Privacy
Pursuant to Article 13 of Regulation (EU) 2016/679 on the protection of individuals withregard to the processing of Personal Data (hereinafter ‘GDPR’).
Dear User,
Thank you for visiting chiesi.com, the institutional website of Chiesi Farmaceutici S.p.A. (hereinafter ‘Chiesi’).
In this section You will find all the information You need to understand how we manage Your Personal Data, in particular in compliance with Regulation (EU) 2016/679 (hereinafter ‘GDPR’).
Click one of the sections below to find out more:
In this section You can find all the information relating to the processing of Your data carried out by reason of Your navigation on our website, unless You decide to access different sections of the site for which a separate information notice is provided.
(1) Processing Purposes
Technical and analytical purposes
To ensure a reliable User experience, we may process technical data or usage data that may indirectly reveal Your identity. This data is collected automatically during the normal operation of each website and is processed for technical purposes (including troubleshooting, testing, system maintenance, support and technical reporting), or statistical and analytical purposes to improve the User experience.
The latter are usually processed in aggregate and non-identifiable form for statistical purposes.
For example, usage data may be processed to measure the engagement rate, or the time spent on a certain section or feature of the Site.
(2) Categories of Personal Data
Technical Data
Including the IP address, browser type and version, time zone and Your location based on the IP address from which You connect, general information about the hardware and operating system of the device used to browse the Site. This data is only used for technical and statistical purposes, as specified above.
Usage Data
Including information on how the website is used, such as the time spent on a particular section.
(3) Legal Basis of the Processing
Performance of Contractual Obligations
With the User accessing and using the Site and the services offered therein.
Legitimate Interest
To ensure the security of the Site and prevent online frauds.
(4) How we share Your Personal Data
Chiesi may share Your Personal Data with other companies, organisations and individuals if any of the following circumstances arise:
- Sharing with Your express consent: after obtaining Your consent, we may share Your Personal Data with certain third parties or categories of third parties;
- Sharing in accordance with laws and regulations: we may share information required under applicable laws and regulations, to solve legal disputes or requests by administrative or judicial authorities
- Sharing with service providers: we may also disclose Your Personal Data to companies that provide services on behalf of or for Chiesi.
In the latter case, Chiesi guarantees the legitimacy of such sharing and will sign agreements and/or data processing clauses with the companies, organisations and individuals with whom Your Personal Data will be shared, requiring them to comply with this Policy and take appropriate security measures.
(5) Retention of Your Personal Data
| Technical, Usage Data and Cookie | Data processing is strictly limited to the User's browsing session on the Site. Please also refer to the Cookie Policy for more specific information on the use of cookies and similar technologies. |
In this section You can find all the information regarding the processing of Your Personal Data by Chiesi, including its affiliated Group Companies, should You decide touse our Chiesi Careers recruitment website to:
(i) create an account and provide Your application details
(ii) apply for a job opportunity with one of the companies belonging to the Chiesi Group.
Please note that the company of reference will be specified in each job advertisement.
For further information on Chiesi and its affiliates, please visit: https://www.chiesi.com/en/about-us/our affiliates/.
If You are based in the European Union, or if You are applying for an open position in a Chiesi Group company based in the European Union, Your data will be processed in accordance with Regulation (EU) 679/2016 (‘GDPR’).
On the other hand, if You are based in a country outside the European Union and You are applying for an open position in a Chiesi Group company based outside the European Union, local regulations will apply.
The Data Controller for the management of Your application will be the Chiesi Group company indicated in the job offer to which You may apply.
The Data Controller for the management of Your application will be the Chiesi Group company named in the job offer to which You may apply.
Our Site may include links to third-party websites, plug-ins and applications, suchas links to our Facebook, LinkedIn and Twitter pages.
Clicking on such links may allow the companies that own the websites to collect or share Your Personal Data.
In this regard, please note that we have no control over these websites and are not responsible for their privacy policies.
