Scope and Identity of the Controller
This Data Protection Notice explains how Michigan Inventors Coalition: Pharma Insights collects, uses, discloses, and safeguards personal data in accordance with applicable United States privacy laws and, where relevant, the principles of the EU/UK General Data Protection Regulation (GDPR). This Notice applies to personal data processed through our website and related services.
Controller: Michigan Inventors Coalition: Pharma Insights, owned and operated by Joe Barnett.
Registered Contact: 15600 NE 8th St, Bellevue, WA 98008, United States.
Contact Email: [email protected]
Effective Date: 2025-09-01
Categories of Personal Data We Process
- Identification and contact details: name, email address, postal address, organization, and similar identifiers you submit through forms or correspondence.
- Account and preference data: credentials (hashed), communication preferences, newsletter subscriptions, saved settings.
- Content you provide: inquiries, feedback, survey responses, and any information voluntarily submitted in free-text fields.
- Usage and device data: IP address, device identifiers, browser type, operating system, referring URLs, pages viewed, time and date of visits, and clickstream data.
- Cookie and similar technology data: identifiers, consent preferences, and information associated with cookies, pixels, local storage, and similar tools.
- Professional information: role, specialty, or affiliation if you choose to provide it in the context of our professional resources.
- Sensitive data: We do not seek to collect sensitive personal information (e.g., health information) through this website. Please do not submit such data unless explicitly requested for a defined purpose with appropriate disclosures and consent.
Sources of Personal Data
- Directly from you when you complete forms, subscribe to communications, or contact us.
- Automatically from your device and browser during site visits.
- From service providers that support our operations (e.g., analytics or email delivery) in accordance with this Notice.
Purposes and Legal Bases for Processing
Purposes
- To operate, maintain, and improve our website and services.
- To respond to inquiries, provide requested information, and offer customer support.
- To send administrative messages and, where permitted, newsletters or research updates.
- To conduct analytics, measure audience engagement, and develop content.
- To protect our services, prevent fraud, and ensure network and information security.
- To comply with legal obligations and enforce terms.
Legal Bases (for GDPR-relevant processing)
- Consent: for optional cookies, marketing communications, and any processing requiring consent.
- Legitimate interests: to secure and improve services, prevent abuse, and understand site usage in a privacy-preserving manner.
- Contractual necessity: to provide services or resources you request.
- Legal obligations: to meet recordkeeping, compliance, and regulatory requirements.
Cookies and Similar Technologies
We use cookies and similar technologies to provide essential site functionality, remember preferences, and perform analytics. Where required by law, we obtain your consent before setting non-essential cookies and record your choices.
- Strictly necessary cookies: enable core features and security; cannot be disabled in our systems.
- Functional cookies: remember preferences and enhance user experience.
- Analytics cookies: help us understand usage and improve content and performance.
- Advertising or cross-context behavioral cookies: not used unless expressly stated and consented to.
You can manage cookie preferences via browser settings and, where available, our consent tools. You may withdraw consent at any time, which will not affect the lawfulness of processing based on consent before withdrawal.
Analytics, Advertising, and Cross-Context Behavioral Advertising
We may use third-party analytics to measure and improve site usage. We do not sell personal information and do not share personal information for cross-context behavioral advertising as defined under applicable U.S. state privacy laws. If this practice changes, we will update this Notice and provide required opt-outs.
We honor recognized browser-based opt-out signals, such as Global Privacy Control (GPC), to the extent required by applicable law.
Data Sharing and Disclosure
- Service providers (processors): We share personal data with vetted vendors who perform services on our behalf under contracts that require confidentiality and limit processing to our instructions.
- Legal and compliance: We may disclose information to comply with applicable law, legal process, or lawful requests, and to protect rights, safety, and security.
- Business transactions: In the event of a reorganization, merger, or transfer, personal data may be transferred subject to continued protection consistent with this Notice.
- Aggregated or de-identified data: We may share aggregated information that does not identify individuals.
International Data Transfers
Our services are operated in the United States. If you access our services from outside the United States, including the EEA, UK, or Switzerland, your personal data may be transferred to and processed in the United States and other jurisdictions that may have different data protection standards.
