing issues.
- Policy updates.
- Legal notices where required.
________________________________________
8.6 Research Support Services
When providing research support, personal information may be processed to:
- Analyze research datasets.
- Prepare statistical analyses.
- Validate research instruments.
- Review scientific documentation.
- Develop research methodologies.
- Prepare manuscripts.
- Assist with journal submissions.
- Prepare responses to peer reviewers.
- Conduct quality assurance reviews.
- Generate scientific reports.
Where Onnmed acts solely on behalf of a client, such processing is performed according to the client's documented instructions and applicable contractual obligations.
________________________________________
8.7 Quality Assurance
Personal information may be used to:
- Monitor service quality.
- Evaluate project outcomes.
- Improve internal procedures.
- Review operational performance.
- Conduct internal audits.
- Train personnel.
- Investigate service issues.
- Improve client satisfaction.
Whenever possible, information used for internal quality improvement is minimized or anonymized.
________________________________________
8.8 Security and Fraud Prevention
We process personal information to:
- Protect our systems.
- Detect unauthorized access.
- Prevent fraud.
- Monitor suspicious activity.
- Protect confidential information.
- Prevent cyberattacks.
- Maintain business continuity.
- Investigate security incidents.
- Enforce contractual rights.
- Protect our employees, contractors, clients, and business partners.
________________________________________
8.9 Legal and Regulatory Compliance
We may process personal information to:
- Comply with applicable laws.
- Respond to lawful governmental requests.
- Satisfy tax and accounting obligations.
- Maintain legally required business records.
- Comply with court orders.
- Respond to regulatory authorities.
- Protect intellectual property rights.
- Enforce contractual obligations.
- Resolve legal disputes.
- Exercise or defend legal claims.
________________________________________
8.10 Financial Administration
Personal information may be processed to:
- Prepare quotations.
- Generate invoices.
- Process payments.
- Maintain accounting records.
- Perform financial reconciliation.
- Prevent payment fraud.
- Comply with tax obligations.
- Manage refunds where applicable.
________________________________________
8.11 Marketing and Educational Communications
Subject to applicable law and your communication preferences, we may use personal information to:
- Send newsletters.
- Announce webinars.
- Share educational materials.
- Inform users about new services.
- Notify users of conferences and scientific events.
- Distribute company announcements.
- Share research-related updates.
Marketing communications are sent only where permitted by applicable law. Users may unsubscribe or withdraw consent at any time without affecting the lawfulness of prior processing.
________________________________________
8.12 Recruitment and Career Opportunities
Where individuals apply for employment, consultancy, internships, or collaboration opportunities, personal information may be used to:
- Review applications.
- Verify qualifications.
- Conduct interviews.
- Assess suitability.
- Perform reference checks where authorized.
- Communicate recruitment decisions.
- Maintain recruitment records.
- Comply with employment-related legal obligations.
________________________________________
8.13 Business Development
We may process limited professional contact information to:
- Respond to partnership inquiries.
- Establish professional collaborations.
- Develop institutional relationships.
- Manage vendor relationships.
- Evaluate prospective business opportunities.
- Conduct due diligence before entering contractual arrangements.
________________________________________
8.14 Business Transactions
If Onnmed undergoes a merger, acquisition, restructuring, financing, asset sale, corporate reorganization, or similar transaction, personal information may be processed as part of the evaluation or completion of that transaction, subject to appropriate confidentiality obligations and applicable legal requirements.
________________________________________
8.15 Aggregated and Anonymized Information
We may create aggregated, anonymized, or de-identified information that no longer identifies any individual.
Such information may be used for purposes including:
- Statistical analysis.
- Service improvement.
- Operational planning.
- Academic reporting.
- Performance measurement.
- Business analytics.
- Research into service effectiveness.
- Publication of non-identifiable statistical summaries.
Where information has been irreversibly anonymized so that individuals cannot reasonably be identified, it is no longer treated as personal information under this Privacy Policy.
________________________________________
8.16 Purposes Incompatible with This Policy
Onnmed does not sell personal information to third parties for monetary consideration.
We do not process personal information for purposes materially incompatible with those described in this Privacy Policy unless:
- you have provided additional consent;
- such processing is required or authorized by applicable law;
- the new purpose is compatible with the original purpose of collection; or
- another lawful basis exists under applicable data protection legislation.
________________________________________
9. Legal Bases for Processing Personal Information
Where applicable, Onnmed processes personal information only where a lawful basis exists under applicable data protection legislation. The legal basis relied upon depends on the nature of the information, the services requested, the relationship with the individual, and the applicable legal requirements.
________________________________________
9.1 Performance of a Contract
We process personal information where such processing is necessary to enter into, perform, administer, or fulfill a contract or to take steps requested before entering into a contract.
Examples include:
- Responding to quotation requests.
- Preparing service agreements.
- Delivering research and consulting services.
- Providing statistical analyses.
- Preparing scientific manuscripts.
- Managing publication support.
- Processing payments.
- Providing customer support.
- Managing project communications.
- Delivering completed work.
Without certain personal information, we may be unable to provide the requested services.
________________________________________
9.2 Compliance with Legal Obligations
We process personal information where necessary to comply with applicable legal or regulatory obligations, including obligations relating to:
- Taxation and accounting.
- Corporate governance.
- Regulatory reporting.
- Court orders.
- Law enforcement requests.
- Fraud prevention.
- Record retention requirements.
- Intellectual property protection.
- Employment legislation.
- Data protection legislation.
- Anti-money laundering or financial compliance requirements where applicable.
________________________________________
9.3 Legitimate Interests
We may process personal information where such processing is necessary for our legitimate business interests, provided that those interests are not overridden by the rights and freedoms of the individual.
Our legitimate interests may include:
- Operating and improving our services.
- Maintaining client relationships.
- Responding to inquiries.
- Protecting business assets.
- Preventing fraud.
- Maintaining cybersecurity.
- Defending legal claims.
- Conducting internal audits.
- Managing business operations.
- Developing new services.
- Maintaining service quality.
- Protecting confidential information.
- Ensuring network security.
- Maintaining business continuity.
- Performing internal reporting and analytics.
Where legitimate interests are relied upon, we assess whether the processing is necessary, proportionate, and appropriately balanced against individual privacy rights.
________________________________________
9.4 Consent
Where required by applicable law, we process personal information based upon the individual's freely given, specific, informed, and unambiguous consent.
Consent may be requested for activities such as:
- Marketing communications.
- Newsletter subscriptions.
- Optional cookies and similar technologies.
- Certain research-related activities.
- Processing certain categories of sensitive personal information where consent is the appropriate legal basis.
- Participation in surveys or promotional activities.
Individuals may withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
________________________________________
9.5 Vital Interests
In limited circumstances, we may process personal information where necessary to protect the vital interests of an individual or another natural person.
