DrugBank Privacy Policy
Last Updated:
This Privacy Policy explains how OMx Personal Health Analytics, Inc., d/b/a DrugBank (“DrugBank”) is committed to protecting your privacy and ensuring that you feel comfortable accessing and using DrugBank’s owned or licensed databases (“Databases”) and websites, be they http://go.drugbank.com, http://www.drugbank.com, portal.drugbank.com, api.drugbank.com, or any other website directly linking traffic thereto (collectively the “Platform”), along with any other technology and services provided by us (collectively with the Platform, the “Services”). This Privacy Policy covers the DrugBank Services and is applicable worldwide.
This policy describes our data handling practices and how we collect and use the Personal Information and other information you provide during your interactions with us and our Service.
This Privacy Policy is a binding contract and by using our Service you agree to it. This Privacy Policy may be updated from time to time for reasons such as operational practices or regulatory changes, so we recommend that you review our Privacy Policy when returning to our website.
What do we mean by Personal Information?
“Personal Information” means any information that can be used to individually identify a person, and may include, but is not limited to name, email address, postal or other physical address, credit or debit card number, title, and other personally identifiable information including metadata, and user content. Personal Information does not include information that cannot be used to identify you, such as internet protocol (“IP”) address, browser type, internet service provider, operating system, or device type, or information that has been aggregated or made anonymous such that it can no longer be reasonably associated with a specific person (collectively "De-Identified Data").
In order for you to register with our Services, you must provide us with your name, email, company/university, use case, job title, and country at a minimum. You may also have chosen to provide other Personal Information, including but not limited to information required to process online payments.
Overall, we collect the following categories of Personal Information about you when you use or otherwise interact with our Services:
Name
Company/University
Job title/industry
Employer information
Email address
Home/work/mobile telephone number
Postal or other physical address
Country
IP addresses and other information collected passively, as further detailed in the “Cookies and Tracking Technologies” section below
Device identifiers
Other unique identifiers (e.g., Hubspot ID, Stripe customer ID)
How do we collect information about you?
The data we collect, and how we collect it depends on the Services you are utilizing. Please see the overview for the different Services offered at DrugBank:
What do we do with your information?
We will use your Personal Information only in accordance with our Privacy Policy. If you do not wish us to continue using your Personal Information in this manner, you can request that your Personal Information be deleted and your account deactivated by contacting us at privacy@drugbank.com.
We will only process your Personal Information if we have a lawful basis for doing so. Lawful bases for processing include consent, contractual necessity (i.e. processing that is necessary for the performance of a contract with you, such as your customer agreement with us that allows us to provide you with the Services) and our “legitimate interests” or the legitimate interest of others (e.g. our users) such as:
Administering, personalizing, improving or operating our Services and business
Better understanding your needs and interests
Fulfilling requests you make related to the Services
Complying with our legal obligations, resolving disputes with users, enforcing our agreements
Protecting, investigating and deterring against fraudulent, harmful, unauthorized or illegal activity
Responding to inquiries from you or our third-party service providers
We may use De-Identified Data to test features in development, and analyze the information we have to evaluate and improve products and services, develop new services or features, and conduct audits and troubleshooting activities. De-identified Data will have all direct and indirect personal identifiers removed. This includes, but is not limited to, name, ID numbers, and date of birth. Furthermore, we agree not to attempt to re-identify De-Identified Data and not to transfer De-Identified Data to any party unless that party agrees not to attempt to re-identify any Personal Information from such data. We may share this De-Identified Data with our affiliates, agents, advertisers, manufacturers and business partners. We may also disclose De-Identified Data in order to describe our Services to current and prospective business partners and to other third parties for other lawful purposes.
When do we share your information?
DrugBank does not sell or rent your Personal Information to any third party for any purpose—including for advertising or marketing purposes. Furthermore, we do not share Personal Information with any third parties except in the limited circumstances described in this Privacy Policy.