After You leave our Site, we encourage You to always read the privacy policy of each website You visit. We also encourage You to read the Social Media Terms of Use for more information about the terms of use of our social pages.
In this section You can find more information about the processing of Your data that may be collected in the event of spontaneous reports of adverse reactionssuspected to have occurred after taking a medicine.
(1) Processing Purposes
Legal Obligations
The Personal Data that You freely provide will be collected and processed solely for the purpose of fulfilling legal obligations relating to pharmacovigilance and, more specifically, for the purposes of identifying any unknown adverse reactions, improving information on suspected adverse reactions already known, assessing the causal link between drug administration and the observed adverse reaction, and notifying the competent authority of such information to ensure that the drugs used have a favourable benefit/risk ratio for the population.
(2) Categories of Personal Data
Identification data of the reporter
Name, surname, contact details.
Data relating to the person to whom the report relates
Initials, age, gender; special categories of data relating to health status may also be collected if they are the subject of the report.
(3) Legal Basis of the Processing
Fulfilment of legal obligations
Chiesi processes Your Personal Data on the basis of a legal obligation to which Chiesi itself is subject (EU Directive 2010/84, EU Directive 2012/26 and relevant national transposing legislation).
(4) How we share Your Personal Data
The data provided will be made available, for the purposes indicated above, to subjects accessing the National Pharmacovigilance Network as well as to subjects obliged to carry out pharmacovigilance activities (AIFA, marketing authorisation holders of medicinal products, Italian Regions, Local Health Units, Pharmacovigilance Office of hospitals or Scientific Research and Treatment Institutes).
The Personal Data provided may also be communicated, for the purposes indicated above, to the following categories of subjects:
- Other companies in the Chiesi Group or commercial partners both in Italy and abroad, including outside the EU in the manner specified below;
- Subjects whose right to access Personal Data is recognised by provisions of law and/or secondary legislation or orders of public authorities.
The subjects belonging to the categories listed above will use the data as autonomous data controllers and in relation to the specific activity carried out, or as data processors pursuant to Article 28 of the GDPR duly appointed by means of a dedicated appointment agreement, indicating the processing methods and security
measures that they will have to adopt for the management and storage of the Personal Data of which Chiesi is the Data Controller.
We may also communicate Personal Data:
- To third parties in the event of extraordinary operations (e.g. mergers, acquisitions, business transfers, etc.) and to our administrative, legal and medical consultants
- To other companies in our group or third parties even outside the territory of the European Union.
International Data Transfers
Whenever Your Personal Data is transferred outside the European Union, Chiesi will take all appropriate and necessary contractual measures to guarantee an adequate level of data protection, including - among others - agreements based on the standard contractual clauses for the transfer of data outside the European Economic Area, approved by the European Commission.
Personal Data will not be disseminated in any way.
(5) Retention of Personal Data
| Personal Data relating to the report and the reported person | Pharmacovigilance reporting data are retained for as long as the product is authorised and for 10 years from the expiry or withdrawal of the marketing authorisation of the product in the last country of marketing, except for any defensive needs of the Data Controller. At the end of this period, the data will be deleted or rendered anonymous in such a way that the data subjects cannot be identified, even indirectly or by linking to other databases. |
(1) Processing purposes
Request of medical information
Your Personal Data will be processed to manage and follow up Your request for medical information. For example, You may submit questions regarding therapeutic indications, drug interactions, ingredients, storage conditions or a request for available scientific evidence on a topic to aid clinical decision-making.
(2) Categories of Personal Data:
Identification data
For the above-mentioned purposes, Chiesi will only process Your identification data (e.g., first name, last name, e-mail, country, role - e.g., whether nurse, patient, caregiver, health professional, or other - and, for some countries e.g., Spain, Your telephone number and city)
Data included in the request of information
Chiesi may also process any other information You wish to share voluntarily through Your request.
With the exception of pharmacovigilance, the processing of so-called special categories of Personal Data as defined by Art. 9 of the GDPR (e.g., data on health status) and/or data relating to minors is expressly excluded.
