If you have any questions in relation to this policy or generally how your personal data is processed by us please contact our Data Protection Responsible Person by email at email@example.com; or by letter addressed to: The Data Protection Responsible Person, Pharmanovia Sovereign House, Miles Gray Road, Basildon, Essex, SS14 3FR.
This policy applies to any personal data that we collect about you when:
WHO ARE WE?
We are a controller of your information which means that we are responsible for looking after it. We will use your personal data fairly, lawfully and in a transparent manner, and in accordance with the applicable Data Protection Laws.
HOW WILL WE USE YOUR PERSONAL DATA?
WHAT PERSONAL DATA DO WE COLLECT ABOUT YOU?
The types of personal data we collect depends on the interactions you have with us, but mainly these may include:
Each time you visit our websites or apps we may also automatically collect information and personal data about your computer for system administration including, where available, your IP address, operating system and browser type. We do this to help us identify returning visitors, enable visitors to move more easily around our websites or apps, and to assist in building up an anonymous profile based on visitor’s browsing patterns across the sites. Please see our Cookies Policy for further information about what information may be automatically collected when you visit our websites or apps.
|Special Categories of Personal Data|
Data Protection Laws define certain personal data as ‘special categories of personal data’ such as personal data regarding your racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purposes of uniquely identifying a person, data concerning your health (including mental and physical health), or data concerning your sex life or sexual orientation.
Exceptionally, we may sometimes ask you for some special category personal data or you may voluntarily give such personal data, such as health-related and racial data, when informing us of an adverse event, making a quality complaint or submitting a medical query to us, using our patient support apps, sending your CV or submitting your job application to us or otherwise participating in any of our recruitment processes for the purposes described in section 6 below, and only when this processing activity is expressly authorized by a law of the European Union or its Member States.
Suitability for employment will be evaluated on the skills and experience demonstrated during the recruitment process. Please note that you are not required to provide special category data when submitting a job application to us. If you do so voluntarily and the processing of such data is expressly authorized by a law of the European Union or its Member States, we will use it for: (a) statistical reporting requirements; and/or (b) in case of disability, for any required work place adjustments and/or to comply with applicable laws.
Criminal Conviction Data
Exceptionally, we may sometimes ask you for some criminal conviction data, when submitting your job application to us, when submitting immigration applications in the UK to the Home Office, or otherwise participating in any of our recruitment processes, for the purposes described in section 6 below, and only when this processing activity is expressly authorized by a law of the European Union or its Member States.
WHERE DO WE GET THIS INFORMATION FROM?
We collect some of your information directly from you, either through information that you give to us or information that we collect during your visits to our websites or apps or through your communications with us. We also obtain some information from other third parties, including the ones described in sub-section C below.
Please note that we may combine personal data we receive from other sources with personal data you give to us and personal data we collect about you.
You may share personal data about yourself and your circumstances by:
You are not obliged to provide your personal data to us. However, if you do not provide your personal data to us, we may not be able to provide services to you, respond to your queries, allow you onto our premises, process your job application or otherwise contact you.
We may collect personal data about you:
We may receive personal data about you from other third parties, including from:
WHY DO WE NEED YOUR PERSONAL DATA?
We may use the personal data we collect for the following purposes:
|Special Categories of Personal Data|
We will use your special category personal data described in section 4 above for the purposes of advising or otherwise communicating with you regarding any queries or reports you may submit and/or monitoring, tracking and responding to medical/health queries, quality complaints, adverse event reports, to comply with our legal, regulatory or compliance obligations and /or managing your job application. The legal basis of this processing is described in section 7 below.
For applicants in the UK, we will also use data about your race or national or ethnic origin as well as data relating to your immigration history, passport and biometric residence permit and other immigration documentation when carrying out right to work checks (including checks using the Employer Checking Service), retaining immigration documents, complying with our obligations as a Tier 2 sponsor, applying for and assigning certificates of sponsorship, and submitting immigration applications.
Criminal Conviction Data
We will only collect criminal conviction data where it is lawful to do so under the Data Protection Laws (only when this processing activity is expressly authorized by a law of the European Union or its Member States) and where it is appropriate to do so given the nature of the role to which your job application relates.
WHICH IS THE LEGAL BASIS FOR USING YOUR DATA?
When you enter into a transaction with us, a contract between you and us will have been formed. In order for us to negotiate, enter into and fulfil our obligations under such contract (e.g. to allow you to place an order for goods or services), we may need to collect, process and share (as further detailed below) your personal information. Please contact firstname.lastname@example.org for further information.
As indicated below, we may also pass your personal data to members of our company group (to see a full list of such group companies, please click here ) and other third parties where necessary for our legitimate business interests.
We are required to carry out a balancing test of our legitimate business interests in using your personal data outlined above against your interests and rights under the Data Protection Laws. As a result of our balancing test, which is detailed below, we have determined, acting reasonably and considering the circumstances, that we are able to process your personal data in accordance with the Data Protection Laws on the basis that this is necessary for our legitimate business interests.
Legitimate interest: We have a legitimate interest in processing your information as:
Impact of processing: We consider that it is reasonable for us to process your personal data for the purposes of our legitimate interests outlined above as such processing of your personal data does not unreasonably intrude on your privacy.
