General Data Protection Regulation (GDPR) Policy
The Journal of Rheumatology Publishing Company Ltd. (hereinafter “The Journal”, “we”) is a publishing company based at 365 Bloor Street East, Suite 901, Toronto, Ontario, Canada, that publishes a monthly international serial featuring peer-reviewed research articles on clinical subjects from scientists working in rheumatology and related fields. The Journal of Rheumatology was founded in 1974 and is published every month, both in print and online.
You can contact us at:
365 Bloor Street East, Suite 901
Toronto, ON M4W 3L4 CANADA
Phone: 416-967-5155
Fax: 416-967-7556
Email: jrheum@jrheum.com
This Privacy Policy details how we are processing personal data, including personal data of individuals in the European Union (EU), the European Economic Area (EEA), and the United Kingdom (UK) when they interact with our services.
In principle:
Collects, uses, and stores the minimum amount of personal data that is necessary for one or more legitimate business purposes and to comply with legal obligations.
Limits who has access to the personal data in our possession to only those who need it for a legitimate business purpose.
Protects personal data through physical and technical security measures tailored to the sensitivity of the personal data we hold.
Communicates with our employees, customers, suppliers, business partners, and others about how we intend to use personal data in our day-to-day operations.
Takes reasonable steps to ensure your personal data are accurate and up to date.
Integrates privacy into the design of our activities and projects that involve the use of personal data.
If you are based in the EU, EEA, or the UK and you are interacting with The Journal in the context of us providing services or goods to you, or we are monitoring your use of our services, then the related processing of your personal data is governed by the General Data Protection Regulation (GDPR) and its implementing national laws. We are controller of the processing of your personal data. If you have any questions or inquiries, contact us at jrheum@jrheum.com.
Types of Information Collected
We recognize personal data as any information related to an identified or identifiable individual. Depending on the context of your interactions with The Journal, we collect and use different types of personal data from website visitors, subscribers, and others who interact with us:
Subscription accounts on our website: Name, email address, full mailing address, country of residence, professional affiliation, information to verify applications for subscription.
Marketing activities: Email addresses and information about the interaction with our communications (such as IP addresses, click-through data). We may also send surveys and collect various responses to these surveys which may include contact and professional information. These surveys may be sent directly from us or from an approved business partner. We do not send independent surveys on behalf of members or third parties.
Videos, audios, and photos: We have a gallery of videos publicly available and some of them include presentations and testimonies of persons who have pre-authorized us to share these artifacts.
Information collected automatically: There is other information that we collect automatically when you visit our site, through the use of cookies or similar technologies, such as your IP address, browser type, access times. See our Cookies Notice for more information.
Why We Process Your Personal Data
The purposes for which we collect and use your personal data may vary depending on the type of relationship you have with us, such as if you are one of our subscribers or a website visitor.
We process personal data of our subscribers when they log into their online accounts for the purpose of managing their subscription and providing them related services.
We process personal data in the context of article/abstract submissions for the purpose of publication of research in the field of rheumatology.
We process personal data of participants to our events for the purpose of organizing the event.
We may process personal data in the context of marketing activities for the purposes of marketing our services and of communicating with our subscribers. To keep our subscribers and others who interact with The Journal informed of our activities, services, and news pertaining to the rheumatology field, we may send out certain marketing emails and publications with their consent. To better serve our constituents’ needs and target communications to their preferences, we collect information about their use of these communications.
We process personal data in the context of the gallery of videos, audio recordings, and photos that we maintain, for the purposes of informing the public about rheumatology-related research.
We process personal data collected through cookies placed by our website to support the operation of our website and to analyze the traffic patterns on our site. See our Cookies Notice for more information.
Our Policy Towards Children
Our services are not directed to children.
Disclosures to Third Parties
At times, The Journal engages third party contractors, service providers, and other vendors to help us accomplish our business objectives. There are other circumstances where we are required by law to disclose personal data to third parties such as public bodies or judicial authorities.
