Privacy Policy

PRIVACY NOTICE
(Last updated: 7th May 2017)

Gedeon Richter Plc. (hereinafter “Company”) is committed to protecting the privacy of individuals. This notice informs you about the processing of personal data collected by us from the users, subscribers of our website’s services (hereinafter collectively "Data Subjects"). Data Subjects below the age 16 (hereinafter “Minors”) are not eligible to use our services and we ask that minors do not submit any personal data to the Company.

Please read this Privacy Notice in conjunction with our general Terms of Use.

We may revise the Privacy Notice at any time by updating this posting and we will obtain your consent to the changes when necessary. You can determine when the Privacy Notice was last revised by referring to the "last updated" legend at the top of this Privacy Notice.

WHO WILL BE THE DATA CONTROLLER?

The data controller is the Company (registered seat: H-1103 Budapest, 19-21 Gyömrői út, Hungary; Company Registration Number: Cg. 01-10-040944; “we”, “us” or “Company”).

WHAT IS THE PURPOSE OF DATA PROCESSING?

We handle personal data in order to provide you with our services you request. These purposes include

  1. Carrying out your requests submitted through our website ("Website"), respond to your inquiries or requests;

  2. Providing a communication channel for the notification of adverse reactions to us for pharmacovigilance purposes (hereafter jointly referred to as “Services”).

The personal data collected from Data Subjects will be handled by our employees, kept confidential and used by us for lawful and relevant purposes for providing our Services to you, including

  1. identification of Data Subjects using our Services;

  2. to measure and improve our Services, including web analytics and statistical purposes;

  3. protect against and prevent fraud, misuse, and providing security of communications at our Website;

  4. to provide you with customer support; the handling of complaints and enforcement of our general Terms of Use and Privacy Policy.

We may also process your personal data for purposes previously communicated to you from time to time, as long as such other purposes are directly relating to and compatible with the purposes indicated in this Privacy Notice.

WHAT IS THE LEGAL BASIS OF DATA PROCESSING?

Unless otherwise indicated to you in this Privacy Notice, processing of your personal data is voluntary and based on your freely given consent. You have the right to withdraw your consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Failure to provide the requested personal data may result in us being unable to provide to you our Services.

In relation to adverse effect notifications, the legal basis of data processing is based on legal regulation.

If you enter into a contract with us, we will process your personal data pursuant to Article 7(b) of the European Data Protection (Directive 95/46/EC) to the extent processing is necessary for the performance of our legal obligation in order to administer the Services you request or in order to take steps at your request prior to entering into a contract with us. If any of our communications constitute direct marketing (including newsletters) we will separately seek your consent to such communications.

WHAT PERSONAL DATA MAY WE COLLECT?

In the course of our activities and for the purposes indicated above, we process (collect) the following personal data of Data Subjects:

  • Name(Family name and Surname): this information allows us to identify you. If you consent to newsletter communications, we must keep record of your name and email address.
  • Language preferences:this information allows us sending communications to you in languages you understand.
  • Email address: this information allows us to identify you and sending communications to you, including direct marketing messages (if you consent to receiving such communications).
    We also use your e-mail when asking for feedback in respect of the quality of provision of our Services or provide you with customer support.
  • Account Information: when registering or deregistering with our Website, we collect and store the subscriber's IP address and the date and time of confirmation in their subscriber profile. We process this data in order to maintain the security of our Website and of the subscribers’ own account and prevent fake signups.
  • Adverse reactions information: this information is necessary for us to process, investigate and notify the adverse reactions to the regulator. Your notification must include the name of the reporting person, your phone and email address; your profession; patient information; patient's initials; date of birth of the patient; age of the patient; sex of the patient; adverse event description, including the symptoms experienced; description of the side effects, adverse conditions, the patient's medical history, other diseases with free text; adverse events observed, such as death; immediate threat to life; necessary treatment; persistent or significant deterioration of health, or loss of function; developmental or birth defects occurred; medicines Information; start and end date of medication; medicines/drugs taken.
  • Message information: we will keep records of our communications with you, including any complaints you submit including any read receipt information in order to provide you with customer support and the handling of complaints.
  • General usage information: information that informs us on how you use our Services when you use our Website, including search behavior and preferences, a record of the searches that you make on our Website and browsing activity. We use this information to measure and improve our Services to you, as well as to identify improvement areas of the quality of our Services.

