Data Privacy Policy
At Mayoly Spindler we are fully aware of the importance of privacy and particularly concerned about the protection of your personal data.
That is why we have taken all necessary measures to comply with all the provisions relating to the protection of personal data.
This policy is intended to inform you about how Laboratories Mayoly Spindler and all of its affiliates (hereinafter collectively referred to as "Mayoly Spindler", "we", "us", "our"), as data controller, undertake to collect, process and protect your personal data in accordance with the Data Protection Act of 6 January 1978 as amended, the General Regulation on Data Protection (GDPR) and, more generally, all applicable legal and regulatory provisions.
More specifically, the purpose of this policy is to explain to you:
- What categories of personal data are likely to be collected and how are they collected?
- For what purpose are your personal data used? On which legal grounds are they processed and what are your rights?
- Who can your personal data be transferred to?- How long are your personal data kept?
- How are your personal data protected?
- How to exercise your rights?
This policy is subject to change. The most recent version will be posted on our websites.
1/ What categories of personal data are likely to be collected and how are they collected?
1.1 The categories of personal data collected
The personal data that can be collected when you interact with us is as follows:
- General identification data: first name, last name, bank details;
- Contact information: postal address, email address, telephone number;
- Subject of your request and content of your message entered;
In any case, that personal data that we collect are the data strictly necessary for the fulfillment of the purposes described in this policy and are adequate, relevant and not excessive in relation to these purposes.
1.2 Sources of collection of personal data
We may collect your personal data in different ways:
- Data that you communicate to us through different media;
- Data that we collect automatically (via our website for example);
- Data that we collect from public sources in accordance with applicable legislation;
- Data that we lawfully collect from third parties with whom we interact.
2/ For what purpose are your personal data used? On which legal grounds are they processed and what are your rights?
Mayoly Spindler collects your personal data as part of the activities and purposes detailed below and in accordance with the legal bases referred to below.
Activity |
Purpose |
Legal ground |
Your rights |
Purchase and Sale of Products and Services |
Customers/suppliers accounts’ management (end-consumers and professionals) |
Legitimate interest |
Access, rectification, deletion, limitation, opposition, right to set guidelines on the fate of your personal data after your death |
Promotional Information |
Medical Visit |
Legitimate interest |
Access, rectification, deletion, limitation, opposition, right to set guidelines on the fate of your personal data after your death |
Legal obligation (French Charter of information by canvassing or prospecting for the promotion of medicines) |
Access, rectification, deletion, limitation, right to set guidelines on the fate of your personal data after your death |
||
Communication operations |
Consent |
Access, rectification, deletion, limitation, withdrawal of consent, portability, right to set guidelines on the fate of your personal data after your death |
|
Legitimate interest |
Access, rectification, deletion, limitation, opposition, right to set guidelines on the fate of your personal data after your death |
||
Sanitary Prevention Programmes (Pharmacovigilance/ Medical device vigilance/ Cosmetic products vigilance/ Nutrivigilance)
|
Notification management (collection, analysis, submission to authorities, etc.) and contacts with notifiers |
Legal obligation (French Public Health Code) |
Access, rectification, limitation, right to set guidelines on the fate of your personal data after your death |
Medical information |
Answers to requests for medical and scientific information about our products |
Legal obligation (French Public Health Code/ French Charter of information by canvassing or prospecting for the promotion of medicines / Certification rules) |
Access, rectification, limitation, right to set guidelines on the fate of your personal data after your death |
Market studies/ Medical studies |
Management and conduct of studies |
Legitimate interest |
Access, rectification, deletion, limitation, opposition |
Consentement |
Access, rectification, deletion, limitation, withdrawal of consent, portability, right to set guidelines on the fate of your personal data after your death |
||
Complaints |
Management of pharmaceutical complaints |
Legal obligation (French Public Health Code) |
Access, rectification, limitation, right to set guidelines on the fate of your personal data after your death |
Management of logistic complaints |
Legitimate interest |
Access, rectification, limitation, opposition, right to set guidelines on the fate of your personal data after your death |
|
Legal obligation (French Public Health Code) |
Access, rectification, limitation, right to set guidelines on the fate of your personal data after your death |
||
Relationships with Healthcare Professionnals |
Management of CRM system |
Legitimate interest |
Access, rectification, deletion, limitation, opposition, right to set guidelines on the fate of your personal data after your death |
Hospitality/Invitation to scientific events |
Legitimate interest |
Access, rectification, deletion, limitation, opposition, right to set guidelines on the fate of your personal data after your death |
|
Consultancy agreements/participation to a study |
Contract |
Access, rectification, deletion, limitation, portability, right to set guidelines on the fate of your personal data after your death |
|
French Anti-Gift Act (« loi anti-cadeaux”) |
Legal obligation (French Public Health Code) |
Access, rectification, limitation, right to set guidelines on the fate of your personal data after your death |
|
Transparency of interest links |
Legal obligation (French Public Health Code) |
Access, rectification, limitation, right to set guidelines on the fate of your personal data after your death |
3/ Who can your personal data be transferred to?
For the purposes described above, your personal data may be shared to the following persons:
- Laboratories Mayoly Spindler and all affiliated companies;
- Our partners (for example, healthcare professionnals and institutions, distributors, etc.);
- Our services providers (including IT);
- All administrative or judicial authorities/bodies.
We make sure that all of these people/bodies comply with this policy and, more generally, all the rules applicable to personal data.
In the event that your personal data are transferred outside the European Union, we implement all the guarantees prescribed by the applicable regulations (in particular the European Commission Standard Contractual Clauses).
4/ How long are your personal data kept?
Your personal data are kept for the period strictly necessary for the fulfillment of the purposes described above.
Once this period has elapsed, your personal data will be deleted or archived in accordance with the legal provisions in force.
5/ How are your personal data protected?
We have a set of procedures and organizational and technical measures to ensure the integrity and confidentiality of your personal data.
Your personal data are thus protected against unauthorized access, use and disclosure as well as against accidental or unlawful destruction, loss or alteration.
In some cases, we may also be required to anonymize your personal data so that no identification is possible.
Anyone to whom your personal data are transferred has security measures that also meet the requirements of integrity and confidentiality.
6/ How to exercise your rights?
Pursuant to the applicable legislation, and according to the framework in which they are exercised, you can exercise the following rights:
- Right of access allowing you to access your personal data;
- Right of rectification allowing you to obtain a correction of your personal data in the event that they are inaccurate, incomplete or obsolete;
- Right of cancellation in the situations provided for by the rules in force;
- Right of limitation in the situations provided for by the rules in force;
- Right of objection when your data has been collected and processed on the basis of our legitimate interests, subject to justification;
- Right to withdrawal of consent when your personal data has been collected and processed on the basis of your consent;
- Right to portability allowing you to transmit your personal data to any third party of your choice (reserved only for cases where your personal data have been collected and processed on the basis of your consent);
- Right to set guidelines on the fate of personal data after your death.
To exercise these rights, you can contact us:
By email: rgpd@mayoly.com
By mail: Mayoly Spindler (To the attention of the Data Protection Officer) - 6 avenue de l’Europe – 78400 Chatou, France
In the event of litigation, you also have the possibility to seize the National Commission for Data Protection and Liberties (CNIL) under the conditions indicated on its Internet site www.cnil.fr.