Privacy Policy – Healthcare Professionals

Nutricia Ireland Limited, with its address at Block 1, Deansgrange Business Park, Deansgrange, Co Dublin, A94 P9T3, Ireland knows that you care how your personal data is used and we recognize the importance of protecting your privacy.

This Privacy Policy explains how Nutricia Ireland Limited, a subsidiary of Danone SA (“Nutricia”, “we”, “our”, “us”) acting as Data Controller collects and manages your personal data. It contains information on the data we collect, how we use it, why we need it and how it can benefit you. This is our Privacy Policy for healthcare professionals (“HCPs”). If you are a consumer, patient or carer please click here to see the privacy notice relevant to you.

Contact us at Data Protection Officer, Block 1, Deansgrange Business Park, Deansgrange, Co Dublin, A94 P9T3, Ireland or click here if you have any queries and comments, or if you want to make a request regarding any of your data subject rights.

This Privacy Policy was last updated on 16 September 2021.

Basic principles of our privacy commitment

Nutricia is committed to protecting your right to privacy. We aim to protect any personal data we hold, to manage your personal data in a responsible way and to be transparent in our practices. Your trust is important to us. We have, for the purposes of complying with our legal obligations to you, committed ourselves to the following basic principles:

  • You have no obligation to provide any personal data requested by us except as required to perform any contract we have with you. However, if you choose not to provide any personal data requested by us, we may not be able to provide you with some services or products;
  • We only collect and process your data for the purposes set out in this Privacy Policy or for specific purposes that we share with you and/or that you have consented to.
  • We aim to collect, process and use as little personal data as possible for the purposes as described in this Privacy Policy.
  • When we do collect your personal data, we aim to keep it as accurate and up to date as possible.
  • If the personal data we collect is no longer needed for any purposes and we are not required by law to retain it, we will do what we can to delete, destroy or permanently de-identify it at the earliest opportunity.
  • Your personal data will not be shared, sold, rented or disclosed other than as described in this Privacy Policy.

What personal data do we collect?

By personal data, we refer to any information about a person from which that person can be identified. This does not include data for which the identity has been deleted (anonymous data).

The personal data we collect varies depending upon the purpose of the collection, how you interact with us (for example online, offline or over the phone) and the product or service we are providing you.

Nutricia collects and uses some or all of the following categories of personal data for the purposes described in this Privacy Policy:

  • Personal contact data, such as your name, email address, work address and telephone number. This is collected as a requirement to set up an account on our website, fulfil sample orders and communicate with account holders;
  • Professional details such as your place of practice, job title, the medical field in which
  • you are active, your professional qualifications and scientific activities (such as
  • previous clinical trial experience, and participation in research), publication of
  • academic or scientific research and articles, and membership in associations and
  • boards;
  • Professional details such as data related to your educational history and professional employment history. This data is collected in relation to the Nutricia Learning platform;
  • Account login details, such as your user ID, e-mail, username and password are collected. This information is required to create and give you access to your personal Nutricia user account;
  • Communications with us, which may include details of our meetings and conversations via email, chat, care lines and/or customer service lines and/or Nutricia sales representatives;
  • Lifestyle information such as areas of professional interest. Areas of interest may include your preference for some of the products and/or services we offer, and your interests related to those products and/or services;
  • Financial details such as payment-related information where relevant;
  • Details available on the OneKey system about you;
  • Dietary requirements if you are attending an event or where relevant;
  • Pictures of you, recordings of your voice, appearance, and statements where relevant, this data may be collected if we engaged you to provide services such as speaking at an event;
  • Browser history, such as pages accessed, date of access, location when accessed, and IP address; and
  • Information about people other than you, such as personal data about your patients. This data will only be collected with the permission of the patient which you will be asked to confirm.

How do we collect personal data?

