By “Personal Data” we mean any information relating to an identified or identifiable natural person, as further defined in the General Data Protection Regulation (EU) 2016/679.
By “Data Controller” we mean the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data, as further defined in the General Data Protection Regulation (EU) 2016/679.
2. Processing of login data
This Site uses a login for some or all parts of this Site. If you login, you are requested to submit Personal Data (e.g. name, email). We process your Personal Data to ensure that you can also use the protected login areas. The legal basis for these processing operations is largely the implementation of an (account) agreement with you. In addition, a legal basis is our legitimate interest in carefully managing accounts and keeping records.
3. Other data processing
This Site also processes Personal Data that is sent by your personal browser, such as your IP address and browser specifications. This processing is needed for the correct functioning of the Site.
5. Retention of Personal Data
We strive to retain Personal Data as short as possible. We determine the retention period of your Personal Data on the basis of the following criteria: (a) the purpose for which we use your Personal Data: we keep the data as long as necessary for that purpose; and (b) legal obligations: various laws and regulations impose minimum retention periods we are obliged to comply with.
6. Your rights
In accordance with the General Data Protection Regulation, you have the:
Right of access. You may contact us to get confirmation as to whether or not we are processing your Personal Data concerning you. If we process your Personal Data, we will inform you about the categories of Personal Data we process, the processing purposes, the categories of recipients to whom Personal Data have been or will be disclosed and the envisaged storage period or criteria to determine that period.
Right to rectification. You have the right to have inaccurate or incomplete Personal Data, we store about you, rectified or completed.
Right to object. In case our processing is based on a legitimate interest of Sanofi, you have the right to object at any time to this processing. We shall then no longer process your Personal Data, unless we demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims.
Right to restriction of processing. You have the right to request us to restrict the processing of your Personal Data in specific situations as foreseen by applicable data protection law (e.g. when the accuracy of your Personal Data is contested by you, for a period enabling us to verify the accuracy of your Personal Data). Restriction of our processing operations may affect the functionality of the Site.
Right to erasure. You have the right to ask us to erase your Personal Data from our systems if your Personal Data are no longer necessary in relation to the purposes for which they were collected or otherwise processed. Furthermore, you have the right to erasure if you exercise your right to object as meant above, unless we have an overriding legitimate ground to not erase the relevant data. We may not immediately be able to erase all residual copies from our servers and backup systems after the active data have been erased. Such copies shall be erased as soon as reasonably possible.
Right to data portability. You have the right to receive your Personal Data in a structured, commonly used and machine-readable format and/or request that we transmit those data to a third party where this is technically feasible. Please note that this right only applies to Personal Data which you have provided to us.
In order to exercise the above mentioned rights, or if you have any questions, please contact our Local Privacy Officer by clicking on the “Contact Us” link at the bottom of the Site or contact us at Genzyme Europe B.V., located in Amsterdam, the Netherlands.
You also have the right to file a complaint before your local data protection authority if you believe that Sanofi has processed your Personal Data unlawfully. For the Netherlands, see www.autoriteitpersoonsgegevens.nl.