We engage with our agents, representatives, contractors, service providers, or other third parties for the following services:
Authorization of credit card transactions (based in CANADA),
Order fulfillment (based in CANADA);
Cloud storage [based in the United States (US)];
Email blasting (based in the US);
Mailing services for our journals;
Surveys for The Journal’s research purposes.
If the engagement involves the transmission of personal data, we require the service provider to treat that data in accordance with this Policy. A contract to protect the personal data is executed before any data are disclosed, if that vendor will process personal data of individuals in the EU, EEA, or the UK on our behalf.
The Journal may also disclose information in special cases when it has a good-faith belief that such action is necessary to: (a) conform to legal requirements or comply with legal process; (b) protect and defend our rights or property; (c) enforce The Journal’s policies regarding online privacy, internal and external linking, and copyright; or (d) act to protect the interests of our users or others.
Occasionally The Journal may be required by law enforcement or judicial authorities to provide personally identifiable information to the appropriate governmental authorities. We will disclose such information upon receipt of a court order, subpoena, or to cooperate with a law enforcement investigation. The Journal reserves the right to report to law enforcement agencies any activities that we in good faith believe to be unlawful.
Your European Privacy Rights
If you reside or otherwise find yourself in the European Union, the European Economic Area (EEA), or the UK, The Journal is committed to processing your personal data lawfully and facilitating the exercise of your rights granted by the European data protection law. You can contact us at any time to discuss your privacy concerns.
Legal basis for data collection and use: we only collect and use personal data when there is a fair and legal basis for its collection and use and/or when you have consented to our collection. For example, we collect personal data because it is necessary to become a subscriber, to meet our legitimate interests to send marketing material, or to comply with legal obligations. See below the legal basis for each collection:
Subscription information and payment details: Collection is based on the necessity to enter into, or for the performance of, a contract and to provide you subscription services and process or receive payments;
Account management and cookies: Collection is based on our legitimate interest in facilitating access to different services to our subscribers, and to analyze traffic patterns.
Publications of articles and submissions: We publish research in the field of rheumatology submitted by health professionals, based on our legitimate interest in advancing research to improve the health of people with rheumatic diseases.
Marketing activities: Collection is allowed where you provide consent for email marketing, and collection for marketing conducted other than through email or phone call is based on our legitimate interests;
Gallery of videos, audios, and photos: Collection is allowed where you consent.
Privacy Rights under the European Regulation
Transparency and the right to information: We provide notice to our subscribers, website users, and other third parties who interact with us about how we use personal data in our day-to-day activities at the time of collecting personal data, or as soon thereafter as possible. We also publish this privacy notice for greater transparency.
Right to access, rectification, restriction of processing, erasure, and data portability: If you are based in the EEA or the UK, we provide you with access to your own personal data. In addition, when requested in writing by you, we will rectify any errors in your personal data when it is incorrect or inaccurate, and we will ensure the right to erasure, portability, and to restriction of processing when these rights are not incompatible with other legal obligations.
Right to object and withdraw consent at any time: For all marketing materials, you can opt out any time and free of charge. The right to object for other processing activities will be balanced to ensure that it is not incompatible with local regulations or our legitimate interests.
These Requests Should be Submitted as Follows
Opt out of marketing communications: You can exercise your right to object and opt out any time by following the opt out instructions in our commercial emails, by logging into your Journal account and changing your communication preferences, or contacting us at jrheum@jrheum.com. You will continue to receive emails relevant to subscription purchases. If you believe that SPAM has been sent from us, please contact us at jrheum@jrheum.com so that we can investigate and rectify the situation.
To exercise the rest of your rights: You should send communication in writing to jrheum@jrheum.com. To fulfill this request, we may require you to provide us information to validate your identity and specify your request. We will attend to your request in a timely manner within 30 days after receiving your request. If for any reason we need to extend this period of time, we will contact you.
If you are not satisfied with our response, you have the right to lodge a complaint with the supervisory authority of your habitual residence, place of work, or place of the alleged infringement.
