4DMedical Limited ABN 31 161 684 831 and its related bodies corporate, including but not limited to 4DMedical USA Inc., 4DMedical R&D Inc. and Australian Lung Health Initiative Pty Ltd ABN 56 631 802 447 (4DMedical, us, we, our) take your privacy seriously and are committed to responsible privacy practices.
Please read the following privacy policy (Privacy Policy) to understand how we collect, use, disclose, store, handle and protect your personal information. We seek to comply with relevant laws, including the Privacy Act 1988 (Cth) (Privacy Act) and the EU General Data Protection Regulation (GDPR), where applicable. We hope that this will help you make an informed decision about sharing personal information with us. As well as applying to our interactions with you, this Privacy Policy also applies to all information collected through this website and any other websites or platforms we operate.
This Privacy Policy sits alongside our Terms of Use, and any other terms and conditions that apply to the products and services we provide to you.
In this Privacy Policy, ‘personal information’ has the meaning set out in the Privacy Act. In general terms, personal information is information (whether fact or opinion) about an individual who is identified or reasonably identifiable from that information or other information combined with that information.
Some types of personal information are classified as ‘sensitive information’ and/or ‘health information’, which are subject to additional protection under the Privacy Act. Sensitive information may include information about your racial origin and health status, and health information may include information about a health-related service you have had or will receive, including test results and appointment details.
The types of personal information we collect about you will depend on the purpose for which the personal information is collected. This can include:
Generally, we will not collect sensitive information about you. However, in certain circumstances, we may collect (intentionally or inadvertently) limited sensitive information about you. For instance, we may collect sensitive information about you where:
Generally, we will not collect sensitive information about you. However, in certain circumstances, we may collect (intentionally or inadvertently) limited sensitive information about you. For instance, we may collect sensitive information about you where:
We collect your personal information directly from you, including when you:
Where it is reasonable and practicable to do so, we will only collect personal information about you from you directly and not from third parties.
In limited circumstances, we may collect personal information about you from:
We may also collect personal information through third parties such as our service providers or through promotional and marketing activities.
Whilst we will always maintain robust privacy practices, we are not responsible for the privacy practices of third parties, including service providers we engage, so you should review their relevant privacy policies to satisfy yourself as to how they protect and handle your personal information.
If you are a commercial customer of 4DMedical, it is your responsibility to ensure that suitable de-identification and re-identification protocols are in place for any clinical data provided to 4DMedical or received from us. 4DMedical works directly with third party vendors, such as Laurel Bridge Software, Inc. and Kailo Medical Pty Ltd to provide a packaged solution. However, ultimate responsibility for the privacy and correct operation of these tools rests with the customer and the relevant vendor.
We also use the following technologies to collect technical information and general analytics:
You may disable your web browser from accepting cookies and other tracking technologies used to collect technical information and general analytics when browsing our website. If you do so, you can still access our website, but it may impact your user experience.
In addition to our cookies, certain third parties may deliver cookies to your device for a variety of reasons. For example, we sometimes use various web analytics tools that help us to understand how visitors engage with our website. Any third party links or advertising on our website may also use cookies; you may receive these cookies by clicking on the link to the third party site or advertising. We do not control the collection or use of information by these third parties, and these third party cookies are not subject to this Privacy Policy. You should contact these companies directly if you have any questions about their collection and/or use of information. When linking to any other site, you should always check the relevant website’s privacy policy before providing any personal information.
You may also opt out of targeted advertising by using the links below:
Additionally, you can opt out of some of these services by visiting the Digital Advertising Alliance’s opt-out portal.
If we cannot collect personal information about you, or if you use a pseudonym, we may not be able to provide you with the information or assistance you require. For example, we will not be able to send you information you have requested if you have not provided us with a valid email address or telephone number.
We use your personal information for purposes for which we collect it, including managing our business and providing our products and services to you, including to:
We may also use or disclose your personal information for our administrative, marketing (including direct marketing), planning, product or service development, quality control, survey and research purposes, and for other purposes to which you have consented, or as otherwise permitted or required by law.
