ePData User Information and Privacy Protection Policy


Xincere Med (hereinafter referred to as "we") deeply understands the importance of user information security and privacy protection. We will implement security measures, strive to enhance the transparency of information processing, and ensure the security and controllability of your personal information.


Xincere Med will strictly comply with legal regulations and follow the principles of user information and privacy protection outlined below to provide you with safe and reliable services, including but not limited to clinical research data collection and disease research:

1. Reasonable and necessary: To provide you with better services, we only collect essential information. This information will be used to provide you with suitable solutions and services.

2. Fully informed: We endeavor to use clear and understandable expressions to explain our user information and privacy protection policy so that you can clearly understand our methods of information processing.

3. Safe and reliable: We do our utmost through reasonable and effective information security technology and management processes to prevent your information from being leaked, damaged, or misused. We integrate the concept of privacy protection in every aspect of our service process.


Before using any services offered by Xincere Med, we hope you will carefully read and thoroughly understand this "User Information and Privacy Protection Policy" (hereafter referred to as "the Policy"), to fully understand our methods of collecting and using information, so that you can better understand our services and make appropriate choices. You can use the relevant services only after you have fully understood and agreed to this policy. Meanwhile, you have the right to choose "disagree" or request the deletion of your personal information according to your preferences. If you begin using the services related to Xincere Med, it is considered as your acceptance and approval of the content described in this policy.

Definitions


Xincere Med refers to Shanghai Xincere Med Technology Inc.


Personal information refers to various information that can identify a specific natural person alone or in combination with other information, or reflect specific activities of a natural person, recorded electronically or by other means.


Deleting personal information refers to actions taken within systems involved in daily business functions to remove personal information, ensuring it remains irretrievable and inaccessible.


This policy will primarily explain and help you understand:

I. Information we may collect;

II. How we collect and use your personal information;

III. How we share, transfer, and publicly disclose your personal information;

IV. How we protect your personal information;

V. How you can manage your personal information;

VI. How we handle personal information of special groups;

VII. How this policy is updated.

I. Information we may collect:


During service provision, based on the principles of legality, legitimacy, and necessity, we may collect, store, and use the following personal-related information:

1. Information related to personal identity: When you use our services, we may collect, aggregate, or require you to provide information related to your personal identity, such as your birthday, contact details, and personal health information including medical history, examination reports, surgery and anesthesia records, nursing records, allergy information to drugs and food, reproductive information, treatment conditions, family medical history, and other health-related information like weight, height, and lung capacity.

2. Information unrelated to personal identity: When you use our services, we may automatically collect, acquire, and store service log information, such as IP addresses, personal location data, user device information, source paths, visit sequences, dwell time, and electronic log information.

3. If you use video or audio features in the services, we may collect your facial and voice print privacy information, subject to your authorization and consent.

II. How we collect and use your personal information:


We strictly comply with legal and regulatory provisions and agreements with users, and collect, store, and use your personal information for the following purposes. If we use the information collected for purposes other than those specified or use information collected for specific purposes for other uses, we will explain this to you again and seek your consent.

1. To provide you with services or products.

2. To recommend information and services that you may be interested in.

3. To invite you to participate in surveys about our services to evaluate and improve our services.

4. To use the collected information for data analysis, e.g., using the information to analyze and generate clinical trial data reports that do not contain any personal information.

5. Exceptions for obtaining consent: In the following scenarios, collecting your personal information does not require your consent:

1) Collecting information related to public safety, public health, or significant public interests under the authorization or approval of relevant authorities;

2) Collecting personal information from legally disclosed sources, such as lawful news reports, government disclosures, etc.;

3) Necessary for maintaining the safe and stable operation of products or services provided to you, such as discovering and handling product or service malfunctions;

4) Necessary for academic research institutions to carry out statistics or academic research for public interest, and when providing results of academic research or descriptions to the outside, personal information in the results is de-identified;

5) Other circumstances as stipulated by laws and regulations.

III. How we share, transfer, and publicly disclose your personal information:


1. Sharing:

We will not share your information with any company, organization, or individual other than service providers, except under the following circumstances:

1) We may share your personal information according to legal and regulatory requirements, or as required by government authorities.

2. Transfer:

Unless with your explicit consent, we will not transfer your personal information to any company, organization, or individual.

3. Public Disclosure:

We will only publicly disclose your personal information in the following circumstances:

1) With your explicit consent or based on your active choice, we may publicly disclose your personal information;

2) If we determine that you have violated laws and regulations or seriously violated the rules of agreements with Xincere Med, or to protect the personal and property safety of Xincere Med and its users or the public from harm, we may disclose your personal information with your consent under the laws and regulations or the agreements of Xincere Med.

4. Exceptions for obtaining prior consent for sharing, transferring, or publicly disclosing personal information:

1) Collecting information related to public safety, public health, or significant public interests under the authorization or approval of relevant authorities;

2) Collecting personal information from legally disclosed sources, such as lawful news reports, government disclosures, etc.