International Transfers of Personal Data
If you are located outside CANADA and you interact with our website or provide us personal data, then your personal data may be transferred to CANADA.
We transfer your personal data to CANADA whenever you interact with us. CANADA has not sought or obtained adequacy status from the EU. The EU-US Privacy Shield framework obtained an adequacy decision. The level of protection of your personal data is not deemed equivalent to the one in the EU, unless the receiving organization is self-certified under the EU-US Privacy Shield. We are not able to adhere to the EU-US Privacy Shield Principles.
We transfer your personal data on the basis of the derogations in Article 49 GDPR, particularly:
Explicit consent, for newsletter subscribers and certain processing in relation to organizing events, such as storing photos;
Necessity to enter and for the performance of a contract for subscription information; to provide services including when logging in to member accounts; and also for processing personal data for online purchases.
As for safeguards to your personal data, we directly apply the GDPR provisions to your personal data. As a matter of principle, we do not engage in any onward transfers regarding your data, beyond the access that our processors have to your data. We select carefully our processors and we require that they are EU-US Privacy Shield certified, or that they provide equivalent safeguard mechanisms.
Data Security
The Journal is committed to the security, confidentiality, and integrity principle. We take commercially reasonable precautions to keep all information obtained from our online visitors secure against unauthorized access and use and we periodically review our security measures.
We care about the security of your transactions and apply industry-standard practices of like organizations and technologies to safeguard your credit card information. We also use several different security techniques to protect your personally identifiable information from unauthorized access by users inside and outside the organization. The web servers for The Journal are located in a secure environment, and computer systems are maintained in accordance with industry standards of like organizations to secure information. You should be aware, however, that “perfect security” does not exist on the Internet, and third parties may unlawfully intercept or access transmissions of private communications.
This site contains links to other sites. While The Journal strives to link only to sites that share our high standards and respect for privacy, The Journal is not responsible for the privacy practices of other sites.
Retention Periods
The Journal applies the storage limitation principle to retain personal data in our records only for the length of time required to fulfill the purpose for which the data were collected.
We keep personal data in our records only as long as necessary for the purposes they have been processed. The retention period depends on the context in which we process data and on specific circumstances such as regulations requiring retaining information for a certain period of time. These circumstances may include local laws, the reasonably anticipated future business needs for the data, the benefit to the user to have the data available, legal requirements to hold the data, or similar circumstances.
Disclaimer
THE JOURNAL MAKES NO CLAIMS, PROMISES, OR GUARANTEES ABOUT THE ACCURACY, COMPLETENESS, OR ADEQUACY OF THE CONTENTS OF ITS SITE, AND EXPRESSLY DISCLAIMS LIABILITY FOR ERRORS AND OMISSIONS IN THE CONTENTS OF THIS SITE. NO WARRANTY OF ANY KIND, IMPLIED, EXPRESSED, OR STATUTORY, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF NON-INFRINGEMENT, TITLE, MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND FREEDOM FROM COMPUTER VIRUS, IS GIVEN WITH RESPECT TO THE CONTENTS OF THIS WEBSITE OR ITS HYPERLINKS TO OTHER INTERNET RESOURCES. REFERENCE IN THIS WEBSITE TO ANY SPECIFIC COMMERCIAL PRODUCTS, PROCESSES OR SERVICES, OR THE USE OF ANY TRADE, FIRM OR CORPORATION NAME IS FOR THE INFORMATION AND CONVENIENCE OF THE PUBLIC AND DOES NOT CONSTITUTE ENDORSEMENT OR RECOMMENDATION BY THE JOURNAL.
Changes to this Policy
We reserve the right to modify this Privacy Policy at any time. We will duly inform you of any changes.
The Journal may occasionally update this privacy statement and other statements referenced by it as new services and programs are introduced. You will be notified of these changes via jrheum@jrheum.com and/or by a prominent notice on our website. The time stamp you see on the policy will indicate the last date it was revised.
Updated April 17, 2020