Privacy policy
Introduction
The Company A. Menarini Industrie Farmaceutiche Riunite S.r.l. (“Company”, or “we”) takes its users’ privacy very seriously and undertakes to comply in full with the applicable law (Regulation (EU) 2016/679 – hereinafter defined as the “GDPR”).
This document (“Privacy Policy”) provides information on how the personal data collected by the Company through this website (“Website”) are processed, and constitutes “an information notice to the data subjects” under the terms of art. 13 of the GDPR. Specific privacy information notices are normally published in the Website sections in which users’ personal data are collected; in any event these are supplemented by this Privacy Policy.
Data Controller and DPO
The Data Controller is A. Menarini Industrie Farmaceutiche Riunite S.r.l., with registered offices in Via dei Sette Santi 1/3, Firenze (“Controller”).
The Data Protection Officer (“DPO”) can be contacted at the following address: dpo@menarini.com
The Data we process
The only data we process are those of the device you use to browse the website – we need to process said information to enable you to use the website itself.
In any event, even without your prior consent, the Controller may process your data to comply with legal obligations stemming from laws, regulations and EU Law, to exercise rights in legal proceedings, to pursue its own legitimate interests and in all cases provided by Articles 6 and 9 of the GDPR, where applicable.
Processing shall take place both using computers and on paper, and shall always entail the implementation of the security measures provided by current law.
Why and how we process your personal data
The Data are processed to view the website’s content and use the functionalities available thereon, pursuant to art. 6.1(b) GDPR (performance of a service for the benefit of the user). Your data may in any case be processed, even without your consent, for the purpose of complying with laws, regulations, EU Law (art 6.1.(c) of the GDPR, to perform statistics on the Website’s usage and ensure its proper functioning (art. 6.1.(f) of the Regulation), to enforce the Code of Conduct of the Menarini Group and to establish or defend the legal claims in the interest of the Company.
Data shall be stored for as long as strictly necessary for the attainment of the purposes for which they were collected. In any event the criterion used to determine that period is based on compliance with the time limits set by law and with the principles of data minimisation, storage limitation and rational management of archives.
Browsing data
If you only visit the Website (i.e., without sending communications or using any of the available services/functions), the processing of your data is limited to browsing data i.e., data whose transmission to the Website is necessary for the functioning of the computers which operate the Website and of the Internet communication protocols. This category includes, for example, IP addresses or computer domain used to visit the Website and other parameters pertaining to the operating system used to connect to the Website. The Company collects these and other data (such as, for example, number of visits and time spent on the Website) merely for statistical purposes and in anonymous form in order to monitor the functioning of the Website and improve its performance. Such data is not collected to be associated with other information regarding, or for the identification of, users; however, such information, by its very nature, may enable the Company to identify users through processing and association with data held by third parties. Browsing data are normally deleted following processing in anonymous form but can be stored and used by the Company to detect and identify perpetrators of any computer offences committed to the detriment of the Website or using the Website. Without prejudice to this possibility and to the provisions of the Cookie Policy which includes a section dedicated to the “Pixel Tags” used on the Website, the browsing data described above are stored only temporarily, in compliance with law.
Links to other websites
This Privacy Policy applies only to the Website as defined above. Even though the Website may contain links to other websites (known as third party websites), please be informed that the Company does not perform any access or control over cookies, web beacons or other user-tracking technologies that may be active on such third party websites, on the contents and materials published thereon, or on their methods of processing of your personal data; for this reason, the Company expressly declines any liability for such matters. You should therefore verify the privacy policies of such third party websites and collect information about their terms and conditions and about how they process your personal data.
Persons who have access to the data
Persons belonging to the following categories are authorised to process the user’s data: technical and administrative staff, IT staff, medical sales representatives, product managers, internal audit and compliance staff, as well as other staff members who require processing the data for performance of their job duties.
The Data can be communicated also in countries outside the EU (“Third Countries”) to other companies of the Menarini Group for the same purposes and/or for administrative and accounting purposes pursuant to Article 6.1.(f) and Recital 48 of the GDPR.
Additionally, the Data can be communicated, also in Third Countries, to: (i) institutions, authorities, public bodies for their institutional purposes; (ii) professionals, independent consultants –working individually or in partnerships- and other third parties and providers which supply to the Company commercial, professional or technical services required to operate the Website (e.g., provision of IT and Cloud Computing services) for the purposes specified above and to support the Company with the provision of the services you requested ; (iii) third parties in the event of mergers, acquisitions, transfers of business -or branches thereof-, audits or other extraordinary operations; (iv) company supervisory bodies, based at the Controller’s address, in the pursuit of their activities (oversight over the enforcement of legal obligations, ethical standards, the Menarini Group’s Code of Conduct, etc.). The mentioned recipients shall only receive the Data necessary for their respective functions and shall duly undertake to process them only for the purposes indicated above and in compliance with data protection laws. The Data can furthermore be communicated to the other legitimate recipients identified from time to time by the applicable laws. With the exception of the foregoing, the Data shall not be shared with third parties, whether legal or natural persons, who do not perform any function of a commercial, professional or technical nature for the Controller and shall not be disseminated. The parties who receive the Data shall perform processing as Data Controller, Processor or persons authorised to process personal data, as the case may be, for the purposes indicated above and in compliance with the applicable data protection law.
Regarding any transfer of Data outside the EU, including in countries whose laws do not guarantee the same level of protection to personal data privacy as that afforded by EU Law, the Controller informs that the transfer shall in any event take place in accordance with the methods permitted by the GDPR, such as, for example, on the basis of the user’s consent, on the basis of the Standard Contractual Clauses approved by the European Commission, by selecting parties enrolled in international programmes for free movement of data or operating in countries considered safe by the European Commission.
Your Rights
You may at any time exercise the rights afforded by Articles 15-22 of the GDPR, including the right to obtain confirmation of the existence of personal data which relate to you, check its content, origin, correctness, location (also with reference to any Third Countries), request a copy, request correction and in cases provided by law, restriction of processing, deletion, oppose to direct contact activities, (also limited to particular means of communication). Likewise, you may always withdraw consent and/or make observations on specific issues regarding processing operations of your personal data which you regard as incorrect or unjustified by your relationship with the Company, or lodge a complaint with the Data Protection Authority.
You may contact the Controller and/or DPO at the addresses displayed above to make any requests regarding personal data processing by the Company, to exercise your legal rights and to obtain an updated list of the parties who have access to your data.