BI PRIVACY STATEMENT

15 January 2019

Boehringer Ingelheim its group companies (hereafter "Boehringer Ingelheim", "we", "us" or "our"), take the protection of your Personal Data seriously. This privacy statement describes what Personal Data is collected from health care professionals ("you") and how we use such data. The privacy statement explains different scenarios to give you a clear understanding of what information Boehringer Ingelheim collects and uses for which purposes. We encourage you to click on the 'more information' links in each section where you are interested in additional information.

A. What is Personal Data?

Personal data is information that can be used to identify you ("Personal Data").

According to data protection laws, Personal Data is defined as any information relating to an identified or identifiable natural person ("Data Subject"); an identifiable person is one who can be identified, directly or indirectly, e.g. by reference to an identification number.

Examples for Personal Data are not only your name, your email address and your phone number, but also any other information that is or can be connected with your name. This could, for instance, be your medical specialty: If we store information about samples we sent to a person and that data is not attached to the person's name but to an identifier (such as the number 1234), this data is Personal Data if we can connect the number 1234 to that particular person's name.

B. When do we collect which categories of Personal Data?

Personal Data is collected in a number of different ways:

1. Information provided on the website when registering

When registering for a protected area of the website or when ordering information material, Boehringer Ingelheim may ask you to provide certain Personal Data (in particular full name, email address).

2. Information provided when interacting with us

Information is collected when you interact with us, e.g. when signing-up for an event, when accepting a speaker engagement, when communicating via email, when requesting and receiving product descriptions or other materials, data about visits from representatives (such as feedback about our products).

  • The Personal Data which we receive and use may be the following (based on your choices):
  • Name and contact data, including first and last name, postal address, email address, phone number or other contact data.
  • Credentials, including passwords, security questions or other security information.
  • Profession, as health care professional as well as therapeutic fields.
  • Interests, e.g. which events you are visiting, what information you request from Boehringer Ingelheim or other interests we learn about from interactions with you such as medical representatives visits.
  • Online behavior consists of data that is created during electronic interaction. It may include IP address or any browser information when navigating on our website, which links were clicked and more information about email usage.
  • Communication: We store and process the content of information we receive from you. For instance, if you write us an email, we may store this email to analyze your interests.

 

3. Log data

When using the website, certain data, including data sent by the browser (e.g. IP address, cookies, referring web page, time and date, content viewed) will be stored temporarily.

Log data may contain the following data fields: Requested URI, request method, IP address, IP port, the protocol version, browser language, and the last page visited (referrer) as well as name and version of the browser (user-agent).

4. Information received from third parties

We collect Personal Data about health care professionals from public or third party information sources, especially to verify their professional credentials and their identity.

C. How does Boehringer Ingelheim use Personal Data and for which purposes?

This section explains for which purposes and how we use Personal Data.

1. General Purposes

We use Personal Data to maintain your account and to deliver products or services you requested from us. We may also use Personal Data to protect against unauthorized access and security issues. Further, we use aggregated or anonymized information to help improve the website.

2. Information from Boehringer Ingelheim

When we plan to send you information about our products or our events we consolidate data available (e.g. which pages you visited, which materials you downloaded, therapeutic fields and events attended). Based on this information we use software tools to choose the content and combine available channels for a seamless communication with you.

What does "consolidating Personal Data" mean and how do we choose which information we send you? We only want to provide you with information about our product and service offerings such as pharmaceutical and medical products and services, promotions, news and events that we believe may benefit you. Therefore, we may bring together and analyze your Personal Data in order to learn more about you and your professional. This includes:

  • Online behavior, which means data about your actions when you visit our website such as viewed pages, clicks, materials downloaded, emails opened.
  • Interactions between you and us, for instance via a call center, a representative or a third party
  • Events you attend, for instance medical conferences, educational events or peer to peer meetings
  • Feedback you provide us, for instance through surveys or automated calls
  • Requests you might have, for instance regarding promotion material, samples or a visit of a representative
  • Information that our representatives collect from you
 

How do we get in contact with you? We may provide you with information through emails, mails, calls, our website or other means. We aim to communicate seamlessly over various channels, which means that we strive to not provide you the same information per email, mail and via our representative. Instead, we combine available communication channels and provide information based on your Personal Data.

When choosing the information we communicate to you we use software tools analyzing the data available to create different groups of recipients which will receive different information.

