PRIVACY POLICY

Consilient Health Limited and its subsidiaries (“We”) are committed to protecting and respecting your privacy.

This policy (together with any other documents referred to in it) sets out the basis on which any personal data (including sensitive personal data) we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.

For the purpose of the GDPR and Data Protection Act 2018 (the “Act”), Consilient Health Limited of Floor 3, Block 3, Miesian Plaza, Dublin 2, D02 Y754, Ireland is a data controller.

INFORMATION WE MAY COLLECT FROM YOU

1.1 We may collect and process the following data about you:

1.1.1 Information you give us.

You may give us information about you by filling in order forms, participating in a recruitment process, or by corresponding with us by phone, e-mail, or otherwise. This includes information you provide when you use our services, place an order, attend one of our events, apply for an open position, or contact us about one of our products. The information you give us may include personal details such as name, address, e-mail address, phone number, financial and credit card information, and sensitive personal data including health-related information.

We process this data under one or more of the following legal bases:

  • Contractual necessity – when processing is necessary for the performance of a contract.
  • Legal obligation – to comply with applicable laws and regulations.
  • Legitimate interests – where processing is necessary for our legitimate business interests, provided those interests do not override your rights and interests.

Consent – when required, we will obtain your explicit consent.

For special category data, we rely on lawful bases under Article 9 of GDPR, including explicit consent, legal obligations, and public interest grounds.

1.1.2 Information we receive from other sources.

We may receive information about you if you use any of the other services we provide. We are also working closely with third parties (such as business partners, service providers, and credit reference agencies) and may receive information about you from them.

USES MADE OF THE INFORMATION

We use information held about you in the following ways:

  • To carry out our contractual obligations and provide services.
  • To provide you with information about goods and services similar to those you have purchased.
  • To provide you, or permit selected third parties to provide you, with information about goods or services that may interest you, where you have given explicit opt-in consent. You may withdraw consent at any time by contacting us directly.
  • To notify you about changes to our services or products.
  • To validate access to certain products or services.
  • To provide customer service and support.

WEBSITE USE

With regard to each of your visits to our site, we may automatically collect and process the following information:

  • Technical information, including the Internet protocol (IP) address used to connect your computer to the Internet, browser type and version, time zone setting, browser plug-in types and versions, operating system, and platform.
  • Information about your visit, including the full Uniform Resource Locators (URL) clickstream to, through and from our site (including date and time); products you viewed or searched for; page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page.

We will use this information:

  • To administer our site and for internal operations, including troubleshooting, data analysis, testing, research, statistical, and survey purposes.
  • To improve our site to ensure that content is presented in the most effective manner for you and for your device.
  • To allow you to participate in interactive features of our service, when you choose to do so.
  • As part of our efforts to keep our site safe and secure.
  • To measure or understand the effectiveness of advertising we serve to you and others, and to deliver relevant advertising to you.

DATA RETENTION

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, regulatory, or contractual obligations. Retention criteria include:

  • Legal and regulatory record-keeping requirements.
  • Contractual obligations.
  • Business and operational requirements.

WHERE WE PROCESS YOUR PERSONAL DATA

We may share your personal information with any member of our group, which means our subsidiaries, our ultimate holding company, and its subsidiaries, as defined in the Irish Companies Act.

The data that we collect from you may be transferred to and processed at a destination outside the European Economic Area (“EEA”). It may also be processed by staff operating outside the EEA who work for us or for one of our suppliers. Such staff maybe engaged in, among other things, the fulfilment of your order, the processing of your payment details and the provision of support services. By submitting your personal data, you agree to this transfer, storing or processing. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy policy.

SECURITY MEASURES

We implement security measures to protect personal data, including:

  • Encryption to secure data in transit and at rest.
  • Access controls to limit data access to authorized personnel.
  • Monitoring systems to detect and prevent security threats.

COOKIES

Our website uses cookies to distinguish users and improve experience. We classify cookies as:

  • Essential cookies – necessary for website functionality.
  • Non-essential cookies – used for analytics, advertising, and personalization.

For detailed information on the cookies we use and the purposes for which we use them see our cookies policy available at https://www.consilienthealth.com/cookies.

YOUR RIGHTS

Under GDPR, you have the right to:

  • Access – Request a copy of your personal data.
  • Rectification – Correct inaccurate or incomplete data.
  • Erasure – Request deletion of your data where applicable.
  • Restriction of processing – Request limited data processing in certain circumstances.
  • Objection – Object to data processing based on legitimate interests.
  • Data portability – Request transfer of data to another provider.
  • Withdraw consent – Withdraw consent at any time for data processing based on consent.

We respond to requests within one month, unless an extension is required due to complexity. Certain exemptions may apply where legal obligations prevent us from fulfilling a request. To exercise your rights, contact DPO@consilienthealth.com.

LODGING A COMPLAINT

If you are unsatisfied with how we handle your personal data, you have the right to lodge a complaint with:

Data Protection Commission Canal House, Station Road, Portarlington, R32 AP23, Co. Laois Phone: +353 57 8684800 | Email: info@dataprotection.ie

Additionally, you have the right to seek judicial remedies if your data protection rights are violated.

For any questions regarding this privacy policy, contact DPO@consilienthealth.com.

Last Updated: 10 March 2025

CORP-CH-1660ga(1) July 2025