Calliditas Therapeutics AB, 556659-9766, Wallingatan 26 B, 1 tr, 111 24 Stockholm (“Calliditas”) shall only process personal data in accordance with applicable data protection law and high industry standards.

Personal data

Calliditas mainly process the personal data provided to us;

(i) by you in the day-to-day communications, or
(ii) in connection with entering into or performing an agreement or business arrangement with you, or
(iii) by a third party allowed by law or your consent.

The personal data may consist of contact and identification details and other information relevant to the situation.

Purpose

Calliditas process personal data for the purpose of communicating with you and to perform, manage and comply with agreements between us as well as rights and obligations which are allowed by law or applicable regulation.

Legal grounds

The legal grounds for processing personal data is either;

(i) your consent which shall be considered provided when you either voluntary submit the personal data or enter into an agreement with us, or
(ii) a legitimate interest allowed under law.

Security

Calliditas shall use adequate technical and organisational security measures to protect the personal data from loss and to safeguard against access from unauthorised persons.

Transfers of personal data may only occur;

(i) to third parties who perform services on Calliditas behalf and who may only process personal data in accordance with our instructions, and may not use personal data for their own purposes; and
(ii) outside the EU/EEA only in accordance with applicable data protection laws and subject to the EU Commission’s standard contractual clauses, and
(iii) as otherwise permitted by law or your consent.

Duration

The duration we process personal data is limited to what is reasonable for the purpose of the processing, unless otherwise required or permitted by law.

Rights

Calliditas is the controller of the personal data processing, meaning that we are responsible for that the personal data is processed correctly and in accordance with applicable data protection laws.

Unless prevented by applicable law, regulation or agreement data subjects have the right to;

(i) know what personal data we process about them, and
(ii) request that we rectify or erase inaccurate or incomplete personal data
(iii) object to specific processing of personal data.
(iv) receive the personal data provided by them and have the personal data transferred to another party responsible for data processing.

All communications with Calliditas regarding how we process personal data or exercise of any of your rights can be sent by e-mail to info@calliditas.com or by post to the address above.

Reports and complaints can also be directed to Datainspektionen who is the supervisory authority for our processing of personal data.