Privacy Policy

Laboratoire HRA Pharma SAS (hereafter “HRA Pharma”), ID number 420 792 582 RCS Nanterre located 200 avenue de Paris, F-92 320 Châtillon, France, and its subsidiaries pay particular attention to the protection of your Personal Data and to privacy and commits to respect them through the following fundamental values:

– to respect individuals expectations regarding the use of their Personal Data,
– to build and preserve trust of our consumers and other involved people or organizations,
– to prevent any damage with Personal Data and privacy,
– and to be compliant with the letter and the spirit of Laws and Regulations regarding Personal Data protection.

HRA Pharma provides on-line resources with the aim to give health information such as contraception.

HRA Pharma is processing personal data through its websites and commits to process your Personal Data with many caution and only for purposes for which personal data have been collected, in accordance with applicable laws and particularly the European General Data Protection Regulation (EU) 2016/679 (hereafter the GDPR).

This Privacy Policy applies to Personal Data collected through www.ellaone.com.

The following terms “Personal Data”, “Processing”, “Controller”, “Processor”, “Data Protection Authority” take the definitions given by article 4 of the GDPR.

1. Information collected about you when you access this website

– Personal Data which are directly shared by you when you contact us: both your name and your email address.

– Information collected about you through the use of the Website without being actively provided by you, thanks to several technologies, notably internet protocol (IP) addresses, cookies, Internet tags, browsing data. Main categories of data which are collected are:

  • Domain and server (host) from which you access this website on the Internet;

  • Address of the website from which you access our website

  • Date, time, length of visits of this website and pages most frequently accessed;

  • Your internet protocol (IP) address;

  • Operating system of your computer and details of your web browser.

For more information regarding the use of cookies by HRA Pharma, please read our Cookies Policy available on the footer of the website. Within this Cookies Policy, you will find information on how to disable all the cookies if you disagree with their use.

2. What are the purposes for processing and the legal basis?

Purposes Legal Basis
Managing and providing the Website (please see our cookie policy) Our legitimate interest to provide a Website
For our commercial needs, notably data analysis, our website improvement, both our products and services improvement, identifying use of the website trends, customization of the website according to your tastes and to determine the efficacy of our promotional campaigns Comply with our legitimate interest to develop our relation with you
Performing statistics on the use of the Website (please see our cookie policy) to improve the quality of our website Your consent

3. Who are the recipients of your Personal Data?

The access to your Personal Data is strictly limited to authorized people at HRA Pharma. These people are the ones for whom the access to such data is necessary to carry out their missions.

The company LOOP (Austria), our IT solution provider, as well as the company DigitalOcean LLC (US), the hosting services provider are processing personal data going through the Website.

DigitalOcean LLC is certified its compliance to the EU-U.S. Privacy Shield Framework, meaning it provides the same level of protection than the level of protection of personal data in force in Europe.

HRA Pharma will also communicate your Personal Data to relevant authorities as required by applicable laws.

In every case, your personal data will be processed according to applicable laws regarding protection of Personal Data and particularly according to the GDPR.

4. How long will your Personal Data be retained?

Personal Data will be stored for a duration in compliance with both ePrivacy and General Data Protection European Regulations.

5. Transfers outside of the European Economic Area

Your Personal Data could be processed in the USA. Level of protection of personal data will be the same as in Europe thanks to DigitalOcean LLC which has certified its compliance to the EU-U.S. Privacy Shield Framework, meaning it provides the same level of protection than the level of protection of personal data in force in Europe.

6. Security

HRA Pharma implements appropriate technical and organizational measures to ensure an appropriate level of security regarding the risk incurred and protect your Personal Data against unauthorized access, disclosure, alteration or destruction.

7. What are your rights? How can you exercise them?

Under applicable Personal Data protection laws, notably the GDPR you have a number of rights with regard to your Personal Data. Those rights are as follows:

  • Right to Access

    • You can ask to see the personal information HRA Pharma holds about you. In connection with a request, HRA Pharma may request specific information about you to enable us to confirm your identity and right access, as well as search for and provide you with the personal information HRA Pharma holds about you. In the event we cannot provide you with access to your personal information (for instance, personal information may have been destroyed, erased or made anonymous), we will inform you of the reasons why.

  • Correction or Deletion of Personal Information

    • HRA Pharma works to ensure that personal information in its possession is accurate, current and complete. If you believe that the personal information HRA Pharma holds on you is incorrect, inaccurate, incomplete or outdated, you may request the revision or correction of that information. If it is determined that personal information is inaccurate, incomplete or outdated, we will revise it.

  • Withdrawal of Consent

    • If you have provided consent for the processing of your data, you have the right to withdraw that consent at any time which will not affect the lawfulness of the processing before your consent was withdrawn.

  • Objection to processing

    • you have the possibility to object to the processing of your personal data including profiling, on grounds relating to your particular situation as provided by Data Protection law. When profiling is related to direct marketing you always have a right to object.

  • Limitation to processing

    • you have the right to obtain from us restriction of processing in certain instances as provided by data protection law.

  • Right to data portability

    • you have the right to receive the personal data, which you have provided to us, in a structured, commonly used and machine-readable format when the processing is based on your consent or on a contract. You also have the right to ask us to transmit it to another data controller of your choice.

  • Complaints

    • You have the right to lodge a complaint to the Data Protection Authority, if you believe that HRA Pharma has not complied with the requirements of the GDPR with regard to your personal data.

If you wish to exercise one of these rights, please send a request in this regard to  dataprivacy@hra-pharma.com or to Laboratoire HRA Pharma, Data Protection Officer, 200 avenue de Paris, 92320 Châtillon, France, stating both your name and your surname, with a copy of your identity card.

If you have unresolved concerns you also have the right to complain to the Data Protection Authority in the country where either you live or either you work or either the country of the place of the alleged infringement.

 

Effective date: AUGUST 2019