Galapagos (“the Company,” “we” or “us”) values your privacy and we want to be transparent about the information we collect, why we collect it, and how the information is used. For the personal data collected through this website, Galapagos NV, Generaal De Wittelaan 11 A3, 2800 Mechelen will act as the controller. In this way, we control the process by which your personal data is collected and the purposes for which your personal data is used.
Furthermore, we want you to know your rights regarding your personal data. This Privacy Statement addresses how we handle and protect personal data collected via the Galapagos website (“the Site”) or a related website controlled by the Company or personal data collected in the provision of any support or other services (“Services”). We strongly recommend that you read this Privacy Statement and, if you have any questions, contact us via email@example.com.
We confirm that personal data will be dealt with in accordance with the Belgian, European, and relevant United States privacy laws and regulations, including Belgian law of 30 July 2018 on the protection of natural persons with regard to the processing of personal data and the Regulation 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data - General Data Protection Regulation (GDPR).
Personal data includes any information relating to an identified or identifiable natural person (also known as a “data subject”). This may include, but is not limited to: your name, address, email address, phone number, identification number or location data. More information on personal data we collect can be found below in specific sections of this Privacy & Cookie Statement.
We use your personal data solely for the purposes of processing your requests, to conduct our business, to develop analytics and aggregated data that allow us and our partners to improve our Site and related Services, recruitment-relating purposes or to correspond with you. Below is a summary of the channels through which information is currently collected on the Site including the type of personal data collected via each channel and how that data is used.
We will only process your personal data if we have obtained your prior consent, if the processing is necessary to perform our contractual obligations or to take pre-contractual steps at your request, if the processing is necessary to comply with legal or regulatory obligations or if the processing is necessary for our legitimate interests.
When using our website to subscribe to press releases, register for clinical trial updates or merely to contact us, we may collect the following information: your name, e-mail address, company you work for and preferred language of communication, as well as other information that you choose to provide to us.
The Contact Page provides you with our office addresses, email addresses and telephone contact information should you wish to contact us. Other contact details can be found on our online reporting page or in the news section of the Site. By contacting us, you may provide us with personal data amongst other information in relation to your query or request. Based on the personal data you provide us, we may communicate with you in response to your inquiries, to provide the services you request. We will communicate with you by email or telephone, in accordance with your preference.
News via mail
To subscribe to Galapagos’ press releases, the mandatory fields required include your name and email address. This information is kept in a database which is hosted outside the EEA. We have made the necessary efforts to ensure that the processor responsible for this database has implemented sufficient technical and organisational measures to safeguard this data.
We may also use your personal data to communicate with you regarding the following:
In case you apply for a job opening or in case of a spontaneous job application, the following personal data can be processed for the job application procedure:
When you apply for a position via our website, we collect the following personal data to facilitate the entire job application procedure for recruiting-relating purposes. These recruitment-related purposes include:
Applicants must provide accurate and up to date information, and cannot knowingly omit any relevant information that is critical for the selection procedure. Job applicants that refuse to provide information that is required to assess suitability for the applied role, may be barred from the selection procedure, unless applicant has a justified reason for refusing to provide such information.
The Company may also collect your personal data from other sources if you would not apply for a position via our website, such as from e.g. recruitment agencies, professional social networks and former employers.
If you have not been successful for the position for which you have applied, you will be contacted via email and the personal data that was provided will be kept in the database to inform you about new positions that may be of interest to you, for a maximum of 2 years after the date of collection. Similarly, in case of a spontaneous application, your application will be kept for 2 years.
From time to time, we create information portals on the Site to provide interested parties with information regarding clinical research studies. When subscribing to future updates on these portals, you may be required to fill in a registration form and provide the following personal data: your name, email address, country and preferences. We store information that we collect to create a “profile” of your preferences. We use this profile to improve the content of the Services and related products in which you have expressed an interest. We do not share your profile with third parties other than as set forth in our Terms and Conditions for any of the Services that may be in effect from time to time.
In case you are a business contact person for Galapagos, your personal data is used for business relationship management purposes such as maintaining the ongoing relationship with, e.g., our contractors, service providers, partners, consultants, etc. The personal data that is being used may include but is not limited to: your name, e-mail address, telephone number, organization related details, contact history, signature. This information may either be directly provided by you or by the organization you are related to.
Our customer database includes individuals with whom we had previous business relations including but not limited to researchers that participated in clinical trials, Key Opinion Leaders, (former-) members of the advisory and scientific boards, contacts gathered at events, and individuals that have contacted Galapagos. The database also includes publically available contact information.
