1. Subject of this data protection notice
We are pleased about your interest in our Internet presence and our offers on our websites under ds-pace.com (our “Website”). The protection of your Personal Data (as described below) is of great and very important concern to us. In the following we would therefore like to inform you in detail about which Personal Data is collected during your visit to our Website and the use of our offers there and how this Personal Data is processed by us. Furthermore, we would like to inform you about the rights you are entitled to and the technical and organisational protective measures we have taken with regard to the processing of your Personal Data.
“Personal Data” refers to any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
2. Name and address of the data controller and service provider
The controller in relation to the processing of your Personal Data in the scope of this Website Data Protection Notice is Daiichi Sankyo Europe GmbH (hereinafter also referred to briefly as “Daiichi Sankyo” or “we”), Zielstattstrasse 48, 81379 Munich.
If you have any questions or comments about this data protection notice or data protection in general, please send them to the following e-mail address: Data-Protection@daiichi-sankyo.eu
You can contact Daiichi Sankyo’s data protection officer as follows:
Daiichi Sankyo Europe GmbH
Attn: Data Protection Officer
Zielstattstrasse 48, 81379 Munich, Germany
dpo@daiichi-sankyo.eu
3. Collection and use of your data
The extent, type and use of your Personal Data will differ depending on whether you visit our website only to access information, or use services offered by us or log into a protected area for employees of Daiichi Sankyo:
a. Informational use
For the informational use of our Website we only collect and use those of your data that your Internet browser automatically transmits to us. These are in particular the following:
- date and time of access to one of our Internet pages
- your browser type
- the last page you visited on our Website
- the transferred data volume and the access status (file transferred, file not found, etc.) as well as
- your IP address.
The data is stored in log files on the server generally up to 14 days for security purposes unless, in individual cases, a longer storage period is necessary, e.g., for investigating security incidents. Except for the IP address, we only process this data in non-personal form during an informational visit. This is done in order to enable you to access and use the Website and for us to be able to check whether our websites are optimally displayed to you. The processing is carried out on the legal basis of Art. 6(1)(f) GDPR and in our interest in order to be able to display our Website to you reliably and as trouble-free as possible. The data arising during the informational use including your IP address are stored in order to ensure the operation of the website and to be able to react to problems. A personal evaluation of the data does not take place. Only statistical evaluations of the use of the Website are made, as described further below in this Notice.
b. Use of the “Get in touch” form
If you would like to contact us via our “Get in touch” form, we collect the following data from you:
- first name, surname
- e-mail address *
- question/ concern (“say hi!”) *
- captcha *
* Mandatory information
We use this data to be able to answer your inquiry by email. In addition, we can use your details to personalise our response and provide you with specific information.
We process the captcha request to verify that it is a real request and not a “login robot” or automated spam requests. Your entry there will only be used for this check and will not be stored.
If your inquiry relates to an existing contractual relationship with you or if you are interested in concluding a contract, e.g. with regard to a consultant activity, the data processing is carried out on the legal basis of Art. 6(1)(b) GDPR (contract fulfilment and initiation).
Otherwise, the Personal Data will be processed on the legal basis of Art. 6(1)(f) GDPR (legitimate interests). It is in our interest to be able to answer your inquiry with the information relevant to you by our internal department. The data processing of the captcha query is in our interest in order to prevent automated logins via logon robots or spam requests. We store the Personal Data collected via the “Get in touch” form for processing and answering the respective inquiry.
c. Use of the “Why do you want to partner with us” form
If you would like to contact us via our “Why do you want to partner with us” form, we collect the following data from you:
- location *
- focus area *
- website *
- reason why you want to partner with Daiichi Sankyo *
- Email *
- captcha *
* Mandatory Information
We use this data to be able to answer your inquiry by email. In addition, we can use your details to personalise our response and provide you with specific information.
We process the captcha request to verify that it is a real request and not a “login robot” or automated spam requests. Your entry there will only be used for this check and will not be stored.
If your inquiry relates to an existing contractual relationship with you or if you are interested in concluding a contract, e.g. with regard to a consultant activity, the data processing is carried out on the legal basis of Art. 6(1)(b) GDPR (contract fulfilment and initiation).
