Testopedia privacy policy​

Date of last revision: 7 NOVEMBER 2023

1.              WHO ARE WE?

1.1.              We are Testopedia BV, a company incorporated under Belgian law, having its registered office at Laarbossenstraat 27, 3980 Tessenderlo (“Testopedia”, “we”) and registered with the Crossroads Bank for Enterprises (Kruispuntbank van Ondernemingen or KBO) under enterprise number 0803.538.595.

1.2.              We at Testopedia provide an easy-to-use platform that brings together laboratories and potential customers, depending on their testing needs (“Platform”).

1.3.              We value your right to privacy and make every effort to protect your personal data in accordance with applicable data protection law, including the General Data Protection Regulation (EU) 2016/679 ("GDPR") and national implementing legislation. In this Privacy Policy, we explain what personal data we collect from you, for what purposes we will process this data, on what legal basis we base this processing, to whom your personal data may be transferred, how long we keep your data, how we protect your data and what rights you have in relation to the processing of your personal data.

1.4.              All concepts not explicitly defined in this Privacy Policy, have the same meaning as in the GDPR.

2.              FROM WHOM DO WE COLLECT DATA?

2.1.              In the course of our business, we may collect personal data from customers, suppliers, visitors of the Platform and persons who contact us by e-mail or otherwise.

3.              WHAT PERSONAL DATA DO WE REQUEST AND WHY?

3.1.              By using our Platform, we collect and process your data. Some aspects of these data can be qualified as personal data.  We process the following categories of personal data, for the following purposes, on the basis of the following legal grounds:

WHY?

WHICH DATA?

ON WHAT BASIS?

To create an account

Name, email address, password

The prior, express, free, specific and informed consent of you (art. 6.1 a) GDPR)

To process orders

Company name, VAT number, telephone number, email address, address

The necessity for the performance of the contract we have concluded with you, in particular the Terms and Conditions (art. 6.1 b) GDPR).

To help you with technical problems or other questions

Data required to resolve these issues

Necessary for the exercise of our legitimate interests (art. 6.1 f) GDPR), in particular to enhance the quality of our Platform

To inform you of new functionalities to our Platform

Name, email address

Necessary for the exercise of our legitimate interests (art. 6.1 f) GDPR, in particular communicate relevant information

To analyse statistics about visitors to our Platform in order to improve the Platform

Data on visitors' behaviour

The prior, express, free, specific and informed consent of you (art. 6.1 a) GDPR)

To comply with legal obligations

Data required by applicable law

Necessary to comply with a legal obligation (art. 6.1 c) GDPR).

To prevent, detect and combat fraud and other illegal or unauthorised activities

Data required for detection of fraud and illegal activities

Necessary for the exercise of our legitimate interests (art. 6.1 f) GDPR, in particular the prevention of fraud and other illegal activities

To fulfil payment obligations

Email address, type of subscription

Necessary for the exercise of our legitimate interests (art. 6.1 f) GDPR, in particular compensating us

To administer your account

Data required for the account administration

The necessity for the performance of the contract we have concluded with you, in particular the Terms and Conditions (art. 6.1 b) GDPR).

 

4.              WITH WHOM DO WE SHARE YOUR PERSONAL DATA?

4.1.              We may disclose your personal data to the following parties:

-          Other users of the Platform: you share information with other users when you disclose information on the Platform. Please be careful with your information and make sure you are comfortable with the visibility of the content you share.

-          With our service providers and partners: We use third parties to help us operate and improve our Platform. These third parties assist us with various tasks, including data hosting and maintenance, analytics, customer care, marketing, advertising, payment processing and security operations. We also share information with partners who distribute and assist us in advertising our Platform. For instance, we may share limited information on you in hashed, non-human readable form to advertising partners.

-          With suppliers of tests, analyses and results: We use third parties labs to provide tests, analyses and results, based on the customer’s samples, on our Platform in order to enable the purchase of such tests.

-          With law enforcement/when required by law: We may disclose your information if reasonably necessary: (i) to comply with a legal process, such as a court order, subpoena or search warrant, government / law enforcement investigation or other legal requirements; (ii) to assist in the prevention or detection of crime (subject in each case to applicable law); or (iii) to protect the safety of any person.