In case you are a customer or prospect customer of Galapagos, your personal data is used for business development purposes such as communication on the Services and related products, organization of focus-group discussions, market studies and others. The personal data that is being used may include but is not limited to: your name, e-mail address, telephone number, organization related details, contact history with Galapagos.
Privacy Notice for Health Care Professionals
Last update: 15 September 2020
Galapagos (the “Company,” “we,” or “us”) is committed to ensuring the protection of the personal data of all individuals who are currently collaborating with Galapagos, including Health Care Professionals as well as respecting the rights of HCPs whose personal data are being processed for different purposes outlined below.
Health Care Professionals’ personal data are therefore handled and protected with the utmost care, in accordance with the requirements imposed by international and local data protection laws.
This Privacy Notice describes the way in which Galapagos handles the personal data of Health Care Professionals.
This Privacy Notice applies to the personal data of Health Care Professionals. It sets out the principles that Galapagos applies, in its capacity as a controller, to all personal data of the Health Care Professionals that is collected and processed in any format, whether electronic or paper.
For the purposes of this Privacy Statement, the following definitions apply:
Personal data: any information relating to a Staff Member or Independent Contractor that can be identified, directly or indirectly, in particular by reference to an identifier such as name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Special categories of personal data: any personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation.
Processing: any operation or a set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Controller: the natural or legal person who (either alone, jointly or together with other persons) determines the purpose(s) “for which” and the manner “in which” any personal data is or will be processed. In most cases, Galapagos acts as a controller when processing personal data of Staff Members and Independent Contractors.
4. Personal data we collect
As an employer or principal, Galapagos collects and stores personal data of Staff Members and Independent Contractors. As the case may be, these personal data include but are not limited to:
Galapagos usually collects personal data directly from individuals but may, from time to time, obtain additional information from other sources such as public databases, social media platforms and other third parties.
Galapagos only collects special categories of personal data to the extent that it is necessary to meet its legal obligations, or to the extent that Galapagos receives consent, or is authorized by law. Special categories of personal data concerning Health Care Professoinals processed by Galapagos includes:
Galapagos only processes the personal data which are adequate, relevant and limited to what is necessary in relation to the specific purpose of establishing, managing or terminating your relationship with Galapagos.
Galapagos will process the personal data of Health Care Professionals as part of its professional relationship with Health Care Professionals.
The main purposes for collecting data with regard to Health Care Professionals are:
1. Transfers of Value
2. Relationship Management
3. Market Research
4. Product Complaints and Adverse events
5. Grants, donations and sponsorship applications
Galapagos only processes personal data in a way that is compatible with the purposes for which the data was collected or which is authorized by Health Care Professionals. The processing of Health Care Professionals’ data by Galapagos can be justified by the existence of a contract between the Health Care Professional and Galapagos, or is necessary to comply with legal obligations to which Galapagos is subject.
Galapagos also processes some personal data based on Health Care Professionals’ consent.
Galapagos also processes some personal data based on legitimate interest to maintain and optimize the relationship and connection with the concerned Health Care Professional.
Galapagos takes all appropriate steps to ensure that personal data are accurate, up to date and reliable for the purposes intended. Health Care Professionals should bear in mind that they are partly responsible for the accuracy of their personal data. Should certain information change during your career at Galapagos, you should promptly notify Galapagos NV/BV/SASU/GmbH.
7. Disclosure to third parties
Galapagos may obtain assistance or use third parties for the abovementioned purposes. These third parties will be required to process the Health Care Professionals’ personal data only in accordance with Galapagos’ instructions and to maintain reasonable security of such personal data. Examples of these third parties include, as the case may be: payroll organizations, social secretariat, health insurance provider, group insurance provider, HR-system providers or other software suppliers, cloud service solutions, other solution service providers that enable Health Care Professionals to fulfil their obligations, banking institutions, authorized medical entities and insurance companies.
In addition, personal data may be disclosed to authorized persons dealing with claims and investigations, law enforcement authorities, legal advisors and public authorities if needed to comply with a request or for the establishment, exercise or defense of legal claims. Please note that our cloud providers may need to give access to data stored on their services to competent law enforcement authorities. Galapagos will take necessary measures to ensure that such access is only granted in compliance with applicable data protection rules.
In addition, information about Health Care Professionals may be shared within the Galapagos group of companies.
8. International data transfers
For Health Care Professionals residing in the European Economic Area, (“EEA”), the data that we collect from you is usually not transferred to or stored at a destination outside the EEA. It may be processed by staff operating outside the EEA who work for us or for one of our suppliers.
