Privacy Policy

We take the protection of your personal data very seriously. The observance of privacy and the careful handling of your personal data is an important concern for us. Compliance with the statutory provisions on data protection is a matter of course for us. In the following, we will give you an overview of how we ensure the protection of your personal data,and which of your data we process for which purpose when you use our Website.

1. Controller / data protection officer / representative

Responsible for the data processing operations we describe here is:

Santhera Pharmaceuticals (Switzerland) Ltd.
Hohenrainstrasse 24
4133 Pratteln
Switzerland
Phone +41 61 906 89 50
info@santhera.com

We are best able to address your concerns through this channel. However, you are free to contact our Data Pro-tection Officer or our representative in the European Union (EU) and the European Economic Area (EEA) using the contact information below:

Santhera's data protection officer (DPO):
Swiss Infosec AG
Centralstrasse 8A
6210 Sursee
Switzerland
privacy@santhera.com

Santhera's representative in the EU and EEA:
Santhera (Netherlands) B.V.
Nevelgaarde 8
3436 ZZ Nieuwegein
The Netherlands
privacy@santhera.com

2. Your rights

You have the following rights under the data protection law applicable to you and to the extent provided therein:

  • Right of access, rectification, erasure and restriction: You have the right to request information at any time about whether and which of your personal data we process. When we process or use your personal data, we strive to take reasonable steps to ensure that your personal data is accurate and up to date for the pur-poses for which it was collected. In the event that your personal data is inaccurate or incomplete, you may request that it be corrected. Furthermore, you may have the right to request the deletion or restriction of the processing of your personal data if, for example, there is no longer a legitimate business purpose for such processing in accordance with this privacy policy or applicable law and legal retention obligations do not require the continued storage.
  • Right to data portability: You may have the right to receive the personal data concerning you that you have provided to us in a structured, common and machine-readable format or to request the transfer of this data to a third party.
  • Right to revoke your consent: If you have consented to the collection, processing and use of your personal data, you may revoke your consent at any time with effect for the future, but without affecting the lawful-ness of the processing carried out on the basis of the consent until revocation.
  • Right of objection: You have the right to object to the processing of your personal data at any time in ac-cordance with the legal requirements.

You also have the right to complain to a data protection supervisory authority about the processing of your per-sonal data carried out by us.

To enforce your data protection rights, you can contact us at any time using the contact details provided in the "Controller" section.

Please note that exceptions apply to these rights. In particular, we may need to process and store your personal data to fulfill a contract with you, to protect our own legitimate interests such as the assertion, exercise or de-fense of legal claims, or to comply with legal obligations. To the extent legally permissible, we may therefore al-so reject your data protection-related requests, e.g. requests for information and deletion, or comply with them only to a limited extent.

3. Data security

The security of your personal data is important to us. We have implemented comprehensive technical and organ-izational security measures to maintain the security of your personal data and to protect it against unauthorized or unlawful processing and/or accidental loss, alteration, disclosure or access. To this end, we regularly review our security measures and adapt them to the state of the art.

The processing of personal data on the Internet can always have security gaps despite appropriate and suitable organizational and technical measures. We can therefore not guarantee absolute data security.

4. Data disclosure and data transfers to third countries

We will not disclose or otherwise disseminate your personal data to third parties unless this is necessary for the performance of our services, you have consented to the disclosure or the disclosure of data is permitted by rele-vant legal provisions.

In order to provide our services, to comply with contractual or legal requirements, or for the other purposes stat-ed in this Privacy Policy, it may be necessary for us to disclose your personal data to the following categories of recipients:

  • Our service providers within the Santhera Group as well as externallyincluding contract processors (such as IT providers);
  • Domestic and foreign authorities, official agencies or courts;

These recipients may be in Switzerland or abroad (anywhere in the world). In particular, you should expect the transfer of your data to all countries where Santhera Group is represented by group companies, branches or other offices, as well as to other countries in Europe and the USA where the service providers we use are located (such as Microsoft, Google LLC). If we transfer data to a country without adequate legal data protection, we ensure an adequate level of protection as required by law by using appropriate contracts namely on the basis of the so-called Standard Contractual Clauses of the European Commission, which are available here or other recognized safeguards (e.g. Binding Corporate Rules, consent in individual cases).

5. Storage duration

We process and store your personal data only to the extent and for as long as it is necessary for the fulfillment of our contractual and legal obligations or otherwise for the purposes pursued with the processing, and beyond that in accordance with the statutory retention and documentation periods. As soon as your personal data is no longer required for the above-mentioned purposes or a prescribed retention period expires, your personal data will be deleted or anonymized as a matter of principle and as far as possible.

6. Use of the website, access data

In principle, you can use our website for purely informational purposes without disclosing your identity. When you call up the individual pages of the website in this sense, only access data is transmitted to our provider so that the website can be displayed to you. These are, among others, the following data:

  • IP address of the requesting computer
  • Date and time of access/retrieval
  • Name and URL of the retrieved data
  • Operating system of your computer and the browser you use
  • Country from which our website is accessed
  • Time zone difference from Greenwich Mean Time (GMT)
  • Content of the request (concrete page)
  • Last visited website
  • Browser settings
  • Language and version of the browser software
  • Browser plugins enabled

This data is processed solely for the purpose of enabling the use of our website (connection establishment), to ensure system security and stability on a permanent basis, to optimize our offer and for internal statistical pur-poses and, thus, based on our legitimate interests. This data is not passed on to third parties or evaluated in any other way. A personal user profile is not created.