This legal basis is expected to arise only in exceptional situations involving immediate threats to health or safety where processing is legally justified.
________________________________________
9.6 Public Interest
Where permitted or required by applicable law, personal information may be processed where necessary for tasks carried out in the public interest or under official authority.
This may include certain research activities, regulatory obligations, or cooperation with governmental authorities where legally required.
________________________________________
9.7 Scientific and Research Purposes
As a provider of medical research and scientific consulting services, Onnmed may process personal information for scientific, academic, healthcare, or statistical purposes where such processing is authorized by applicable law, contractual obligations, institutional requirements, or valid instructions from the relevant Data Controller.
Whenever reasonably practicable, research data should be anonymized or pseudonymized before being provided to Onnmed.
Where Onnmed processes research data solely on behalf of a client, Onnmed acts in accordance with the client's documented instructions and applicable contractual obligations.
________________________________________
9.8 Sensitive Personal Information
Sensitive Personal Information is processed only where:
- Processing is required for the performance of agreed professional services.
- The individual has provided valid consent where required.
- Processing is necessary for scientific or medical research as permitted by applicable law.
- Processing is necessary to establish, exercise, or defend legal claims.
- Processing is required by law.
- Another lawful basis exists under applicable data protection legislation.
Onnmed applies enhanced administrative, technical, and organizational safeguards when processing Sensitive Personal Information.
________________________________________
9.9 Research Data Provided by Clients
Where clients provide research datasets containing personal information, clients represent and warrant that:
- They possess the necessary legal authority to disclose such information to Onnmed.
- Appropriate participant consent has been obtained where required.
- Applicable ethics approvals have been obtained where required.
- The disclosure complies with applicable privacy and research regulations.
- The information has been appropriately anonymized or pseudonymized where reasonably practicable.
Onnmed relies upon these representations when accepting client-provided research data.
________________________________________
9.10 Automated Decision-Making
Onnmed does not make decisions that produce legal or similarly significant effects solely through automated processing.
While certain automated technologies may be used to support website functionality, cybersecurity, analytics, spam detection, workflow management, or operational efficiency, meaningful human oversight remains integral to our professional services.
________________________________________
9.11 Data Minimization
Regardless of the legal basis relied upon, Onnmed seeks to process only the personal information reasonably necessary for the relevant purpose.
We regularly review our processing activities to ensure that unnecessary personal information is not collected, retained, or processed beyond what is required for legitimate business, contractual, legal, or research purposes.
________________________________________
9.12 Purpose Limitation
Personal information collected for one specified purpose will not be processed for a materially incompatible purpose unless:
- additional consent is obtained where required;
- another lawful basis exists under applicable law;
- the new purpose is compatible with the original purpose of collection; or
- processing is otherwise authorized or required by applicable legislation.
Where a new processing purpose is identified that materially differs from the original purpose, Onnmed will provide appropriate notice where required by law before commencing such processing.
________________________________________
10. Sharing and Disclosure of Personal Information
Onnmed recognizes the confidential nature of the personal information entrusted to us. We do not sell personal information and disclose it only where necessary to provide our services, fulfill contractual obligations, comply with applicable laws, protect our legitimate business interests, or where disclosure has been authorized by the individual or the relevant Data Controller.
________________________________________
10.1 Internal Access
Access to personal information within Onnmed is limited to personnel who require such access to perform their professional responsibilities.
Depending on the nature of the engagement, authorized personnel may include:
- Executive management
- Project managers
- Medical writers
- Biostatisticians
- Clinical research consultants
- Scientific editors
- Quality assurance personnel
- Information technology staff
- Finance and accounting personnel
- Customer support representatives
- Legal and compliance personnel
All personnel are subject to confidentiality obligations and are expected to comply with Onnmed's internal privacy, security, and information governance policies.
________________________________________
10.2 Third-Party Service Providers
Onnmed engages trusted third-party service providers that support our business operations and service delivery.
These providers may include:
- Cloud infrastructure providers
- Website hosting providers
- Email service providers
- Customer relationship management (CRM) systems
- Payment processors
- Accounting platforms
- Project management software
- Video conferencing providers
- Communication platforms
- Analytics providers
- Cybersecurity providers
- Backup and disaster recovery providers
- Identity verification providers where required
- Technical support providers
These providers are permitted to process personal information only as necessary to perform services on our behalf and are contractually obligated to maintain appropriate confidentiality and security measures.
________________________________________
10.3 Research Partners and Collaborators
Where required to perform the services requested by a client, personal information or research-related information may be shared with authorized collaborators, including:
- Universities
- Hospitals
- Research institutions
- Principal investigators
- Co-investigators
- Clinical trial sponsors
- Contract research organizations (CROs)
- Ethics Committees
- Institutional Review Boards (IRBs)
- Academic collaborators
- Scientific consultants
Such disclosures occur only where authorized by the client, required for the agreed scope of work, or otherwise permitted by applicable law.
________________________________________
10.4 Academic Journals and Publishers
Where Onnmed provides manuscript preparation, submission, or publication support services, we may disclose relevant information to academic journals, editorial offices, manuscript submission platforms, peer-review systems, indexing services, or publishing partners in accordance with the client's instructions.
Examples include:
- Author names
- Institutional affiliations
- ORCID iDs
- Contact information
- Funding disclosures
- Conflict of interest statements
- Manuscripts
- Supplementary files
- Responses to peer reviewers
Publication decisions remain solely within the authority of the respective journal or publisher.
________________________________________
10.5 Professional Advisers
We may disclose personal information to professional advisers where reasonably necessary, including:
- Legal advisers
- External auditors
- Accountants
- Tax consultants
- Insurance providers
- Regulatory consultants
- Compliance advisers
These parties are subject to professional duties of confidentiality and, where appropriate, contractual confidentiality obligations.
________________________________________
10.6 Payment Service Providers
Payments made for our services may be processed through authorized third-party payment providers.
These providers process payment information under their own privacy policies and security standards. Onnmed does not intentionally store complete payment card numbers, CVV codes, or payment authentication credentials on its own systems unless required as part of a compliant payment infrastructure.
________________________________________
10.7 Legal and Regulatory Authorities
We may disclose personal information where required or permitted by applicable law, including disclosures to:
- Courts
- Law enforcement agencies
- Government authorities
- Regulatory authorities
- Tax authorities
- Data protection authorities
- Professional licensing bodies
- Other competent public authorities
Where legally permitted, we may notify the affected individual before making such disclosure.
________________________________________
10.8 Protection of Rights, Property, and Safety
Personal information may be disclosed where reasonably necessary to:
- Protect the rights or property of Onnmed.
- Protect our employees, contractors, clients, or business partners.
- Prevent fraud or unlawful activities.
