Privacy Notice

Pursuant to art. 14 of the EU Reg. No. 679/2016 on the protection of personal data (“GDPR”)

Dear Madam/Sir,

The pharmaceutical company Dompé farmaceutici S.p.A. (also referred to as “Data Controller”) provides you with the following information about the purposes and methods with which it will collect and use Your Personal Data, or the adolescent You represent, in the context of the website You are visiting (“Website”) related to the clinical research study LDX0319 (“Study”) sponsored by Dompé farmaceutici S.p.A..

Identity and contact details of the Data Controller and the DPO In this section we indicate our references

Dompé farmaceutici S.p.A., with registered office in via San Martino 12, 20122, Milan, Italy, in the person of its pro-tempore legal representative

E-mail: privacy@dompe.com;

DPO: dpo@dompe.com

Purpose and legal basis of the processing In this section we explain to You why we collect Your data

Your Personal Data, or of the adolescent You represent, is processed by us:

  • Without Your consent (art. 6.1 (b), GDPR)

For browsing the Website, in relation to the possibility of detecting data necessary at a technical level while browsing the Website itself.

  • With Your consent (Articles 6.1 (a) and 9.2 (a) GDPR)

Before starting the enrollment in the Study, You will be asked to fulfill a questionnaire available on the Website in order to see if You may meet the preliminary criteria to participate in the Study.

After fulfillment of the questionnaire, if You meet the preliminary criteria for participation, You will be asked, with Your previous consent, to share Your contact details in case You allow being contacted by the clinical study center closest to You.

The provision of Your Personal Data is not mandatory, consequently You can revoke Your consent at any time, submitting Your request to the contact details indicated below in the section “Withdrawal of consent”.

Finally, we inform You that your personal data may be used for data analysis. In this case, we guarantee that Your Personal Data will be processed in aggregate form, consequently we are not able to identify You.

Categories of personal data In this section we indicate what data we collect

We will process the following Personal Data:

• navigation data: Internet Protocol Address (IP) or the domain names of the computer used by You that is connected to the Website, the type of web browser, the referring website, exit page, internet service provider, the addresses in URI (Uniform Resource Identifier) notation of the requested resources, the date and time of the request, the method used in submitting the request to the server, error logs in response to Your use of the website, if any, and other parameters relating to the operating system and IT environment.

• data voluntarily provided by You (i) by filling in the questionnaire, such as data relating to health: age range, gender, diabetes diagnosis relevant treatment and pregnancy status (related possibly also to the adolescent You represent) (ii) personal data (e.g. first name, last name) and contact data (e.g. e-mail address, telephone number, zip code, best time to reach You, best contact method) in order to allow the clinical study center closest to You to possibly contact you.

• cookies: regarding the navigation data processed by means of cookies, please refer to the cookie policy available below.

Methods of data processing
In this section we tell You how we use Your personal data

Your Personal Data will be collected by the Website during the browsing and fulfillment of questionnaire.

We process Your Personal Data through the use of supports and/or IT tools, manual and/or telematics, in compliance with adequate technical and organizational security measures.

Recipients or categories of recipients of the data
In this section we indicate who uses Your personal data

In relation to the purposes indicated above, Your Personal Data is also processed by the following entities:

a) police force, public authorities whenever this is required by a rule of law or by a provision of a competent authority.
b) Clinical study centers in case You consent to be contacted.

c) Companies of the Dompé Group, located, also outside the EU, to which the Data Controller belongs;

d) Professionals and/or companies appointed by the Data Controller to carry out support activities for the conduct of the research study; by way of example:

• contract research organizations (“Clinical Research Organization – CRO”) and its providers acting as sub-processors (among others Patient Recruiting Agency LLC (“TPRA”), the provider of the Website);

• IT service providers for the management of the technological infrastructure,
information systems and telecommunications networks.

The complete and updated list of data recipients (included data controllers, data processors as well as those authorized pursuant to GDPR) can be requested at the addresses indicated above.

Dissemination of data
In this section we indicate whether Your data is disclosed to indeterminate subjects

Your Personal Data is not disclosed to indeterminate subjects.

Data transfer abroad

Your Personal Data may be disclosed to third parties located in countries outside the European Union. We guarantee that this transfer will only take place in accordance with the principles expressly established by the GDPR in order to adequately protect the data.

In case You are an extra European citizen, Your Data will be transferred to European countries in accordance with the GDPR.

Data retention period
In this section we indicate how long we will keep Your data

Your Personal Data will be retained for the time necessary to achieve the purposes for which they are processed or to comply with legal obligations. In any case such data will be retained for a period no longer than one (1) year as of the date of its collection.

With specific reference to the data collected with cookies please see the summary table of cookies below.

At the end of the retention period, Your Personal Data will be deleted, destroyed, or anonymized, without prejudice to any additional retention periods required by law.

Rights of the interested parties
In this section, we indicate which rights You are entitled to in relation to Your data

At any time You may obtain confirmation of the existence or not of Your Personal Data with us and to know its content and origin; furthermore, You may ask for its integration, rectification, portability, limitation of use, cancellation, as well as to oppose its processing.

The full text of articles 15 to 22, GDPR can be consulted on the website of the Guarantor for the Protection of Personal Data (https://www.garanteprivacy.it/web/garante-privacy-en/rights).

You can exercise Your rights contacting us to the contact details indicated above.

