PI we collect and how we use it
We may collect the following personal information (“PI”) necessary for our business purposes:
- Basic personal details
- e.g., name; alias; date of birth; gender; family member names; family, lifestyle & social circumstances; image/photograph/video; marital status; physical characteristics/descriptions; signature; voice/audio
- Education & skills
- e.g., academic transcripts; Curriculum Vitae (CVs); educational background; languages; qualifications/certifications; training records/test scores
- Financial information
- e.g., investment account number; mortgage/loan account number; personal bank account information; personal credit card number
- Professional contact information
- e.g., email address; postal address; telephone number; company/entity name; title
- Professional details
- e.g., payment information; professional license number/status; professional memberships; reference/background checks
- Transactional data
- e.g., clinical trial participation; interactions with Lilly for products and services; speaking engagements; structured call notes; interactions with Lilly systems; audit logs; meeting minutes
We collect PI from you directly or indirectly, vendors and service providers, suppliers, contractors, data agencies and associations, publicly accessible sources, employees and former employees.
Lilly and/or Third Parties may process PI for the following purposes.
-
To meet our contractual obligations to you or others. Examples include contracting and business planning activities, study management, including monitoring of study activities, engaging scientific experts and leaders, product orders or requests for samples.
- In certain circumstances, you may be able to opt-out of this type of processing, but it could terminate the contract or otherwise impact our ability to perform a contractual obligation that may be owed to you.
-
Compliance with legal or regulatory obligations. Examples include processing and reporting adverse event information and product complaints, complying with company policies and security purpose, exercising or defending legal claims, and financial disclosure reporting.
- You may not be able to opt-out of this processing, but you still have the other rights described below.
- Lilly recommends that you inform patients when you report an adverse event/product complaint relating to them.
-
Through your use of various Lilly Services, you may have consented to receive specific types of electronic communications from us or consented to our using or disclosing your PI in certain ways.
-
Communicating information about our products and services (online or in-person) and other marketing purposes (e.g., providing promotional material, using email read receipts and online activity to enhance professional interactions) with your consent.
- Communications by email. If you consented to receive email communications, including for marketing and promotional purposes, then Lilly will process your PI (including your email and contact information, and information from web beacons) to contact you by email to provide you with health-related information, as well as information on our products and services (including promotional materials). Lilly uses business standard web beacons (also known as an “action tag” or “clear GIF technology”) in its commercial email communications to enable us (and our sales representatives) to determine if you’ve received, and opened, the emails. This information then can be used to create a profile of your activity for business and commercial purposes to enable us to provide offers and information (online or in person) based on your profile, and profiles of persons with similar interests, that may enhance your professional interactions with us.
- Text messaging to mobile telephone. If you consented to receive text messaging communications to your mobile telephone, including for marketing and promotional purposes, then Lilly will process your PI (including your mobile phone number and contact information) to provide you with health-related information, as well as information on our products and services (including promotional materials) via text. Text messages may include any standard text messaging rates that your carrier may impose.
- Communications to telephone. If you consented to receive telephone communications, including for marketing and promotional purposes, then Lilly will process your PI (including your phone and contact information) to contact you by telephone to provide you with health-related information, as well as information on our products and services (including promotional materials).
- Consenting to receive email(s), text message(s), and/or telephone calls from us is voluntary, but failure to do so means that we will be unable to provide promotional messaging to you via each/all mechanism(s). Remember, you can change or withdraw your consent at any time. All communications you receive will include instructions on how to opt-out of future communications. Your information may also be used for profiling for the same purposes shared above.
-
-
Lilly may have a legitimate interest in processing your PI to carry out the following business purposes, where such processing does not impact your privacy rights:
- Administration of our business processes
- Business and marketing research
- Company record retention
- Data analytics
- Engaging scientific experts and leaders
- Event management
- Financial disclosure reporting
- Maintaining and securing our systems and records (e.g., testing, validation, fixing software errors)
- Responding to requests for information
- Security and protection of rights
- Services and support
- Statistical analytics
- Validating your ability access/use certain product, services, and information
We may share your PI in compliance with applicable law with:
- Advisors and agents
- Affiliates and subsidiaries
- Business partners
- Lilly employees
- Vendors, suppliers, and contractors
- Others with your permission or as required by law
Where permitted by law, your PI may be:
- Combined with other information that you have previously provided or that Lilly has received from third parties, publicly available information, or other legitimate data sources for the same purposes shared above;
- Used to create a profile of you in order to analyze, predict your preferences, provide offers and services and to share information based on your professional profile and the profiles of people with similar interests;
In compliance with applicable law, Lilly may use Artificial Intelligence (AI) to assist in our processing of information for the purposes described above and may offer services through tools and platforms using AI.
We also value your input about the quality of the services you receive and may also contact you to ask for your opinion.
Cookies and tracking
We and other third parties may use cookies, pixel tags, session replay technology, and other similar tracking technologies to automatically collect information about browsing activity, device type, and similar information within our websites. This information, which may be considered personal information in some jurisdictions, is used, for example, to analyze and understand how you access, use, and interact with our websites; to identify and resolve bugs and errors in our websites; to assess, secure, protect, optimize, and improve the performance of our websites; for marketing, advertising, measurement and analytics purposes; and to personalize content on our websites. We may also de-identify and/or aggregate such information to analyze trends, administer our websites, and gather broad demographic information for aggregate uses, and for any other lawful purposes.
Cookies
Cookies are alphanumeric identifiers used for tracking purposes. Some cookies allow us to make it easier for you to navigate our websites, while others are used to enable a faster log-in process, to support the security and performance of the websites, or to allow us to track activity and usage data within and across our websites.
Pixel Tags and Similar technologies
Pixel tags (sometime called web beacons or clear GIFs) are tiny graphics with a unique identifier, similar in function to cookies. We may use these tracking technologies to understand users’ activities, to help manage content and compile usage statistics, and in emails to let us know when they have been opened or forwarded so we can track response rates and gauge the effectiveness of our communications.
Data analytics
We may collect and process data from server logs designed to capture your user events or specific conditions pertinent to the websites utilizing them. This aids Lilly in assessing the marketing key performance metrics of our websites, such as determining the individual visitors count or observing the frequency at which individual users interact with essential components of our website and helps to us understand your personal preferences to provide better services.
Third-party analytics and tools
We may use third-party tools, such as Google Analytics, which are operated by third party companies to evaluate usage and traffic on our websites. These third-party analytics companies use cookies, pixels, and other tracking technologies to collect usage data to provide us with reports and metrics that help us analyze, improve, and enhance performance and user experience. You can learn more about how Google uses your information at www.google.com/policies/privacy/partners/ (“How Google uses information from sites or apps that use our services”). You can also download the Google Analytics Opt-out Browser Add-on to prevent your information from being used by Google Analytics at https://tools.google.com/dlpage/gaoptout.
Cross-device tracking.
We and Third Parties may use the information we collect about you within our websites, and on other third-party websites, to help us and these third parties identify other devices that you use (e.g., a mobile phone, tablet, other computer, etc.) to interact or engage with us or our websites.
Targeted advertising.
We work with third parties, such as ad networks, channel partners, mobile ad networks, analytics and measurement services, and others (“third-party ad companies”) to personalize content and display advertising within our Services, as well as to manage our advertising on third-party websites, mobile apps, and online services. We may share certain information with third-party ad companies, and we and third-party ad companies may use cookies, pixels tags, and other tools to collect usage and browsing information within our Services, as well as on third-party websites, apps, and services. This information may include IP address, location information, cookie and advertising IDs, and other identifiers, as well as browsing information.
You have certain choices available to you to help manage the use of cookies and other technologies:
-
When you visit our websites, we may provide you a choice about whether to “agree” or “disagree” to the use of cookies and other technologies to personalize content and ads on our websites. You should feel free to select “disagree” to limit the circumstances in which personal information collected through tracking technologies on the website may be used for targeted advertising.
-
Provided to you by third parties:
- Google Analytics offers an opt-out provision for website visitors who do not want their data to be used by Google Analytics. You can receive more information about this option here.
- There also are choices provided by the Network Advertising Initiative and the Digital Advertising Alliance. Ads displayed to you using targeted advertising technologies will usually have an AdChoices logo in the corner, which you can also click on to begin the industry opt-out process. Additionally, if you receive ads on a social media site, you can check that site’s privacy statement and terms of use to determine how to stop seeing such ads. The European Interactive Digital Advertising Alliance keeps a website where people can opt out of receiving interest-based advertising from some or all of the network advertising companies participating in the program. You can find information about the EIDAA here.
- Do Not Track: There are different ways you can prevent tracking of your online activity. One of them is setting a preference in your browser that alerts websites you visit that you do not want them to collect certain information about you. This is referred to as a Do-Not-Track (“DNT”) signal. Please note that currently our websites and web-based resources do not respond to these signals from web browsers. At this time, there is no universally accepted standard for what a company should do when a DNT signal is detected.
Reasons we share PI
We may share your PI with the recipients listed above for purposes consistent with those identified in this notice. These Third Parties have agreed to protect the information and to process it as directed by us (if acting on our behalf) or as required by law.
We may also be required to disclose your information in response to lawful requests by public authorities, including to comply with national security or law enforcement requests.
Where we transfer and process PI
This website is owned and operated by Eli Lilly and Company Limited in United Kingdom.
Your PI may be transferred and processed by and between Eli Lilly and Company, its affiliates and wholly-owned subsidiaries, and Third Parties worldwide. When transferring PI across country borders, Lilly utilizes appropriate transfer mechanisms as applicable (which may include consent, Standard Contractual Clauses, existing adequacy decisions, intra-corporate data transfer agreements, etc.). To obtain additional information regarding the mechanism for transfers that Lilly has in place for cross-border transfers of PI, please contact us at privacy@lilly.com or visit https://privacynotice.lilly.com/.
We may also provide your PI to a Third Party in connection with the merger, sale, assignment, or other transfer of the business to which the information relates, in which case PI may be shared with, sold, transferred, rented, licensed or otherwise in connection with the contemplated transaction to the Third Party. We will require any such Third Party to agree to treat PI in accordance with this notice.
How long we keep PI
How we secure PI
Your rights and choices
Upon verification of your identity, and as applicable by law, you have the right to request:
- information from us on how your PI is being processed and with whom it is being shared;
- to see and get a copy of the PI that we have about you;
- that we correct, restrict the processing of, and/or erase/delete your PI;
- to have your information transmitted to another entity or person in a machine-readable format, in limited circumstances;
- a copy of the Standard Contractual Clauses (SCCs) and Appendix for European Economic Area, Swiss, and United Kingdom data transferred pursuant to SCCs.
You also have the right to:
- change or withdraw your consent at any time;
- unsubscribe/opt out from communications or profiling for marketing, including direct marketing;
- object to the processing of your PI;
There may be exceptions that apply to your request. To exercise your rights, you or your authorized representative may submit a request to:
- For Greece: privacy@lilly.gr
- For EEA, Serbia, Switzerland and UK: datarights@lilly.com.
You will not be discriminated against for exercising any of your rights.
How to contact us
If you have any questions about this Notice, you may contact us at:
Data privacy officer
Eli Lilly and Company Limited
Lilly House, Basing View, Basingstoke
Hampshire - RG21 4FA
Telephone +44 (0) 1256 315000
Email: privacy@lilly.com
For more information about Lilly’s privacy practice, please view the Privacy Statement at https://www.lilly.com/privacy.
How to submit a complaint
If you are not satisfied with our response or believe we are processing your PI out of accordance with the law, you can register a complaint with a relevant regulatory authority (e.g., a Data Protection Authority (DPA) or Attorney General).
Links to third-party websites
Changes to our privacy practices
Options for PI and SPI categories
- Basic personal details
- e.g., name; alias; date of birth; gender; family member names; family, lifestyle & social circumstances; image/photograph/video; marital status; physical characteristics/descriptions; signature; voice/audio
- Behavioral information
- e.g., behavior; computer ergonomics; inferences reflecting preferences
- Biometric identifiers
- Commercial information
- e.g., purchasing/consuming history or tendencies
- Criminal/conviction Records
- Education & skills
- e.g., academic transcripts; Curriculum Vitae (CVs); educational background; languages; qualifications/certifications; training records/test scores
- Employment details
- e.g., benefits/entitlements data; bullying/harassment details; business unit/division; contract type; corporate credit card number; disciplinary action; end date & reason for termination; exit interview & comments; grievances & complaints; hours of work; job application details; job title/role; line/reporting manager; office location; path/level; pay history; performance appraisal; personnel number; previous work history; record of absence/time tracking/annual leave; salary/wage; salary/wage expectation; start date; succession planning/talent potential; workers compensation claims
- Financial information
- e.g., investment account number; mortgage/loan account number; personal bank account information; personal credit card number
- Government identifiers
- e.g., driving license number; national identification number; national identity card details; passport number; social insurance number; tax ID number; U.S. Social Security Number; visa number
- Health information, and any other data that could easily result in an inferred health status
- Location data
- e.g., GPS position; geotracking; precise geolocation
- Online/electronic resources activity
- e.g., account name/number/user ID/username, account age; browsing time; cookie information; email read receipts; network/device Identifiers (e.g., IP address, MAC address, device ID, device name, device type); secret component(s) of authentication (e.g., password, passcode, biometrics, PIN, certificate); website history
- Personal contact information
- e.g., email address; postal address; telephone number; unique personal identifier. This may also include information for your emergency contact(s).
- Professional details
- e.g., payment information; professional license number/status; professional memberships; reference/background checks
- Professional contact information
- e.g., email address; postal address; telephone number; company/entity name; title
- Protected characteristics
- e.g., nationality/citizenship/immigration status; privately held political/philosophical/religious beliefs and opinions; racial or ethnic origin; sex life information; sexual orientation; status as a victim of a crime; trade union membership; transgender or non-binary status
- Social media information
- e.g., social media account/contact/history
- Transactional data
- e.g., clinical trial participation; interactions with Lilly for products and services; speaking engagements; structured call notes; interactions with Lilly systems; audit logs; meeting minutes
- Travel & expense details
- e.g., expense details; travel booking details; travel history
Options for sources
- Adverse event reporters and subjects
- Affiliates and Subsidiaries
- Business partners
- Clinical/medical investigators and staff conducting clinical/medical research
- Consumers
- Customers
- Directly or indirectly from you
- Your interactions with our products and services
- Employees, former employees, potential employees, and their family members
- Government officials
- Healthcare professionals
- Investors and shareholders
- Internet service providers
- Lilly systems and devices
- Marketing and data analytics providers; Joint marketing partners
- Operating systems and platforms
- Patients and clinical/medical trial participants
- Publicly accessible sources
- Public databases; social media platforms
- Vendors and service providers, suppliers, contractors, and associations
- Data agency
- Other third parties
Options for purposes
- Activities for public health and interest
- Administration of our business processes
- Business and marketing research
- Communicating information about our products and services (online or in-person)
- Contracting and business planning activities
- Data analytics
- Engaging scientific experts and leaders
- Event management
- Finance or tax activities
- Marketing purposes (e.g., providing promotional material, using email read receipts and online activity to enhance professional interactions)
- Merger and acquisition due diligence but only to the extent that PI is necessary for such transactions, in which case we will comply with applicable legal requirements
- Processing and reporting adverse event information and product complaints
- Product orders or requests for samples
- Responding to requests for information
- Statistical analytics
- Study management, including monitoring of study activities
- Validating your ability access/use certain product, services, and information
Options for basis
- Consent
- Required by law (e.g., pharmacovigilance, product complaints, etc.)
- To conduct human resources management per local labor rules and collective labor contracts
- To establish, exercise or defend legal claims
- To establish, manage or terminate an employment relationship
- To perform a contract (e.g., to compensate a person)
- To perform a task in the public’s interest (i.e., to avoid a major public threat)
- To protect the vital interest of the person (e.g., safety or survival of the person)
- To pursue Lilly’s legitimate interest as part of its normal course of business, provided there are no overriding interests of the person
- To process PI that is already disclosed by the individual themselves or otherwise legally disclosed
Options for recipients
- Advertising networks
- Advisors and agents
- Affiliates and subsidiaries
- Business partners
- Data analytics providers
- Data brokers
- Government officials
- Healthcare professionals
- Healthcare providers and pharmacies (at your direction)
- Internet service providers
- Lilly employees
- Operating systems and platforms
- Regulators, government entities, and law enforcement
- Social networks
- Vendors, suppliers, and contractors
- Others with your permission or as required by law