Effective Date of this Privacy Notice: April 1, 2017.
Shire recognizes and respects the privacy rights of individuals with regards to their personal data. This Privacy Notice (“Notice”) explains what type of personal data we may collect from you and how we use it.
Your privacy is important to us. If you have any questions concerning Shire’s privacy practices or wish to access or correct personal data that Shire has collected from you, please contact us as described in the “How to Contact Us” section below.
Applicability and organizations covered by this Privacy Notice
Shire is a group of companies with operations globally. The Shire enterprise (“Shire”, “we”, “us”, “our”) includes the parent company, Shire plc, and its affiliated entities. For contact information related to your local affiliate, please refer to Shire’s website at http://www.shire.com/contact-us.
This Notice applies to Shire websites, social media pages, (mobile) applications, surveys, patient and healthcare professional support activities, as well as other Shire services that display or refer to this Notice (together “Services”). Any person accessing, browsing or otherwise using the Services, either manually or via an automated device or program, shall be considered a “User.”
Personal data we collect and use
Shire collects personal data to operate effectively and provide you with the best experiences from our Services. You may provide some of this data directly to Shire through registrations, applications and surveys, and in connection with your inquiries. For example, you may choose to provide your name and contact information, health, insurance and/or financial information in connection with a promotion, a patient assistance or support program or a clinical trial. Healthcare professionals may provide information related to their specialties and professional affiliations.
We also may receive data about you by tracking how you interact with our Services. For example, using technologies such as cookies (see also section on “Web technologies”).
Shire also obtains data from third parties (including other companies). For example, we may use such third-party data to confirm contact or financial information, to verify licensure of healthcare professionals or to better understand your interests by associating demographic information with other information you have provided.
Wherever required or appropriate, Shire will obtain consent for the processing of your personal data for the purposes outlined in this Notice and consistent with the terms and conditions herein.
The type of personal data we collect depends on the interactions you have with Shire and the Shire Services you use. These may include:
- Name and contact data: We may collect your name, postal address, email address, telephone number and other similar contact data.
- Credentials: We may collect passwords, password hints and similar security information used for authentication and Shire account access.
- Government-issued Identification: We may collect certain types of government-issued data from you, including Social Security Numbers, national identification numbers, driver’s license data, and passport data.
- Demographic data: We may collect data about you such as your age, gender, country of origin or residence, and preferred language.
- Interests and favorites: We may collect data about your professional or personal interests and favorites, such as the websites you visit, your professional affiliations, publications, etc.
- Financial data: We may collect data necessary to process payments, such as a bank account or credit card number.
- Usage data: We may collect data about how you and your device interact with our Services, such as time spent on a site, which pages you have visited, time to accomplish a task etc.).
- Relationship and interaction data: We may collect data about our interactions and meetings, such as when you contact us for information and support
- Location data: We may collect data about your location, which can be either precise or imprecise. Precise data includes geolocation data. Imprecise location data includes, for example, a location derived from your IP address or data that indicates where you are located with less precision, such as at a city or postcode level.
- Health-related data: We may collect data related to your healthcare, including prior authorization for payment of healthcare services, patient engagement and support services, and prescription information.
- Clinical data: We may collect data related to our research and development and clinical studies, registries and trials.
- Biometric Information: We may collect data related to your biometrics, such as fingerprints, voice prints, or other unique physical characteristics.
- Legally Required Information: We may collect additional data about you that is related to patient safety and adverse events, or that may be required by laws that apply to Shire.
In some cases, we may augment the information we hold about you with information we receive from third-parties and with information which is publicly or commercially available and/or which is obtained by any other legal means.
For example, Shire may also collect information provided by you on message boards, chats, profile pages, blog pages, and other services to which you are able to post information and materials (including, without limitation, our Shire social media pages). Please note that any information you post or disclose through these services may become publicly available information to users of the service you provided it to, and to the general public. We urge you to be very careful when deciding to disclose your personal data, or any other information, in these forums, and to carefully review and familiarize yourself with applicable privacy settings and options.
How we use personal data
Shire uses the personal data we collect for a number of basic purposes, described in more detail below: (1) for business operations (marketing and sales, research and development, patient support, donations and sponsorships, communications), (2) for business administration (finance and accounting, human resources, prevention and investigatory activities), (3) for business management (internal audit, asset management, system and business controls), and (4) as necessary to protect the health, safety, and security of Shire personnel and to comply with legal requirements and obligations.
We may use personal data:
- To communicate with you regarding any requests or inquiries you may submit and to provide you with related support or service.
- To contact you from time to time to provide you with important information, required notices, and promotional materials.
- To send administrative information to you, for example, information regarding the (changes to) Services we provide.
