Legal
Social listening notice
How we process content published online in our social listening, patient listening and web reputation activities. Notice under Article 14 of Regulation (EU) 2016/679 (GDPR).
Why this notice
ThatMorning analyses conversations and content freely published online (social networks, forums, blogs, news outlets, review sites) to understand how people talk about health topics, conditions, treatments, companies and products.
This content may include personal data of its authors, which we do not collect from them directly. Since informing each author individually would be impossible or would involve a disproportionate effort, under Article 14(5)(b) GDPR we publish this notice so that it is always freely accessible, and we apply the safeguards described below.
Who is the controller
ThatMorning Srl, Via Meda 45, 20141 Milan (MI), Italy, VAT IT09310870960, email info@thatmorning.com.
ThatMorning acts in two roles:
- as controller, for the analyses it carries out on its own behalf, such as reputation indexes, research and insights published on its own channels;
- as processor (Article 28 GDPR) on behalf of its clients, such as pharmaceutical companies and associations, under a written agreement that sets out purposes, instructions and security measures. In these cases the client is the controller: we still handle any request we receive and, where needed, forward it to the client without delay.
What data we process
We only process publicly accessible content, i.e. content visible to anyone without registration or with a standard account, without bypassing privacy settings or restricted areas:
- the text of the published content (post, comment, article, review) and any associated image;
- public metadata: date, platform, language, link to the content, public engagement indicators (e.g. likes and shares);
- the author's public username or nickname and the public profile information strictly needed to assess the source (e.g. number of followers, or whether it is a news outlet or an institutional account).
Content may concern the health of the people who published it. This is a special category of data (Article 9 GDPR) that we process only when it has been manifestly made public by the data subject, and always with the safeguards described in this notice.
We do not process content from closed groups, private messages, private profiles or data obtained by circumventing platform terms of use.
Sources
Social networks, online forums and communities, blogs, news sites and outlets, review sites and other public web sources. Content is collected with ThatMorning's proprietary technology and, where applicable, through the platforms' official interfaces or authorised data providers.
Purposes
- Aggregated analysis of online conversations on health topics, conditions, treatments, companies, brands and products, for market research, reputation analysis, understanding the needs of patients and caregivers (patient listening) and supporting communication.
- Pharmacovigilance: when a piece of content contains a possible adverse event report about a medicinal product of one of our clients, we forward it to the client according to its procedures, so that it can meet its legal obligations on medicine safety.
- Research and editorial content in aggregated form only (e.g. statistics and infographics published on our channels).
Analysis results are delivered to clients and published only in aggregated or anonymised form. Any quotes in reports are anonymised and do not allow the author to be identified.
Legal bases
- Legitimate interest (Article 6(1)(f) GDPR) of ThatMorning and its clients in understanding how health topics, companies and products are perceived online, in order to improve services, communication and the response to patients' needs. We have assessed that this interest does not override the rights of data subjects, because we only process content they chose to make public, we neither profile nor contact them, and we only deliver aggregated results.
- For health data: data manifestly made public by the data subject (Article 9(2)(e) GDPR).
- For pharmacovigilance: reasons of public interest in the area of public health, such as ensuring high standards of quality and safety of medicinal products (Article 9(2)(i) GDPR), and the legal obligations of pharmaceutical companies (Article 6(1)(c) GDPR).
What we do not do
- We do not contact the authors of the content.
- We do not build individual profiles or take automated decisions that produce legal or similarly significant effects on people (Article 22 GDPR).
- We do not sell personal data or use it for targeted advertising.
- We do not try to identify people who post under a nickname.
How we protect data
- Data minimisation: we only collect content relevant to the project and the metadata needed for the analysis.
- Pseudonymisation of author identifiers in analysis datasets.
- Segregation of data by client and by project: each project is separate and accessible only to authorised people.
- Access control with named accounts and least privilege, and logging of access, exports and changes.
- Encryption in transit (HTTPS), regular backups, regular security testing and an incident and data breach management procedure.
- Staff trained and bound by confidentiality.
How long we keep data
Collected content is kept for the duration of the analysis project and in any case no longer than 24 months from collection, unless otherwise agreed in writing with the client acting as controller or required by law (e.g. pharmacovigilance). It is then deleted or anonymised. Aggregated, anonymous results may be kept indefinitely, as they contain no personal data.
If an author deletes a piece of content or makes it non-public, on request we remove it from our archives too.
Recipients
- ThatMorning staff authorised to process the data.
- Technical providers acting as processors (e.g. hosting services and data providers), bound by agreements under Article 28 GDPR.
- Clients, who receive results in aggregated or anonymised form; for pharmacovigilance, the marketing authorisation holder receives only the information needed to handle the report.
- Authorities, when required by law.
Transfers outside the European Union
Some data providers or platforms may be established outside the European Economic Area. In these cases transfers take place only to countries covered by a European Commission adequacy decision (e.g. companies certified under the EU-US Data Privacy Framework) or under the standard contractual clauses approved by the Commission.
Your rights
At any time you can ask us to:
- confirm whether we process your data and give you a copy (access, Article 15);
- correct it (Article 16) or erase it (Article 17);
- restrict its processing (Article 18);
- object to processing based on legitimate interest (Article 21): we will then stop processing your content, unless there are compelling legitimate grounds or legal obligations (e.g. pharmacovigilance).
Write to info@thatmorning.com including, if possible, the link to the content or the username concerned: we need it to find the data about you. We reply within one month. If the processing is carried out on behalf of a client, we still handle your request and pass it on to the client.
You also have the right to lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the authority of your country of residence.
Updates
This notice may be updated. The version in force is always published at this address, with the date of the last update.