This Privacy and Cookie Statement outlines how RAIN, an expert-network recruitment agency focused on interim consulting, collects, stores, and processes personal data of individuals engaged in our consulting projects. It also describes your rights and our obligations regarding your personal information.

The term “personal data” within this document encompasses any information that fits the definitions provided under GDPR, as well as “personal information” as defined by the CCPA, PIPL, or any applicable data protection legislation.

Personal Data We Collect and Process

RAIN may collect and process the following categories of personal data:

- Full name (first name, last name, maiden name)

- Contact information ( address, email, phone numbers)

- National Insurance and tax ID numbers

- Professional background (CVs, job titles, training, qualifications, memberships, industry expertise)

- Payment and financial details (bank accounts, PayPal, Venmo, Zelle, etc.)

- Responses to project-related screening questions

- Technical data (IP address, browser, OS, location, time zone, etc.)

If consent is necessary for the processing of your data, you have the right to access, update, or withdraw your consent at any time.

How We Collect Data

RAIN may gather your personal data through various means, including:

- Directly from you (via phone, email, surveys, our website, or other methods)

- From third parties

- From publicly available sources (such as professional website publications like PubMed and ResearchGate, clinical trial sites, and professional social networks like LinkedIn)

Occasionally, our team may reach out to you to confirm the accuracy of the personal data we hold.

Special Category Data

At RAIN, we prioritize the protection of individuals’ rights and freedoms in all our data processing activities. We do not engage in automated decision-making or profiling to evaluate individuals, nor do we conduct large-scale monitoring of publicly accessible areas.

We do not process sensitive personal data — such as information regarding racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data used for unique identification, or data concerning health, sexual orientation, or sexual life — unless required by law or based on your explicit consent. We also do not process any data related to criminal convictions or offenses.

In rare cases where the processing of sensitive data is necessary to provide our services, such processing will be carried out strictly in accordance with applicable legal requirements, with appropriate safeguards in place to protect your rights and freedoms..

Purpose of Data Use

RAIN collects, stores, and processes personal data to support the effective execution of our projects and maintain high service standards. This includes:

- Fulfilling contractual obligations, including expert engagement and project participation

- Processing payments for your involvement in projects.

- Facilitating efficient recruitment, including expert screening and verification

- Enhancing performance management.

- Sharing information on recruitment and retention policies.

- Tracking financial modeling and planning.

- Improving workforce data management.

- Meeting legal obligations and addressing our legitimate interests, ensuring they do not conflict with your rights.

- Enhancing services to strengthen client and expert relationships.

- Analyzing technical data about website visitors.

- Assisting with legal claims, dispute resolution, and compliance audits

- Responding to lawful requests from authorities and supporting investigations

Cookies

RAIN uses cookies on our website to enhance user experience, improve site functionality, and analyze performance. Below is an overview of the types of cookies we use:

Essential Cookies: Required for the website to operate properly. These cookies do not collect personal information and cannot be disabled through our cookie settings.

-Functional Cookies: Enable enhanced features and personalization, such as remembering user preferences or allowing content sharing via social media platforms.

-Performance Cookies: Collect aggregated and anonymized data about how users interact with the website. This information helps us improve functionality, navigation, and overall performance.

-Marketing Cookies: Used to deliver relevant advertising content and track the effectiveness of marketing campaigns. These cookies may collect data about your browsing behavior across websites to personalize ads.

Legal Grounds for Data Usage

RAIN collects and processes your personal information in accordance with international data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the China Personal Information Protection Law (PIPL).

We typically process your personal data based on one or more of the following legal grounds:

- To fulfill a contract with you

- To comply with legal obligations

- To perform public interest tasks

In certain circumstances, we may also process your data when:

- You have provided explicit consent for a specific purpose

- It’s necessary to protect your vital interests or those of others

- It's based on our legitimate interests

You have the right to withdraw or modify your consent at any time, and we will inform you on how to do so when we request it.

For Residents of China

This section supplements and, where applicable, overrides other provisions of this Privacy Policy for individuals located in China, as we process personal information in accordance with the China Personal Information Protection Law (PIPL).

We collect, store, and use your personal information for the following purposes:

- Facilitating client engagements and recommending your profile for specific projects.

- Managing client and user profiles for support and billing.

- Utilizing non-essential cookies and similar technologies.

- Executing our contractual obligations and delivering related communications

- Processing payments in accordance with legal and financial requirements

- Complying with legal requests from authorities.

- Carrying out other activities as permitted by applicable laws

We may also gather information about you from public online sources and our interactions. Your explicit consent will always be obtained before we process your personal information. With your consent, we may also transfer your data outside of China, ensuring that the recipient implements adequate protection measures consistent with the requirements of the PIPL.

