Privacy Policy
1. INTRODUCTION
The fair and lawful processing of your personal data is a top priority for us. Therefore, we would like to inform you about when and why Lundbeck Limited (referred to as “Lundbeck”, “we”, “us”, “our”) collect and hold personal data about you, how this data is used, the conditions under which it may be disclosed to others and how it is kept secure.
Lundbeck Limited (company number 01040798) is the data controller in relation to the processing activities described below. This means that we decide why and how your personal data is processed.
In processing your personal data, Lundbeck will always comply with applicable data protection laws, including the Data Protection Act 2018 and the UK General Data Protection Regulation (“UK GDPR”).
2. WHAT PERSONAL DATA DO WE PROCESS?
As part of our professional dealings with you, we may collect, store and use the following types of personal data:
Contact details (including last name, first name, title, location, address(es), telephone and fax number, e-mail address, preferred communication method)
Communications and other information (enquiry details, marketing preferences, legal information relating to claims made by you, information contained in our correspondence, or other communications with you about business).
We will collect the above categories of personal data as follows as part of our interaction with you. This is information that you voluntarily give to us via:
- Our field representatives and office staff that you engage with;
- Data collection at trade fairs, conferences and other events; and/or
- Corresponding with us by phone, video conferencing, email, or otherwise.
We may also ask you for information when you report a problem with our site. If you complete any surveys that we request you complete for research purposes, we will collect information in such circumstances as well.
Personal data you give to us: This is information that you voluntarily give to us via our On My Terms website and/or by correspondence with us by phone, email, or otherwise.
We may also ask you for information when you report a problem with our website.
The categories of personal data that may be collected voluntarily includes: name, email address, job title or status, location, address, contact telephone number, professional registration number (GMC, GNC etc) if applicable, enquiry details, or information contained in our correspondence or other communications with you (including responses to any surveys), and your marketing preferences.
In case you report an adverse event, side-effect, or any issue with any product via our website, we will collect your name, location, health-related information, and contact information such as a phone number or email address in order to report to our Pharmacovigilance Department and the relevant health authorities in accordance with applicable laws.
As part of an adverse event report, Lundbeck may also process sensitive personal data about you where it is proportional and necessary to do so in order to comply with our reporting obligations or where required under law. This includes certain medical or health information in connection with a supply of a particular medicinal product. We will always seek to anonymise any specific named users of our products when holding or processing any sensitive personal data and request your explicit consent where required.
Personal data we collect about you: We may automatically collect the following information: details of your visits to our website, including, but not limited to, traffic data, location data, weblogs and other communication data, the resources you access, and the length, number and frequency of your visits. We may also automatically collect technical information, including anonymous data collected by the hosting server for statistical purposes, the Internet protocol (IP) address used to connect your computer or device to the Internet, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform.
Please see our Cookies Policy for further information on how we use cookies.
We may also obtain your personal data from sources outside of our business which may include our group companies or our third party marketing partners. The personal data that we receive from our group companies is as described in the paragraphs above.
The personal data that we receive from our third party marketing partners is where you have indicated that you would like Lundbeck to contact you with information about our services. If you would like to opt-out of receiving marketing information from us after providing your consent, you can do so at any time. Please see ’Your rights‘ for further details on how you can do this.
As an overriding principle, we only process such personal data as is necessary to achieve the various purposes (data minimisation principle) of processing. Where possible, we make use of pseudonymisation and anonymisation of data.
The purposes for which we collect and use your personal data and the legal basis under data protection laws on which we rely on do this are explained below.
Legitimate interests or that of a third party for the following purposes:
- for analysis to inform our business strategy, to research users’ demographics, interests, and behaviour, and to assist, enhance and personalise user experience (including with customised services and to make improvements to our services, products and site);
- to carry out surveys for market research purposes;
- to monitor the quality of our support to the public and your communications with us, and to assess and improve our service where necessary;
- to correspond or communicate with you;
- for business administration, including statistical analysis;
- for network and information security in order for us to take steps to protect your information against loss or damage, theft or unauthorised access;
- to comply with a request from you in connection with the exercise of your rights;
- for the management of enquiries, queries, complaints, or claims;
- for prevention of fraud and other criminal activities;
- for the establishment and defence of our legal rights; and
- using ‘list-based’ targeting tools offered by social media platforms and match you on social media for the purposes of marketing our brand.
