GDP Medical Info Questions Data Privacy Notice



Biocodex Oy

Metsänneidonkuja 8, P.O. Box 52, FI-02101 Espoo, Finland

+358 9 329 59100

(hereafter ”we” or ”Biocodex Oy”)

Contact person for register matters

Data Privacy Coordinator

Metsänneidonkuja 8, P.O Box 52, FI-02101 Espoo, Finland

+358 9 329 59100

Name of register


What is the legal basis for and purpose of the processing of personal data?

The basis for processing personal data is to fulfil the Biocodex business purpose, e.g. the legitimate interest of the company based on customer relationship or other connection or; the performance of a contract.

The purpose of the processing of personal data is;

  • The objective of the information given on a medicine is to maintain and promote the professional expertise of the healthcare professionals related to the use of medicines, as well as to promote patient safety.
  • The aim of the handling medical information questions is to provide accurate, up to date and timely information to customers
  • fulfilment of contractual obligations and other undertakings of the company,
  • national regulations for collecting and processing personal data
  • legistative regulations for collecting and processing personal data


What data do we process?

We process the following personal data of the customer or other data subject in connection with the customer register:

  • basic information of the data subject such as name*;
  • contact information of the data subject such as email address*, street address*;

Providing the information marked with a star is a prerequisite for our contractual relationship and/or customer relationship. We cannor deliver the requested information without the necessary information.

From where do we receive information?

We receive data primarily from the data subject himself and from the authorised personnel representing a relevant healthcare organisation, such pharmacy or hospital.

To whom do we disclose data and do we transfer data outside of EU or EEA?

We disclose information to the following parties:

We use subcontractors that process personal data on behalf of and for us. We have outsourced the IT-management to an external service provider, to whose server the data is stored. The server is protected and managed by the external service provider.

We do not disclose personal data outside of EU/EEA.

How do we protect the data and how long do we store them?

Only those of our employees, who on behalf of their work are entitled to process customer data, are entitled to use a system containing personal data. Each user has a personal username and password to the system. The information is collected into databases that are protected by firewalls, passwords and other technical measures. The databases and the backup copies of them are in locked premises and can be accessed only by certain pre-designated persons.

We store the personal data for as long as is necessary considering the purpose of the processing. According to the Good Distribution Practice (GDP (2013/C 68/01)) requirements, we store the data for six (6) years.

We regularly assess the need for data retention in light of the applicable legislation. In addition, we take reasonable measures to ensure that the personal data in the register is not incompatible, obsolete or inaccurate considering the purpose of the processing. We rectify or delete such information without delay.

What are your rights as a data subject?

As a data subject you have a right to inspect the personal data concerning yourself, which is stored in the register, and a right to require rectification or erasure of the data, provided that the request has a legal basis. You also have a right to withdraw or change your consent.

As a data subject, you have a right, according to EU’s General Data Protection Regulation (applied from 25.5.2018) to object processing or request restricting the processing and lodge a complaint with a supervisory authority responsible for processing personal data.

For specific personal reasons, you also have the right to object to profiling and other processing operations, when the processing of your data is based on our customer relationship with you. In connection with your request, you will need to identify the specific situation, based on which you object to the processing. We can refuse the request of objection only on legal grounds.

Who can you be in contact with?

All contacts and requests concerning this privacy notice must be submitted in writing or in person to the person mentioned in section two (2).

Changes in the Privacy Notice

Should we make amendments to this privacy notice we will place the amended statement on our website, with an indication of the amendment date. If the amendments are significant, we may also inform you about this by other means, for example by sending an email or placing a bulletin on our homepage. We recommend that you regularly visit out webpage and notice possible amendments to this privacy notice. review these privacy protection principles from time to time to ensure you are aware of any amendments made.