SANOFI Corporate Privacy Policy for Health Care Professionals

Last updated: November 13, 2023

Our commitment

SANOFI fully understands the importance of privacy and the protection of Personal Data in the digital era and is committed to ensure an adequate level of data protection for all Health Care Professionals (“HCPs”) with whom SANOFI interacts. 

What will you find in this document?

This Privacy Policy (“Policy”) describes the activities carried out by SANOFI requiring the use of Personal Data of HCPs. The objective of this Policy is to explain why SANOFI processes your Personal Data and the measures it implements to protect such Personal Data. 

Personal Data means any information that relates to an individual (‘Data Subject’) which directly or indirectly identifies him/her.

This Privacy Policy does not describe the cookies used in our website(s). To know more, please refer to our cookies policy available in the banner of our websites.

SANOFI’s role

For the purposes of this Policy SANOFI means SANOFI and its affiliates, acting as data controllers either independently or jointly. Please note that in order to exercise your rights or ask any question, you should reach the Affiliate in your country or use the form available here.

Each specific privacy notice shall set out which SANOFI entity determines for what reasons (i.e. the purposes) your Personal Data is processed as well as the resources (i.e. the means) allocated to such processing.

Validity and evolution of this policy

This Policy may be modified by SANOFI, from time to time, in particular to reflect changes in applicable legislations and / or in SANOFI’s practices. Changes will be available on this page. We invite you to check this Policy periodically.

This Policy is a Global Privacy Policy which explains SANOFI’s processing activities regarding Health Care Professionals. It is subject to local adaptations and translations in order to comply with any applicable law. In the event that this Privacy Policy for HCPs contradicts the Local Privacy Policy for Health Care Professionals, the provisions of the Local Privacy Policy for Health Care Professionals shall prevail.

List of activities requiring SANOFI to process Personal Data of Health Care Professionals

In the context of your various dealings and relationships with SANOFI, SANOFI may process your Personal Data or the various purposes set out below. 

Purpose 1: SANOFI may process your Personal Data to send Commercial Marketing & Services Communications and Medical Communications Campaigns

If you consent to such processing, SANOFI will process your Personal Data to be able to send personalized content to you, to offer personalized services to you and adapt its interactions you will have with us (hereinafter “Communication Campaigns”).

The consent that you will provide for Communication Campaigns covers digital or mailing from SANOFI, whether promotional, commercial or medical content. This purpose does not cover the direct exchanges you may have with sales representatives or medical scientific liaisons, which are addressed further in the document. 

You are entitled, at any time, to withdraw your consent to receive all or part of this Communication covered in this purpose and exercise your data protection rights.

During each interaction that you have with SANOFI (digital, phone, in person, etc.), you can unsubscribe, exercise your rights or withdraw your consent for this activity of Communication.

Tracking technologies or click rating are placed on our communications to ensure the content provided is of interest for you.

In accordance with the Agreement signed between SANOFI's entities, your local SANOFI entity is responsible for: (i) the provision of specific information to you on each processing, (ii) the collection of your consent where needed and (iii) the management of your requests seeking to exercise your data protection rights.

Where does the data come from?

The personalization of such content, services and interactions uses several sources, such as the interactions you have with medical scientific liaisons or Sales Representatives, your reactions on our digital communications, your participation to events, our contractual relationships with you. These data can be collected in various contexts and are gathered to build adequate profiles to ensure we provide you with adequate content, based on your interests, preferences and specialty. These data may also be collected from partners or vendors who provide your Personal Data where duly authorized.

The communication campaigns are adapted to your interests through data management processes, explained further below.

How long is the data processed for the sending of Communication Campaigns?

Your Personal Data will not be used for this purpose if you withdraw your consent or if the data is deleted from our data management systems (usually 3 years after our last interaction with you).

Means of processing

Algorithms and automated systems may be used to send our Communication Campaigns.
SANOFI may use online spaces made available by social media and third-party websites to communicate adapted content, according to your profile and interests on these specific social media. In such a context, SANOFI will not be able to identify you in the framework of this activity: SANOFI will not have knowledge of who is receiving the communications but will only be providing to social media the type of profiles to which the communication is adapted and made for. If you wish to avoid such communications through advertisement spaces on social media, please make sure to customize your settings in such social media.

