Chiesi

Privacy Policy

Privacy Policy for Chiesi Pharma AB

Scope of the Privacy Policy

1.1 Below is a description of how Chiesi Pharma AB, org. no. 556827-5746, with address Klara Norra Kyrkogata 34, 111 22, Stockholm, ("Chiesi", "us" or "we") processes personal data in relation to you who have registered for training or webinars we are responsible for, subscribed to our newsletter, or use our website for another reason.


1.2 Privacy protection is a priority for us. Therefore, it is important for us to protect your personal data and ensure that our processing of them is done correctly and legally.


1.3 In this privacy policy, we explain what types of personal data we may process and for what purpose we process them. We also describe our processing of personal data and what choices and rights you have in relation to it. We ask you to read our privacy policy carefully and understand its content.


1.4 Please note that this privacy policy concerns the processing of personal data for which Chiesi is the data controller. This means that we are responsible for the handling and processing of your personal data. It also means that you should contact us with questions or comments, or if you want to exercise any of the rights you have in relation to our handling of your personal data (see point 7 below).


Processing of Personal Data

Personal data are data that can be attributed to you. We process the personal data you have provided to us. However, you are not obliged to provide us with any personal data. If you decide not to do so, this may, for example, result in us not being able to contact you with invitations to training and webinars or with desired marketing material.


If you decide to provide us with your personal data, we may handle them in accordance with the table below.

Category of Registered

Invited to webinar or training. Participant in webinar or training.

Type of Personal Data

Name, email address, title, workplace.

Purpose of Processing

To follow up on your participation in the webinar or training and market our services.

Legal Basis

Our legitimate interest in administering mailings to you in accordance with your stated preferences. Our legitimate interest in administering the implementation of the webinar or training with you as a participant in accordance with your stated preferences.

Category of Registered

Subscribers to our newsletter.

Type of Personal Data

Name, email address, title, workplace.

Purpose of Processing

To market our services and products.

Legal Basis

Your consent.

Category of Registered

Job applicants.

Type of Personal Data

Name, email address, phone number, address, CV, cover letter, and any other documents to support your competence.

Purpose of Processing

To conduct the recruitment process.

Legal Basis

Our legitimate interest in effective and correct recruitment.

Category of Registered

Orderers of information and demonstration material.

Type of Personal Data

Name, email address, phone number, your workplace including any department, and postal address to your workplace.

Purpose of Processing

To deliver the material you order.

Legal Basis

Our legitimate interest in marketing and informing about our products in accordance with your stated preferences.

Category of Registered

Conduct satisfaction surveys and market surveys, and request reviews from you via email or other communication channels.

Type of Personal Data

Name, email address, title, workplace.

Purpose of Processing

To follow up on the perceived quality after participation in the webinar, seminar, training, product meeting, or the perceived quality with Chiesi as a whole, etc.

Legal Basis

Our legitimate interest in administering satisfaction surveys to you.

Category of Registered

Contact seekers via contact form.

Type of Personal Data

Name and email address.

Purpose of Processing

To contact you and follow up on your case.

Legal Basis

Our legitimate interest in following up on your contact request.

Profiling

3.1 Automated processing of personal data

Profiling involves automated processing of personal data to assess certain characteristics, such as analyzing or predicting your personal preferences.


We use profiling to:

• deliver customized mailings, meeting requests, and product news to you through our platforms and services.


If you have questions about how the profiling process works, you can contact us. Contact details can be found in point 9. You can object to our profiling at any time by contacting us (and we will stop profiling). You can also end our profiling by unsubscribing from our services.


3.2 Chiesi's automated decisions

Automated decisions mean that certain decisions are made exclusively automated, without the involvement of our employees, and can have a significant impact on you. By making such decisions automatically, Chiesi increases objectivity and transparency in decisions to offer you our services. You always have the right to object to these types of decisions.


Automated decisions also mean that profiling is done based on your information before the decision is made. Profiling for this type of decision is done to assess relevance for meetings, product information meetings, congresses, and/or other gatherings.

Storage of Personal Data


4.1 We store your personal data as long as it is necessary to fulfill the purpose of the processing.


4.2 As a subscriber, your data is stored until you choose to withdraw your consent. You have the right to withdraw your consent at any time. If you no longer wish to receive our email mailings, you can withdraw your consent by unsubscribing from them. You unsubscribe by following the instructions for unsubscribing in the email you have received.


4.3 Data about you as a job applicant may be stored during the recruitment process, after which the data is deleted. If you have consented to us processing the data for future recruitments, the data may instead be retained for two years after the consent is given (or until the consent is withdrawn), after which they are deleted. Despite the above, we may store the data as long as a job applicant who has not been hired can take legal action regarding the recruitment process. If you ask us to delete your personal data, this will be done without undue delay as soon as it is practically possible.


4.4 To the extent your personal data is no longer necessary to fulfill the purpose of the processing, or the processing for other reasons would no longer be allowed, the data is deleted.

Recipients


We may disclose your personal data to our data processors, e.g., companies that work with IT and cloud services. In such cases, data processing agreements are entered into to ensure that your personal data is processed in accordance with this privacy policy.

Transfers


If your data is transferred by us or any of our processors to a country outside the EU/EEA, we ensure that appropriate security measures are taken during the transfer of data to such operations.

Your Rights


7.1 You have the right to receive confirmation of whether we process personal data concerning you, and if so, access to these personal data and also information about the personal data and our handling of them.


7.2 You have the right to have incorrect personal data concerning you corrected by us without undue delay. You also have the right, considering the purpose of the processing, to in certain cases complete incomplete personal data.


7.3 You have the right, under certain circumstances, to have your personal data deleted by us, e.g., if the personal data is no longer necessary to fulfill the purposes for which they were collected, or if the personal data has been processed unlawfully.


7.4 You have the right, in certain cases, to require that we restrict the processing of your personal data. If you, for example, dispute the accuracy of the personal data, you can require that we restrict the processing of them during the time it takes for us to verify that the data is correct.


7.5 You have the right to object to the processing of your personal data based on our legitimate interest. If this happens, we must demonstrate compelling legitimate grounds that outweigh your interests, rights, and freedoms to continue the processing.


7.6 You have the right to obtain the personal data you have provided to us and that concerns you in an electronic format that is commonly used. You have the right to transfer such data to another data controller (data portability).


7.7 You have the right to withdraw your consent at any time. Your withdrawal will not affect the legality of the processing that took place based on the consent before it was withdrawn.


7.8 If you have comments on our processing of your personal data, you are welcome to contact us. You also have the right to file complaints about the processing of your personal data with the Swedish Authority for Privacy Protection.


Additions and Changes

We may make additions or changes to this privacy policy. If we do, we will notify you appropriately, for example via email. If this happens, we ask you to carefully read the updated privacy policy.


Contact Us

To update, correct, or delete data we have about you or exercise rights that belong to you as mentioned above, you are welcome to contact us at infonordic@chiesi.com.


This privacy policy is effective from May 23, 2025.