Last updated April 2024, replaced the previous version
Why we collect and use your data
As our valued commercial prospect, client, vendor, interested business contact or otherwise representative of an organization we interact with (business contact), we may collect and use certain personal data from you. Depending on the business relationship we have with you and/or the organization you are working for, we may collect and use your data for the following purposes:
- Asses a potential business relationship and/or maintaining our business relationship with you or the organization you are working for (including customer relationship management, supplier management, investor relations management, and business partner qualification)
- Vendor assessment and qualification (e.g., whether you and your organization meet certain quality and certification requirements)
- Procurement of products and services from you or the organization you are working for
- Exchange of information related to existing contracts or potential future contracts with you or the organization you are working for
- Fulfill our contract with the organization you are working for, including the enforcement of any rights we may have under such contract
- Termination of contracts and agreements
- Fulfillment of compliance requirements related to a business transaction (e.g., conflict checks, business partner due diligence, sanction list screening, anti-money laundering laws, secure supply chain requirements, customs and export law requirements, tracing requirements for products)
- Manufacture and quality management of products
- Provide and deliver products and services
- Marketing (e.g., informing you about products and services or related information)
- Carry out surveys to understand customer requirements in more detail
- Relationship administration and key account management including external communication and public relationship
- Assess and categorize which specific business needs match best with your abilities (e.g., when we look for a key opinion leader in a certain field or for specific products, the extent you belong to the group of scientific input providers, based on scientific or professional experience) or if you can influence in your professional capacity, the use, purchase, ordering, prescribing or recommendation of Fresenius Kabi products, or affect tender decisions, formulary placement, award status or other preferential or qualifying status of Fresenius Kabi products in accordance with applicable law
- Finance and accounting, invoicing, payment collection and reporting
- Assess your company’s financial solvency and credit risk
- Assess potential investments in Fresenius shares, a potential acquisition, divestiture or joint venture transaction with us or any Fresenius Kabi affiliate
- Improve our products and services
- Organize, secure and improve internal processes including communication, administration, research and IT
- Develop, provide, support and maintain IT infrastructure and solutions
- Security analysis of our IT systems, to protect the confidentiality, availability, integrity of the data and systems
- Facilitate mergers, acquisitions and re-organizations.
What data we collect and how we do that
We collect and use your personal data in the following ways:
Information you provide to us
We may collect your personal data when you contact us, order our products and services or enter into a contract with us for the supply of goods and services. Such personal data include:
- First and last name
- Gender
- Contact and address information, including address, e-mail address, phone number, fax number
- Country of residence
- Role and function in your organization
- Your areas of expertise
- Your profession and qualifications
- Information on the kind of a relationship you have with Fresenius Kabi
- Employer name and employer address
- Contact preferences
Information we collect from other organizations
We may process data that is provided to us by contracted service providers, by competent authorities or obtained from publicly accessible trade registers or trade associations and other publicly available sources, including rating agencies, financial solvency, risk information and financial service agencies and institutions, government or supranational agencies, in particular tender authorities or procurement agencies, data brokers, websites, blogs and printed media. Such personal data may include:
- First and last name
- Contact and address information (e.g., address, e-mail address, phone number, fax number)
- Organization / Company
- Your organization’s bank accounts
- Your profession and qualifications
- Professional identifiers
- Organizational details, affiliation details of your company
- Certifications and quality statements issued by your organization’s officers, representatives or auditors
- Percentage of shares held
- Details related to public filings, trade registers and professional boards
- Details related to published transactions of your organization including tenders and financial arrangements
- Details related to specially designated nationals or blocked persons lists
- Previous interactions with Fresenius Kabi and any of our subsidiaries.
Profiling and automated decision making
An automated decision making (e.g., in the EU Art. 22 GDPR) occurs according to our obligation to conduct a sanction-control-procedure. Within this procedure we check if you, or your organization is listed on an official published sanctions list applicable to the business transaction or relation you have with us. This is necessary for entering into, or performance of, a contract between you and us. The consequence of this can be the refusal to enter into a contractual relationship with you.
We create profiles in our systems, that enable us to assess and categorize which specific business needs match best with your abilities (e.g. when we look for a key opinion leader in a certain field or for specific products, the extent you belong to the group of scientific input providers, based on scientific or professional experience) or if you can, in your professional capacity, influence the use, purchase, ordering, prescribing or recommendation of Fresenius Kabi products, or affect tender decisions, formulary placement, award status or other preferential or qualifying status of Fresenius Kabi products in accordance with applicable law
Legal basis to collect, use and share your data
Depending on the business contact we have with you and the purposes we collect and use your data, we process your personal data on one or more of the following legal bases:
- The processing of your personal data is necessary for the performance of a contract (to be) concluded between you and us (e.g., in the EU Art. 6.1 b GDPR)
- The processing of your personal data is necessary for us to comply with a legal obligation we are subject to (e.g., in the EU Art. 6.1 c GDPR). More specifically we are obliged to comply with laws on anti-money laundering, customs and export, secure supply chain requirements, product tracing requirements, statutory disclosure and notification requirements or similar compliance requirements that might require us to process certain of your personal data
- The processing is necessary for purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data (e.g., in the EU Art. 6.1 f GDPR). These legitimate interests are:
- Investigate your interests for a potential business relationship and/or maintaining our business relationship with you or the organization you are working for
- Fulfilling our contract with the organization you are working for, including the enforcement of any rights we may have under such contract
- Gather information and knowledge management related to the interests in and satisfaction about internal processes, products and services
- Development, optimization and improvement of our products and services
- Optimization of internal communication
- Optimization of administration
- Carrying out research work
- Organizational management
- Risk Management: safeguarding against e.g., financial / reputational risks
- Maintenance of the IT infrastructure, IT security, guarantee of IT support and the detection and correction of errors
- Complying with legal requirements outside the EEA
- Establishment, exercise or defense of legal claims.
Requirements to provide personal data
You may need to provide your personal data to us for the purpose of fulfilling a contract with you or the organization you are working for, e.g., we might need your contact details if you are our business contact at a supplier. If you do not provide your personal data, we might not be able to enter into the respective contractual relationship.
With whom we share your data
Besides the general recipients as mentioned under With Whom We Share Your Data, we collaborate with professional data and analytics providers such as IQVIA, Veeva, CDQ and Acxiom to achieve our purposes.
How long we retain your data
We store your personal data for one of the following periods of time:
- Until the purpose of the data collecting and using is fulfilled, e.g. for the term of the contractual relationship with you or the organization you are working for. The exact period depends on the organization you are working for and your position in the company.
- As long as we have a duty to retain the data in line with applicable laws (e.g., because we are obliged to store the data for tax purposes)
- If longer retention periods apply after the time periods listed above (e.g., because we are obliged to store the data for tax purposes or civil or criminal proceedings where initiated) our aim also includes that the data will be blocked until the end of the respective retention period and then erased.