- Investigate cybersecurity incidents.
- Enforce contractual rights.
- Protect intellectual property.
- Establish, exercise, or defend legal claims.
- Prevent imminent harm where disclosure is legally justified.
________________________________________
10.9 Business Transactions
If Onnmed undergoes a merger, acquisition, corporate restructuring, financing, sale of assets, or similar business transaction, personal information may be transferred as part of that transaction.
Any successor organization receiving personal information will be expected to protect it in accordance with applicable data protection laws and this Privacy Policy or provide an equivalent level of protection.
________________________________________
10.10 International Transfers
As an international medical research and consulting organization, Onnmed may transfer or permit access to personal information across national borders where necessary to provide services.
Where required by applicable law, international transfers are protected through appropriate safeguards, including:
- Adequacy decisions issued by competent authorities.
- Standard Contractual Clauses (SCCs).
- International Data Transfer Agreements (IDTAs).
- Contractual confidentiality obligations.
- Technical and organizational safeguards.
- Other legally recognized transfer mechanisms.
________________________________________
10.11 Client Instructions
Where Onnmed acts solely as a Data Processor on behalf of a client, we process and disclose personal information only in accordance with the client's documented instructions unless otherwise required by applicable law.
________________________________________
10.12 Aggregated and Anonymized Information
We may disclose aggregated, anonymized, or de-identified information that cannot reasonably identify an individual.
Such information may be used for:
- Statistical reporting
- Service improvement
- Business analytics
- Academic publications
- Operational planning
- Research
- Industry benchmarking
Information that has been irreversibly anonymized is no longer considered personal information for the purposes of this Privacy Policy.
________________________________________
10.13 No Sale of Personal Information
Onnmed does not sell personal information to third parties for monetary consideration.
We do not disclose personal information to third parties for their independent marketing purposes unless expressly authorized by the individual or otherwise permitted by applicable law.
Where applicable privacy laws grant individuals the right to opt out of the sale or sharing of personal information, Onnmed will honor those rights in accordance with applicable legal requirements.
________________________________________
10.14 Disclosure Minimization
Whenever personal information is disclosed to another party, Onnmed seeks to disclose only the minimum amount of information reasonably necessary to achieve the intended purpose.
Where appropriate, personal information is anonymized, pseudonymized, encrypted, or otherwise protected before disclosure to reduce privacy risks and support compliance with applicable data protection laws.
________________________________________
10.15 Data Processing Agreements
Where Onnmed processes personal information on behalf of a client acting as the Data Controller, the processing relationship may be governed by a separate Data Processing Agreement ("DPA") or equivalent contractual provisions. Such agreements define the parties' respective responsibilities regarding data protection, confidentiality, security measures, international transfers, incident notification, and compliance with applicable privacy laws, including the GDPR, UK GDPR, UAE PDPL, and other relevant legislation.
__________________________
11. Data Security and Information Protection
Protecting the confidentiality, integrity, and availability of personal information is a fundamental responsibility of Onnmed. We maintain administrative, technical, organizational, and physical safeguards designed to protect personal information against unauthorized or unlawful access, disclosure, alteration, loss, destruction, or other forms of misuse.
Although no method of electronic transmission or storage can be guaranteed to be completely secure, Onnmed implements security measures appropriate to the nature, sensitivity, and volume of the information processed, taking into account current industry standards, applicable legal requirements, and the risks associated with our processing activities.
________________________________________
11.1 Administrative Safeguards
We maintain internal policies and procedures governing the collection, use, storage, disclosure, retention, and disposal of personal information.
Administrative safeguards include:
- Information security policies and procedures.
- Privacy governance policies.
- Confidentiality obligations for employees and contractors.
- Role-based access management.
- Staff training on privacy and information security.
- Vendor risk assessments where appropriate.
- Incident response procedures.
- Business continuity planning.
- Periodic review of internal security practices.
________________________________________
11.2 Technical Safeguards
Where appropriate, Onnmed employs technical measures that may include:
- Secure encrypted communications using HTTPS/TLS.
- Encryption of sensitive information during transmission where appropriate.
- Password-protected systems.
- Multi-factor authentication for supported administrative systems.
- Firewalls and network security controls.
- Endpoint protection.
- Malware detection.
- Intrusion detection and prevention mechanisms.
- Access logging and monitoring.
- Secure authentication procedures.
- Backup and disaster recovery systems.
- System updates and security patch management.
- Controlled access to cloud infrastructure.
The specific security technologies implemented may evolve over time as part of our continuous security improvement program.
________________________________________
11.3 Physical Security
Where personal information is stored or accessed within physical facilities, reasonable physical safeguards may include:
- Controlled building access.
- Restricted office access.
- Visitor management procedures.
- Secure storage of confidential documents.
- Secure disposal of paper records.
- Protection of company-issued devices.
- Environmental safeguards for critical infrastructure where applicable.
________________________________________
11.4 Access Control
Access to personal information is limited to individuals who require such access for legitimate business purposes.
Access controls are designed to ensure that:
- Users receive only the level of access necessary for their responsibilities.
- Access rights are periodically reviewed.
- Access is removed when no longer required.
- Authentication measures help prevent unauthorized access.
- Privileged access is limited and monitored where appropriate.
________________________________________
11.5 Confidentiality
Employees, contractors, consultants, interns, and other authorized personnel with access to personal information are expected to maintain the confidentiality of such information both during and after their relationship with Onnmed.
Where appropriate, confidentiality obligations are supported by contractual agreements.
________________________________________
11.6 Research Data Protection
Because Onnmed provides scientific and medical research services, additional safeguards may be applied when processing research-related information.
Where reasonably practicable, we encourage clients to provide:
- Anonymized datasets.
- Pseudonymized datasets.
- De-identified patient information.
Where identifiable research information must be processed, access is limited to authorized personnel involved in the relevant engagement.
________________________________________
11.7 Vendor Security
Before engaging third-party service providers that may process personal information on our behalf, Onnmed may evaluate whether the provider maintains security measures appropriate to the nature of the services provided.
Where appropriate, contractual provisions require service providers to:
- Protect confidential information.
- Implement reasonable security measures.
- Process personal information only for authorized purposes.
- Notify us of certain security incidents where required.
- Comply with applicable data protection obligations.
________________________________________
11.8 Security Monitoring
We may monitor our systems and networks to:
- Detect unauthorized access.
- Identify suspicious activity.
- Prevent fraud.
- Protect against cyber threats.
- Maintain service availability.
- Investigate security incidents.
- Improve our overall security posture.
Such monitoring is conducted in accordance with applicable law.
________________________________________
11.9 Data Breach Response
Onnmed maintains procedures for responding to actual or suspected security incidents involving personal information.
Where a personal data breach is identified, we may:
- Investigate the incident.
