Privatlivserklæring
Privatlivserklæring – Danmark
Senest opdateret: 01 september 2026
1. Hvem er dataansvarlig, og hvad omfatter erklæringen?
Dette websted, https://www.grunenthalhealth.dk/ ("webstedet"), udbydes af Grünenthal GmbH, Zieglerstraße 6, 52078 Aachen, Tyskland ("Grünenthal", "vi", "os" eller "vores"). Medmindre andet oplyses på det tidspunkt, hvor oplysningerne indsamles, er Grünenthal GmbH dataansvarlig for den behandling af personoplysninger, der beskrives i denne erklæring.
Grünenthal Denmark ApS, Arne Jacobsens Allé 7, 2300 København S, Danmark, er vores lokale kontakt i Danmark. Hvis Grünenthal Denmark ApS er dataansvarlig eller fælles dataansvarlig for en bestemt lokal aktivitet, vil dette fremgå ved indsamlingen eller af en særskilt privatlivserklæring. Hvis der er fælles dataansvar, vil erklæringen beskrive parternes væsentligste ansvarsområder og gøre hovedindholdet af ordningen i henhold til GDPR artikel 26 tilgængeligt.
Du kan kontakte vores databeskyttelsesteam på dataprivacy.de@grunenthal.com eller dk-info@grunenthal.com. Du kan kontakte databeskyttelsesrådgiveren (DPO) for Danmark på UKINORdataprotectionofficer@grunenthal.com.
Denne erklæring gælder for brugen af webstedet. Bestemte aktiviteter, f.eks. registrering som sundhedsperson, indberetning af bivirkninger eller deltagelse i et webinar, kan være omfattet af yderligere information. Den mere specifikke information har forrang for den pågældende aktivitet.
2. Grundlæggende principper for vores behandling
Vi behandler kun personoplysninger til udtrykkeligt angivne formål og på et gyldigt behandlingsgrundlag. De relevante formål og behandlingsgrundlag fremgår nedenfor. Vi begrænser indsamlingen til de oplysninger, der er nødvendige, og beskytter personoplysningerne ved hjælp af passende tekniske og organisatoriske foranstaltninger.
Når behandlingen er baseret på dit samtykke, kan du til enhver tid trække samtykket tilbage med virkning for fremtiden. Tilbagetrækningen påvirker ikke lovligheden af den behandling, der fandt sted, før samtykket blev trukket tilbage.
3. Når du besøger webstedet
Når du tilgår webstedet, sender din browser tekniske oplysninger til vores webserver. Vi kan behandle:
- din IP-adresse og den omtrentlige geografiske placering, der udledes heraf;
- dato og tidspunkt for adgang samt oplysninger om tidszone;
- den side eller fil, der anmodes om, den henvisende side, HTTP-statuskode og datamængde;
- browser, sprogindstillinger, operativsystem, enhedstype og skærmoplysninger; og
- sikkerheds- og fejloplysninger, der er nødvendige for at drive og beskytte webstedet.
Vi bruger disse oplysninger til at levere det indhold, du anmoder om, sikre teknisk stabilitet, forebygge misbrug og undersøge faktisk eller forsøgt uautoriseret adgang. Behandlingsgrundlaget er vores legitime interesse i at drive et sikkert og funktionsdygtigt websted, jf. GDPR artikel 6, stk. 1, litra f, og, når behandlingen er nødvendig for at levere en tjeneste, som du udtrykkeligt har anmodet om, GDPR artikel 6, stk. 1, litra b.
Hosting-, sikkerheds- og IT-leverandører kan behandle disse oplysninger som databehandlere efter vores instruks. Oplysningerne opbevares i den almindelige sikkerheds- og fejlsøgningsperiode og i længere tid, hvis det er nødvendigt for at undersøge en sikkerhedshændelse, opfylde en retlig forpligtelse eller håndtere et retskrav.
4. Cookies og lignende teknologier
4.1 Hvad er cookies?
Cookies og lignende teknologier er små filer eller identifikatorer, der kan lagres på eller aflæses fra din enhed. De kan f.eks. huske dine sprogvalg, opretholde en sikker session eller måle brugen af webstedet.
4.2 Nødvendige og valgfrie teknologier
Vi anvender strengt nødvendige cookies og lignende teknologier, når de er nødvendige for at levere, sikre eller stabilisere webstedet. Den tilknyttede behandling af personoplysninger er baseret på GDPR artikel 6, stk. 1, litra b og/eller f, afhængigt af formålet.
Analyse-, marketing- og andre valgfrie teknologier aktiveres kun, efter at du har givet et frivilligt, specifikt, informeret og utvetydigt samtykke i vores samtykkeløsning, jf. GDPR artikel 6, stk. 1, litra a og de gældende danske cookieregler. Valgfrie teknologier og tredjepartsindhold må ikke indlæses, før det relevante samtykke er givet.
Under "Privatlivsindstillinger" kan du se den aktuelle liste over teknologier og leverandører samt deres formål, kategorier og opbevarings- eller udløbsperioder. Du kan acceptere eller afvise efter formål og til enhver tid ændre eller trække dit samtykke tilbage lige så let, som du gav det. Hvis du afviser valgfrie teknologier, begrænser det ikke webstedets grundlæggende funktioner, men enkelte valgfrie funktioner kan være utilgængelige.
