PRIVACY NOTICE

This notice explains how and why CASEN RECORDATI, S.L. uses your personal data (for example. when we provide you with information that you have requested, within the framework of any contract under which you provide services to CASEN RECORDATI, S.L., or when you simply use this website (hereinafter the “Website”) owned by CASEN RECORDATI, S.L.) or when you are contacting us for any other reason. In all cases, CASEN RECORDATI, S.L. understands and respects your privacy and recognizes that especially the information about the health and health care of a person is confidential and sensitive.

In this notice when we talk about personal data we refer to any information relating to an identifiable natural person (in this case “the Data Subject” or “you”). For the purposes of this notice, CASEN RECORDATI, S.L. is the responsible, that is, CASEN RECORDATI, S.L. determines how and to what extent your personal data will be processed (the person in charge is also referred to in this notice as “we”, “our” and “us”).

You should read this notice, so that you know what personal data we collect about you, what we do with it and how you can exercise your rights in this regard. You should also read any other privacy notice we provide to you, which may be applicable to our use of your personal data in specific circumstances from time to time. If you have questions about this notice, you can contact the Data Protection Delegate of the RECORDATI Group, or the Key Person for Privacy of CASEN RECORDATI, S.L., whose contact details appear in the following section.

  1. Data Controller / Data Protection Officer

Identity: CASEN RECORDATI, S.L. – NIF: B81094922

Postal address: AUTOVIA LOGROÑO KM 13,300 – 50180 – UTEBO – ZARAGOZA – (ESPAÑA)

Data Protection Officer of the RECORDATI Group: groupDPO@recordati.it

Key Person for the Privacy of CASEN RECORDATI, S.L.: lopd@casenrecordati.com


  1. What kind of personal data do we collect and where do we get it from?

The personal information we process about you can broadly fall into five main categories: (i) Contact Information; (ii) Contract Information; (iii) Candidate Information, (iv) Navigation Information and (v) Medical Information.

We collect your personal data from limited sources, in particular the following:

▪ Directly through you, by providing them to us voluntarily (after obtaining, where appropriate, your consent).

▪ Automatically through this Website (see our cookie policy on https://casenrecordati.com/en/terms-and-conditions/cookies-policy/ ).

▪ Of IQVIA (formerly IMS Health) with address at C / Juan Esplandiú, 11 – 6º, 28007 Madrid, as a provider of the ONE KEY platform, which contains a database of health professionals worldwide, and that pharmaceutical companies use to manage the different legitimate activities and services contracted with health professionals in different medical specialties.

▪ Of available public resources.

▪ From a healthcare professional or a third party service provider engaged by us, in the field of adverse reaction management (pharmacovigilance) or clinical trials and other clinical research.

The following table sets out the different types of personal information we collect and the sources from which we collect it:

In the cases expressly indicated in this notice, we may process health-related data, genetic data and/or biometric data. We do not process other special categories of personal data, such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or data concerning the sex life or sexual orientation of a natural person. We do not make automated decisions based on profiling.


  1. What do we do with your personal data, and why?

We use your personal data for different purposes. We must always have a “legal basis” (i.e. a reason, stipulated by law) for processing your personal data. The table below sets out the purposes for which we process the different categories of your personal data and the corresponding legal basis for such processing. For some processing activities, we consider that more than one legal basis may be applicable, depending on the circumstances:

3.1. Website Visitors

3.2. Healthcare professionals

3.3. Job seekers

3.4.Patients

*The consent for the processing of data of children under 14 years of age, will only be lawful if it is that of the holder of parental authority or guardianship, with the scope determined by the holders of parental authority or guardianship.

3.5.Website visitors, healthcare professionals, job seekers and patients.

3.6.Cookies

In the case of visitors to the Website, in order to speed up and improve navigation on said Website, cookies are used when they access it. For more information regarding how we use cookies, please read our (https://casenrecordati.com/en/terms-and-conditions/cookies-policy/).


  1. Who do we share your personal data with, and why?

As part of the data processing for the purpose referred to in paragraph above, the data may be disclosed or otherwise made accessible to the companies belonging to the Recordati Group and to third parties.

