Privacy Policy

Last Updated: November 2020

This Privacy Policy (“Privacy Policy”) applies to Personal data (as defined below) collected through the website https://hana.co.uk (hereafter “Website”).

Laboratoire HRA Pharma (hereafter “HRA Pharma” “we,” “our,” “us”), located at 200 avenue de Paris, 92320 Châtillon, France and registered to the Trade Registry of Nanterre under the number 420 792 582, is the Controller for the Processing of your personal data Personal data for the purposes described below. HRA Pharma will collect your Personal data in accordance with this Privacy Policy and applicable data protection and privacy laws, including but not limited to the General Data Protection Regulation (hereafter “GDPR”).

We may change this Privacy Policy from time to time. If we make changes, we will notify you by revising the date at the top of this policy and, in some cases, we may provide you with additional notice (such as adding a statement to our website or sending you a notification). We encourage you to review this Privacy Policy regularly to stay informed about our information practices and the choices available to you.

The following terms “Personal data”, “Processing”, “Controller”, “Processor”, “Data Protection Authority” take the definitions given by Article 4 of the GDPR.

CONTENTS

  • Collection of Personal Data
  • Your Choices
  • Advertising and Analytics
  • For Data Subjects within the European Economic Area (“EEA”)
  • Contact Us

Collection of Personal Data

Information You Provide To Us

What Personal data is collected?
We collect information you provide directly to us. For example, HRA Pharma collects Personal data when you submit such information to us via the Website and the forms available on the Website, communicate with us via third-party platforms, request customer support, or otherwise communicate with us. The types of Personal data we may collect include your name, email address, location, and any other information you choose to provide.

When choosing to complete and submit a form available on the Website, Personal data may be collected. Please note, the completion of a form found on our Website is not mandatory. Depending on the form, the collected data is:

  • Contact Form: You may complete this form if you have a suggestion or would like to contact us on a particular subject, such as a medical information or product request, partnership or media requests, product questions or complaints, or pharmacovigilance issues. The categories of Personal data processed are the following: your name, email address, the content of your message (which may include medical information if relevant to your message), and our corresponding answer (if we deem appropriate).

 

These forms are at your disposal in case you want to contact us. We would like to remind you that their completion is not mandatory.

Please note, you may reduce the amount of Personal data we collect about you by limiting the amount of Personal data you provide through the forms to the fields denoted as “mandatory.”

Information Collected Automatically About You When You Access This Website

When you access or use our Website or otherwise transact business with us, we automatically collect certain information corresponding to the following categories:

  • Activity Information: We collect information about your activity on our Website, such as the date and time you browsed the Website, length of visit to the Website, and pages most frequently accessed.
  • Device and Usage Information: We collect information about how you access our Website, including data about the device and network you use, such as your hardware model, operating system version, mobile network, IP address, unique device identifiers, browser type, and the website from which you access our Website.
  • Location Information: If applicable In accordance with your device permissions, we may collect information about the precise location of your device. You may stop the collection of precise location information at any time (see the YOUR CHOICES section below for details and our Cookies policy).
  • Information Collected by Cookies and Similar Tracking Technologies: We (and our service providers) use tracking technologies, such as cookies and web beacons, to collect information about you. Cookies are small data files stored on your hard drive or in device memory that help us improve our Website and your experience, see which areas and features of our Website are popular, and count visits. Web beacons (also known as “pixel tags” or “clear GIFs”) are electronic images that we use on our Website and in our emails to help deliver cookies, count visits, and understand usage and campaign effectiveness. For more information about cookies and how to disable them, see the YOUR CHOICES section below and our Cookies policy.

INFORMATION COLLECTED FROM OTHER SOURCES

HRA Pharma may supplement the Personal data it collects with information obtained from other third-party sources. Additionally, if you create or log into your “Hana” account through a third-party platform (such as Facebook or Google), we will have access to certain information from that platform, such as your name, birthday, and profile picture, in accordance with the authorization procedures determined by such platform.

