Privacy Policy

Introduction
Novus Clinical respects your privacy and is committed to protecting your personal data. This privacy policy will tell you about how we look after your personal data when you visit our websites and/or deal with us and tell you about your privacy rights and how the law protects you.
This privacy policy aims to give you information on how the Novus Clinical collects and processes your personal data through your use of its websites or your dealings with us, including any data you may provide through these sites, when you sign up to our newsletters, or submit any information or purchase a product or service, both online and offline (collectively referred to in this statement as our “Data Activities”).
This website is not intended for children and we do not knowingly collect data relating to children, unless we have agreed this with you.
It is important that you read this privacy policy together with any other privacy notice/statement or fair processing notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This privacy policy supplements the other notices/statements and is not intended to override them.
Who are we?
Novus Clinical Ltd is a UK limited company, with headquarters in Leeds, UK. Novus Clinical Ltd is referred to as “Novus Clinical” in this Privacy Notice.
What do we do?
Novus Clinical is a pharmaceutical services business providing clinical trial supply and expanded access program services to its global pharmaceutical and biotech customers, along with businesses in related fields (Novus Clinical customers being referred to in this Privacy Statement as “Customers”).
This Privacy Notice relates to all of Novus Clinical’s services (which are referred to in this Privacy Notice as Novus Clinical Services). Novus Clinical Services include but are not limited to:
- Supply of commercial medicines / drugs, comparator products and related pharmaceutical products to Customers for use in clinical trials, biosimilar development, generic product development and analytical laboratory / pre-clinical testing (referred to in this Privacy Notice as “Clinical Trial Supply” or “CTS”).
- Communications with users of our websites, newsletters or apps: for example, responding to enquiries made via our websites.
Novus Clinical operates globally in a highly regulated, safety-focused field. As a necessary element of providing the Novus Clinical Services, Novus Clinical carries out Data Activities.
Our Suppliers
Novus Clinical engages a number of different types of specialist suppliers to aid it in providing the Novus Clinical Services. Such Novus Clinical suppliers are referred to in this Privacy Notice as “Suppliers”.
Data relationships – controller and processor
In almost all cases where we supply Novus Clinical Services to a Customer, the applicable Customer is considered to be the ‘controller’ of the Personal Data collected (for the purposes EU and UK data protection law), with Novus Clinical and its Vendors being considered to be ‘processors’ (or ‘sub-processors’) of such Personal Data. However, where Personal Data is collected by Novus Clinical for its own business uses and not on behalf of a Customer, Novus Clinical is usually considered to be the ‘controller’ of such Personal Data. This Privacy Notice applies to all Personal Data processed by Novus Clinical, whether Novus Clinical is controller or processor (where those concepts apply).
Use of your Personal Data and this Privacy Notice
Please read this Privacy Notice before using Novus Clinical Services or submitting Personal Data to Novus Clinical. By accessing and using any of our Novus Clinical Services, you agree and consent to the collection, use and disclosure of your Personal Data as outlined in this Privacy Statement.
For ease of use, this Privacy Notice is provided in a layered format so you can click through to the specific areas set out below. Alternatively, you can download a pdf version of the Privacy Notice.
It is important that you read this Privacy Notice together with any other privacy or fair processing notice, or consent form (where applicable), that may be provided to you in specific circumstances, so you are fully aware of how and why we use your Personal Data. This Privacy Notice supplements such other notices/forms and does not override them.
How does Novus Clinical collect Personal Data?
Novus Clinical collects Personal Data (or Personal Data is collected on behalf of Novus Clinical) in several different ways and from several different sources, to enable us to provide the Novus Clinical Services, as follows:
- Directly from individuals (for example, by individuals using our website, newsletters, surveys, or our apps to make enquiries, and supplying contact details).
- From healthcare professionals (who may inform us about themselves and/or patients), particularly in performance of Clinical Trial Supply services.
- From Customers, in connection with our performance of Novus Clinical Services for them.
- From other service providers (i.e., Contract Research Organisations, Contract Development Manufacturing Organisations) we are working with, from clinical trial sites / investigators, from Suppliers, and from other third parties engaged by our Customer who we interact with in provision of a Novus Clinical Service.
- From other business partners.
- From government agencies or public records.
- From industry and patient groups and associations.
From time to time, we may also use or augment the Personal Data we have about you with information obtained from other sources, such as public databases, social media platforms and other third parties. For example, we may use such third-party information to confirm or verify service providers and/or healthcare professionals’ licences or to better understand your requirements by associating demographic information with the information you have provided.
Novus Clinical may also share your Personal Data with some or all of the parties or entities mentioned in the above list, as part of its legitimate Data Activities. Further information on the sharing of Personal Data is set out below.
What type of Personal Data might we collect/process?
We may collect, use, store and/or transfer (together referred to in this Privacy Notice as Processing) different kinds of Personal Data about you.
You should note that in relation to certain of our Data Activities, we are likely to collect and Process what in the UK is called sensitive Personal Data. Sensitive Personal Data includes data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, data concerning a person’s sex life or sexual orientation, and health-related data (together referred to in this Privacy Notice as Sensitive Personal Data). In our case, we are most likely to collect health-related Sensitive Personal Data, potentially including genetic and biometric data, in relation to the Novus Clinical’s Services. We will only Process such Sensitive Personal Data if we need to do so to provide the applicable Novus Clinical Service to you or to discharge our obligations to our applicable Customer or to comply with applicable law.
We have grouped together the types of Personal Data we collect (dependent on the applicable Novus Clinical Service), some of which is Sensitive Personal Data, as follows:
- Contact information and contact preferences (such as name or initials, email address, mailing address, phone number, and emergency contact information).
- Biographical and demographic information (such as date of birth/age, marital status, professional/employment status and type, gender, ethnicity and sexual orientation).
- Health and medical information (such as information about physical and mental health conditions and diagnoses, weight, treatments for medical conditions, genetic information, family medical history, medications an individual may take, including the dosage, timing, and frequency, and Adverse Events suffered), which we Process where necessary in connection with the Bionical Emas Services.
- Information regarding any parents or legal guardians.
- Financial information.
- Username and password that you may select in connection with establishing an account on our website.
- Your photograph, social media handle or digital or electronic signature.
- Publicly available information.
- Internet activity, such as your browsing history, your search history, and information on your interaction with the Novus Clinical Services.
- We may use the Personal Data we collect about you with information obtained from other sources, such as public databases, social media platforms and other third parties.
If you are a healthcare professional, Novus Clinical may also collect or share, in accordance with this Privacy Statement:
- Professional credentials, educational and professional history, institutional and government affiliations, and information included on a resume or curriculum vitae (such as work experience, education, and languages spoken).
- Information about the Novus Clinical Services with which you have engaged.
- Details about our interactions with you, your use of Customer products via the Novus Clinical Services and the agreements you have executed with us.
- Publicly available information related to your practice, such as licence information, disciplinary history, prior litigation and regulatory proceedings, and other due diligence related information.
How Novus Clinical uses Personal Data
Novus Clinical collects Personal Data (or Personal Data is collected on behalf of Novus Clinical) in several different ways and from several different sources, to enable us to provide the Novus Clinical Services, as follows:
- Directly from individuals (for example, by individuals using our website to make enquiries, and supplying contact details).
- From healthcare professionals (who may inform us about themselves and/or patients) in performance of our Services.
- From Customers, in connection with our performance of Novus Clinical Services for them.
- From other CRO’s and/or CDMO’s we and/or our Customer are working with, and from other third parties engaged by our Customer who we interact with in provision of a Novus Clinical Service.
- From other business partners
- From government agencies or public records
- From industry and patient groups and associations
From time to time, we may also use or augment the Personal Data we have about you with information obtained from other sources, such as public databases, social media platforms and other third parties. For example, we may use such third-party information to confirm or verify healthcare professionals’ licences or to better understand your requirements by associating demographic information with the information you have provided.
Novus Clinical may also share your Personal Data with some or all of the parties or entities mentioned in the above list, as part of its legitimate Data Activities. Further information on the sharing of Personal Data is set out below.
Legal bases for Processing your Personal Data
Novus Clinical Processes Personal Data only where it has a legal basis for doing so in the applicable jurisdiction. Such legal basis may include:
- The Processing being in Novus Clinical’s legitimate interest in providing you with access to the applicable Novus Clinical Services.
- The Processing being necessary for the performance of a contract between you and Novus Clinical.
- The Processing being necessary for the performance of a contract, concluded in your interest, between Novus Clinical and a third party, such as a Customer.
- The Processing is necessary, or legally required, on important public interest grounds, for the establishment, exercise, or defence of legal claims, or to protect your vital interests.
- Where the Processing is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
- The Processing is required by applicable law.
- With your consent (where such consent is required and given) as described in specific terms, privacy notices and/or consent forms. Where Novus Clinical relies on consent, the opportunity to give that consent will be provided prior to the Personal Data in question being collected. Your consent is valid only if given by yourself or through your authorised representative such as a legal guardian, agent, or holder of a power of attorney. Where Novus Clinical relies on consent, you may be entitled to withdraw that consent (in relation to future Processing only).
How Novus Clinical shares Personal Data
You should note that we may share your Personal Data with a limited number of other parties. For example, we may report the information to our appropriate Customer, and we may share the information with appropriate Vendors, in order to perform the applicable Novus Clinical Services. Examples follow:
Within the Novus Clinical Group
In the normal course of performing the Novus Clinical Services, Personal Data may be shared within the Novus Clinical Group for research and statistical purposes, drug safety and efficacy purposes, disease management, system administration and crime prevention or detection, or any purpose otherwise identified in this Privacy Statement.
With our Customers
We may share your Personal Data with our applicable Customer, in order for such Personal Data to be used for the benefit of the applicable project (for example, a clinical trial), and for research and statistical purposes, drug safety and efficacy purposes, disease management, system administration and crime prevention or detection, or any purpose otherwise identified in this Privacy Statement.
With our Vendors and other third parties
As mentioned elsewhere in this Privacy Notice, we may retain Vendors to perform elements of the Novus Clinical Services on our behalf and we may collaborate with other companies, regulatory authorities (or similar) and individuals with respect to the Novus Clinical Services. Examples of our Vendors include data analysis firms, consultants working with us to provide Novus Clinical Services, companies providing us with storage and distribution services, companies providing services related to the provision of Clinical Trial Supply Services, credit card processing companies, customer service and support providers, email and SMS vendors, web hosting and development companies and fulfilment companies. Some Vendors may collect Personal Data on our (or our Customers’) behalf. We endeavour to ensure all Vendors and other third parties respect the security of your Personal Data and treat it in accordance with law. We do not allow our Vendors to use your Personal Data for their own purposes and only permit them to Process your Personal Data for specified purposes and in accordance with our (or our applicable Customers’) instructions.
Through our website, we may provide links to other websites, services, and applications that are not operated or controlled by us. This Privacy Statement does not apply to the websites or other platforms of such third parties. While we attempt to facilitate access only to those third-party services that share our respect for your privacy, we cannot take responsibility for the content, privacy policies, or practices of those third parties. We encourage you to review and understand the privacy practices of any third party before providing any information to or through them. Your interactions with these third parties are governed by the privacy policy of the third party.
In connection with business transactions
As we continue to develop our business, we might sell or buy assets. In such transactions, user information, including Personal Data, may be one of the transferred business assets. Also, if either Novus Clinical itself or substantially all of Novus Clinical’s assets were to be acquired by another party, your Personal Data may be one of the transferred assets. Therefore, we may disclose and/or transfer your Personal Data to such third party in these circumstances.
To comply with our legal obligations
Novus Clinical reserves the right to disclose, without your prior permission, any Personal Data about you or your use of the Novus Clinical Services in circumstances where we have a good faith belief that such action is necessary to: (a) protect and defend the rights, property or safety of Novus Clinical, our employees, other users of the Novus Clinical Services, or the public; (b) enforce the terms and conditions that apply to use of the Novus Clinical Services; (c) as required by a legally valid request from a competent governmental authority and/or to comply with a judicial proceeding, court order, or legal process; or (d) respond to claims that any content violates the rights of third parties. We may also disclose Personal Data as we deem necessary to satisfy any applicable law.
Please be aware that we may also disclose to third parties, for any purpose, aggregated de-identified (anonymised) data that is not personally identifiable.
However, it should be noted that Novus Clinical does not sell Personal Data to third parties.
How we collect Personal Data online
Novus Clinical’s website may collect information that could contain Personal Data about your visits to our website, without you actively submitting such information. Unidentified information may be collected using various technologies, such as cookies and web beacons. Cookies are small text files that are transferred to your computer’s hard disk by a website. Web beacons (also referred to as GIF files, pixels, or internet tags) help Novus Clinical understand how you navigate around the Novus Clinical website. As part of your use of such sites, your internet browser automatically transmits to Novus Clinical’s website some of this information, such as the URL of the website you just visited and the browser version your computer is operating. Passive information collection technologies can make your use of Novus Clinical’s website easier by allowing Novus Clinical to provide better Novus Clinical Services, customise Novus Clinical websites based on user preferences, compile statistics, analyse trends, and otherwise administer and improve Novus Clinical’s websites. You can prevent the storage of cookies by adjusting the settings on your browser, though certain features of Novus Clinical’s website may not work without use of passive information collection technologies. Information collected by these technologies cannot be used to identify you without additional information.
Some of Novus Clinical’s business partners (such as Customers or Vendors with whom Nouvs Clinical contracts to assist it in carrying out Novus Clinical Services, including website providers), may use their cookies on the Novus Clinical website. Although Novus Clinical may not have direct access to or control over such cookies, this Privacy Notice governs the use of cookies by Novus Clinical and such business partners on Novus Clinical’s website. Novus Clinical may also allow social media companies (e.g., Facebook, LinkedIn) to put “widgets” on Novus Clinical websites. These third-party tools may also be used to track you across websites. For example, so long as you are logged in to Facebook, every time you land on a webpage that has a Facebook widget, Facebook will know you are on that webpage. Novus Clinical does not control the privacy practices of these third parties.
Some internet browsers allow you to limit or disable the use of tracking technologies that collect unidentified information, such as a Do Not Track (“DNT”) setting.
You should also be aware that our website may include links to third party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share Personal Data about you. We do not control these third-party websites and are not responsible for their privacy statements. We encourage you to read the privacy statement/policy of every website you visit.
International Personal Data and Personal Data transfers
Your data may be collected and Processed in any country or jurisdiction in which you access our services. Privacy law varies in different countries, but Novus Clinical will always comply with the privacy law prevailing and which applies to you, wherever you may be in the world.
Novus Clinical may transfer Personal Data outside of its country of origin for the purposes and in the manner set out in this Privacy Notice, including for Processing by Customers, Vendors, other appropriate third parties and Novus Clinical companies in connection with such purposes. In all situations, Novus Clinical takes reasonable steps to ensure that your privacy is protected. Such steps include, but are not limited to, implementing privacy, security, and contractual controls, as well as steps noted in this Privacy Notice, and steps as required by applicable law.
Where Personal Data is sent outside of the individual’s country, it may be subject to the laws of the country in which it is held, and may be subject to disclosure to the governments, courts, or law enforcement or regulatory agencies of such other country, pursuant to the laws of such country.
