Our commitment to privacy
Thank you for your interest in our website. Metronomia Clinical Research GmbH (“Metronomia”) is committed to protect the privacy of personal data (as defined below) and data privacy as well as information security are an inherent part of our corporate philosophy. Metronomia respects individual privacy and values the trust of clients, employees, patients, healthcare providers, business partners, and others who provide personal data. Metronomia adheres to regulatory requirements, including the EU General Data Protection Regulation (GDPR) and the German data protection law (Bundesdatenschutzgesetz (BDSG)), regarding the protection of personal data. We also process personal data that arise from visiting our websites strictly observing these regulations.
We very much follow the principles of data reduction and data economy.
This data privacy statement contains information about the processing of personal data at Metronomia, i.e. what personal data are collected, how it is used and about the way in which you can exercise your rights with respect to personal data.
Collecting and processing or using personal data
As a globally active contract research organization, Metronomia collects, hosts and analyzes health data relating to clinical trial subjects, on behalf of our clients. To enhance privacy, consistent with Good Clinical Practice (GCP), subjects’ names and other direct identifiers are not attached to any records collected by Metronomia for research purposes. Instead, subjects are only identified by a code (information is anonymized or pseudonymized). Only study doctors and authorized personnel, may access named subject records at the investigational site. In certain cases where local law allows, Metronomia may collect full date of birth attached to study records. We maintain that this indirect identifier can on occasion serve to verify subject identity to the benefit of patient safety. All clinical and medical information processed by Metronomia is done so under contract with our clients. In terms established by current regulations, Metronomia considers that the sponsor/client is ultimately in control of how and why clinical and medical data are processed within our services and as such is the “controller,” whilst Metronomia is “processor".
Metronomia collects personal information from applicants to open positions within Metronomia, including private contact details, professional qualifications and previous employment history to inform employment decisions. Once employed, Metronomia collects information on staff for human resource, performance, payroll and tax purposes. Various Metronomia internal systems will collect and record employee information consistent with standard business operations. Metronomia processes similar information relating to consultants contracted on a freelance basis.
Metronomia collects personal information from clients and client employees for operational purposes (including addresses, email addresses, phone numbers).
Metronomia collects named information about visitors to Metronomia websites where this is voluntarily provided to meet a request from those individuals, for example where a client requests information on a Metronomia service. This website does not use cookie-based technologies to allocate a virtual identity to visitors, and the aggregated usage statistics described under “Web analytics by Plausible” below cannot be linked to a named individual.
Use of personal data
Metronomia will process personal data for the purposes for which it has been collected or authorized, including:
- Respond to inquiries;
- Provide requested information on Metronomia’s services;
- For legitimate interests purposes.
Metronomia will not keep personal data for any longer than strictly necessary to realize the purposes for which personal data are collected or for the statutory period. A back-up of personal data that is submitted via the forms on the website are saved in the website’s Content Management System (CMS) and will be removed after 3 months by default.
Personal data may be saved in Metronomia’s CRM system for legitimate interest’s purposes.
Metronomia has Data Processing Agreements in place meeting GDPR requirements, with vendors processing personal data on behalf of Metronomia.
Contact form
If you contact us via email or the website’s contact form we store the content for processing purposes and possible following questions. In this context, there is no disclosure of the data to third parties and the transmission of the data to our server is encrypted.
The contact form contains the following mandatory fields:
- First name and name
- Subject
- Content of the message
- Consent to the purposeful processing of your personal data and to the notice of our privacy policy.
At the time of sending the message, the following data is also stored:
- The IP address of the user
- Date and time of registration.
You have the right at any time to revoke your consent to the processing of your personal data. We will then delete your data immediately.
Use of cookies
Cookies are small text files that a website can store on your device. Our website does not set cookies. We use no advertising, tracking or profiling cookies, and there is no cookie-consent banner, because nothing is placed on your device that would require your consent. The web analytics we use works without cookies; see “Web analytics by Plausible” below.
Most browsers accept cookies by default and let you view, block and delete them in their settings. General information about cookies and how to manage them is available at www.aboutcookies.org.
Our content management system, which requires an account and is used only by authorised Metronomia staff, sets a cookie to keep editors signed in. It is not part of the public website and no such cookie is set for visitors.
