Last Reviewed: 20/07/2022
Introduction
Mediccom is a healthcare society made to bring together students from around the UK, however for the moment in Cardiff, Wales. Students provide to this as they make presentations in their own groups and present in front of a group of many people, ranging from fellow students to charity representatives. We seek opportunities to support aspiring medical students allowing them to garner the skills for their career path whilst persevering through working in a multi-disciplinary team. Mediccom is a non-profit platform, and hence we do not receive or require payment in any way.
Our registered members (each 'member' that has chosen to fill out a registration form), share their professional identities, engage with their network, exchange knowledge and professional insights, post and view relevant content, learn and find career opportunities. Content and data on some of our Services is viewable to non-members (“Visitors”).
We use the term "Cardiff-wide" to represent schools from different areas around Cardiff.
Services
This Privacy Policy, including our Cookie Policy applies to your use of our Services.
This Privacy Policy applies to mediccomsociety.com, Mediccom events, Mediccom-related sites, communications (“Services”), including off-site Services, such as our webinars on YouTube, posters and other electronic publications, but excluding services that state that they are offered under a different privacy policy.
Data Controllers and Connecting Parties
If you are a member of Mediccom Society, admins at Mediccom will be the controller of your personal data provided to, or collected by or for, or processed in connection with our Services; you are entering into the User Agreement with Mediccom.
As a Visitor or Member of our Services, the collection, use and sharing of your personal data is subject to this Privacy Policy (which includes our Cookie Policy and other documents referenced in this Privacy Policy) and updates.
Change
Changes to the Privacy Policy will be made aware after the effective date of implementation. We at Mediccom are able to change the Privacy Policy , and provide notice to members of the society through the services or other means. If one may object to these changes they can e-mail us at mediccomhealthcaresoc@gmail.com. You can do this at any time, and personal information or data that we hold for you will be erased within 28 days.
You acknowledge that your continued use of our Services after we publish or send a notice about our changes to this Privacy Policy means that the collection, use and sharing of your personal data is subject to the updated Privacy Policy.
Data We Collect
1.1 Data Provided
You provide data through the use of our Registration form on the home page of the Website (www.mediccomsociety.com). In the course of completing this registration form, you have the option to provide information about yourself as personal data which includes: Name, Surname, E-mail Address, place of study and Age (Not Date of Birth). We at www.mediccomsociety.com are the ‘data controller’ for this information, which means we decide how to use it and are responsible for looking after it in accordance with the General Data Protection Regulation and associated data protection legislation. If necessary, we may use your data to reply to you about the feedback you have provided and the processing of your data will be done on the basis that you have given us your consent to do so, by choosing to supply your contact details. You can withdraw your consent at any time by contacting us at aryanc.mediccom@gmail.com, namitha.mediccom@gmail.com or the admin at mediccomhealthcaresoc@gmail.com. You do not have to provide additional information such as social media handles as it does not follow suit to the 'required' sections of the forms. Information that you have shared from Mediccom about your sensitive personal information through the use of our social media platforms will still be present even after your data is deleted from our databases. It must be noted that this information may have been re-shared elsewhere which is beyond our control. Mediccom does not take responsibility for this.
Posting and Uploading
We collect personal data from you when you provide, post or upload it to our Services, such as when you fill out a form, respond to a survey, or submit an application to nominate your school etc. This is done through YouTube for events, and we ask explicit consent in the forms for recordings and usage on the website and hence online. Mediccom is not liable for any personal sensitive data shown on the google meet recording such as full name on google account (which can be changed as to the user's wishes), profile picture, and camera usage. Nevertheless, all attendees must give their consent before providing such information. Guest speakers and Judges must also give their consent in a separate form to the students.
You don’t have to post or upload personal data; though if you don’t, it may limit your ability to grow and engage with your network over our Services.
1.2 Data From Others
You and others may post content that includes information about you (as part of articles, posts, comments, videos) on our Services such as on YouTube comments or Instagram posts, on the discord server or as part of the event as a whole. Customers and partners may provide data to us.
