PI We Collect and How We Use It
Depending on your interactions with Dermira, we may collect the following PI:
- Full Date of Birth;
- Full Date of Birth;
- Business/Professional Contact Information (e.g., title, company name, business address, business email address, business phone/fax number);
- Personal Contact Information (e.g., personal address, personal email address, personal phone/fax, personal web/internet address, family member names);
- Online identifiers that correspond to your device(s) (e.g., personal IP [Internet Protocol] address, cookies, RFID, etc.);
- Employment/Professional Job or Qualifications Information;
- Biographic Information;
- Financial and Government Identifying Numbers (e.g., Social Security number);
- Criminal/Conviction Records (e.g., on Federal Exclusion list);
- Biometric Identifiers;
- Website Utilization and Social Media Use;
- Education Information;
- Commercial Information, (e.g. purchasing, consuming history or tendencies);
- Inferences Reflecting Preferences
We collect PI from a number of sources, including:
- Employees, potential employees and their family members;
- Patients and clinical/medical trial participants;
- Clinical/medical investigators and staff conducting clinical/medical research;
- Health care professionals;
- Adverse event reporters and subjects;
- Lilly investors and shareholders;
- Vendors, suppliers, and contractors
- Business partners;
- Government officials
We process/use PI for the following business or commercial purposes:
- Activities as an employer to support and fulfill our obligations to our employees;
Research and development of our products;
- Compliance with legal or regulatory obligations (e.g., adverse event reporting, exercising or defending legal claims, financial disclosure reporting);
- Business and market research;
- Market research for our products and services;
- Study recruitment;
- Marketing and sales of our products;
- Communicating information about our products, responding to requests and registration for services;
- Providing patient assistance;
- Finance and tax activities;
- Statistical analytics;
- Event management;
- Contracting and business planning activities; and
- Administration of other legal and business processes that are in Dermira’s legitimate interest, inclusive of company record retention, safeguarding our physical and electronic workplace, and website management.
Dermira may share your PI with:
- Dermira and Lilly employees and affiliates;
- Health care professionals;
- Vendors, suppliers and contractors;
- Business partners); and
- Government officials (e.g., law enforcement authorities, the courts, regulatory authorities).
Where permitted by law, Dermira may also enhance or merge information, including PI, with information obtained from third parties for the same purposes shared above. PI may also be used for profiling for the same purposes shared above. You may object to profiling via automated-decision making by contacting us using the information in the “How to Contact Us” section below.
You do not have to share your PI with us, but if you choose not to share your PI, we may not be able to provide you with certain information, products or services.
In the ordinary course of business, Dermira sometimes collects Social Security numbers to fulfill legal or regulatory obligations or for other administrative purposes. We respect the confidentiality of Social Security numbers and we avoid the unnecessary collection of them, limit access to them, and disclose them only (i) according to Dermira’s internal policies and procedures, (ii) with those third parties who are legally or contractually obligated to protect them, and (iii) as required or permitted by law.
Through this website, Dermira may:
- Collect your Name and Personal Contact Information if you opt-in to receive communications (such as requests for information, responses to inquiries, newsletters, etc.). Dermira may also use this information to verify your relationship with Dermira and take other actions in order to respond to your request.
- Collect online identifiers that correspond to your device(s) that do not directly identify you in order to improve, manage and secure our websites, network systems and other assets; verify your relationship with us; understand your interests and preferences; and take other actions that may be necessary to respond to your request.
- Analyze your website usage including the date and time of your website session, geographic location, how you have navigated the website, and other information collected through our web beacons, cookies, third-party and digital advertising, Google Analytics® and social media plug-ins. This information is collected for our legitimate business purposes.
Web beacons: A web beacon (also known as an “action tag” or “clear GIF technology”) is a tiny graphic on a web page or in an email message designed to track pages viewed or messages opened, and allows the collection of web log information. Web log information is gathered by the computer that hosts our website (called a “web server”) when you visit one of our websites. We may use web beacons to help determine which email messages sent by us were opened and whether a message was acted upon. Web beacons also help Dermira analyze the effectiveness of websites by measuring the number of visitors to a site or how many visitors clicked on key elements of a site.
- Do Not Track: There are different ways you can prevent tracking of your online activity. One of them is setting a preference in your browser that alerts websites you visit that you do not want them to collect certain information about you. This is referred to as a Do-Not-Track (“DNT”) signal. Please note that currently our websites and web-based resources do not respond to these signals from web browsers. At this time, there is no universally accepted standard for what a company should do when a DNT signal is detected.
Third-Party and Digital Advertising: We may partner with third-party advertising networks to manage our advertising on other sites. Our ad network partners may place cookies and web beacons and similar digital markers on your browser when you visit our websites to collect information about your activities over time on this and third-party websites, apps, and other online services, to provide you targeted advertising based upon your interests. We may also share PI about you with third parties in order to have those third parties, on our behalf, directly serve advertising to you on their websites.
- Opt-Out Provision: Google Analytics offers an opt-out provision for website visitors who do not want their data to be collected. You can receive more information about this option here.