Vi opbevarer en registrering af dit samtykke eller afslag så længe, det er nødvendigt for at respektere dit valg og dokumentere, at samtykkekravene er overholdt.
5. Analyse og tagstyring
5.1 Sitecore
Dette websted anvender webanalysetjenesten "Sitecore Experience Analytics" for at hjælpe os med løbende at forbedre brugervenligheden på webstedet. Sitecore anvender cookies, som lagres på din enhed, og som gør det muligt at analysere din brug af webstedet. De oplysninger, som cookien genererer om din brug af webstedet, overføres til og lagres på tidssvarende, sikrede EU-baserede cloudservere i Azure Cloud i Dublin. Du kan ændre indstillingerne i din browser, så cookies ikke gemmes. Vi gør dog opmærksom på, at du i så fald muligvis ikke vil kunne bruge alle webstedets funktioner fuldt ud.
5.2 Matomo
Vi anvender open source-softwareværktøjet Matomo, tidligere PIWIK, fra InnoCraft Ltd, 150 Willis Street, 6011 Wellington, New Zealand, på vores websted for at analysere brugernes adfærd på webstedet. Matomo er et open source-værktøj til webanalyse.
Matomo Tag Manager er et tagstyringssystem til administration af JavaScript- og HTML-tags, der anvendes til implementering af sporings-, analyse- og marketingværktøjer.
Matomo anvender cookies. Disse tekstfiler lagres på din enhed og gør det muligt for os at analysere brugen af webstedet. Til dette formål overføres de brugsoplysninger, som indsamles via cookien, til os og lagres, så brugeradfærden kan analyseres. Din IP-adresse anonymiseres med det samme, og du forbliver dermed anonym som bruger. De oplysninger, som cookien genererer om din brug af dette websted, videregives ikke til tredjeparter.
Vi betragter denne analyse som en del af vores internettjenester. Vi ønsker at anvende den til løbende at forbedre webstedet og i højere grad tilpasse det til brugernes behov.
Disse behandlingsaktiviteter gennemføres kun, hvis du har givet dit udtrykkelige samtykke, jf. GDPR artikel 6, stk. 1, litra a.
Når enkelte sider på vores websted tilgås, lagres følgende oplysninger:
- De relevante dele af IP-adressen for det system, som brugeren tilgår webstedet fra, anonymiseres.
- Det websted, hvorfra brugeren tilgik den pågældende side, den såkaldte referrer.
- De undersider, som brugeren tilgår fra den besøgte side.
- Den tid, brugeren opholder sig på webstedet.
- Hyppigheden af brugerens besøg på webstedet.
Softwaren kører udelukkende på servere, som er under vores kontrol, og i Matomo Cloud. Vi har indgået en databehandleraftale med InnoCraft Ltd om behandling af personoplysninger på vores vegne. Brugernes personoplysninger lagres kun dér. Oplysningerne videregives ikke til tredjeparter.
Vi opbevarer oplysningerne i mindst to år, medmindre du trækker dit samtykke tilbage inden udløbet af denne periode.
Du kan læse Matomos bestemmelser om databeskyttelse på: https://matomo.org/privacy/.
5.3 Matomo Tag Manager
Vi anvender Matomo Tag Manager på vores websted. Matomo Tag Manager er en udvidelse af open source-webanalyseløsningen Matomo. Matomo Tag Manager anvendes til at integrere sporingshændelser, herunder marketingcookies, og til at styre integrationen af tredjepartskode. Behandlingsgrundlaget for behandlingen af personoplysninger er GDPR artikel 6, stk. 1, litra f. Vores legitime interesse er at sikre, at webstedet fungerer korrekt og uden fejl. Oplysningerne slettes, så snart formålet med indsamlingen er opfyldt.
6. Kontaktformularer og markedsføring
Når du kontakter os, behandler vi de oplysninger, du indtaster i formularen eller sender til os, f.eks. navn, titel, kontaktoplysninger, organisation, land, emne og besked, sammen med de tekniske oplysninger, der er nødvendige for at sende og beskytte formularen. Obligatoriske felter er markeret. Uden disse oplysninger kan vi muligvis ikke behandle eller besvare din henvendelse.
Vi bruger oplysningerne til at håndtere din konkrete henvendelse. Hvis henvendelsen vedrører indgåelse eller opfyldelse af en aftale, er behandlingsgrundlaget GDPR artikel 6, stk. 1, litra b. I andre tilfælde er grundlaget vores legitime interesse i at besvare henvendelser og administrere forretningsrelationer, jf. GDPR artikel 6, stk. 1, litra f. Henvendelser om bivirkninger eller produktkvalitet behandles som beskrevet i afsnit 10.
Hvis du særskilt har givet samtykket til elektronisk markedsføring, bruger vi dine kontakt- og præferenceoplysninger til de formål, der fremgår af samtykket, jf. GDPR artikel 6, stk. 1, litra a og gældende danske markedsføringsregler. Du kan til enhver tid afmelde dig via linket i meddelelsen eller ved at kontakte os. Vi kan opbevare en begrænset afmeldingsregistrering for at sikre, at dit valg respekteres.
