HCP Privacy Notice
Last updated: October 23, 2024
IO Biotech Aps and its affiliates (together, “IO Biotech”, “we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Notice for Healthcare Professionals (“HCPs”, “you”, or “your”) (“Privacy Notice”) describes our practices regarding the collection, use, and disclosure of your Personal Information (as defined below) when you visit our website (iobiotech.com) (the “Website”), and interact with us offline. This Privacy Notice also describes your privacy rights in connection with Personal Information we collect and process about you.
This Privacy Notice will not apply to Personal Information collected and processed by us:
- in the context of a clinical trial that we are sponsoring;
- if you are an individual other than an HCP;
- should you apply for a job with us; or
- in the course of your employment with us.
For purposes of this Privacy Notice, “Personal Information” means information that identifies you or from which you can be identified.
Personal Information We Collect
We collect the following categories of Personal Information:
- Personal identifiers: name, residential and business address, home and business telephone number(s), email address(es), and National Provider Identifier (NPI), IP address;
- Commercial and financial information: payment information, account information, and details of any financial relationship with us, inquires or requests for assistance regarding our products or services;
- Professional or employment-related information: name of your practice, academic background, professional designation, medical specialty, licensing and disbarment status, publications and information about public speeches, and additional Personal Information you provide in your curriculum vitae or other similar documents or communications;
- Education information: academic background and credentials;
- Internet or electronic network information: your browser type, operating system, domain names visited, click activity, referring websites, the date and time and length of visit of your visit to our Website or other websites or mobile applications;
- Audio and visual information: audio and visual recordings of presentations given by you; and
- Inferences drawn from any above data to create a profile reflecting your interests as they relate to the types of products and educational offerings provided by us.
Retention Periods
We retain the categories of Personal Information we collect for as long as we need for a legitimate business purpose. The criteria used to determine the retention periods include: (i) how long the Personal Information is needed to provide / receive the services and operate the business; (ii) the type of Personal Information collected; and (iii) whether we are subject to a legal, contractual or similar obligation to retain the Personal Information (e.g., mandatory data retention laws, government orders to preserve data relevant to an investigation or data that must be retained for the purposes of litigation or disputes).
Sources From Which We Collect Personal Information
We collect Personal Information from you when you: (i) attend or register to attend an event sponsored by us; (ii) participate in one of our advisory boards or speak at an event on our behalf; (iii) request information from us about our products or services; (iv) apply for a grant, donation or sponsorship; (v) respond to one of our surveys; or (vi) otherwise interact with us including, via the Website. We may also collect your Personal Information from patients, other HCPs or medical professionals, dispensing entities, from data brokers specializing in HCP data, and from publicly available sources.
Cookies and Other Technologies
We collect some of the Personal Information above through “cookies” and other similar technologies. Cookies are small, sometimes encrypted text files that are stored on computer hard drives by websites that you visit. They are used to help users navigate websites efficiently as well as to provide information to the owner of the website. For detailed information on the cookies we use and the purposes for which we use them, please see our Cookie Policy.
How we Use Personal Information we Collect
We have set out below, a description of the ways we use your Personal Information (referred to as “processing purposes”), and which of the legal bases we rely on.
Categories of Personal Information | Processing Purposes | Legal Basis |
Where you register to attend and/or attend a sponsored event: | ||
Personal identifiers; Audio and visual information | The administration and conduct of the relevant event, including to respond to your enquiries and communicate with you about the event. | Where we have a legitimate interest to ensure the effective administration and conduct of the relevant event. |
Personal identifiers; Audio and visual information | Enabling the creation, distribution, broadcast or other use of any recordings made during the event | Where we have a legitimate interest to promote the event, to leverage the learnings from the event, and to more generally operate and improve our business |
Personal identifiers | To invite you to future events and to send you other promotional information about our products (where permitted by law).
If you wish to stop receiving marketing or market research communications from us you can contact us using the contact details below. |
If applicable law requires that we receive your consent before we send you certain types of marketing communications, we will only send you those types of communications after receiving your consent.
In other instances, we will send marketing communications to you where this is in our legitimate interest. |
Personal identifiers | The storage of your Personal Information in databases for use when sending invites to future events. | Where we have a legitimate interest to manage our business and the conduct of future events. |
All categories of Personal Information | Compliance with and satisfaction of legal obligations and regulatory requirements for purposes of financial reporting / public disclosure obligations in relation to agreements with and/or payments and benefits to HCPs and healthcare organizations. | To comply with a legal obligation.
Where we have a legitimate interest to comply with applicable transparency reporting obligations (including, those in the United States). |
Where you participate in an advisory board: | ||
Personal identifiers; Professional or employment information; Education information; Audio and visual information | The administration and conduct of the relevant advisory board, including to respond to your enquiries and communicate with you about the advisory board. | Where we have a legitimate interest to ensure the effective administration and conduct of the advisory board. |
Personal identifiers; Audio and visual information | Enabling the creation, distribution, broadcast or other use of any recordings made during the advisory board | Where we have a legitimate interest to leverage the learnings from the advisory board, and to more generally operate and improve our business |
Personal identifiers; Professional or employment information; Education information | The storage of your Personal Information in databases for use when selecting HCPs for future advisory boards. | Where we have a legitimate interest to manage our business and the conduct of future advisory boards. |
All categories of Personal Information | Compliance with and satisfaction of legal obligations and regulatory requirements in the context of safety data reporting activities, and for purposes of financial reporting / public disclosure obligations in relation to agreements with and/or payments and benefits to HCPs and healthcare organizations. | To comply with a legal obligation.