Your personal data provided while using the website is deleted as soon as it is no longer required to achieve the purpose for which it was collected.

7. Notice on data transfers to the USA

Some of the third-party service providers mentioned in this privacy policy are based in the USA. For the sake of completeness, we would like to point out that the USA does not have a sufficient level of data protection in terms of data protection law. US companies are obliged to hand over personal data to security authorities with-out you as the data subject being able to take legal action against this. It can therefore not be ruled out that US authorities (e.g. intelligence services) process, evaluate and permanently store your data located on US servers for monitoring purposes. We have no influence on these processing activities.

8. Cookies

Our use of cookies and other similar technologies to process personal data is explained in our cookie policy https://www.santhera.com/cookie-policy.

9. Contact

When contacting us, e.g. by e-mail or via a contact form on the website, the personal data you provide will be processed by us in order to answer your inquiry and to contact you.

The legal basis for the processing is our legitimate interest in processing your request or the fulfillment of our contractual obligations, if the contact is aimed at the conclusion of a contract. If the provision of your data is nec-essary for the conclusion of a contract, it may be impossible to conclude or execute a contract or to process the request if the data is not provided.

In this context, the data will not be passed on to third parties. The data is processed exclusively for the processing of the conversation. We delete the data accruing in this context after the processing is no longer necessary or re-strict the processing to compliance with the existing legally mandatory retention obligat

10. Newsletter

When registering for our newsletter, you are required to provide your name, e-mail address and country, among other things. Insofar as you have given us your consent to data processing when registering for the newsletter, we process and store the personal data provided when registering for the newsletter exclusively to provide the newsletter service and to inform you about us and our offers.

The legal basis for the processing is your consent.

You have the option to unsubscribe from the newsletter at any time and to revoke the consent you have given. To do this, click on the corresponding button (link) in the newsletter sent to you. You will find this link to cancel the newsletter at the end of each newsletter. The data you have provided us with for the purpose of receiving the newsletter will be deleted by us after you unsubscribe.

11. Career

When you apply for a job with us, we process the personal data that we receive from you as part of the applica-tion process. In addition to your personal details, education, work experience and skills, this includes the usual correspondence data such as postal address, e-mail address and telephone number. In addition, all documents submitted by you in connection with the application, such as letters of motivation, curriculum vitae and the certif-icates are processed. In addition, applicants may voluntarily provide us with additional information. This data is stored, evaluated, processed or forwarded internally exclusively in connection with your application. Furthermore, they may be processed for statistical purposes (e.g. reporting). In this case, no conclusions can be drawn about individual persons.

The legal basis for the processing is our legitimate interest in processing your application or the fulfillment of our contractual obligations if the processing is aimed at concluding an employment contract. If the application is suc-cessful, the data submitted by you will be stored for the purpose of implementing the employment relationship.

If we conclude an employment contract with you, the transmitted data will be stored for the purpose of pro-cessing the employment relationship in compliance with the statutory provisions. If the application process ends without employment, your data will be deleted unless you have given us permission to use your information for further application processes with us and, if necessary, to contact you again.

12. DocCheck

We use the "DocCheck Single Sign-on" service of DocCheck Community GmbH, Vogelsanger Str. 66, 50823 Co-logne, Germany ("DocCheck") on our website.

We use this identification service for registration and proof of licensure on restricted access subpages of our website.

DocCheck uses cookies to provide the identification service on its own responsibility. For this purpose, you must enter your user name and password in the DocCheck input mask. The information generated by cookies is only transmitted to the DocCheck server in Germany and is not shared with us or other third parties.

For more information on how DocCheck processes your data, please click here: https://more.doccheck.com/en/privacy.

13. Google Analytics

Google Analytics, a service of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For users who are habitually resident in the European Economic Area or Switzerland, Google states that Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, is the controller of your data.

Google Analytics uses cookies and similar technologies that are stored on your computer and allow the analysis of your use of this website. We have added the code "anonymizeIP" to Google Analytics on the website. This guarantees the masking of your IP address, so that in principle all data is passed anonymously to Google. Only in exceptional cases will the full IP address be transmitted to a Google server and only shortened there. Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. Google may al-so transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's behalf. Google will, according to its own information, in no case associate your IP address with other data from Google.

You may refuse the use of cookies by selecting the appropriate settings on your browser, however, please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the col-lection of data and the processing of data by Google by downloading and installing the browser add-on available at the following link https://tools.google.com/dlpage/gaoptout. You can deactivate Google Analytics for display advertising and adjust the ads in the Google Display Network by accessing the ad settings: https://adssettings.google.en.

Further information on the terms of use and data protection of Google Analytics can be found at: https://marketingplatform.google.com/about/analytics/terms/en/ and https://policies.google.com/privacy.

14. Links to other websites

The website may contain links to other websites. We have no control over the privacy practices or the content of that other website. Therefore, we encourage you to carefully read the respective privacy policies of such other website you visit.

15. Changes to the privacy policy

We expressly reserve the right to amend or change this privacy policy at any time. The version published on our website at any given time shall apply.