Privacy Notice
Nabriva Therapeutics GmbH (in this Privacy notice referred to as “Nabriva”, “us”, “we” and “our”) respects your privacy and is committed to protecting personal data. This Privacy Notice explains how particular we collect, use and disclose your personal data when you visit our website (regardless of where you visit it from) and explains your rights in relation to the personal data we hold.
1. Controller
Nabriva is the controller and responsible for this website.
Nabriva is part of a clinical-stage biopharmaceutical group with locations in the United States (King of Prussia, PA), Austria (Vienna), and Ireland (Dublin) and is subject to the EU General Data Protection Regulation 2016/679 (“GDPR”) and any locally applicable data protection laws. The Nabriva group is engaged in the research and development of novel antibiotics to treat serious infections, with a current focus on the pleuromutilin class of antibiotics.
2. Third-Party Links
This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit.
3. Your rights
Under the GDPR you have the following rights:
- To obtain access to, and copies of, the personal data that we hold about you;
- To require that we cease processing your personal data if the processing is causing you damage or distress;
- To require us not to send you marketing communications;
- To require us to erase your personal data;
- To require us to restrict our data processing activities;
- To object to processing your personal data;
- To receive from us the personal data we hold about you which you have provided to us, in a reasonable format specified by you, including for the purpose of you transmitting that personal data to another data controller;
- To require us to correct the personal data we hold about you if it is incorrect.
- Where processing is based on the individual's consent, the right to withdraw that consent at any time;
- To lodge a complaint with the supervisory authority;
Please note that the above rights are not absolute, and we may be entitled to refuse requests where exceptions apply.
You can find out more about your rights at the Austrian Data Protection Authority (www.data-protection-authority.gv.at).
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, retentive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
4. Contact Details
If you have any questions about how we use your personal data, or you wish to exercise any of the rights set out above, please contact us using the following:
By post Nabriva Therapeutics GmbH, Leberstrasse 20, 1110 Vienna, Austria
By email privacy@nabriva.com
By telephone +43 1 74393 – 0
If you are not satisfied with how we are processing your personal data, you can make a complaint by using one of the above mentioned contact details or by contacting the Austrian Data Protection Authority.
5. How we collect your data
We use different methods to collect data from and about you including through:
- Direct Interactions: You may give us your personal data by filling in forms or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you apply for our products or services, apply for a job, subscribe to our service or publications, request marketing to be sent to you, enter a competition, promotion or survey or give us some feedback. In this respect, we may monitor, record and store any such communication;
- Information obtained from publicly available sources such as the internet, filings on stock exchanges, commercial or company registers such as the Companies Registration Office in Ireland and similar public sources;
- Information received from clients or third parties as part of the service we provide to you or in connection with a legal requirement that applies to us. By way of example, this might apply where information is requested or obtained from you or your agent, adviser or intermediary because you are a director, shareholder or possible beneficial owner of a company connected to us or a (prospective) client of ours; and/or
- Automated technologies or interactions: As you interact with our website, we may automatically collect Technical Data about your equipment, browsing actions and patterns by using for example Google reCAPTCHA. We do not collect data about you by using cookies and other similar technologies.
6. The categories of personal data we collect
We may collect, use, store and transfer different kinds of personal data about you to carry out our products and / or services under a contract, recruitment and selection of employees and intermediaries, getting in contact with you, process Grant Request Forms and to subscribe you to our email alerts, which we have grouped together as follows:
Identity Data includes first name, maiden name, last name, username or similar identifier, marital status, title, date of birth, tax ID, ID card number, passport number, drivers license number, license plate number, gender;
Contact Data includes billing address, delivery address, email address and telephone numbers;
Financial Data includes income, possessions, investments, total income, professional income, savings, start and end dates of investments, investment income, debts owed on assets;
Background Data includes overview of schools, institutions, colleges, and universities attended, nature of the completed courses, diplomas or certificates pursued, exam results, other diplomas awarded, evaluation of study progress, job titles, Professional interests, research interests, academic interests, specializations, teaching experience, consultations;
Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website;
Profile Data includes your interests, preferences, feedback and survey responses;
Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.
We do not collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data), unless you voluntarily provide us with such Special Categories of Personal Data by including it in your job application.
Nor do we collect any information about criminal convictions and offences.
7. How we use your personal data
We process your personal data because it is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract. In this respect, we use your personal data to provide you with the services as set out in our terms of service with you or as otherwise agreed with you from time to time, to prepare a proposal for you regarding the services we offer, to deal with any complaints or feedback you may have or any other purpose for which you provide us with your personal data.
We also process your personal data because it is necessary for our legitimate interests, or sometimes where it is necessary for the legitimate interests of another person or for our compliance with a legal obligation which we are under by using your personal data to meet our compliance and regulatory obligations, such as compliance as required by tax authorities or any competent court or legal authority.