USE AND SHARING OF INFORMATION

What are the purposes for Processing and the legal basis?

Your Personal data will be processed for the following purposes and in accordance with the legal basis set out below. The table below will also provide you with categories of recipients of your Personal data.

PURPOSE LEGAL BASIS CATEGORIES OF RECIPIENTS
General Managing and providing the Website (please see our Cookie Policy) Performing statistics on the use of the Website (please see our Cookie Policy) to improve the quality of our website Our legitimate interest to provide a Website; Your consent Laboratoire HRA Pharma SAS its subsidiaries
Users of the Contact Form Answering your request or your comment Our legitimate interest to develop or maintain our commercial relationship and comply with our legal obligations as the case may be Laboratoire HRA Pharma SAS or its subsidiaries
Access to the website parts dedicated to health care professionals HRA Pharma, as well as the Laboratoire HRA Pharma SAS which the holding company of HRA Pharma Rare Diseases and headhunter firm as the case may be

In addition to the categories of recipients above mentioned, HRA Pharma will transmit your Personal data to our authorized Processors which will process your Personal data on behalf of HRA Pharma. HRA Pharma will also communicate your Personal data to relevant authorities as required by applicable laws.

DATA RETENTION
In accordance with applicable data protection laws, the information collected about you when you access the Website will not be retained for longer than three years.
Regarding your Personal data, the retention period is fixed according to the purpose of the Processing, as follows:
• Managing and providing the Website: 3 years
• Performing statistics on the use of the Website: 3 years
• Managing your question or comment: the time needed to process your request

DATA SECURITY

HRA Pharma implements appropriate technical and organizational measures to ensure an appropriate level of security regarding the risk incurred and protect your Personal data against unauthorized access, disclosure, alteration or destruction.

What are your rights? How can you exercise them?

YOUR RIGHTS

Under applicable data protection and privacy laws, you have a number of rights with regard to your Personal data. Those rights are as follows:

RIGHT TO ACCESS

You can ask to see the Personal data HRA Pharma holds about you. In connection with a request, HRA Pharma may request specific information about you to enable us to confirm your identity and right access, as well as search for and provide you with the Personal data HRA Pharma holds about you. In the event we cannot provide you with access to your Personal data (for instance, Personal data may have been destroyed, erased or made anonymous), we will inform you of the reasons why.

CORRECTION OR DELETION OF PERSONAL DATA

HRA Pharma works to ensure that Personal data in its possession is accurate, current and complete. If you believe that the Personal data HRA Pharma holds on you is incorrect, inaccurate, incomplete or outdated, you may request the revision or correction of that information. If it is determined that Personal data is inaccurate, incomplete or outdated, we will revise it.

WITHDRAWAL OF CONSENT

If you have provided consent for the Processing of your data, you have the right to withdraw that consent at any time which will not affect the lawfulness of the Processing before your consent was withdrawn.

OBJECTION TO PROCESSING

You have the possibility to object to the Processing of your Personal data including profiling, on grounds relating to your particular situation as provided by data protection laws. When profiling is related to direct marketing you always have a right to object.

LIMITATION TO PROCESSING

You have the right to obtain from us restriction of Processing in certain instances as provided by data protection laws.

RIGHT TO DATA PORTABILITY

You have the right to receive the Personal data, which you have provided to us, in a structured, commonly used and machine-readable format when the Processing is based on your consent or on a contract. You also have the right to ask us to transmit it to another data controller of your choice.

COMPLAINTS

You have the right to lodge a complaint to the Data Protection Authority, if you believe that HRA Pharma has not complied with the requirements of the GDPR with regard to your Personal data.

If you wish to exercise one of these rights, please send a request in this regard to our Group Data Protection Officer, stating both your name and surname, together with a copy of your identity card:

Via the email address dataprivacy@hra-pharma.com. By post to HRA Pharma, 200 avenue de Paris, 92320 Châtillon, France. If you have unresolved concerns you also have the right to complain to the Data Protection Authority in the country where you live or work, or to the Data  Protection Authority of the place of the alleged infringement.