Partners
We receive personal data about you when you use the services of our customers and partners, such as your schools, universities etc.
Related Companies and Other Services
We never share your personal data with third parties. We will chose to make you aware of such third party offerings if they were to come in the future, having explicit consent from yourself to be 'opted in'.
1.3 Service Uses
We log your visits and use of our Services.
We log usage data when you visit or otherwise use our Services, including our sites, such as when you view or click on content (e.g., learning video), perform a search, finalise a PBL presentation or make comments/questions on third party software that relate to our event, such as Google Meet or Slido. We use log-ins, cookies, device information and internet protocol (“IP”) addresses to identify you and log your use.
1.4 Cookies and Technology
Some or all of the cookies described below may be stored in your browser. To manage how cookies are used, you can refuse the use of certain cookies through your Google personalization settings anytime by visiting g.co/privacytools. You can also manage cookies in your browser (though browsers for mobile devices may not offer this visibility). For example, if you use Google Chrome as your browser, you can visit chrome://settings/cookies. Learn more at https://policies.google.com/technologies/cookies?hl=en-US. We do this in order to identify your device on, off and across different Services and devices. We also allow some others to use cookies as described in our Cookie Policy. You can control cookies through your browser settings and other tools. You can also opt-out from our use of cookies and similar technologies that track your behaviour on the sites of others for third party advertising.
1.5 Partners
When your employer, university or school is in contact with Mediccom, they can give us data about you.
Others using our Services, such as your employer or your school, provide us with personal data about you and your eligibility to use the Services that they purchase for use by their workers, students or alumni. For example, we will get contact information for you if your school has registered you for an event and we need your email address to send you event venue details. Generally, students are able to register themselves, regardless of school intervention, however any collaboration with schools will be relevant towards you and your details. Schools are generally just a way for Mediccom to relay information from admin to pupils, and a mid-point in order to make schools aware of student collaboration and student safety.
Charities are a fundamental part of Mediccom. Although we support the charities that attend the event, we do not endorse them, and hence Mediccom does not take responsibility for anything demonstrated by these charities. Furthermore, any donations made to the charities are made straight to the charity, not being through Mediccom whatsoever. Mediccom committee are only responsible for raising awareness and attempting to garner donations for the charities in order to support a cause that means something. Additionally, any NHS partners are not endorsed by us, but only act as a source of guidance and support.
2.1 Services
We use your data to authorize access to our Services. It is your choice whether you invite someone to use our services and be a part of the Mediccom Society.
Unsubscribing
Visitors have choices about how we use their data. For example if you wish to unsubscribe:
Unsubscribe from admin at Mediccom Emails: Mediccom uses email addresses to keep you informed of upcoming events, relevant opportunities provided by third parties and partners that we work with if we feel that it is directly relevant to you. To unsubscribe, simply reply to Mediccom email communication stating that you would like or unsubscribe and your personal data will be erased from our databases.
Stay Informed
Mediccom society applicants are able to demonstrate their professional skills at the event, and ameliorate researching in groups. Research will have to be cited by groups and done professionally in order to exclude false-information or any plagiarism. Mediccom does not warrant any of the claims made by individuals that use the platform, and mentions our role in Disclaimers.
Productivity and Collaboration
We provide students with the opportunity to collaborate within their schools . Anything done, such as organisation of group meetings, presentations and discussions will be done amongst schools without the input of Mediccom. Mediccom does not endorse the presentations shown on the platform, but only provides the platform to do so.
2.2 Events
We allow students to register for the events running on a regular basis, in order to receive emails that hold the Google Meet webinar link, and convey relevant information to those members that are willing to make a PBL group. Each student is free to choose whether they consent to having their video on or off during their presentation, and is free to choose whether their name is available on the Google Meet call. Recordings for the event will be hosted on the website, and any previous presentations from students will be copied and collected and added to the website in order to fill up the library of events that have been hosted by Mediccom, to prevent any changes consequent of the event. We do not endorse any third-party sources of information that are displayed on the website, including previous PBL presentations and recordings of the event. Mediccom provides a platform for these things to occur. Any data shared is data that is already made public through your consent. You have control over whether you want to have this data public or not when registering for a space. If you decide to opt out from a video/post that is already public, we can re-edit the video if possible to remove this, blur out and photography and delete any posts. Furthermore, If you would like to request your data by GDPR regulations we will deliver to your request, and publish all the data that we have collected on you at your personal email account. All Guest Speakers are required to fill out a consent form.