Otherwise, the Personal Data will be processed on the legal basis of Art. 6(1)(f) GDPR (legitimate interests). It is in our interest to be able to answer your inquiry with the information relevant to you by our internal department. The data processing of the captcha query is in our interest in order to prevent automated logins via logon robots or spam requests. We store the Personal Data collected via the “Why do you want to partner with us” form for processing and answering the respective inquiry.
d. Login to the non-public area
We also offer our employees the opportunity to log in to the non-public area. This is reserved for employees of Daiichi Sankyo.
The processing of your data on our Website for logging into the non-public sector is based on the legal basis of our legitimate interests to protect information for internal use(Art. 6(1)(f) GDPR) and to verify that only employees have access to such information.
e. Data processing of reports of adverse reactions
As a pharmaceutical company Daiichi Sankyo and its affiliated companies must adhere to local statutory obligations to monitor the safety of all their pharmaceutical products on the market. The monitoring and assessment of potential adverse reactions in relation to the use of our products is called pharmacovigilance. In this context we may collect and further process Personal Data of the individuals who suffered the suspected adverse reaction (“Patients”) as well as the treating physician of the Patient or any other HCPs, or third parties, e.g., a family members of the Patient, who report the adverse reaction event to us (altogether referred to as “Reporting Persons”).
If you, as a Reporting Person, report adverse reactions directly to Daiichi Sanko Europe GmbH – which is possible, e.g., via phone or email, please see for details here – we will collect and further process Personal Data about the Patient and the Reporting Person, in particular, the following data categories:
- Patient: initials of the first and last name of the patient, date of birth, gender, height, weight, information on the suspected medication (including information on the brand name of the drug, daily dose, dose form, the duration of the therapy, interacting drugs), the course of the adverse reaction (including the duration, the severeness and the outcome of the adverse reaction), concomitant medication, relevant concomitant diseases and medical history (including information on previous and current pregnancies);
- Reporting Person: profession, name, address and contact information (including telephone / fax number and email address).
If you, as a Reporting Person, report adverse reactions, e.g. by email or phone, to one of our national subsidiaries in Europe – you can find a full list of our subsidiaries here – (“Daiichi Sankyo Subsidiaries”), the above data of the Patient and the Reporting Person will be collected and further processed by the respective Daiichi Sankyo Subsidiary to which you report to and which will act as separate and individual controller. Please refer to the respective data protection notice of the relevant Daiichi Sankyo Subsidiary to obtain further information on how they collect and process your Personal Data in this regard. The Daiichi Sankyo Subsidiary will submit a report about adverse reaction in pseudonymised form to us. This means that we do not receive any Personal Data, such as names or contact details, that could be used to directly identify the Patient or the Reporting Person without the use of additional information. The additional information which would allow us such re-identification is stored securely by the Daiichi Sankyo Subsidiary without us having access to it.
The pharmacovigilance department at Daiichi Sankyo Europe GmbH will medically assess and evaluate the information on the potential adverse events obtained to identify the necessary next steps to ensure compliance with applicable pharmacovigilance rules and company procedures, e.g., where necessary, notifying the adverse event to the competent drug safety authorities and relevant institutions.
In both cases, i.e. where you report the adverse reaction directly to us (Daiichi Sankyo Europe GmbH) or to a Daiichi Sankyo Subsidiary which submits the report to us (as described above), we will forward and store the report with the adverse reaction in pseudonymised form for internal documentation purposes in our global Daiichi Sankyo Safety Database which is operated by Daiichi Sankyo Co. Ltd. (“DSJ”) and hosted on servers in the USA. As a rule, the pseudonymised reports will be stored in the Daiichi Sankyo Safety Database for a period of at least 10 years after the expiration of the marketing authorisation for the product to which the adverse reaction report relates.