Where necessary, the Data Controller will appoint third parties as its Data Processors pursuant to Article 28 of the GDPR.

Data will not be transferred outside the Economic European Area. This said, any Data transfer outside the Economic European Area will be carried out in compliance with the applicable provisions of GDPR.


  1. How do we keep your personal data secure?

5.1. We will implement appropriate security measures to protect your personal data from any unlawful or unauthorised processing and accidental loss, destruction or damage.

5.2. Please note, however, that in relation to the personal data you submit to us online, we cannot fully guarantee the security of the data we receive in this way. The transmission of data over the Internet is at your own risk.


  1. How long will we keep your personal data?

6.1. We will only retain your personal data for a limited period of time, and will not exceed the time necessary to fulfil the purposes for which we are processing it. This will depend on a number of factors, including: (i) any rules we are required to follow; (ii) if both parties are in litigation or with any third party; (iii) the type of information we hold about you; and (iv) if you or a regulatory authority requires us to keep your personal data for a valid reason. In any case, we will not keep your data beyond the legally established conservation and limitation periods of responsibilities.

6.2. When it is no longer necessary to keep such data for such purposes, they will be deleted with appropriate security measures to ensure the pseudonymization of the data or the total destruction thereof.


  1. Publication of transfers of value

7.1. What data does the information related to transfers of value contain?

▪ Business address

▪ First name, last name

▪ ID

7.2.  Where will personal data related to transfers of value be published?

The personal data of the Data Subject and relating to transfers of value will be published individually and cumulatively for each category, in the form shown in the table below, on the company’s website:

7.3. Who will be able to know my personal data related to transfers of value?

In accordance with the Code of Good Practices of FARMAINDUSTRIA, your data will be published on the website of CASEN RECORDATI, S.L. (casenrecordati.com) and will be freely accessible to the public, in compliance with the current transparency standards of the Pharmaceutical Industry.

7.4. How long will data relating to transfers of value be kept?

The data of the Interested Party will be kept for a minimum period of 5 years from the end of each period, and the information that must be published, to comply with the duty of transparency, at least for 3 years from the date of publication of said information, which will be carried out, during the semester following the applicable period, in compliance with the provisions of the Code of Good Practices of FARMAINDUSTRIA, unless in any case, a shorter period is legally established.


  1. What are your data protection rights, and how can you exercise them?

8.1. In the event that our processing of your personal data is based on your consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of the processing based on consent prior to its withdrawal. If you choose to withdraw consent, we will stop processing your personal data for that purpose, unless there is another legal basis on which we can rely, in which case we will inform you.

8.2.In the event that the processing of your personal data is based on legitimate interest, you may object to this processing at any time. If you do so, we will stop processing such data, unless we inform you either of the existence of a compelling reason why such processing should continue, or because such processing is necessary to establish, exercise or defend a legal claim.

8.3. You are entitled to (subject to certain limitations) to:

(I) access your personal data and be provided with certain information in relation to it, such as the purpose for which your data is processed, the persons to whom it is disclosed and the period for which it will be stored

RIGHT OF ACCESS

(II) require us to rectify any errors in your personal data without undue delay;

RIGHT TO RECTIFICATION

(III)require us to erase your personal data;

RIGHT TO ERASURE

(IV) require us to restrict the processing of your personal data;

RIGHT TO RESTRICTION OF PROCESSING

(V) receive the personal data you have provided us, in an electronic readable format, in the event that we are processing your data based on your consent or because it is necessary for your contract with us, and this in case the processing is automated;

RIGHT TO PORTABILITY

(VI) object to a decision we make based solely on the automated processing of your personal data.

RIGHT TO OBJECT

In the event that you wish to exercise any of the aforementioned rights, please contact us at (lopd@casenrecordati.com).

8.4. We also recommend that you inform us if you have any concerns about how we are processing your personal data so that we can try to remedy such a situation. Likewise, if you consider that we are breaching our obligations under data protection regulations, you are always entitled to file a complaint with the competent supervisory authority (in Spain the Spanish Agency for Data Protection – www.aepd.es).


This notice may be subject to future updates so we recommend that you periodically consult its contents.

For any questions or suggestions, please write to ebusiness@casenrecordati.com