AngioInsight, Inc. (“AngioInsight,” “we,” “us,” or “our”) respects your privacy and is committed to protecting personal data. This Privacy Policy explains how we collect, use, disclose, and protect personal data when you visit our website, contact us, engage with us as a customer, supplier, investigator, site personnel member, research partner, vendor, or professional contact, or otherwise interact with us.
This Privacy Policy applies to personal data collected through our website and through related business, clinical, research, regulatory, and operational activities. It does not apply to information that has been fully anonymized so that it can no longer reasonably be linked to an identifiable person.
Contact Information for all Privacy and Data Privacy Framework Policy US-EU, U.K.-extension, and Swiss-U.S. Inquiries
ANGIOINSIGHT PRIVACY POLICY
Table of Contents – ANGIOINSIGHT PRIVACY POLICYs
AngioInsight Privacy Policy
Who We Are
Personal Data We Collect
How We Collect Personal Data
Legal Bases for Processing
How We Share Personal Data
International Transfers
Data Retention
Your Privacy Rights
Marketing Communications
Cookies and Similar Technologies
Third Party Websites
Complaints and Regulatory Authorities
ANGIOINSIGHT PRIVACY POLICY
1. Who We Are
AngioInsight, Inc. is a U.S.-based medical device company with its principal place of business at:
AngioInsight, Inc.
601 Carlson Parkway, Suite 1290
Minnetonka, MN 55305
United States
Website:
If you have questions about this Privacy Policy or would like to exercise a privacy right, please contact us at:
Email: privacy@angioinsight.com
Mail: Privacy Office, AngioInsight, Inc., 601 Carlson Parkway, Suite 1290, Minnetonka, MN 55305, United States
2. Personal Data We Collect
We may collect the following categories of personal data:
A. Website and Communications Data
- Name
- Business email address
- Telephone number
- Company name
- Job title
- Information you include in forms, emails, or inquiries
- Technical website usage information, such as IP address, browser type, device information, and usage data
B. Business Relationship and Professional Contact Data
- Contact details for customers, prospective customers, suppliers, consultants, and other professional contacts
- Contract, project, and communications records
- Billing or payment-related business contact information where relevant
C. Clinical, Research, and Regulatory Data
Where relevant to our clinical, research, regulatory, or safety activities, we may control and process:
- Coded or pseudonymized study data
- Investigator and study-site personnel information
- Safety, complaint, or adverse event information
- Regulatory correspondence and audit-related records
- Limited health-related or other sensitive data where permitted or required by applicable law
D. Vendor and Partner Data
- Business contact information for vendors, CROs, consultants, and research or service partners
- Due diligence, contracting, and compliance-related information
3. How We Collect Personal Data
We collect personal data in several ways, including:
- Directly from you when you contact us, submit a form, request information, sign up for communications, or otherwise communicate with us
- Automatically when you use our website, through cookies or similar technologies, subject to your browser settings and any cookie controls we make available
- From your organization, colleagues, business partners, conference organizers, or other third parties who provide your professional contact information in a business context
- From investigator sites, Clinical Research Organzations, vendors, service providers, regulators, and other counterparties in the course of clinical, regulatory, quality, safety, or business operations
- From publicly available sources, such as professional networking sites, conference materials, publications, or company websites
4. How We Use Personal Data
A. Website, Inquiries, and Communications
- To operate, secure, and improve our website
- To respond to your inquiries, requests, or feedback
- To provide information you request about our company, technology, services, or activities
B. Business Operations
- To manage customer, supplier, consultant, and partner relationships
- To negotiate, enter into, and perform contracts
- To maintain business records, financial controls, and internal administration
C. Clinical, Research, Safety, and Regulatory Activities
- To support clinical, research, quality, safety, and regulatory activities
- To manage relationships with investigators, sites, CROs, vendors, and partners
- To document, investigate, and respond to complaints, safety events, or regulatory matters
- To comply with applicable legal, regulatory, quality, and recordkeeping obligations
D. Marketing and Professional Outreach
- To send business-related updates, invitations, or communications where permitted by law
- To maintain and develop professional relationships
- To manage our presence on business and professional communication channels, including social media
E. Security and Compliance
- To protect our systems, website, personnel, users, and business
- To detect, investigate, prevent, or respond to fraud, misuse, security incidents, or other unlawful activity
- To enforce our legal rights and comply with applicable law
5. Legal Bases for Processing
Where required by applicable data protection law, we process personal data only where we have an appropriate legal basis, including:
- Your consent
- Performance of a contract or steps taken at your request before entering into a contract
- Compliance with a legal or regulatory obligation
- Our legitimate interests, such as operating and improving our business, managing professional relationships, securing our systems, and communicating with relevant business contacts
- Scientific research, public interest, public health, safety, or regulatory grounds where permitted by law
- Protection of vital interests where applicable
Where we process sensitive personal data, including health-related data, we do so only where permitted or required by applicable law and with appropriate safeguards.
