Consent Privacy Policy

Information notice under Art. 14 of the REGULATION (EU) 2016/679 (GDPR)

Dear Sir/Madams, in compliance with Articles 14 and 28 of Regulation (EU) 2016/679 (General Data Protection Regulation or ”GDPR”), a Nordic affiliate of the Italfarmaco Group, CampusPharma AB has appointed WebExpress AB as a Data Processor for Email Consent Collection. This appointment enables WebExpress AB to carry out specific processing activities, particularly the collection and management of consent for email communication. As required under Article 14 of the GDPR, where personal data is not directly obtained from the data subject by CampusPharma AB, but collected through its Data Processor, WebExpress AB shall ensure that:
  1. Data subjects are informed of the identity and contact details of CampusPharma AB.
  2.  The purposes of data processing and the legal basis, including the consent of the data subject, are clearly communicated.
  3. Any further information necessary to guarantee transparent and lawful processing is provided, as outlined in this Privacy Policy.
The data processing activities undertaken by WebExpress AB shall include:
  • The secure collection and storage of personal data necessary for obtaining email consent.
  • Ensuring that data subjects are properly informed in compliance with Article 14, including the means to access or withdraw their consent.
  • Transmission of collected consent to CampusPharma AB, ensuring compliance with the GDPR principles of transparency, lawfulness, and accountability.
WebExpress AB agrees to:
  • Act solely under the instructions from CampusPharma AB for all processing activities.
  • Implement appropriate technical and organizational measures to protect personal data from unauthorized access, processing, or disclosure, as required by GDPR.
For inquiries regarding the role of WebExpress AB as a Data Processor or data processing activities, please contact CampusPharma AB info email at: This appointment ensures that all processing activities related to email consent collection are conducted in compliance with GDPR, safeguarding the rights and freedoms of data subjects, as detailed in Article 14.

Information notice under Art. 13 of the GDPR of the REGULATION (EU) 2016/679 (GDPR)