- To personalize your experience when using our Services by presenting products and offers tailored to you.
- To identify you to anyone to whom you send messages using our Services.
- For our business purposes, such as data analysis, audits, fraud monitoring and prevention, developing new products, enhancing, improving or modifying our Services, identifying usage trends, determining the effectiveness of our promotional campaigns, conducting surveys, and operating and expanding our business activities.
- To better understand how our products and Services impact you, to track and respond to safety concerns and to further develop and improve our products and Services.
- To offer special programs, activities, clinical trials, events or promotions via our Services that have specific terms, privacy notices and/or informed consent forms that explain how personal data you provide will be processed in connection with such special program. Some of these special programs may involve sharing information with a third party and Shire will provide you with notice of this. You may be offered the opportunity to agree to or opt-out of the sharing of your data with such third party. But, in some instances, it may be necessary to agree to share with a third party in order to participate in the special program. The personal data you provide may be used by the third party in accordance with the special program terms and, unless provided otherwise in such special program terms, for their own purposes in accordance with their own policies/terms. We encourage you to review both the special program terms and any applicable third party policies/terms before participating.
- As we believe necessary or appropriate: (a) under applicable law, including laws outside your country of residence; (b) to comply with legal process; (c) to respond to requests from public or government authorities, including authorities outside your country of residence; (d) to enforce our terms and conditions; (e) to protect our operations or those of any of our affiliates; (f) to protect our rights, privacy, safety or property, and/or that of our affiliates, you or others; (g) to allow us to pursue available remedies or limit the damages that we may incur.
Who we share personal data with
We share your personal data, with your consent or as necessary, to complete any transaction or provide any service that you have requested or authorized. We also share data with Shire-controlled affiliates and subsidiaries; with vendors working on our behalf; when required by law or to respond to legal process; to protect our customers; to protect lives; to maintain the security of our Services; and to protect the rights or property of Shire.
We may disclose your personal data to affiliates and third parties as follows:
- Among affiliates for the purposes described in this Notice. Shire is the party responsible for the management of the jointly-used personal data.
- To our third-party service providers that provide services such as website hosting, data analysis, payment processing, order fulfillment, information technology and related infrastructure provision, customer service, email delivery, auditing and other similar services. Shire notice requires that our service providers adhere to appropriate restrictions on access and use of your personal data.
- To third parties to permit them to send you marketing communications.
- To third-party sponsors of sweepstakes, contests and similar promotions.
We may also disclose your personal data in the following circumstances:
- As required by law, including laws outside your country of residence, to comply with a subpoena, required registration, or legal process.
- In the event of a merger, reorganization, acquisition, joint venture, assignment, spin-off, transfer or sale or disposition of all or any portion of our business, including in connection with any bankruptcy or similar proceedings.
We may also disclose aggregate or de-identified data that is not personally identifiable to third parties. Aggregate data is created by collecting and processing information about individuals and summarizing the data, eliminating the possibility to identify an individual.
How we protect your personal data
We have implemented a variety of security technologies and organizational procedures to protect your personal data from unauthorized access, use and disclosure. For example, we store your personal data on computer systems that have various types of technical and physical access controls, such as encryption. Although Shire has implemented commercially reasonable data security controls consistent with industry standards, Shire cannot guarantee the security of your information. It is also important for you to remember to protect against unauthorized access to your password(s) and your computer, mobile devices, etc. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of any account you might have with us has been compromised), please notify us immediately as described in the “How to Contact Us” section below.
Where we store and process personal data
As Shire is a multi-national organization with locations in many countries around the world, your personal data may be stored and processed in any country where we have facilities or in which we engage service providers. Shire takes steps to process personal data according to the provisions of this Notice and the requirements of applicable law.
Shire may transfer personal data to countries outside of your country of residence. The laws of the receiving countries may not provide as stringent protections for personal data as your country of residence. In instances where a lesser level of protection is provided by a receiving country, Shire undertakes to enter into contractual agreements (e.g., European Union Standard Contractual Clauses), or relies on other available data transfer mechanisms that aim to provide adequate protections. A copy of the EU Standard Contractual Clauses boilerplate contracts may be found at: http://ec.europa.eu/justice/data-protection/international-transfers/transfer/.
Shire will retain your personal data for the period necessary to fulfill the purposes outlined in this Notice unless a longer retention period is required or permitted by law.
How you can access and control your personal data
You have choices about the data we collect. When you are asked to share your personal data with Shire, you may decline; however, your choice not to share your personal data with Shire may mean you will not be able to use or (fully) benefit from our Services, features or offerings.
