HEALTH CARE PROFESSIONALS’ PRIVACY NOTICE (HCP outside France)

This notice aims to inform non French healthcare professionals about the processing of their personal data.

HEALTH CARE PROFESSIONALS’ PRIVACY NOTICE (HCP outside France)

Here you can find the privacy policy in German:
Hier finden Sie die Datenschutzerklärung auf Deutsch

LFB BIOMEDICAMENTS (hereinafter LFB) takes its legal obligations relating to the processing of personal data very seriously and implements various actions to ensure the protection of your data and the respect of your privacy.
In this context, LFB undertakes to provide clear and concise information to any person concerned on the processing of their data.
This notice is dedicated to health care professionals (hereinafter “health care professional”, “HCP”, “you”, “your”).
The purpose of this notice is therefore to inform you, in full transparency, of the way in which your personal data are processed by LFB.
References to “LFB”, “we”, “us” and “us” are references to the data controller mentioned below.

Data controller
LFB BIOMEDICAMENTS (3 avenue des Tropiques, BP 40305, 91958 Courtabœuf Cedex – France) acts as a data controller as defined in General Data Protection Regulation (GDPR).

Purpose of the processing:
We process your personal data for the following purposes:
Purpose 1: Receive information on (i) LFB’s medicinal products, (ii) its activities and (iii) medical and scientific information.
Purpose 2: Receive information on scientific events (such as symposium, conferences, congresses…).
Purpose 3: Participate in market studies and surveys.
Purpose 4: understand in a better way the environment in which LFB operates and provide the best possible experiences to health care professionals. To this end, LFB carries out profiling to establish a personalized profile of health care professionals (information from our databases and professional information publicly available on the Internet in particular).
Purpose 5: Management of the activity (medical and commercial) of LFB employees with whom you may interact. For example, we keep a record of the interactions you have with the MSL (Medical Science Liaison).
Purpose 6: Management of hospitality, logistics and organisation of events (excluding invitations).
Purpose 7: Compliance with applicable laws or local guidelines (e.g. transparency, local sunshine act, declaration to local agencies).

Legal basis
We can only process your personal data if it is lawful. Processing is only lawful insofar as it is based on one of the legal bases mentioned in the applicable law (GDPR).

The processing of your personal data is based on the following legal bases:
Purpose 1 to 3: we can only process your personal data if you provided your explicit prior consent (for information, your consent can be withdraw at any time).
Purpose 4 & 5: LFB has a legitimate interest in processing your personal data in the context of its activity. These include economic interests or interests related to the organisation and development of the business pursued by LFB, but also to ensure and guarantee compliance with the high quality and safety standards of medicines and medical devices.
Purpose 6: We process your data for this purpose in order to execute the contract between you and LFB.
Purpose 7: according to the applicable local regulation, the processing is necessary to respect a local regulation or is subject to your prior consent.

Categories of personal data concerned
We only process your personal data that is necessary for purposes above.

The following categories of personal data are concerned by the processing:
– Information about your identity: such as name, surname.
– Information about your professional information: such as email / postal address, phone number, job title, identification in national registers, employer.
– Assessment information: such as your interest in our products, participation in our events or partnership, publication, participation in scientific committees, member of a professional association, feedback from our visits or from our events, appointment dates (and if necessary, your participation in a lunch or dinner), interests and experiences, prescription habits.

Sources of personal data
Personal data come:
– Directly from you.
– From alternative sources including publicly accessible sources (from websites, publication databases) and also from third party vendors and service providers acting as data processor on our behalf.

Obligation to provide your personal data
As a prospect, the processing of your data is not mandatory and failure to provide your data has no consequences for you.

In the context of a relationship established between you and us, the processing of your data is mandatory and failure to provide your data may prevent the continuation of our relationship with you.