Our Services are not aimed at collecting sensitive personal data from Data Subjects, other than adverse reactions information (health data) for pharmacovigilance purposes.

WHAT COOKIES DO WE USE?

Our Website may use cookies to distinguish you from other users of our Website. This helps us to provide you with a good experience when you are browsing our Website and also allows us to improve our Website.

A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your computer if you agree. Cookies contain information that is transferred to your computer's hard drive.

We may use the following cookies:

  • Strictly necessary cookies. These are cookies that are required for the operation of our Website. They include, for example, cookies that enable you to log into secure areas of our Website. This category of cookies cannot be disabled.
  • Analytical/performance cookies. They allow us to recognize and count the number of visitors and to see how visitors move around our Website when they are using it. This helps us to improve the way our Website works, for example, by ensuring that users are finding what they are looking for easily.
  • Functionality cookies. These are used to recognize you when you return to our Website. This enables us to personalize our content for you, greet you by name and remember your preferences (for example, your choice of language or region).
  • Targeting cookies. These cookies record your visit to our Website, the pages you have visited and the links you have followed. We will use this information to make our Website and the advertising displayed on it more relevant to your interests. We may also share this information with third parties for this purpose.

You can find more information about the individual cookies we use and the purposes for which we use them in the table below:

Cookie Source Purpose Expiry
“SESS" prefix for HTTP requests and “SSESS" prefix for HTTPS requests + 32 digit random string Richter Gedeon NYRT The main purpose of this cookie is: Functionality. The Drupal CMS session cookie identifier. expire in the end of the month.
has_js Richter Gedeon NYRT The main purpose of this cookie is: Functionality. Drupal CMS uses this cookie to indicate whether or not the visitors browser has JavaScript enabled. expire when the session expires
_ga GOOGLE The main purpose of this cookie is: Survey. This cookie name is asssociated with Google Universal Analytics - which is a significant update to Google's more commonly used analytics service. This cookie is used to distinguish unique users by assigning a randomly generated number as a client identifier. It is included in each page request in a site and used to calculate visitor, session and campaign data for the sites analytics reports. 2 years
_gid GOOGLE The main purpose of this cookie is: Survey. This cookie name is asssociated with Google Universal Analytics. This appears to be a new cookie and as of Spring 2017 no information from Google. It appears to store and update a unique value for each page visited. 1 day
_gat GOOGLE The main purpose of this cookie is: Survey. This cookie name is associated with Google Universal Analytics, according to documentation it is used to throttle the request rate - limiting the collection of data on high traffic sites. It expires after 10 minutes. immediately
cookie-agreed Richter Gedeon NYRT A cookie to manage the acceptance of other cookies by the visitor to the site. 8 days

You can block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies (including essential cookies) you may not be able to access all or parts of our Website. For more information about cookies and how to disable them please visit www.allaboutcookies.org

WHERE IS THE INFORMATION STORED AND WHO WILL SEE THE INFORMATION?

Only those authorized persons and departments within the Company will have access to your personal data who have an essential need to know that data for the fulfilment of their activities. We will not disclose any of your personal data to third parties, any external bodies or organizations unless you consent to data transfer or the data transfer is required or permitted by law.

In case of information provided in the course of adverse reaction notification, we will disclose that information for the National Institute for Pharmacy and Nutrition (H-1051 Budapest, Zrínyi utca 3.; phone: +36 1 886 9300; fax: +36 1 886 9460; www.ogyei.gov.hu) who will process personal or other data connected to adverse event as a sole data controller.

After concluding a confidentiality and non-disclosure agreement, we may engage third party vendors as data processors to provide services to us.

HOW LONG WILL PERSONAL DATA BE RETAINED?

We keep personal data for no longer than is necessary for us to fulfil the purposes for which such personal data was processed (collected) unless we are specifically required to process personal data longer by applicable law.

