HRA Pharma pays particular attention to the protection of Personal data and to privacy and commits to respect them through the following fundamental values: to respect individuals expectations regarding the use of their Personal data, to build and preserve trust of our consumers and other involved people or organizations, to prevent any damage with Personal data and privacy and to be compliant with the letter and the spirit of Laws and Regulations regarding Personal data protection.
HRA Pharma provides on-line resources with the aim to give information on health and our products.
The following terms “Personal data”, “Processing”, “Controller”, “Processor”, “Data protection authority” take the definitions given by article 4 of the General Data Protection Regulation (Regulation (EU) 2016/679).
1. Information collected about you when you access this website
- Data which are directly shared by you when you contact us: main categories of collected data are your email address, content of your email and our answer.
- Information collected about you when you access this website: these data are collected through the use of the Website without being actively provided by you, thanks to several technologies, notably internet protocol (IP) addresses, cookies, Internet tags, browsing data. Main categories of data which are collected are:
2. What are the purposes for processing and the legal basis?
|Managing and responding to your questions||Comply with our legal obligations and with our legitimate interest to answer your questions|
|For our commercial needs, notably data analysis, audits, new products development, our website improvement, both our products and services improvement, identifying use of the website trends, customization of the website according to your tastes and to determine the efficacy of our promotional campaigns||Comply with our legitimate interest to develop our relation with you|
|Managing information received concerning adverse effects or quality claim
|Comply with our legal obligations|
3. Who are the recipients of your Personal Data?
The access to your personal data is strictly limited to authorized people at HRA Pharma. These people are the ones for whom the access to such data is necessary to carry out their missions.
In addition to the categories of recipients above mentioned, HRA Pharma will transmit your Personal data to our authorized Processors which will process your Personal data on behalf of HRA Pharma. Processors involved in managing consumer care are CPM France and RNI Conseil.
HRA Pharma will also communicate your personal data to relevant authorities as required by applicable laws.
In every case, your personal data will be processed according to applicable laws regarding protection of personal data and particularly according to Regulation (EU) 2016/679.
4. How long will your personal data be retained?
In accordance with applicable data protection legislations, the information collected about you when you access the website will not be retained for more than two years.
Regarding your personal information, the retention period is:
- until 3 years when Personal Data are processed for managing and providing the Website, performing statistics on the use of the Website;
- until 10 years after the commercialization of the last batch of product when Personal Data are processed for managing information received concerning adverse effects or quality claim.
5. Transfers outside of the European Economic Area
Personal data will not the processed outside of the European Economic Area.
Only aggregated data or anonymized data should be processed out of the European Economic Area.
HRA Pharma will implement appropriate technical and organizational measures to ensure an appropriate level of security regarding the risk incurred and protect your personal data against unauthorized access, disclosure, alteration or destruction.
7. What are your rights? How can you exercise them?
Under applicable Data Protection Law, notably the Regulation (EU) 2016/679 you have a number of rights with regard to your personal data. Those rights are as follows:
- Right to Access – You can ask to see the personal information HRA Pharma holds about you. In connection with a request, HRA Pharma may request specific information about you to enable us to confirm your identity and right access, as well as search for and provide you with the personal information HRA Pharma holds about you. In the event we cannot provide you with access to your personal information (for instance, personal information may have been destroyed, erased or made anonymous), we will inform you of the reasons why.
- Correction or Deletion of Personal Information – HRA Pharma works to ensure that personal information in its possession is accurate, current and complete. If you believe that the personal information HRA Pharma holds on you is incorrect, inaccurate, incomplete or outdated, you may request the revision or correction of that information. If it is determined that personal information is inaccurate, incomplete or outdated, we will revise it.
- Withdrawal of Consent – If you have provided consent for the processing of your data, you have the right to withdraw that consent at any time which will not affect the lawfulness of the processing before your consent was withdrawn.
- Objection to processing – you have the possibility to object to the processing of your personal data including profiling, on grounds relating to your particular situation as provided by Data Protection law. When profiling is related to direct marketing you always have a right to object.
- Limitation to processing – you have the right to obtain from us restriction of processing in certain instances as provided by data protection law.
- Right to data portability – you have the right to receive the personal data, which you have provided to us, in a structured, commonly used and machine-readable format when the processing is based on your consent or on a contract. You also have the right to ask us to transmit it to another data controller of your choice.
- Complaints – You have the right to lodge a complaint to the Data Protection Authority, if you believe that HRA Pharma has not complied with the requirements of the GDPR with regard to your personal data
If you wish to exercise one of these rights, please send a request in this regard via email to email@example.com or by post to Laboratoire HRA Pharma, 15 rue Béranger, 75003 Paris, France, stating both your name and your surname, with a copy of your identity card.
If you have unresolved concerns you also have the right to complain to the data protection authority in the country where you live or work or place of the alleged infringement.
Effective date: May 25, 2018