Privacy Policy
Hereinafter, we wish to inform you regarding the processing of personal data carried out by NEURO GROUP XR, INC. Through this Privacy Policy we wish to comply with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (hereinafter, the “General Data Protection Regulation” or “GDPR”), as well as any legislation on data protection that applies to us by reason of the territories in which we operate.
The Privacy Policy forms part of the General Conditions governing this website, as well as all those applications, content and tools offered by the data controller.
Responsible for the treatment:
-
Data controller: NEURO GROUP XR, INC.
-
Address: 1000 Rue Saint-Jacques, C.P. H3C 1G7, Montreal - Quebec.
-
VAT NUMBER: 1177329688.
-
Mail: privacy@kinesixvr.com
You can contact us in any way to communicate with us.
We reserve the right to modify or adapt this Privacy Policy at any time. We recommend that you review it periodically to keep up to date. If you have registered and access from your account or profile you will be informed of the modifications.
At the moment, we treat data in different ways and with different types of relationships. Therefore, it is possible that some of these sections apply to you because they are generic and that in others you only need to consult some of their sections. If this is the case, you will only have to go to the subsection that interests you.
What personal data do we process?
We will process the identification and contact data of our clients' representatives for the purpose of managing the contractual relationship we have with the legal entities they represent. In case you are an individual, we will process your identification, contact and financial data only for the purpose of managing the contractual relationship we have with you.
For what purposes will we process your personal data?
-
Elaboration of the budget and follow-up of the same by means of communications between both parts.
-
Information by electronic means, concerning your requests.
-
Commercial or event information by electronic means, as long as there is express authorization or it is within our legitimate interest.
-
Invoicing and declaration of the appropriate taxes.
What is the legitimacy for the processing of your data?
The existence of a contractual relationship between the parties.
For how long will we keep the personal data?
For the duration of the relationship between the parties and, once terminated, duly blocked during the limitation periods arising therefrom.
WEB OR EMAIL CONTACTS
What data do we collect through the Web?
We will process different categories of data depending on the relationship we have with you. We may process your name and contact information to perform the contractual relationship between us. If you are a user, we will process data such as your profile name, password, profile picture, avatar, frequency and duration of game play; we may also process data relating to your physical characteristics and movements in order to provide a more immersive and realistic experience, for example, we will process your height and the pattern of your movements to infer your body position to make your avatar's movements as similar as possible.
We may treat your IP, what operating system or browser you use, and even the duration of your visit, anonymously. If you provide us with data in the contact form, you will be identified so that we can contact you, if necessary.
When we maintain a business relationship with you, we may process your payment methods, such as your credit card number. Similarly, if you are a user of the website we will process the essential cookies of the device from which you access, as well as other cookies that you consent to, in accordance with our Cookies Policy.
For what purposes will we process your personal data?
-
To answer your queries, requests or petitions.
-
Manage the requested service, answer your request, or process your request.
-
Information by electronic means, related to your request.
-
Commercial information or events by electronic means, provided that there is express authorization.
-
Perform analysis and improvements on the Web, about our products and services. Improve our business strategy.
What is the legitimacy for the processing of your data?
The acceptance and consent of the interested party, granted through an affirmative action, as in cases where to make a request is necessary to complete a form and make a “click” on the submit button, the completion of the same necessarily imply that it has been informed and has expressly consented to the content of the clause attached to the form or acceptance of the privacy policy.
All our forms have the symbol * in the obligatory data. If you do not provide these fields, or do not check the checkbox to accept the privacy policy, the information will not be allowed to be sent. It usually has the following formula: “□ I have read and accept the Privacy Policy.”
KINESIXVR USERS
What data do we collect from KINESIXVR users?
At NEURO GROUP, we deeply value your privacy and strive to protect it at all times. When you use our KINESIX system, we want you to be informed that we collect and process personal data, which we do exclusively for the purpose of providing you with a more personalized service and constantly optimizing the quality of our platform.
We offer the option to register and use our system by using initials and/or aliases, thus avoiding the need to enter sensitive personal patient data. In addition, we offer a guest mode that allows you to use the system without saving any personal or training data, ensuring an option of use that fully respects the anonymity and privacy of the user.