7. Eksternt indhold og videotjenester
Vi kan indlejre indhold fra tredjeparter, herunder YouTube og Vimeo. Indhold, der lagrer eller får adgang til oplysninger på din enhed, videregiver online-identifikatorer eller overfører oplysninger til et tredjeland, blokeres som udgangspunkt, indtil du aktivt vælger at indlæse det eller giver samtykke under Privatlivsindstillinger.
Når du giver samtykke, kan udbyderen modtage din IP-adresse, oplysninger om din enhed og browser, den side, du besøger, tidspunktet for besøget samt oplysninger om din interaktion med indholdet. Hvis du er logget ind hos udbyderen, kan besøget blive knyttet til din konto. Behandlingsgrundlaget for vores aktivering af indholdet er dit samtykke, jf. GDPR artikel 6, stk. 1, litra a.
• YouTube leveres af Google Ireland Limited og YouTube LLC. Privatlivspolitik: https://policies.google.com/privacy.
• Vimeo leveres af Vimeo.com, Inc. Privatlivspolitik: https://vimeo.com/privacy.
Udbyderne kan handle som selvstændige dataansvarlige for deres egen efterfølgende behandling. Oplysninger kan overføres til USA som beskrevet i afsnit 13. Du kan trække dit samtykke tilbage under Privatlivsindstillinger; dette hindrer fremtidig indlæsning af det valgfrie indhold.
8. Registrering for lukkede brugergrupper og profilering af sundhedspersoner
Visse oplysninger om lægemidler må kun stilles til rådighed for sundhedspersoner. Når du registrerer dig, kan vi behandle dit navn, dine kontaktoplysninger, dit land, din organisation, din stilling eller dit speciale, autorisationsoplysninger eller andre faglige identifikatorer, login- og kontooplysninger samt oplysninger om din brug af det lukkede område.
Oplysningerne indsamles fra dig og kan suppleres med oplysninger fra IQVIA OneKey, relevante faglige registre eller andre pålidelige kilder med henblik på at verificere din faglige status. IQVIA Commercial GmbH & Co. OHG og relevante koncernselskaber kan levere autentifikations- eller verifikationstjenester.
Formålene er at oprette og sikre din konto, kontrollere adgang til lovreguleret indhold, dokumentere berettiget adgang og tilpasse indhold og kommunikation til din faglige rolle og dine angivne præferencer. Den behandling, der er nødvendig for at levere kontoen, er baseret på GDPR artikel 6, stk. 1, litra b. Verifikation, sikkerhed og beskyttelse af begrænset indhold er baseret på vores legitime interesser, jf. GDPR artikel 6, stk. 1, litra f. Markedsføring og profilering, der kræver samtykke, gennemføres kun på grundlag af GDPR artikel 6, stk. 1, litra a.
En profil kan bestå af segmenter baseret på forhold som fagområde, organisationstype, valgte interesser, samtykkepræferencer og interaktioner med vores indhold. Vi bruger profilen til at gøre indhold og kommunikation mere relevant. Vi træffer ikke afgørelser, der alene er baseret på automatisk behandling, og som har retsvirkning eller på tilsvarende måde påvirker dig væsentligt, medmindre du først har modtaget særskilt information i overensstemmelse med GDPR artikel 22.
Yderligere information til sundhedspersoner findes på https://www.grunenthal.com/other-privacy-statements..Du kan gøre indsigelse mod profilering baseret på legitime interesser og trække dit samtykke tilbage som beskrevet i afsnit 15.
9. Webinarer og onlinemøder
Vi kan bruge GoToWebinar, GoToMeeting eller lignende løsninger. GoTo-tjenester leveres af GoTo Technologies Ireland Unlimited Company, 77 Sir John Rogerson's Quay, Block C, Suite 207, Grand Canal Docklands, Dublin 2, D02 VK60, Irland.
Afhængigt af de funktioner, du bruger, kan vi behandle dit navn, kontakt- og organisationsoplysninger, loginoplysninger, IP-adresse, enhedsoplysninger, møde- og telefonioplysninger, chat, spørgsmål, svar og undersøgelsesdata samt lyd-, video- og præsentationsmateriale. Du kan selv slå kamera og mikrofon til eller fra. Behandlingsgrundlaget er GDPR artikel 6, stk. 1, litra b, når webinaret indgår som en del af en aftale eller registrering, og ellers vores legitime interesse i at gennemføre effektive faglige arrangementer, jf. GDPR artikel 6, stk. 1, litra f. Hvis vi optager et webinar, informerer vi dig tydeligt på forhånd og indhenter samtykke, hvor dette er påkrævet, jf. GDPR artikel 6, stk. 1, litra a.
GoTo behandler oplysninger som tjenesteudbyder i henhold til vores aftale og kan anvende underdatabehandlere. Rapporter i GoTo kan være tilgængelige i op til en måned, mens vores egne deltager- og opfølgningsoplysninger opbevares efter kriterierne i afsnit 14. Overførsler til USA eller andre tredjelande er beskrevet i afsnit 13. GoTos privatlivsinformation findes på https://www.goto.com/company/legal/privacy.
