ARION PRIVACY POLICY
Last Updated: January 15, 2025
Version: v1.0
1. Introduction
Arion ("we", "our") is committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and applicable Spanish regulations.
This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our eCRD platform service.
2. Data Controller Identity
[PENDING: Complete with real entity data]
- Legal name: [ARION'S LEGAL NAME]
- Registered address: [FULL ADDRESS]
- Tax ID: [●]
- Contact email: [PRIVACY EMAIL]
- Data Protection Officer (if applicable): [DPO DATA]
3. Personal Data We Collect
3.1 Authentication and Profile Data
When you register on Arion via Google Identity Service, we collect:
- Email (provided by Google)
- Full name
- Profile picture (optional)
- Unique Google identifier (Google Sub)
3.2 Usage and Activity Data
During service use, we collect:
- Audit logs (actions performed, date/time)
- Organization and role information
- Access data (IP address hash, user agent hash)
- Language and configuration preferences
3.3 Clinical Data (Delegated Processing)
Clinical data you introduce into the platform is processed by Arion as Data Processor. Your organization is the Data Controller of this data.
4. Legal Basis for Processing
We process your personal data based on:
| Purpose | Legal Basis |
|---|---|
| Provide service access | Contract execution (Terms of Service) |
| Manage your account and authentication | Contract execution |
| Ensure security and prevent fraud | Legitimate interest |
| Comply with legal obligations | Legal obligation |
| Audit and traceability | Legitimate interest and legal obligation |
| Clinical data introduced by your organization | Controller's instructions (DPA) |
5. Processing Purposes
5.1 Service Provision
We use your data to:
- Allow platform access and authentication
- Manage your user and organization account
- Provide clinical study functionalities
- Facilitate collaboration with other members
5.2 Security and Audit
We log activities to:
- Guarantee data integrity
- Detect and prevent unauthorized access
- Comply with regulatory requirements (GDPR, good clinical practice)
- Resolve technical incidents
5.3 Communications
We send you communications related to:
- Important service notifications
- Legal terms updates
- Security notices
- (Optional) Product updates, if you have consented to receive them
5.4 Service Improvement
We analyze aggregated and anonymized data to:
- Improve platform functionalities
- Optimize performance
- Develop new features
6. Data Recipients
Your personal data may be communicated to:
6.1 Organization Members
Your organization's administrators can view:
- Your name, email, and role
- Your activity within shared studies
- Audit logs related to your account
6.2 Service Providers (Processors)
We share data with trusted providers who help us operate the service:
- Google Cloud Platform / AWS / Azure: Infrastructure and storage
- Google Identity Service: Authentication
- AI Providers (if applicable): For data extraction functionalities (only if you enable it)
All providers are subject to contractual data protection obligations equivalent to this document.
6.3 Authorities and Legal Compliance
We may disclose personal data when legally required by:
- Judicial or administrative authorities
- Regulatory bodies (AEPD, etc.)
- State security forces and bodies
7. International Transfers
Currently, data is stored on servers located in the European Union.
In case international data transfers are made outside the EEA, we guarantee:
- Use of standard contractual clauses approved by the European Commission
- Assessment of adequacy of the level of protection
- Transparency regarding transfers made
8. Data Retention
We retain your personal data for:
| Data Type | Retention Period |
|---|---|
| Active account data | While you maintain your account |
| Audit data | 5 years from last activity (legal obligation) |
| Data after cancellation | 30 days (except legal retention obligation) |
| Clinical data | According to Data Controller's instructions |
After the retention period ends, data is securely and permanently deleted.
9. Your Rights
Under GDPR, you have the following rights:
9.1 Right of Access
You can request a copy of your personal data we process.
9.2 Right of Rectification
You can request correction of inaccurate or incomplete data.
9.3 Right to Erasure ("right to be forgotten")
You can request deletion of your data when no longer necessary or you withdraw consent.
Limitations: We cannot delete data subject to legal retention obligations or necessary for legal claims.
9.4 Right to Restriction of Processing
You can request that we suspend processing of your data in certain circumstances.
9.5 Right to Data Portability
You can request to receive your data in a structured, machine-readable format, or that we transfer it to another controller.
9.6 Right to Object
You can object to processing based on legitimate interest or for direct marketing purposes.
9.7 How to Exercise Your Rights
To exercise any of these rights:
- Send an email to: [PRIVACY EMAIL] (PENDING CONFIGURATION)
- Include: Full name, registered email, request description, copy of ID
- We will respond within a maximum of 1 month
10. Right to Complain
If you believe data processing violates regulations, you can file a complaint with the Spanish Data Protection Agency (AEPD):
- Website: www.aepd.es
- Address: C/ Jorge Juan, 6, 28001 Madrid
- Phone: 901 100 099 / 912 663 517
11. Security Measures
We implement technical and organizational measures to protect your data:
11.1 Technical Measures
- Communication encryption (TLS/SSL)
- Data encryption at rest
- Role-based access control (RBAC)
- Multi-factor authentication (Google Identity)
- Complete activity and audit logging
- Regular backups
11.2 Organizational Measures
- Access policies with least privilege principle
- Staff training on data protection
- Privacy impact assessments (DPIA)
- Security breach response plan
12. Use of Cookies and Similar Technologies
12.1 Essential Cookies
We use cookies strictly necessary for service operation:
- Authentication session token
- Language preferences
- Active organization identifier
These cookies are essential and do not require express consent.
12.2 Analytical Cookies (if applicable)
[PENDING: Complete if analytics tools like Google Analytics are implemented]
You can manage cookies from your browser settings.
13. Minors
Arion is intended exclusively for health and research professionals. We do not intentionally collect data from persons under 18 years of age.
If we detect that a minor has provided personal data, we will proceed with immediate deletion.
14. Changes to this Policy
We may update this Privacy Policy occasionally.
In case of substantial changes:
- We will notify you via email or platform notice
- Your explicit acceptance will be required to continue using the service
- We will publish the updated version with the "last updated" date
15. Contact
For any questions about this Privacy Policy or processing of your data:
- Email: [PENDING CONFIGURATION]
- Postal address: [PENDING CONFIGURATION]
- Data Protection Officer: [PENDING CONFIGURATION]
Last revision: January 15, 2025
This policy is part of Arion's legal framework together with the Terms of Service and DPA.