We collect your personal data directly from you via the following sources, this collection includes when:

  • you communicate with us via post, email, chat, text or telephone (including our Careline and/or customer service lines), or through our sales representative including face to face meetings and otherwise;
  • you interact with us on our Nutricia websites and apps, including when you register for an account with Nutricia, or send or post queries or comments (including on our social media pages);
  • you place an order, or request certain products, samples or services from us;
  • you fill in one of our registration forms (online or offline), such as registering for an account with us, or an educational platform, webinar or event;
  • you participate in research activity, survey, promotional activity or competitions; 
  • you sign up or request marketing communications or other promotional materials to be sent to you; or
  • you give us feedback for one of our products or services or contact us.

We may also collect personal data about you indirectly when:

a) you share content on social media pages, websites or applications related to our products or services or in response to our promotional material on social media;

b) we may collect personal data about you from reading information collected by other third party websites (for instance, we may place an ad on a third party website, and when you click on that ad, we may receive information about you and other website visitors in order to measure the reach and success of that ad);

c) we may collect data about when you open and/or click on a link in a Nutricia email. This allows us to see how well our communications with you are performing;

d) you provide a reference to us and we contact that person for information about you;

e) a patient of yours provides your name and details to us;

f) we may collect information about you which is available from publicly available sources such as the Irish Medical Directory or if you have published an article in an academic journal; or

g) we may collect your professional information made available by third party healthcare database providers or event/conference organisers; or third party providers such as OneKey (which is a provider of a worldwide healthcare professional’s database).

We may combine this data with information we already hold about you. We may process this information for the purposes described below under the legal grounds of legitimate interests.

Why do we collect and use your personal data?

We collect your personal data so we can perform any contract we have with you; provide you with the best online experience and to provide you with a high quality of customer service.

We collect hold, use and disclose your personal data for the following purposes:

a. Customer service

We use your personal data:

  • To create your Nutricia user account and to manage your account with us
  • To process your orders of products or samples, to provide you with your order status, order tracking and to deliver your products or samples, deal with your enquiries and requests, and assess and handle any complaints
  • To process and answer your inquiries or to contact you in order to answer your questions and/or requests
  • To organise and secure your professional services e.g speaker and writer opportunities, participation in roundtables, advisory boards, organise associated logistics, to calculate honoraria that are fair market value and to manage and process payments, fees for these services
  • To share and match your (anonymised) data to external research companies for analysis purposes
  • For training and quality control purposes and to verify your identity when contacting us by telephone, electronic means or otherwise
  • To register you to attend an event (face to face and/or virtual) or a webinar organised by us or via a third party, for example to place you on a guest-list to the event, to provide associated support with your attendance at the event, and to help us better understand what products and services you would like to receive information about in the future following the event.
  • To supply you with the Nutricia Care team where you have requested or registered for this service. Full details of Nutricia Care app privacy policy can be found here
  • To manage our relationship with you which will includes notifying you about changes to our Terms & Conditions or Privacy Policy

The legal basis for processing your data for this purpose is:

  • performance of a contract
  • legal obligations
  • legitimate interests – to improve the customer service experience; to improve and develop new products and services and to grow our business; to meet our compliance requirements with our internal Healthcare Systems policies and procedures; to identify and prevent fraud; to monitor, detect and protect our organisation, systems, network, and staff.

b. E-learning Management

We use your personal data:

  • To enable your participation in an e-learning, create your personalised learning record, administer your learning completion certificate, send you relevant content or remind you of your progress.

The legal basis for processing your data for this purpose is:

  • performance of a contract
  • legal obligations
  • legitimate interests – to keep records updated, to improve and develop the e-learning experience; to improve and develop new products and services; to identify which products and services may interest you and to communicate these to you; to monitor, detect and protect our organisation, systems, network, and staff.

c. Communications, personalisation and marketing

We use your personal data:

  • To enable Nutricia to contact you for example to advise changes to our products or services
  • To   communicate   information   to   you   and   to   manage   your   registration  (and attendance) at an event, or participation in a competition or promotion organised by us or a third party
  • To manage your subscription to our newsletters or other direct marketing communications and consents (where relevant)
  • To send emails or postal communications about our products or services which may interest you, this may include contact from Nutricia sales representatives
  • To send educational information about conditions or products relevant to your area of interest, field or expertise, this may include contact from Nutricia sales representatives
  • To send information about events that may be of interest to you (virtual or face to face events), this may include contact from Nutricia sales representatives
  • To contact you to share details of speaker or writing opportunities which we think may be of interest to you
  • To analyse your preferences, anticipate your needs and to personalise your experience on our websites and platforms to deliver and show you content and advertising tailored to your interests as well as product recommendations, and to measure or understand the effectiveness of the content we serve to you

The legal basis for processing your data for this purpose is:

  • consent (where required)
  • performance of a contract
  • legitimate interests - to analyse how customers use our products and services, to improve and develop them and to grow our business and to inform our marketing strategy; to identify which products and services may interest you and to communicate these to you; to define types of audiences to develop and improve our products, services and campaigns

d. Development and enhancement of our products, services, events, communication methods and the functionality of our websites:

We use your personal data:

  • To request feedback on Nutricia products and services to provide us with insights and when you respond to such requests
  • To inform and develop the content we show on our website to ensure that our website content is relevant for our audience. The content shown on our website is not personalised unless you have consented to this via cookies.
  • To request and manage your participation in surveys and/or market research to provide us with insights and when you respond to such requests
  • To measure the effectiveness of our advertising and promotional materials and to improve the quality of your online experience
  • To monitor and conduct data analytics on our website or apps,pages and links clicked, patterns of navigation, time at a page, devices used, and/or where you are coming from
  • To administer and protect our business and this website including troubleshooting, data analysis, system testing, maintenance, support, reporting and hosting of data.

The legal basis for processing your data for this purpose is:

  • consent (where required)
  • legitimate  interests  –  to  understand  and  assess  the  interests,  wants,  and changing  needs  of  customers  in  order  to  improve  our  website,  our  current products and services, and/or to develop new products and services and grow our business and inform our marketing strategy; to  identify which products and services, events may be of interest to you and to communicate these to you, this also may include contact from Nutricia sales representatives; to study how customers use our products and services; to define types of audiences to develop and improve our products, services and campaigns; to monitor, detect and protect our organisation, systems, and network

We may also need your personal data to comply with legal obligations to you, your patients for example payment disclosures (transfer of value) where appropriate, or in the context of a contractual relationship that we have with you.

When we collect and use your personal data on the legal basis of our legitimate interests, we believe the risk to your data protection rights in connection with personal data is not excessive or overly intrusive. We have also put in place protections for your rights by ensuring proper retention periods and security controls.

When we collect and use your personal data for new purposes, we will inform you before or at the time of collection unless we reasonably consider that we need to use your personal data for another reason and that reason is compatible with the original purpose of collection as detailed above.

Where legally required to do so or where appropriate, we will ask for your consent to process the personal data. Where you have given consent for processing activities, you have the right to withdraw your consent at any time by informing us of your decision. If you wish to withdraw your consent, please contact us via this link.

Marketing

We may use your personal data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant for you. Where legally required to do so or where appropriate, we will ask for your consent to process your personal data for marketing purposes, otherwise we may rely on legitimate interests to process your personal data collected in a professional capacity for our marketing purposes.

Where you have given your consent to do so, we may share your personal data with a named third-party organisation for them to supply you with marketing materials. We will always obtain your opt-in consent before we share your personal data with any named third party for marketing purposes.

Opting out

You can ask us or our third parties to stop sending you marketing messages at any time by visiting the update my details page and changing your preferences on your Nutricia account (if you have an account with us), or by following the opt-out links on any marketing message sent to you or by contacting us at any time.

Where you opt out of receiving marketing messages, this will not apply to service or transactional messages e.g communications related to product/service purchases or requests, product/service experience, or communications that contain content that we are legally or contractually obliged to inform you of for example product recalls or safety notifications.