Server log files
Each time a page or file is requested, our web server writes an entry to its access log. The entry contains the IP address of the requesting device, the date and time of the request, the page or file requested, the status code and volume of data returned, the page from which the request came (referrer), and the browser and operating system your device reports.
This data is needed to deliver the website, to keep it available and secure, and to identify and correct faults. It is not merged with any other data source and is not used to identify individual visitors. Log files are rotated daily and deleted automatically after 14 days, unless an entry is required for longer in order to investigate a technical fault or a security incident.
Legal basis for data processing
Article 6 (1) point (f) of the GDPR. Our legitimate interest lies in the secure, stable and fault-free operation of our website.
Social media plugins
Our website does not use social media plugins. Where a social network's icon appears in our footer, it is a plain weblink to the respective profile (see “Links to other websites” below). No connection to that network is established and no data is transmitted to it unless you follow the link yourself.
Use of Google Analytics
Our website does not use Google Analytics.
Web analytics by Plausible
Scope of processing personal data
We use Plausible Analytics to understand in aggregate how our website is used. The service is provided by Plausible Insights OÜ, Tartu, Estonia. Plausible works without cookies: it stores nothing on your device, assigns you no identifier, does not follow you across websites or devices and builds no user profiles. There is therefore no consent banner, and nothing that you would need to switch off.
When a page of our website is opened, the following is recorded:
- the page opened, and the page or search engine that referred you (referrer)
- the country the request comes from, derived from the IP address
- the device type, browser and operating system your browser reports
- the campaign parameters in the address, if you arrived through a campaign link
- the date and time of the request, and how long the page stayed open
Your IP address is used only in passing, to derive the country and to recognise repeat page views within a single day without storing an identifier. It is not stored and is not visible to us. What we see are aggregated counts, from which an individual visitor cannot be singled out. The data is processed on servers within the European Union and is not transferred to a third country. Plausible acts as our processor under Article 28 of the GDPR; it does not use the data for its own purposes and does not pass it on.
Legal basis for processing personal data
Article 6 (1) point (f) of the GDPR. Our legitimate interest lies in measuring how our website is used so that we can improve it. Because no information is stored on or read from your device, this does not require consent under Section 25 of the TDDDG.
Purpose of data processing
The statistics show us which pages are read, which sources bring visitors to us and where the website is difficult to use, so that we can improve it. No decisions about individual people are taken on this basis.
Duration of storage
The aggregated statistics are kept for as long as they remain useful for that purpose. They contain no personal data and cannot be traced back to an individual visitor.
Right to objection and deletion
You can prevent the measurement altogether by blocking the script from plausible.io in your browser or with a content blocker; the website works normally without it. As no identifier is stored, there is no cookie to delete and no opt-out cookie to set. Further detail is set out in Plausible's own data policy at https://plausible.io/data-policy. Your rights to information, correction, erasure and objection under Articles 15 to 21 of the GDPR are described under “Right for information, correction, blocking, deletion and objection” below.
Web fonts
The typefaces used on this website — “Skyling” and “Manrope” — are delivered from our own server together with the rest of the website. Your browser makes no connection to Google Fonts or to any other external font service when a page opens, and no data is transmitted to a third party in order to display our fonts.
Images from our content management system
Photographs and other images on our website are held in our content management system and delivered to your browser from its content delivery network (cdn.sanity.io). When a page opens, your browser requests those images directly from that network, which receives your IP address and the technical details of the request. The service is provided by Sanity AS, Norway; its privacy policy is available at https://www.sanity.io/legal/privacy. The legal basis is Article 6 (1) point (f) of the GDPR — our legitimate interest in delivering the website reliably and quickly.
Use of Google Maps
We do not embed Google Maps on our website. Our contact and office pages contain plain weblinks to Google Maps. Google Maps opens only if you follow such a link, at which point you leave our website and Google's own privacy policy applies.
Links to other websites
Our website may contain links to other websites owned by third-party vendors, conferences, and/or our clients. This enables you to easily access websites that may be of interest to you. However, once you click on a hyperlink that transfers you from our website to a hyperlinked site, Metronomia is not responsible for the privacy practices or the content of such hyperlinked sites. You should carefully review the privacy policies and practices of other websites.