Withdrawal of consent
We highlight Your right to withdraw Your consent at any time

You may revoke Your given consent at any time without the revocation affecting the legitimacy of the processing carried out previously. In this case, You can contact in the first instance TPRA by email addressed to privacy@tprausa.com.

Complaint to the Data Protection Authority
We highlight Your right to be able to contact the Data Protection Authority

You also have the right to lodge a complaint with Data Protection Authority if You believe that Your rights have not been respected or that You have not received any response to Your requests under the law.

COOKIE POLICY
Whenever you visit or interact with this website (“Site”), we, as well as any of our third-party service providers, may use a variety of technologies such as cookies, web beacons, pixel tags, log files, local shared objects (Flash cookies), HTML5 cookies, or other technologies to automatically or passively collect certain information about your online activity.

Please note that we may automatically collect the following information about you:

  • Computer or Device Information. We may automatically collect your Internet Protocol (“IP”) address, MAC Address, mobile carrier, or other unique identifier or information from the computer, mobile device, tablet, or other device that you use to access the Site, including but not limited to your browser type, device type, operating system, software version, phone model, phone operating system, and the domain name from which you accessed the Site.
  • Usage Information. We may collect information about your use of the Site, including the date and time you visit the Site, the areas or pages of the Site that you visit, the amount of time you spend viewing or using the Site, the number of times you return to the Site, other click-stream or site usage data, emails that you open, forward or click-through to our Site, and other sites that you may visit.
  • Location Information. We collect general information about where traffic on our site is coming from around the world. This is used at an aggregate level that does not identify individual users to create reports to better understand our engagement with visitors to the site. Location information at an individual level may be used for narrowly tailored efforts for our products or research activities.
  • Our Third-Party Service Providers. We, as well as third parties that provide content, advertising, or other functionality on the Services, may use cookies, pixel tags, local storage, and other technologies (“Technologies”) to automatically collect information through the Services. Technologies are essentially small data files placed on your computer, tablet, mobile phone, or other devices that allow us and our partners to record certain pieces of information whenever you visit or interact with our Services.

Use of Third Party Analytic Technologies. We may use third parties’ analytics and tracking tools, including Google Analytics, to better understand who is using the Site, how people are using the Site, and how to improve the effectiveness of the Site and related content. These tools may use technology such as cookies, web beacons, pixel tags, log files, Flash cookies, HTML5 cookies, or other technologies to automatically collect and store certain information. They may also combine information they collect from your interaction with the Site with information they collect from other sources.

You may review Google’s cookie policies here: https://policies.google.com/technologies/cookies?hl=en-US

You may review Facebook’s cookie policies here: https://www.facebook.com/policy/cookies/

The following categories are applicable for this website:

  • Necessary cookies: Necessary cookies are necessary for the site to work and cannot be disabled in our systems. They are usually set only in response to actions you take that constitute a request for services, such as setting privacy preferences. You can set your browser to block or have warnings about these cookies, but as a result some parts of the site will not work. These cookies do not store personal information.
  • Performance (Statistics) cookies: Performance (Statistics) cookies help count visits and traffic sources so that we can measure and improve the performance of the Site. They help to know which pages are the most and least popular and see how visitors move around the Site. These cookies are on by default but can be turned off at any time No information about the user’s identity or any personal data is collected with these cookies. The information is processed in aggregate and anonymous form. If the user does not allow these cookies, the use of the site will not be affected.
  • Marketing cookies: Marketing cookies are used to present the user with content, including advertising, that is more suitable for them. They can also be used, for example, to limit the number of times that advertising content is offered or to help us evaluate the effectiveness of our advertising or advertising campaigns on our websites. They are not necessary, but they enable us to offer users content closer to their interests.
  • Personalization (Preferences) cookies: Personalization (Preferences) cookies are used to enable specific features of the Site and a set of selected criteria (e.g. language) in order to improve the service rendered to the user. These cookies are active by default but can be deactivated at any time. If you disable functionality cookies, the Site may be unavailable or some services or certain features of the Site may be unavailable or may not function properly. You may also be forced to change or manually enter certain information or preferences each time you visit the Site;

SUMMARY TABLE OF COOKIES

CookieOwn/third partyRetentionPurposeCategory
CookieConsentcookiebot.com1 yearProvides cookie consent banner and controls users consentNecessary
test_cookieGoogle1 dayUsed to see of browser supports cookiesNecessary
elementorWord Press (html)persistent on the websiteFacilitates website changesNecessary
_ga and gc_#Google Analytics2 yearsProvides Google Analytics informationStatistics
_fbpFacebook (Meta) and Instagram3 monthsProvides ad performance informationMarketing
_gads, etc.Google Adsup to 1 yearProvides ad performance informationMarketing

You can accept or reject cookies by changing your browser security settings. You will find instructions on how to set up the most common browsers below:

Chrome: https://support.google.com/chrome/answer/95647?hl=it

Firefox: https://support.mozilla.org/it/kb/Gestione%20dei%20cookieInternet

Explorer: http://windows.microsoft.com/it-it/windows7/how-to-manage-cookies-in-internet-explorer-9

Safari: http://support.apple.com/kb/HT1677?viewlocale=it_IT

Opera: http://help.opera.com/Windows/10.00/it/cookies.html

You can also control the cookies on this website using the cookie consent feature that drops down when you first come to the Website. Thereafter, you may review your consent choices, withdraw, or change your consent, and obtain your consent date and consent ID by clicking the following icon that appears on each page of the website: