Medical Information Privacy Notice

INFORMATION SHEET PURSUANT TO ART. 13 OF EU REGULATION 679/2016 AND PRIVACY CODE AS MODIFIED BY THE D. LGS (DECRETO LEGISLATIVO [LEGISLATIVE DECREE]) 101/2018

Introduction

For Kedrion S.p.A., your privacy and the security of your personal data are of particular importance. For this reason, we collect and process this data with the utmost care and attention, as well as adopting technical and structural measures in order to guarantee the full security of its processing.

We inform you that, pursuant to art. 13 of the European Regulation 2016/679 (hereinafter referred to as “Regulation”) and the Privacy Code as modified by the D. Lgs. 101/2018, the processing of your personal data is carried out in accordance with methods that are suitable for guaranteeing the security and confidentiality of your data; the processing is carried out using IT and/or telematic devices, in accordance with what is detailed in this information sheet.

This information sheet concerns the processing of personal data of individuals who send unsolicited requests for information on Kedrion S.p.A proprietary medicinal products, via the completion of a specific form provided by the Company and also available on the Company’s website.

Personal Data Processing Controller 

The processing of your personal data is carried out by Kedrion S.p.A., in its role as Data Processing Controller, pursuant to and in accordance with the EU Regulation 2016/679 and the Privacy Code as modified by the D. Lgs 101/2018.

For any questions or requests concerning the processing of your personal data, you may send a request to the following contact points:

Data Processing Controller 

Kedrion S.p.A.

Registered office address: Loc. Ai Conti Castelvecchio Pascoli (LU) Contact email address: [email protected]

The Data Processing Controller has appointed a [Personal] Data Protection Officer (DPO) or [bilingual text] who may be contacted about the policy and the practices adopted with regard to personal data protection.

The contact details for the Data Protection Officer are as follows: [email protected]

Type of data and the purposes of processing 

The personal data that Kedrion processes is your identifying information, that being your first name, last name, e-mail address, landline telephone number and/or mobile telephone number and perhaps also special categories of data (art. 9 EU Regulation) related to your health. These are necessary for the Controller to be able to follow up on your request to receive information on the Kedrion S.p.A. proprietary medicinal products.

Communication and circulation of personal data

We point out that your data will not be communicated nor circulated, with the exception of the communication of your data to “Eureka InfoMed Srl Unipersonale”, which, on behalf of Kedrion, manages the unsolicited requests for information on the Company’s proprietary medicinal products and was duly appointed as the [Data] Processor pursuant to art. 28 of the EU Regulation 2016/679.

Data provision obligations 

The personal data that concerns you and identifies you is necessary for the fulfilment of the request made by you to obtain information on the Kedrion S.p.A. proprietary medicinal products.

Data processing methods. 

The processing of the data that concerns you is carried out using means and tools, both electronic and in hard copy format, by persons who are expressly authorised and trained according to the specific directions of the Controller.

Legal basis of the Processing

The legal basis of the data processing is the consent.

Data Retention

Personal data is stored for the time necessary to fulfil the requests for information made by you and, in any case, in compliance with the Company’s data retention policies.

Rights of the individual concerned 

Your rights are those foreseen by the EU Regulation UE 679/2016, from articles 15-22, as well as those foreseen by the Privacy Code as modified by the D. Lgs 101/2018, which are, for example:

  • to access your personal data and to know its origin (the purposes and objectives of the processing, the data of the subjects to which the data will be communicated, the storage period of your data or the criteria needed to determine it);
  • to update or correct your personal data so that it is always precise and accurate;
  • to delete your personal data from databases and/or from archives, including also backup archives of the Controller;
  • to restrict the processing of your personal data in certain circumstances; for example, in a situation in which you dispute its correctness, for the period of time necessary for the Controller to verify its

For any further information and, in any case, in order to send your request, please contact the Controller at the e-mail address: [email protected]

For reasons related to your specific circumstances, you may oppose the processing of your personal data at any time if this is based on legitimate interests, by sending your request to the Controller at the e-mail address: [email protected]

Complaints

Without prejudice to any other action of an administrative or judicial nature, you may submit a complaint to the supervisory authorities in accordance with what is foreseen by the EU Regulation 2016/679 and the Privacy Code as modified by the D.Lgs 101/2018.

Provision of consent 

If you have received this information sheet and you have understood its content, we ask you to give your consent to the processing of your personal data and the data regarding your health that is required for the management of the unsolicited request for information on Kedrion S.p.A. proprietary medicinal products, sent by you by means of the completion of the specific form provided by the Company and also available on the Company’s website.

  • Yes, I give my consent
  • No, I do not give my consent

Signature and date