IV. How we protect your personal information:


1. We have implemented security measures that meet industry standards and are reasonably feasible to ensure the safety of the personal information you provide, preventing unauthorized access, public disclosure, use, modification, damage, or loss of personal information.

2. We will take reasonable and feasible measures to avoid collecting irrelevant personal information.

3. We will use various security measures within a reasonable level of security to ensure the safety of information, such as using encryption technology and anonymization processes to protect your personal information.

4. We have established specialized management systems, processes, and organizations to ensure information security. For example, we strictly limit the range of people who have access to information, require them to comply with confidentiality obligations, and conduct reviews.

V. How you can manage your personal information:


1. We will collect and use your information only for the functionality of our products or services as described in this policy. If you find that we have violated legal, regulatory provisions, or our agreements in collecting or using your personal information, you may request us to delete it.

2. Exceptions to responding to your requests: In the following situations, we may not be able to respond to your requests:

1) Collecting information related to public safety, public health, or significant public interests under the authorization or approval of relevant authorities;

2) There is sufficient evidence to indicate that the subject of the personal information has malicious intentions or is abusing rights;

3) Responding to your request would cause serious harm to the legal rights and interests of you or other individuals or organizations;

4) Involving trade secrets.

VI. How we handle personal information of special groups:


1. If you belong to a special group with no capacity to make autonomous choices, including but not limited to minors and individuals incapable of giving informed consent, we suggest that you have your guardian carefully read this policy. You should use our services or provide us with information only with the consent of your guardian.

2. In cases where personal information of special groups is collected with the consent of a guardian for the use of our products or services, we will use, share, transfer, or disclose this information only when legally permitted, with explicit consent from the guardian, or when necessary to protect special groups.

VII. How this policy is updated:


We may revise the content of this policy from time to time. If such changes will substantively reduce your rights under this policy, we will notify you before the changes take effect through prominent positioning on the page or other methods. In such cases, if you continue to use our services, it means you agree to be bound by the revised policy.


Signature: I have read and understand the above "User Information and Privacy Protection Policy," and I "agree" to authorize Xincere Med to collect, organize, and record my personal information and provide me with services.

Version update date: January 1, 2022

Version effective date: January 1, 2022

ePData用户信息及隐私保护政策


信华医药(以下简称“我们”)深知用户信息安全与隐私保护的重要性,我们将采取安全保护措施,致力于提升信息处理透明度,保障您的个人信息安全可控。


信华医药将严格遵守法律法规并遵循以下用户信息及隐私保护原则,为您提供安全、可靠的服务,包括并不限于临床研究数据采集、疾病调研等:

1、 合理必要:为了向您提供更好的服务,我们仅收集必要的信息。这些信息的收集将用于为您提供适合的解决方案和服务。

2、 充分知情:我们努力使用简明易懂的表述,向您陈述用户信息及隐私保护政策,以便您清晰地了解我们的信息处理方式。

3、 安全可靠:我们竭尽全力通过合理有效的信息安全技术及管理流程,防止您的信息泄露、损毁、滥用。我们在服务流程的各个环节,融入隐私保护的理念。


在使用信华医药的各项服务前,希望您务必仔细阅读并透彻理解本《用户信息及隐私保护政策》(以下简称“政策”),详细了解我们对信息的收集、使用方式,以便您更好地了解我们的服务并作出适当的选择,在您确认充分理解并“同意”该政策后方可使用相关服务。同时,您有权选择“不同意”或依据您的要求删除您的个人信息。若您开始使用信华医药之相关服务,即被视为您对本政策所述内容的接受和认可。

定义


信华医药,是指上海信华医药科技有限公司。


个人信息,是指以电子或者其他方式记录的能够单独或者与其他信息结合识别特定自然人身份或者反映特定自然人活动情况的各种信息。


删除个人信息,是指在实现日常业务功能所涉及的系统中去除个人信息的行为,使其保持不可被检索、访问的状态。


本政策将主要向您说明并帮助您了解:

一、 我们可能收集的信息;

二、 我们如何收集和使用您的个人信息;

三、 我们如何共享、转让、公开披露您的个人信息;

四、 我们如何保护您的个人信息;

五、 您如何管理您的个人信息;

六、 我们如何处理特殊人群的个人信息;

七、 本政策如何更新。

一、我们可能收集的信息


我们在提供服务时,根据合法、正当、必要的原则,仅可能收集、储存、和使用为您提供服务所必要的下列与个人(“您”)有关的信息:

1. 与个人身份相关的信息:

当您使用服务时,我们可能收集、汇总或要求您提供的与个人身份相关的信息。例如生日、联系方式等;您在使用服务时提交的个人健康信息,例如病历病史资料、检查报告、手术及麻醉记录、护理记录、药物食物过敏信息、生育信息、诊治情况、家族病史、其他与个人身体健康状况相关的信息,如体重、身高肺活量等。

2. 与个人身份无关的信息:

当您使用服务时,我们将可能自动收集、获取并存储为服务日志的信息,例如IP地址、个人位置信息、用户的设备信息、来源途径、访问顺序、停留时间以及电子日志信息等。

3. 如您在服务中使用到了视频或音频功能,可能会收集您的人脸、声纹等隐私信息,系统会征得您的授权同意才会收集。

二、我们如何收集和使用您的个人信息


我们严格遵守法律法规的规定及与用户的约定,出于以下目的,收集、储存和使用您的个人信息。若我们超出以下用途或者将基于特定目的收集而来的信息用于其他目的使用您的信息,我们将再次向您进行说明,并征得您的同意。

1. 向您提供服务或产品。

2. 向您展示并推送您可能感兴趣的相关信息和服务。

3. 邀请您参与有关我们服务的调查,评估、改善我们的服务。

4. 将所收集到的信息用于数据分析。例如,我们将收集到的信息用于分析形成不包含任何个人信息的临床试验数据报告。

5. 征得授权同意的例外:以下情形中收集您的个人信息无需征得您的授权同意:

1) 在取得有关机关的授权或批准前提下,收集您与公共安全、公共卫生、重大公共利益有关的信息;

2) 从合法公开披露的信息中收集个人信息的,如合法的新闻报道、政府信息公开等渠道;

3) 用于维护为您提供的产品或服务的安全稳定运行所必需的,例如发现、处理产品或服务的故障;

4) 学术研究机构基于公共利益开展统计或学术研究所必要,且对外提供学术研究或描述的结果时,对结果中所包含的个人信息进行去标识化处理的;

5) 法律法规规定的其他情形。

三、我们如何共享、转让、公开披露您的个人信息


1. 共享:

我们不会向除服务提供者以外的任何公司、组织和个人分享您的信息,但以下情况除外:

1) 我们可能会根据法律法规规定,或按政府主管部门的强制性要求,对外共享您的个人信息;

2. 转让:

除非在您的明确同意情况下,我们不会将您的个人信息转让给任何公司、组织和个人。

3. 公开披露:

我们仅会在以下情况下,公开披露您的个人信息:

1) 获得您明确同意或基于您的主动选择,我们可能会公开披露您的个人信息;

2) 如果我们确定您出现违反法律法规或严重违反信华医药相关协议规则的情况,或为保护信华医药及用户或公众的人身财产安全免遭侵害,我们可能依据法律法规或信华医药相关协议规则征得您同意的情况下披露关于您的个人信息。

4. 共享、转让、公开披露个人信息时事先征得授权同意的例外:

1) 在取得有关机关的授权或批准前提下,收集您与公共安全、公共卫生、重大公共利益有关的信息;

2) 从合法公开披露的信息中收集个人信息的,如合法的新闻报道、政府信息公开等渠道。

四、我们如何保护您的个人信息


1. 我们已采取符合业界标准、合理可行的安全防护措施保护您提供的个人信息安全,防止个人信息遭到未经授权访问、公开披露、使用、修改、损坏或丢失。

2. 我们会采取合理可行的措施,尽力避免收集无关的个人信息。

3. 我们将在合理的安全水平内使用各种安全保护措施以保障信息的安全。例如,我们使用加密技术、匿名化处理等手段来保护您的个人信息。

4. 我们建立专门的管理制度、流程和组织确保信息安全。例如,我们严格限制访问信息的人员范围,要求他们遵守保密义务,并进行审查。

五、您如何管理您的个人信息


1. 我们将按照本政策所述,仅为实现我们产品或服务的功能,收集、使用您的信息。如您发现我们违反法律、行政法规的规定或者双方的约定收集、使用您的个人信息,您可以要求我们删除。

2. 响应您请求的例外:在以下情形中,我们将无法响应您的请求:

1) 在取得有关机关的授权或批准前提下,收集的您与公共安全、公共卫生、重大公共利益有关的信息;

2) 有充分证据表明个人信息主体存在主观恶意或滥用权利的;

3) 响应您的请求将导致您或其他个人、组织的合法权益受到严重损害的;

4) 涉及商业秘密的。

六、我们如何处理特殊人群的个人信息


1. 如您为无自主选择能力的特殊人群,包括并不限于未成年人、无能力知情同意个人,建议您请您的监护人仔细阅读本政策,并在征得您的监护人同意的前提下使用我们的服务或向我们提供信息。

2. 对于经监护人同意使用我们的产品或服务而收集特殊人群个人信息的情况,我们只会在法律法规允许、监护人明确同意或者保护特殊人群所必要的情况下使用、共享、转让或披露此信息。

七、本政策如何更新


我们可能适时修订本政策内容。如该等变更会导致您在本政策项下权利的实质减损,我们将在变更生效前,通过在页面显著位置提示等方式通知您。在该种情况下,若您继续使用我们的服务,即表示同意受经修订的政策约束。


签署:我已阅读并理解上述《用户信息及隐私保护政策》,并“同意”授权信华医药收集、整理、记录我的个人信息并为我提供服务。

版本更新日期:2022年1月1日

版本生效日期:2022年1月1日