2.3 Communications
We use G-suite and G-mail, to send mail to participants that are listed on a google sheets with all the data we collect from the google forms. We will communicate with society members by Gmail, notices posted on the website, We will send you messages about the availability of our Services, security, or other service-related issues. You may change your communication preferences at any time, by getting in touch with us at . Please be aware that you cannot opt-out of receiving service messages from us, including security and legal notices. Contact at mediccomhealthcaresoc@gmail.com.
2.4 Marketing
We use Google Analytics to track retention and viewership on the website. We do not host any advertising, or share data with any third party organisation, only using google as our forms of communication and marketing.
2.5 Developing Services
We develop our services through the use of your feedback from surveys that we send out to you. You are not obligated to respond to these emails, but it would be helpful for us to improve your Mediccom experience with, and engage on what topics you believe are most important to be highlighted in the next sessions.
2.6 Training and Support
All Mediccom admins are trained with GDPR awareness and will handle your data. Only Mediccom admins trained in GDPR will use your data compliantly. The GDPR sets out the key principles that all personal data must be processed in line with:
Data must be: processed lawfully, fairly and transparently; collected for specific, explicit and legitimate purposes; limited to what is necessary for the purposes for which it is processed; accurate and kept up to date; held securely; only retained for as long as is necessary for the reasons it was collected. There are also stronger rights for individuals regarding their own data: The individual’s rights include: to be informed about how their data is used, to have access to their data, to rectify incorrect information, to have their data erased, to restrict how their data is used, to move their data from one organisation to another, and to object to their data being used at all.
2.7 Aggregate Insights
We use data from surveys in order to evaluate changes and small implementations to make the next session as inclusive and educational for new members as possible. We anonymise all data, and can present this data as pie charts or graphs on our platforms.
2.8 Security Violations and Responsibility
We use data for security, fraud prevention and investigations.
We use your data (including your communications) if we think it’s necessary for security purposes or to investigate possible fraud or other violations of our User Agreement or this Privacy Policy and/or attempts to harm our Members or Visitors. Furthermore, we have moderators on our discord server that are responsible for banning individuals that do not comply with our Terms of Service.
We implement security safeguards designed to protect your data, such as HTTPS. We regularly monitor our systems for possible vulnerabilities and attacks. However, we cannot warrant the security of any information that you send us. There is no guarantee that data may not be accessed, disclosed, altered, or destroyed by breach of any of our physical, technical, or managerial safeguards.
How we share information
3.1 Our Services
Any form of content of data that you post on our services such as Discord, YouTube, Instagram (e.g. comments, likes, follows, shares, profile names and profile photos) will be seen by others.
Posts, Likes, Follows, Comments, Messages
Our Services enable the viewing and sharing of information via posts, likes, follows and comments. If you publicly share a post related to Mediccom (e.g an update, picture, video or article) it can be viewed by everyone and re-shared anywhere. In a group server, posts and messages will be visible to others, as well as the committee, in the group. Your profile name (and photo if you have provided one) will be visible to other users. If we do not agree with or support the "social action" you have carried out, the Mediccom Team can consult you requesting that you delete it. This includes posts with sensitive information, comments with sensitive information, and inappropriate comments on our posts.
When you like or re-share and tag or comment on a post, others will be able to view these "social actions" and associate it with your account (e.g. you name, profile and photo if you provided it)
When you follow a person or organisation, you are visible to others and that “page owner” as a follower.