Daiichi Sankyo Europe GmbH, the Daiichi Sankyo Subsidiaries and DSJ process the Reporting Person’s and Patient’s Personal Data exclusively for processing to the extent necessary to fulfil their legal obligations, for reasons of public interests in the area of public health, in particular to ensure high standards of quality and safety in healthcare and medicinal products, and to safeguard their legitimate interests (ensuring compliance with legal pharmacovigilance requirements and asserting, exercising and defending our legal claims) according to Art. 6(1)(c) and (f), and Art. 9(2)(i) GDPR. This includes the processing of data for the internal documentation, review and support of the adverse reaction case, including the review of any claims.
f. Data processing in case of medical enquiries
If you contact a Daiichi Sankyo Subsidiary to enquire about product information in the medical field, Daiichi Sankyo receives and stores the Personal Data which you provided at the time of contact. To ensure we are dealing with an HCP, this data includes your name, professional details and contact data as well as the date and time of this contact. The purpose of this processing of Personal Data is to be able to respond to your medical enquiry.
You will find the name and contact data for Daiichi Sankyo Subsidiaries as well as contact data for their respective Data Protection Officers in the respective data protection notice of the contacted Daiichi Sankyo Subsidiary. You can find a full list of Daiichi Sankyo Subsidiaries here.
The legal basis for such data processing is Art. 6(1)(f) GDPR. The Personal Data is deleted when the specific enquiry is no longer relevant from any conceivable perspective. In general, this will occur 10 years after the expiration of the marketing authorisation for the medicine to which the enquiry relates or earlier, should you request deletion.
g. Website analytics (etracker)
We use the services of etracker GmbH from Hamburg, Germany on this website (https://www.etracker.com) to analyse usage data, including the data categories listed in Section 3(a) in this Notice, in order improve and optimise our Website and services. For this analysis, we only use data that your browser transmits automatically when you visit our Website or that is generated directly through interaction with our Website. However, we do not use cookies and/or similar technologies in order to obtain further data for the web analysis. The data generated with etracker is processed and stored by etracker on behalf of Daiichi Sankyo exclusively in Germany and is therefore subject to the strict German and European data protection laws and standards. etracker has been independently audited, certified and awarded the data protection seal of approval in this respect. The processing of your data is carried out on the basis of our legitimate interests in improving and optimising our Website and services (Art. 6(1)(f) GDPR). Since the privacy of our visitors is important to us, the data that may allow a reference to an individual person, such as the IP address, login or device identifiers, are anonymised or pseudonymised as soon as possible. No other use, merging with other data or disclosure to third parties takes place. You can object to the data processing described above at any time by clicking on the slider. The objection has no negative consequences. If no slider is displayed, data collection has already been prevented by other blocking measures.
4. Use of cookies
We use cookies on our Website. Cookies are small text files that are sent from our web server to your browser during your visit to our Website and are stored on your computer, tablet computer or smartphone for later retrieval. Cookies may act as a memory for a website and allow that website to remember your device on your return visits. Cookies can also be used to remember your preferences, improve the user experience and tailor the content or advertisements to your personal preferences.
a. Which cookies do we use?
Some of the cookies we use on our Website are strictly necessary, i.e., they are essential for the correct functioning of the website and enabling of basic features thereof. They are required to give you access to our Website and features, such as site navigation, authentication and secure login and remembering your cookie preferences. Since the Website will not function without them, you do not have the option to opt-out of strictly necessary cookies.
Other cookies may not be strictly necessary but help us to analyse how you use and interact with our Website (including page views, searches, number of visits), so we can improve the functionality and experience on our websites (functional cookies) or optimise content according to the interests and preferences of the Website users (analytics/marketing cookies). We will only place functional and analytics/marketing cookies, and process your related Personal Data, if you provide your prior consent.
Some of the cookies used on our Website are set by us (first party cookies), while others are set by third parties (third party cookies).
