Santen Privacy policy for Georgia
Our commitment to privacy
This website (www.santen.ge) is operated by Santen Oy ("Santen" or “Santen Oy”) to offer to our website visitors (“you”, “your” or “website users”) general information about the activities of Santen as further described below.
Santen Oy carries out its activities in Georgia through its local Representative Office Santen Oy in Georgia. Any and all personal data concerning individuals located in Georgia collected by Santen Oy as described in the Policy (as defined below) will be collected and handled by Santen Oy in accordance with applicable data protection laws and regulations as further described in this Policy.
At Santen, we recognize the importance of, and are fully committed to protecting the privacy of personal data related to all individuals with whom we interact – including third party service providers, patients, clinical study participants, members of the public, employees, regulatory authorities’ representatives, healthcare organizations’ representatives, healthcare professionals and business partners.
Introduction
This Privacy policy (the “Policy”) sets out how Santen collects, processes and safeguards the personal data of the individuals with whom we interact. This Policy is designed to assist you in making informed decisions when using our website or interacting with us.
Individuals are recommended to read carefully this Policy before disclosing any personal data and/or filling in any electronic form posted on this website. By visiting our website or by providing us your personal data, you agree and consent to the collection, use and disclosure of your personal information as outlined in this Policy.
Scope of this policy
This Policy is specifically intended to provide information to our website users, Santen’s shareholders, members of the public who interact with Santen, patients that use Santen products, clinical study participants of Santen sponsored clinical studies and persons with whom we do business such as suppliers, contractors, consultants, regulatory authorities, personnel, agents, delegates of suppliers and partners and visitors to Santen offices.
Policy and other privacy notices
This website has been designed with the main function of providing information on the activities of Santen. Therefore, in most cases, the collection of the user’s personal data will not be required.
In certain instances, such as the career section, the main contact page and the medical enquiries form, the interested user is required to fill out a submission/data collection form. In these cases, the user is always free to provide his/her own data and a privacy notice specifying the use of data and other information required by law is provided. We recommend you read these notices before providing your personal data.
In addition, should it be necessary in limited cases to collect personal data for other purposes, this will be clearly shown in the privacy notices required by law, in order to enable transparency and user awareness.
These privacy notices aim to define limits and methods of personal data processing of each service, according to which the visitor can freely express his consent (if necessary) and eventually allow the collection of data and its subsequent use.
You can find more detailed information about how Santen processes personal data on the following topics by clicking on the following links:
Personal data we collect
We may collect and process the following personal data about you, including but not limited to:
-
General data such as name, postal and/or email address, phone number, date of birth, and other information such as photographs and digital imagery, your communications preferences; queries you make to Santen;
-
Professional data, such as your business address, business email address, business phone numbers, job title/position, educational information, professional qualifications, work experience, affiliations, professional networks, programs and activities in which you participated;
-
Identification data, such as your registration/identification information (for example, identity card numbers) insofar as required for the delivery of services to Santen, including onsite access to Santen premises);
-
Financial information such as bank name, bank accounts, credit card numbers (for the purposes of services by third-party service providers);
-
Health, biometric/genetic data related to identifiable or non-identifiable individuals, and only where necessary and strictly permitted under applicable laws (including in relation to Santen’s risk management and drug safety programs, or for accessibility purposes of visitors to Santen’s sites); and
-
Digital data generated from your use of our website or for the delivery of services to Santen, such as IP address, login user credentials, employee ID number, your browser type and version, time zone setting, time period of user’s staying on a single page, the internal path analysis and/or other parameters regarding the user’s operating system and computer environment, browser plug-in types and versions, operating system and platform and other data transmitted via cookies. This data is collected and used only in an aggregated and not immediately identifiable manner; they could be used among others to ascertain responsibility in case of hypothetical crimes against the site or upon public authorities’ request.
Ways of obtaining personal data
In most cases, Santen will collect data directly from you, although sometimes we will obtain data about you from public or third-party data sources, including but not limited to:
- Your employer when we need to process personal data of our service providers’ personnel;
- Santen may collect information about health care professionals from public or third-party sources for marketing, and research purposes and to verify professional data (including, but not limited to access to publicly accessible data, national registries or third-party databases);
- Health care professionals or other third parties may provide patient data to Santen where necessary under applicable drug safety and risk management laws;
- Santen may collect data from your computer or any other devices you use when visiting Santen’s website such as internet protocol (IP), domain name, internet service provider (ISP), data about date and time of your request and other information provided by tracking technologies. Please see our Cookies policy.
- Data may be shared in compliance with applicable data protection laws within Santen Group, which includes our worldwide affiliates.
When you are asked to provide personal data, you may decline. But if you choose not to provide data that is necessary for us to provide the requested services, we may not be able to provide you those services.
Purpose of processing personal data
Santen will process your personal data only for purposes permitted by applicable laws, including the Data Protection Act of Finland, the Law of Georgia on Personal Data Protection , and on the terms set forth in this Policy. The purposes of the data processing activities may include:
- Managing our business and to provide you goods and services: to administer our business and services, including to carry out our obligations arising from any agreements entered into between you/your employer and us (e.g. handling billing and invoicing).
