Laboratoire HRA Pharma SAS («HRA Pharma») pays particular attention to the protection of Personal data and to privacy and commits to respect them through the following fundamental values: to respect individuals expectations regarding the use of their personal data, to build and preserve trust of our consumers and other involved people or organizations, to prevent any damage with personal data and privacy and to be compliant with the letter and the spirit of Laws and Regulations regarding personal data protection.
HRA Pharma provides on-line resources with the aim to give information on health and our products.
The following terms take the definitions given by article 3 of the Law on Personal Data and have the following meaning:
1) personal data – any information referring directly or indirectly to a particular or identifiable individual (personal data subject);
2) operator – state agency, municipal authority, legal entity or individual who independently or in cooperation with others organizes and/or processes personal data as well as determines the purposes of, scope of personal data subject to the processing and data processing operations;
3) processing of personal data – any action (operation) or a combination of actions (operations) performed both automatically and manually with personal data, including collection, recording, systematising, accumulation, storage, modification (updating, changing), extraction, use, transfer (including disseminating, providing, access), anonymizing, blocking, deleting and destruction of personal data;
4) automated personal data processing — personal data processing by means of computer technology;
5) dissemination of personal data – actions related to making the data available to indefinite range of persons;
6) provision of personal data – actions related to making the data available to a defined person or a defined range of persons;
7) blocking of personal data – the temporary cessation of personal data processing (except for the cases when the processing is needed for personal data modification);
8) destruction of personal data – actions performed on personal data contained in the respective database that prevent such data from being restored and (or) actions aimed at the physical destruction of the tangible medium of personal data;
9) anonymization of personal data – actions performed on personal data that do not permit the identity of the individual concerned to be verified solely from such anonymized data;
10) personal data information system – a database that contains personal data as well as information technologies and hardware used for data processing;
11) cross-border transfer of personal data – cross-border transfer of personal data to a foreign state agency, foreign legal entity or individual located in a foreign state.
1. Information collected about you when you access this web-site
- Data which are directly shared by you when you contact us: your email address, content of your email and our answer.
- Information collected about you when you access this web-site: these data are collected through the use of the Web-site without being actively provided by you, thanks to several technologies, notably internet protocol (IP) addresses, cookies, Internet tags, browsing data. Main categories of data which are collected are:
- Domain and server (host) from which you access this web-site on the Internet;
- Address of the web-site from which you access our web-site, only in case of failure;
- Date, time, length of visits of this web-site and pages most frequently accessed;
- Your internet protocol (IP) address;
- Operating system of your computer and details of your web browser.
HRA Pharma is only processing these technical personal data by automated personal data processing.
2. What are the purposes for processing and the legal basis?
|· Your email address
· The content of your email
|Managing and responding to your questions Managing information received concerning adverse effects or quality claim|
|· Domain and server (host) from which you access this web-site on the Internet;
· Address of the web-site from which you access our web-site, only in case of failure;
· Date, time, length of visits of this web-site and pages most frequently accessed;
· Your internet protocol (IP) address;
· Operating system of your computer and details of your web browser.
|For our Web-site improvement, both our products and services improvement, identifying use of the Web-site trends, customization of the Web-site according to your tastes and to determine the efficacy of our product information
Performing statistics on the use of the Web-site to improve the quality of our Web-site
Managing and providing the Web-site
Processing of personal data by HRA Pharma is based on constitutional documents of HRA Pharma, Federal Law No 323-FZ dated 21 November 2011 On the Fundamental Principals of Protecting Individuals’ Health in the Russian Federation and consent of the users of the Web-Site to processing as the legal basis for processing of personal data.
3. Who are the recipients of your Personal Data?
HRA Pharma shall not disclose your Personal data to any third party without your consent. The access to your personal data is strictly limited to authorized people at HRA Pharma. These people are the ones for whom the access to such data is necessary to carry out their duties.
In addition to the categories of recipients above mentioned, HRA Pharma will provide your Personal data and you consent to such provision of data to our authorized Processors which will process your Personal data on behalf of and in accordance with the instructions of HRA Pharma on the basis of an agreement. Processors involved in managing consumer or user information are CPM located in Spain and RNI Conseil SAS located in France. Processors shall comply with the principles and rules of processing of personal data which are provided in the Law On Personal Data. The agreement with a Processor shall provide for: (i) the data processing operations which may be undertaken by the Processor, (ii) the purposes of processing, (iii) the obligations to provide for confidentiality of personal data and secure the safety of personal data whilst processing and (iv) the requirements to the protection of the processed personal data in accordance with the Law On Personal Data.
