Privacy & Data Protection
ProductLife Group is committed to protecting your personal data. This page gives you a short overview of who we are, why we process personal data, what we would particularly like you to be aware of, and what rights you have. Full details are set out in the notices linked at the bottom of this page.
Who we are
The data controller is Groupe ProductLife , a simplified joint stock company registered with the Company Registry of Nanterre under number 392 639 266, whose head office is located at 8-14 avenue de l'Arche, 92400 Courbevoie, France, or any one of its affiliates, whose contact details are available here (together, "ProductLife Group", "PLG", "we", "us"). For health vigilance and medical information activities, ProductLife Group acts as a data processor and processes personal data on behalf of its clients, who act as data controllers: the controller is the client on whose instructions we handle the case, typically the holder of the marketing authorisation for the product concerned.
You can contact our Data Protection Officer at any time:
Data Protection Officer – ProductLife Group
8*14 avenue de l'Arche, 92400 Courbevoie, France
Why we process your personal data
We process personal data for the following purposes, depending on your relationship with us:
-
If you visit our websites — to operate and secure our websites and to deliver their content and services correctly and, where you have given your consent, for comfort, analytics and marketing purposes. → [Cookie Policy]
- If you register for one of our webinars or events — to manage your registration, to give you access to the session and to send you the related practical information and follow-up materials.
- If you are a client, prospect or supplier (or work for one) — to identify potential commercial relationships, to manage our client, prospect and supplier contacts, to manage our commercial relationship with you, to manage contacts in the context of our services (including pharmacovigilance and medical information where applicable), and to issue and process invoices and, subject to opt-in/opt-out, to send you commercial communications, advertising or direct sales material and to carry out market research. → [Privacy Notice – Clients, Prospects and Suppliers]
- If you have been exposed to or have reported an adverse health event, or have asked us for medical information — on the instructions of our clients, who are the controllers, to manage health vigilance (collecting, recording, analysing, documenting, transmitting and storing information on adverse events and reporting them to the competent authorities) and to handle requests for medical information about the products concerned. → [Privacy Notice – Patients and Notifiers]
- If you are an executive, director, manager or key person at a client, prospect or other market participant — to monitor publicly reported business events (appointments, departures, mergers, acquisitions, reorganisations) in order to understand the economic and strategic context of the organisations we work with or seek to work with. → [Privacy Notice – Commercial Intelligence]
- If you apply for a position with us — to assess, select and recruit candidates, to consider your profile for other opportunities more closely aligned with your experience, to defend our rights in the event of a dispute and, where you have asked for it, to send you job alerts. → [Applicant Privacy Notice]
What we would particularly like to bring to your attention
- We may hold data about you that we did not obtain from you. Depending on the situation, we may receive your personal data from the organisation you work for, from a person who has reported an adverse health event, from a third party who introduced you to us, or from publicly available sources. The notice that applies to you explains, in each case, the categories of data concerned, where they come from and how you can object.
- Some of our activities involve special categories of data. In health vigilance and medical information, we process health data relating to the adverse event and, where necessary to assess it, other special categories of data. If you apply to us, we may process healthrelated data (membership of protected categories) and, where applicable law so permits with appropriate safeguards, criminalrecord data.
- Your data may be transferred outside the European Economic Area. PLG is a multinational organisation with subsidiaries, partners and processors in many countries, including countries that may not offer a level of protection equivalent to that of the country in which you reside. Where this occurs, we implement appropriate safeguards.
Your rights
You have the right to access your personal data and obtain a copy of it; to have inaccurate or incomplete data rectified ; to request erasure ; to request restriction of processing; to object to processing, including at any time where we rely on our legitimate interests; to receive your data in a machinereadable format ( portability ); and, where processing is based on your consent, to withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal. Please note that we are subject to legal retention obligations and may not always be able to grant a request for erasure.
To exercise your rights, or for any question about how we process your personal data, write to dpo@productlife-group.com , describing your request and indicating the context in which we hold your data so that we can identify it. We will respond within one month. Where we act as a data processor on behalf of a client — in particular in health vigilance and medical information — we will pass your request on to that client, who is the controller; you may also liaise with the controller directly, at the address shown in their privacy policy.
If you are not satisfied, you have the right to lodge a complaint with the competent supervisory authority — in your country of habitual residence, your place of work or the place of the alleged infringement — and to seek a judicial remedy. In France, the competent authority is the CNIL . A list of all EU supervisory authorities is available here .
Full information
The complete information required by Articles 13 and 14 GDPR — including the legal bases, the categories of data, the recipients, the retention periods, the transfers and the sources of the data — is set out in the following notices:
- Cookie Policy
- Privacy Notice – Clients, Prospects and Suppliers
- Privacy Notice – Commercial Intelligence
- Applicant Privacy Notice
- Privacy Notice – Patients and Notifiers