Links to each of the media platforms are as follows - Discord Terms of Service, Instagram Terms of Service
3.2 Services Providers
Mediccom uses Gmail accounts to send and receive emails between members and the committee and therefore some personal data is stored on Gmail servers as a result. Google has taken measures towards being GDPR compliant and Mediccom is not responsible for GDPR-related issues affecting Google or Gmail. Mediccom also uses OBS software to record video meet sessions and presentations.
3.3 Legal Disclosure
We may need to share your data when we believe it is required by law or to help protect the rights and safety of you, us or others.
It may be that we disclose information about you when required by law, subpoena, or other legal process or if we have a good faith belief that disclosure is reasonably necessary to (1) investigate, prevent, or take action regarding suspected or actual illegal activities or to assist government enforcement agencies; (2) enforce our agreements with you, (3) investigate and defend ourselves against any third-party claims or allegations, (4) protect the security or integrity of our Service. We attempt to notify Members about legal demands for their personal data when appropriate in our judgment, unless prohibited by law or court order or when the request is an emergency. We may dispute such demands when we believe, in our discretion, that the requests are overbroad, vague or lack proper authority, but we do not promise to challenge every demand.
3.4 Changes in Control
We might have to share your data when/if Mediccom is passed on to another committee but it will always be GDPR-compliant and in accordance with this Privacy Policy and Terms of Service. Any other entity which becomes a part of our society will have the right to continue to use to your data, but only in the matter set out in this Privacy Policy unless you agree otherwise.
Your Rights and Actions
4.1 Rights to your own Personal Data
You have access to you personal data and can delete your personal data. You have many choices about how your data is collected used and shared. We provide the following choices about the collection, use and sharing of your data:
Delete Data: You can request for us to delete all or some of your personal data by putting this in writing to us via our email mediccomhealthcaresoc@gmail.com.
Change or manage data: You can edit some of your personal data by asking us to fix or update your data also by emailing us at mediccomhealthcaresoc@gmail.com in certain cases such as if it is inaccurate.
Limit or restrict our use of your data: You can ask us to stop using all or some of your personal data. With regards to YouTube and Instagram, we will be obliged to take down any posts containing your data from our account however It must be noted that this information may have been re-shared elsewhere which is beyond our control. Mediccom does not take responsibility for this.
Access Data by Request: You can ask for a copy of your personal data via email.
Members and committee members can make this request via our email mediccomhealthcaresoc@gmail.com. You may also contact us using the contact information in our website or contact tab footer .
4.2 Data Storage and Retention
We retain data as long as you are a member of Mediccom, on the mailing list and in events. This includes data explicitly stated in forms and implicitly shown from your use in our services.
4.3 Deleting Stored Data
We retain your personal data even after you have opted out of the mailing list, if reasonably necessary to comply with our legal obligations (including law enforcement requests), meet regulatory requirements, resolve disputes, maintain security, prevent fraud and abuse, enforce our User Agreement. We will retain de-personalized information after your account has been closed such as statistics and polls. We generally delete the email from our mailing list, and explicit personal data within 24 hours, however, implicit data such as recordings and pictures may take around 30 days.
4.4 Lawful Processing Services
We will only collect data where consent has been directly displayed, and explicitly given such as the Mediccom mailing list with 2 consent requests, and before the start of each recording which in itself is a call for indirect consent by staying in the session event even despite us, the hosts, repetitively mentioning whether the recording is live or not. All shared links of the google meet is followed with a short disclaimer about the fact each session is lively recorded. Some data may come under "legitimate interest". This falls into data that can enable us to enhance our services and communication, prevent fraud, enhance network security, understand how people interact with our websites, provide postal communication and determine the effectiveness of advertising campaigns from Mediccom. At any time you can withdraw consent to process sensitive data, and where we rely on legitimate interests at our email mediccomhealthcaresoc@gmail.com.
Contact Information
If you have questions or complaints regarding this Policy, please first contact Mediccom through the admin email: mediccomhealthcaresoc@gmail.com. If contacting us does not resolve your complaint, you can contact the EU Data Protection Authorities. Contact us