If we do transfer data outside the EEA, we will ensure it is protected employing the following safeguards:
9. Retention period
Galapagos takes adequate measures to ensure your personal data are not stored for longer than necessary to realize the aforementioned purposes or as necessary in the context of a contract or legal obligation.
10. Security of processing
Galapagos acknowledges its responsibility to ensure an appropriate level of security with regard to the information provided by Health Care Professionals. Therefore, Galapagos has implemented various measures in order to protect the personal data against loss, alteration, accidental or unlawful destruction, unauthorized disclosure of, or access to the personal data. On an organizational level measures are taken such as the limitation of access to and monitoring of the buildings and systems, while on technical level firewalls and encryption are in place, personal passwords are used and verified and verification requirements regarding access to personal data on a ‘need-to-know’-basis is provided.
11. Your rights
Each Health Care Professional is considered to be a data subject. As a result, you can exercise your rights as described in the GDPR. These rights include:
However, this withdrawal does not affect any processing operations previously carried out on the basis of your consent.
Unless specified otherwise above, you can exercise those rights by sending a request to firstname.lastname@example.org. After verifying your identity and right applicability criteria, we will do everything reasonably possible to comply with your request unless it will require completely unreasonable measures (e.g. would be technically or organizationally virtually impossible or extremely costly). We may refuse to process requests that are unreasonably repetitive or systematic.
As a data controller, it is our duty to inform you that you have the right to lodge a complaint. If, at any time, you are of the opinion that Galapagos infringes your privacy, you have the right to lodge a complaint with the national supervisory authority. The contact details of the supervisory authorities in Europe, can be found here: https://ec.europa.eu/commission/sites/beta-political/files/national-data-protection-authorities-jan_2018_en.pdf
Changes to this Privacy Notice can be made from time to time, in accordance with international and local data protection laws. When we change the content of this Privacy Notice, we will change the date and version number of the ‘last update’ of this Privacy Notice.
If you have any questions with regard to the contents of this Privacy Notice or your rights in relation to the data processed by Galapagos, you can contact the Data Protection Officer by sending an email to email@example.com.
Privacy Notice for Patient Representatives
Last update : 8 February 2021
1. Our purpose, the personal data we collect and how long we keep it
We process your personal data in order to get your input and insights in patient-related matters.
To achieve this purpose, we collect your personal identification data and contact details (name, surname, title, photo, email address and profession) and your opinions and insights in patient-related matters.
We will keep your personal data as long as we have a relationship with you. We frequently review the personal data we hold and delete it when we no longer need it.
We take all appropriate steps to ensure that personal data are accurate, up to date and reliable for the purposes intended. Please be aware that you are partly responsible for the accuracy of your personal data. Should certain information we hold about you change, please notify us promptly.
3. Disclosure to third parties
We obtain assistance or call on third parties for the abovementioned purpose. These third parties will be required to process your personal data only in accordance with our instructions and to maintain reasonable security of such personal data.
It may occur that data about you is shared within the Galapagos group of companies if this is necessary to achieve specific purposes. We take appropriate measures to ensure that all the entities of the Galapagos group are submitted to the same or equivalent data protection rules. If the entity is located outside the EEA, we will take the necessary measures to ensure the equivalent protection as within the EEA.
As a general rule, the data that we collect from you is not transferred outside the EEA. If we, in exceptional circumstances, do transfer data outside the EEA, we will appropriately inform you about this and we will ensure it is protected employing the following safeguards:
4. Security of processing
We acknowledge our responsibility to ensure an appropriate level of security with regard to your personal data. Therefore, we have implemented various technical and organizational security measures in order to protect the personal data against loss, alteration, accidental or unlawful destruction, unauthorized disclosure of, or access to the personal data.
5. Your rights
When we collect and use your personal data, you enjoy a number of rights which include:
6. Changes to this Privacy Notice
Changes to this Privacy Notice can be made from time to time, in accordance with European and local data protection laws. When we change the content of this Privacy Notice, we will change the date and version number of the ‘last update’ of this Privacy Notice.
If you have any questions or comments with regard to the contents of this Privacy Notice or if you want to exercise one of your rights in relation to the data processed by us, you can contact our Data Protection Office by sending an email to firstname.lastname@example.org.
Your personal data is kept for no longer than is necessary in relation to the purposes for which it is collected. We will frequently review the information we hold and when there is no longer a legal or business need for us to store it. In cases of clinical research information portals providing information on clinical research studies, your personal data will be removed once the portal is no longer live, or our Services are no longer being provided.