This measure, along with the ability to use the system in guest mode, reflects our commitment to ensuring that the data collection process is primarily oriented towards improving our system and enriching the user experience, while maintaining the integrity of your privacy.
Training Data
-
Date
-
Time
-
Repetitions
-
Assessment Metrics
-
Movements (speed, angles, etc.)
Mandatory data for the creation of a user
-
First name or Alias
-
Last name or Initials
Optional data for the creation of a user
-
Personal Data related to your Identity: name, age, sex and laterality.
Contact Information
-
Phone
-
E-mail address
-
Address
Clinical and Performance Data
-
Neurological disease, impairment or need
-
Frequency of treatment, including dates of each session.
-
Type of treatment and exercise, duration, repetitions.
-
Performance in each exercise
Center and Therapist Information
-
Neurological treatment center providing the service, including contact information for that center.
-
Name(s) of the therapist(s) using KINESIX
Device and Connection Data
-
IP address
-
Location data
-
Type of device used
-
Link from which KINESIX is accessed
For what purposes will we treat your personal data?
-
To correctly provide the contracted services. This purpose will include registering you as a user, creating an account, managing the extra services you contract, resolving your requests and, in general, properly executing all actions related to the use and enjoyment of Kinesixvr.
-
To provide evidence and collect information for scientific research, including the publication of academic and scientific studies.
-
Facilitate clinical evaluations, studies and validations.
-
Develop new solutions, systems and services.
-
Statistical and analytical purposes.
-
Collect information about the way you play to improve our products.
-
Manage administrative, communications and logistics services performed by the Responsible Party.
-
Invoicing and declaration of the appropriate taxes.
-
Control and recovery management.
What is the legitimacy for the processing of your data?
The existence of a contractual relationship between the parties. The processing is necessary for the performance of a contract to which the data subject is a party or for the implementation at his request of pre-contractual measures. Our legitimate interest in improving our products and services. Consent to receive personalized information and news.
For how long will we keep personal data?
For the duration of the relationship between the parties and for the limitation periods arising therefrom. We will treat the categories of data legitimized by the consent until you revoke it.
QUALITY SURVEYS
What data will we process?
Your identification data and those data derived from the answers provided in the survey.
For what purposes will we process your personal data?
-
To assess the degree of quality in the service provided.
-
To improve the services offered, in compliance with the ISO.
What is the legal basis for the processing of your data?
The legal basis is the express consent of the respondent.
For how long will we keep the personal data?
Until the revocation of the consent given.
SUPPLIERS
What personal data do we process?
We will process the identification and contact data of the representatives of our suppliers for the purpose of managing the contractual relationship we have with the legal entities they represent.
For what purposes will we process your personal data?
-
Information by electronic means, concerning your request.
-
Commercial or event information by electronic means, as long as there is express authorization.
-
To manage administrative, communications and logistics services carried out by the Responsible.
-
Invoicing.
-
To carry out the corresponding transactions.
-
Invoicing and declaration of the appropriate taxes.
-
Control and recovery management.
What is the legal basis for the processing of your data?
The legal basis is the acceptance of a contractual relationship.
For how long will we keep the personal data?
For the duration of the relationship between the parties and for the limitation periods arising therefrom.
JOB SEEKERS
What personal data do we process?
We will process the data you share with us as part of the selection process or spontaneous application. In general, we will process your identification data, contact data and data relating to your professional and/or academic experience.
For what purposes will we treat your personal data?
-
Organization of selection processes for the recruitment of employees.
-
To summon you for job interviews and evaluate your candidacy.
-
If you have given us your consent, we may pass it on to collaborating or related companies, with the sole purpose of helping you find a job.
-
If you check the checkbox to accept the privacy policy, you give us your consent to transfer your job application to the entities that make up the group of companies in order to include you in their recruitment processes.
We also inform you that after one year from the receipt of your curriculum vitae, we will proceed to its secure destruction.
What is the legal basis for the processing of your data?
The legal basis for the processing is the necessity of the same for the execution of an employment contract, being the selection process a pre-contractual measure.
For how long will we keep the personal data?
For the duration of the selection process or the period determined in case of consent.