Purpose 2: SANOFI may process your Personal Data to ensure proper data management and handle Customer Relationships Management

In order to be able to adapt its interactions with you, SANOFI processes your Personal Data to build adequate profiles according to your interests, scopes, preferences and specialty. This processing is based on legitimate interests since it permits to ensure a solid relationship with you and adapt our interactions.

Your Personal Data (identity, specialty, country, topics of interest, engagement towards SANOFI) is processed by algorithms to:

  • Understand your professional interests in our content, communications, products and services
  • Match your interests, specialty and country with one or several of existing groups of Health Care Professionals profiles
  • Adapt our content and formats of the communications with you to make them more efficient and adapted to your needs and preferences as well as to present you products and offers tailored to you

In accordance with the Agreement signed between SANOFI's entities, your local SANOFI entity is responsible for: (i) the provision of specific information to you on each processing, (ii) the collection of your consent where needed and (iii) the management of your requests seeking to exercise your data protection rights.

Where does the data come from?

Interactions that you have with SANOFI with medical scientific liaisons or Sales Representatives, your reactions on our digital communications, your participation to events, our contractual relationships with you are registered in our data management systems. 
These data can be collected in various contexts and are gathered to build adequate profiles to ensure we provide adapt our interactions with you to your interests, preferences and specialty. These data may also be collected from partners or vendors who provide your Personal Data where duly authorized.

How long is the data processed for the customer relationship management?

Your Personal Data will be processed as long as SANOFI has interactions with you. Your Personal Data will usually not be kept longer than 3 years after our last interaction with you, except where justified by applicable laws or judicial claims.

Means of processing

Algorithms and automated systems may be used to build profiles and manage Personal Data in our CRM tools. Where we resort to such tools, they help us identify data subjects based on professional data such as publications, specialties or subspecialities.

Purpose 3: SANOFI may process your Personal Data in the context of Sales Representatives Activities

SANOFI's Sales Representatives carry out visits to provide promotional information or get your feedbacks on specific disease, SANOFI's product or, more generally, your specialty and your needs.

This activity is based on the legitimate interests of SANOFI, as SANOFI needs, as a company to ensure promotional activities and ensure to collect feedbacks to gather its customers’ needs and improve its quality of services and products.

How long is the data processed for this purpose?

Your Personal Data is processed for this purpose as long as SANOFI is able to justify its legitimate interests and that you do not object to such as processing.

Who can access your Personal Data?

The feedback that is collected through our Sales Representatives is used to improve our products and services in the framework of the next visits. The feedback is also taken into account, where you provided consent for receiving Communication Campaigns, to provide you personalized content, services and interactions in the future.

Data Management and Segmentation as described above is also used, as a source and as a destination of the data processes in the framework of Sales Representatives’ visits.

Purpose 4: SANOFI may process your Personal Data in the context of Medical Scientific Liaisons activities

SANOFI's Medical Scientific Liaisons carry out visits to provide medical information or get your feedbacks on specific disease, more generally, your specialty and your needs.

This activity is based on the legitimate interests of SANOFI, as SANOFI needs, as a company to ensure medical knowledge of the Health Care Professionals and make them aware of the last medical improvements, studies and research, as well as collecting their opinions, feedbacks and needs.

The feedback is also taken into account, where you provided consent for receiving Communication Campaigns, to provide you personalized content, services and interactions in the future. 

How long is the data processed for this purpose?

Your Personal Data is processed for this purpose as long as SANOFI is able to justify its legitimate interests and that you do not object to such as processing.

Who can access your Personal Data?

The feedback that is collected through our Medical Scientific Liaisons are used to adapt our medical improvements and strategies to the actual needs as well as to decide the next MSLs visits that may be of interest for you. 

Purpose 5: SANOFI may process your Personal Data in the context of Mapping

This processing activity is based on SANOFI's legitimate interests. Indeed, in order to improve SANOFI's knowledge on health care medical trends and progress, SANOFI studies the latest research, improvements, conferences and the HCPs involved in such events, using data publicly available on such events, as well as data already obtained in passed interactions between SANOFI and HCPs.

