Privacy Policy

Identity of the Data Controller

“Data controllers” are the people or organisations that determine the purposes for which, and the manner in which, any Personal Data is processed, and make independent decisions in relation to the Personal Data and/or who/which otherwise control that Personal Data. For the purposes of the GDPR, Nordic Pharma Ltd. is the data controller with regard to the Personal Data described in this Privacy Policy. Nordic Pharma Ltd. is based in the United Kingdom. Nordic Pharma Ltd. is a speciality pharmaceutical company focussed on ensuring healthcare professionals have access to innovative products that make a real difference to patients’ lives. In response to unmet medical needs, we pride ourselves on the development and commercialisation of niche products which are often outside the scope of larger companies. Our Data Protection Coordinator can be contacted as follows: Telephone: +44 (0)118 207 9160 Email: [email protected] Post: Nordic Pharma Ltd., Unit 3 Commerce Park, Brunel Road, Theale, Berkshire RG7 4AB, United Kingdom

Purpose and Scope of this Policy

The purpose of this Privacy Policy is to provide you, as our data subject, with a statement regarding the Data Protection and Privacy practices and obligations of Nordic Pharma Ltd. and an explanation of your rights as a data subject. This Data Protection and Privacy Policy and Notice applies to our business practices, our websites, which are accessible from https://www.nordicpharma.co.uk, https://nordimet.co.uk/, https://www.aprotinin.co.uk/ As the Organisation is established in the United Kingdom, this document is written in the vein of UK Data Protection Law, and Nordic Pharma Ltd. falls under the jurisdiction of the Information Commissioner’s Office. This Privacy Policy sets out what Personal Data we collect and process about you in connection with the services and functions of the Organisation. We are not responsible for the content or the privacy notices for any websites to which we may provide external links.

Laws that apply to us:

Why and how do we ensure compliance?

Data protection and privacy laws provide rights to individuals with regard to the use of their Personal Data by organisations, including our organisation. UK and EU laws on data protection govern all activities we engage in with regard to our collection, storage, handling, disclosure and other uses of Personal Data. We must comply with data protection and privacy laws because the law requires us to but we also would like you to have confidence in dealing with us, and compliance with data protection law helps us to maintain a positive reputation in relation to how we handle Personal Data. We are required to demonstrate accountability for our data protection obligations. This means that we must be able to show how we comply with the applicable data protection and privacy laws, and that we have in fact complied with the laws. We do this, among other ways, by our written policies and procedures, by building data protection and privacy compliance into our systems and business rules, by internally monitoring our data protection and privacy compliance and keeping it under review, and by acting if our representatives, including employees or contractors, fail to follow the rules. We also have certain obligations in relation to keeping records about our data processing.

Who must comply?

All our representatives, which include employees and contractors, are required to comply with our Data Protection and Privacy Policies, which includes this Privacy Policy, when they process Personal Data on our behalf. What are the data protection principles and rules? We aim to comply with the following principles found in Data Protection Law:

What types of personal data will we process?

Personal Data We will collect personal data from you in accordance with the purposes outlined in this document. This will be basic or regular personal data used to facilitate a consultant/client type relationship usually your name and email address and from time to time billing information. If you are a sole trader or partnership, we would consider your address to be personal data. Ways in which Nordic Pharma Ltd. may process your Personal Data. Special Category Personal Data We will not collect special category data from you in relation to your use of this website. Nordic Pharma Ltd. may process special category data when you are receiving nursing and medical care / services from us. Criminal Conviction Data We will not collect criminal conviction data from you. Children’s Personal Data Where consent is required to process your Personal Data as a child, we will obtain that consent from the adult who is authorised to give the consent on your behalf. You must be at least 18 years old to engage in activities and transactions on our digital and social media. By engaging in activities or transactions on our digital and social media, you affirm that you are at least 18 years old and are fully able to enter into and comply with our regular Terms of Use and this Privacy Policy and Notice. If we are notified or learn that a child has submitted Personal Data to us through our digital or social media without the correct permissions or consents, we will delete such Personal Data.