- Contain the breach.
- Assess potential risks.
- Mitigate adverse effects.
- Restore affected systems.
- Document the incident.
- Notify affected clients where appropriate.
- Notify competent regulatory authorities where required by applicable law.
- Notify affected individuals where legally required.
The timing and manner of notifications will depend on the applicable legal requirements and the nature of the incident.
________________________________________
11.10 User Responsibilities
Users also play an important role in protecting their personal information.
Individuals using our Website or services are encouraged to:
- Protect their account credentials.
- Use strong passwords.
- Avoid sharing login information.
- Notify Onnmed promptly of suspected unauthorized access.
- Use secure internet connections when accessing sensitive information.
- Exercise caution when transmitting confidential information electronically.
________________________________________
11.11 Continuous Improvement
Information security is an ongoing process.
Onnmed periodically reviews and updates its administrative, technical, organizational, and physical safeguards to address evolving technologies, emerging cybersecurity threats, changes in applicable legal requirements, and improvements in industry best practices.
We reserve the right to modify our security measures as necessary to maintain an appropriate level of protection for the personal information entrusted to us.
________________________________________
12. Data Retention
Onnmed retains personal information only for as long as necessary to fulfill the purposes for which it was collected, to comply with applicable legal, regulatory, contractual, and professional obligations, to resolve disputes, enforce our agreements, and protect our legitimate business interests.
Retention periods vary depending on the nature of the information, the services provided, applicable legal requirements, contractual commitments, and operational needs.
________________________________________
12.1 General Retention Principles
When determining the appropriate retention period, we consider factors including:
- The purpose for which the information was collected.
- The nature and sensitivity of the information.
- The duration of the client relationship.
- Applicable legal and regulatory requirements.
- Contractual obligations.
- Professional standards and industry best practices.
- Potential legal claims or dispute resolution requirements.
- Information security considerations.
- Business continuity requirements.
Personal information is not retained longer than reasonably necessary unless continued retention is required or permitted by applicable law.
________________________________________
12.2 Categories of Retention
Depending on the nature of the engagement, Onnmed may retain information relating to:
- Client correspondence.
- Quotations and proposals.
- Service agreements.
- Financial records.
- Project documentation.
- Research documentation.
- Statistical analyses.
- Manuscripts.
- Publication records.
- Customer support communications.
- Technical logs.
- Security logs.
- Recruitment records.
- Marketing preferences.
- Website analytics.
Each category may be subject to a different retention period based on its purpose and applicable legal obligations.
________________________________________
12.3 Research Data
Research-related information may be retained for periods required by:
- Client agreements.
- Institutional policies.
- Funding agency requirements.
- Research ethics approvals.
- Journal publication requirements.
- Regulatory obligations.
- Scientific recordkeeping standards.
Where Onnmed acts solely as a Data Processor, research data is retained in accordance with the client's documented instructions and applicable contractual obligations.
________________________________________
12.4 Financial and Accounting Records
Invoices, payment records, accounting documents, and related financial information may be retained for the period required by applicable tax, accounting, audit, and corporate recordkeeping laws.
________________________________________
12.5 Communications
Business correspondence, customer support records, and project-related communications may be retained as reasonably necessary to:
- Maintain accurate business records.
- Provide ongoing client support.
- Resolve disputes.
- Verify prior instructions.
- Comply with legal obligations.
- Improve service quality.
________________________________________
12.6 Website and Technical Information
Technical logs, security records, cookies, and analytics information are retained only for as long as reasonably necessary to:
- Maintain Website functionality.
- Protect Website security.
- Diagnose technical issues.
- Improve Website performance.
- Comply with applicable legal obligations.
Specific retention periods for cookies are described in our Cookie Policy.
________________________________________
12.7 Recruitment Information
Information relating to employment or consultancy applications may be retained for a reasonable period following the completion of the recruitment process unless:
- The applicant requests deletion where permitted by law.
- Continued retention is required by applicable employment legislation.
- The applicant consents to future recruitment consideration.
________________________________________
12.8 Secure Deletion and Disposal
When personal information is no longer required, Onnmed takes reasonable steps to securely dispose of or delete the information.
Depending on the circumstances, this may include:
- Secure electronic deletion.
- Permanent removal from active systems where feasible.
- Secure destruction of physical documents.
- De-identification.
- Anonymization.
- Controlled archival destruction.
Deletion methods are selected based on the nature of the information and applicable security standards.
________________________________________
12.9 Legal Holds
Notwithstanding any retention period described in this Privacy Policy, Onnmed may retain personal information for longer periods where necessary to:
- Comply with legal obligations.
- Respond to litigation.
- Preserve evidence.
- Conduct investigations.
- Enforce contractual rights.
- Protect legal interests.
- Comply with court orders or regulatory requirements.
Information subject to a legal hold will be retained until the relevant legal or regulatory matter has been resolved.
________________________________________
12.10 Anonymization
Where appropriate, personal information may be irreversibly anonymized rather than deleted.
Information that has been permanently anonymized so that individuals can no longer be identified is no longer considered personal information and may be retained for purposes including:
- Statistical analysis.
- Scientific research.
- Service improvement.
- Operational planning.
- Quality assurance.
- Business reporting.
________________________________________
12.11 Periodic Review
Onnmed periodically reviews retained information to determine whether continued retention remains necessary.
Where information is no longer required for the purposes for which it was collected and no legal or contractual obligation requires continued retention, it will be securely deleted, anonymized, or otherwise disposed of in accordance with our internal information governance procedures.
________________________________________
13. Your Privacy Rights
Onnmed respects the privacy rights of individuals and is committed to facilitating the exercise of those rights in accordance with applicable data protection laws. The rights available to you may vary depending on your country of residence, the nature of our relationship with you, and the legal basis upon which your personal information is processed.
Where permitted by law, we may request information necessary to verify your identity before responding to a privacy-related request.
________________________________________
13.1 Right to Access
You may have the right to request confirmation as to whether Onnmed processes your personal information and, where applicable, to obtain access to that information.
Subject to applicable legal limitations, you may also request information regarding:
- The categories of personal information processed.
- The purposes of processing.
- The sources from which the information was obtained.
- The categories of recipients to whom information has been disclosed.
- The anticipated retention period.
- The legal basis for processing.
- Applicable safeguards for international transfers.
________________________________________
13.2 Right to Correction
You may request that inaccurate, incomplete, or outdated personal information be corrected or updated.
Onnmed will take reasonable steps to ensure that personal information remains accurate and current based on the information available to us.
________________________________________
13.3 Right to Erasure
Subject to applicable legal and contractual obligations, you may request that we delete your personal information where:
- The information is no longer necessary for the purposes for which it was collected.
- You withdraw consent where consent is the legal basis for processing.
- Processing is unlawful.
- Deletion is required by applicable law.
- You successfully object to processing where no overriding lawful grounds exist.
This right is not absolute and may be limited where retention is required by law, contractual obligations, scientific research requirements, legal claims, or other legitimate grounds.
________________________________________
13.4 Right to Restrict Processing
Where permitted by applicable law, you may request that we temporarily restrict the processing of your personal information under certain circumstances, including where:
- The accuracy of the information is contested.
- The processing is alleged to be unlawful.
- The information is required for legal claims.
- An objection to processing is under review.
During periods of restriction, personal information may continue to be stored but will otherwise be processed only where legally permitted.
________________________________________
13.5 Right to Object
Where processing is based on legitimate interests or another applicable legal basis that permits objection, you may object to the processing of your personal information.
If you object, Onnmed will evaluate the request in accordance with applicable law and determine whether compelling legitimate grounds exist to continue the processing.
You may also object to the use of your personal information for direct marketing purposes at any time.
________________________________________
13.6 Right to Data Portability
Where applicable, you may request a copy of certain personal information you have provided to us in a structured, commonly used, and machine-readable format.
Where technically feasible and legally permissible, you may also request that such information be transmitted directly to another organization.
This right applies only where required under applicable law and where the processing is carried out by automated means based on consent or the performance of a contract.
________________________________________
13.7 Right to Withdraw Consent
Where processing is based on your consent, you may withdraw that consent at any time.
Withdrawal of consent does not affect:
- The lawfulness of processing carried out before the withdrawal.
- Processing conducted under another applicable legal basis.
- Information retained to comply with legal obligations.
Withdrawal of consent may affect our ability to provide certain services.
________________________________________
13.8 Right to Opt Out of Marketing Communications
You may opt out of receiving promotional or marketing communications from Onnmed at any time by:
- Clicking the unsubscribe link included in marketing emails.
- Updating your communication preferences where available.
- Contacting us using the details provided in this Privacy Policy.
Even after opting out of marketing communications, we may continue to send service-related communications that are necessary to administer our relationship with you.
________________________________________
13.9 Rights Relating to Automated Decision-Making
Onnmed does not make decisions that produce legal or similarly significant effects solely through automated processing.
If this practice changes in the future, affected individuals will be provided with the rights required under applicable law, including, where applicable, the right to request human review.
________________________________________
13.10 California Privacy Rights
Where the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), applies, eligible California residents may have additional rights, including:
- The right to know the categories and specific pieces of personal information collected.
- The right to know the categories of sources from which personal information is collected.
- The right to know the purposes for which personal information is used.
- The right to request deletion of personal information, subject to applicable exceptions.
- The right to request correction of inaccurate personal information.
- The right to limit the use or disclosure of sensitive personal information where applicable.
- The right to opt out of the sale or sharing of personal information where applicable.
- The right not to be subjected to unlawful discrimination for exercising privacy rights.
Onnmed does not sell personal information for monetary consideration.
________________________________________
13.11 Rights Under the UAE Personal Data Protection Law
Where the UAE Personal Data Protection Law (PDPL) applies, individuals may have rights including, where applicable:
- The right to obtain information regarding the processing of personal data.
- The right to request correction of inaccurate personal data.
- The right to request deletion of personal data where legally applicable.
- The right to restrict or suspend processing under certain circumstances.
- The right to object to certain processing activities.
- The right to request the transfer of personal data where applicable.
- The right to withdraw consent where consent forms the legal basis for processing.
These rights are exercised subject to the provisions and limitations established by the applicable legislation.
________________________________________
13.12 Exercising Your Rights
Requests concerning personal information may be submitted using the contact information provided in this Privacy Policy.
To protect personal information from unauthorized disclosure, Onnmed may request reasonable evidence to verify the identity of the requesting individual before processing a request.
We may decline or limit a request where:
- Applicable law permits or requires us to do so.
- We are unable to verify the requester's identity.
- The request is manifestly unfounded or excessive.
- Compliance would adversely affect the rights of others.
- Retention is required for legal, contractual, regulatory, accounting, scientific, or security purposes.
Where a request cannot be fully granted, we will provide an explanation to the extent permitted by applicable law.
________________________________________
13.13 Response Time
Onnmed will respond to verified privacy requests within the timeframes required by applicable law.
Where permitted by law, response periods may be extended if the request is particularly complex or if multiple requests have been submitted. Where an extension is required, the requester will be informed accordingly.
________________________________________
13.14 Complaints
If you believe that your personal information has been processed in a manner inconsistent with applicable data protection laws, you may contact Onnmed using the contact details provided in this Privacy Policy.
Where applicable, you may also have the right to lodge a complaint with the competent data protection authority in your jurisdiction.
We encourage individuals to contact Onnmed first so that we may have the opportunity to address concerns promptly and in good faith.
________________________________________
14. Cookies and Tracking Technologies
Onnmed uses cookies and similar technologies to enhance the functionality, security, performance, and usability of our Website. These technologies help us understand how visitors interact with our Website, improve user experience, protect our online services, and support certain business operations.
Where required by applicable law, non-essential cookies are placed on your device only after obtaining your consent through our cookie consent mechanism.
________________________________________
14.1 What Are Cookies?
Cookies are small text files that are stored on your computer, smartphone, tablet, or other device when you visit a website.
Cookies enable websites to recognize your device, remember your preferences, maintain secure sessions, and improve website functionality.
In addition to cookies, we may use similar technologies such as:
- Web beacons
- Pixels
- Local storage
- Session storage
- Log files
- Software development kits (SDKs), where applicable
- Other comparable tracking technologies
For simplicity, these technologies are collectively referred to as "cookies" throughout this Privacy Policy.
________________________________________
14.2 Types of Cookies We Use
Essential Cookies
Essential cookies are necessary for the operation of our Website and cannot be disabled through our cookie preference tools.
These cookies support functions such as:
- Website security
- Session management
- User authentication
- Load balancing
- Network management
- Fraud prevention
- Accessibility features
Without these cookies, certain portions of the Website may not function properly.
________________________________________
Functional Cookies
Functional cookies enable the Website to remember user preferences and improve the browsing experience.
Examples include:
- Language preferences
- Region selection
- Display settings
- Accessibility preferences
- Previously selected options
________________________________________
Performance and Analytics Cookies
Performance and analytics cookies help us understand how visitors interact with our Website.
These cookies may collect information such as:
- Pages visited
- Time spent on pages
- Navigation paths
- Device information
- Browser information
- Approximate geographic location
- Website performance metrics
- Error reports
Analytics information is generally used in aggregated form to improve Website functionality and user experience.
________________________________________
Security Cookies
Security-related cookies help us:
- Detect suspicious activity.
- Prevent unauthorized access.
- Protect user sessions.
- Identify fraudulent behavior.
