Privacy and Cookie Notice

This privacy and cookie notice (“Notice”) is provided by Astute Healthcare Limited (“Astute,” “we,” “us,” or “our”). This Notice explains how we collect, use, and share personal data and describes the choices and rights individuals have regarding their personal data.

Scope of this Notice

This Notice applies to the general processing of personal data conducted by Astute Healthcare Limited. However, specific scenarios may require a different privacy notice, which will be provided to you when applicable. These scenarios include reporting adverse events or fulfilling transparency requirements.

This Notice applies to personal data collected through the following:

Website

We may process personal data when you visit or use our website. This data may include device and network activity information, such as device type, IP address, device or user identifiers, operating system, internet service provider, date and time of website use, interactions with links or content, and other log information. In case of technical errors, we may also receive error-reporting information, including device or software details and the time and content associated with the error.

Our Sites may contain links to other websites or organizations beyond our control. We are not responsible for the privacy policies or practices of those websites or organizations. If you access these websites through our Sites, we recommend reviewing their privacy policies to understand how they collect, use, and share your personal data.

Conflict of interest checks

We process personal data if our employees have declared potential conflicts of interest that concern you. These conflicts of interest involve personal, social, financial, political, or other interests that may affect our relationship with you.

Interactions with us or our representatives

We collect information about healthcare professionals/experts, business information, personal information when you interact with us or our representatives. This includes contact details and professional and employment-related information. We also maintain records of communications and meetings with you.

Supplier/vendor and customer relationships

When you engage with Astute Healthcare Limited as a supplier/vendor, customer, or personnel of a supplier/vendor/customer, we process your personal data. This includes name, personal identification number, business contact details, business bank account details, and other relevant information. We also maintain records of our interactions, including order/payment data and survey responses.

Third parties

We collect personal data from third-party sources, including publicly available sources such as healthcare professional registers, published journals, event materials, and websites of healthcare professionals, suppliers, distributors, vendors or their employers. We may also use third-party data providers to enhance our knowledge of the healthcare and FMCG sector. This data includes information related to your profession, qualifications, experience, publications, and other relevant details.

How we use your personal data

We rely on different legal bases for processing personal data, depending on the purposes for which we collect it.

Legitimate interests

We process personal data when it is necessary for our legitimate interests as a data controller or the interests of a third party. These legitimate interests include:

  • Responding to your queries or correspondence submitted through our Sites.
  • Analyzing engagement with our sites, communications, events, and services to improve content, performance, and relevance.
  • Detecting, investigating, preventing, or reporting activities that violate our policies or are illegal.
  • Conducting conflict of interest checks and taking appropriate actions.
  • Developing and maintaining relationships, understanding the healthcare and FMCG sector, and providing information about products or events (when consent is not required).
  • Tailoring communications based on your expertise and professional interests.
  • Assessing and analyzing interests and experience based on information collected during interactions.
  • Conducting market research, scientific cooperation, or research activities.
  • Checking professional expertise and experience before entering into personal services contracts.
  • Managing business relationships, supplier/vendor/customer contracts, and handling questions or complaints.
  • Investigating allegations of misconduct, performing due diligence, or for dispute resolution, audit, or legal purposes.

We carefully balance our legitimate business interests against your interests and rights under data protection law. For more information, please contact us at the addresses specified in the “Your Rights” section below.

Contract

We process personal data when it is necessary for the performance of a contract with you or when you request steps prior to entering into a contract. This includes:

  • Fulfilling obligations under the contract, such as managing orders, arranging goods/services provision, and making payments.
  • Managing event-related information.
  • Handling orders, questions, and complaints regarding products.
  • Legal obligation

We process personal data to meet legal, regulatory, and compliance requirements, including:

  • Responding to information requests from government authorities.
  • Complying with legal and self-regulatory obligations, transparency requirements, or anti-gift regulations.
  • Managing medical information requests.
  • Checking professional expertise and experience before entering into personal services contracts.
  • We may also process personal data for dispute resolution, legal claims, compliance, regulatory purposes, or investigative needs as necessary.

Consent

We generally do not rely on consent as a legal basis for processing personal data. However, for direct marketing communications sent via email, we may ask for your consent. You can withdraw consent for marketing at any time by contacting us.

Sharing your personal data

We may disclose personal data to the following recipients and/or categories of recipients when necessary for their functions:

  • Our staff, professional advisors, and agents.
  • Astute group companies providing IT support, hosting, HR, finance, and other support services.
  • Third-party service providers processing personal data on our behalf, subject to confidentiality obligations.
  • Government authorities, regulatory agencies, and law enforcement officials, as required by law or for the legal protection of our interests.
  • Relevant regulators and self-regulatory bodies.
  • Third-party sources of personal data to validate and update information.
  • Nominated wholesalers for pharmaceutical and FMCG customers.
  • Advisers and new owners in the event of a business sale or integration.
  • Cookies and related tracking technologies

We use cookies and similar technologies on our sites to collect information and improve user experience. Cookies are text files that are downloaded to your device when you visit a site, allowing the site to recognize your device. Web beacons or clear gifs, count users who have visited pages or read emails, collecting information on web behaviour.

We use the following categories of cookies:

Strictly Necessary Cookies: These cookies are essential for Site functionality.

Performance Cookies: These cookies help us understand Site usage and improve user experience.

Functionality Cookies: These cookies remember user preferences to provide a tailored experience.

Information storage

Personal data is retained for the duration of the relevant contract and a reasonable period thereafter. Otherwise, it is retained for a maximum of two years or as required by applicable laws.

Yourrights

You have various rights regarding your personal data under applicable law. These rights include accessing, correcting, erasing or restricting the processing of your personal data. You can also request data transfers, object to processing or withdraw consent. Some limitations may apply based on legal requirements.

For inquiries or to exercise your rights, contact Astute Healthcare Limited’s data protection personnel (hr.astute@astutehealthcare.co.uk). If concerns remain unresolved, you can lodge a complaint with the relevant data protection authority.

Changes to this Notice

This Notice may be updated periodically. Revised versions will be posted on this page, and changes may be communicated as appropriate. Regularly reviewing this Notice ensures awareness of our data collection, use, and sharing practices. For inquiries or further information, please contact Astute Healthcare Limited’s data protection personnel using the provided contact details.