OTHER ASPECTS:
Do we include personal data of third parties?
No, as a general rule we only process the data provided by the owners. If you provide us with data of third parties, you must previously inform and request their consent to such persons, otherwise you exempt us from any liability for failure to comply with this requirement.
However, information such as your profile name, user name, profile picture, avatar will be public for other Kinesixvr users. This means that your avatar may appear in photos, recordings or live streams taken and shared by other users who are interacting with or near you.
Will we communicate with you by electronic means?
-
They will only be made to manage your request, if it is one of the means of contact that you have provided us.
-
If we send commercial communications, they will have been previously and expressly authorized by you.
What security measures do we apply?
You can rest assured: We have adopted an optimal level of protection of the Personal Data we handle, and we have installed all the technical means and measures at our disposal according to the state of technology to prevent the loss, misuse, alteration, unauthorized access and theft of Personal Data.
At NEURO GROUP XR, INC we implement state-of-the-art security standards to prevent unauthorized access, maintain data accuracy and ensure the correct use of information. We also apply appropriate organizational measures to protect your data.
We apply these same security standards also when working with business and technology partners. We only select and contract with data processors and third party providers that have adequate security measures in place and offer sufficient guarantees, including technical and organizational measures, to ensure adequate protection of the data we entrust to them in accordance with the GDPR, as well as the various data protection regulations in force in the countries where we operate.
In addition, internally we also ensure that any member of NEURO GROUP XR, INC that will have access to your data has signed a non-disclosure agreement or clause and we have established internal measures and processes such as continuous training and a series of policies that are updated recurrently to ensure data security, as well as the confidentiality, availability and resilience of our systems and services. Among other measures, we emphasize that in NEURO GROUP XR, INC we have defined a management procedure and an incident response plan in case of detecting any vulnerability in our systems and / or that may affect your personal data.
To which recipients will your data be communicated?
Your data will not be disclosed to third parties, unless legally required. In particular, they will be communicated to the State Agency of Tax Administration, banks, financial institutions for the collection of the services provided or products purchased and to the persons in charge of the processing necessary for the execution of the agreement.
In case of purchase or payment, if you choose any application, web, platform, bank card, or any other online service, your data will be transferred to that platform or will be treated in their environment, always with maximum security.
When we order it, the web development and maintenance company, web hosting/hosting, will have access to our website. They will have signed a service contract that obliges them to maintain the same level of privacy as we do.
The information will be stored in the servers of the country and in case of carrying out international transfers, you will be previously informed and will adopt the corresponding measures in terms of data protection corresponding to the country where we develop our activity.
What rights do you have?
-
To know if we are processing your data or not.
-
To access your personal data.
-
To request the rectification of your data if it is inaccurate.
-
To request the deletion of your data if they are no longer necessary for the purposes for which they were collected or if you withdraw your consent.
-
To request the limitation of the processing of your data, in some cases, in which case we will only keep them in accordance with the regulations in force.
-
To submit your data, which will be provided to you in a structured, commonly used or machine-readable format. If you prefer, we can send them to the new person in charge that you designate. This is only valid in certain cases.
-
To file a complaint with the Spanish Data Protection Agency or competent supervisory authority, if you believe that we have not served you properly.
-
To revoke consent for any processing for which you have consented, at any time.
If you change any information, please let us know so that we can keep it updated.
Do you want a form to exercise your rights?
-
We have forms for the exercise of your rights, ask for them by email or if you prefer, you can use the forms prepared by the Spanish Data Protection Agency or third parties.
-
The forms can be submitted in person, sent by letter or by mail to the address of the Data Controller at the beginning of this text.
How long does it take us to respond to the Exercise of Rights?
It depends on the right, but a maximum of one month from your request, and two months if the issue is very complex and we notify you that we need more time.
Do we process cookies?
If we use other types of cookies that are not necessary, you can consult the cookies policy in the corresponding link at the top of our website.
Do we update our Privacy Policy?
In NEURO GROUP XR, INC we reserve the right to modify this Privacy Policy whenever we believe necessary to keep it updated and adapt it to the reality of the development of our products and services, industry standards or new regulations. If such changes are substantial or important, we will do our best to inform you of them.
-