This information is used to build a dataset to map the medical progresses and projects and the HCPs involved in such progresses or projects. This dataset also comprises Personal Data about the HCPs such as their identification and contact details, professional biographical data such as the publications, characteristics of clinical trials HCP has been involved in, research grants, attendance to advisory boards, academic positions, honors and awards, etc.

This information is related to the data SANOFI has related to your past, current and future engagements and interactions with us or with our Partner Regeneron and other alliance partners with whom we collaborate.

The feedbacks that are collected through our Medical Scientific Liaisons are used to adapt our medical improvements and strategies to the actual needs as well as to decide the next MSLs visits are of interest for you. 

Those feedbacks can also be taken into account, where you provided consent for receiving Communications Campaigns, to provide you personalized content, services and interactions in the future. 

How long is the data processed for this purpose?

Your Personal Data is processed for this purpose as long as our scientific focus will remain consistent with your areas of research and that you do not object to such as processing.

Purpose 6: SANOFI may process your Personal Data in the context of Medical Tiering

According to your country, this purpose can be based on SANOFI's legitimate interests, in order to comply with a legal obligation, based on your consent or in order to prepare or perform an agreement with you.

Where SANOFI is engaging with you, it has the duty to fee your services according to the fair market value. This process stems from legal obligations in some countries, codes of conduct to which SANOFI is signatory or based on good market practices, notably regarding the ethics and business integrity standards of SANOFI.

In order to comply with the above-mentioned rules and thus be able to contract with HCPs, SANOFI processes Personal Data about the HCPs such as their identification and contact details, professional biographical data such as the publications, characteristics of clinical trials HCP has been involved in, research grants, attendance to advisory boards, academic positions, honors and awards, etc.

This processing will allow SANOFI to match such data with the object of the engagement with you and determine the fair market value for the fees.

This information is related to the data SANOFI has related to your past, current and future engagements and interactions with us.

Purpose 7: SANOFI may process your Personal Data in the context of Transparency and Ethics

Where SANOFI is engaging with you or wishes to engage with you, SANOFI has the duty to ensure there is no ethical or business integrity concern related to such engagement. This concern also leads to transparency, and notably public or non-public disclosure of information related these engagements. This duty stems from legal obligations in some countries, and codes of conduct to which SANOFI is signatory or based on good market practices in other countries.

These Ethical and Business Integrity principles include anti-bribery & corruption and handling conflicts of interests. They conduct internal policies and behaviors within SANOFI as well as our interactions with external stakeholders, including HCPs.

In order to comply with these rules, HCPs Personal Data can be processed in the framework of due-diligence or precontractual measures, as well as public or non-public disclosure. In accordance with the Agreement signed between SANOFI's entities, your local SANOFI entity is responsible for: (i) the provision of specific information to you on each processing, (ii) the collection of your consent where needed and (iii) the management of your requests seeking to exercise your data protection rights.

Where does the data come from?

The Personal Data used to comply with these standards can be collected directly through you, via publicly available information or through a third party duly authorized to.

How long is the data processed for this purpose?

The Personal Data is kept as long as necessary to comply with the obligation of being able to evidence of all implemented transparency and Ethics and Business Integrity processes.

Purpose 8: SANOFI may process your Personal Data in order to provide you with medical information

Where you use or purchase a product or a service from SANOFI, SANOFI is obliged by Law to provide you proper assistance and information related to these products or services.

1. Answer a request you address (e.g. helpline to HCP)

 HCPs can submit to SANOFI practical medical questions related to SANOFI's products or services, in order to ensure proper administration, storage or prescription of such products and services.  

In order to be able to answer the asked question, SANOFI General Medical Information teams collect and process the Personal Data that is necessary to address the request.

The data used is the data related to our contractual relationships if any and the data that you directly provide in this framework. No further use will be done with the data collected in such a context. The data concerning the question is kept as long as necessary to be able to evidence the answer has been provided.