HRA Pharma will also communicate your personal data to relevant authorities as required by applicable laws.
In every case, your personal data will be processed according to applicable laws regarding protection of personal data and particularly according to the Law On Personal Data.
4. How long will your personal data be retained?
Regarding your personal information, the retention period is:
- until 3 years when Personal Data are processed for managing and providing the Web-site, performing statistics on the use of the Web-site;
- until 10 years after the commercialization of the last batch of product when Personal Data are processed for managing information received concerning adverse effects or quality claim.
Except where the applicable legislation authorises continued processing, the processing of personal data shall cease when the purposes of the processing of personal data are achieved, your consent to processing of personal data is revoked and/or illegitimate processing of personal data is identified.
5. Transfers outside of the European Economic Area
Collecting, recording, systemising, accumulating, storing, modifying (updating and changing) and retrieving of personal data are carried out by using the data bases located in the territory of Russian Federation.
HRA Pharma will implement requisite legal, technical and organizational measures or procure that such measures are implemented to ensure an appropriate level of security regarding the risk assessed and incurred and protect your personal data against unauthorized or accidental access, blocking, copying, providing, disseminating, disclosure, alteration or destruction and also from any other illegal actions in relation to personal data.
7. What are your rights and obligations? How can you exercise them?
Under applicable Law on Personal Data, you have a number of rights with regard to your personal data. Those rights are as follows:
- Right to Access – You can ask to see on a gratuitous basis the personal information HRA Pharma holds about you. You can also ask to obtain the personal information HRA Pharma holds about you which includes, but not limited to:
- confirmation of the processing of personal data by HRA Pharma;
- legitimate basis, purposes and methods of personal data processing used by HRA Pharma;
- name and location of HRA Pharma, information about parties (except for employees of HRA Pharma), who have access to personal data or who may be disclosed personal data under an agreement with HRA Pharma or on the basis of a federal law;
- scope of personal data processed which relates to you and source of such data unless other procedure for providing such data is set out by federal law;
- timing for processing of personal data, including its retention periods;
- procedure for exercising your rights under the Law on Personal Data;
- information on cross-border transfer of data which is carried out or planned to be carried out;
- name of a company and/or full name of an individual and their address who process personal data on behalf of HRA Pharma, if processing is or going to be instructed to such parties;
- other information required by the Law on Personal Data and other legislation.
Your request to obtain the above listed information should contain the number of your or your representative’s main identification document, its issuing date and issuing authority, information confirming that you are participating in a relationship with HRA Pharma (the reference number of and date of an agreement, any other reference information or information which in any other way confirms the processing of personal data by HRA Pharma), your or your representative’s signature. In the event we cannot provide you with access to your personal information (for instance, personal information may have been destroyed, erased or made anonymous), we will inform you of the reasons why.
- Correction or Deletion of Personal Information – HRA Pharma works to ensure that personal information in its possession is accurate, current and complete. You have the right to (i) request HRA Pharma to correct your personal data, (ii) block or destroy the personal data in case the personal data is incomplete, outdated, inaccurate, unlawfully obtained or not necessary for the stated purpose of processing, and (iii) take legal action to protect your rights.
- Withdrawal of Consent – If you have provided consent for the processing of your data, you have the right to withdraw that consent at any time which will not affect the lawfulness of the processing before your consent was withdrawn. In certain cases authorised by the Law on Personal Data we may have a right to continue processing of personal data after your consent is revoked.
- Objection to processing – you have the possibility to object to the processing of your personal data for direct marketing.
- Complaints – You have the right to lodge a complaint to the Federal Service for Supervision of Communications, Information Technology, and Mass Media or file a claim in court, if you believe that HRA Pharma has not complied with the requirements of the Law on Personal Data with regard to your personal data or infringed your rights in any other way. You have a right to protect your rights and legitimate interests and file a claim for reimbursement of damages and moral damages in court.
If you wish to exercise one of these rights, please send a request in this regard via email to firstname.lastname@example.org or by post to Laboratoire HRA Pharma, 200 avenue de Paris, 32320 Châtillon, France, stating both your name and your surname.
You are required to provide HRA Pharma with accurate personal data for processing.
8. What are the rights and obligations of HRA Pharma?
HRA Pharma has a right to:
- defend its rights in court;
- provide personal data to the third parties where authorised to do so by the current legislation and subject to your consent;
- refuse to provide personal data to you in cases allowed by the legislation;
- to use personal data without your consent when allowed by the legislation.
HRA Pharma shall comply with the obligations of a data operator in accordance with the legislation of the Russian Federation.
Effective date: August 16, 2018