10. Bivirkninger, lægemiddelsikkerhed og produktkvalitetsklager
Webstedets almindelige kontaktfunktioner er ikke beregnet til indberetning af bivirkninger eller produktkvalitetsklager. Brug venligst vores særlige rapporteringsside på https://www.grunenthal.com/drug-safety-reporting eller kontakt drugsafety.dk@grunenthal.com. Du kan også kontakte en sundhedsperson eller den relevante sundhedsmyndighed.
Hvis vi modtager sikkerheds- eller kvalitetsoplysninger, er vi forpligtet til at behandle dem. Oplysningerne kan omfatte identitets- og kontaktoplysninger om indberetteren og patienten, oplysninger om lægemidlet, hændelsen eller klagen, helbredsoplysninger, behandlingshistorik og relevante baggrundsoplysninger.
Vi bruger oplysningerne til at vurdere, følge op på og rapportere om lægemiddelsikkerhed og produktkvalitet samt til at overholde gældende EU-lovgivning og dansk lægemiddellovgivning. Behandlingsgrundlaget er GDPR artikel 6, stk. 1, litra c, og for helbredsoplysninger GDPR artikel 9, stk. 2, litra i. Hvor det er nødvendigt i forbindelse med retskrav, kan GDPR artikel 9, stk. 2, litra f også finde anvendelse.
Oplysninger kan deles med relevante sundheds- og lægemiddelmyndigheder, Grünenthal-koncernselskaber, samarbejdspartnere og tjenesteudbydere, der har en sikkerheds- eller rapporteringsforpligtelse. Oplysningerne pseudonymiseres, hvor det er muligt, men myndigheder eller andre modtagere kan i særlige tilfælde kræve identificerende oplysninger.
Hvis du indberetter oplysninger om en anden person, modtager vi disse oplysninger fra dig. Vi giver den pågældende person den information, der kræves efter GDPR artikel 14, medmindre en lovlig undtagelse finder anvendelse.
Sikkerhedsrapporter opbevares som minimum i 10 år efter, at det relevante produkt er trukket tilbage fra markedet, eller i længere tid, hvis gældende lovgivning kræver det. Visse registreredes rettigheder kan være begrænsede, når behandlingen og opbevaringen er nødvendig for at overholde retlige forpligtelser eller beskytte folkesundheden.
11. Brugerundersøgelser
Deltagelse i brugerundersøgelser er frivillig. Vi kan behandle de svar, du indsender, og de tekniske oplysninger, der er nødvendige for at gennemføre undersøgelsen. Hvor det er muligt, holdes svarene adskilt fra direkte identifikatorer og analyseres i aggregeret eller anonymiseret form.
Behandlingsgrundlaget er vores legitime interesse i at forbedre webstedet og vores information, jf. GDPR artikel 6, stk. 1, litra f, eller dit samtykke, hvor undersøgelsen eller teknologien kræver det. Valgfrie undersøgelsesteknologier aktiveres ikke, før der er givet samtykke. Svarene slettes eller anonymiseres, når analysen og den nødvendige kvalitetssikring er afsluttet.
12. Modtagere og databehandlere
I det omfang det er nødvendigt for de beskrevne formål, kan personoplysninger deles med:
- Grünenthal-koncernselskaber og autoriseret personale;
- hosting-, sikkerheds-, analyse-, kommunikations-, autentifikations-, webinar- og andre IT-leverandører;
- rådgivere, revisorer og andre professionelle tjenesteudbydere, der er underlagt fortrolighed;
- selvstændige udbydere af eksternt indhold, når du vælger at aktivere deres tjenester; og
domstole, tilsynsmyndigheder, lægemiddel- og sundhedsmyndigheder samt andre offentlige myndigheder, når videregivelsen er påkrævet eller lovlig.
Databehandlere må kun behandle oplysninger efter vores dokumenterede instrukser og på grundlag af en aftale, der opfylder kravene i GDPR artikel 28. Selvstændige dataansvarlige behandler oplysninger i henhold til deres egne privatlivsoplysninger og retlige forpligtelser.
13. Overførsel af oplysninger uden for EU/EØS
Nogle modtagere eller deres underdatabehandlere kan være placeret i eller få adgang til personoplysninger fra lande uden for EU/EØS, herunder USA og Storbritannien. Det kan bl.a. omfatte Google/YouTube, Vimeo, GoTo, IQVIA, visse Grünenthal-koncernselskaber og deres underdatabehandlere.
Vi anvender et gyldigt overførselsgrundlag i henhold til GDPR kapitel V. Dette kan være en tilstrækkelighedsafgørelse fra Europa-Kommissionen, herunder EU-U.S. Data Privacy Framework for amerikanske modtagere med en gyldig certificering, eller Europa-Kommissionens standardkontraktbestemmelser kombineret med en vurdering af overførslen og passende supplerende tekniske og organisatoriske foranstaltninger. Udtrykkeligt samtykke anvendes kun undtagelsesvist, når betingelserne i GDPR artikel 49 er opfyldt, og ikke som en generel erstatning for passende garantier.