- Maintain Website integrity.
________________________________________
Marketing Cookies
Where applicable, marketing cookies may be used to:
- Measure the effectiveness of marketing campaigns.
- Understand user engagement with promotional content.
- Improve communication with users who have consented to receive marketing information.
Onnmed does not use marketing cookies for cross-context behavioral advertising without obtaining consent where required by law.
________________________________________
14.3 Third-Party Cookies
Certain third-party service providers may place cookies on our Website when their services are integrated into our Website.
Depending on the services used, these providers may include:
- Website analytics providers
- Cloud service providers
- Content delivery networks
- Video conferencing or embedded media providers
- Payment service providers
- Security monitoring providers
Each third party is responsible for its own privacy practices and the processing of information collected through its technologies.
________________________________________
14.4 Google Analytics and Similar Services
Onnmed may use analytics services, including Google Analytics or comparable tools, to better understand Website usage and improve our online services.
These services may collect information such as:
- IP address (which may be shortened or anonymized where supported)
- Browser type
- Device type
- Operating system
- Website interactions
- Session duration
- Referral sources
- General geographic location
Analytics providers process information in accordance with their own privacy policies.
Where required by applicable law, analytics cookies are activated only after obtaining the necessary consent.
________________________________________
14.5 Cookie Consent
Where required by applicable law, visitors will be presented with a cookie consent banner upon their first visit to the Website.
Users may be able to:
- Accept all cookies.
- Reject non-essential cookies.
- Customize cookie preferences.
- Change cookie preferences at a later time.
Consent records may be maintained where required to demonstrate compliance with applicable legal obligations.
________________________________________
14.6 Managing Cookies
Most web browsers allow users to:
- View stored cookies.
- Delete existing cookies.
- Block future cookies.
- Restrict certain categories of cookies.
- Receive notifications before cookies are stored.
Disabling certain cookies may affect the functionality, security, or availability of portions of the Website.
Browser settings differ depending on the browser software being used.
________________________________________
14.7 Do Not Track Signals
Some web browsers offer a "Do Not Track" (DNT) setting.
Because there is currently no universally accepted standard governing DNT signals, our Website may not respond consistently to such browser settings.
If industry standards or applicable legal requirements change, Onnmed may update its practices accordingly.
________________________________________
14.8 Retention of Cookie Information
Cookie retention periods vary depending on the type and purpose of the cookie.
Some cookies are automatically deleted when your browser session ends, while others remain on your device for a defined period or until manually deleted.
Retention periods are periodically reviewed to ensure they remain appropriate for the purposes for which the cookies are used.
________________________________________
14.9 Updates to Cookie Technologies
Onnmed may introduce new cookies or similar technologies as our Website, services, or business operations evolve.
Where required by applicable law, we will obtain consent before implementing new categories of non-essential cookies.
Material changes to our use of cookies may also be reflected in updates to this Privacy Policy and our separate Cookie Policy.
________________________________________
15. International Data Transfers
Onnmed operates internationally and provides services to individuals, healthcare professionals, universities, hospitals, research institutions, pharmaceutical companies, governmental organizations, and commercial entities located in multiple jurisdictions. As a result, personal information may be transferred to, stored in, or accessed from countries other than the country in which it was originally collected.
We are committed to ensuring that international transfers of personal information are conducted in accordance with applicable data protection laws and are subject to appropriate safeguards designed to maintain an equivalent level of protection.
________________________________________
15.1 Circumstances of International Transfers
Personal information may be transferred internationally where necessary to:
- Provide requested services.
- Perform contractual obligations.
- Facilitate scientific or academic collaborations.
- Support multinational research projects.
- Enable secure cloud hosting and infrastructure services.
- Process payments through international payment providers.
- Deliver customer support.
- Maintain business continuity and disaster recovery systems.
- Comply with legal or regulatory obligations.
- Protect the rights, safety, and security of Onnmed or its clients.
________________________________________
15.2 Appropriate Safeguards
Where required by applicable law, Onnmed implements appropriate safeguards before transferring personal information across international borders.
Depending on the circumstances, these safeguards may include:
- Adequacy decisions issued by competent authorities.
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- International Data Transfer Agreements (IDTAs) or other legally recognized transfer mechanisms.
- Contractual confidentiality obligations.
- Data Processing Agreements (DPAs).
- Technical and organizational security measures.
- Encryption during transmission and storage where appropriate.
- Access controls and authentication measures.
- Other safeguards recognized under applicable data protection laws.
The safeguards implemented will depend on the destination country, the nature of the information, and the legal requirements applicable to the transfer.
________________________________________
15.3 Transfers from the European Economic Area and the United Kingdom
Where personal information originating from the European Economic Area (EEA) or the United Kingdom is transferred to a country that has not been recognized as providing an adequate level of data protection, Onnmed will implement an appropriate transfer mechanism as required under applicable law.
Such mechanisms may include:
- Standard Contractual Clauses (SCCs).
- International Data Transfer Agreements (IDTAs).
- Binding contractual obligations.
- Additional technical, contractual, and organizational safeguards where appropriate.
________________________________________
15.4 Transfers from the United Arab Emirates
Where personal information is transferred outside the United Arab Emirates, Onnmed seeks to ensure that such transfers comply with the applicable requirements of the UAE Personal Data Protection Law (PDPL) and any implementing regulations, including the use of legally recognized transfer mechanisms where required.
________________________________________
15.5 Cloud Service Providers
Onnmed may utilize reputable cloud service providers to support the secure delivery of its services.
Depending on operational requirements, personal information may be stored or processed in secure data centers located in one or more jurisdictions.
Cloud service providers engaged by Onnmed are expected to maintain security measures appropriate to the nature of the information they process and are contractually required to protect personal information in accordance with applicable legal requirements.
________________________________________
15.6 Research Collaborations
International scientific research often requires collaboration between institutions located in different countries.
Where research-related personal information is transferred internationally as part of a client's engagement, Onnmed seeks to ensure that:
- Appropriate contractual arrangements are in place where required.
- Transfers occur only for legitimate research purposes.
- Confidentiality obligations are maintained.
- Access is restricted to authorized personnel.
- Applicable ethical and regulatory requirements are respected.
Where Onnmed acts solely as a Data Processor, international transfers are performed in accordance with the client's documented instructions unless otherwise required by law.
________________________________________
15.7 Data Security During International Transfers
When personal information is transferred internationally, Onnmed seeks to protect such information through appropriate security measures, which may include:
- Secure encrypted transmission protocols.
- Authentication controls.
- Access restrictions.
- Role-based permissions.
- Confidentiality agreements.
- Continuous monitoring where appropriate.
- Secure cloud infrastructure.
- Information security policies.
- Incident response procedures.
The safeguards applied depend on the nature and sensitivity of the information being transferred.