2. Dear Healthcare Provider Letter

In order to ensure the proper and safe administration and prescription of its products within the framework of medical and clinical studies, SANOFI communicates with Health Care Professionals acting as investigators of these studies. 

These communications can relate to product label change, package change, safety concerns, etc. The use of Personal Data is necessary to enable these communications.

This Personal Data is collected directly from Health Care Professionals when they are appointed as investigators for a study. It is collected either by SANOFI directly, or by a service provider acting on behalf of SANOFI. 

This Personal Data is kept as long as necessary to evidence the sending of information from SANOFI to Health Care Professionals. 

Purpose 9: SANOFI may process your Personal Data for Pharmacovigilance and Safety management

SANOFI has the legal obligation to process Personal Data to address safety concerns, notably during the management of an adverse event which may be reported.

This data relates to all the adverse event’s elements, as well as contact details to enable SANOFI to contact you in the future for further inquiries related to this adverse event.

This data will not be used for any other purpose, and it will be kept for as long as required by applicable law. 

Purpose 10: SANOFI may process your Personal Data for the management of our contractual relationships

In the framework of the contractual relationships that SANOFI has with  HCPs, whether it is to provide a service to an HCP or to receive a service from an HCP, SANOFI processes HCPs’ Personal Data to perform the contract.

The data collected and processed in the course of our relationships can be reused, if you have granted your consent, for Communication Campaigns purposes.

This activity includes the management of finance and accounting activities as well as the fight against fraud, notably, data used to authenticate you, data to process payments, verify your financial information or facilitate further payments. This financial data is also used, in a second stage to comply with SANOFI's transparency duties. When we need to confirm financial information or to verify licensure, we generally receive Personal Data from third parties that are authorized to share it with us in the framework of their own privacy and data protection policies or in accordance with the law.

How long is the data processed for this purpose?

The data is kept as long as the contract is valid and kept afterwards for as long as any judicial action is no longer possible (statutory limitations).

Our websites and applications

Your navigation data, sometimes linked with your account data, will be used to improve our websites or applications. Specific consents related to cookies and other tracking technologies placed on our websites and applications are requested from you according to applicable Law.

For instance, certain contents/services are restricted to Health Care Professionals and therefore, SANOFI has to verify your credentials including via passwords, password hints, security information and questions, government-issued ID, healthcare professional number, driver’s license data, and passport data.

Subscription to a service such as access to a specific content via a SANOFI website or application includes the processing of data necessary to provide the service, since a contractual relationship exists.

Moreover, data related to your navigation, revealing as well your preferences will be reused for Communication Campaigns if you consented for it.

Organization of events

Where you register or you participate to an event organized by SANOFI, your Personal Data will be processed to allow you to receive the invitation or information related to this event and to ensure the proper participation and attendance to such event. 
Generally, these events are followed with non-mandatory surveys.

Personal Data, feedbacks and interests expressed during the event or after the event can be reused for Communication Campaigns purposes if you have granted your consent for such use.

Purpose 11: SANOFI may process your Personal Data to address legal requests

Data related to HCPs can be processed to respond to legal requests from administrative or judicial authorities, in accordance with applicable Law, to comply with a subpoena, a required registration, or a legal process. This purpose is based on SANOFI's legal obligations.

Purpose 12: SANOFI may process your Personal Data in the context of market research

SANOFI may use your Personal Data to carry out market research or to provide such Personal Data to market research agency so that they can contact you to be part of the participants. 

This processing is based on legitimate interests of SANOFI as market research permit to address global opinions of Health Care Professionals, on a service, a product or a disease, and permit to SANOFI to collect these opinions at high level, get aggregated datasets to adapt its strategy.

Your contact details can be part of a participation list that SANOFI can send to certain market research agency, according to the scope of such market research. You can object to being into these lists at any time (see “How to contact us” section).