Recipients of personal data
Depending upon their respective needs, recipients of all or part of the personal data are the following:
– The LFB Group parent company and its subsidiaries (if necessary).
– Our service providers acting as a data processor on our behalf (within the limit necessary for the performance of the work we have entrusted to them).

In the event that personal data is entrusted to a data processor, an agreement will be concluded in order to ensure and guarantee that personal data is processed in accordance with our instructions and that adequate technical and organizational measures are taken to protect it.

Public authorities, government bodies, etc.

Period for which the personal data will be stored
The data above (identity, job title, medical specialty, identification in the national register, professional background and professional contact information) are kept for the period during which you carry out your professional activity.

However, data relating to our interactions are kept for a period of three years following the last contact with us.

Data necessary to comply with our legal obligations are retained for the time required to meet these obligations.

Data transfers outside the European Union
Your personal data are processed in the European Union but may be transferred to countries outside the European Union.
When we transfer your data to countries which do not offer a level of protection equivalent to that implemented within the European Union, we put in place appropriate technical and legal guarantees (scuh as Standard Contractual Clauses) in order to protect your data against any access, use or unauthorized disclosure.

Security
We put in place technical and organizational measures allowing the protection of your personal data. We take reasonable steps to protect your data from loss, misuse, unauthorized access, disclosure, modification, or destruction of your data.

Your rights
Within the conditions and limits of the applicable regulations, you have the following rights:
Right of access: you can access the personal data that we hold about you.
Right of rectification: you can ask us to correct data that is inaccurate or incomplete.
Right to erasure (right to be forgotten): you have the possibility under certain conditions to obtain the erasure of the personal data that we hold about you. However, we have the possibility of not responding favourably to your request, in particular in the event that we need your personal data to meet a legal obligation.
Right to restriction of processing, in particular in the event that you dispute the accuracy of the personal data that we hold about you.
Right to object: you can object, for reasons relating to your particular situation and under certain conditions, to the processing of data concerning you.
Right to withdraw your consent.

Under certain circumstances, we will not be able to respond to your request if you want to exercise your rights. In such a case, we will explain the reasons for our refusal. For example, if the process of your personal data is based on the execution of a contract between you and LFB, you don’t have a right of erasure or a right to object.

Other processing
Other data processing may be implemented by LFB in addition to the processing mentioned above.
Your data may be processed for pharmacovigilance management purposes (if you report an adverse effect), for medical information purposes (if you ask a medical information question), for monitoring the proper use of our medicinal products, etc.

A specific information notice will be communicated for each data processing.

Miscellaneous
This information leaflet may be updated regularly. We invite you to consult it regularly on the LFB BIOMEDICAMENTS website (https://www.groupe-lfb.com/en/information-notices/)

Contact and reclamation
To exercise the above rights or for any questions relating to the processing of personal data, please send a request to the Data Protection Officer:
– Email: privacy@lfb.fr
– Mail: LFB BIOMEDICAMENTS – Direction des Affaires Juridiques – DPO – 3 avenue des Tropiques, BP 40305, 91958 Courtaboeuf Cedex – FRANCE

If you consider, after contacting us at the contact details above, that your rights are not respected or that data processing does not comply with data protection rules, you may lodge a complaint with a supervisory authority (for example the Agencia Española de Protección de Datos in Spain or the Bundesbeauftragte für des Datenschutz und die Informations freiheit Husarenstr in Germany).

Version: August 2022

PROCESSING OF YOUR PERSONAL DATA IN THE CONTEXT OF THE “SUNSHINE ACT”

The Laboratoire français du Fractionnement et des Biotechnologies (hereinafter LFB SA) takes its legal obligations relating to the processing of personal data very seriously and implements various actions to ensure the protection of your data and the respect of your privacy.

In this context, LFB SA undertakes to provide clear and concise information to any person concerned, in particular American healthcare professionals, on the processing of their data.
The purpose of this notice is therefore to inform you, in full transparency, of the way in which your personal data is processed by LFB SA.

