Privacy Policy

1. DATA CONTROLLER

  • Company name: VIRALGEN VECTOR CORE, S.L.U.
  • Tax ID No.: B75181040
  • Registered office: Paseo Mikeletegi, 83, 2nd floor of the San Sebastian Technology Park (Gipuzkoa)
  • Contact email: info@viralgenvc.com
  • Data Protection Officer (DPO): dpo@viralgenvc.com
  • Telephone: +34 943 47 77 33

The Data Controller informs the USER that, in compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data (GDPR), and Organic Law 3/2018 of December 5 on the Protection of Personal Data and guarantee of digital rights (LOPDGDD), it will process their data as described in this Privacy Policy.

2. DATA PROCESSED, PURPOSES, AND LEGAL BASES

Management of professional contacts, inquiries, and business development prospecting (BD):

  • Data processed: identification and professional contact data (first name, last name, company, position, email, country, and state/region) and data regarding corporate interests (type of company, contact area, and services of interest). In the case of specific campaigns, additional data related to the data subject’s research or development project may be collected (disease indication, serotype, development stage, DNA starting material needs, target dates (IND), and financing strategy).
  • Purposes: (i) To handle, route, and respond to inquiries, requests for information, quotations, or technical support; and (ii) To refer the contact to the Business Development (BD) department for follow-up and commercial prospecting regarding our services.
  • Legal basis: for handling inquiries and applying pre-contractual measures, the legal basis is Art. 6.1.b GDPR and the presumption of lawfulness of B2B contact (Art. 19 LOPDGDD and legitimate interest, Art. 6.1.f GDPR). For sending commercial communications and conducting prospecting activities (BD), the legal basis will be the data subject’s explicit consent (Art. 6.1.a GDPR), collected through the checkboxes enabled in our forms.

Real-time assistance management (Live chat):

  • Data processed: identification and contact data (name and email address, if required by the system to start the session), technical session metadata (IP address, user ID), and the full content of communications (transcripts and conversation logs) exchanged with our team or virtual assistants.
  • Purposes: to address and resolve, in real time, any questions, incidents, or inquiries raised by the user while browsing the website. In addition, the conversation history will be linked and integrated into the user’s profile within our CRM (HubSpot) to ensure traceability of the inquiry, optimize follow-up by the Business Development (BD) team, and perform quality controls of the support service.
  • Legal basis: processing to respond to the inquiry is based on the implementation of pre-contractual measures at the request of the data subject (Art. 6.1.b GDPR) and on our legitimate corporate interest in offering an agile and efficient support channel (Art. 6.1.f GDPR). For processing related to commercial prospecting or linking the lead to future marketing campaigns, the legal basis will be the data subject’s explicit consent (Art. 6.1.a GDPR).

Management of applications and recruitment processes:

  • Data processed: information contained in the résumé/CV (academic and professional profile) and data generated during the evaluation stages of the recruitment process.
  • Purposes: assessment of candidates’ suitability for current vacancies or future hiring opportunities.
  • Legal basis: for managing the current application, the implementation of pre-contractual measures (Art. 6.1.b GDPR). For storing the profile in our historical database, the explicit consent given by the data subject when providing their information or registering on our employment portal (Art. 6.1.a GDPR).

Maintenance, security, and protection of the web infrastructure

  • Data processed: technical connection and browsing metadata.
  • Purposes: to ensure the security of the networks and information of our digital assets. This includes monitoring web traffic to detect anomalies, as well as preventing, investigating, and mitigating security incidents (such as denial-of-service attacks—DDoS—unauthorized access, or malicious bot traffic), thereby ensuring the availability, resilience, and integrity of the platform.
  • Legal basis: processing is based on the legitimate interest of the Controller (Art. 6.1.f GDPR), expressly recognized in Recital 49 of the GDPR, as a strictly necessary and proportionate measure to ensure an adequate level of security against digital threats (Art. 32 GDPR). This legitimate interest does not infringe the rights and freedoms of users, as the data is collected at the technical infrastructure level and is not used to profile or directly identify individuals for purposes other than security.

Management of the Whistleblowing Channel (Internal Reporting System):

  • Data processed: identification and contact data of the reporting person (unless they choose to submit an anonymous report), data of the person affected by the information, data of third parties mentioned in the report, and any other information provided to clarify the facts. Incidentally, the report may contain special categories of data (Art. 9 GDPR) or data relating to criminal convictions and offenses (Art. 10 GDPR).
  • Purposes: receipt, management, processing, and investigation of reports concerning possible regulatory, criminal, administrative, or internal policy violations (Compliance), as well as, where applicable, the adoption of the corresponding corrective, disciplinary, or legal measures.
  • Legal basis: processing is necessary for compliance with a legal obligation applicable to VIRALGEN (Art. 6.1.c GDPR) under Law 2/2023 of February 20, regulating the protection of persons who report regulatory violations and the fight against corruption; as well as for the performance of a task carried out in the public interest (Art. 6.1.e GDPR and Art. 24 LOPDGDD). Where special categories of data are processed, the basis will be substantial public interest (Art. 9.2.g GDPR).

