LUPIN PHARMA CANADA LTD. PRIVACY STATEMENT (“PRIVACY STATEMENT”)

Effective Date: May 9, 2024

You care about the protection of your Personal Information – and so do we. At Lupin Pharma Ltd. (“Lupin,” “we,” “us,” or “our”), we work to maintain the privacy and security of your Personal Information, including when you use the Lupin Pharma Canada Ltd. website (lupinpharma.ca), the Zaxine product website (Zaxine.ca), the Intrarosa product website (Intrarosa.ca) (collectively, the “Website”) or when you otherwise interact with us.

This Privacy Statement (“Statement”) applies to Personal Information that Lupin collects, uses, or shares, including when you visit our Website. This Statement only applies to residents of Canada.

Please read this Statement carefully. Should you have any questions about this Statement or how we handle Personal Information, please contact us at complianceandethicsoffice@lupin.com

WE MAY MODIFY THIS STATEMENT AT ANY TIME. ALL CHANGES WILL BE EFFECTIVE IMMEDIATELY UPON POSTING TO THE WEBSITE. MATERIAL CHANGES WILL BE CONSPICUOUSLY POSTED ON THE TOP OF THIS STATEMENT, ON THE WEBSITE OR OTHERWISE COMMUNICATED TO YOU.

PLEASE SEE SECTION 14 BELOW FOR INFORMATION ABOUT YOUR DATA PRIVACY RIGHTS.

FOR QUEBEC RESIDENTS: IN ADDITION TO THE RIGHTS IN SECTION 14 BELOW, PLEASE SEE SECTION 15 BELOW FOR INFORMATION ABOUT ADDITIONAL PRIVACY RIGHTS THAT MAY APPLY TO YOU AS A RESIDENT OF QUEBEC.

IF YOU PROVIDE PERSONAL INFORMATION WITH REGARD TO OUR PHARMACOVIGILANCE PROGRAM, PLEASE SEE OUR PHARMACOVIGILANCE PRIVACY STATEMENT AT http://www.lupinpharma.ca/privacy WHICH DESCRIBES HOW WE COLLECT, USE AND SHARE PERSONAL INFORMATION YOU PROVIDE OR RECEIVE IN CONNECTION WITH THAT PROGRAM.


  1. WHAT INFORMATION DOES THIS PRIVACY STATEMENT COVER?

    This Statement applies to Personal Information of Canadian residents that Lupin collects, uses, and shares. Personal Information means information about an identifiable individual. Personal Information does not include government records, de-identified or aggregated information, or other types of information excluded under Canadian law.

  2. PERSONAL INFORMATION WE COLLECT

    We may collect your Personal Information in the following ways:

    Contact Information. If you request information from us by completing the form on our Website, we may collect your name and e-mail address. If you are a healthcare professional, we may collect your name, address, gender, job profession, physician license information and the language in which you prefer we communicate with you.

    Profile Information. If you are a healthcare professional, and you choose to join our community for information about our products, you will be required to create a username and password to access certain parts of our Website and to create a profile with your business contact information. We may ask you to provide your phone number or email address to verify your password for security purposes.

    Adverse Event (Pharmacovigilance) Information. We may collect certain personal information in connection with our Pharmacovigilance program at http://www.lupinpharma.ca/privacy.

    Customer Service Recordings. If you call the phone number on our Website for medical inquires, drug safety, adverse reactions and product complaints, we may collect Personal Information and record your conversation for customer service purpose and to comply with legal obligations.

    Career Information. If you apply to an open position with Lupin, we will collect Personal Information you provide us about your work history, skills and qualifications, contact information, and education history.

    Internet Activity and Cookie Information. We may collect internet or other electronic network activity information, including information regarding your interaction with our Website, information about your browser and device, and your IP address. Location Data. We may collect your imprecise location information, like the country and city, associated with your IP address. User Generated Information. We collect survey feedback, comments, videos, photos, messages, social media, and other user generated content.