Your rights

Where we process your personal data, you are entitled to a number of rights and can exercise these rights at any point. We have provided an overview of these rights below together with what this entails for you. Should you want to exercise your rights, please contact us via this link. If you have a Nutricia.ie account, you can also change your preferences any time by visiting the update my profile page

Some of these rights only apply in certain circumstances and so are not guaranteed or absolute rights. Please contact our Data Protection Officer if you have any questions about your rights.

The right to access your personal data and correction

You have the right to access, correct or update your personal data at any time. We understand the importance of this and should you want to exercise your rights, please contact us via this link.

The right to data portability

Your personal data is portable. This means it can be moved, copied or transmitted electronically. However, this right only applies where:

a) The processing is based on your consent;

b) The processing takes place for the performance of a contract;

c) The processing takes place by automated means

If you wish to exercise your right to data portability, please contact us via this link.

The right to deletion of your personal data 

You have the right to request that we delete your data if:

a) your personal data is no longer necessary in relation to the purposes for which we collected it; or

b) you withdraw the consent that you had previously given us to process your personal data, and there is no other legal ground to process that personal data; or

c) you object to us processing your personal data for direct marketing purposes; or

d) you object to us processing your personal data for Nutricia’s legitimate interests (such as improving overall user experience on websites); 

e) the personal data is not being processed lawfully; or

f) your personal data needs to be deleted to comply with the law.

If you wish to delete the personal data we hold about you, please contact us via this link . Alternatively, you can contact the Careline during office hours Monday - Thursday 9am – 5pm and Friday 9am – 4pm by calling 1800 923 404 in ROI or 08007834379 in NI. We will respond to your request in accordance with our legal requirements.

If the personal data we collect is no longer needed for any purposes and we are not required by law to retain it, we will delete, destroy or permanently anonymise it. This is discussed in further detail below.

The right to restriction of processing

You have the right to restrict the processing of your personal data if;

a) you do not believe the personal data we have about you is accurate; or

b) the personal data is not being processed lawfully, but instead of deleting the personal data, you would prefer us to restrict processing instead; or

c) we no longer need your personal data for the purposes we collected it, but you require the data in order to establish, exercise or defend legal claims; or 

d) you have objected to the processing of your personal data and are awaiting verification on whether your interests related to that objection outweigh the legitimate grounds for processing your data.


If you wish to restrict our processing of your personal data, please contact us via this link and we will respond to your request in accordance with our legal requirements.

The right to object

You have the right to object to the processing of your personal data at any time. Please contact us via this link.

The right to withdraw consent

Where legally required to do we will ask for your consent to process the personal data. When we process your personal data on the basis of your consent, you have the right to withdraw your consent at any time. However, such withdrawal does not affect the lawfulness of the processing that took place prior to this withdrawal. If you wish to withdraw your consent, please contact us via this link.

The right to lodge a complaint with a supervisory authority

While we would be grateful if you lodged any complaints with us, you have the right to lodge a complaint directly with the Data Protection Commission’s Office about how we process personal data. 

For more information about your privacy and data protection rights, or if you are not able to resolve a problem directly with us and wish to make a complaint, please contact the Irish Data Protection Commission at:

Mailing Address: Canal House, Station Road, Portarlington, R32 AP23 Co. Laois

Phone Numbers: +353 57 8684800 or +353 (0)761 104 800

Email Address: info@dataprotection.ie

You can also contact our Data Protection Officer directly at DPO.UKIE@danone.com.

How we protect your personal data

We understand that the security of your personal data is important. We make our best efforts to protect your personal data from misuse, interference, loss, unauthorized access, modification or disclosure. We have implemented a number of security measures to help protect your personal data. For example, we implement access controls, use firewalls and secure servers, and we encrypt personal data. 

We also make sure that any third parties that we deal with keep all personal data they process on our behalf secure.

Sharing of your personal data

When we share your personal data with affiliates of Nutricia Ireland Limited and other organizations as described below, we make sure we only do so with organizations that safeguard and protect your personal data and comply with applicable privacy laws in the same or similar way that we do.