6. How We Share Personal Data
We may disclose personal data to the following categories of recipients, as appropriate for the relevant purpose:
- Service providers and vendors that support our website, IT, security, communications, hosting, analytics, legal, accounting, or administrative operations
- Clinical research organizations (CROs), study vendors, central laboratories, imaging providers, clinical systems providers, safety vendors, and other research or regulatory support providers
- Business, research, or service partners
- Professional advisers, including legal, audit, insurance, and financial advisers
- Regulators, governmental authorities, ethics committees, review boards, or law enforcement where required or permitted by law
- Transaction counterparties and their advisers in connection with a corporate transaction, financing, restructuring, merger, acquisition, or asset sale
- Other parties where you request or authorize the disclosure
We may also disclose personal data where necessary to establish, exercise, or defend legal claims, protect rights or safety, or comply with law.
7. International Transfers
AngioInsight is based in the United States. If you are located outside the United States, your personal data may be transferred to, stored in, or accessed from the United States and other jurisdictions where we or our service providers operate.
Where required by applicable law, we implement appropriate safeguards for international transfers. Depending on the circumstances, these safeguards may include:
- Contractual protections, such as standard contractual clauses
- Other approved transfer mechanisms recognized under applicable law
- Additional technical, organizational, or administrative safeguards appropriate to the data and transfer
8. Data Retention
We retain personal data for as long as reasonably necessary for the purposes described in this Privacy Policy, including for legal, regulatory, research, safety, quality, contractual, dispute-resolution, and recordkeeping purposes.
Retention periods vary depending on the type of data and the context in which it was collected. For example:
- Website and inquiry data is retained for a period reasonably necessary to respond to and manage the inquiry and related follow-up
- Business contact and marketing data is retained until you object, unsubscribe, or it is no longer reasonably needed for the relationship
- Contract and transaction records are retained for the duration of the relationship and a reasonable period afterward for legal, accounting, and compliance purposes
- Clinical, research, safety, and regulatory records may be retained for longer periods where required or justified by applicable law, regulation, protocol obligations, good clinical practice, safety reporting, audit requirements, or defense of legal claims
When personal data is no longer required, we will delete it, de-identify it, anonymize it, or securely dispose of it in accordance with applicable law and our records management practices.
9. Your Privacy Rights
Depending on your location and the applicable law, you may have the listed rights regarding your personal data:
- Request access to personal data we hold about you
- Request correction of inaccurate or incomplete personal data
- Request deletion of personal data in certain circumstances
- Request restriction of processing in certain circumstances
- Object to certain processing, including direct marketing
- Request portability of certain personal data, where applicable
- Withdraw consent where processing is based on consent
- Lodge a complaint with a regulator or supervisory authority
These rights are not absolute. We may decline or limit a request where permitted by law, including where we need to retain data for legal, safety, scientific, regulatory, quality, contractual, or dispute-related reasons.
To exercise a privacy right, please contact us at privacy@angioinsight.com. We may need to verify your identity before responding to your request.
10. Marketing Communications
If you receive marketing or promotional communications from us, you may opt out at any time by:
- Using the unsubscribe link in the communication, where available
- Contacting us at privacy@angioinsight.com
Please note that even if you opt out of marketing communications, we may still send you non-marketing communications where necessary for an existing relationship, transaction, service, safety matter, legal obligation, or other permitted purpose.
11. Cookies and Similar Technologies
We may use cookies and similar technologies to operate our website, remember preferences, understand website usage, improve performance, and support security and communications.
If you disable certain cookies, some website functions may not operate as intended.
12. Third-Party Websites
Our website may contain links to third-party websites, services, or content. We are not responsible for the privacy, security, or content practices of third parties. We encourage you to review the privacy policies of those third parties before providing personal data to them.
13. Complaints and Regulatory Authorities
If you have concerns about how we handle your personal data, we encourage you to contact us first so we can try to resolve your concern promptly.
You also may have the right to lodge a complaint with a regulatory authority, depending on your location.
United States
If you are located in the United States, you may file a complaint with a government authority responsible for consumer protection, privacy, or, where applicable, health information privacy.
- The Federal Trade Commission (FTC): https://www.ftc.gov/
- FTC complaint portal: https://reportfraud.ftc.gov/
- U.S. Department of Health and Human Services Office for Civil Rights, for certain health privacy matters: https://www.hhs.gov/hipaa/filing-a-complaint/index.html
- You also may contact the Attorney General’s office in your state
European Economic Area (EEA)
If you are located in the European Economic Area, you may lodge a complaint with your local data protection authority in the country where you live, work, or where you believe a breach has occurred.
A list of EEA supervisory authorities is available at:
Lodging a complaint with a regulatory authority does not affect any other legal rights or remedies you may have.
DATA PRIVACY FRAMEWORK PRIVACY POLICY
EU-U.S. Data Privacy Framework (DPF), UK Extension, and Swiss-U.S. PENDING
EU-U.S. DPF, UK Extension & Swiss-U.S. DPF Notice.
AngioInsight has applied for self-certification to the EU-U.S. Data Privacy Framework (“EU-U.S. DPF”), the UK Extension to the EU-U.S. DPF (“UK Extension”), and the Swiss-U.S. Data Privacy Framework (“Swiss-U.S. DPF”), as set forth by the U.S. Department of Commerce. We have certified to the U.S. Department of Commerce that we adhere to the EU-U.S. Data Privacy Framework Principles (“EU-U.S. DPF Principles”) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. We have also certified to the EU-U.S. DPF Principles with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. To learn more about the Data Privacy Framework program, and to view our certification, please visit https://www.dataprivacyframework.gov/.
In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, AngioInsight commits to subject all personal data received from the European Union, the United Kingdom and Gibraltar, and Switzerland in reliance on the applicable Framework to the EU-U.S. DPF Principles. If there is any conflict between the terms in this Privacy Policy and the EU-U.S. DPF Principles (including as they apply to UK/Gibraltar data via the UK Extension and to Swiss data via the Swiss-U.S. DPF), the Principles shall govern.
1. Information We Collect
Consistent with the Notice Principle of the EU-U.S. DPF, we provide clear notice of our data practices before or at the time we collect your information, and in any event before we use it for a purpose other than that for which it was originally collected or disclose it to a third party for the first time. The categories of personal data we collect include:
1.1. Information You Provide Directly
- Identifiers: name, email address, postal address, and telephone number.
- Communications: messages, feedback, customer support inquiries.
- Employment-Related Information (if applicable): where personal data is transferred from the EU, UK/Gibraltar, or Switzerland in the context of an employment relationship, additional information described in our Human Resources Privacy Notice.
1.2. Information Collected Automatically
- Device and Usage Data: IP address, browser type, operating system, device identifiers, referring URLs, pages visited, and timestamps.
- Cookies and Similar Technologies: small data files placed on your device to enable functionality, analytics, and advertising. See Section 6 for details.
- Location Data: approximate location derived from IP address
1.3. Information from Third Parties
- Social media platforms when you interact with our content or log in via social authentication.
- Service providers
- Publicly available sources, where permitted by law.
2. EU-U.S. DPF, UK Extension, and Swiss-U.S. DPF Notice Disclosures
As required by the Notice Principle of the EU-U.S. DPF (which, under the UK Extension and the Swiss-U.S. DPF, applies in a manner consistent with its application to EU data transfers), we provide the following specific disclosures to individuals whose personal data we receive from the European Union, the United Kingdom and Gibraltar, or Switzerland:
2.1. Participation in the EU-U.S. DPF, UK Extension, and Swiss-U.S. DPF
AngioInsight has applied for self-certification to the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework. The official Data Privacy Framework List, which identifies organizations that have self-certified to the U.S. Department of Commerce and includes information regarding which organizations have elected to participate in the UK Extension, is available at https://www.dataprivacyframework.gov/list, where you may verify our active participation.
2.2. Types of Personal Data Collected and Covered Entities
The categories of personal data covered by our DPF certification (including personal data received from the United Kingdom and Gibraltar in reliance on the UK Extension and data received from Switzerland in reliance on the Swiss-U.S. DPF) are described above.
2.3. Commitment to Subject EU/UK/Gibraltar/Swiss Data to the Principles
We commit that all personal data received from the European Union in reliance on the EU-U.S. DPF, from the United Kingdom and Gibraltar in reliance on the UK Extension to the EU-U.S. DPF, and from Switzerland in reliance on the Swiss-U.S. DPF will be subject to the EU-U.S. DPF Principles. Our undertaking to apply the Principles to such data is not time-limited and continues for as long as we retain, use, or disclose such data, even if we subsequently leave the DPF program(s).
The principles are founded on the European Regulation (EU) 2016/679 (“the General Data Protection Regulation” or “the GDPR”) and Switzerland’s Federal Act on Data Protection (FADP), and all subsequent amendments and updates in force and actively monitored by AngioInsight.
2.4. Purposes of Collection and Use
3. We collect and use personal data for the purposes described in Section 4 How We Use Your Information.
3.1. How to Contact Us with Inquiries or Complaints
Contact informationis provided in Section 15. UK and Gibraltar individuals, as well as EU and Swiss individuals, may also use the same contact information. We respond to all complaints regarding compliance with the EU-U.S. DPF Principles within 45 days of receipt.
3.2. Third Parties to Whom We Disclose Personal Data
Categories of recipients are described in Section 5. We disclose personal data only for the purposes stated and consistent with the choices you have exercised.
3.3. Right of Access
You have the right to access personal data we hold about you and to correct, amend, or delete it where it is inaccurate or has been processed in violation of the EU-U.S. DPF Principles. See Section 7 for details and limitations.
3.4. Choices and Means for Limiting Use and Disclosure
We provide opt-out mechanisms for disclosures to third parties (acting as controllers) and for materially different secondary uses, and opt-in (affirmative express consent) for sensitive personal data. See Section 5.
3.5. Independent Dispute Resolution Body
If you have a complaint about how we handle your personal data under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, or the Swiss-U.S. Data Privacy Framework (together, the “Data Privacy Framework”), you may contact us directly and we will investigate and respond within 45 days.
If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your DPF Principles-related complaint to your satisfaction, the Independent Recourse Mechanism (IRM) designated by AngioInsight, Inc. and available to you at no charge is the ICDR-AAA. The ICDR®—International Centre for Dispute Resolution®— is the international division of the largest arbitral institution in the world, the American Arbitration Association® (AAA®).
To register a complaint visit: .
In addition, individuals in the European Union, the United Kingdom, and Switzerland may also contact their local data protection authority, including:
- EU/EEA supervisory authorities, your local Data Protection Authority (DPA);
- The UK Information Commissioner’s Office (ICO) at ico.org.uk;
- for Gibraltar residents, the Gibraltar Regulatory Authority (GRA) at gra.gi
- The Swiss Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch
We commit to cooperate with EU DPAs, the UK ICO, the Gibraltar GRA (as applicable), and the Swiss FDPIC, including with respect to the resolution of complaints concerning human resources data, and to comply with the advice given by such authorities to take specific action to comply with the Principles.
Under certain conditions, you may also be able to invoke binding arbitration to address residual complaints not resolved by other Data Privacy Framework mechanisms.
3.6. FTC Jurisdiction
The Federal Trade Commission has jurisdiction over AngioInsight’s compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF), following the acceptance of its self-certification application.
3.7. Binding Arbitration
Under certain conditions described more fully in Annex I of the EU-U.S. DPF Principles, you may invoke binding arbitration before the “EU-U.S. Data Privacy Framework Panel” to address residual claims that have not been resolved by other recourse mechanisms. The provisions of Annex I, including the obligation to arbitrate residual claims, apply to personal data transfers from the United Kingdom and Gibraltar to the United States in a manner consistent with their application to transfers from the European Union, in accordance with the UK Extension. See Section 12 for more information.
3.8. Disclosure to Public Authorities
We may be required to disclose personal data in response to lawful requests by public authorities, including to meet U.S. national security or law enforcement requirements. Where permitted by law, we will challenge requests that we believe are overbroad or unlawful, and we may publish a transparency report describing the volume and nature of such requests.
3.9. Liability for Onward Transfers
AngioInsight remains liable under the EU-U.S. DPF Principles the UK Extension to the EU-U.S. DPF if our agents (third-party service providers) process personal data we transferred in a manner inconsistent with the Principles, unless we prove that we are not responsible for the event giving rise to the damage. See Section 6.3.
4. How We Use Your Information
Consistent with the Data Integrity and Purpose Limitation Principle, we limit personal data to information that is relevant for the purposes of processing, and we do not process personal data in a way that is incompatible with the purposes for which it was collected or subsequently authorized by you. Specifically, we use information to:
- Provide, maintain, and improve our Services.
- Communicate with you about products, services, and updates (subject to your choices).
- Detect, prevent, and respond to fraud, security incidents, and unlawful activity.
- Comply with legal obligations and enforce our Terms of Service.
- Conduct research and analytics to understand how our Services are used.
- Conduct clinical studies in compliance to ISO 14155 to investigate the safety and effectivity of medical devices. Personal data and its uses collected during clinical studies are included in each study specific informed consent form and requires explicit consent of individual study participants prior to collection.
We take reasonable steps to ensure that personal data is reliable for its intended use, accurate, complete, and current. We retain personal data in identifiable form only for as long as it serves a purpose of processing as described above, except where extended retention is permitted under the EU-U.S. DPF (e.g., archiving in the public interest, scientific or historical research, or statistical analysis).
5. Your Choices
Consistent with the Choice Principle of the EU-U.S. DPF, we offer you the opportunity to choose (opt out) whether your personal data is (i) to be disclosed to a third party acting as a controller, or (ii) to be used for a purpose that is materially different from the purposes for which it was originally collected or subsequently authorized by you. We provide clear, conspicuous, and readily available mechanisms to exercise these choices, including the contact information in Section 15.
5.1. Marketing Communications
You may opt out of promotional emails at any time by clicking the “unsubscribe” link in any email or by contacting us at . Transactional messages (e.g., order confirmations) are not affected by marketing opt-outs. We will give effect to your opt-out request within a reasonable time.
5.2. Cookies and Tracking
You can manage cookies through your browser settings or our cookie preference center. We honor Global Privacy Control (GPC) signals as a request to opt out of the sale or sharing of personal information.
5.3. Sensitive Personal Data
Consistent with the EU-U.S. DPF, we obtain your affirmative express consent (opt-in) before we (i) disclose to a third party, or (ii) use for a purpose other than that for which it was originally collected or subsequently authorized, any sensitive personal data. Sensitive personal data under the EU-U.S. DPF includes information specifying medical or health conditions, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or information specifying the sex life of the individual. We also treat as sensitive any personal data received from a third party where the third party identifies and treats it as sensitive.
5.4. Targeted Advertising
You may opt out of interest-based advertising through the Digital Advertising Alliance (optout.aboutads.info), the Network Advertising Initiative (optout.networkadvertising.org), or the European Interactive Digital Advertising Alliance (youronlinechoices.eu).
5.5. Clinical Studies and Transfers for Regulatory Purposes
Personal data collected previous to withdrawal (i.e., opt out) may be processed along with other data collected as part of the clinical trial, as documented by patient informed consent agreements.
AngioInsight may be required to transfer data from clinical trials conducted in the EU, UK, and Switzerland to regulators in the United States for regulatory and supervision purposes. The recipients of data from clinical trials may parties other than regulators, such as company locations and other researchers. AngioInsight shall be bound by the Principles of Notice and Choice for these transfers.
Exceptions to the Principles of Notice, Choice, Onward Transfer, and Access are strictly limited to instances where the Principles interfere with compliance with regulatory requirements. These instances may include product safety and efficacy monitoring activities, including the reporting of adverse events and the tracking of patients/subjects using AngioInsight and clinical study protocol included medical devices, reports by health care providers, and reports to government agencies like the Food and Drug Administration and Notified Bodies defined in EU MDR 2017/745.
6. How We Share Information
We do not sell your personal data for monetary consideration. Consistent with the Accountability for Onward Transfer Principle of the EU-U.S. DPF (as applied through the UK Extension and the Swiss-U.S. DPF), when we transfer personal data received from the EU, the UK or Gibraltar, or Switzerland to third parties, we comply with the Notice and Choice Principles and enter into appropriate written contracts with such third parties.
6.1. Categories of Recipients
| Recipient Category | Purpose |
|---|---|
| Service Providers (Agents) | Hosting, payment processing, analytics, and customer support, under contracts requiring at least the same level of privacy protection as the EU-U.S. DPF Principles. |
| Third-Party Controllers | Only with your consent or after providing notice and choice; under contracts requiring the same level of protection as the Principles and limiting processing to specified purposes. |
| Affiliates within Our Corporate Group | Pursuant to intra-group agreements that ensure continuity of Principles-level protection. |
| Business Transfers | In connection with a merger, acquisition, financing, or sale of assets, with notice to affected users. |
| Legal Compliance / Public Authorities | To comply with subpoenas, court orders, regulatory requests, national security or law enforcement requirements, or to protect rights, safety, and property. |
| With Your Consent | When you direct us to share information with a third party. |
| Public Disclosure | When subject to a court order that is based on compliance or an order from a U.S. statutory body (e.g., FTC or DOT), the organization shall make public any relevant Swiss-U.S. DPF-related sections of any compliance or assessment report submitted to the court or U.S. statutory body to the extent consistent with confidentiality requirements. |
6.2. Contractual Safeguards for Onward Transfers
Before transferring personal data to a third party acting as our agent, we (i) transfer such data only for limited and specified purposes, (ii) ascertain that the agent is obligated to provide at least the same level of privacy protection as required by the EU-U.S. DPF Principles, (iii) take reasonable and appropriate steps to ensure the agent processes personal data consistently with our obligations, (iv) require the agent to notify us if it can no longer meet this obligation, (v) take reasonable and appropriate steps to stop and remediate unauthorized processing upon such notice, and (vi) provide a summary or representative copy of relevant privacy provisions of our contract with the agent to the U.S. Department of Commerce upon request.
For transfers to third parties acting as controllers, we enter into contracts that limit processing to specified purposes consistent with your consent and require the recipient to provide the same level of protection as the EU-U.S. DPF Principles, and to notify us if it can no longer meet that obligation.
Onward transfers of data from Switzerland and/or of Swiss shall be conducted pursuant to agreements or contracts fully reflecting the requirements of the relevant standard contractual clauses approved, established or recognized by the Federal Data Protection and Information Commissioner (“the FDPIC”).
6.3. Liability for Onward Transfers
AngioInsight remains responsible and liable under the EU-U.S. DPF Principles if our agents process personal data we transferred in a manner inconsistent with the Principles, unless we prove that we are not responsible for the event giving rise to the damage.
Cookies and Tracking Technologies
We use the following types of cookies and similar technologies:
- Strictly Necessary: required for the Services to function (cannot be disabled).
- Performance and Analytics: help us understand how visitors interact with our site.
- Functional: remember your preferences and settings.
- Advertising: deliver relevant ads and measure campaign effectiveness.
Detailed information is available in our Cookie Notice at
7. Your Rights of Access, Correction, and Deletion
Consistent with the Access Principle, you have the right to:
- Confirmation: obtain confirmation of whether or not we are processing personal data relating to you.
- Access: have communicated to you the personal data we hold about you, including the purposes of processing, categories of personal data, and recipients or categories of recipients.
- Correction, Amendment, or Deletion: where personal data is inaccurate or has been processed in violation of the Principles.
- Portability: receive your information in a structured, machine-readable format (where applicable under law).
To exercise these rights, contact us at We will verify your identity before responding and will respond within a reasonable time period (generally within 30–45 days). You do not need to justify your request. We may charge a non-excessive fee only where requests are manifestly excessive (e.g., due to repetitive character).
AngioInsight agrees to be bound by the requirements of The Access Principle in Practice, Section 8 of the EU-U.S. DPF Principles. AngioInsight will always make good faith efforts to provide access. In order to be guided by the request purpose, response inquiries may be required regarding the parts of the organization individuals may have interacted with or the nature of the information or its use. These inquiries are not limitations on access, but instead are design to protect the privacy of all the request may or may not encompass.
When information needs to be protected and can be readily separated from other personal information subject to an access request, AngioInsight may redact the protected, while making the other information. In cases where access restrictions are warranted, AngioInsight shall provide the requestor an explanation of that determination, as much information as can be provided, even if adjacent information is redacted, and a contact point for any further inquiries.
Access shall be limited only in the exceptional circumstances permitted by the EU-U.S. DPF Principles. The right of access to personal data shall only be restricted in exceptional circumstances where the legitimate rights of persons other than the individual would be violated or where the burden or expense of providing access would be disproportionate to the risks to the individual’s privacy within the scope of individual requests. Expense and burden are important but never controlling factors in determining the reasonableness of access requests.
Access shall be limited where disclosure would breach a legal or professional privilege; where it would interfere with law enforcement, national security, or important countervailing public interests; or where it would prejudice confidentiality necessary for monitoring, regulatory functions, or ongoing negotiations. If access is restricted, we will provide all requesters with an explanation and a contact point for further inquiries.
When the fulfilling of an access request would include the release of AngioInsight Confidential Commercial Information, access may be limited or denied. Access requests with confidential commercial information in scope may be answered with redactions of that information to separate it from the required personal information.
8. Data Security
Consistent with the Security Principle of the EU-U.S. DPF, we take reasonable and appropriate measures to protect personal data from loss, misuse, and unauthorized access, disclosure, alteration, and destruction, taking into due account the risks involved in the processing and the nature of the personal data. Our measures include:
- Encryption of personal data in transit (TLS 1.2 or higher) and at rest (AES-256).