  • Example: If you participate in events that inform about asthma therapies and download materials containing information about the newest asthma research, we may assume that you are interested in additional information about such asthma therapies. Therefore, we may provide you with additional material over various channels, for instance, a Boehringer Ingelheim representative may visit you and present you related product samples or – if you are very responsive to newsletters – we may send you further e-mails with information about asthma therapies.

  • On the other hand, if you do not accept invitations for events about a new Boehringer Ingelheim product and do not download materials related to such products or view information about such products in our newsletter we may assume that you will very likely not be interested in further information material about such a product or therapeutic field and will not communicate such information to you.

 

3. Reporting obligations to regulators

As a pharmaceutical company, Boehringer Ingelheim is subject to specific regulations, such as pharmacovigilance or transfer of values (e.g. speaker honorariums, travel costs for event participations, etc.). Some of those laws may require us to send reports to regulators or other authorities. We will only provide Personal Data to authorities where legally required.

D. Cookies

We use cookies and similar technologies such as pixel tags, web beacons and clear GIFs (referred to hereafter as "Cookies"). Cookies are widely used in order to make websites work, or work more efficiently, as well as to recognize devices on subsequent visits to provide information to the owners of the site

What types of Cookies exist?

- Necessary Cookies

Necessary Cookies are used for "technical" reasons, such as re-establishing a user's session at login if their previous session was cancelled due to user inactivity. Such Cookies are not used to analyze the use of our website or emails.

- Analytical Cookies

These Cookies help us analyzing the use of our website and emails: They allow us to analyze activities on our sites in order to improve and optimize the way our sites work. For example, we may use these types of Cookies to ensure that visitors can easily find the information they are looking for on our sites. One way we do this is to recognize and count the number of visitors and see how they move around our site when they are using it. Analytics Cookies also help us measure the performance of our advertising campaigns and to optimize our sites' content for those who engage with our advertising. Cookies play an important part when we choose which information we send to users (see Section C.2 above for more information on this).

One way you can manage the acceptance of Cookies is through your browser's settings. Most browsers allow control of Cookies through the browser settings (please note that if you use your browser settings to block all Cookies you may not be able to access parts of our websites). The following list provides information on how to adjust the Cookies settings on some popular browsers:

 

You can also use a browser plug-in such as Ghostery from Evidon Inc. or the Tracking Protection List from TRUSTe.

Adobe Analytics

We use Adobe Analytics, a web analytics service provided by Adobe Systems Software Ireland Limited ("Adobe"). Adobe Analytics uses Cookies in order to analyze overall traffic and usage patterns on behalf of Boehringer Ingelheim. The IP address collected by the Cookie is anonymized before geo-localization is performed. Adobe will not associate your IP address with any other data held by Adobe. You can prevent Adobe's collection and use of data (Cookies and IP address) by making use of your options under

http://www.adobe.com/privacy/opt-out.html

E. How and when do we share information?

Boehringer Ingelheim only transfers Personal Data to third parties according to applicable law, especially when you have expressly given your consent, when required to deliver services that you ordered, or when we engage service providers that use Personal Data on our behalf and according to our instructions.

Boehringer Ingelheim undertakes to ensure an adequate protection of Personal Data transferred outside of the European Union (usually using EU Model Contracts which have been issued by the European Commission).

Third parties that may receive Personal Data are the following:

1. Regulators

Where we are legally obliged to do so (see Section C.3 above), we will share information including Personal Data with regulators or other competent authorities.

2. Service providers and Boehringer Ingelheim companies

We employ other companies, including other Boehringer Ingelheim Group companies, to store, manage and analyze the Personal Data about you. Where we employ third party companies which do not belong to Boehringer Ingelheim Group or individuals to process Personal Data provided by us (and not collected by themselves), they only process such Personal Data on our behalf, based on our instructions and in compliance with this privacy statement.

One of our service providers is Adobe Systems Software Ireland Limited, 4-6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland which is providing data and web analytics services.

Involving other companies may be necessary for other services. This is the case for example for the delivery of sample materials.

Where those companies are located outside of the EU/EEA we ensured by means of contractual clauses or other approved instruments that the Personal Data transferred to those companies is adequately protected. Adequate protection means that the protection of Personal Data complies with the level of protection that exists in the EU/EEA.