Novus Clinical endeavours to obtain assurances from its Vendors that they will safeguard Personal Data consistent with this Privacy Notice. An example of appropriate assurances that may be provided by Vendors includes a contractual obligation that they provide at least the same level of protection as is required by Novus Clinical’s privacy principles set out in this Privacy Notice. Where Novus Clinical becomes aware or suspects that a Vendor is using or disclosing Personal Data in a manner contrary to this Privacy Notice, Novus Clinical will take appropriate steps to prevent or stop the use or disclosure.
If you are an EEA or UK citizen and/or accessing Novus Clinical website in the EEA or the UK, then this paragraph may apply in addition to the above. Transfers of your Personal Data may be made to entities located outside the EEA/UK, including entities located in the United States, for Processing consistent with the purposes described in this Privacy Notice. Novus Clinical will implement appropriate contractual measures (including standard contractual data protection clauses) and other security measures where applicable, to ensure that the relevant Novus Clinical companies and third parties (Customers, Vendors, etc.) outside the EEA/UK provide an adequate level of protection for your Personal Data as set out in this Privacy Notice and as required by applicable law.
Security
Novus Clinical has implemented reasonable physical, technical, organisational and managerial controls and safeguards to keep your Personal Data protected from unauthorised access, disclosure, alteration, and destruction. Such measures may include but are not limited to:
- Encryption of communications.
- Encryption of information whilst it is in storage.
- Firewalls.
- Access controls.
- Separation of duties of staff.
- Pseudonymisation (where appropriate).
- Use only of properly validated software systems.
Novus Clinical trains its personnel on the importance of privacy and how to handle and manage Personal Data appropriately and securely. All employees and consultants are subject to a duty of confidentiality. Novus Clinical maintains physical, electronic and procedural measures to safeguard Personal Data from accidental or unauthorised access, use, disclosure, or deletion. Personal Data handled by Vendors or companies with which Novus Clinical may conduct joint programs, is governed by this Privacy Notice.
However, it should be noted that the confidentiality of Personal Data transmitted over the internet cannot be guaranteed. Novus Clinical urges you to exercise caution when transmitting Personal Data over the internet. Novus Clinical cannot absolutely guarantee that unauthorised third parties will not gain access to your Personal Data. Therefore, when submitting Personal Data to Novus Clinical online, you must consider both the benefits and the risks of doing so.
Data integrity, purpose limitation and retention periods
We will use Personal Data only in ways that are compatible with the purposes for which they were collected or consented to by the individual (where applicable), unless we reasonably consider that we need to use the information for another reason and that reason is compatible with the original purpose.
Novus Clinical has appropriate steps in place to ensure that Personal Data is relevant to its intended use, and is accurate, complete, and current.
Novus Clinical will only retain Personal Data for as long as it is needed to fulfil the purposes for which it was collected, subject to applicable data retention periods imposed upon Novus Clinical by applicable law. This may mean that your Personal Data is stored by Novus Clinical or its Vendors or Customers for a number of years, depending on the purpose and need for that Personal Data to be processed. For more information about Novus Clinical’s retention periods for Personal Data, please refer to the Contacts section below. You should also note that retention periods for Personal Data related to Novus Clinical Services is seven (7) years. These requirements are mandatory, for the purpose of safety.
Children
Novus Clinical does not intend to collect any Personal Data from children on the Novus Clinical website (children being individuals who have not reached the age of majority in their residential jurisdictions).
Your rights
You have certain rights and choices regarding our (and our applicable Customer’s and Vendors’) Processing of your Personal Data. Depending on your jurisdiction and the purposes for which the Personal Data is Processed, applicable law may entitle you to additional consumer rights, including the right to:
- Know the categories of and/or specific pieces of information regarding the Personal Data collected about you, including whether your Personal Data is sold or disclosed, and with whom your Personal Data is shared.