- Multi-factor authentication and role-based access controls.
- Regular vulnerability scanning, penetration testing, and patch management.
- Employee training on privacy and security obligations, with mandatory refreshers.
- Vendor due diligence and contractual security requirements.
- Incident response and business continuity planning tested at least annually.
- Periodic risk assessments and program updates to address evolving threats.
If we experience a security incident affecting your personal data, we will notify you and applicable authorities as required by law.
9. Data Retention
Consistent with the Data Integrity and Purpose Limitation Principle, we retain personal data in identifiable form only for as long as it serves a purpose of processing. When personal data is no longer needed, we securely delete or de-identify it. We may retain data for longer periods only to the extent necessary for archiving in the public interest, scientific or historical research, statistical analysis, or to comply with legal, accounting, or reporting requirements.
10. Recourse, Enforcement, and Liability
In compliance with the EU-U.S. DPF Recourse, Enforcement and Liability Principle (as applied through the UK Extension and the Swiss-U.S. DPF), AngioInsight provides multiple avenues for individuals to obtain recourse for any concerns related to our processing of personal data received under the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, or the Swiss-U.S. DPF. AngioInsight maintains controlled follow-up procedures for verifying that the attestations and assertions they have made about their privacy practices are true. As of the date of this procedure’s release, AngioInsight’s application for DPF self-certification is pending.
AngioInsight commits to cooperate in investigations regarding the use of human resources data in the context of employment relationships as required by the Swiss-U.S. DPF.
AngioInsight commits to abide by the Supplemental Principles on Human Resources data and commits to commit to cooperate in investigations by and to comply with the advice of competent EU and UK/Gibraltar authorities in such cases.
10.1. Step One: Contact Us Directly
Please contact us first at so we can address your concern. We will respond to all DPF-related complaints within 45 days of receipt, as required by the Principles.
10.2. Step Two: Independent Recourse Mechanism
If your complaint is not resolved through our internal procedures, we have agreed to refer unresolved Principles-related complaints (including complaints concerning data received under the UK Extension) to JAMS (https://www.jamsadr.com/about), an independent alternative dispute resolution provider, at no cost to you. To learn more or file a complaint, visit https://www.jamsadr.com/file-a-dpf-claim
10.3. Step Three: Data Protection Authorities
For complaints concerning human resources data transferred from the EU, UK/Gibraltar, or Switzerland in the context of the employment relationship, and for any other complaint, you may contact the relevant data protection authority: your local EU Data Protection Authority (for EU/EEA residents), the UK Information Commissioner’s Office (ICO) at ico.org.uk (for UK residents), the Gibraltar Regulatory Authority (GRA) at gra.gi (for Gibraltar residents), or the Swiss Federal Data Protection and Information Commissioner (FDPIC) (for Swiss residents). We commit to cooperate with these authorities in the investigation and resolution of complaints, and to comply with the advice given by such authorities (including, where required, providing written confirmation that any specified action has been taken). When cooperation and direct correspondence to national authorities is required (e.g., Section 7b of the Swiss-U.S. DPF), AngioInsight shall regard local requirements as superior and governing and adhere to all required process and correspondence requirements.
Human Resources Data that is not individually identified, identifiable, anonymized, or used for statistical reporting relying on aggregate employment data does not raise privacy concerns.
10.4. Step Four: U.S. Department of Commerce
You may also raise concerns with your local DPA, the UK ICO, the Gibraltar GRA, or the Swiss FDPIC, which can refer the matter to the U.S. Department of Commerce. The Department maintains a dedicated point of contact for these authorities and will use best efforts to facilitate resolution. More information is available at https://www.dataprivacyframework.gov/.
10.5. Step Five: FTC Enforcement
AngioInsight is subject to the investigatory and enforcement authority of the U.S. Federal Trade Commission, which reviews on a priority basis referrals alleging non-compliance with the EU-U.S. DPF Principles (including as relates to personal data received from the United Kingdom and Gibraltar in reliance on the UK Extension). The FTC may take enforcement action under Section 5 of the FTC Act for any violation.