Technical information and general analytics is used for the purpose of gauging visitor traffic, trends and delivering personalised content to you while you are using our website, and to improve our website and our products and services.
We may use or disclose your personal information:
We may disclose your personal information to third parties in connection with the purposes described above (see the “How do we use your personal information?” section).
This may include disclosing your personal information to the following types of third parties:
We use third party service providers to provide us with web analytics services, such as Google Analytics. You can read more about how Google uses your personal information here.
If we disclose your personal information to third parties, we will use reasonable commercial efforts to ensure that such third parties only use your personal information as reasonably required for the purpose of disclosure and in a manner consistent with applicable laws, for example (where commercially practical) by including suitable privacy and confidentiality clauses in our agreement with a third party service provider to which we disclose your personal information.
We will only send you direct marketing communications (either through mail, SMS or email), including any news and exclusive offers, promotions, or events, where you have consented for us to do so.
You may opt-out of receiving direct marketing communications at any time by contacting us or by using opt-out facilities provided in the direct marketing communications.
We store your personal information in paper-based files and/or other electronic record keeping methods in secure databases. Personal information may be collected in paper-based documents and converted to electronic form for use or storage (with the original paper-based documents either archived or securely destroyed). We may combine or link personal information we hold about you with other personal information about you from third party sources.
Your personal information may be stored through third party service providers located in Australia, New Zealand, the United Kingdom, the European Union or the United States of America. We may disclose your personal information to overseas recipients, such as to our subsidiaries and service providers located overseas, in order for them to provide their products and services, and to obtain services connected with our business.
New Zealand, the United Kingdom, Switzerland and European Union member countries have data protection laws which protect personal information in a way which is at least substantially similar to the Privacy Act and the Australian Privacy Principles, and there will be mechanisms available to you to enforce protection of your personal information under those data protection laws. In these circumstances, we do not require the overseas recipients to comply with the Privacy Act and the Australian Privacy Principles and we will not be liable for a breach of the Privacy Act or the Australian Privacy Principles if your personal information is mishandled by overseas recipients.
Your personal information may be transferred to recipients located in the United States of America. The United States of America does not have data protection laws as comprehensive as Australia’s, and we will accordingly take commercially reasonable steps to secure a contractual commitment from the recipient to handle your information in accordance with the Privacy Act and the Australian Privacy Principles (except where you are located in the United States). Where you are located in the United States, we will handle your personal information in accordance with the provisions below related to HIPAA, California and other US State privacy laws as applicable.
We implement reasonable measures to protect and safeguard your personal information from misuse, loss, theft and unauthorised access, modification or disclosure.
We maintain physical security over paper and electronic data stores, such as through locks and security systems at our premises. We also maintain computer and network security, for example, we use firewalls (security measures for the internet) and other security systems such as user identifiers and passwords to control access to our computer systems.
However, particularly for electronic data stores and due to the fact that the Internet is inherently insecure, we cannot guarantee the security of transmission of personal information disclosed to us online. Accordingly, you transmit your personal information to us online at your own risk and are encouraged to exercise care in sending personal information via the internet.
Please notify us immediately if you know or reasonably suspect that your personal information has been subject to any data breach, breach of security or other unauthorised activity.
To the maximum extent permitted by applicable law, we exclude all liability (including in negligence) for the consequences of any unauthorised access to, modification of, disclosure of, misuse of or loss or corruption of any personal information. Nothing in this Privacy Policy restricts, excludes or modifies or purports to restrict, exclude or modify any statutory consumer rights under any applicable law, including the Competition and Consumer Act 2010 (Cth), the GDPR, or any liability which cannot be excluded due to the operation of applicable laws.
Generally, we will retain your personal information for the period necessary for the purposes for which your personal information was collected (as outlined in this Privacy Policy) unless a longer retention period is required by law or if it is reasonably necessary for us to comply with our legal obligations, resolve a dispute or maintain security.