Your personal data will not be shared, sold, rented or disclosed other than as described in this Privacy Policy. We may, however, share your data when required by law and/or government authorities. 

Trusted third parties may assist us in providing specific services or functions on our behalf, such as IT services, both internal and external. This includes platform providers, hosting services, maintenance and support on our website as well as on our software and applications that may contain data about you, or to perform on our behalf the statistical analyses associated with the use of the website, apps or e-learning platforms.

 

Category of third partiesData typePurposes
External Processors  
Adobe Audience ManagerNon-identifying Nutricia website membership dataTo show you products and services appropriate to topics of interest.
FacebookOnline behavioural dataTo allow Nutricia to see how well adverts perform on our website.
TwitterBehavioural data

To allow Nutricia to see how well adverts perform.

 

Retargeting for the purpose of advertising to users who have been on the website.

Commerce Tools (ecommerce platform)HCP name, email and address, product ordered. Patient name and address.To allow the order and delivery of requested product samples.
Google AnalyticsAnonymised membership dataTo analyse user behaviours on a website and email the allow us to enhance your experience.
Adobe AnalyticsAnonymised membership data

Analyse user behaviours on a website and email the allow us to enhance your experience.

 

Retargeting for the purpose of advertising to users who have been on the website.

Adobe CampaignName, email address, areas of interestTo provide you with newsletters and other marketing communications relating to our business which we think may be of interest to you by email.
One Key DatabaseHCP name, speciality, work address, product ordered and OneKey ID.For the management of your online account, internal reporting and deployment of sales reps.
CRMHCP name and work address, email, areas of interests, products ordered, events and webinars attended, consentsFor the creation and management of your Nutricia profile whereby we can identify products, events or services that may be of interest to you, manage consents and perform internal reporting.
Vendor Management PlatformName, business or personal email, business or personal phone number, payment/billing informationTo process payments for services provided e.g performing as a quest speaker at a Nutricia event.
Logistics companiesPatient/HCP, Carer/Consumer name, address and product orderedFor the delivery of required product samples.
MPS mailing houseName, postal addressSending hard copy communications.
Event Management ProvidersName, email, telephone, areas of interest, place of work and role, dietary requirementsTo support with registrations, and organise and manage digital and/or in person events on our behalf.
Survey & Market Research ProvidersProfessional and contact details such as name, email title role & your responsesTo gather feedback, gain insights on our services and/or products.
Internal Processors  
Other Nutricia / Danone internal teamsPersonal contact data (email, phone number, address and name)To process, handle and respond to complaints and queries or where we reasonably need to do so.

If we decide to reorganise or to sell our business or our company, directly or indirectly through a sale, merger, or acquisition, we may share your personal data with actual or prospective purchasers of the business, or of our company. We will require that any such purchasers treat your personal data consistently with this Privacy Policy.

Sharing data internationally

Personal data may be processed outside the European Economic Area (EEA). When processed outside the EEA, Nutricia will make sure that this cross-border data processing is protected by adequate safeguards. 

The safeguards that we use to protect cross-border data processing comprise of:

a) Standard Contractual Clauses approved by European Commission. These standardized contractual clauses provide sufficient safeguards to meet the adequacy and security requirements of the European General Data Protection Regulation;

b) Certifications which demonstrate that third parties outside of the EEA process personal data in a way that is consistent with the European General Data Protection Regulation. These certifications are approved either by the European Commission, a competent supervisory authority or a competent national accreditation body in terms of General Data Protection Regulation.

c) An adequacy decision whereby we will only transfer your personal data to countries that have been deemed by the European Commission to provide an adequate level of protection for personal data.

We may share your personal data with other Danone subsidiaries as detailed above. This may involve transferring your data outside of the EEA to our UK based entities. This transfer will be protected by using one of the safeguards as detailed above.

