IHC - Invest in Healthcare GmbH · Version of text: a831c2caef69
So that you can see what happens to your data when you use this data room, we have summarised it here. Please read the notice once and then confirm it. You can call it up again at any time via the link in the footer.
The controller within the meaning of Art. 4(7) GDPR is IHC - Invest in Healthcare GmbH, Rudolf-Diesel-Str. 7b, 86899 Landsberg am Lech, Germany. Please direct questions about data protection and the exercise of your rights to vdr@investinhealthcare.de or to the address above.
Regarding you personally we process the details of your account — name, email address, company, role and language — together with the security attributes of your sign-in: the password verifier, the one-time codes, failed attempts and lockout periods. Added to this are the technical details of every request: time, IP address, browser identification and the page or file requested.
We process your account data in order to provide you with the contractually or pre-contractually agreed access to the data room; the legal basis is Art. 6(1)(b) GDPR. Logging, sign-in protection and watermarking rest on our legitimate interest in the security of the documents entrusted to us and in the traceability of access, Art. 6(1)(f) GDPR. Retaining your acceptance of the legal notice and this data protection notice serves our accountability obligation under Art. 5(2) GDPR.
Every sign-in, every document opened, every export, every download, every search and every change is recorded with time, user identifier and IP address. In the protected viewer and in PDF exports a personal watermark is additionally burned into the rendering which, depending on the data room settings, may contain your email address, your name, your role, your company, the time and your IP address. These details serve to establish the origin of a document that has gone astray. No evaluation for the purpose of monitoring the conduct or performance of employees takes place.
Within IHC - Invest in Healthcare GmbH only those people have access who need it to operate the data room and support the transaction. Engaged as processors within the meaning of Art. 28 GDPR are the operator of the server in Germany and the provider of the email delivery. Other data room participants see your name, your email address and your group insofar as this is necessary for collaboration; data room administrators additionally see your access in the insights. Data is transferred to public authorities only where we are legally obliged to do so.
The data room runs on a server in Germany; documents are stored there encrypted with AES-256. For sending email we use Microsoft 365, where processing in third countries cannot be excluded and is based on the European Commission standard contractual clauses. Analysis of documents by artificial intelligence must be enabled separately and can be switched off per data room. When it is on, the text of the document being analysed leaves the server and is processed by a language model provider; the content is not used for training there. For documents relating to patients this function remains switched off.
Healthcare documents may contain health data and other special categories of personal data within the meaning of Art. 9(1) GDPR. Such details should be anonymised, pseudonymised or redacted before being placed in the data room; the data room provides a redaction function for this. If you come across details that obviously do not belong in the data room, please stop reading them and inform us without delay.
We delete your account data when your access ends and no retention obligation stands in the way. After completion of the transaction we retain the access logs and the records of your acceptances in accordance with our deletion policy, so that breaches can still be investigated and we can meet our accountability obligation, and delete them thereafter. The documents placed in the data room are deleted after the transaction is completed or discontinued, unless a statutory retention obligation applies.
You have the right to obtain information about the data stored about you, to have inaccurate details corrected, to erasure, to restriction of processing and to data portability. Where we rely on a legitimate interest, you may object to the processing on grounds relating to your particular situation. Independently of this you have the right to lodge a complaint with a data protection supervisory authority; the authority responsible for us is the Bavarian Data Protection Supervisory Authority in Ansbach. Providing your account data is necessary in order to use the data room; without it no access can be set up.
Legal notice and terms of use · Terms and conditions · Back to sign-in