4.2.              When transferring personal data to third parties, we always ensure that we implement appropriate technical and organisational protection measures. Where necessary, we will, for example, conclude a transfer agreement or a processor agreement, which sets out restrictions on the use of your personal data and obligations in respect of the security of your personal data.

4.3.              Your personal data will not be lent or sold to third parties for marketing purposes without your prior express consent.

4.4.              To the extent that your data is transferred in the context of this article to countries outside the European Union which do not provide an adequate level of protection for your data, Testopedia will ensure that the companies to which your data is transferred do provide an adequate level of protection. In particular, we have concluded Standard Contractual Clauses (SCC) with them. Testopedia guarantees to always verify, on a case-by-case basis, whether an adequate level of protection is in place for transfers to third countries.

5.              HOW LONG DO WE STORE YOUR PERSONAL DATA?

5.1.              We do not keep your personal data longer than necessary for the purposes for which it is collected and processed (as described above).

5.2.              For the purposes of providing Platform to our customers, we will retain it for as long as necessary to fulfil the purposes set out above, unless a longer retention period is (i) necessary to cover our liability or (ii) required or permitted by law.

5.3.              All personal data purely for the purpose of scientific research or statistical purposes may be stored for longer periods.

5.4.              Regarding the data of visitors to our Platform, we refer to our Cookie Policy.

6.              HOW DO WE SECURE YOUR PERSONAL DATA?

6.1.              We take appropriate technical and organisational measures to ensure a level of security appropriate to the specific risks we have identified.

6.2.              We thus protect your personal data as best as we can against the destruction, loss, alteration or unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed. More information on our security measures is available upon request.

7.              WHICH RIGHTS DO YOU HAVE AS A DATA SUBJECT?

7.1.              Withdraw your consent at any time: you have the right to withdraw consent where they have previously given their consent to the processing of your personal data.

7.2.              Object to processing of your personal data: you have the right to object to the processing of your personal data if the processing is carried out on the legal basis of a legitimate interest, including profiling. You also have the right to object to the processing of your personal data for direct marketing purposes. This right is absolute - we will always comply with it.

7.3.              Right to access: You have the right to obtain confirmation from us as to whether or not we are processing your personal data, to obtain access to that personal data and how and why it is being processed, as well as to receive a copy of that data.

7.4.              Right to rectification: You have the right to obtain a correction of your personal data or to request that we complete your personal data if you notice that we are processing incorrect or incomplete data about you.

7.5.              Right to erasure: You have the right to obtain data erasure in certain specific cases.

7.6.              Right to restriction: You have the right to have the processing of your personal data restricted in certain specific cases.

7.7.              Right to data portability: You have the right to obtain the personal data you have provided us with in a structured, commonly used and machine-readable form, and to transfer that personal data (or have it transferred) to another controller.

7.8.              You may exercise the above rights by sending an e-mail to info@fl3xlab.com or in the case of the right to object to direct marketing also via the opt-out link included in our marketing e-mails. The exercise of these rights is in principle free of charge. Only in case of unreasonable or repeated requests may we charge a reasonable administrative fee. We always try to answer your requests or questions as quickly as possible. It is possible that we will first ask you for proof of identity in order to verify your identity. For further information and advice on the above rights, please visit the Platform of the Data Protection Authority: www.gegevensbeschermingsautoriteit.be. In addition to the above rights, you also have the right at any time to lodge a complaint with the Data Protection Authority in connection with the processing of your personal data by us. You can contact the authority at contact@apd-gba.be or by mail at the following address:

Gegevensbeschermingsautoriteit
Drukpersstraat 35
1000 Brussel

7.9.              Furthermore, you can always choose to delete your account. When the information on your profile is inaccurate, you have the right to update your information.

8.              References to other websites

8.1.              Our Platform may contain links to other sites that are not operated by us. If you click on a third-party link, you will be redirected to that third-party site. We strongly recommend that you review the Privacy Policy of each site you visit.

8.2.              We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party websites or Platform.

9.              CHANGES TO THE PRIVACY POLICY

9.1.              From time to time, it may be necessary to amend this Privacy Policy. When we post changes to the policy, we will change the "last updated" date at the top of the document. The most recent version of this Privacy Policy will be available on our Platform at all times.

10.            CONTACT

10.1.          If you have any questions or concerns regarding this Privacy Policy or our processing of your personal data, you may contact us at info@fl3xlab.com or Laarbossenstraat 27, 3980 Tessenderlo.