Privacy Policy
Updated on 06/11/24
Table of Contents
Introduction
This document describes how the website https://www.recordatirarediseases.co.uk (hereinafter “Site“) is managed, with reference to the processing of the personal data of users who visit it. The Site is managed by Recordati UK Ltd, with registered office in Breakspear Park, Breakspear Way, Hemel Hempstead, HP2 4TZ, United Kingdom and Recordati Rare Diseases UK Ltd with registered office at Greengarth, Thicket Grove, Maidenhead, Berkshire, England, SL6 4LW (hereinafter collectively referred to “Recordati“, “we“, “us“), in its capacity as data controller.
When you browse our Site, interact with us, or use our services (“Services“), we may collect information and personal data about you. For this reason, in accordance with the provisions of UK General Data Protection Regulation (Regulation (EU) (2016/679) (‘UK GDPR‘) and the Data Protection Act 2018 (‘the Act‘), we have created the following document (hereinafter “Privacy Policy“) in order to describe what personal data we collect, the purposes and methods of processing it and the security measures we take to protect it.
This Privacy Policy constitutes the information that is provided pursuant to Art. 13 et seq. of and exclusively concerns the Site and the processing of data by Recordati. Any third-party websites referred to on this Site, including through links, are not covered by the information indicated in this Privacy Policy.
Who processes your data
The data controller is Recordati as described above, a company of the Recordati Group. The Data Protection Officer of the Recordati Group can be contacted at the following email address:
What personal data do we process?
Navigation data:
The computer systems and software procedures used to operate this Site acquire, during their normal operation, some personal data whose transmission is implicit in the use of internet communication protocols. This information is not collected to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes the IP addresses or MAC addresses of the computers used by users who connect to the Site, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters related to the user’s operating system and IT environment. These data are used to obtain statistical information on the use of the Site and to check its correct functioning and are deleted in accordance with the applicable legislation. The data could be used to ascertain responsibility in the event of hypothetical offenses against the Site only to the extent permitted by applicable legislation.
Data necessary to access the Site, cookies and other similar technologies:
Our Site, on the basis of your prior consent, when required by applicable law, uses cookies and other tracking technologies; for more information please visit our Cookie Policy.
The optional sending of questions through the appropriate forms on the Site involves the acquisition of the sender’s address, as well as any other personal data included in the message, necessary to answer the question. If you collect, process and communicate to us information about third parties, you must do so in accordance with the provisions of the UK GDPR and the Act and, therefore, you must give them prior information on the purposes and methods of the processing and, if necessary, you must obtain their free and express consent before carrying out the processing.
For what purposes we process your data
We process your personal data for the following purposes and set out the corresponding legal bases below:
To operate, improve and troubleshoot our Site. The processing is based on Recordati’s legitimate interest, consisting in the interest in guaranteeing a space reserved for our business partners and our affiliated companies, in ensuring the functioning of the Site, in improving its appearance and user experience.
To get to know our users through the use of cookies and similar tracking technologies. The use of cookies and similar technologies allows us to recognize you when you return to our Site. For more information visit our Cookie Policy.
For more information on how we interact with Healthcare Professionals, please visit the dedicated Privacy Policy for Healthcare Professionals.
Unless otherwise indicated, the provision of your data does not represent a legal or contractual obligation. You are not obliged to provide us with your data, however failure to provide it may prevent you from using all the features of the Site or all of our Services.
How your data is processed
Your personal data may be processed by electronic and/or paper means.
The security of your personal data is important to us. We adopt and request our service providers to adopt – appropriate technical and organizational security measures to prevent the loss or destruction, even accidental, of data, illicit or incorrect use and unauthorized access to data, in compliance with applicable legislation. In addition, the IT systems are configured in such a way that personal and identification data are used only when necessary to achieve the specific processing purposes pursued from time to time.
We implement multiple security technologies and procedures to protect your personal data from the risks described above. However, we would like to point out that electronic transmissions or storage of information are not 100% secure. Therefore, despite the security measures we have put in place to protect your personal data, we cannot guarantee that data loss, misuse or alteration will never occur.