“LFB SA”, “we” and “us” are references to the data controller mentioned below.

Data controller
LFB SA (3 avenue des tropiques – ZA de Courtaboeuf – 91940 les Ulis – France) acts as a data controller as defined in General Data Protection Regulation (GDPR).

Purpose of the processing
We process your personal data for the following purposes:
– Compliance with the American Physician Payments Sunshine Act (section 6002 of the Affordable Care Act of 2010) or related state laws (hereafter “Sunshine Act”).
In the context of this processing, the Sunshine Act requires drug manufacturers, as LFB SA, to collect and track all financial transactions made to American healthcare professionals and to report these transactions to the Centers of Medicare and Medicaid Services (CMS). It involves a processing of your personal data.

Legal basis
We can only process your personal data if it is lawful. Processing is only lawful insofar as it is based on one of the legal bases mentioned in the applicable law (GDPR).
This legal base for the processing is to comply with the Sunshine Act.

Data subject
This processing of personal data concerns the following data subject: American healthcare professionals.

Categories of personal data concerned
We only process your personal data that is necessary for purposes above.
The following categories of personal data are concerned by the processing:
– Information about your identity: such as name, surname
– Information about your professional information: such as email / postal address, phone number, job title, identification in national registers, employer.
– Information about financial transaction between LFB SA or its subsidiaries and you

Sources of personal data
Personal data come:
– Directly from you.
– From LFB SA or its subsidiaries (for the information about financial transaction).

Obligation to provide your personal data
In the context of a relationship established between you and us, the processing of your data is mandatory and failure to provide your data may prevent the continuation of our relationship with you.

Recipients of personal data
Depending upon their respective needs, recipients of all or part of the personal data are the following:
– LFB SA, LFB BIOMEDICAMENTS and its subsidiaries if necessary.
HEMA BIOLOGICS and its service provider MEDISPEND (American companies) in charge of transmitting information including personal data to the CMS website (https://openpaymentsdata.cms.gov/).
– Our other service providers acting as a data processor on our behalf (within the limit necessary for the performance of the work we have entrusted to them).

In the event that personal data is entrusted to a data processor, an agreement will be concluded in order to ensure and guarantee that personal data is processed in accordance with our instructions and that adequate technical and organizational measures are taken to protect it.

Public authorities, government bodies, especially the CMS in the context of the processing.

Period for which the personal data will be stored.
Data necessary to comply with our legal obligations (Sunshine Act) are retained for the time required to meet these obligations.

Data transfers outside the European union
Your personal data is processed by LFB SA in the European Union but may be transferred to countries outside the European Union (USA). In particular we transfer your data to HEMA BIOLOGICS an American company which is in charge transmitting your data (including financial data) to CMS.

Security
We put in place technical and organizational measures allowing the protection of your personal data. We take reasonable steps to protect your data from loss, misuse, unauthorised access, disclosure, modification or destruction of your data.

Your rights
Within the conditions and limits of the applicable regulations, you have the following rights:
Right of access: you can access the personal data that we hold about you.
Right of rectification: you can ask us to correct data that is inaccurate or incomplete.
Right to restriction of processing, in particular in the event that you dispute the accuracy of the personal data that we hold about you.

Under certain circumstances, we will not be able to respond to your request if you want to exercise your rights). In such a case, we will explain the reasons for our refusal.

Contact and reclamation
– To exercise the above rights or for any questions relating to the processing of personal data, please send a request by email to privacy@lfb.fr or by post to the following address: LFB BIOMEDICAMENTS – Legal department – Data Protection Officer – 3 avenue des tropiques – ZA de Courtaboeuf – 91940 les Ulis – France).

If you consider, after contacting us at the contact details above, that your rights are not respected or that data processing does not comply with data protection rules, you may lodge a complaint with a supervisory authority.
We may update this privacy notice from time to time by posting any revisions on our website. Please refer regularly to our website for updates.

Version: 06/30/2021