Further information regarding Chiesi's processing of Personal Data for pharmacovigilance purposes is available here and in the dedicated privacy section.
(3) Legal Basis of the Processing
Consent
Consent is the legal basis for the processing. The communication of Your Personal Data for the above-mentioned purposes is optional. However, without it, we will not be able to comply with Your request. Therefore, any refusal to provide such data will make it impossible for Chiesi to respond to Your request.
Fulfilment of legal obligations
Your data may be processed without Your prior consent, to fulfil legal obligations (i.e. pharmacovigilance), to comply with laws and regulations.
Legitimate Interest
Your data may also be processed to exercise or defend a right of Chiesi in court.
(4) How we share Your Personal Data
Chiesi may share Your Personal Data with other companies, organisations and individuals if any of the following circumstances arise:
- Sharing with Your express consent: after obtaining Your consent, we may share Your Personal Data with certain third parties or categories of third parties;
- Sharing in accordance with laws and regulations: we may share information required under applicable laws and regulations, to resolve legal disputes or requests by administrative or judicial authorities
- Sharing with service providers: we may also disclose Your Personal Data to companies that provide services on behalf of or for Chiesi.
In the latter case, Chiesi guarantees the legitimacy of such sharing and will sign agreements and/or data processing clauses with the companies, organisations and individuals with whom Your Personal Data will be shared, requiring them to comply with this Policy and take appropriate security measures.
(5) Retention of Personal Data
| Personal Data related to the request | Time necessary to process the request and no longer than the time necessary to carry out all activities related to it, in any case for a maximum period of 10 (ten) years from receipt. |
| Personal Data related to pharmacovigilance and adverse events | Data concerning pharmacovigilance activities are retained for as long as the product is authorised and for 10 years from the expiry or withdrawal of the marketing authorisation of the product in the last country of marketing, except for any defensive needs of the Holder. |
Following these periods, Your Personal Data will be anonymised unless otherwise provided for by law.
(1) Processing purposes
Replying to enquiries
Your Personal Data will be processed in order to handle and reply to Your request.
(2) Categories of Personal Data
Identification data
e.g. first name, surname, place and date of birth, marital status, address, professional profile, etc.), which You wish to communicate to us.
Personal Data that may be contained in the request
Further Personal Data that You wish to communicate to us within the request.
We inform You that the processing of special categories of data is excluded and that, if You provide them, they will be deleted.
(3) Legal Basis of the processing
Consent
We inform You that Your consent is the basis of legitimacy of the processing. The provision of Your data, in relation to the purposes indicated, is optional but necessary to allow us to respond to Your request. Therefore, any refusal to provide this data will make it impossible for Chiesi to deal with Your request.
Legitimate interest
In order to comply with legal obligations, regulations and EU legislation, to assert or defend Chiesi's rights in court, to pursue legitimate interests and in all cases provided for in Articles 6 and 9 of the GDPR, where applicable, Your data may be processed even without Your prior consent.
(4) How we share Your Personal Data
Access to and processing of Your data are restricted to Chiesi personnel who need to process them in the performance of their duties.
In this regard, personnel have been assigned to process Personal Data with specific operating instructions, in which instructions are specified concerning the type of data collected and/or processed and the relative purposes; databases for access to Personal Data; security measures and precautions to be observed in data processing operations; scope of permitted processing, also for the purpose of receiving and correctly documenting consent or dissent to the processing operations described herein.
Chiesi, moreover, is part of a international Group; therefore, it is also possible that Your Personal Data may be transferred to other countries, even outside the European Union, to subsidiary or associated companies, as well as to external service companies, even if only for technical or IT reasons. With regard to the possible transfer of Your data to countries outside the European Union, including some that may not guarantee the same level of protection provided by the applicable privacy legislation, we would like to inform You that Chiesi will only proceed with their transfer in the presence of one of the conditions of legitimacy referred to in Chapter V of the GDPR.