________________________________________
15.8 Requests for Information Regarding International Transfers
Where required by applicable law, individuals may request additional information regarding the safeguards used for international transfers of their personal information.
Requests may be submitted using the contact information provided in this Privacy Policy.
Certain information may be withheld where disclosure would adversely affect security, confidentiality obligations, intellectual property rights, or the rights and freedoms of other individuals.
________________________________________
15.9 Future Changes
As Onnmed expands its international operations, the countries in which personal information is processed or stored may change.
Where material changes affect the manner in which international transfers are conducted, this Privacy Policy will be updated accordingly, and additional safeguards will be implemented where required by applicable law.
________________________________________
16. Children's Privacy
Onnmed's Website and professional services are intended for use by adults, including healthcare professionals, researchers, universities, hospitals, academic institutions, governmental organizations, commercial entities, and other professional users.
Our Website and services are not directed to children, and we do not knowingly collect personal information directly from children through our Website.
________________________________________
16.1 No Intentional Collection from Children
Onnmed does not knowingly solicit, collect, or process personal information directly from individuals who have not reached the minimum age required under applicable law to provide valid consent for the processing of their personal information.
Where age thresholds differ between jurisdictions, the applicable legal age in the relevant jurisdiction shall apply.
________________________________________
16.2 Information Submitted by Third Parties
Certain research, scientific, or healthcare-related projects may involve information relating to minors or pediatric populations.
In such circumstances:
- Onnmed does not collect such information directly from children through its Website.
- Any information relating to minors is provided by authorized clients acting as Data Controllers or other legally authorized entities.
- Clients remain responsible for ensuring that all required parental consent, legal authority, ethics approvals, and regulatory approvals have been obtained before disclosing such information to Onnmed.
- Onnmed processes such information only in accordance with applicable law, contractual obligations, and the documented instructions of the relevant Data Controller.
________________________________________
16.3 Accidental Collection
If Onnmed becomes aware that personal information has been collected directly from a child in a manner inconsistent with applicable law or this Privacy Policy, we will take reasonable steps to:
- Verify the circumstances.
- Remove the information where appropriate.
- Restrict further processing where required.
- Comply with applicable legal obligations.
- Notify the appropriate parties where legally required.
________________________________________
16.4 Parental or Guardian Requests
Parents or legal guardians who believe that a child has provided personal information directly to Onnmed through our Website may contact us using the contact details provided in this Privacy Policy.
Upon receiving a verified request, we will review the matter and, where appropriate and legally required, take reasonable steps to correct, restrict, or delete the relevant personal information.
________________________________________
16.5 Educational and Research Activities
Nothing in this section is intended to restrict the lawful processing of research-related information involving pediatric participants where such processing is:
- Authorized by the relevant Data Controller.
- Approved by the appropriate ethics committee or Institutional Review Board (IRB), where applicable.
- Conducted in accordance with applicable laws and regulations.
- Supported by the required parental consent or other lawful authorization where applicable.
Onnmed processes such information solely for the professional services requested by its clients and in accordance with applicable contractual, ethical, and legal requirements.
________________________________________
16.6 International Compliance
Onnmed seeks to comply with applicable laws governing children's privacy, including, where relevant:
- The United States Children's Online Privacy Protection Act (COPPA).
- The European Union General Data Protection Regulation (GDPR).
- The United Kingdom General Data Protection Regulation (UK GDPR).
- The UAE Personal Data Protection Law (PDPL).
- Other applicable privacy legislation governing minors' personal information.
Where different jurisdictions impose different standards regarding the processing of children's personal information, Onnmed will apply the requirements that are applicable to the particular processing activity.
________________________________________
17. Third-Party Websites and External Services
The Onnmed Website may contain links to third-party websites, platforms, applications, software, or services that are owned or operated by organizations independent of Onnmed.
These links are provided solely for the convenience of our users or to facilitate the delivery of our professional services. The inclusion of a link does not constitute an endorsement, approval, or recommendation of any third-party website, product, service, or organization unless expressly stated.
________________________________________
17.1 External Websites
Our Website may contain links to external resources, including but not limited to:
- Academic journals
- Scientific publishers
- Universities
- Hospitals
- Government agencies
- Professional organizations
- Regulatory authorities
- Research databases
- Clinical trial registries
- Professional networking platforms
- Payment service providers
- Cloud-based collaboration platforms
- Educational resources
When you leave the Onnmed Website, your interactions are governed by the privacy policies, terms of use, and practices of the respective third-party website.
________________________________________
17.2 Independent Privacy Practices
Onnmed does not control the content, privacy practices, security measures, or data processing activities of third-party websites or services.
Accordingly, we are not responsible for:
- The collection of personal information by third parties.
- Their privacy policies.
- Their security practices.
- Their use or disclosure of personal information.
- The accuracy or availability of external content.
- Changes made to external websites after links are published.
Users are encouraged to review the privacy policies and terms of use of any third-party website before submitting personal information.
________________________________________
17.3 Third-Party Service Integrations
To support the operation of our Website and the delivery of our services, Onnmed may integrate with third-party services, including those relating to:
- Payment processing
- Website analytics
- Customer relationship management
- Email communications
- Cloud hosting
- Video conferencing
- Document management
- Appointment scheduling
- Security monitoring
- Content delivery
These providers process personal information in accordance with their own privacy notices and any applicable contractual obligations with Onnmed.
________________________________________
17.4 Embedded Content
Certain pages of our Website may contain embedded content or services provided by third parties, including videos, maps, forms, publications, presentations, or other interactive features.
Embedded content may function as though you have visited the third-party website directly and may allow that provider to collect information about your interaction with the content, subject to its own privacy practices.
________________________________________
17.5 Social Media Platforms
Onnmed may maintain official profiles on social media and professional networking platforms.
If you choose to interact with us through these platforms, including by following our accounts, sending messages, commenting on content, or engaging with our publications, your interactions are also subject to the privacy policies and terms of the respective platform.
Information you voluntarily make publicly available through social media may be visible to other users in accordance with your account settings on those platforms.
________________________________________
17.6 Third-Party Authentication
Where available, users may choose to access certain services using third-party authentication providers.
By selecting such authentication methods, you authorize the relevant provider to share certain account information with Onnmed as permitted by your settings and the provider's applicable terms and privacy policy.
The specific information shared depends upon the permissions granted by you and the functionality offered by the authentication provider.
________________________________________
17.7 No Responsibility for Third-Party Policies
Onnmed cannot guarantee that third-party organizations will maintain privacy practices equivalent to those described in this Privacy Policy.
Users access third-party websites and services at their own discretion and are encouraged to review the applicable legal documentation before providing personal information.
________________________________________
17.8 Future Third-Party Integrations
As our services evolve, Onnmed may introduce additional third-party platforms or service providers to enhance functionality, security, or service delivery.