In this respect, we use your personal data for the following:
Purpose/Activity
|
Type of data
|
Lawful basis for processing including basis of legitimate interest
|
To publish your publication on our website
|
(a) Identity
(b) Contact
(c) Background
|
Performance of a contract with you
|
To process your inquiries
|
(a) Identity
(b) Contact
(c) Marketing and Communications
|
(a) Performance of a contract with you
(b) Necessary for our legitimate interests (to develop our products/services, to grow our business and to develop our marketing strategy; for customer administration)
|
To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)
|
(a) Identity
(b) Contact
(c) Technical
|
(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganization or group restructuring exercise)
(b) Necessary to comply with a legal obligation
|
To process your job application in connection with a recruiting process
|
(a) Identity
(b) Contact
(c) Background
(d) Technical
(e) Profile
|
(a) Performance of a contract with you
(b) Necessary for our legitimate interests (to match applicants with the requirements for a vacant job position in the company)
|
To process your grant request and to verify if funding can be provided
|
(a) Identity
(b) Contact
(c) Financial
(d) Background
(e) Technical
(f) Profile
|
(a) Performance of a contract with you
(b) Necessary for our legitimate interests (to match requestors of grants with the requirements for granting a grant and to approve or reject the grant)
|
To send you a newsletter or updates about our products and services
|
(a) Identity (limited to first and last name)
(b) Contact (limited to email address)
|
Necessary for our legitimate interests (to develop our products/services and grow our business – including creating goodwill for the organization)
|
Marketing
With your express opt-in consent we may send you marketing about similar services we provide, as well as other information in the form of alerts, newsletters and invitations to events or functions which we believe might be of interest to you.
Third-Party Marketing
We will get your express opt-in consent before we share your personal data with any company outside Nabriva for marketing purposes.
Opting Out
You can ask us or third parties to stop sending you marketing messages by contacting us at any time via the contact details provided in point 4. above.
8. Disclosure of your personal data
We may share the personal data that we collect with our corporate affiliates and third parties operating on our behalf. We will only share personal data with companies that are required to protect personal data in accordance with relevant laws, regulations and rules, and subject to any appropriate security measures and directions from us.
In this respect, we may share your personal data with or transfer it to the following:
- Third parties whom we engage to assist in delivering the services to you, including other companies or our professional advisers where it is necessary for us to obtain their advice or assistance, including lawyers, accountants, IT or public relations advisers;
- Other third parties such as intermediaries who we introduce to you. We will wherever possible tell you who they are before we introduce you; and/or
- Our data storage providers.
In respect of processing your personal data for our compliance with a legal obligation we will share your personal data with the following:
- Our advisers where it is necessary for us to obtain their advice or assistance;
- Our auditors where it is necessary as part of their auditing functions;
- With third parties who assist us in conducting background checks; and/or
- With relevant regulators or law enforcement agencies where we are required to do so.
9. Transfer and processing of your personal data outside the European Union
When sharing your personal data with third parties as set out in this Privacy Notice, it may be transferred outside the European Union. In these circumstances, your personal data will only be transferred on one of the following bases:
- the country that we send the personal data to is approved by the European Commission as providing an adequate level of protection for personal data;
- the transfer is to a recipient in the United States of America who has registered under the EU/US Privacy Shield;
- the recipient has entered into European Commission standard contractual clauses with us; or
- you have explicitly consented to the same.
To find out more about transfers by us of your personal data outside the European Union and the countries concerned please contact us using the details provided via the contact details provided in point 4. above.
10. Retention of your data
We will only retain your personal data for as long as we have a lawful reason to do so. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
Details of the retention period for different aspects of your personal data are set out in the table below.
Purpose/Activity
|
Retention Period
|
To publish your publication on our website
|
No longer than 3 years following the termination of the contractual relationship
|
To process your inquiries
|
For no longer than 3 years after your inquiry has been duly processed
|
To manage our relationship with you which will include:
(a) Notifying you about changes to our terms or privacy policy
(b) Asking you to leave a review or take a survey
|
For no longer than 3 years
|
To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)
|
For no longer than 3 years
|
To process your job application in connection with a recruiting process
|
For the duration of the recruiting process and in case of a rejection no longer than 6 months following the receipt of the job application being rejected
|
To process your grant request and to verify if funding can be provided
|
If the request has been granted, for the duration of the project and in case the request has been rejected no longer than 3 years following the receipt of the rejection
|
To send you a newsletter or updates about our products and services
|
Until your objection to further receive newsletter or updates
|
11. Changes to the Privacy Notice and your duty to inform us of changes
This version was last updated on 24MAY2018 and historic versions can be obtained by contacting us.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.