(6) Retention of Personal Data
| Identification data | Your data will be retained for the period of time strictly necessary to fulfil the For the above-mentioned purposes we may keep some data even after for the time necessary to comply with the law. |
| Personal Data included in the request | Your data will be retained for the period of time strictly necessary to fulfil the purposes for which it was collected, i.e. to answer and process Your request. For the above-mentioned purposes we may keep some data even after and for the time necessary to comply with the law. |
In this section You will find all information about the processing of Your datafor Whistleblowing purposes.
If You submitted Your report through the SpeakUp&BeHeard website and platform, You can find the relevant privacy information here.
If You submitted Your report by voicemail, You can find the relevant privacy notice here.
This notice applies to providers that have entered into a contract with Chiesi Farmaceutici S.p.A. and whose data we process as Data Controller.
(1) Processing purposes
Contract management and execution
Personal Data will be processed for the correct and complete management of the pre-contractual, contractual and post-contractual relationship between the parties.
(2) Categories of Personal Data
Identification data
Name, surname, role, signature, addresses
Contact details
E-mail address, telephone number
Bank and financial data
e.g. payment data
Any additional Personal Data required for the above specified purposes.
(3) Legal basis of the Processing
Performance of contractual obligations
The processing of Personal Data is necessary for the performance of a contract to which the company is a party and the fulfilment of related contractual obligations.
Legal Obligations
Personal Data will also be processed to ensure compliance with legal and regulatory obligations by Chiesi, such as tax regulations.
Legitimate Interest
Personal Data processed for the purposes referred to in point 1 may be processed by Chiesi in order to take legal action and/or constitute itself in court as well as to exercise its right of defence or to enable Chiesi to carry out or take part in, manage or organise corporate operations, including mergers, acquisitions and restructuring
(4) How we share Your Personal Data
The Personal Data provided may be communicated, for the above-mentioned purposes, to the following categories of subjects:
· Third parties strictly authorised to make payments and related activities;
· Third parties appointed to audit the financial statements of Chiesi and to Public Authorities and Administrations for the fulfilment of legal obligations;
· Data processors or persons authorised by Chiesi within the scope of the services assigned to the execution of the Agreement and of the individual assignments.
(5) Retention of Personal Data
| Identification data | 10 years from the time the contract ceases to be effective |
| Contact details | 10 years from the time the contract ceases to be effective |
| Bank and financial data | 10 years from the end of the calendar year in which the administrative/accounting/fiscal document was drawn up or in which the Data Controller fulfilled its legal obligation. |
| Personal Data required for the contract execution | 10 years fromthe time the contract ceases to be effective. |
In the event of disputes, the retention term is the prescriptive term provided for by the law for the protection of rights, without prejudice in any case to longer retention periods provided for by specific sector regulations.
(1) Processing Purposes
Engagement
To engage You in connection with professional services and activities, including, by way of example, participation in events, congresses, advisory boards, training initiatives or other similar consultancy and collaborations.
Compliance
To comply with the applicable laws, regulations, or decisions of the competent authorities, in particular in the areas of pharmacovigilance of medical products and drug safety.
Internal administrative and management purposes
To communicate Your Personal Data to the affiliates for administrative activities.
(2) Categories of Personal Data
Identification data:
Your name, surname, personal contact details (e.g., address, phone number, e-mail address), VAT number, fiscal code.
Curriculum Vitae/Professional data
Your academic title, additional professional qualifications (e.g., postgraduate specialization diploma, postgraduate master, PhD), professional job title, area of expertise, registration in a professional register and registration date, lectures and publications;
Payment details
Amount payable, bank details.
(3) Legal Basis of the Processing
Fulfillment of legal obligations
Your data are necessary to comply with legal obligations.
Legitimate Interest
For Chiesi administrative and management purposes. Providing Personal Data for these purposes is optional and failure to do so will prevent the Controller from optimizing the internal administration and management of its activities.