Du kan kontakte databeskyttelsesteamet for at få yderligere information om det relevante overførselsgrundlag og, hvor det er muligt, en kopi eller beskrivelse af de anvendte garantier.
14. Hvor længe opbevarer vi oplysningerne?
Vi opbevarer ikke personoplysninger længere end nødvendigt til det pågældende formål, medmindre en længere periode kræves ved lov eller er nødvendig for at fastlægge, gøre gældende eller forsvare retskrav. De vigtigste kriterier er:
- Server- og sikkerhedslogfiler: den almindelige sikkerheds- og fejlsøgningscyklus; længere ved en konkret hændelse, retlig forpligtelse eller et retskrav.
- Cookies, samtykke og analyse: de perioder, der fremgår af Privatlivsindstillinger, samt den nødvendige periode for at dokumentere og respektere dit valg.
- Kontakt- og kontraktoplysninger: indtil henvendelsen eller relationen er afsluttet og derefter i den relevante lovbestemte opbevarings- eller forældelsesperiode.
- Markedsføring: indtil du trækker samtykket tilbage eller gør indsigelse; en begrænset afmeldingsregistrering kan opbevares længere.
- HCP-konto og adgangsverifikation: Mens kontoen er aktiv og derefter i den periode, der er nødvendig for sikkerhed, dokumentation af lovlig adgang og retskrav.
- Webinarer: Leverandørrapporter normalt op til en måned; optagelser og interne deltagerdata i den periode, der oplyses ved arrangementet, eller er nødvendig for opfølgning og retskrav.
- Brugerundersøgelser: Indtil analysen og kvalitetssikringen er afsluttet, hvorefter oplysningerne slettes eller anonymiseres.
- Lægemiddelsikkerhed og produktkvalitet: I mindst 10 år efter, at produktet er trukket tilbage fra markedet, eller i længere tid, hvis lovgivningen kræver det.
15. Dine rettigheder
Afhængigt af omstændighederne har du ret til:
- indsigt i dine personoplysninger og information om behandlingen;
- berigtigelse af urigtige eller ufuldstændige oplysninger;
- sletning af oplysninger;
- begrænsning af behandlingen;
- dataportabilitet for oplysninger, du har givet os, når behandlingen er baseret på samtykke eller kontrakt og foretages ved hjælp af automatiske processer;
- at gøre indsigelse mod behandling baseret på GDPR artikel 6, stk. 1, litra e eller f, herunder profilering, samt en ubetinget ret til at gøre indsigelse mod direkte markedsføring;
- at trække dit samtykke tilbage med virkning for fremtiden; og
ikke at være genstand for en afgørelse, der alene er baseret på automatisk behandling, og som har retsvirkning eller på tilsvarende måde påvirker dig væsentligt, med forbehold for undtagelserne og garantierne i GDPR artikel 22.
Disse rettigheder er ikke absolutte og kan være begrænset ved lov, f.eks. når vi skal opbevare oplysninger af hensyn til lægemiddelovervågning eller retskrav. Vi besvarer normalt en anmodning senest en måned efter modtagelsen. Vi kan bede om de oplysninger, der er nødvendige for at bekræfte din identitet. Anmodninger er normalt gratis, men GDPR giver mulighed for at opkræve et rimeligt gebyr eller afvise en anmodning, hvis den er åbenbart grundløs eller overdreven.
Du kan udøve dine rettigheder ved at kontakte dataprivacy.de@grunenthal.com, dk-info@grunenthal.com eller databeskyttelsesrådgiveren (DPO) for Danmark på UKINORdataprotectionofficer@grunenthal.com.
16. Klage til en tilsynsmyndighed
Du har ret til at klage til en kompetent databeskyttelsesmyndighed, navnlig i det land, hvor du bor eller arbejder, eller hvor den påståede overtrædelse er sket. I Danmark kan du kontakte:
Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, telefon 33 19 32 00, e-mail dt@datatilsynet.dk, www.datatilsynet.dk.
Vi opfordrer dig til først at kontakte os, så vi får mulighed for at behandle din henvendelse. Dette begrænser dog ikke din ret til at klage.
17. Ændringer og yderligere privatlivserklæringer
Vi kan opdatere denne erklæring, når vores behandling, teknologier eller retlige forpligtelser ændrer sig. Den gældende version offentliggøres på webstedet med datoen for seneste opdatering. Ved væsentlige ændringer giver vi yderligere meddelelse, når det er relevant.
Yderligere privatlivserklæringer, herunder for sundhedspersoner og tredjeparter, findes på https://www.grunenthal.com/other-privacy-statements.
Dokument-/referencenummer: [indsættes efter godkendelse].
Privatlivserklæring – English version
Last updated: 01 September 2026
1. Who is the controller and what does this statement cover?
This website, https://www.grunenthalhealth.dk/ (the "website"), is provided by Grünenthal GmbH, Zieglerstraße 6, 52078 Aachen, Germany ("Grünenthal", "we", "us" or "our"). Unless you are told otherwise when personal data are collected, Grünenthal GmbH is the controller for the processing described in this statement.
