Expert privacy notice

Chinese (中文)| Japanese (日本語)

This Expert Privacy Notice (“the Notice”) supplements our Global Privacy Notice and provides information about our personal information collection and processing practices related to individuals whose information is included in our products.

Norstella (“we”, “us” or “our”) processes personal information about healthcare professionals, medical, scientific and healthcare staff, clinical trial investigators, academic experts, authors and other professionals (referred to hereinafter as “Experts” or also “you” or “your” if we have collected personal information about you subject to this Notice) which we curate and publish for use by us and our customers and their users in our relevant products, services and associated databases (our “Products”).

Our Products benefit Experts by providing opportunities for you to connect and engage with life sciences companies and develop meaningful collaborations across therapeutic areas in the pursuit of helping patients gain access to life saving therapies and improving patient outcomes.

Norstella maintains profiles of Experts that we make available to our customers through our products and platforms. We maintain profiles of and process personal information about Experts that we collect from publicly available sources and databases; institution, government, and NGO websites (such as hospital or medical society websites); public news sources; and other readily available public resources (such as government publications). In addition, we may acquire lawfully obtained proprietary data from third-party data providers.

In some limited cases we may receive Expert personal information from our customers, and in those cases our customer may be the data controller. In such a case, you should refer to the respective privacy notice(s) of the relevant customer for more information about how they collect and use your personal information.

We may also collect information Experts share with us directly, such as if you contact us or use our Products.

The personal information in our Products generally may include information about Experts such as:

  • Professional details (such as information about your position, title, institution, education, degree, practice, patient mix, industry affiliations, clinical trials involved in and areas of specialization);
  • Contact information (such as your name, business email address, postal address, phone number, fax number);
  • Content, publications, editorial records, event and speaking engagement details and media of public record (such as Award and recognition details, journal contributions, research papers or articles you have published or feature in, clinical trials where you are named as an investigator and speeches or lectures you have given);
  • Self-reported demographic information available through public registries (U.S. only);
  • Publicly available video recordings and still images. Social media information such as hyperlinks to professional network sites, posted content, handles, tweets, hashtags, likes, followers and mentions (only if publicly available);
  • Where this information is publicly available, and subject to applicable law, we may collect special category or sensitive personal information such as race;
  • We also may collect inferences, such as interests and engagement preferences, that may be drawn from the above identifiers;
  • Our Products may use algorithms to generate Expert professional profiles and to calculate Experts’ relevance based upon search terms input by Norstella customers.

We may also collect de-identified and aggregated information relating to medical claims and treatments, patient populations, and clinical trials. We do not knowingly collect personal information about children.

We use Expert personal information we collect to curate and publish content in our Products to our customers and end users, which include searchable directories of Experts containing professional details described above.

Our customers generally process the personal information in our Products for the purposes of (i) identifying Experts, (ii) engaging and communicating with those Experts and (iii) conducting business planning and market intelligence.

Norstella or our customers may also process personal information for:

  • Scientific, historical, and statistical research purposes
  • Detecting, preventing, or investigating fraud, contract or policy violations, or criminal acts
  • Legal, compliance, and audit related purposes (including for the purposes of enforcing legal rights or defending legal proceedings)
  • General business administration, data management and analytics purposes
  • Corporate restructuring, including a reorganization or sale of business or assets
  • Marketing purposes, to the extent permitted by applicable law

The processing of the Expert personal information is based on the legitimate interests of Norstella and our customers for the purposes described above. In cases where legitimate interests are not a suitable basis to process Expert personal information, we may process the personal information pursuant to a separate legal basis under applicable law (such as the consent of the Expert).

We may share personal information we process about Experts with the following types of recipients.

  • Sharing across Norstella We may share your personal information across Norstella.
  • Norstella Customers Through our Products, we share Expert personal information with our customers and their end users, which are generally companies in the life sciences industry. Once our customers have accessed or downloaded the Expert personal information through our Products, they are an independent data controller and are responsible for meeting their own obligations under applicable privacy and data protection laws arising out of their processing of the personal information.
  • Service Providers We may share personal information with third party service providers, contractors or business partners to support our business. These third parties may perform services for us such as cloud hosting, product engineering or quality assurance services or we may work with a business partner to provide services to common customers.
  • Business partners with whom we deliver co-branded services or host events; or whose content or technology we make available through our services.
  • Government agencies, law enforcement, courts and other public authorities We may process your personal information to comply with our legal and regulatory requirements or to respond to regulators where applicable. This may include disclosing your personal information to third parties, the court service and/or regulators or law enforcement agencies in connection with enquiries, proceedings or investigations by such parties anywhere in the world or where compelled to do so. In some circumstances, we may be legally required to disclose your personal information because a court, the police, another judicial or law enforcement body or government entity has asked us for it.
  • Prospective and actual buyers, investors, sellers, advisers or partners If we are subject to negotiations for the sale of all or a part of our business to a third party, are sold to a third party or undergo a re-organisation, we may need to transfer some or all of your personal information to the relevant third party or its advisors as part of any due diligence process. Any information that is transferred to that re-organized entity or third party will be used for the same purposes as set out in this notice, or for the purpose of analyzing any proposed sale or re-organisation.

Norstella is a global business, and Expert personal information will be transferred to countries with different privacy and data protection laws than your own. If you are located or reside in a jurisdiction that places certain restrictions on the transfer of personal information (such as the EU, EEA or UK), your personal information will be transferred in accordance with appropriate legal safeguards to other countries including the United States.

We protect transfers of personal information outside of the EU, EEA and the UK with legal safeguards that include:

  • The existence of European Commission and Information Commissioner’s Office adequacy decisions (for example, transfers to Japan, Canada or Switzerland);
  • Norstella’s Intra-Group Data Sharing Agreement incorporating Standard Contractual Clauses and the UK Addendum approved by the European Commission and the Information Commissioner’s Office;
  • Transfer Impact Assessments to ensure to assess the potential risk of any international transfers in accordance with applicable law;
  • Standard Contractual Clauses and other contract terms executed between Norstella and third-party service providers who processes personal information on our behalf;
  • The existence of binding corporate rules or other certification mechanism approved by applicable law.

We retain Expert personal information for as long as necessary to support our Products, or for other essential purposes such as complying with our legal obligations, maintaining business and financial records, resolving disputes, maintaining security, detecting and preventing fraud and abuse, and enforcing our agreements.

Experts may contact us to exercise their rights as afforded by applicable privacy and data protection laws. We may ask you to verify your identity to ensure that we only disclose personal information to authorized individuals and to help us respond efficiently to the request. If you would like to make a data subject request, you may contact us using the contact information provided at the end of this Notice.

Depending on where you are located or where you reside, you may have certain rights granted to you over your personal information under local privacy and data protection laws. We will honor the requests you make related to your rights as the law requires. This means in some cases, there may be legal or other official reasons that we may not be able to fulfil the specific request you make.

One or more of the following rights may be available to you, however applicable rights may differ based upon local data protection and privacy laws. You may have the right to:

  • Information and access: know what personal information we hold about you and be given information about how we process or have processed it. You may also have the right to obtain confirmation from us that we process your personal information, and if so, to request access to or a copy of such personal information.
  • Correction: request that we correct inaccurate personal information we hold about you. You may also have the right to have incomplete personal information completed.
  • Erasure/Deletion: request that we erase some or all of your personal information, subject to certain exceptions permitted by law.
  • Restriction: ask us to restrict further processing your personal information.
  • Objection: object that we process some or all of the personal information we hold about you.
  • Data portability: receive your personal information in a structured, commonly used and machine-readable format, or, where feasible, to have us transfer your personal information directly to another organization.
  • The right to withdraw consent: withdraw your consent to the processing of your personal information where we rely solely on your consent for processing such data. Your withdrawal will not affect the lawfulness of our processing based on your consent before your withdrawal, and you can always give us your consent again in the future.
  • Automated individual decision-making not be subject to a decision based solely on automated processing of your personal information, including profiling, which produces legal or similarly significant effects on you. We will inform you if automated individual decision-making takes place.
  • Right to lodge a complaint: lodge a complaint with an applicable data protection authority. However, If you believe that we have infringed your rights, we encourage you to first contact our Privacy team so that we can try to resolve the issue.

To exercise applicable rights in relation to your personal information, please submit a request here.

Upon receiving a request, we will verify your identity by matching the information provided (such as name, email address, or phone number) with the information we hold. We may ask for additional information to verify your identity or to comply with your request. We will complete your request in the timeline prescribed by applicable law.

We recognize the importance of protecting and managing personal information. Your personal information will be treated with the utmost care and security. We use industry-standard physical, procedural and technical security measures, including encryption as appropriate.

We use a variety of technical and organizational measures to keep personal information safe and prevent unauthorized access to or use or disclosure of it. Electronic data and databases are stored on secure systems with control over who has access to information using both physical and electronic means. Our employees receive data protection, privacy and information security training and we maintain a set of detailed information security and data protection policies to which employees are required to adhere when managing personal information. All third-party contractors, consultants and service providers are subject to the appropriate contractual undertakings and due diligence.

While we take all reasonable steps to ensure that personal information will be kept secure from unauthorized access, we cannot guarantee it will be secure during transmission by you to a website or other services, as we do not control that transmission. We make use of HTTPS (HTTP Secure) whereby the communication protocol is encrypted via Transport Layer Security (TLS) for secure communication over a computer network. Our websites are loaded via HTTPS, represented by the lock icon in your web browser ensuring the transmission is secured with a certificate issued by an official security certificate authority.

This notice was last updated as of the effective date listed above.

To keep up with changing legislation, best practice and changes in how we process personal information, we may revise this notice at any time. If the notice changes in a way that significantly affects how we manage Expert personal information and we are obligated under applicable law, we will not use the personal information we previously gathered in the manner described in the new notice without providing notice and/or obtaining your consent as appropriate.

Minor changes to the notice may occur that will not significantly affect our use of personal information without notice or consent. We encourage you to periodically review this page for the latest information on our privacy practices.

For any questions about this notice or our use of your information, you can contact our Privacy team here, or using the details contained in the ‘Contacting us’ section of our Global Privacy Notice.


Work With Us

Join our mission

We’re looking for agile, growth-oriented team players who are passionate about client success and helping patients get access to the care they need.

Work with us

Get In Touch

Let's Connect

Have questions about Norstella or its brands? Or do you want to know more about how to solve your market access challenges?

We want to hear from you