Please be informed that the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter also “GDPR”) provides the regulations concerning the protection of persons regarding the processing of personal Data. In accordance with the requirements of art. 13 of GDPR, pleased be informed as follows: Personal Data processing means any operation or set of operations which is performed on personal Data or on sets of personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. 1. Controller. Personal Data Protection Officer For the purposes of this document, the following are joint controllers of your Personal Data (the “Joint Controllers” and, each, the “Joint Controller”): – Italfarmaco S.p.A., with registered office at Viale F. Testi, 330 20126 Milan (Italy) – each of the companies controlled and/or participated in, directly or indirectly, by Italfarmaco S.p.A. and adhering to the joint controllership agreement (the “Affiliates”). The Joint Controllers have entered into a joint controllership agreement (the “Joint Controllership Agreement”) to govern their respective duties and responsibilities with respect to the processing of Your Personal l Data. A complete list of the Joint Controllers can be obtained by requesting to the Personal Data Protection Officer c/o Italfarmaco S.p.A. Via dei Lavoratori, 54 20092 Cinisello Balsamo (MI) or the following e-mail address: infoprivacy.italy@italfarmacogroup.com The Personal Data Protection Officer (DPO) of Italfarmaco S.p.A. is available to reply to any request sent to the following e-mail address: infoprivacy.italy@italfarmacogroup.com or at the address: Personal Data Protection Officer c/o Italfarmaco S.p.A. Via dei Lavoratori, 54 20092 Cinisello Balsamo (MI). 2. Categories of Personal Data and source of Personal Data The Joint Controllers collect your name, contact details (such as address, e-mail, phone numbers), personal data related to work and education history. 3. Purposes of the Personal Data processing The Joint Controllers have set up a corporate CRM, which is the support tool for managing the Italfarmaco Group’s relations with its heath care professionals. Italfarmaco, together with the Affiliates adhering to the Joint Controllership Agreement, are joint controllers of the Personal Data contained therein, due to the purposes of the unitary management of the relations with its heath care professionals. Given the above, Personal Data will be processed by the Joint Controllers, as part of their respective activities, for the purposes of: a) comply with legal obligations (anti-corruption law, transparency obligations) as well as provisions issued by authorities empowered by law or by supervisory and control bodies. b) protect Company’s interests and carry out its defensive rights in legal proceedings. In addition, with prior consent, the above personal data may be used for the following purposes: c) Provide medical-scientific information or non-promotional or promotional material (regularly approved by the competent authorities) related to diseases and products d) Comply with regulations of pharmaceutical industry associations to which company adheres and which are responsible for controlling the activities of scientific medical information e) Sending by e-mail, SMS or other electronic systems, of informative medical-scientific material (regularly approved by the competent authorities) on products and/or promotional/non promotional activities initiated and organized by the company f) perform marketing research g) definition of your technical-scientific areas of interest and of your professional profile. through indicative estimates by company’s medical-scientific representatives and use of anonymous market data regarding your interest in the therapeutic areas pertaining to the company, based on your professional activity and of your current and potential patients, to: i. Enable visits to be planned and guide the scientific information and product advertising activities carried out by company’s medical-scientific representatives and the company’s authorized personnel ii. Optimizing our technical-scientific information service through an interaction that is truly targeted to the doctor’s scientific update needs for greater protection of collective health. h) definition of your technical-scientific areas of interest and of your professional profile, through indicative estimates by company’s medical dept. team based on your professional activity and of your current and potential scientific interest, in order to: i. Enable visits to be planned and guide the medical scientific exchange activities carried out by company’s medical dept. team and the company’s authorized personnel ii. Optimizing our scientific exchange activities through an interaction that is truly targeted to the doctor’s scientific update needs for greater protection of collective health. 4. Nature of the provision of Personal Data and consequences of the refusal. Legal Basis Company informs you that the provision and processing of personal data is: I. With reference to the processing of data point 3 letters a) and b) compulsory insofar as it is necessary for the fulfilment of obligations laid down by law, regulation and/or European legislation. The legal basis for the aforementioned processing consists in the fulfilment of a legal obligation, pursuant to Art. 6(1)(c) of GDPR and the legitimate interests of the data controller pursuant to Art. 6(1)(f) of GDPR II. With reference to the processing of data point 1 letters c), d) e), f), g) and h), optional and free. Your consent constitutes the legal basis for the aforementioned data processing, pursuant to Art. 6, paragraph 1 letter a) GDPR. Any refusal on the part of the data subject to provide such data will result, in the cases of sub I. in the impossibility of establishing relations with the company whose purposes are indicated in point 1 for which knowledge of the data is objectively indispensable and, in the cases of sub II., the impossibility of carrying out the processing operations for the individual purposes for which consent is not given. 5. Methods of processing and communication of personal data The processing of the Personal Data will be carried out by authorized persons using appropriate tools to ensure security and confidentiality and may be carried out manually or with the support of manual, computerised and electronic tools to memorize, organize and transfer Personal Data. The Personal Data will be accessible only to authorized persons, who are expressly in charge and instructed by the Joint Controller with regard to the processing of Personal Data pursuant to Article 29 of the GDPR. Furthermore, other trusted companies will carry out, as Personal Data processors, the processing of Personal Data. These companies perform technical and organizational tasks on behalf of the Joint Controller (e.g. companies responsible for the technical management and maintenance of the IT System or third parties, with whom the Joint Controller collaborates in business services, consultancy firms). The Joint Controller has appointed the aforementioned companies as external Personal Data Processors pursuant to Article 28 of the GDPR. The Personal Data may be transferred to other Italfarmaco Group companies in Europe in compliance with the GDPR (i.e. Intercompany Joint Controllership Agreement or Personal Data Processor appointments). An updated list of Personal Data Processors is available, on request, sending a communication to the addresses above. Moreover, in addition to the aforementioned subjects, the Personal Data might be communicated, when required or provided by applicable laws, to competent supervisory authorities, tax authorities and other authorities, within the respective area of competence. As to the potential transfer of Personal Data to non-EU countries, included countries that could not guarantee the same level of Personal Data protection provided for by the GDPR, the Joint Controller informs you that the processing will be carried out in compliance with GDPR, i.e. through gathering your consent, by the adoption of standard clauses approved by the European Commission, participating to international programs for the free movement of Personal Data or working in countries deemed safe by the European Commission. Personal Data will not be disclosed in any way. 6. Personal Data retention period The personal data will be processed for the above-mentioned purposes until you decide to revoke your consent and/or obtain the termination of the processing. Your personal data will be retained for 10 years from the termination of the processing or from the date of a binding decision issued by a competent authority (e.g. court ruling), whichever is later, for longer periods of time prescribed by law. 7. Personal Data Subject rights According to articles 15 to 22 of the GDPR, the Personal Data subject has the right to: a) Obtain from the Data Controllers the knowledge whether the Personal Data are being processed and, where applicable, have access to them b) Rectification and right to erasure, obtaining the rectification of inaccurate and/or incomplete Personal Data, as well as the erasure of Personal Data when the request is legitimate c) Request suspension of the processing when the request is legitimate (right to restriction of processing) d) Personal Data portability, meaning the right to obtain Personal Data in a structured format, ordinary used and readable, as well as the right to transfer Personal Data to other controllers e) Object to the processing of Personal Data f) Complain about the collection, processing, use, and disclosure of your personal information to the national Personal Data protection authority. For a complete list please visit: https://gdpr-info.eu/chapter-3/

CONSENT

to the processing of my personal data, for the purpose indicated in art. 2 Lett. c) (Provide medical- scientific information or non-promotional or promotional material) within the limits and using the methods indicated in the information sheet provided to me with this document.
to the processing of my personal data, for the purpose indicated in art. 2 Lett. e) receiving by: [X] e-mail
of informative medical- scientific material (regularly approved by the competent authorities) on products and/or promotional / non promotional activities within the limits and using the methods indicated in the information sheet provided to me with this document.
to the processing of my personal data, for the purpose indicated in art. 2 Lett. f) (marketing research) within the limits and using the methods indicated in the information sheet provided to me with this document.
to the processing of my personal data, for the purpose indicated in art. 2 Lett. g) (definition of technical-scientific areas of interest and of professional profile by company’s medical-scientific representatives) within the limits and using the methods indicated in the information sheet provided to me with this document.
to the processing of my personal data, for the purpose indicated in art. 2 Lett. g) (definition of technical-scientific areas of interest and of professional profile by company’s medical dept. team) within the limits and using the methods indicated in the information sheet provided to me with this document.

Godkännande nummer