Grünenthal Denmark ApS, Arne Jacobsens Allé 7, 2300 Copenhagen S, Denmark, is our local contact in Denmark. Where Grünenthal Denmark ApS is the controller or a joint controller for a specific local activity, this will be stated at the point of collection or in a separate privacy notice. Where joint controllership applies, that notice will describe the parties' principal responsibilities and make the essence of the Article 26 GDPR arrangement available.
You can contact our Data Protection Team at dataprivacy.de@grunenthal.com or dk-info@grunenthal.com. You can contact the Data Protection Officer (DPO) for Denmark at UKINORdataprotectionofficer@grunenthal.com.
This statement applies to use of the website. Specific activities, such as HCP registration, adverse-event reporting or webinar participation, may be covered by additional information. The more specific information takes precedence for that activity.
2. Core principles for our processing
We process personal data only for specified purposes and on a valid legal basis. The relevant purposes and legal bases are described below. We limit collection to what is necessary and protect personal data using appropriate technical and organisational measures.
Where processing is based on your consent, you may withdraw that consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
3. When you visit the website
When you access the website, your browser sends technical information to our web server. We may process:
your IP address and the approximate location derived from it;
the date and time of access and time-zone information;
the page or file requested, referring page, HTTP status code and data volume;
browser, language settings, operating system, device type and screen information; and
security and error information needed to operate and protect the website.
We use these data to deliver the content you request, ensure technical stability, prevent misuse and investigate actual or attempted unauthorised access. The legal basis is our legitimate interest in operating a secure and functional website under Article 6(1)(f) GDPR and, where processing is necessary to provide a service you expressly requested, Article 6(1)(b).
Hosting, security and IT providers may process these data as processors acting on our instructions. The data are retained for the normal security and troubleshooting cycle and for longer where needed to investigate a security incident, comply with a legal obligation or handle a legal claim.
4. Cookies and similar technologies
4.1 What are cookies?
Cookies and similar technologies are small files or identifiers that may be stored on or read from your device. They can, for example, remember language choices, maintain a secure session or measure use of the website.
4.2 Necessary and optional technologies
We use strictly necessary cookies and similar technologies where they are needed to provide, secure or stabilise the website. The associated processing of personal data is based on Article 6(1)(b) and/or (f) GDPR, depending on the purpose.
Analytics, marketing and other optional technologies are activated only after you have given a freely given, specific, informed and unambiguous consent in our consent-management platform, under Article 6(1)(a) GDPR and the applicable Danish cookie rules. Optional technologies and third-party content must not load before the relevant consent.
In "Privacy Settings" you can see the current list of technologies and providers, their purposes, categories and retention or expiry periods. You can accept or reject by purpose and change or withdraw your consent at any time as easily as you gave it. Refusing optional technologies does not restrict the website's core functions, although an optional feature may be unavailable.
We retain a record of your consent or refusal for as long as needed to respect your choice and demonstrate compliance with consent requirements.
5. Analytics and tag management
5.1 Sitecore
This Website uses the web analytics service “Sitecore Experience Analytics” in order to help us continually improve the customer friendliness of our Website. Sitecore uses "cookies" that are stored on your computer and allow your use of the Website to be analyzed. The information generated by the cookie on your use of this Website is transmitted to and stored by state of the art secured EU based cloud servers (Azure Cloud, Dublin). You can use a corresponding setting in your browser software to prevent cookies from being saved; we would, however, like to draw your attention to the fact that, if you do so, you may not be able to use all of the functions offered by the website in full.
5.2 Matomo
We use the open source software tool Matomo (formerly PIWIK) from InnoCraft Ltd, 150 Willis St, 6011 Wellington, New Zealand on our website to analyze the surfing behavior of our users. Matomo is an open source tool for web analysis.
Matomo Tag Manager is a tag management system for managing JavaScript and HTML tags used to implement tracking, analytics and marketing tools.
Matomo uses cookies. These text files are stored on your computer and make it possible for us to analyze the use of the website. For this purpose, the usage information obtained by the cookie is transmitted to us and stored so that the usage behavior can be evaluated. Your IP address is immediately anonymized; thus you remain anonymous as a user. The information generated by the cookie about your use of this website will not be disclosed to third parties.
We understand this analysis as part of our Internet services. We would like to use it to further improve the website and adapt it even more to the needs of the users.
These processing operations are only carried out if explicit consent is given in accordance with Art. 6 (1) a) GDPR.
If individual pages of our website are called up, the following data is stored:
Bytes of the IP address of the calling system of the user are anonymized.
The website from which the user accessed the called website (referrer).
The subpages accessed from the accessed website
The time spent on the website
The frequency of accessing the web page
In this regard, the software runs exclusively on the servers within our control and within the Matomo Cloud. We have concluded a data processing agreement with InnoCraft Ltd. about data processing on our behalf. Storage of the users' personal data only takes place there. The data is not passed on to third parties.
We store this data for a period of at least two years, unless you revoke your consent beforehand.