- Managing our relationships/communications with individuals: for example, responding to questions and comments or inquiries about applications, studies or services, inviting individuals to Santen events, making proposals for future service needs.
- For collaboration and research purposes: for example, to enable Santen to make more informed and objective decisions when identifying, engaging with health care professionals and key opinion leaders and managing the collaboration relationship with health care professionals.
- Recruitment: processing professional data to assess the individual suitability for job openings at Santen.
- Market research: processing data about individuals for lawful market research purposes. We collect data through surveys and interviews with patients and health care professionals to help us improve our products and services.
- Direct marketing: to provide promotional material and engage in marketing and promotional activities with individuals in accordance with applicable laws.
- Website functions: to ensure that content from our website is presented in the most effective manner for you and for your device.
- Legal or regulatory obligations and the directions of law enforcement agencies and court orders: to comply with our legal or regulatory requirements (reporting for the safety of information and product quality complaints) or to fulfil transparency requirements with respect to transfers of value to HCPs by us).
Santen will process personal data for further purposes, where lawful to do so (such as for archiving, scientific or market research purposes) or when legally obliged to do so (such as reporting information for Santen‘s risk management and drug safety obligations).
Legal basis of processing
Santen processes personal data based on one or more of the following conditions:
- Where you have provided your consent (in which cases, such consent can be withdrawn at any time and without giving any reason);
- Where it is necessary to comply with contractual obligations with you;
- Where the processing is necessary for our compliance with a legal obligation;
- Where the processing is necessary to protect the vital or legitimate interests of an individual;
- Where processing is necessary in the public interest or for a public task;
- Where the processing is in Santen’s legitimate interest, for example, Santen processes data for scientific and statistical research purposes, for scientific development, for the improvement of our products and services, to provide security measures to protect Santen’s employees, contractors, patients, information and other assets and to prevent crime (such as fraud, financial crime and theft of intellectual and industry property and to ensure the integrity of its manufacturing and other operations) or in other ways strictly necessary to carry out our business or
- When the data subject’s personal data are publicly available or a data subject has made them publicly available.
Special categories of data
In addition to the above, where Santen processes special categories of data about individuals (information about individuals’ health, ethnicity, religion, trade union membership, genetic and biometric data etc.) – it shall only do so in accordance with applicable laws and regulations. For such processing Santen relies on the following conditions:
- Where individuals provide written consent;
- Where required for rights and obligations related to employment;
- Where required for vital or legitimate interests of any individual;
- Where processing is necessary for the purposes of provision of healthcare or occupational medicine, pursuant to a contract with a health care professional
- Where data subject has made his/her data publicly available without an explicit prohibition of their use and;
- Where processing is necessary for scientific research.
Redirect to other web sites
From this website, you can connect through special links to other websites of third parties. Santen does not endorse or recommend these sites' content or services and assumes no responsibility regarding the processing activities of personal data or any activity by or content on third-party sites to which our website provides links. We encourage you to read and be aware of the privacy policy, and all other policies, of each site you visit. Remember, the statements in this Policy apply solely to information collected by Santen.
Place of data processing and ways of transmission
Santen Oy is located in Finland. Santen also operates through its Representative Office Santen Oy in Georgia and through affiliates in Japan and other countries around the world. Personal data about you may be accessible to Santen affiliates located in the European Union (“EU”)/European Economic Area (“EEA”) as well as, to the extent permitted by applicable data protection law, to Santen affiliates outside the EU/EEA, and to selected vendors and partners, established in Finland, Georgia, in EU/EEA or globally.
Where Santen processes personal information in countries that may not provide the same level of data protection as in Georgia, Santen will implement reasonable and appropriate legal, technical and organisational security measures with the aim to ensure the security of the processing and in particular to protect your personal data from unauthorised access, use or disclosure. In the absence of an adequacy decision adopted by the competent authority, Santen will implement appropriate data transfer mechanisms (such as the execution of data transfer agreements as appropriate) and request permission from competent data protection authority, as necessary, for any cross border data transfers from Finland or Georgia to an affiliate or a third party (controller or processor) located in a non-adequate country with the aim to secure such transfers and achieve an adequate level of data protection.
Contractual arrangements with third parties and international data transfers
As a data controller, Santen aims to establish a high level of data protection and privacy for its data subjects and partners alike. To that end, Santen has developed and uses specific privacy and security related language in its contractual arrangements with third party service providers acting for the benefit of Santen as data processors in compliance with applicable data protection legislation.
Through its privacy-compliant contractual arrangements, Santen sets out the scope, subject-matter, duration and purpose of the data processing activities carried out by its data processors and their sub-processors (if any) as well as the types of personal data processed and the involved categories of data subjects. Moreover, details are provided with regard to the service provider’s obligations in its role as data processor which include indicatively its confidentiality obligations, the procedure to be followed in case of a data breach incident, cooperation regarding inquiries from data subjects and authorities, assistance for the performance of data protection impact assessments, international data transfer mechanisms to be executed in the case of cross border data transfers, specific rules for the due diligence and engagement of sub-processors, implementation of appropriate security measures and personal data breach indemnification commitments.