We do not use automated individual decision-making that would have legal effects on you or, similarly, significantly affect you.
How long we process your data
Personal data is processed for the time necessary to provide the requested information or Services and, in any case, in accordance with any applicable legal or regulatory obligations. Notably:
We process your registration data until your request for deletion or the termination of the relationship between us and our business partners/affiliated companies.
If you receive communications by email, we process your personal data until the relationship between us and our business partners/affiliated companies ends or until you request deletion or objection to processing. You can exercise your rights at any time. More information can be found in section 8 below.
If you send us questions or requests, we process your personal data for as long as necessary to respond to you and comply with your request.
For information on the storage of cookies and other technologies, please visit our Cookie Policy.
To whom your data is communicated or transferred
Your personal data will be processed by our duly authorised staff, based on their respective needs. Your data will also be processed by our suppliers for technical and organizational services functional to the processing purposes indicated above, such as providers for maintenance services for the Site and hosting services. They act as our data processors on the basis of our instructions and in accordance with the provisions of the contracts they have entered into with us.
We may disclose your personal data to public authorities or bodies and to any other legitimate recipient in accordance with the law. In this case, the recipients will act as independent data controllers according to their respective institutional purposes.
If we are involved in a reorganization, acquisition, or sale of our company or parts of it, we will disclose your personal data to the third parties involved in the process, in accordance with applicable law. Any third party that is the recipient of your personal data as part of this procedure may only use it within the limits established by this Privacy Policy and applicable legislation.
To receive the updated list of recipients of your personal data, you can contact us using the contact details indicated above.
If your data is transferred abroad to countries that do not provide the same level of data protection as your country, we will ensure that the transfer is carried out in accordance with applicable law, i.e. by obtaining your consent, when necessary, or by taking any other measures necessary to ensure equivalent protection of the data being transferred, including, but not limited to, to implementing the EU Standard Contractual Clauses which may require the recipient to put in place supplementary measures to ensure an essentially equivalent level of protection is provided, as in the EU/EEA, the UK or Switzerland. We will ensure that your rights and an adequate level of protection essentially equivalent to that ensured within the EU/EEA, UK and Switzerland are guaranteed. If you would like to receive a copy of these safeguards, please contact us using the contact details set out in section 2 of this Privacy Policy. At this time, your personal data is not transferred outside the UK or European Union.
What are your rights and how can you exercise them?
In accordance with the applicable legislation on the protection of personal data, you may at any time request access to your personal data, verify its accuracy or request that it be corrected or updated.
You may also request the erasure of personal data concerning you, as well as the restriction of the processing of the same, in the cases provided for by the law, and you may object in any case to the processing of your data, on the basis of reasons related to your particular situation, unless we demonstrate the existence of compelling legitimate grounds for the processing of the data by us or as otherwise established by the applicable legislation on the protection of personal data.
You may object to the processing of your personal data at any time in the case of processing for direct marketing purposes.
You can also request the portability of your data, i.e. to receive such data in a structured, commonly used and machine-readable format, and the transmission of your data to another data controller without hindrance from us.
Finally, you can withdraw your consent to the processing of your personal data, if given, at any time.
To exercise the rights mentioned above, you can contact Recordati or the Data Protection Officer of the Recordati Group at the addresses indicated in section 2 of this Privacy Policy.
Finally, you may lodge a complaint with the competent supervisory authority or contact the authority if the exercise of your rights is subject to delay, limitation or exclusion by the data controller.
The contact details of the UK Information Commissioner (ICO) can be found here: https://ico.org.uk/make-a-complaint/ for EU national supervisory authorities can be found here: https://edpb.europa.eu/about-edpb/board/members_en and of the Swiss Federal Data Protection Authority (FDPIC) can be found here: https://www.edoeb.admin.ch/edoeb/en/home/deredoeb/kontakt.html?ref=blog.xgeeks.com
Changes to this privacy policy
We may update and amend all or part of this Privacy Policy at any time. The version published on the Site is the version currently in force. In the event of a change in the text of this Privacy Policy, we will inform you of such changes with a specific banner, link or pop-up on the home page of the Site or through a dedicated email.