You can view the data protection provisions of Matomo at: https://matomo.org/privacy/
5.3 Matomo Tag Manager
Our website we use Matomo Tag Manager. Matomo Tag Manager is an extension of the open source Matomo web analytics solution. The Tag Manager is used to integrate tracking events (marketing cookies) and control the integration of third-party code. The legal basis for the data processing is Art. 6 (1) f) GDPR. The legitimate interest is the error-free functioning of the website. The deletion of the data takes place as soon as the purpose of the collection has been fulfilled.
6. Contact forms and marketing
When you contact us, we process the data you enter in the form or send to us, such as your name, title, contact details, organisation, country, subject and message, together with technical information needed to transmit and protect the form. Mandatory fields are marked. Without them, we may not be able to process or answer your request.
We use the data to handle your specific request. Where the request concerns entering into or performing a contract, the legal basis is Article 6(1)(b) GDPR. In other cases, the basis is our legitimate interest in responding to requests and administering business relationships under Article 6(1)(f). Adverse-event or product-quality communications are handled as described in section 10.
Where you have separately consented to electronic marketing, we use your contact and preference data for the purposes described in the consent under Article 6(1)(a) GDPR and applicable Danish marketing law. You may unsubscribe at any time using the link in the message or by contacting us. We may retain a limited suppression record to ensure that your choice is respected.
7. External content and video services
We may embed third-party content, including YouTube and Vimeo. Content that stores or accesses information on your device, discloses online identifiers or transfers data to a third country is blocked by default until you actively choose to load it or consent in Privacy Settings.
When you consent, the provider may receive your IP address, device and browser information, the page you visit, the time and information about your interaction with the content. If you are logged in to the provider, the visit may be linked to your account. The legal basis for our activation of the content is your consent under Article 6(1)(a) GDPR.
YouTube is provided by Google Ireland Limited and YouTube LLC. Privacy policy: https://policies.google.com/privacy.
Vimeo is provided by Vimeo.com, Inc. Privacy policy: https://vimeo.com/privacy.
The providers may act as independent controllers for their subsequent processing. Data may be transferred to the United States as described in section 13. You can withdraw consent in Privacy Settings; this prevents future loading of the optional content.
8. Registration for restricted user groups and HCP profiling
Certain medicinal-product information may be made available only to healthcare professionals. When you register, we may process your name, contact details, country, organisation, role or specialty, licence or other professional identifiers, login and account data, and information about your use of the restricted area.
The data are collected from you and may be supplemented with data from IQVIA OneKey, relevant professional registers or other reliable sources to verify your professional status. IQVIA Commercial GmbH & Co. OHG and relevant group companies may provide authentication or verification services.
The purposes are to create and secure your account, control access to legally restricted content, document authorised access, and tailor content and communications to your professional role and stated preferences. Processing needed to provide the account is based on Article 6(1)(b) GDPR. Verification, security and protection of restricted content are based on our legitimate interests under Article 6(1)(f). Marketing and profiling that require consent are carried out only under Article 6(1)(a).
A profile may consist of segments based on matters such as professional field, organisation type, selected interests, consent preferences and interactions with our content. We use the profile to make content and communications more relevant. We do not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you, unless you have first received separate information in accordance with Article 22 GDPR.
Additional information for healthcare professionals is available at https://www.grunenthal.com/other-privacy-statements. You may object to profiling based on legitimate interests and withdraw consent as described in section 15.
9. Webinars and online meetings
We may use GoToWebinar, GoToMeeting or similar solutions. GoTo services are provided by GoTo Technologies Ireland Unlimited Company, 77 Sir John Rogerson's Quay, Block C, Suite 207, Grand Canal Docklands, Dublin 2, D02 VK60, Ireland.
Depending on the features you use, we may process your name, contact and organisation data, login information, IP address, device information, meeting and telephone data, chat, questions, answers and survey data, and audio, video and presentation material. You can switch your camera and microphone on or off.
The legal basis is Article 6(1)(b) GDPR where the webinar forms part of a contract or registration and otherwise our legitimate interest in conducting effective professional events under Article 6(1)(f). If we record a webinar, we will tell you clearly in advance and obtain consent where required under Article 6(1)(a).
GoTo processes data as a service provider under our agreement and may use subprocessors. Reports in GoTo may be available for up to one month, while our own attendance and follow-up data are retained under the criteria in section 14. Transfers to the United States or other third countries are described in section 13. GoTo's privacy information is available at https://www.goto.com/company/legal/privacy.
10. Adverse events, pharmacovigilance and product-quality complaints
The website's general contact functions are not intended for adverse-event reports or product-quality complaints. Please use our dedicated reporting page at https://www.grunenthal.com/drug-safety-reporting or contact drugsafety.dk@grunenthal.com. You may also contact a healthcare professional or the relevant health authority.
If we receive safety or quality information, we are required to process it. The data may include identity and contact data about the reporter and patient, medicinal-product details, the event or complaint, health data, treatment history and relevant background information.
We use the data to assess, follow up and report medicinal-product safety and product quality and to comply with applicable EU and Danish medicines law. The legal basis is Article 6(1)(c) GDPR and, for health data, Article 9(2)(i). Where necessary for legal claims, Article 9(2)(f) may also apply.