(4) How we share Your Personal Data:
The processing of Your Personal Data is performed by authorized persons only, such as the employees of the Controller and our representatives, acting under the instructions of the Controller and accessing Your Personal Data on a need-to-know basis. To pursue the above-mentioned purposes, the Controller may also transfer Your Personal Data to the following third parties:
- to a subsidiary or an affiliate within the Chiesi Group for internal administrative and management purposes;
- to the competent public and governmental authorities, including judicial courts, when required by the applicable laws or regulations;
- to the service providers of the Controller (the “Data Processors”) such as cloud providers, direct marketing providers, or market research operators, which process Your Personal Data subject to appropriate contractual measures and instructions provided by the Controller and aimed at ensuring the protection of Your Personal Data.
International Data Transfers
Some of the above-mentioned recipients may be located in countries outside the European Economic Area ("EEA"). If the recipient is in a country which does not provide for adequate protection of Personal Data, we will take all necessary measures to ensure that the transfer out of the EEA is adequately protected as required by applicable laws (e.g., through the implementation of EU Standard Contractual Clauses). You can ask for a copy of such appropriate safeguards as well as the list of our Data Processors by contacting the Controller as set out below.
(5) Retention of Your Personal Data
| Identification data | 10 years from the time the contract ceases to be effective |
| Curriculum Vitae/Professional data | 10 years from the time the contract ceases to be effective |
| Payment details | 10 years from the time the contract ceases to be effective |
How we protect your personal data
Chiesi considers of extreme importance the security of Personal Data and has adopted appropriate security measures to ensure that Personal Data is safeguardedagainst unauthorised access, disclosure or loss.
To this end, Chiesi takes the following measures:
- We take reasonable measures to ensure that Personal Data is collected to the minimum extent possible, as well as relevant to what is necessary to pursue the purposes for which it is processed. We retain Personal Data for no longer than is necessary for the purposes set out in this Policy, unless an extension of the retention period is required or permitted by law;
- We use a range of technologies to ensure the confidentiality of data during transmission;
- We use trusted security mechanisms to protect data and storage servers from attack;
- We rigorously select business partners and suppliers and require them to comply with our Personal Data protection requirements through specific provisions in business agreements with those companies. In addition, we carry out other audits to assess the technical measures employed in order to verify compliance with the requirements;
- We organise privacy and security training courses, tests and information activities to raise awareness of the protection of Personal Data among our employees and collaborators.
Your rights
Access, rectification, erasure, data portability, restriction of processing, right toobject and withdrawal of consent.
Chiesi provides specific channels so that You can access, modify, oppose and/or limit the processing of Your data, as well as request its deletion, portability to other parties and revoke Your consent.
In this regard, we invite You to contact the Data Protection Officer (Data Protection Officer or DPO) to obtain the list of data processors, the parties with whom Your data has been shared and to request the exercise of Your rights listed above: dpoit@chiesi.com
If You believe that Chiesi is not processing Your Personal Data in accordance with this Policy or applicable law, You may exercise Your rights by lodging a complaint with the Data Protection Authority.
Data Controller:
Chiesi Farmaceutici S.p.A., with registered office in Via Palermo 26/A, 43122 Parma.
In some specific cases, indicated in the relevant sections, the Data Controller may be a different entity from the one indicated above (e.g. Whistleblowing, Recruiting).
In such cases, please refer to the Data Controller specified in the relevant notice.
Updates
These notices may be updated from time to time. Any update will become effective when it is posted on the Site.
Definitions
“Personal Data” means information of various kinds, including electronic information, which makes it possible to identify a person (‘data subject’) individually or in combination with other information.
“Processing of Personal Data” means, within the meaning of Article 4 (2) of the GDPR, any operation or set of operations which is performed with or without the help of automated processes and applied to Personal Data, such as collection, recording, organisation, storage, adaptation or alteration, retrieval, consultation, use and disclosure.
“Data Controller” means the entity that determines the purposes and methods of the processing of Personal Data.