Where such integrations materially affect the processing of personal information, this Privacy Policy will be updated as appropriate, and any additional notices or consents required by applicable law will be provided.
________________________________________
18. Changes to This Privacy Policy
Onnmed may update this Privacy Policy from time to time to reflect changes in our business operations, services, technologies, legal obligations, regulatory requirements, industry standards, or privacy practices.
We encourage users to review this Privacy Policy periodically to remain informed about how we collect, use, disclose, protect, and otherwise process personal information.
________________________________________
18.1 Reasons for Updates
This Privacy Policy may be revised for reasons including, but not limited to:
- Changes in applicable laws or regulations.
- New regulatory guidance.
- Introduction of new products or services.
- Expansion into additional jurisdictions.
- Changes in business operations.
- Adoption of new technologies.
- Improvements to our information security practices.
- Changes in third-party service providers.
- Updates to our data processing activities.
- Clarification of existing privacy practices.
________________________________________
18.2 Effective Date
The effective date of this Privacy Policy appears at the beginning of the document.
Unless otherwise stated, any amendments become effective on the date specified in the updated version.
________________________________________
18.3 Notification of Material Changes
Where required by applicable law or where changes materially affect the way personal information is processed, Onnmed may provide notice through one or more of the following methods:
- Publication of the updated Privacy Policy on our Website.
- Website notifications or banners.
- Email notifications to registered users or clients.
- Client account notifications, where applicable.
- Other communication methods reasonably designed to bring the changes to users' attention.
The method of notification may vary depending on the significance of the changes and applicable legal requirements.
________________________________________
18.4 Continued Use
Subject to applicable law, your continued access to or use of the Website or our services after the effective date of an updated Privacy Policy constitutes acknowledgment of the revised Privacy Policy.
Where applicable laws require renewed consent for certain processing activities, Onnmed will obtain such consent before continuing those activities.
________________________________________
18.5 Previous Versions
Onnmed may retain previous versions of this Privacy Policy for legal, regulatory, operational, or recordkeeping purposes.
Where appropriate, earlier versions may be made available upon reasonable request, subject to applicable legal restrictions and operational considerations.
________________________________________
18.6 Conflict with Applicable Law
If any provision of this Privacy Policy is determined to be inconsistent with applicable law, the relevant legal requirements shall prevail to the extent of the inconsistency.
The remaining provisions of this Privacy Policy shall continue in full force and effect to the fullest extent permitted by law.
________________________________________
18.7 Ongoing Commitment
Privacy and data protection are ongoing responsibilities. Onnmed regularly reviews its privacy governance framework, internal policies, security measures, and processing activities to ensure they remain appropriate, effective, and aligned with evolving legal requirements and recognized industry best practices.
________________________________________
19. Contact Information and Privacy Requests
Onnmed welcomes questions, comments, and requests relating to this Privacy Policy and the processing of personal information. We are committed to addressing privacy concerns in a timely, transparent, and professional manner.
If you wish to exercise your privacy rights, request additional information regarding our processing activities, or submit a complaint relating to the handling of your personal information, you may contact us using the details below.
________________________________________
19.1 Contact Details
Onnmed
Website: https://www.onnmed.com
Email: [email protected] (or your preferred privacy contact email)
General Contact Email: [email protected] (or your preferred contact email)
Registered Office: Sharjah Media City, Sharjah, United Arab Emirates
Telephone: +971 4 879 0768
________________________________________
19.2 Privacy Requests
Individuals may submit requests concerning their personal information, including requests to:
- Access personal information.
- Correct inaccurate or incomplete information.
- Request deletion of personal information where applicable.
- Restrict or object to certain processing activities.
- Withdraw consent where consent is the legal basis for processing.
- Request data portability where applicable.
- Obtain information regarding international data transfers.
- Submit privacy-related questions or complaints.
Requests should include sufficient information to enable Onnmed to verify the identity of the requester and understand the nature of the request.
Where additional information is reasonably required to verify identity or clarify a request, Onnmed may request further documentation before processing the request.
________________________________________
19.3 Response Time
Onnmed will acknowledge and respond to verified privacy requests within the timeframes required by applicable data protection laws.
Where permitted by law, response periods may be extended if:
- the request is particularly complex;
- multiple requests have been submitted simultaneously;
- additional verification is required; or
- exceptional circumstances reasonably justify an extension.
Where an extension is necessary, the requester will be informed where required by applicable law.
________________________________________
19.4 Complaints
If you believe that your personal information has been processed in a manner inconsistent with this Privacy Policy or applicable data protection laws, we encourage you to contact Onnmed first so that we may investigate and, where appropriate, resolve your concerns.
Where applicable, individuals may also have the right to submit a complaint to the competent supervisory authority or data protection regulator in their jurisdiction.
________________________________________
19.5 Authorized Representatives
Where permitted by applicable law, authorized representatives may submit requests on behalf of another individual.
Onnmed may require reasonable documentation demonstrating the representative's authority before responding to such requests.
________________________________________
19.6 Verification of Identity
To protect personal information from unauthorized disclosure, Onnmed may request reasonable evidence of identity before fulfilling any privacy request.
Failure to provide sufficient verification may prevent us from processing the request where identity verification is necessary to protect the rights and privacy of individuals.
________________________________________
19.7 Language of Communications
Privacy requests and related correspondence may be submitted in English or any other language accepted by Onnmed.
Where translation is required, reasonable additional time may be necessary to process the request accurately.
________________________________________
19.8 Good Faith Commitment
Onnmed is committed to maintaining the trust of its clients, partners, researchers, healthcare professionals, institutions, and Website users by handling personal information responsibly and in accordance with applicable data protection laws.
We continually review and enhance our privacy practices, information governance framework, and security measures to support the responsible processing of personal information and to promote transparency, accountability, and regulatory compliance across all aspects of our operations.
________________________________________
20. Governing Law and Jurisdiction
This Privacy Policy shall be governed by and construed in accordance with the laws of the United Arab Emirates.
Nothing in this Privacy Policy is intended to limit or exclude any mandatory rights or protections afforded to individuals under applicable data protection laws, including but not limited to the European Union General Data Protection Regulation (GDPR), the United Kingdom General Data Protection Regulation (UK GDPR), the United Arab Emirates Personal Data Protection Law (PDPL), the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), or other applicable privacy legislation.
Any dispute arising out of or relating to this Privacy Policy that cannot be resolved through good-faith discussions shall, unless otherwise required by mandatory applicable law or agreed in writing between the parties, be subject to the exclusive jurisdiction of the competent courts of the United Arab Emirates.
Nothing in this section shall prevent an individual from exercising any rights or remedies available under mandatory data protection laws applicable to the processing of their personal information.