Privacy Policy

Platform Privacy Policy

Last updated: 09/07/2024

1. Overview

This Privacy Policy (Policy) describes how We at Alkemio B.V. (Alkemio, We, Us, Our) collect, protect, share, and use the Personal Data You (User, You, or Your) may provide on the Alkemio Platform (Platform) and within any of Our products or services (Products).

This Privacy Policy applies to the following Data Subjects:

  • Registered Users of the Platform who have a contractual relationship with Alkemio B.V.;
  • Visitors to the Platform that do not have a contractual relationship with Us;
  • Participants at Alkemio B.V. promoted events;
  • Individuals with whom we interact and process their personal data.

Depending on the Data Subject category and country of residence, this Policy may sometimes be supplemented by additional privacy notices issued by Us and other parties which will be notified to You separately.

We have a Data Protection Officer (DPO) who monitors Our compliance with the EU 2016/679 General Data Protection Regulation (EU GDPR). To reach out to Our DPO, please send an email to dpo@alkem.io.

The terms “Personal Data”, “processing”, “Data Subject”, “Controller”, “Processor” have the same meaning as in the GDPR.

2. Roles

Under GDPR, We may process Personal Data as a Controller or a Processor. This Privacy Policy applies to Personal Data We collect and process for Our own purposes where We act as a Controller. Where We process Your Personal data on behalf of Our Users, We act as a Processor and We have limited rights and responsibilities.

We process Your information for the purposes described in this policy based on the following legal bases:

  • Consent: You have given clear consent for Us to process Your personal data for a specific purpose.
  • Legitimate interests: a legitimate interest is when We have a business or commercial reason to use Your information so long as this is not overridden by Your own rights and interests.
  • Contractual Obligations: the processing is necessary for a contract We have with You or because You have asked Us to take specific steps before entering a contract.
  • Legal Obligations: the processing is necessary for Us to comply with the law.

4. How We use Your data as a Platform User

Alkemio may collect Your Personal Data through Our communication and Your usage of Our Platform. Personal Data can be directly provided by You or indirectly collected by Us (i.e., from Your interactions, use, and experiences with Our Products).

PurposePersonal data categoryLegal justification
Accounts ReceivableContact Details, Financial Data, Identifiers, and Legal DocumentsContractual Obligations
B2B Email/Text Digital Marketing (existing customers)Contact Details, Personal Characteristics, Views, and OpinionsLegitimate Interest
B2C Email/Text Digital Marketing (existing customers)Contact Details, Personal CharacteristicsLegitimate Interest
Calendar SchedulingContact DetailsLegitimate Interest
Consent ManagementActivity and Behavioural, Technical IdentifiersLegal Obligations
Customer SupportContact Details, Personal Characteristics, Views, and OpinionsContractual Obligations
Customer Relationship managementContact Details, Personal Characteristics, Views, and OpinionsLegitimate interest
Financial ReportingContact Details, Financial DataLegitimate interest
Infrastructure/Integrations or File StorageActivity and Behavioural, Contact Details, Identifiers and Legal Documents, Technical IdentifiersContractual Obligations
Product Surveys and QuestionnairesContact Details, Technical Identifiers, Views, and OpinionsConsent
Provide collaboration softwareCommunications Data, Contact Details, Technical Identifiers, Views, and OpinionsContractual Obligations
Website trackingActivity and Behavioural, Technical IdentifiersConsent

5. How We use Your data as a Contractor

PurposePersonal data categoryLegal justification
Accounts payableContact Details, Financial Data, Identifiers, and Legal DocumentsContractual Obligations
Calendar SchedulingContact detailsLegitimate interest
Infrastructure/integrations or file storageContact DetailsLegitimate interest
Internal communicationCommunications Data, Contact Details, Views, and OpinionsLegitimate interest
Legal archivingContact Details, Identifiers, and Legal DocumentsLegal Obligations
Password and credential safekeepingContact Details, Technical IdentifiersContractual Obligations

6. How We use Your data as a Website visitor

PurposePersonal data categoryLegal justification
Account Customer Relationship Management (CRM)Contact Details, Personal CharacteristicsLegitimate Interest
Embedding VideosTechnical IdentifiersConsent
Website HostingContact Details, Technical IdentifiersLegitimate interest
Website TrackingActivity and Behavioural, Technical IdentifiersConsent

7. Third-parties & Sub-Processors

We might store or send personal data about You to various third parties. These disclosures apply to all categories of Data Subjects in the scope of this Policy. These disclosures are either necessary for the purpose of fulfilling Our contract with You or necessary for the purposes of Our legitimate interests (that are to provide, maintain, improve, secure, and promote Our Products). When none of these bases apply, We will seek permission (consent) to share Personal Data with a specific supplier.

Our suppliers may change over time but You can find the latest list of key suppliers (Processors and sub-Processors) here.

8. Data security

We have put in place appropriate security measures to prevent Your personal data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, We limit access to Your personal data to those employees, agents, contractors, and other third parties who have a business need to know. They will only process Your personal data on Our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach and will notify You and any applicable regulator of a breach where We are legally required to do so.

Where You have chosen a password that enables You to access certain parts of Our Platform, You are responsible for keeping this password confidential. We ask You not to share the password with anyone.

9. Data retention

We will only retain Your personal data for as long as reasonably necessary to fulfil the purposes We collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements. We may retain Your personal data for a longer period in the event of a complaint or if We reasonably believe there is a prospect of litigation with respect to Our relationship with you.

To determine the appropriate retention period for personal data, We consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of Your personal data, the purposes for which We process Your personal data and whether We can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting, or other requirements.

For more detailed information about the retention periods of the Personal Data that Alkemio processes, You can request a copy of Our Retention Policy via dpo@alkem.io.

You have the following data subject rights under GDPR:

  • You may access, correct, update, or request deletion of Your Personal Data;
  • You can object to the processing of Your Personal Data, ask Us to restrict processing of Your Personal Data or request portability of Your Personal Data;
  • You have the right to opt-out of marketing communications We send You at any time. You can exercise this right by clicking on the unsubscribe or opt-out link in the marketing emails We send You. If You choose to opt-out of marketing, We will still send You non-promotional emails such as emails about Our ongoing business relations.
  • If We have collected and processed Your Personal Data with Your consent, then You can withdraw Your consent at any time.
  • You have the right to complain to a supervisory authority about Our collection and use of Your Personal Data.
  • You may exercise any data subject rights under GDPR related to the Personal Data We process as a Controller via reaching out to Our DPO: dpo@alkem.io.

That period may be extended by two more months where necessary considering the complexity and number of the requests. We will inform You of any such extension together with the reasons for the delay.

Where GDPR is not applicable, We will respond to such requests within the prescribed time according to the applicable law.

We note that where requests are unfounded or excessive, particularly due to their repetitive character, We may refuse to act on the request. In such cases, Alkemio shall bear the burden of demonstrating the manifestly unfounded or excessive character of the request.

We kindly inform You that if We are not the Controller, We may not be able to directly address data subject requests We receive. In cases where We act as the Processor for Your personal data, We will promptly notify the Controller about Your request. Please understand that any response to Your request will be provided only if We are authorized by the Controller. For any inquiries or more information, We encourage You to contact the Controller directly.

11. Cookies

For detailed information about cookies and which types of cookies We use, please read Our cookie policy.

Previous Privacy Policy

Find our previous Privacy Policy here (from 07/07/2021 until 08/07/2024).