3. Healthcare information providers

When we receive incorrect Personal Data from healthcare information providers (see Section B.4 above), we inform these providers where their data is incorrect.

4. Anonymous information

We may also share aggregated or non-personally identifiable information with other parties.

F. How long do we store Personal Data?

We will retain Personal Data as long as required for the specific business purpose or purposes for which it was collected.

We may be obliged to store some data for a longer time (e.g. in cases of pharmacovigilance). In this case, we will ensure that your data will not be used for direct marketing purposes.

G. How we secure Personal Data

We use industry standard practices to protect the confidentiality, integrity, and availability of data, e.g. by access controls. All Personal Data provided to us is secured using industry standard procedures. We strive to update our security measures on a regular basis to keep track of new industry standards.

H. Who we are and how to contact us

The Personal Data is collected and used by

Boehringer Ingelheim Middle East & North Africa FZ-LLC
The Index Tower, Floor 13
P.O. Box 506077
Dubai International Financial Center
Dubai
United Arab Emirates

and

Boehringer Ingelheim Pharma GmbH & Co. KG
Binger Straße 173
55216 Ingelheim am Rhein
Germany

Both entities cooperate closely when using Personal Data and are designated "joint controllers", meaning that each entity is responsible for all use of Personal Data in the platform.

Boehringer Ingelheim is an entity of the Boehringer Ingelheim group of companies (hereinafter the "Boehringer Ingelheim Group"). The Boehringer Ingelheim Group is one of the world's twenty leading research-driven pharmaceutical companies. Its headquarters are located in Ingelheim, Germany.

As part of research and development activities for innovative drugs, the family-owned company focuses primarily on the therapeutic areas of cardiovascular disease, respiratory diseases, diseases of the central nervous system, metabolic diseases, virological diseases and oncology. It has been committed to researching, developing, manufacturing and marketing novel medications of high therapeutic value for human and veterinary medicine.

 

If you have any questions or other enquiries regarding our collection and use of Personal Data or this privacy statement, please feel free to contact us or our data protection officer at any time:
Boehringer Ingelheim Middle East & North Africa FZ-LLC
The Index Tower, Floor 13
P.O. Box 506077
Dubai International Financial Center
Dubai
United Arab Emirates
E-mail:[email protected]

or

Boehringer Ingelheim Pharma GmbH & Co. KG
Binger Straße 173
55216 Ingelheim am Rhein
Germany
E-mail:[email protected]

Additional contact information is provided in the imprint.

I. What are your rights?

Upon your request, we will inform you in writing or electronically whether and what Personal Data relating to you Boehringer Ingelheim has stored and will review any requests you may have.

You can also withdraw a consent you may have given to the collection and/or processing of your Personal Data at any or by mail/email to the addresses mentioned in Section H above.

Right to access modify or delete your Personal Data

You may modify, add, delete or update your Personal Data or request deletion of Personal Data by emailing us at [email protected] or by contacting us as described in Section H above.

In case you request deletion of Personal Data, you may no longer be able to use all features and functions of our services. Please note that we may be required to keep some of your Personal Data for legal reasons, for instance to comply with statutory retention periods or for tax purposes. In such cases, we will mark your Personal Data accordingly to make sure that it is not used for any other purpose than complying with the retention requirement.

Right to opt-out of Boehringer Ingelheim Marketing Communication

You can unsubscribe from Boehringer Ingelheim emails by following the unsubscribe instructions included in each email.

If you do not want us to use any of your Personal Data for direct marketing or market research purposes such as receiving mailings, you can inform at us any time by emailing us at [email protected]1

Right to contact the competent data protection authority

In case you have any questions or concerns regarding our use of your Personal Data and if you do not wish to contact us directly, you may also contact the data protection authority competent for us which is

"Commissioner of Data Protection", PO Box 74777, DIFC, Dubai , United Arab Emirates

or

"Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz", Hintere Bleiche 34, 55116 Mainz, Germany.

J. What happens when we change this privacy statement?

We may update this privacy statement from time to time and for any reason. We will notify you of any changes to our privacy statement by posting the new privacy statement here or, if the changes are material with regard to information collected from you, by posting a prominent notice on our website or by sending an email to the email address you provided to us prior to the change becoming effective. If required, we may also seek your prior consent. You should consult this privacy statement regularly for any changes.

1 Opting out does not mean that visits from Boehringer Ingelheim representatives or providing you with medical information are excluded.