Social Media Plug-ins: Our websites may use social media plug-ins to enable you to share information with others easily. When you visit our websites, the operator of the social media plug-in that is on our website can place a cookie on your computer that lets that operator recognize individuals on their website who have previously visited our sites. Social media plug-ins may allow social media websites to receive directly identifiable information about you that shows you have visited our website. The social media plug-in may collect this information for visitors, whether or not they specifically interact with the plug-in on our website. Social media plug-ins also allow the social media website to share information about your activities on our website with other users of their social media website. Dermira does not control any of the content from social media plug-ins. For more information about social plug-ins from social media websites, you should refer to those sites’ privacy and data-sharing statements.
This website is not intended for or designed for individuals under the age of 18. We do not knowingly collect PI from any person under the age of 18.
Reasons We Share PI
We may share your PI with third parties in connection with work that they do for or with Dermira, for purposes consistent with those listed above. These third parties must agree to protect the PI and to use it only as directed by Dermira.
We may also be required to disclose your information in response to lawful information requests for PI by law enforcement authorities, the courts or regulatory authorities, including complying with national security or law enforcement requests.
In the event that Dermira may decide to reorganize or divest part or all of its business, including its information databases, through a sale, divestiture, merger, acquisition or other means of transfer, then PI may be shared with, sold, transferred, rented, licensed or otherwise provided or made available by Dermira to third parties in connection with the contemplated transaction (without your consent or any further notice to you). In such circumstances, Dermira will seek written assurances that the PI will be protected appropriately.
Where We Transfer and Work With PI
This website is owned and operated by Dermira in the United States. However, any information collected on this website may be transferred to other third parties worldwide. Some of these third parties may be located in countries that do not require the same level of data protection as the country you reside in. Nevertheless, all third parties are required to treat PI in a manner consistent with applicable law. As explained in the “Reasons We Share PI” section above, PI may be shared as appropriate with third parties that process information on behalf of, or with, Dermira. If we disclose PI to a third party, Dermira ensures that the third party has contractual provisions that require an appropriate level of security and confidentiality safeguards as provided by Dermira. By using this website, you consent to the collection, storage, and processing of your PI in the United States and in any country to which we may transfer your information in the course of our business operations.
If you want to view your PI that Dermira processes and request its correction, amendment or deletion, please contact us using the information in the “How to Contact Us” section below.
To obtain additional information regarding the basis for transfers and safeguards that Dermira has in place for cross-border transfers of PI, please contact us at privacy@Dermira.com.
How Long We Keep PI
PI will be saved for a period of time needed to fulfill legitimate and lawful business purposes in accordance applicable laws and regulations.
How We Secure PI
We provide reasonable physical, technical, and procedural safeguards to protect PI we work with and maintain. We limit access to PI to authorized employees and third parties who need access to carry out their assigned roles and responsibilities on behalf of Dermira. Although we strive to protect the PI, we work with and maintain, no security system can prevent all potential security breaches.
Your Rights and Choices
Upon verification of your identity and as applicable by law, you have the right to request information from us on how your PI is being used and with whom it is being shared. You also have the right and choice to request to see and receive a copy of the PI that we have about you, request that we correct, restrict the processing of, and/or erase/delete your PI, or in France, set expectations for the handling of your data after your death.
There may be exceptions that apply to your request.
To exercise your rights, you or your authorized representative may submit a request to or by contacting us using one of the methods listed under the “How to Contact Us” section.
You will not be discriminated against for exercising any of your rights.
California Privacy Rights
California Civil Code Section 1798.83 entitles California residents who have an established business relationship with Dermira the right to request information regarding Dermira’s disclosure of certain PI to third parties for their direct marketing purposes. To make a request for such information, you may contact us using the information in the “How to Contact Us” section below.
California Consumer Privacy Act (CCPA) entitles California residents to certain rights with regards to their PI. Those rights have been incorporated into this privacy statement.
How to Contact Us
You may make any of the above requests by using the contact information below:
You may also contact us at the above if you have questions about this Privacy Statement.
How to Submit a Complaint
If you wish to raise a complaint on how we have handled your PI, you can contact our Data Protection Officer at privacy@Dermira.com who will investigate the matter.
If you are not satisfied with our response or believe we are not processing your PI in accordance with the law, you can register a complaint with a relevant regulatory authority (e.g., Data Protection Authority or Attorney General).
Links to Third-Party Websites
As a convenience to our visitors, this website may contain links to other sites owned and operated by third parties that we believe may offer useful information. The policies and procedures we describe here do not apply to those sites. We are not responsible for the collection or use of PI at any third-party sites. Therefore, we disclaim any liability for any third party’s use of PI obtained through using the third-party website. We suggest contacting those sites directly for information on their privacy, security, data collection and distribution policies.
Changes to Our Privacy Practices
We may update this Privacy Statement from time to time. When we do update it, for your convenience, we will make the updated statement available on this page. We will always handle your PI in accordance with the Privacy Statement in effect at the time it was collected unless we provide you with the new notice and/or obtain your consent, as appropriate.
Last Updated: May 11, 2020.
Other company and product names are trademarks of their respective owners.