Consent. We may use and process your personal data to contact you where you have consented for us to do so to send you direct marketing communications or for market research purposes when launching products and developing marketing strategies. We may collect your consent to be contacted by telephone or by post in the following ways (i) if you register for an account with us and indicate that you would like to receive such marketing from us; (ii) if you sign up to our newsletter via our site or other medium where available; or (iii) when you refresh your marketing preferences when responding to a request from us to do so. You have the right to opt-out of our use of your personal data to provide marketing to you. Please see ’Your rights‘ for further details on how you can do this.
Compliance with a legal obligation. We will use your personal data to comply with our legal or regulatory obligations (specifically, as required under pharmacovigilance law): (i) to assist any public authority or criminal investigation body; (ii) to identify you when you contact us; and/or (iii) to verify the accuracy of data we hold about you.
4. WHO MAY RECEIVE OR HAVE ACCESS TO YOUR DATA?
Access to your personal data is restricted to Lundbeck personnel to the extent necessary for processing the data for above-mentioned purposes.
We may also disclose your information to the following third parties:
Group companies. We may share your personal data with other companies within the Lundbeck group. They may use your personal data in the ways set out in ’How we use your personal data‘, in connection with data analysis, business management, and to assist in the provision of content, products and services to you. They may also process personal data on behalf of Lundbeck for the purposes of providing services to us.
Our suppliers and service providers.
- Other third parties may include cloud service providers (such as hosting and email management), IT providers, technical and professional advisors (including accountants and lawyers), advertising and marketing agencies, communication fulfilment service providers, and administrative service providers.
- When we use third party service providers, we only disclose to them any personal data that is necessary for them to provide their service and we have a contract in place that requires them to keep your information secure and not to use it other than in accordance with our specific instructions.
Surveys. As research and market engagement important to us, we may ask a third party research company to contact you for the sole purpose of gathering general information and specific information relating to us and our products and services.
Business sale or restructure. We may transfer your personal data to a third party as part of a sale of some or all of our business and assets to any third party or as part of any business restructuring or reorganisation. It also includes in the event of any liquidation, dissolution, or administration.
Legal obligation. We may also transfer your personal data if we’re under a duty to disclose or share it in order to comply with any legal obligation, to detect or report a crime, to enforce or apply the terms of our contracts or to protect the rights, property or safety of our visitors and customers.
When disclosing your personal data to third parties, we will always take steps with the aim of ensuring that your privacy rights continue to be protected.
5. WHERE IS YOUR DATA STORED?
All personal data you provide to us is stored on our secure servers which are located within the United Kingdom and/or the European Economic Area (EEA).
If at any time we transfer your personal data to, or store it in, countries located outside of the United Kingdom or the EEA (for example, as a result of our engagement of our CRM provider or if our hosting services provider changes) we will ensure that appropriate safeguards are in place for that transfer and storage as required by applicable law. This is because some countries do not have adequate data protection laws equivalent to those in the United Kingdom and EEA.
If your personal data is transferred to other companies in the Lundbeck Group, the transfer will be based on the Lundbeck Intra Group Agreement as applicable from time to time. The current agreement is based on the EU standard contractual clauses.
6. HOW LONG DO WE STORE YOUR PERSONAL DATA?
If we collect your personal data, the length of time we retain it is determined by a number of factors including the purpose for which we use that information and our obligations under other laws. We will only keep your personal data in an identifiable format for as long as is reasonably necessary to achieve the respective purpose of the processing unless we believe that the law requires us to preserve it.
If you have contacted us with a complaint or enquiry, we will store your personal data for as long as is reasonably required to resolve your complaint or enquiry.
When it is no longer necessary to retain your personal data, we will delete the personal data that we hold about you from our systems. After that time, we may aggregate the data (from which you cannot be identified) and retain it for analytical purposes.
The exceptions to the above are where:
- we need your personal data to establish, bring or defend legal claims or to comply with a legal or regulatory requirement;
- the law requires us to hold your personal data for a longer period, or delete it sooner;
- you exercise your right to have the information erased (where it applies) and we do not need to hold it in connection with any of the reasons permitted or required under the law, or you exercise your right to require us to retain your personal data for a period longer than our stated retention period; or
- in limited cases, the law permits us to keep your personal data indefinitely provided we put certain protections in place.
7. SECURITY AND LINKS TO OTHER SITES
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your information transmitted to our site and any transmission is at your own risk. Once we have received your personal data, we put in place reasonable and appropriate controls to ensure that it remains secure against accidental or unlawful destruction, loss, alteration, or unauthorised access.