We will delete and erase personal data if

(i) you withdraw consent on which the data processing is based and there is no other legal ground for the processing;

(ii) if you object to the data processing and there are no overriding legitimate grounds for the data processing, or you object to the processing for purposes of direct marketing;

(iii) the personal data have been unlawfully processed;

(iv) the personal data have to be erased for compliance with a legal obligation to which the Company is subject.

Deletion shall not apply to the extent that processing is necessary for compliance with a legal obligation which requires data processing by the Company or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Company (if any); for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes; or for the establishment, exercise or defense of legal claims of the Company.

In case of registrations or subscriptions of health professionals with our Website that have not been confirmed, we store the data for a period of fifteen (15) days. In case of completed registrations or subscriptions, we store your personal data and maintain your account with us for twenty-four (24) months counted from the last date of your login with our Website, unless you withdraw your consent to data processing or you request that we delete your personal data or you unsubscribe from our newsletters or other direct marketing communications.

Job application data will be retained for a period of sixty (60) days counted from the communication of the final decision about your hiring, unless you consent that we may retain your personal date for future applications.

WHAT INTERNATIONAL DATA TRANSFERS OCCUR?

We do not transfer your personal data to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection or you expressly consent to the data transfer abroad.

HOW DO WE ENSURE DATA INTEGRITY?

All practicable and reasonable steps will be taken to ensure that personal data held by us is accurate. Please, keep your personal data up to date, and to inform us of any changes to such personal data you provide to us.

HOW DO WE PROTECT PERSONAL DATA?

We will take all necessary steps to ensure security of the personal data and to avoid unauthorized or accidental access, collection, use, disclosure, copying, modification, disposal, erasure or other unauthorized use. Please note that electronic transmission of information cannot be entirely secure. We use Secure Sockets Layer (“SSL”) and password encryption in order to protect the security of information that we process. Please note that you have the affirmative duty to keep your password information safe and not to share this data with third persons.

WHAT ARE YOUR RIGHTS AND REMEDIES?

You have the right to have incomplete, incorrect inappropriate or outdated personal data deleted or updated, marked or blocked. If you believe any of the personal data we hold about you is incomplete, incorrect or outdated, you can contact us and we will make the necessary corrections within twenty-five (25) days. All practicable and reasonable steps will be taken to ensure that personal data held by us is accurate. We will mark personal data if you dispute its correctness or up-to-date status and such claim cannot be verified beyond doubt. You may request that we delete your personal data, but we may be required by law to keep such information and not delete it (or to block or mark this information for a certain time, in which case we will comply with the deletion request only after having fulfilled such requirements).

You have the right to be informed what personal data is processed about you. We will respond to such request for access to personal data as soon as possible, but within twenty-five (25) days from its submission at the latest. We may request the provision of additional information necessary to confirm your identity. You are also entitled to object to the processing of your personal data if processing or transfer of personal data is necessary solely for the performance of a contractual obligation, necessary for the enforcement of the legitimate interest of ours, a data recipient or any other third person (except if the data processing is compulsory); as well as if permitted by law. Such objection will be investigated by us within fifteen (15) days of filing the objection. If you do not agree with our decision as regards any objection, you are entitled to initiate court proceedings within thirty (30) days after receipt of the decision refusing such objection.

If you consider that your privacy and data protection rights have been infringed, you may contact the Hungarian National Data Protection and Freedom of Information Agency (Nemzeti Adatvédelmi és Információszabadság Hatóság, H-1024 Budapest, Szilágyi Erzsébet fasor 22/C.; phone: +36-1-391-1400; fax: +36 1 391 1410; email: ügyfelszolgalat [at] naih.hu) or may file court proceedings against the Company (or other data controller, i.e. OGYÉI) in which you also may request compensation of damages sustained as a result of the unlawful processing of personal data or as a result of an infringement of the security requirements of data protection. You are hereby notified that court action may be filed before the regional court having jurisdiction over your place of domicile or habitual residence within Hungary.

This Website may contain links to third-party sites. These linked sites are not under our control, and we are not responsible for the privacy practices of any such linked sites.

HOW CAN YOU CONTACT US ABOUT THIS PRIVACY NOTICE?

For information regarding data protection inquiries and requests by Data Subjects, please contact the Company’s Legal and Global Operations Management Department (phone: +36 1 431 4700; email: compliance [at] richter.hu).