  3. SOURCES OF PERSONAL INFORMATION

    We collect Personal Information from the following sources:

    Source 1: Information that you provide or that is provided on your behalf: We collect Personal Information and other data that you or persons on your behalf may provide us when using our Website and when you email or call us. By way of example, we may collect Personal Information you provide in the following circumstances:
  • When You Request Information. When you request information by calling, writing, or emailing us, communicating with us through our Website, or signing up for educational communications.
  • When You Create a Profile. If you are healthcare provider, we collect your Personal Information if you create a profile on the Website. In that case, we will require you to create a username and password and provide business contact information and professional licensing information.
  • When Your Request Product Information and Safety. We collect your Personal Information when you seek product information, drug safety information or seek help on how to use our products. We also collect Personal Information if you report an adverse event or provide us with any comments or concerns about our products. For more information about how we collect, use and share personal information related to the report of a possible adverse event, please see our Pharmacovigilance Privacy Statement at https://www.lupinpharma.ca/privacy
  • Career Opportunities. When you submit a job application or related materials online for employment with Lupin, you will be redirected from our Website to the website of our third-party service provider, ICIMS, Inc. You may be required to create an account with that service provider. We encourage you to review the iCIMS’ Privacy Statement posted on their website since this Statement does not govern your use of that website. If you send us your job application materials directly, we will only use and share those job application materials to evaluate your qualifications to work with Lupin. Your submission of an application or inquiry does not require Lupin to review your information or consider you for employment.
  • Feedback. When you provide comments or feedback about our Website or our products (“Feedback”), we may collect Personal Information.

    Source 2: Information from healthcare professionals, public or third-party sources: We may collect Personal Information from healthcare professionals, including their Medical Information Number, and from public or third-party sources, to verify their professional credentials and identity.
    We may also collect Personal Information from your family members or others providing information through our Pharmacovigilance program.

    Source 3: Information automatically collected through technology: We may collect your Internet Activity and Cookie Information in addition to your Location Information when you visit our Website. Please reference the How We Use Technology and Your Privacy Choices in Section 13 below for more information about how we use cookies and how you can control the use of cookies when visiting our Website.

  1. HOW WE USE PERSONAL INFORMATION

    We may use the categories of Personal Information listed in Section 2 above for the following business purposes:

    As Stated or Agreed to at the Point of Collection. We may use Personal Information for the purposes stated or agreed to (or as is obvious) at the point of collection. For example, we use Personal Information to respond to your questions, requests, comments, or concerns. We may also use Personal Information as requested or consented to by you.

    Educational Communications. We may use the email and mailing address of healthcare providers to send them educational information and other electronic and hardcopy communications as permitted by law. We may use third-party providers to deliver these communications to you. You may opt out of these emails by using the unsubscribe link in the email. To opt out of other educational communications (e.g., postal marketing and telephone), please contact us as set forth in the “Contact Us” Section below. Opting out of educational communications does not opt you out of other types of communications from us.

    Operation of our Business. We use Personal Information for administrative purposes, such as to inform our business strategies, improve our products and customer service, to operate and improve our Website, to understand Website visitor demographics and user preferences, and for evaluating job applications.

    To Provide Patient Support. We may receive requests from healthcare providers and pharmacies to assist with patient support related to our products. We use third- party service providers to administer such patient support requests, including reimbursement and rebates, the distribution of copay cards, and processing requests for compassion use. These- third party service providers collect Personal Information in conjunction with fulfilling requests for patient support, including patients’ initials and date of birth.

    Risk Mitigation. To enroll each patient, physician and pharmacist, and to administer our risk mitigation plan as required by applicable law. We use third parties to administer this program, which includes collection of a patient’s age and income.

    Website Management. We use Personal Information for website management, such as troubleshooting problems, improving the content and functionality of the Website, statistical and other analyses of the Website, and to customize the Website. We also may use Personal Information to audit our Website for compliance, authorized access, and security.

    To Protect Our Rights and Comply with Our Legal Obligations. We may use Personal Information to protect our legal rights or interests, or those of third parties, including to bring a legal action against you or anyone who may be causing harm to us, our Website, or to others. We may use Personal Information to seek business, financial or legal advice, and to respond to other legal requests. Additionally, we will use Personal Information as necessary to comply with our legal and regulatory requirements.