Our sites may contain links to other websites run by other organisations. This policy does not apply to those other websites‚ so we encourage you to read their privacy statements. We cannot be responsible for the privacy policies and practices of other websites even if you access them using links that we provide. In addition, if you linked to our site from a third party website, we cannot be responsible for the privacy policies and practices of the operators of that third party website and recommend that you check the policy of that third party website.
8. DATA ANONYMISATION AND USE OF AGGREGATED INFORMATION
Your personal data may be converted into statistical or aggregated data in such a way as to ensure that you are not identified or identifiable from it. Aggregated data cannot be linked back to you as a natural person. We may use this data to share with our partners or for analytical and research purposes. This information may be collected by cookies placed on our site – please see our Cookies Policy for more information.
In the UK and EEA, you have certain rights in relation to your personal data under data protection law and these are described below. Please note that we may ask you for information to confirm your identity and, where applicable, to help us to search for your personal data.
- Right of access. You have the right to request access to the personal data Lundbeck processes about you. We may not be able to provide you with a copy of your personal data if this concerns other individuals or we have another lawful reason to withhold that information.
- Right to rectification. You have the right to rectification of inaccurate personal data concerning you, including completion of incomplete personal data. If you discover that any of the other information we hold is inaccurate or out of date. Alternatively, please let us know.
- Right to erasure or restriction of processing. Under certain circumstances, you may ask for your personal data to be removed from our systems. Unless there is a reason that the law allows us to use your personal data for longer, we will make reasonable efforts to comply with your request. You may also ask us to restrict processing your personal data where you believe it is unlawful for us to do so, you have objected to its use and our investigation is pending or you require us to keep it in connection with legal proceedings. In these situations, we may only process your personal data whilst its processing is restricted if we have your consent or are legally permitted to do so, for example, for storage purposes or in connection with legal proceedings.
- Right to data portability. Where processing is based on a consent or a contract and the processing is carried out by automated means, you have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format. You have the right to ask us to transmit this personal data to a third party and we will do so if technically possible. We may not provide you with a copy of your personal data if this concerns other individuals or we have another lawful reason to withhold that information.
- Right to object. Where we rely on your legitimate business interests as the legal basis for processing your personal data for any purpose(s), you may object to us using your personal data for these purposes. Except for the purposes for which we are sure we can continue to process your personal data, we will temporarily stop processing your personal data in line with your objection until we have investigated the matter. If we agree that your objection is justified in accordance with your rights under data protection laws, we will permanently stop using your data for those purposes. Otherwise we will provide you with our justification as to why we need to continue using your data. If you wish to object to us using your personal data for direct marketing purposes, please use our unsubscribe tool and we will automatically comply with your request.
- Withdrawing your consent. Where we rely on your consent as the legal basis for processing your personal data, you may withdraw your consent at any time. If you would like to withdraw your consent to receiving any direct marketing, you can do so at anytime by clicking on the unsubscribe link at the bottom of our emails. If you withdraw your consent, our use of your personal data before you withdraw is still lawful.
- Automated decisions. In certain circumstances, you may contest a decision made about you based on automated processing.
If you want to exercise any of your rights as described above, please email or write to us using the contact details at the end of this policy.
10. COMPLAINTS
If you wish to file a complaint regarding Lundbeck’s processing of your personal data, you can email or write to us using the contact details at the end of this policy.
You also have the right to complain to the relevant data protection authority, which in the UK is the Information Commissioner’s Office (ICO), if you are concerned about the way that we have processed your personal data.
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone Number: 0303 123 1113
Website: https://ico.org.uk/
11. CHILDREN
The On My Terms website is not intended or designed to attract children. Lundbeck do not knowingly collect personal data from any person we know to be under the age of 18 years.
12. CHANGES
We may review this policy from time to time and any changes will be notified to you by posting an updated version on our website and/or contacting you by email. Any changes will take effect 7 days after the date on which we post the modified terms on our site or the date of our email, whichever is earlier. We recommend you regularly check for changes and review this policy whenever you visit our site. If you do not agree with any aspect of the updated policy, you must immediately notify us and cease using our services.
This policy was last updated on 12 April 2024.
13. CONTACT
If you have any questions regarding this privacy policy or Lundbeck’s processing of your personal data, please contact our Data Protection Officer using the details below.
- Email: Our email address for data protection queries is [email protected]
- Post: If you wish to write to us, please write us at Iveco House, Station Road, Watford, Hertfordshire, England, UK WD17 1ET
- Phone: If you would prefer to speak to us by phone, please call 01908 649 966