In order to protect the Company against any legal claims or to respond to potential inquiries, files may be stored in back-ups of the Company or in the archives in function of the applicable statutes of limitation. These archived copies will only be used if strictly required by the Company for the establishment, exercise or defense of legal claims and can, in such situations, be shared with legal advisors.
You have the possibility to exercise your rights as described in the GDPR. As a data subject, you can exercise the following rights:
To exercise the above rights, you can contact Galapagos Data Protection Officer, email@example.com. After verifying your identity and data subject rights applicability criteria, we will do everything reasonably possible to comply with the request unless it will require completely unreasonable measures (e.g. technically or organizationally virtually impossible or extremely costly). We may refuse to process requests that are unreasonably repetitive or systematic.
Your personal data may be used by a parent, subsidiary, or affiliate entity within the Galapagos NV corporate family, partner entities, and the vendors and service agencies that we may engage to assist us. We will never pass your personal data to anyone else without your consent, except for (a) successors in title to our business, or (b) when required by law. We will share your personal data with providers only in the ways that are described in this Privacy Statement.
We do not sell, trade, or otherwise transfer to outside parties, personal data we collect from you without your consent, except in cases where we may share personal data for any Services that may be in effect from time to time, including, without limitation, the situations described below:
For users residing in the European Economic Area, (“EEA”), the data that we collect from you may be transferred to, and stored at, a destination outside the EEA. It may also be processed by staff operating outside the EEA who work for us or for one of our suppliers.
If we do transfer data outside the EEA, we will ensure it is protected employing the following safeguards:
We are committed to protecting the security and privacy of your information. We will use appropriate technical and organisational measures to restrict access to personal data to those of our employees, agents, contractors, or representatives who require access to such information to perform tasks assigned to them by us. All data gathered by our Services is stored by us in a secure, password-protected database. Only we and our third party processors, if any, have access to this database.
We will protect personal data provided to us by using reasonable security safeguards against loss, theft, unauthorized access, disclosure, copying, use, or modification. Although we and our third party processors implement standard security protections, we cannot guarantee the physical or electronic security of the servers and databases on which the Services are hosted. We require our partners who receive your information to agree to security requirements consistent with this Privacy Statement. If you create copies of information from the Services, we cannot protect the security and privacy of the information contained in such copies.
This table shows the type of cookies, the purposes for which they are used and their retention periods.
|Cookie Name||Purpose||Retention period|
(set by Google Analytics)
|To help understand how visitors interact with
the websites by providing information about
the areas visited, the time spent on the
website, and any issues encountered, such as
error messages. This helps Us improve the
performance of our websites.
|By default, this cookie is set to expire after 2 years|
(set by Google Analytics)
|This cookie is used to limit the collection of
data when there is high traffic on the site.
(set by Google Analytics)
|To store and group the session’s activity for
|_PHPSESSID||Temporarily saves the information of your
session so that you do not need to fill the form
again when you reload the page.
|When the browsing session ends.|
|_wfvt_ [ID of website]||These contain information about your general
|When the browsing session ends.|
(set by the Wordfence Security WordPress plugin)
|To protect the site against malicious attacks.||24 hours|
|_gat_gtag_[ID of website]||Identification code of website for tracking visits||2 years|
|scf_cookielayer_storage||Saves the information regarding the fact that
Certain cookies are placed by a third party, for example Google Analytics to measure the use of the website. These cookies are found in other companies’ internet tools which we use to enhance our site, for example LinkedIn and Twitter all have their own cookies, which are controlled by them. If you do not want a website to place cookies on your device, you can change the settings of your browser as abovementioned.
Our Site and Services currently do not respond to “Do Not Track” (DNT) signals.
Our Services are not aimed at people under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that a child under 16 has provided us with personal data, we will take reasonable steps to remove such information from our systems and terminate the applicable account.
From time to time, this Privacy Statement may be revised. Any changes to this Privacy Statement will be indicated through the mention of effective date and version number. Continued use of our sites after changes made to our Privacy Statement indicates your consent to the use of newly submitted information.
We reserve the right to disclose personal data in the following circumstances: as required by law; if we believe that disclosure is necessary to protect ours or others’ rights, property, or safety; to comply with a judicial proceeding, court order, or legal process served on us or the Services; or in connection with an actual or proposed corporate transaction or insolvency proceeding involving all or part of the business or assets to which the information pertains. By using the Services, you consent to having any personal data you provide to us transferred to and processed in the United States. BECAUSE SOME JURISDICTIONS DO NOT PERMIT CERTAIN LIMITATIONS OR DISCLAIMERS OF LIABILITY, THESE LIMITATIONS MAY NOT APPLY TO YOU.