    For Drug Safety and To Meet Our Regulatory Obligations. We use Personal Information for drug safety and to meet our regulatory obligations, including for pharmacovigilance. Please see our Pharmacovigilance Privacy Statement http://www.lupinpharma.ca/privacy for more information about how we collect, use, and share such Personal Information.

  2. DISCLOSURE OF PERSONAL INFORMATION

    We may transfer, communicate, or disclose Personal Information with the following parties, in compliance with this Statement and applicable laws.

    Uses and transfers of Personal Information by service providers acting on our behalf are governed by agreements that require Personal Information to be treated as confidential and protected. Personal Information will only be used and disclosed by us and those working on our behalf in a manner consistent with this Statement, other applicable privacy statements or notices, with access controlled as needed, and as explicitly permitted or required by applicable laws, rules and regulations.

    Employees and Affiliates. We may transfer or make accessible your Personal Information with our parent company, subsidiaries, divisions, and groups worldwide (“Affiliates”) who have a need to know the information for our business purposes. We maintain an agreement between our Affiliates which requires each Affiliate to handle your Personal Information transferred to them in a confidential manner and in compliance with applicable data protection laws.

    Service Providers. We may transfer Personal Information to our service providers that provide services to us. For example, we may share Personal Information with service providers and third parties that host and manage the Website; improve the content and functionality of the Website; perform data analysis and statistical analysis; troubleshoot problems with the Website; provide public relations services; administer our patient support and risk mitigation programs; assist with our drug safety and Pharmacovigilance programs; provide email services; provide data processing services; and support or provide the security for the Website.

    Professional Advisors. We may make your Personal Information available to our professional advisors, such as our attorneys, accountants, financial advisors, and business advisors, in their capacity as advisors to Lupin.

    Third Parties. We may disclose Internet Activity, Cookie Information, or Location Information regarding healthcare professionals who login into our Intrarosa or Zaxine websites with our third-party advertising partners for remarketing purposes.

    Government Officials / Law Enforcement. We will cooperate with law enforcement and other governmental agencies, and may disclose Personal Information: (i) if we believe in good faith we are legally required to disclose that Personal Information, (ii) if we are advised to disclose Personal Information by our legal counsel, or (iii) when necessary to identify, contact or bring a legal action against someone who may cause or be causing harm to, or interfering with the legal rights of Lupin or any other party.

    Change in Ownership. In the event Lupin is the subject of a due diligence process concerning the sale of all or part of the Company, if the Company is a participant to a sale, merger or acquisition transaction or in the event of a bankruptcy, receivership or a similar transaction, we may provide Personal Information to the prospective or subsequent owner(s). In these circumstances, we may share Personal Information with actual or prospective purchasers or successors, and we may disclose your Personal Information to them in the case that a transaction is completed.

    Other. We may disclose Personal Information with third parties or service providers when explicitly requested by or consented to by you, or for the purposes for which you disclosed the Personal Information to us as indicated at the time and point of the disclosure (or as was obvious at the time and point of disclosure).

  3. DATA TRANSFERS OUTSIDE OF CANADA OR OUTSIDE OF QUEBEC

    We are a global pharmaceutical company based in Mumbai, India. As a result of our global operations, we may share your Personal Information with our Affiliates located outside of Canada, including the United States and India. We do so in accordance with our internal data transfer and processing agreement which addresses protection of Personal Information in accordance with applicable laws.

    We may also transfer or make your Personal Information accessible with service providers located both in Canada (both inside and outside Quebec) and throughout the world to assist us in meeting our operational, legal and regulatory requirements. In those cases, we maintain written agreements with our service providers which require compliance with applicable data privacy laws. For instance, your Personal Information may be stored in our service providers’ global cloud for purposes such as website hosting, requests for feedback, protecting our legal rights, financial reporting, accounting, adverse event reporting, administering employment and employee benefits and regular business communications and document management.