In the following you can find an overview of cookies that we use on our websites:
Name of cookie | Service provider | Type of cookie | Purpose and function of cookie | Lifespan of cookie |
__cf_bm | CloudFlare | Third party cookie | Used to read and filter requests from bots | 30 minutes |
cookie_banner | ds-pace.com | First party cookie | Tracks if a user on that browser has already accepted our cookie policy | 6 months |
wordpress_[hash] | ds-pace.com | First party cookie | Authentication details storage | During the Session |
wordpress_logged_in_[hash] | ds-pace.com | First party cookie | Authentication details storage for logged-in users | During the Session |
wordpress_test_cookie | ds-pace.com | First party cookie | Check if cookies are enabled | During the Session |
wp-settings-[UID] | ds-pace.com | First party cookie | Customize admin interface and main site interface | 6 months |
wp-settings-time-[UID] | ds-pace.com | First party cookie | Customize admin interface and main site interface | 6 months |
wordpress_sec_[hash] | ds-pace.com | First party cookie | Store authentication details on a secured connection | During the Session |
__cf_bm | Vimeo.com | Third party cookie | Support security features | 1 day |
_cfuvid | Vimeo.com | Third party cookie | Unique session identification | During the Session |
wp-settings-2 | ds-pace.com | First party cookie | Used to preserve user’s wp-admin settings | 1 year |
wp-settings-time-2 | ds-pace.com | First party cookie | Time at which wp-settings-{user} was set | 1 year |
et_allow_cookies | ds-pace.com | First party cookie | When using data-block-cookies, this cookie is set to “1” by the API call _etracker.enableCookies() to indicate that etracker is allowed to set cookies. The cookie will be deleted when _etracker.disableCookies() is called. | 480 days |
et_oi_v2 | ds-pace.com | First party cookie | Opt-In Cookie stores the visitor’s decision when the tracking opt-in is played on the customer’s page. Also used for an eventual opt-out. | “no” – 50 years”yes” – 480 days |
et_scroll_depth | ds-pace.com | First party cookie | Data for the scroll depth measurement | During the Session |
isSdEnabled | ds-pace.com | First party cookie | Detection of whether the scroll depth is measured for the visitor. | 24 hours |
et_cssSelectors | ds-pace.com | First party cookie | Cache for the configured CSS Selector events. Only active for set events. | During the session |
et_cssSelectorsLoaded | ds-pace.com | First party cookie | State for the cache of configured CSS Selector events. | During the session |
_et_coid | ds-pace.com | First party cookie | Cookie recognition | 720 days or configurable |
BT_sdc | ds-pace.com | First party cookie | Contains Base64-encoded data of the current visitor session (referrer, number of pages, number of seconds since the start of the session, smart messages displayed in the session), which is used for personalization purposes. | During the session |
BT_pdc | ds-pace.com | First party cookie | Contains Base64 encoded visitor history data (is customer, newsletter recipient, visitor ID, smart messages displayed) for personalization. | 1 year |
BT_ecl | ds-pace.com | First party cookie | Contains a list of project IDs for which the visitor is excluded. This cookie is set by the web service if the client has configured that not all visitors are assigned to a test, but only to a certain fraction. | 30 days |
b. Managing your cookie preferences
You can manage your cookie preferences and withdraw your consent at any time via the privacy preferences tool which you can also access at any time by clicking on the “change cookie preferences” link at the footer of our Websites.
Whether cookies can be set and retrieved can also be determined by the settings in your browser. For example, you can completely deactivate the storage of cookies in your browser, limit it to certain websites or configure your browser so that it automatically informs you as soon as a cookie is to be set and asks you for feedback. You can block or delete individual cookies. For technical reasons, however, this can lead to some functions of our internet presence being impaired and no longer functioning completely.
5. Involvement of service providers and transfer of data to third parties
Your data will be passed on to service providers supporting us (e.g. website hosting and support) for the provision of this Website and for the aforementioned purposes, including support services in order to optimise pharmacovigilance case processing, which we have of course carefully selected and commissioned in writing.
These service providers are bound by our instructions and are regularly checked by us.
We may also disclose information about you, where we are obliged to do so by law, regulation or legal process (such as a court order or subpoena), in response to requests by government agencies, such as law enforcement authorities, or when we believe disclosure is necessary to prevent physical harm or financial loss as well as in connection with an investigation of suspected or actual fraudulent or illegal activity.
7. International transfers of Personal Data
Some of the service providers we share your Personal Data with are located outside the European Economic Area including the USA. Further, as described above under section 3.d., we share certain Personal Data in the context of pharmacovigilance with DSJ which is located in Japan and hosting the data in the Daiichi Sankyo Safety Database in the USA. For data transfers to Japan we rely on the adequacy decision for Japan enacted by the European Commission (Art. 45 GDPR). With regard to the data transfers to recipients in the USA and further third countries which do not benefit from an adequacy decision we have implemented appropriate safeguards in the form of the execution of EU Standard Contractual Clauses, and where necessary, supplementary measures, with each recipient to ensure an adequate level of data protection as required by applicable EU data protection laws. For more information on the appropriate safeguards in place and to collect a copy of such safeguards, please contact us at the contact information set forth above.