You may request access to any personal information we hold about you at any time by contacting us as described in the “How to contact us” section below. We will provide access to that information in accordance with the Privacy Act, subject to any exemptions that may apply. We may charge an administration fee in limited circumstances, but we will let you know in advance if that is the case.
If you believe that personal information we hold about you is incorrect, incomplete or inaccurate, then you may request us to amend it by contacting us as described in the “How to contact us” section below. Where we agree that the information needs to be corrected, we will update it. If we do not agree, you can request that we make a record of your correction request with the relevant information.
You can also ask us to notify any third parties that we provided incorrect information to about the correction. We’ll try and help where we can – if we can’t, then we’ll let you know.
If you have any questions, concerns or complaints about our collection, use, disclosure or management of your personal information, you may contact us as described in the “How to contact us” section below.
We are committed to resolving any complaints reasonably and to ensuring that we are doing the right thing by our customers. We will make all reasonable inquiries and your complaint will be assessed with the aim of resolving any issue in a timely and efficient manner.
If you consider your concerns have not been resolved satisfactorily by us, or you have concerns regarding the way we handle your personal information, you can contact:
If you are located in the European Union, you may have the following rights:
We may ask you to provide suitable identification when you seek to exercise any of these rights.
In certain cases we may process your personal information in connection with services provided to your health care provider. In such a case, if you are a resident of the United States, your personal information may be treated as “protected health information” subject to the protections of the Health Insurance Portability and Affordability Act (HIPAA). In such cases, we act as a business associate to the health care provider and will comply with the requirements of HIPAA with respect to your protected health information. Any requests relating to your protected health information in connection with such a service through your health care provider should be directed to your health care provider in the first instance.
If you are a resident of California, you may have the following rights under the California Consumer Privacy Act and California Privacy Rights Act (California Privacy Laws):
We may not discriminate against you because of your exercise of any of the foregoing privacy rights, or any other rights under the California Privacy Laws.
You can make a request under California Privacy Laws by contacting us as described in the “How to contact us” section below. As required or permitted under applicable law, please note that we may take steps to verify your identity before granting you access to information or acting on your request to exercise your rights, which may include your name, email address, and residence address. If we believe we need further information to verify your request as required by law, we may ask you to provide additional information to us. We may limit our response to your exercise of the above rights as permitted under applicable law.
As a California resident, you also have the right to designate an agent to exercise these rights on your behalf. We may require proof that you have designated the authorized agent to act on your behalf and to verify your identity directly with us.
We collect the following categories of personal information from California residents for the following business purposes:
Identifiers, Personal information described in California Civil Code § 1798.80(e), Commercial information, including records of products or services purchased, Characteristics of protected classifications under California or US federal law, such as demographic information like age, race or gender, Internet or other electronic network activity information, Audio, electronic, visual, thermal, olfactory, or similar information; professional or employment-related information, and education information:
Sensitive personal information. We may collect this category of information in providing services from our customers, but such information will generally be covered by HIPAA and exempt from the California Privacy Laws. We may also collect such information from job applicants and employees in processing job applications and managing the employment relationship, but do not infer characteristics based on such information.
We do not share personal information with third parties for their own direct marketing purposes, unless you give us permission to do so. When we give you notice, and you consent, we will share your personal information as you direct us to.
Where local laws allow for an exemption to compliance with certain legal obligations, we may rely on such an exemption.
This Privacy Policy will not apply to the extent that it is inconsistent with any applicable law.
If you have a query, concern or complaint about the manner in which your personal information has been collected or handled by us or would like to request access to or correction of the personal information we hold about you, please contact us using the details provided below:
Data Privacy Officer
4DMedical
Online: https://4dmedical.com/privacy/
Email: dpo@4dmedical.com
We may change or update this Privacy Policy from time to time to keep up-to-date with legal requirements and the way we operate our business. An up-to-date version of this Privacy Policy is available at any time on this page. You are responsible for reviewing this Privacy Policy periodically and informing yourself of any changes. We suggest that you check back regularly. If we make significant changes to our Privacy Policy, we will seek to inform you by notice on our website or by email.
Last updated: 14 August 2023