    When we transfer your Personal Information outside of Canada, your Personal Information may be available to government officials in locations where the Personal Information is transferred. These countries have privacy laws that differ from Canadian privacy laws. If you are a resident of Quebec, where applicable, we will conduct privacy impact assessments prior to transfer of your Personal Information to another jurisdiction outside Quebec.

  4. CONSENT

    We will request your consent to collect and use your Personal Information, except where we are permitted or required to use or disclose your Personal Information under applicable laws or regulations. We may obtain your express consent or we may obtain your permission based on implied consent. Implied consent is consent that can be reasonably inferred. For example, we infer your provide consent for us to collect your Personal Information when you communicate with us through the Website. You may change or withdraw your consent, subject to certain legal, regulatory and contractual exceptions, by contacting us as described in this Privacy Policy.

  5. SECURITY AND CONFIDENTIALITY

    We use commercially reasonable administrative, technical, and physical safeguards to help secure Personal Information against loss, misuse, and alteration. If a breach of your Personal Information occurs, we will notify you if required under applicable law.

  6. USE OF DE-IDENTIFIED INFORMATION

    Lupin may collect, use, share, transfer, and otherwise process de-identified and aggregated information that it receives or creates for any purposes in its sole discretion, in compliance with applicable laws. Lupin is the sole and exclusive owner of such de-identified and aggregated information, including if Lupin de-identifies Personal Information so that it is no longer considered Personal Information under applicable laws.

  7. STATEMENT ON CHILDREN

    The Website is not directed at children and is designed for individuals who are 18 years of age or older. Where requests for information about a product are permitted by law, individuals must be 18 years of age or older when requesting information about a product that is indicated for use by children.

    We do not knowingly collect Personal Information from children, without obtaining verifiable parental consent prior to collection. If you are a parent or guardian that has knowledge that we have collected Personal Information from your minor child, please contact complianceandethicsoffice@lupin.com to request removal and we will endeavor to verify the identity of any applicable child Personal Information and make commercially reasonable attempts to delete such Personal Information.

  8. THIRD-PARTY WEBSITES AND SOCIAL MEDIA PLATFORMS

    Social Media. We are active on YouTube and LinkedIn (“Social Media”). Anything you post on Social Media is public information and will not be treated confidentially. We may post (or re-post) on the Website and our Social Media pages any comments or content that you post on our Social Media pages.

    Your use of Social Media is governed by the privacy policies and terms of the providers that own and operate those websites and not by this Statement. We encourage you to review those policies and terms.

    Third- Party Sites. This Statement applies only to our Website and not to third-party websites. We may provide links on our Website to third-party websites not owned or controlled by us. We are not responsible for third parties’ privacy statements or practices. This Statement does not apply to any third-party websites or to any data that you provide to third parties. You should read the privacy statement for each website that you visit.

  9. HOW WE USE TECHNOLOGY AND YOUR PRIVACY CHOICES

    We may use cookies, web beacons, pixel tags and other tracking technologies (collectively “Cookies”) on the Website. A Cookie is a small text file that our Website saves onto your computer or device when you use the Website that provides us certain information about your activities. Cookies allow the Website to remember your actions and preferences and recognize you or your browser. Web beacons / pixel tags are small graphics on a webpage that monitor your activity when viewing a webpage.

    Most browsers automatically accept cookies. You can disable this function by changing your browser settings, but disabling cookies may impact your use and enjoyment of the Website. Not all features or functions of the Website may work properly if you disable Cookies. You cannot disable all Cookies, such as Cookies that are essential to the functioning of the Website.

    To change your preferences with respect to certain online ads or to obtain more information about ad networks and online behavioral advertising, visit National Advertising Initiative Consumer opt-out page or the Digital Advertising Alliance of Canada at https://youradchoices.ca/choices/. Changing your settings with individual browsers or ad networks will not necessarily carry over to other browsers or ad networks. As a result, depending on the opt-outs you request, you may still see our ads. Opting out of targeted advertising does not opt you out of all ads, just those targeted to you.

    If you opt out, you may still receive online advertising from Lupin, which is based on your preferences or online behavior. Lupin uses multiple online advertising programs, so opting out of one program does not opt you out from all online advertising.