Where we have a legitimate interest to comply with applicable transparency reporting obligations (including, those in the United States). |
Where you are engaged to speak on our behalf: | ||
Personal identifiers; Professional or employment information; Education information; Audio and visual information | The administration and conduct of the relevant event, including to respond to your enquiries and communicate with you about the event. | Where we have a legitimate interest to ensure the effective administration and conduct of the relevant event. |
Personal identifiers; Audio and visual information | Enabling the creation, distribution, broadcast or other use of any recordings made during the event | Where we have a legitimate interest to promote the event, to leverage the learnings from the event, and to more generally operate and improve our business |
Personal identifiers; Commercial and financial information; Professional or employment information; Education information | Meeting our contractual obligations under the speaker agreement with you including, to pay you for your speaking services. | Where necessary for performance of a contract. |
Personal identifiers; Professional or employment information; Education information | The storage of your Personal Information in databases for use when selecting speakers for future events. | Where we have a legitimate interest to manage our business and the conduct of future events. |
All categories of Personal Information | Compliance with and satisfaction of legal obligations and regulatory requirements for purposes of financial reporting / public disclosure obligations in relation to agreements with and/or payments and benefits to HCPs and healthcare organizations. | To comply with a legal obligation.
Where we have a legitimate interest to comply with applicable transparency reporting obligations (including, those in the United States). |
When you contact us or we communicate with you: | ||
Personal identifiers; Audio and visual information | To respond to your enquiries and communicate with you including, where these relate to, for example, requests for funding, grants, early access programs. | Where we have a legitimate interest to manage our business, and to process and respond to your communications. |
You have a right to object to the processing of your Personal Information where that processing is carried out for our legitimate interests (including for any direct marketing or profiling purposes). Please note however, that we may not be able to fulfill such requests in all instances.
Disclosure of Personal Information
We disclose Personal Information to the following third parties for the purposes identified above:
- service providers that manage customer information and provide patient support services, facilitate email communications, provide security services and cloud-based data storage, host our Website and assist with other IT-related functions, advertise and market our products and services, provide analytics information, and provide legal and accounting services;
- third parties we consult and engage as part of our clinical research and compliance activities, such as research partners, ethics committees, and professional advisors, and clinical research monitors and research organizations;
- third parties as required or permitted by law to comply with a subpoena or similar legal process or government request, or when we believe in good faith that disclosure is legally required or otherwise necessary to protect our rights and property or the rights, property or safety of others, including to law enforcement agencies, and judicial and regulatory authorities;
- third parties to help detect and protect against fraud or data security vulnerabilities; and
- third parties in the event of an actual or contemplated sale, merger, reorganization of our entity or other restructuring.
Security
We take reasonable steps, consistent with generally accepted industry standards, including technical, administrative and physical safeguards to protect Personal Information we process from loss, misuse and unauthorized access, disclosure, alteration and destruction. However, no system is fully secure and we cannot guarantee the security of your Personal Information.
International Transfers of Personal Information
Where we disclose Personal Information originating in the EEA/UK to a third party located outside of the EEA/UK we will as deemed necessary, enter into a data transfer agreement (e.g., standard contractual clauses) with that third party, seek to rely on the third party’s Binding Corporate Rules or otherwise make the transfer in reliance on a derogation under EEA/UK data protection laws (e.g., where the transfer is necessary for the defence of legal claims). If you would like further information in relation to, or a copy of, the relevant safeguards, you can contact us using the details set out below.
Third Party Links
Our Website may contain social media buttons or links to third-party websites, which may have privacy policies that differ from our own. We are not responsible for the activities and practices that take place on those social media platforms or third-party websites.
Your Data Privacy Rights
You have the following data privacy rights which may be subject to limitations / restrictions:
- The right to request access to your Personal Information;
- The right to request that your Personal Information be corrected or deleted;
- The right to request that we restrict our processing of your Personal Information;
- The right to object to the processing of your Personal Information where it is carried out (i) for our legitimate interests – unless we can demonstrate compelling legitimate grounds for the processing, and/or (ii) for direct marketing purposes;
- The right to withdraw consent to the processing of your Personal Information; and
- The right to request that Personal Information be provided to you or a third party in a machine-readable format.
Please contact us using the details set out below in case you wish to exercise any of the above rights.
You also have the right to file a complaint with the competent data protection authority if you believe we did not properly handle your Personal Information or did not respect your rights.
Changes to this Privacy Notice
We may change this Privacy Notice from time to time. You will be informed about any material changes through a notice on our Website.
Contact Us
Please do not hesitate to contact us if you have any questions in regard to the protection of your Personal Information or if you wish to exercise your data protection rights (as described above).
IO Biotech ApS, Ole Maaløes Vej 3, DK-2200 Copenhagen N, Denmark
Data Protection Officer: privacy@iobiotech.com