Effective Date: 10/16/2024
At SalaryMed.com, we are committed to protecting your personal data in compliance with the General Data Protection Regulation (GDPR). This policy outlines your rights regarding your personal data and how we ensure your information is secure.
- Data Controller
SalaryMed.com is the data controller of the personal information you provide on this website. You can contact us if you have any questions regarding our GDPR compliance. For more on data protection in healthcare, you can explore the Health Information Privacy section of the U.S. Department of Health & Human Services.
- Legal Basis for Data Collection
We collect and process your personal data based on one or more of the following legal grounds:
- Your Consent: When you provide explicit consent for us to process your personal information.
- Contractual Obligations: To fulfill our contract with you by providing services through our website.
- Legitimate Interests: We process your data for legitimate interests, such as improving our services, as long as your data protection rights do not override these interests.
- Compliance with Legal Obligations: We may process your data to comply with applicable laws and regulations.
Visit the European Data Protection Board (EDPB) for more information on the legal frameworks surrounding data collection.
- Your GDPR Rights
As a user within the European Economic Area (EEA), you have the following rights under GDPR:
- Right to Access: You have the right to request access to your personal data that we hold.
- Right to Rectification: You can request corrections to your personal data if it is inaccurate or incomplete.
- Right to Erasure: In certain circumstances, you have the right to request the deletion of your personal data (also known as the ‘right to be forgotten’).
- Right to Restrict Processing: You can request that we restrict the processing of your personal data under specific conditions.
- Right to Data Portability: You are entitled to request the transfer of your personal data to another organization or directly to you in a structured, commonly used, and machine-readable format.
- Right to Object: You have the right to object to processing your personal data in certain situations, including for direct marketing purposes.
- Right to Withdraw Consent: If we are processing your personal data based on your consent, you can withdraw that consent at any time.
For a deeper understanding of GDPR rights, you can visit the ICO – Your Data Matters page.
- Data Collection and Usage
We collect the following types of personal data:
- Contact Information: Such as name and email address, provided when you subscribe to our newsletter or fill out forms on our site.
- Usage Data: This includes IP addresses, browser types, and browsing behavior on our website.
- Cookies: We use cookies to enhance your user experience. You have the right to manage cookie settings in your browser.
For more on how cookies are used and managed, check out Cookiebot.
- Data Retention
We will retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy unless a longer retention period is required by law.
- Data Protection and Security
We take reasonable steps to protect your personal data from unauthorized access, loss, or misuse. We use security measures such as encryption and secure servers to ensure your data is handled safely. For best practices in data security in healthcare, see the National Institute of Standards and Technology (NIST) Guide to Cybersecurity in Healthcare.
- Third-Party Data Sharing
We do not sell or share your personal data with third parties except when required to provide services, such as with trusted service providers who assist us in operating the website. These third parties are obligated to maintain the confidentiality of your data and comply with GDPR.
- International Data Transfers
If we transfer your data outside the EEA, we will ensure that appropriate safeguards are in place to protect it, such as using standard contractual clauses approved by the European Commission.
- Data Breach Notification
In the event of a data breach that may result in a high risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay, as required by GDPR. For guidelines on managing data breaches, refer to EDPS – Data Breach Notification Guidelines.
- Your Right to Lodge a Complaint
If you believe your data protection rights have been violated, you can complain to your local Data Protection Authority. You can find more information on your local authority on the European Commission’s Data Protection Website.
For any further information or to exercise your rights under GDPR, please contact us.