- Access a copy of the Personal Data retained about you.
- Request deletion of your Personal Data (but please note that we may not be lawfully permitted to delete Personal Data we have processed).
- Correct or amend your Personal Data.
- Request transfer of your Personal Data to you or another person in a commonly utilisable format.
- Object to certain uses of your Personal Data.
- Where we are relying on consent to process your Personal Data, you may usually withdraw your consent at any time. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain Novus Clinical Services to you. We will advise you if this is the case at the time you withdraw your consent.
- File a complaint with an appropriate data protection authority. For the UK, this is the Information Commissioner’s Office (ICO) at www.ico.org.uk. We would however always appreciate the chance to deal with your concerns before you make such a complaint, so please do contact us in the first instance at DPO@novusclinical.com.
We reserve the right to verify your identity in connection with any requests regarding Personal Data to help ensure that we provide the Novus Clinical Services to the individual to whom it pertains and allow only those individuals or their authorised representatives to exercise rights with respect to that information. If you are an authorised agent making a request on behalf of an individual, we may require additional information to verify that you are authorised to make that request. This may include obtaining a written authorisation and proof that you are authorised to make the request.
Novus Clinical may not be able to comply with a request where Personal Data has been destroyed, erased or made anonymous in accordance with Novus Clinical’s record retention obligations and practices. In the event that Novus Clinical cannot provide an individual with access to his/her Personal Data, Novus Clinical will endeavour to provide the individual with an explanation, subject to any legal or regulatory restrictions.
Contacts
Any questions or concerns regarding this Privacy Notice, the Processing of Personal Data by Novus Clinical, or related to revocation of consent to Process your Personal Data (where applicable), or any other of your data protection rights, should be directed to the contact address set out below. To submit a request to us, please contact us at: DPO@novusclinical.com, or by mail to the following address:
FAO The Data Protection Officer
Novus Clinical Ltd.
Priestley House
170 Elland Road
Leeds
LS11 8BU
To help us respond to your request, all communications should include the sender’s name and contact information (such as e-mail address, phone number or mailing address), and a detailed explanation of the request. In addition, communications related to Novus Clinical websites should include, as applicable, the e-mail address used for registration and the Novus Clinical website address on which Personal Data was provided. E-mail requests to delete, amend, or correct Personal Data should include “Deletion Request” or “Amendment/Correction Request”, as applicable, in the subject line of the e-mail or header of the letter, as applicable. Novus Clinical will endeavour to respond to all reasonable requests in a timely manner (generally, one month in the UK), and in any case, within any time limits prescribed by applicable local law. If we cannot meet these timelines, we will notify you and keep you updated.
We will not usually charge a fee to access your Personal Data, or to exercise any of the other rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. Alternatively, we could refuse to comply with your request in these circumstances. We will endeavour not to restrict or deny you access to our Services because of choices and requests you make in connection with your Personal Data. However, please note that certain choices may affect our ability to deliver Novus Clinical Services to you.
Any requests to opt-out of future communications from Novus Clinical or to opt-out of a particular Novus Clinical program should be directed to Novus Clinical using the contact methods above.
Changes to the Novus Clinical Privacy Notice
Novus Clinical keeps its data protection/privacy arrangements under review, and accordingly reserves the right to amend this Privacy Notice from time to time to reflect technological advancements, legal and regulatory changes and/or changes to Novus Clinical’s business practices, subject to applicable laws. If Novus Clinical changes its privacy practices, an updated version of this Privacy Notice will reflect those changes. Novus Clinical will provide notice of such changes by updating the effective date listed on this Privacy Notice. It is your responsibility to check this Privacy Notice frequently on our website to view any amendments. Your continued interaction with Novus Clinical will, in respect of Data Activity, be subject to the then-current Privacy Notice.
It is of course important that the Personal Data we hold about you is accurate and current. Please keep us informed if your Personal Data changes during your relationship with us.