We work with vendors, service providers, and other partners to help us provide our Services by performing tasks on our behalf. We may need to share or provide information (including Personal Information) to them to help them perform these business functions, for example sending emails on our behalf, database management services, database hosting, providing customer support software, and security. These service providers do not have the right to use your Personal Information we share with them beyond what is necessary to assist us. These service providers must adhere to confidentiality and security obligations in a way that is consistent with applicable law and their own terms and policies.
DrugBank is responsible for the processing of Personal Information it receives in accordance with the European Commission’s Standard Contractual Clauses, and subsequent transfers to a third party acting as an agent on our behalf. We comply with the Standard Contractual Clauses, for all onward transfers of Personal Information from the EU or Switzerland, including onward transfer liability provisions.
You may request a list of the third parties we work with by contacting us at privacy@drugbank.com. Such third parties may include: HubSpot, Stripe, BambooHR, Google Analytics, Microsoft Clarity, Indeed, and WagePoint.
See the complete list of third parties we work with (sub-processors).
If you would like to opt out of third party tracking via Google Analytics, please visit https://tools.google.com/dlpage/gaoptout .
This Privacy Policy only applies to information collected during your use and access of the Services or any other interactions you may have with DrugBank. Our Services may contain links to other locations on the Internet that are not owned or controlled by us. We are not responsible for the privacy practices of other websites or services. We encourage you to read the privacy statements of each website that collects your Personal Information.
We may also disclose your Personal Information to effect a merger or acquisition or to support the sale or transfer of business assets. If we are involved in a merger, acquisition, or sale of all or a portion of its assets, you will be notified via email and/or prominent notice via the Services of any change in ownership or uses of your Personal Information, as well as any choices you may have regarding your Personal Information.
We may disclose your information to a third party where we believe, in good faith, that it is desirable to do so for the purposes of investigating, preventing, or taking action regarding suspected or actual illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, violations of our Terms of Service, to comply with subpoenas, or as otherwise required by law. In the event that we receive a subpoena affecting your privacy, we will notify you unless prevented by applicable law, court order, rule or regulation, but are not required to quash the subpoena ourselves.
How do we store and protect your data?
We retain Personal Information only for as long as necessary to provide the Services you have requested and thereafter for a variety of legitimate legal or business purposes. These might include retention periods:
mandated by law, contract or similar obligations applicable to our business operations;
for preserving, resolving, defending or enforcing our legal/contractual rights; or
as needed to maintain adequate and accurate business and financial records.
Certain aspects of the Services are operated in the United States. If you are located outside of the United States, please be aware that any information you provide to us will be transferred to the United States. By providing us with any information through the Site, or the Services, you consent to this transfer.
We may transfer your Personal Information to third parties acting on our behalf for the purposes of processing or storage. By using any of our Services or providing any Personal Information for any of the purposes stated above, you consent to the transfer and storage of your Personal Information, whether provided by you or obtained through a third party, to the U.S. as set forth herein, including the hosting of such Personal Information on U.S. servers.
DrugBank uses reasonable administrative, technical, and physical security measures to protect data about DrugBank customers. DrugBank stores your Personal Information and other data on servers located in the United States. If you would like to know more, please email privacy@drugbank.com. You are responsible for maintaining the strict confidentiality of your account login credentials, and for any activity that occurs under your account credentials. Notify us if you suspect any unauthorized use of your account or other breach of security.
What if we change this privacy policy or any of our privacy notices?
We may modify the terms of this Privacy Policy from time to time. In the event of any material change to our Privacy Policy, in DrugBank’s sole discretion, you may be notified by email of such change, if you are a registered user of the Service. If any change is unacceptable to you, you should immediately cease use of the Service. Your continued use of the Service following a notice of a change in the Agreement via the Service will constitute your binding acceptance of the changes.
What else should I know?
Who can I contact for more information?
If you have any comments or questions, you may address them to OMx Personal Health Analytics, Inc., 700-10130 103 St. NW Edmonton, Alberta, Canada T5J 3N9, or by email at privacy@drugbank.com.