Where GDPR or similar laws apply, we use appropriate safeguards for international transfers, such as European Commission-approved Standard Contractual Clauses and supplementary measures where necessary.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes outlined in this Notice, comply with legal obligations, resolve disputes, and enforce agreements. Illustrative periods include:
- Inquiry and correspondence records: up to 24 months after last interaction.
- Newsletter subscription data: until you unsubscribe or your subscription becomes inactive, plus a reasonable period to comply with opt-out requirements.
- Web server logs and security records: typically 12 months, unless longer retention is required for security or legal reasons.
- Analytics data: generally up to 24 months in aggregate form.
Security
We implement appropriate technical and organizational measures designed to protect personal data, including encryption in transit, access controls, least-privilege policies, and regular review of vendor security. No method of transmission or storage is entirely secure, and we cannot guarantee absolute security.
Your Rights
EU/UK GDPR Rights (where applicable)
- Access your personal data and obtain a copy.
- Rectify inaccurate or incomplete personal data.
- Erase personal data where permitted by law.
- Restrict or object to processing, including objection to processing based on legitimate interests or for direct marketing.
- Data portability for information you provided to us.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with a supervisory authority. Please contact us first so we may address your concerns.
U.S. State Privacy Rights
Depending on your state of residence (e.g., California, Colorado, Connecticut, Utah, Virginia), you may have the right to:
- Know and access the categories and specific pieces of personal information we collected about you.
- Request deletion of personal information, subject to exceptions.
- Correct inaccuracies in personal information.
- Receive personal information in a portable format.
- Opt out of sales or sharing of personal information for cross-context behavioral advertising (we do not sell or share as defined by law).
- Limit the use and disclosure of sensitive personal information (we do not use sensitive personal information to infer characteristics).
- Be free from unlawful discrimination for exercising your privacy rights.
How to Exercise Your Rights
You may submit a request by emailing [email protected]. We will verify your identity using information you provide and records we maintain. Authorized agents may submit requests on your behalf where permitted by law, subject to verification of agent authority and your identity. We will respond within the timeframes required by law (generally 45 days, with a permissible extension where reasonably necessary). If we deny a request, you may have the right to appeal; instructions will be provided in our response where applicable.
Children’s Privacy
Our services are intended for a general audience and are not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, please contact us to request deletion. For visitors in the EEA/UK, we do not knowingly process data from children under the age of consent applicable in your country without appropriate authorization.
Automated Decision-Making and Profiling
We do not engage in automated decision-making that produces legal or similarly significant effects concerning individuals. Any profiling for analytics is limited to improving site content and performance and does not produce such effects.
Do Not Track and Global Privacy Control
Some browsers transmit Do Not Track (DNT) signals. Our services do not currently respond to DNT. We process recognized Global Privacy Control (GPC) signals as an opt-out of certain processing where legally required.
Notice at Collection for California Residents
Categories Collected
- Identifiers (e.g., name, email address, IP address, online identifiers)
- Internet or network activity (e.g., browsing history on our site, interactions with pages)
- Geolocation data (coarse, derived from IP address)
- Professional or employment-related information (if you provide it)
- Inferences (limited, derived from site interactions to improve content)
Purposes
To operate and secure the website, respond to requests, provide communications, perform analytics, and comply with law.
Retention
We retain personal information only as long as reasonably necessary for the purposes disclosed or as required by law, consistent with the Data Retention section above.
Selling/Sharing
We do not sell personal information and do not share personal information for cross-context behavioral advertising.
Changes to This Notice
We may update this Notice from time to time to reflect changes in our practices or legal requirements. Material changes will be indicated by updating the effective date and, where appropriate, by additional notice.
Accessibility
Individuals who require this Notice in an alternative format may request it by contacting us at [email protected].
Contact Information
Controller: Michigan Inventors Coalition: Pharma Insights
Owner: Joe Barnett
Postal Address: 15600 NE 8th St, Bellevue, WA 98008, United States
Email: [email protected]
Definitions
- Personal data/personal information: Information that identifies, relates to, describes, or can reasonably be linked to an identified or identifiable individual.
- Processing: Any operation performed on personal data, such as collection, storage, use, disclosure, or deletion.
- Controller/Business: The entity that determines the purposes and means of processing personal data.
- Processor/Service provider: An entity that processes personal data on behalf of the controller/business.
- Sell/Share (U.S. state laws): Disclosing personal information to a third party for monetary or other valuable consideration (sell) or for cross-context behavioral advertising (share).