Automated decision-making and profiling

For some services and products we may process your personal data using automated means. Essentially this means that decisions are taken automatically without human intervention. An example of this would be deciding which type of campaign emails you receive from us.

We may also process your personal data to predict your behaviour on our website and show you content or products that may be of interest to you. We may also use your data to send tailored communications via email and direct mail, where you have consented or where we assessed that we have a legitimate interest to do so.

When we send or display personalised communications, content, we may use some techniques qualified as “profiling” (i.e. any form of automated processing of personal data consisting of using those data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s personal preferences, interests, professional experience, economic situation, behaviour, location, reliability, or movements). This means that we may collect personal data about you in the different scenarios mentioned above. We centralise this data and analyse it to evaluate and predict your personal preferences and/or interests, to help us understand engagement and to create relevant content that may be of interest to you. Based on our analysis, we send or display communications and/or content tailored to your interests. You have the right to object to the use of your data for “profiling” in certain circumstances.

We confirm that you will not be subject to a decision based solely on automated decision-making, including profiling which produces legal effects, or which will significantly affect you. If we intend to make use of such methods, we will inform you and we will give you an opportunity to object to these processes in advance. You are also free to contact us for further information on such processing or to change your mind in relation to this type of processing. Please contact us via this link for further information on such processing.

Personal data retention period

We will only retain your personal data for the minimum time necessary to achieve the purposes for which we collected it as set out in this Privacy Policy, including to comply with any legal, regulatory, tax, accounting or reporting requirements.

Your personal data will also be retained for the duration of your contractual relationship with us, including where we maintain an ongoing relationship with you (for example where you have consented to marketing communications and have not unsubscribed from our mailing lists).

HCP details are stored for 5 years in Gigya and then moved to Gigya's consent vault for a further 7 years before being full deleted. This consent vault is a redacted, read only version of the record which can only be accessed in a compliance view. Records cannot move from the vault back to an active status. Patient data is stored in CommerceTools for 90 days before being fully deleted.

To determine the appropriate retention period for personal data, we take into account the quantity, nature and sensitivity of personal data, the potential risk of harm resulting from the unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and the possibility of attaining those purposes by other means, as well as the applicable legal, regulatory, tax, accounting or other requirements.

After the established deadlines, the data is either deleted or retained after being anonymized, especially for statistical purposes. It may be retained in case of pre-litigation and litigation. It should be noted that deletion or anonymization are irreversible operations, and that Nutricia is no longer able, thereafter, to restore this data.

Cookies and other technologies

We may also collect personal data about you through the use of cookies and other technologies. This may occur when you visit our sites or third-party sites, view our online content, or use our/third-party mobile applications and may include the following information:

a) Information about your device browser and operating system;

b) The IP address , device ID and Mac ID of the device you are using;

c) Web pages of ours that you view;

d) Adverts you view;

e) Links that you click while interactive with our services, and emails you open.

f) Time and date of activity

Please see our cookie policy for more information on this link.

Privacy considerations for local law

Although the General Data Protection Regulation (“GDPR”) applies in the same way to all EU Member States, sometimes local privacy laws may contain stricter rules or information that is relevant on a local level. We will hold and process your personal data in accordance with the Irish Data Protection Act 2018 and the EU GDPR.

Changes to this privacy policy

This notice was last updated on 16 September 2021.  We reserve the right to change this notice at any time (for example, to comply with changes in laws or regulations, our practices, procedures and organisational structures, requirements imposed or recommended by supervisory authorities or otherwise).  Changes to this notice shall be applicable on the effective date of implementation.  Please refer to our website for the latest version of this notice.  We will also communicate any changes to you, where we are legally required to do so.

How to contact us

If you have any questions, comments or complaints regarding this Privacy Policy or the processing of your personal data, please contact us via this link or write to us at:

Data Protection Officer, Nutricia Ireland Limited, Block 1, Deansgrange Business Park, Deansgrange, Co Dublin, A94 P9T3, Ireland

You can also contact our Data Protection Officer directly via email at: DPO.UKIE@danone.com.

x