Data Protection

Scope and Who We Are

This Data Protection Notice explains how AutoradioRx (lautoradio.net), a United States–based pharmaceuticals resource, processes personal data in connection with its services, including educational content that connects medications, diseases, and supplements through evidence and clear explanations. This Notice is intended to align with applicable United States privacy laws while honoring the rights afforded under the EU/UK General Data Protection Regulation (GDPR) for visitors where those frameworks apply.

AutoradioRx provides drug monographs, dosage and side-effect overviews, interaction insights, and condition guides, and offers updates related to radiopharmaceuticals and imaging-driven discoveries. We do not provide medical advice and our content is for informational purposes only.

Data Controller and Contact

Data Controller: Tamsin Riverton

Postal Address: 5215 Oakton St, Skokie, IL 60077, United States

Email: [email protected]

No dedicated Data Protection Officer has been appointed. Please direct all privacy inquiries to the contact above.

Definitions

“Personal data” means any information relating to an identified or identifiable natural person. “Processing” means any operation performed on personal data, such as collecting, storing, using, disclosing, or deleting. “Special category data” includes data concerning health.

Categories of Personal Data We Process

  • Identification and contact details (e.g., name, email address you provide to us).
  • Account and preference data (e.g., saved settings, notification choices).
  • Usage and log data (e.g., pages viewed, referring/exit pages, timestamps, IP address, user agent, device and browser information).
  • Cookie and tracking data (e.g., identifiers, analytics data, consent preferences).
  • Health-related content you may submit in queries or forms (e.g., topics of interest, medication names you search or mention). We do not require such data and request that you share only what is necessary for your inquiry.
  • Communications (e.g., messages you send to us, feedback, support requests).
  • Transactional data if paid features are used in the future (e.g., limited billing metadata; we rely on payment processors for card data).

Sources of Personal Data

  • Directly from you (e.g., forms, emails, account registration).
  • Automatically through our website and cookies/analytics tools.
  • Service providers and partners (e.g., analytics vendors), where permitted by law and your settings.
  • Publicly available sources where legally permissible.

Purposes of Processing

  • To provide, maintain, and improve our services and content.
  • To personalize content and remember your preferences.
  • To perform analytics, measure performance, and understand audience engagement.
  • To communicate with you, respond to inquiries, and provide support.
  • To manage security, prevent fraud and abuse, and ensure integrity of the service.
  • To comply with legal obligations and enforce our terms.
  • With your consent, to send informational updates or optional communications.

Lawful Bases for Processing (GDPR)

  • Consent: for non-essential cookies, certain analytics and marketing, and any processing of special category data you voluntarily provide.
  • Legitimate interests: to secure and operate our services, perform audience measurement, prevent fraud, and improve content—balanced against your rights.
  • Contract performance: where processing is necessary to provide requested features or services.
  • Legal obligations: to comply with applicable laws, court orders, or regulatory requirements.

Special Category and Health-Related Information

AutoradioRx is not a healthcare provider and is not a HIPAA covered entity. We do not seek to collect health information. If you choose to share health-related details in your communications with us, we will process such information only as necessary to address your request, based on your explicit consent or to protect vital interests where applicable. Please avoid sharing sensitive information unless it is essential.

Cookies, Analytics, and Tracking Technologies

We use cookies and similar technologies to operate and improve our website.

Categories of Cookies

  • Strictly necessary: required for core functionality and security.
  • Functional: remember settings and user choices.
  • Analytics: measure traffic and performance to improve content.
  • Advertising or cross-context behavioral: used to deliver or measure ads where applicable (used only with consent where required).

Your Choices

  • You can manage cookie preferences via your browser or consent tools we provide. Disabling certain cookies may affect site functionality.
  • We endeavor to honor widely recognized browser-level opt-out signals (such as global privacy control signals) for selling/sharing where required by law.

Do Not Sell or Share (U.S. State Privacy Laws)

We do not sell personal data for monetary consideration. If we engage in cross-context behavioral advertising, such activity may be considered a “sale” or “sharing” of personal information under some U.S. state laws. You may opt out of sale/sharing by adjusting cookie settings and by emailing [email protected] with the subject line “Do Not Sell or Share.” We will honor applicable opt-out signals where legally required.

Disclosure to Third Parties

  • Service providers (e.g., hosting, security, analytics, customer support) under appropriate contractual safeguards.
  • Advertising or measurement providers, with your consent where required.
  • Legal, regulatory, and compliance recipients (e.g., to comply with law, enforce terms, protect rights or safety).
  • Business transfers (e.g., merger, acquisition, or asset sale), subject to this Notice or a successor notice that is materially consistent.
  • Aggregated or de-identified data that cannot reasonably identify you.

International Transfers

We are based in the United States. If we transfer personal data from the EEA/UK/Switzerland to the United States or other countries lacking an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses and implement supplementary measures as needed. You may contact us to obtain information about such safeguards.

Data Retention

  • Account data: retained for the life of the account and for a reasonable period thereafter (typically up to 24 months) for recordkeeping and legal purposes.
  • Communications/support: typically retained up to 24 months after resolution unless longer retention is required by law.
  • Analytics: typically retained up to 26 months in aggregate form.
  • Server logs and security data: typically retained up to 12 months, subject to extension in case of investigations.
  • Backups: typically retained up to 90 days on rolling cycles.
  • Anonymized or de-identified data may be retained indefinitely.

Security Measures

We implement technical and organizational measures designed to protect personal data, including encryption in transit, access controls, least-privilege practices, audit logging, and vendor due diligence. No method of transmission or storage is entirely secure; we cannot guarantee absolute security.

Your Rights

GDPR Rights (EEA/UK, where applicable)

  • Access: obtain confirmation and a copy of your personal data.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: request deletion where grounds apply.
  • Restriction: request temporary limitation of processing.
  • Portability: receive data in a structured, commonly used format and transmit it to another controller.
  • Objection: object to processing based on legitimate interests or direct marketing.
  • Withdraw consent: where processing is based on consent, withdraw at any time.
  • Complaint: lodge a complaint with a supervisory authority. Contact us first so we may address your concerns.

U.S. State Privacy Rights (e.g., CA, CO, CT, UT, VA)

  • Right to know/access and obtain a portable copy of certain personal information.
  • Right to correct inaccuracies.
  • Right to delete, subject to exceptions.
  • Right to opt out of sale/sharing and targeted advertising.
  • Right to limit the use of certain sensitive data (if applicable).
  • Right to non-discrimination for exercising privacy rights.
  • Right to appeal a denial of a request (where applicable). Appeal instructions will be provided in our response.

Exercising Your Rights

To submit a request, email [email protected]. Please include your name, the nature of your request, your jurisdiction, and sufficient information for us to verify your identity. We may request additional information to verify and to locate the data. We aim to respond within one month for GDPR requests and within 45 days for U.S. state law requests, subject to permitted extensions.

Automated Decision-Making

We do not engage in automated decision-making or profiling that produces legal or similarly significant effects without human involvement.

Children’s Privacy

Our services are not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will take appropriate action. For users under the age thresholds set by applicable law (e.g., under 16 in some jurisdictions), certain processing will occur only with appropriate consent where required.

Third-Party Sites and Content

Our website may reference third-party content or services. We are not responsible for the privacy practices of third parties. Review their notices where applicable.

Changes to This Notice

We may update this Notice to reflect changes in our practices or legal requirements. Material changes will be posted on this page, and the “Last Updated” date will be revised. Continued use of the site after an update indicates your acknowledgment of the revised Notice.

Effective Date

Last Updated: September 12, 2025

Write a comment