8. Referral to external websites and services
We have integrated various third-party services into our websites. In these cases you technically leave our Websites and enter the websites of the respective third party provider. In such cases, the respective third party provider is responsible for the processing of any Personal Data. If you have any questions relating to the data processing carried out by the third-party service provider, please contact the third party service provider directly via the contact data provided on their websites.
This also applies, where we refer you by link to the websites of third parties. We use such links, for example, on various social networks, however, we do not use so-called social media plug-ins for data protection reasons.
For both of the above cases we will inform you about the circumstance that a certain area of our website is offered by a third party or that you will be forwarded to a third party.
9. Retention of your Personal Data
We retain your Personal Data for as long as needed for the purpose the data was collected and further processed pursuant to this Notice.
Any Personal Data which you disclose to us in the context of an enquiry, a request for information or any other communication will generally be retained only for as long as it is necessary for the complete processing and handling of your request or enquiry, except in case as longer storage is necessary to achieve the further purposes described in this Notice.
The Personal Data collected for informational use of the website will be stored in log files on the server generally up to 14 days for security purposes unless, in individual cases, a longer storage period is necessary, e.g., for investigating security incidents.
Personal Data from reports of adverse reactions will be retained for at least 10 years after the expiration of the marketing authorisation for the medicine to which the adverse reaction report relates.
Your Personal Data will then be deleted, except where any further storage is necessary to comply with our legal obligations, in particular any applicable data retention obligations, or for the establishment, exercise or defense of our legal claims (e.g., the need to retain records in order to resolve disputes, and investigate or defend against potential claims).
For more information about the specific retention periods that apply to your Personal Data, please contact us using the contact details set out above.
10. Your rights
According and subject to applicable data protection laws you have the following rights regarding the processing of your Personal Data:
- You have the right to request confirmation from us whether Personal Data relating to you is processed; if this is the case, you have a right of access to this Personal Data and the information specified in Art. 15 GDPR.
- You have the right to request us to rectify any incorrect Personal Data concerning you and, if necessary, to complete incomplete Personal Data without delay (Art. 16 GDPR).
- You have the right to request us to delete Personal Data relating to you immediately if one of the reasons listed in Art. 17 GDPR applies, e.g. if the data is no longer required for the purposes pursued (right of deletion).
- You have the right to request us to restrict processing if one of the conditions listed in Art. 18 GDPR is met, e.g. if you have filed an objection to the processing, for the duration of our examination.
- You have the right to receive from us the data concerning you that you have provided to us in a structured, common and machine-readable format. You can also transfer this data to other locations or have it transferred by us (right to data portability according to Art. 20 GDPR).
- You have the right to object at any time for reasons arising from your particular situation to the processing of Personal Data concerning you, which is carried out on the basis of Art. 6(1)(e) or (f) GDPR. We will then no longer process the personal data unless we can prove compelling reasons worthy of protection for the processing that outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims (Art. 21 GDPR). Where Personal Data is processed for direct marketing purposes based on our legitimate interests, you have the right to object at any time to processing for such marketing. We will then no longer process your data for such purposes.
Where the processing of your Personal Data is based on your consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal (right to withdraw consent). You can do this at any time via the Cookie preferences tool (with regard to the collection and further processing of your data by means of cookies), or by contacting us at the below contact information.
For exercising any of your above rights, please contact us at: Data-Protection@daiichi-sankyo.eu
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a competent supervisory authority, e.g., if you believe that the processing of your Personal Data is contrary to the GDPR (Art. 77 GDPR). You can contact for this purpose, in particular, the data protection supervisory authority of Bavaria (Bayerisches Landesamt für Datenschutzaufsicht), P.O. Box 606, 91511 Ansbach, www.lda.bayern.de.
11. Data security
We also use technical and organisational security measures to protect personal data that is collected, in particular against accidental or intentional manipulation, loss, destruction or against the attack of unauthorised persons. Our security measures are continuously improved in line with technological developments.
When using our website, your personal data is encrypted using SSL/TLS technology to prevent access by unauthorised third parties.