10.6. Step Six: Binding Arbitration (Last Resort)
Under certain conditions described in Annex I of the EU-U.S. DPF Principles (which applies to UK/Gibraltar transfers via the UK Extension in a manner consistent with EU transfers), if other dispute resolution mechanisms have not fully resolved your complaint, you may invoke binding arbitration before the “EU-U.S. Data Privacy Framework Panel.” Pre-arbitration requirements include first raising the claimed violation directly with us, using the independent recourse mechanism, and contacting the U.S. Department of Commerce through your DPA, the ICO, the GRA, or the FDPIC (as applicable). Arbitration is available only for residual claims regarding alleged violations of the Principles. The Panel may impose individual-specific, non-monetary equitable relief (such as access, correction, deletion, or return of your data). Each party bears its own attorney’s fees, and arbitration costs are covered by a fund maintained by participating organizations. Arbitral decisions are subject to judicial review and enforcement under the U.S. Federal Arbitration Act.
11. Verification
AngioInsight’s application for self-certification is pending. We currently have established policies and procedures designed to comply with the EU-U.S. DPF Principles (including as they apply to personal data received from the United Kingdom and Gibraltar in reliance on the UK Extension and from Switzerland in reliance on the Swiss-U.S. DPF) through self-assessment. We retain records of our DPF-related privacy practices and make them available upon request to the relevant independent dispute resolution body, the FTC, or the U.S. Department of Commerce.
12. International Data Transfers
Our Services are operated in the United States. Personal data of individuals located in the European Union and the European Economic Area is transferred to the United States in reliance on our certification under the EU-U.S. Data Privacy Framework. Personal data of individuals located in the United Kingdom and Gibraltar is transferred to the United States in reliance on our certification under the UK Extension to the EU-U.S. DPF, in accordance with UK adequacy regulations governing the data bridge to the United States. Personal data of individuals located in Switzerland is transferred in reliance on our certification under the Swiss-U.S. DPF. For transfers from other jurisdictions, we use additional safeguards as required by applicable law (e.g., Standard Contractual Clauses, the UK International Data Transfer Agreement, or the UK International Data Transfer Addendum to the EU SCCs).
Data Transfers of personal data received in the United States from Switzerland and/or Swiss citizens must be governed by contracts fully reflecting the requirements of the relevant standard contractual clauses approved, established or recognized by the FDPIC.
13. Human Resources Data
Where we receive human resources personal data from the EU, the UK or Gibraltar, or Switzerland in the context of an employment relationship, we commit to cooperate with the competent EU Data Protection Authorities, the UK Information Commissioner’s Office, the Gibraltar Regulatory Authority (as applicable), and the Swiss Federal Data Protection and Information Commissioner in the investigation and resolution of complaints brought by current or former employees, and to comply with the advice given by such authorities. Employees with concerns regarding the handling of their personal data should follow the procedures described in our Human Resources Privacy Notice.
14. Other Privacy Frameworks
14.1. UK and Gibraltar Residents
In addition to the protections provided under the UK Extension to the EU-U.S. DPF, residents of the United Kingdom have rights under the UK General Data Protection Regulation (UK GDPR) and the UK Data Protection Act 2018, and residents of Gibraltar have rights under the Gibraltar General Data Protection Regulation and the Data Protection Act 2004 (Gibraltar). These rights include access, rectification, erasure, restriction of processing, data portability, and objection. To exercise these rights, contact us using the information in Section 15. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ico.org.uk) or the Gibraltar Regulatory Authority (gra.gi).
14.2. EU/EEA Residents (GDPR)
In addition to the protections provided under the EU-U.S. DPF, residents of the EU/EEA have rights under the General Data Protection Regulation (GDPR), including access, rectification, erasure, restriction of processing, data portability, and objection. You also have the right to lodge a complaint with your local supervisory authority.
14.3. California Residents (CCPA/CPRA)
California residents have additional rights, including the right to know categories of personal information collected, sold, or shared in the preceding 12 months; the right to opt out of sale or sharing; and the right to limit use of sensitive personal information. We have not sold personal information for monetary consideration in the preceding 12 months. To submit a request, visit .
14.4. Other U.S. State Laws
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have rights similar to those described in Section 8. Contact us using the information below to exercise these rights.
14.5. Children’s Privacy
Our Services are not directed to children under 13 (or under 16 in the EU/UK, where higher protection applies). We do not knowingly collect personal data from children without verifiable parental consent in compliance with COPPA, the GDPR, and the UK GDPR.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, please contact our Privacy Office:
AngioInsight — Privacy Office
601 Carlson Parkway
Suite 1290
Minnetonka, MN 55305
Email: privacy@angioinsight.com
Data Protection Officer: bdelfs@angioinsight.com
16. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through prominent notice on our website or by email at least 30 days before they take effect. The “Last Updated” date at the top of this Policy indicates when it was most recently revised. We will continue to apply the EU-U.S. DPF Principles to all personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, even if we leave the DPF program(s).