    Google Analytics. We may use Google Analytics to collect and process information about your use of the Website. Google sets cookies on your browser or device, and then your web browser will automatically send information to Google. Google uses this information to provide us with reports that we use to better understand and measure how users interact with the Website.

    To learn more about how Google uses data, visit Google’s Privacy Statement and Google’s page on “How Google uses data when you use our partners’ sites or apps.” You may download the Google Analytics Opt-out Browser Add-on for each web browser you use, but this does not prevent the use of other analytics tools.

    Email Communications; Opt out. We may send you educational information or surveys about how we can improve the Website. We do not collect any Personal Information from you when you submit your feedback through surveys. We may use third-party service providers to deliver communications to you. You may opt out of such emails by using the unsubscribe link in the email or contacting us at complianceandethicsoffice@lupin.com with “Unsubscribe” in the subject line. Opting out of educational or survey communications does not opt you out of communications about your account or transactions.

  10. YOUR PRIVACY RIGHTS

    This Section provides your privacy rights under Canadian law, subject to identity verification requirements and certain exceptions.

    Right to Access. You have the right to confirm that we hold Personal Information about you, receive an explanation about how we use your Personal Information, and obtain access to your Personal Information.

    Right to Rectification. You have a right to examine and challenge the accuracy of your Personal Information.

    Right to Withdraw Your Consent. You have the right to withdraw your consent to processing your Personal Information at any time, subject to legal or contractual restrictions and reasonable notice. If your withdrawal of consent implicates the quality of our services to you, we will notify you.

    Right to Complain to a Data Protection Authority. You also have the right to lodge a complaint regarding the processing of your Personal Information with the applicable data protection authority. Please contact your local data protection authority for more information.

    How to Exercise Your Rights. To exercise your rights described in this Section, you may submit your request to us by contacting us at any of the following:

    Mail:
    Attn: Compliance & Ethics Office Americas and EMEA
    Lupin Pharma Canada
    1111, St-Charles street West, Suite 550
    Longueuil, Quebec J4K 5G4

    Email: complianceandethicsoffice@lupin.com

  11. ADDITIONAL TERMS APPLICABLE TO QUEBEC RESIDENTS ONLY

    If you are resident of Quebec, Quebec law provides you with additional rights regarding the use of your Personal Information, subject to identity verification requirements and certain exceptions.

    Right to Restriction of Processing. You have a right to direct us to cease disseminating your Personal Information or to de-index any hyperlink attached to your name that provides access to the information by a technological means, if the dissemination of the information contravenes the law or a court order.

    Right to Request Deletion. You have a right to request that we delete Personal Information we collected from you. We will comply with such requests, and direct our service providers to do the same, subject to certain exceptions permitted by applicable law.

    Right to Portability. You may request copies of the Personal Information you have provided to us. Where possible, we will deliver the copy of your Personal Information to you using a structured, commonly used, and machine-readable format. Alternatively, you may request that we send your Personal Information to another business. How to Exercise Your Rights. To exercise your rights described in this Section, you may submit your request to us by contacting us at any of the following:

    Mail:
    Attn: Compliance & Ethics Office Americas and EMEA
    Lupin Pharma Canada
    1111, St-Charles street West, Suite 550
    Longueuil, Quebec J4K 5G4

    Email: complianceandethicsoffice@lupin.com

    Translations. This Privacy Statement may be provided in several languages. In the event of conflict or inconsistency, the English language version of this Privacy Statement controls, unless otherwise required by applicable law. En cas de conflit ou d'incohérence, la version anglaise de cette politique de confidentialité contrôle, sauf si la loi applicable l'exige.

  12. CONTACT

    We seek to constantly improve how we manage the collection and use of Personal Information. If you have questions regarding this Privacy Statement or how we treat your Personal Information, please contact us by:

    Mail:
    Attn: Compliance & Ethics Office Americas and EMEA
    Lupin Pharma Canada
    1111, St-Charles street West, Suite 550
    Longueuil, Quebec J4K 5G4

    Email: complianceandethicsoffice@lupin.com