Recipients of the data

Only persons with a need-to-know to perform the activity have access to the Personal Data processed. SANOFI imposes to third party adequate contracts to protect the Personal Data, according to applicable data protection law. These recipients can include:

  • SANOFI and its affiliates
  • Our partners (distributors, other members of the healthcare and pharmaceutical industry)
  • Selected suppliers, service providers or vendors acting upon our instructions
  • Legal or administrative authorities, as required by applicable laws including laws outside your country of residence
  • Potential acquirers and other stakeholders in the event of a merger, legal restructuring operation such as, acquisition, joint venture, assignment, spin-off or divestitures
  • Sponsors of sweepstakes, contests and similar promotions

Besides, additional content regarding certain types of recipients of Personal Data may be provided directly within the different purposes’ sections.

International Transfers of Data

SANOFI is a multinational organization with affiliates, partners and subcontractors located in many countries around the world. For that reason, SANOFI may need to transfer (via access, visualization, storage..) your Personal Data in other jurisdictions, including from the European Economic Area to outside the European Economic Area, in countries which may not be regarded as providing the same level of protection as the jurisdiction you are based in. In cases where SANOFI needs to carry out an international transfer of Personal Data, it shall ensure that adequate safeguards, as required under applicable data protection legislation, will be implemented (including, notably, the European Commission’s Standard Contractual Clauses, as applicable).

In this respect and in particular, for intra-group transfers of Personal Data implemented for clinical studies and pharmacovigilance purposes, SANOFI has implemented and shall apply its “Binding Corporate Rules” validated by the EU Data Protection Authorities. For other purposes, SANOFI implements internal agreements between SANOFI's entities to cover these transfers.

Is the collection of this data mandatory or optional?

SANOFI must process your Personal Data to fulfill the purposes listed above. 

The collection of some Personal Data is necessary to comply with our obligations toward you or toward administrative or judicial authorities.

Further processing

We do not intend to process Personal Data for any other purpose that is listed in this Privacy Policy. However, should processing of Personal Data for purposes other than those for which the Personal Data was initially collected occur, we will comply with the requirements pursuant to applicable laws.

Security measures

SANOFI has implemented a variety of technical and organizational procedures and measures to ensure the integrity and confidentiality of your Personal Data from unauthorized access, use and disclosure. These measures take into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons.

For instance, we store your Personal Data on servers that have various types of technical and physical access controls, which may include, for instance, if appropriate, encryption. We may also aggregate, pseudonymize or anonymize Personal Data to ensure that no personally identifiable information is communicated to third parties.

Your Privacy and Data Protection rights

You may, where required by applicable law and subject to limitations which may apply by exceptions or legal requirements, be entitled:

  • To have access upon simple request to your Personal Data. You may receive a copy of such data; unless it is directly available to you, for instance within your personal account
  • To obtain a rectification of your Personal Data if inaccurate, incomplete or obsolete
  • To obtain the deletion of your Personal Data in the situations set forth by applicable data protection law (‘right to be forgotten’)
  • To withdraw your consent, at any time, for the activities without affecting the lawfulness of the processing where your Personal Data is used on the basis of your consent
  • To object to the processing of your Personal Data, where your Personal Data has been used on the basis of legitimate interests of SANOFI, in which case you will need to justify your request by explaining to us your particular situation
  • To request a limitation of the data processing in the situations set forth by applicable law
  • To request that some of the Personal Data you provided to us is brought to you, or to another data controller, in a commonly used, machine-readable format

While we suggest that you contact us beforehand, you are entitled to lodge a complaint with your local Data Protection Authority regarding the processing of your Personal Data.

If you would like to exercise any of these rights, please contact us as described in the “How to Contact Us” section below.

How to contact us?

SANOFI welcomes any questions or comments you may have regarding this Policy or its implementation. Any such questions or comments should be submitted using the contact form.

For US Residents

Sanofi US (Sanofi-Aventis U.S. LLC and Sanofi US Services Inc.) respects the interest that visitors to our websites have in understanding what information is collected electronically, how it is collected, to whom it is or may be disclosed and how it is used. Sanofi US has developed this online privacy policy to address those questions. 

State-Specific Privacy Policy

If you are a resident of certain U.S. states, including California, Colorado, Connecticut, Virginia, or Utah, you may be entitled to additional rights and disclosures, depending on the law of your state.