Notwithstanding the foregoing, please note that in accordance with Data Protection Laws and other applicable laws we may, on occasion, send you marketing messages by email and post about us, our products and services and our events and offers without your consent where you or your organisation have purchased similar goods or services from us and you have not unsubscribed.
|Special Categories of Personal Data and Criminal Conviction Data|
We may also use your special category personal data and criminal conviction data for the purposes described in section 6 above when processing is necessary for complying with a legal obligation to which we are subject, such as our pharmacovigilance and employment obligations, or where otherwise allowed by applicable Data Protection Laws.
WHO DO WE SHARE YOUR PERSONAL DATA WITH?
We (and the members of our group of companies) may also disclose your personal data to carefully selected third-party service providers who provide services such as:
We will only share your information with these suppliers where this is necessary for them to provide us with the services we need. We do not share your information with third parties for marketing purposes.
Please contact email@example.com for further information.
We may also disclose your personal data as required by law, including laws outside your country of residence, to comply with a court order or to comply with other legal or regulatory requirements, for example, to the relevant agencies responsible for the supervision and safety monitoring of medicines, data protection supervisory authorities or tax authorities. With applicants in the UK, we may also share your personal data with your legal advisers and also the Home Office (including UK Visas and Immigration).
The information which we collect about you may be transferred outside the European Economic Area as detailed in sections A, B and C above.
While some members of our group and third-party services providers are located in countries whose laws (according to the European Commission) do not offer the same level of protection to personal data as that granted by countries within the EEA, we and the members of our group of companies adopt appropriate security measures to prevent unauthorised and unlawful use of personal data. Furthermore, such transfers are usually supported by contractual commitments between such group entities and/or third parties to ensure that the relevant technical and organisational and other safeguards required by the Data Protection Laws have been put in place.
For further information on transfers outside of the European Economic Area and/or specific safeguard methods adopted, please contact firstname.lastname@example.org.
HOW LONG DO WE KEEP IT FOR?
We will keep your personal data for as long as required:
or as otherwise set forth below or notified by us to you.
In some circumstances, some of your data will be deleted in much shorter timescales, for example:
SECURITY OF YOUR PERSONAL DATA
When handling your personal data, we take appropriate measures reasonably designed to protect your information from unauthorised access, loss, misuse, disclosure, alteration or destruction. Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our websites or apps; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
YOUR RIGHTS IN RELATION TO YOUR PERSONAL DATA
In some instances, we may be unable to carry out your request, in which case we will write to you to explain why.
You have the right to request access to your personal data
You have the right to request confirmation that your personal data is being processed, access to your personal data (through us providing a copy) and other information about how we process your personal data.
You have the right to ask us to rectify your personal data
You have the right to request that we rectify your personal data if it is not accurate or not complete.
You have the right to ask us to erase your personal data
You have the right to ask us to erase or delete your personal data where there is no reason for us to continue to process your personal data. This right would apply if we no longer need to use your personal data to provide services to you, where you withdraw your consent for us to process special categories of your personal data, or where you object to the way we process your personal data (see sub-section F below).
You have the right to ask us to restrict or block the processing of your personal data
You have the right to ask us to restrict or block the processing of your personal data that we hold about you. This right applies where you believe the personal data is not accurate, you would rather we block the processing of your personal data rather than erase your personal data, where we do not need to use your personal data for the purpose we collected it but you may require it to establish, exercise or defend legal claims.
You have the right to port your personal data
You have the right to obtain and reuse your personal data from us to reuse for your own purposes across different services. This allows you to move personal data easily to another organisation, or to request us to do this for you.
You have the right to object to our processing of your personal data
You have the right to object to our processing of your personal data on the basis of our legitimate business interests, unless we are able to demonstrate that, on balance, our legitimate interests override your rights or we need to continue processing your personal data for the establishment, exercise or defence of legal claims.
You have the right not to be subject to automated decisions
You have the right to object to any automated decision making, including profiling, where the decision has a legal or significant impact on you.
You have the right to withdraw your consent
You have the right to withdraw your consent, at any time, where we are relying on it to process your personal data.
We do not knowingly collect, retain or use personal data received from children under 13 years of age, and no part of our websites or apps is directed to children under the age of 13. If your child has provided us with personal information without your consent, you may inform us at email@example.com, or write us a letter to the address given at the beginning of this policy. If we discover that we have received or collected any personal information from children under 13 years old, we will take steps to delete such information promptly.
WHAT IF YOU HAVE A COMPLAINT?
You also always have the right to lodge a complaint with the competent data protection authority of your country of residence (in the United Kingdom, the Information Commissioner’s Office at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom, www.ico.org.uk).
SOLE TRADERS, PARTNERSHIPS AND BUSINESSES
THIRD PARTY AND SOCIAL MEDIA WEBSITES AND APPS
Our websites and apps may, from time to time, contain links to and from the websites and/or apps of third parties. If you follow a link to any of these websites or apps, please note that these websites and apps have their own privacy policies and that we do not accept any responsibility or liability for these policies or your use of those websites and apps.
MERGER, SALE, OR OTHER ASSET TRANSFERS
If we are involved in a reorganisation, acquisition, asset sale, merger, financing, transition of services to another provider, due diligence, bankruptcy or receivership, your information may be disclosed and transferred in connection with and as part of such a transaction as permitted by law and/or contract.
REFERENCES TO THE EU/MEMBER STATES
For the purposes of this policy, references to the EU or its Members States shall include the United Kingdom.
This policy was last reviewed and updated in May 2023.