Our service providers are required to be transparent and inform us in advance about their affiliates and any external collaborators (acting as sub processors) that might be involved in processing activities. In case that a service provider and/or any of its collaborators, are located outside Finland, Georgia, the EU and/or the EEA we request where necessary that they also execute appropriate data transfer mechanisms with such third parties to cover any onward transfers; in particular, the execution of data transfer agreements, in the absence of an adequacy decision and/or any other data protection related certifications implemented by such third parties. This approach establishes and maintains a high level of data protection and privacy for the individuals we interact with in Georgia and beyond.
Disclosure of personal data
Personal data are not disseminated to unspecified recipients. Santen discloses your personal data to third party recipients on a need to know basis where this is reasonably permitted to pursue its legitimate business aims and as required by applicable law. Your personal data will be disclosed only in accordance with applicable laws, and appropriate safeguards through contractual agreements, will be established to protect your personal data.
In order to conduct Santen’s business, Santen may also disclose personal data to third parties such as public/regulatory authorities/governmental bodies (government, including social and benefits departments), third parties that provide services to Santen (such as but not limited to service providers, conducting audits, providing IT services, assisting in or managing our clinical studies, consulting/outsourcing companies, hosting service providers, event management agencies, travel agencies, banks and insurance companies and other support and administrative service providers that deliver support services to us), business partners and collaborators (such as external scientists, diagnostic labs), who review and assist Santen with health care compliance activities. Moreover, a disclosure of personal data may take place if Santen or substantially all of our assets are acquired by a third party, in which case personal data held by us about individuals will be included as transferred assets, or if Santen is under a duty to disclose or share individuals’ information in order to comply with any legal or regulatory obligation or request.
Detailed information on the names of the data processors can be requested by emailing the Santen EMEA Privacy Office at privacy-emea@santen.com.
Security and data retention
We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Policy, applicable data protection laws and regulations as well as international security standards. All data you provide to us is stored on secure servers and accessed and used subject to our security policies and standards. Santen has implemented reasonable physical, technical and managerial controls and safeguards to keep your personal data protected from unauthorised access, disclosure, alteration, and destruction. Such measures may include, but are not limited to: firewalls, access controls, encryption of information while it is in storage, separation of duties, and similar security protocols. Access to your personal data is limited to a restricted number of Santen employees whose duties reasonably require such information and third parties with whom Santen contracts to carry out business activities on its behalf. Our employees have been trained on the importance of privacy and how to handle and manage personal information appropriately and securely.
We will retain your personal data for the time strictly necessary to achieve the purposes for which the data were collected and any other permitted associated purpose. Data may be retained for a longer duration where applicable laws or regulations require, or allow Santen to do so. When your data is no longer needed it will be either irreversibly anonymised (and the anonymised information may be retained) or securely destroyed.
Choices about marketing
If we intend to use your data for marketing purposes or if we intend to disclose your data to any third party for such purposes, we will inform you respectively asking for your consent. In the case of direct advertising for our products and/or services through electronic communications (e.g. email), we will take all necessary steps to the extent required by applicable law, to offer you a method by which you can expressly consent to the receipt of further advertising material or the choice to refuse it. In any case, you always have the right to object to personal data being used for the purposes of direct marketing and sending scientific information and newsletters, and/or to withdraw your consent. You can also exercise the rights at any time by contacting us as set out below.
Your data protection rights
Under applicable laws and subject to any legal restrictions, you may have the right to request us to:
- Provide you access to your personal data that we hold about you;
- Update any inaccuracies in the personal information we hold that is demonstrated to be inaccurate or incomplete;
- Block Delete any personal information that we no longer have a lawful basis to use;
- Stop a particular processing when you withdraw your consent; and
- Object to any processing for marketing purposes.
All data protection related requests should be addressed to Santen privacy EMEA office at privacy-emea@santen.com.
If we do not handle your request in a timely manner, or if you are not satisfied with our response to any exercise of these rights, you are entitled to lodge a complaint with the competent supervisory authority of your residence; the Data Protection Authority of Georgia: Office of the Personal Data Protection Inspector can be found here. You may also complain to the supervisory authority of Santen Oy; the Office of the Data Protection Ombudsman (also known as Tietosuojavaltuutetun toimisto) can be found here.
Policy updating
Santen reserves the right to amend this Policy from time to time to reflect technological advancements, legal and regulatory changes, and Santen’s business practices, subject to applicable laws. If Santen changes its privacy practices, an updated version of this Policy will reflect those changes by posting any revisions on with the respective update of the effective date listed on the bottom of this Policy. We therefore encourage you to periodically visit this page to stay informed of how we are using your personal data.
Contact information
If you have any questions in relation to this Policy, or you want to obtain more information about Santen’s privacy practices, please contact our Santen privacy EMEA office by email at privacy-emea@santen.com.
Last updated on 11th January 2021