Shire respects your right to know and inquire about what personal data we have collected about you. In addition, you have the right to request correction or deletion of such personal data, as well as to request removal of your personal data held by third-parties with whom we conduct business. In addition, you may contact your jurisdiction’s legal authority overseeing implementation of data protection laws to file a complaint regarding the processing of your personal data.
If you would like to make a request for Shire to correct or delete personal data that you have provided to Shire, please contact us as described in the “How to Contact Us” section below, and we will respond in a reasonable time. We will make a good faith effort to provide you with access to your personal data and to correct any inaccuracies or delete such information at your request, if it is not otherwise required to be retained by law or for Shire’s legitimate business purposes. We may decline to process requests that are unreasonably repetitive or systematic, require disproportionate technical effort, jeopardize the privacy of others, or would be extremely impractical or for which access is not otherwise required. Before fulfilling your requests we may need to verify your identity.
While in some instances we may collect personal data about children with the consent of a parent or guardian for the provision of our Services such as clinical activities or for patient support programs, we do not otherwise knowingly solicit data from, or market to, children. If a parent or guardian becomes aware that his or her child has provided us with personal information, he or she should contact us as described in the “How to Contact Us” section below. We will take reasonable steps to delete such information from our database within a reasonable time.
In the event your personal data is accessed, lost, or stolen by an unauthorized third party, Shire will exercise commercially reasonable efforts to notify you to the extent required by law and disclose to you the personal data that was accessed/disclosed using the contact information provided to us or by other reasonable means.
Generally, social networks are interactive tools that enable you to collaborate and share information. Shire may collect certain personal data from you to enable you to use online social network features. Shire may also use these tools to post or share personal data with others. When using social networks, you should be very vigilant about what personal data you choose to share with others. Shire provides notices and choices about how personal data is collected, used and disclosed on its website, social networks and other Services. When engaging in social network activities, you should not post information about third parties without their consent.
Web, Cookies and similar technologies
You have a variety of tools to control cookies and similar technologies, including browser controls to block and delete cookies. Please look at your particular browser for instructions on these functions. You may also wish to refer to http://www.allaboutcookies.org/manage-cookies/index.html.
Your browser settings and other tools to control cookies and similar technologies may impact your experience with our Services.
We use various types of cookies, as well as similar technologies such as Local Shared Objects (or “Flash Cookies”) and web beacons (also called single-pixel tags) to identify your IP address, browser type, device characteristics, domain name, referring URLs and specific links and web pages through which you click. This data is collected automatically and is used for purposes as mentioned above. This technology also allows us to recognize you when you return to this Site and to provide you with a customized experience that we feel will be of value to you.
In addition, Shire uses web analytics services (e.g. Google Analytics) to collect website analytics. The information generated about website usage (including your shortened IP address) is transmitted to these web analytics services. This information is used to evaluate visitors’ use of the domain, compile statistical reports on website activity, and provide other services related to the site and internet use activity.
Furthermore, we may partner with third-party service providers to serve ads regarding goods or services that may be of interest to you when you access and use our Services and third party-sites. Some of the ads on our Services or on third party sites may be personalized, meaning that they are intended to be relevant to you based on what we, or the online advertising network serving the ad, know about you or your computer’s browsing activity on both the Service and third-party sites. To do so, these companies may place or recognize a unique cookie on your browser (including through the use of pixel tags).
The Network Advertising Initiative (NAI) offers useful information about internet advertising companies, including information about how to opt-out of interest-based advertising by their members. See http://www.networkadvertising.org for general information about the NAI and http://www.networkadvertising.org/managing/opt_out.asp for the opt-out page. You may also visit http://www.aboutads.info/consumers to learn about interest-based advertising and how to opt-out from ads served by some or all participating companies.
These opt-out mechanisms rely on cookies to remember your choices. If you delete your cookies, use another computer or device, or change browsers, you will need to repeat this process. In addition, opting out of interest-based ads will not opt you out of all ads, but rather only those ads that are personalized to your interests.
How to Contact Us
Shire welcomes any questions or comments you may have regarding this Notice or its implementation. Any such questions or comments should be submitted using the contact information below. We will use reasonable efforts to resolve or address your concern. Please note that email communications are not always secure, so please do not include credit card information or other sensitive information in your emails to us.
Shire Privacy Office
300 Shire Way
Lexington, MA 02421
Tel: +1 (781) 482-9500
Updates to our Privacy Notice
Shire may update this Notice from time to time. Please check this Notice periodically for changes. If we make any changes, the updated Notice will be posted with a revised effective date. We encourage you to periodically review this page for the latest information on our privacy practices.
Your continued use of our Services following the posting of changes to the Notice will mean you accept those changes.