Who has access to or processes personal data?

Directors and Employees of the Organisation Directors and employees of the Organisation who are bound by confidentiality agreements will process personal data on behalf of the Organisation. Service Providers We may use trusted service providers who could be considered data processors, sub-processors or third parties. We need to have written agreements in place with all of our service providers and, before we sign each agreement, we need to have vetted and be satisfied with the service provider’s data security. The agreements also need to contain specific clauses that deal with data protection. We require all third parties to have appropriate technical and operational security measures in place to protect your Personal Data, in line with UK and EU laws on data protection. Any such organisation or individual will have access to Personal Data needed to perform these functions but may not use it for any other purpose. We may pass on your details if we are This includes reporting information about incidents (as appropriate) to the law enforcement authorities and responding to any requirements from law enforcement authorities to provide information and/or Personal Data to them for the purposes of them detecting, investigating and/or prosecuting offences or in connection with crime sentencing. Other than the above, or captured herein or in another agreement with you, we will not disclose personal information to any third party without your consent or prior knowledge except in incidences where an individual is potentially at risk or where the law requires it. Information on Consent By consenting, where this is the appropriate and identified grounds for processing, to our processing your Personal Data in line with this Data Protection and Privacy Policy you are giving us permission to process your Personal Data specifically for the purposes identified. You may withdraw consent at any time by providing an unambiguous indication of your wishes by which you, by a statement or by a clear affirmative action, signify withdrawal of consent to the processing of Personal Data relating to you. If you have any queries relating to withdrawing your consent, please contact our Data Protection Coordinator using the contact details set out below. Withdrawal of consent shall be without effect to the lawfulness of processing based on consent before its withdrawal. Your Rights Under certain circumstances, and dependent on legal basis under which your personal data is processed, by law you have the right to:

How do you exercise your rights?

We have appointed a Data Protection Coordinator to monitor compliance with our data protection obligations and with this policy and our related policies. If you have any questions about this policy or about our data protection compliance, please contact the Data Protection Coordinator. If you wish to exercise your rights please contact our Data Protection Coordinator who will respond to the request within 30 days. We are obliged to comply with exceptions to your requests where laid out in law. Such exceptions relate to health data, disclosures that would be likely to cause serious harm to your physical or mental health or emotional condition and opinions given in confidence. Our Data Protection Coordinator can be contacted as follows: Telephone: +44 (0)118 207 9160 Email: [email protected] Post: Nordic Pharma Ltd., Unit 3 Commerce Park, Brunel Road, Theale, Berkshire RG7 4AB, United Kingdom Your Right to Lodge a Complaint You as the Data Subject have the right to complain at any time to a supervisory authority in relation to any issues related to our processing of your Personal Data. We would like to hear from you first if you have a complaint about how we use your data so that we may rectify the issue. As our organisation is located in UK and we conduct our data processing here, we are regulated for data protection purposes by the Information Commissioner’s Office. You can contact the Information Commissioner’s Office as follows: Website: https://ico.org.uk/ Phone: +44 (0)303 123 1113 Email: See the website here https://ico.org.uk/global/contact-us/email/ Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom Updates This Privacy Policy was updated in December 2020 and is effective from 1st December 2020. Our practices as described in this Privacy Policy may be changed, but any changes will be posted, and changes will only apply to activities and information on a going forward, not retroactive basis. You are encouraged to review this Privacy Policy periodically to make sure that you understand how any personal information you provide will be used. We may also email you in certain circumstances to let you know if and when we update this Privacy Policy to ensure you are informed. Any changes to this Privacy Policy will be posted on this website so you are always aware of what information we collect, how we use it, and under what circumstances, if any, we disclose it. If at any time we decide to use Personal Data in a manner significantly different from that stated in this Privacy Policy, or otherwise disclosed to you at the time it was collected, we will notify you by email, and you will have a choice as to whether or not we use your Personal Data in the new manner.