Data may be shared with relevant health and medicines authorities, Grünenthal group companies, cooperation partners and service providers that have a safety or reporting obligation. Data are pseudonymised where possible, but authorities or other recipients may in specific cases require identifying information.
If you report information about another person, we receive that information from you. We will provide the person with the information required under Article 14 GDPR unless a lawful exception applies.
Safety reports are retained for at least 10 years after the relevant product has been withdrawn from the market, or longer where applicable law requires. Some data-subject rights may be restricted where processing and retention are necessary to comply with legal obligations or protect public health.
11. User surveys
Participation in user surveys is voluntary. We may process the answers you submit and the technical information needed to run the survey. Where possible, answers are kept separate from direct identifiers and analysed in aggregated or anonymised form.
The legal basis is our legitimate interest in improving the website and our information under Article 6(1)(f) GDPR, or your consent where the survey or technology requires it. Optional survey technology does not activate before consent. Answers are deleted or anonymised when analysis and necessary quality assurance are complete.
12. Recipients and processors
To the extent necessary for the purposes described, personal data may be shared with:
Grünenthal group companies and authorised personnel;
hosting, security, analytics, communications, authentication, webinar and other IT providers;
advisers, auditors and other professional providers subject to confidentiality;
independent providers of external content when you choose to activate their services; and
courts, supervisory, medicines, health and other public authorities where disclosure is required or lawful.
Processors may act only on our documented instructions and under an agreement meeting Article 28 GDPR. Independent controllers process data under their own privacy information and legal obligations.
13. Transfers outside the EU/EEA
Some recipients or their subprocessors may be located in, or access personal data from, countries outside the EU/EEA, including the United States and the United Kingdom. This may include Google/YouTube, Vimeo, GoTo, IQVIA, certain Grünenthal group companies and their subprocessors.
We use a valid transfer mechanism under Chapter V GDPR. This may be a European Commission adequacy decision, including the EU-U.S. Data Privacy Framework for U.S. recipients holding a valid certification, or the European Commission Standard Contractual Clauses together with a transfer assessment and appropriate supplementary technical and organisational measures. Explicit consent is used only exceptionally where the conditions in Article 49 GDPR are met, and not as a general substitute for appropriate safeguards.
You may contact the Data Protection Team for further information about the relevant transfer mechanism and, where available, a copy or description of the safeguards used.
14. How long do we retain personal data?
We do not retain personal data longer than necessary for the purpose, unless a longer period is required by law or is needed to establish, exercise or defend legal claims. The main criteria are:
server and security logs: the normal security and troubleshooting cycle; longer for a specific incident, legal obligation or claim;
cookies, consent and analytics: the periods shown in Privacy Settings and the period needed to document and respect your choice;
contact and contract data: until the request or relationship is complete and then for the relevant statutory retention or limitation period;
marketing: until you withdraw consent or object; a limited suppression record may be retained for longer;
HCP account and access verification: while the account is active and then for the period needed for security, evidence of lawful access and legal claims;
webinars: provider reports normally for up to one month; recordings and internal attendance data for the period notified for the event or needed for follow-up and legal claims;
user surveys: until analysis and quality assurance are complete, after which data are deleted or anonymised; and
pharmacovigilance and product quality: for at least 10 years after the product is withdrawn from the market, or longer where law requires.
15. Your rights
Depending on the circumstances, you have the right to:
access your personal data and information about the processing;
rectify inaccurate or incomplete data;
erase data;
restrict processing;
data portability for data you provided where processing is based on consent or contract and carried out by automated means;
object to processing based on Article 6(1)(e) or (f) GDPR, including profiling, and an unconditional right to object to direct marketing;
withdraw consent with effect for the future; and
not be subject to a decision based solely on automated processing that produces legal effects or similarly significant effects, subject to the exceptions and safeguards in Article 22 GDPR.
These rights are not absolute and may be restricted by law, for example where we must retain data for pharmacovigilance or legal claims. We normally respond within one month of receiving a request. We may ask for information needed to verify your identity. Requests are normally free, although GDPR permits a reasonable fee or refusal for manifestly unfounded or excessive requests.
You can exercise your rights by contacting dataprivacy.de@grunenthal.com, dk-info@grunenthal.com or the Data Protection Officer (DPO) for Denmark at UKINORdataprotectionofficer@grunenthal.com.
16. Complaints to a supervisory authority
You have the right to complain to a competent data-protection authority, particularly in the country where you live or work or where the alleged infringement occurred. In Denmark, you can contact:
Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, telephone 33 19 32 00, email dt@datatilsynet.dk, www.datatilsynet.dk.
We encourage you to contact us first so that we have an opportunity to address your concern, but this does not limit your right to complain.
17. Changes and additional privacy statements
We may update this statement when our processing, technologies or legal obligations change. The current version will be published on the website with its last-updated date. Where appropriate, we will provide additional notice of material changes.
Additional privacy statements, including those for healthcare professionals and third parties, are available at https://www.grunenthal.com/other-privacy-statements.
Document/reference number: M-ALL-DK-03-26-0009
Privatlivserklæring sundhedsfagligt personale
https://www.grunenthal.com/other-privacy-statements