Application procedure
We process your applicant data exclusively for the purpose of and within the scope of the application procedure in accordance with the legal requirements. Applicant data is processed in order to fulfill our (pre)contractual obligations within the scope of the applicant selection process in accordance with Art. 6 para. 1 lit. b. DSGVO as well as § 26 BDSG, insofar as data processing becomes necessary for us, e.g. in the context of legal procedures.
The application procedure requires applicants to send us their application documents. The required applicant data are marked in the online form and otherwise result from the job descriptions. In principle, this includes personal details, address and contact data, as well as the documents relating to the application, such as cover letter, curriculum vitae and certificates. In addition, applicants may voluntarily provide us with additional information.
By submitting their application to us, applicants consent to the processing of
their data for the purposes of the applicant selection process in the manner and to the
extent set out in this privacy policy.
Insofar as special categories of personal data within the meaning of Art. 9 (1)
DSGVO are voluntarily communicated within the scope of the application procedure, their
processing is additionally carried out in accordance with Art. 9 (2) lit. b DSGVO (e.g.
health data, severely disabled status or ethnic origin). Insofar as special categories
of personal data within the meaning of Art. 9 (1) DSGVO are requested from applicants as
part of the application process, their processing is additionally carried out in
accordance with Art. 9 (2) a DSGVO (e.g. health data if this is necessary for the
exercise of the profession).
Applicants can submit their applications to us using an online form on our
website. The data is transmitted to us in encrypted form in accordance with the state of
the art. Applicants can also send us their applications by e-mail. However, please note
that e-mails are generally not encrypted and applicants must ensure that they are
encrypted themselves. In addition to applying via the online form and by e-mail, you
also have the option of sending us your application by mail.
If the application for a job offer is not successful, the applicants' data will be
deleted. Applicants' data will also be deleted if an application is withdrawn, which
applicants are entitled to do at any time.
Subject to a justified withdrawal by the applicants, the deletion will take place
after the expiry of a period of six months so that we can answer any follow-up questions
about the application and satisfy our obligations to provide evidence under the Equal
Treatment Act. Invoices for any reimbursement of travel expenses are archived in
accordance with tax law requirements.
- Types of data processed: applicant data (e.g. personal details, address and contact data, CV, certificates and other information provided with regard to a specific position or voluntarily by applicants regarding their person or qualifications).
- Data subjects: Applicants
- Purposes of processing: Applicant selection procedure
- Legal basis: Art. 6 para. 1 lit. b DSGVO in conjunction with Section 26 para. 1 BDSG, legitimate interests (Art. 6 para. 1 p. 1 lit. f DSGVO).
We use the following third-party providers to carry out the online application
process:
Services used and service providers: Kenjo.io: applicant management system and
candidate database; service provider: Kenjo GmbH, Urbanstr. 71, 10967 Berlin; website:
www.kenjo.io ; privacy policy: https://www.kenjo.io/legal/privacy
Commitment to data security
To prevent unauthorized access, maintain data integrity, and ensure the correct use of information, we secure our website and other systems through technical and organizational measures against loss, destruction, access, modification or distribution of your data by unauthorized persons. Additionally, Metronomia has issued a corporate policy for the protection of the confidentiality of individually identifiable information in accordance with applicable laws and regulations, regardless of the nature, source or form of the information.
Amendments
As we provide more services on our website and as privacy laws and regulations evolve, it may be necessary to revise or update our Privacy Policy without notice, but we will post those changes on our website's home page so our users are aware of what information we collect, use and disclose. However, we will continue to protect your identifiable information.
Right for information, correction, blocking, deletion and objection
You have a right to free information about your personal data we have stored, as well as the right to correct, block, or delete this data. If you have questions about the collection, processing or use of your personal data, the disclosure, correction, blocking or deletion of data and, if applicable, revocation of permission granted, or objection to a particular use of the data, please contact us. You will the contact information at the end of this data privacy statement.
How to contact us
Should you have any questions or concerns about our data privacy policies, please contact our data protection officer.
Also in case of questions on the collection, processing or use of personal information, the disclosure, correction, blocking or deletion of data and revocation of consent, our data protection officer is the right person to be contacted:
Oliver Kunert
Data Protection Officer
Metronomia Clinical Research GmbH
Paul-Gerhardt-Allee 42, 81245 München,
Germany
phone: +49-89-829265-100
data_privacy@metronomia.net
This data privacy statement was last updated on July 1, 2022.