3. RETENTION PERIODS

The personal data provided will be retained for the time strictly necessary to fulfill each of the stated purposes, as well as to determine any potential liabilities that may arise. Specifically, we will apply the following retention criteria:

  • Professional contacts, B2B inquiries, and support (including Live chat): data linked to isolated inquiries (contact forms or chat) will be retained for the time necessary to resolve and close the request. If such interaction results in a pre-contractual or contractual relationship, the data will be retained for the duration of that relationship.
  • Business Development (BD) and commercial prospecting: data of leads integrated into our CRM for follow-up and commercial communications will be retained indefinitely until the data subject withdraws consent, exercises their right to erasure or objection, or until the organization determines that the contact has become obsolete due to prolonged inactivity (in application of the principles of data minimization and accuracy).
  • Applications and recruitment processes: résumés/CVs and candidate profiles will be retained during the recruitment process for which they were collected. If the candidate authorized their retention for future vacancies, the data will be retained for a maximum period of one (1) year from receipt or last update. Once this period has elapsed without any update, the data will be securely deleted.
  • Web maintenance and security (Logs/Metadata): security records and technical browsing metadata will be retained for the technically indispensable period required to ensure infrastructure security (generally a maximum of between 6 and 12 months), unless they are linked to the investigation of a specific cybersecurity incident, in which case they will be retained until the investigation is closed or the relevant legal actions are exercised.
  • Whistleblowing Channel: data will be retained in the reporting system only for the time strictly necessary to decide whether to initiate an investigation. In any case, if three (3) months have elapsed since receipt of the report without any investigative actions having been initiated, the data will be deleted from the whistleblowing system (although it may remain outside the system solely to provide evidence of the operation of the prevention model). Reports that are not admitted for processing will be anonymized or immediately destroyed.

Legal blocking of data: once the operational periods described above have ended, VIRALGEN will block the data in accordance with Article 32 of Organic Law 3/2018 (LOPDGDD). During this blocking period, the data will remain available exclusively to Judges and Courts, the Public Prosecutor’s Office, or the competent Public Administrations (in particular, the Spanish Data Protection Agency) to address any potential liabilities arising from the processing. Once the statutory limitation periods for such liabilities have expired, the data will be irreversibly destroyed or anonymized.

4. RECIPIENTS AND INTERNATIONAL TRANSFERS

VIRALGEN VECTOR CORE, S.L.U. will not disclose personal data to third parties, except where there is a legal obligation or a judicial request issued by a competent authority.

Notwithstanding the foregoing, for the proper operation of the web platform and the provision of the requested services, VIRALGEN collaborates with third-party providers (virtual infrastructure services, analytics tools, CRM, and IT support). These entities access the data solely and exclusively as Data Processors, and the corresponding agreements have been entered into to ensure the application of appropriate technical and organizational measures in accordance with Article 28 of the GDPR.

If the provision of these services involves the storage of or access to data from outside the European Economic Area (EEA), VIRALGEN guarantees that such International Data Transfers (IDTs) will be carried out by applying the legally required safeguards (Articles 44 et seq. GDPR), either under European Commission Adequacy Decisions or, failing that, through the execution of current Standard Contractual Clauses (SCCs) and the adoption of any necessary supplementary measures.

In particular, the web platform uses technology services provided by U.S. entities (such as HubSpot, Inc., Google LLC, LinkedIn Corp., and Cloudflare, Inc.). International transfers to these providers are fully legitimate and covered by the EU-U.S. Data Privacy Framework, an adequacy decision adopted by the European Commission to which these entities are certified, thereby ensuring a level of protection of rights and freedoms comparable to the European standard.

With respect to the Internal Reporting System, access to the data will be restricted exclusively to the System Manager and duly authorized personnel with Compliance or investigation responsibilities. The identity of the reporting person will be treated with absolute confidentiality and will under no circumstances be disclosed to the affected person (the reported party). It may only be disclosed to the Judicial Authority, the Public Prosecutor’s Office, or the competent administrative authority in the context of a criminal, disciplinary, or sanctioning investigation.

5. DATA SUBJECTS’ RIGHTS

The user has full control over their personal data and may exercise, before the Controller, their rights of access, rectification, erasure (right to be forgotten), objection, restriction of processing, portability, and the right not to be subject to individual automated decisions (including profiling).

How to exercise rights: the data subject must send a written request to the Data Protection Officer at the following email address: dpo@viralgenvc.com.

Identity verification: in strict compliance with the principles of fairness and processing security, and following the guidelines of the European Data Protection Board (EDPB), additional documentation proving the applicant’s identity (copy of ID card or passport) will only be required where there are reasonable doubts regarding the authenticity of the sender, thereby preventing fraudulent access by third parties.

If the user believes that their rights have been violated, they may file a complaint with the Spanish Data Protection Agency (AEPD) through its electronic office (www.aepd.es).

6. SECURITY MEASURES

The Controller, in accordance with the provisions of the GDPR and the LOPDGDD, has implemented all technical and organizational measures within its reach that are appropriate to ensure a level of security suitable to the risk, protecting personal data against accidental or unlawful destruction, loss, alteration, and unauthorized disclosure or access.