For California Residents

This section applies specifically to residents of California and takes precedence over other sections of this Privacy Policy where we process personal information under the California Consumer Privacy Act (CCPA) and its amendments under the California Privacy Rights Act (CPRA).

As a California resident, you have the following rights regarding your personal data:

- Right to Know: You can request details about the personal data we store and process, including your name, address, contact info, and any sensitive information you provide for identity verification. We do not store data on racial, health, or sexual orientation.

- Right to Access: You may request a copy of the personal information we hold about you, which may require identity verification.

- Right to Delete: You have the right to request the deletion of your personal data from our systems and those of our service providers, subject to any applicable legal or contractual retention obligations.

- Right to Opt-Out: You may opt out of data sharing for behavioral advertising by updating your cookie preferences.

- Right to Correct: You have the right to change or update your personal data.

- Right to Limit Processing: You may request restrictions on the use and disclosure of sensitive personal information. We will only use such data as necessary to perform our contractual duties or comply with applicable laws.

Data Storage

RAIN maintains a secure and regularly updated database of experts participating in our projects. Your personal data is stored in encrypted files and secure cloud environments protected by multi-factor authentication. This information is used exclusively for purposes directly related to your professional experience and participation in our projects. Access to your data is strictly limited to authorized RAIN personnel who are appropriately trained in data protection and require such access to fulfill contractual or legal obligations on behalf of RAIN and its clients.

If you decide to withdraw or modify your consent to being part of the RAIN Expert Network, simply notify the RAIN Data Protection Officer (contact details below), and we will promptly update or delete your information as required by law.

Regarding cookies, we aggregate usage data from website visitors to create datasets that help us analyze and enhance our services. This anonymized and aggregated data does not directly impact your rights or freedoms and is not classified as personal data.

While RAIN has implemented strong organizational, technical, and physical security measures to protect personal information, please be aware that no online transmission or processing can be entirely secure. Despite our best efforts, we cannot guarantee complete security during data transmission.

Data Sharing

RAIN may share your personal information with the following entities when required by law or data protection regulations:

• Local authorities – to fulfill legal obligations, including safeguarding issues.

• Family members or representatives – with verified identities acting on your behalf.

• Clients (including advisors) – to meet project commitments.

• Financial institutions.

• Regulatory bodies and government agencies – as necessary for compliance, legal actions, fraud investigations, or other legal requirements.

• Professional consultants like accountants and attorneys, who are bound by confidentiality.

• Health and social welfare organizations.

• In the event of a business restructure (merger or acquisition), your data may be transferred, and you will be notified.

• Currently, we do not share your data with third parties, and any future sharing will require your consent.

Access and Rights Regarding Your Personal Information

You have the right to request access to your personal information held by RAIN through a “subject access request.” If we possess information about you, we will provide a description, the reasons for processing, the source of the data, potential disclosures, and a copy in an intelligible format. You may also have the right to request electronic transmission of your personal information to another organization, and to contact our data protection officer at dpo@rainpartners.ua for this purpose.

In addition, under applicable data protection laws, you are entitled to exercise a range of other rights regarding your personal data. These include the right to object to processing, to opt out of direct marketing, to correct or delete inaccurate data, to restrict processing, and to request the pseudonymization of your data. You may also opt out of profiling for marketing purposes, temporarily suspend processing, request data portability, or seek compensation for any damages arising from a breach of your data rights. Accessing and updating your data is generally free of charge; however, a reasonable fee may apply for repetitive, excessive, or unfounded requests. We may require verification of your identity before responding to any such requests. To initiate any of these actions, please contact our Data Protection Officer at the address provided above.

Data Breach Procedures

In the event of a data breach, RAIN takes swift action depending on its role. If we are the Data Controller, our employees are trained to notify the Data Protection Officer (DPO) at dpo@rainpartners.ua within 12 hours of discovering the breach. The DPO will then evaluate the breach and inform the relevant Data Protection Authority within 48 hours. If the breach poses a high risk to affected individuals, we will notify them within 72 hours. Conversely, if RAIN is acting as the Data Processor and the client is the Data Controller, employees must report any suspected breaches to the DPO within 12 hours as well. The DPO will then alert the client within 48 hours, sharing all necessary information. Clients who suspect a breach involving our services should also reach out to our DPO promptly. This cooperative approach ensures that both RAIN and our clients can effectively manage and mitigate potential risks in compliance with data protection laws.

Concerns and Complaints

At RAIN, we take all complaints concerning the handling of personal information with the utmost seriousness. If you believe that our data collection or processing practices are unfair, misleading, or otherwise inappropriate, or if you have any concerns regarding how your personal data is being used, we encourage you to contact us directly. To submit a complaint, please contact our Data Protection Officer at dpo@rainpartners.ua .

публикации

Рекомендуемые статьи
+38 (044) 228-8071